EIN: 840644739
UEI: V4FMY71FYXZ6
262374576, 383721881, 811725341, 840517947, 840559160, 840600334, 846000542, 846000545, 846000546, 846000551, 846000555, 846000556, 846000558, 846000574, 846001656, 980256500 · unlinked EINs have no separate FAC filing
Audited by: Office of the State Auditor
Cognizant agency: 93 [Department of Health and Human Services]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 9, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 9, 2026 (2 days from today).
What is a management decision? →Finding 2025-034 Compliance with Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Eligibility for Medicaid The Department is responsible for ensuring that all of its expenditures under the Medicaid program [ALN 93.778] are appropriate, and that it complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the Department (in this case, the State). Individuals and families apply for Medicaid benefits at their local county departments of human/social services, designated MA sites, or online through the Department’s Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, reviewing the PEAK system for application data, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility based on program criteria. Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits (also known as redetermination). States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at the time, either from the beneficiary’s case file or other electronic data sources, like PEAK and CBMS, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. Once the renewal forms are completed and returned to the Department for processing, the caseworker enters the applicant’s information into CBMS, and, once all required information is entered, they can mark the application as complete. At that point, CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services that they provide to Medicaid beneficiaries. The Department pays for Medicaid services through one of two reimbursement methods: (1) fee-for-service (FFS) payments for specific services rendered or (2) capitation payments, monthly fixed payments that are paid to managed care entities (MCEs). Once a beneficiary is determined eligible, then they determine whether to enroll in FFS or an MCE. FFS reimbursements are paid directly to providers for services rendered. Capitation payments are paid to MCEs, which are groups or organizations of medical service providers who contract with a network of providers for services. The Department pays monthly capitation payments to MCEs on behalf of beneficiaries based on the number of eligible beneficiaries enrolled in its plan. These payments are made to the MCE regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that it only provides Medicaid payments to eligible providers for providing allowable services on behalf of Medicaid-eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had appropriate internal controls over and complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to ensure local counties and MA site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. The Department planned to implement this recommendation by January 2025. During our audit, we performed testing related to the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2025. In addition, we performed specific testing on a random nonstatistical sample of 125 beneficiaries to determine if they were properly deemed eligible for and received Medicaid benefits during Fiscal Year 2025. Our sampling methodology, including the strata and sample sizes, was developed based on our risk assessment procedures and included the following procedures: *We obtained a listing of Medicaid FFS claims that were submitted by providers and paid by the Department during Fiscal Year 2025 and a listing of capitation payments made to MCEs on behalf of Medicaid-eligible individuals during Fiscal Year 2025. The Department pulled this data from the Colorado interChange claims system. • We summarized each listing by Medicaid ID numbers (ID), and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in two populations: (1) a population of capitation payments totaling $2,156,417,706, made on behalf of 1,398,794 individual beneficiaries, and (2) a population of FFS claims totaling $10,553,035,025, made on behalf of 1,018,911 individual beneficiaries. • We stratified our population, as shown in the following table, into six strata defined by the total amount of payments for each unique ID. As part of our analysis, we noted FFS beneficiaries represented 42 percent of the total number of individual beneficiaries who had payments made on their behalf during Fiscal Year 2025, and beneficiaries with capitation payments represented 58 percent of the total number of individual beneficiaries who had capitation payments made on their behalf during Fiscal Year 2025. Although FFS claims represented only 42 percent of the total number of individual beneficiaries, they represented 83 percent of the total dollar amount of all claims and individual capitation payments made during Fiscal Year 2025. As such, we stratified the data with two strata for capitation payments and four strata for FFS payments. We selected 26 capitation samples and 99 FFS samples from the strata for a total sample of 125 payments for beneficiaries. • For each sampled ID, we tested eligibility covering the dates of service for every Fiscal Year 2025 payment made on the beneficiary’s behalf. See " Schedule of Findings and Questioned Costs" for table/chart. Our testing included reviewing each payment’s supporting documentation, which included case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents that supported eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? Based on the testwork performed, we determined that the Department is still in the process of fully implementing our Fiscal Year 2023 recommendation. While we did not identify any errors related to processing beneficiary applications within the required timeframes, we continued to identify issues related to missing case file documentation and income calculations. We identified at least one error in 7 of the 125 Medicaid case files tested (6 percent). These errors resulted in a total of $240,606 in known federal and state questioned costs for Fiscal Year 2025 ($120,302 in federal costs and $120,304 in state costs). Specifically, we found the following: • Missing Case File Documentation. In three cases, we determined the case file did not have documentation to support income and/or resources, such as wage stubs or bank statements, which are necessary to support the Medicaid eligibility determination, as required by federal and state regulations. This resulted in known questioned costs of $237,745 ($118,872 in federal costs and $118,873 in state costs). Federal regulation [420 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.4.B] notes that income may be self-attested by an applicant or member and verified through an electronic data source. If the self-attested income cannot be verified electronically, the applicant must provide documentation of income. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. State regulation [10 CCR 2505-10, 8.100.7.A] notes that applicants receiving long-term case services under the 300% Institutionalized Special Income category must conform with the regulations regarding resource limits and exemptions set forth in section 10 CCR 2505-10, 8- 100.5, which notes that the resource limit for these long-term care individuals is $2,000. State regulation [10 CCR 2505-10, 8.100.5.M] notes that the resource limit for individuals receiving Home and Community Based Services assistance is $2,000. • Issues with Income Calculations. In four cases, we identified issues with the income calculation used to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, we found the following: III-8 Colorado Office of the State Auditor In two cases, the incorrect number of household members was entered into CBMS, which caused the incorrect income threshold to be used in the income calculation. In addition, one of these cases also incorrectly excluded reportable income in the member’s income calculation. These issues resulted in known questioned costs of $725 ($362 in federal costs and $363 in state costs). In two cases, out-of-date income information was used in the calculation. We noted in both instances, CBMS had current income information that was not used in the income calculation. For one of those cases, if the correct income was used in the calculation, the members’ total income would have been over the eligibility limit. This resulted in known questioned costs of $2,136 ($1,068 in federal costs and $1,068 in state costs). Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.G.4] notes that adults applying for medical assistance shall be determined financially eligible for medical assistance as long as their total household income does not exceed 133% of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.C] notes that the financial eligibility of applicants for medical assistance shall be determined based on current or previous monthly household income and family size. The Modified Adjusted Gross Income calculation for the purposes of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. Why did these problems occur? We determined that the Department’s existing internal controls over the income calculations and income and resource documentation requirements, which are necessary for Medicaid eligibility determinations, did not ensure caseworkers were determining eligibility appropriately, and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that (1) the required documentation to support the income calculation was maintained within the case file, (2) current income and resource information is used when calculating monthly income and resource amounts, and (3) the correct household composition is used when determining eligibility. Why do these problems matter? As the state department responsible for ensuring that all Medicaid expenditures are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See " Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-034 The Department of Health Care Policy and Financing should strengthen its internal controls over the income calculation and income and resource documentation requirements that are necessary for Medicaid eligibility determinations to ensure eligibility is determined appropriately and in accordance with federal and state regulations. This should include ensuring that (1) local counties and Medical Assistance site caseworkers are sufficiently trained to maintain the required documentation to support eligibility in the case file, (2) current income and resource information is used when calculating monthly income and resource amounts, and (3) the correct household composition is used when determining eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2027 The Department agrees with the recommendation and will strengthen internal controls over Medicaid eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring the development and implementation of Department-approved Corrective Action Plans. These plans will be required to address root causes related to income and resource calculation, documentation of eligibility determinations, and household composition, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are appropriately addressed.
Show full finding ▾Hide full finding ▴Finding 2025-034 Compliance with Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Eligibility for Medicaid The Department is responsible for ensuring that all of its expenditures under the Medicaid program [ALN 93.778] are appropriate, and that it complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the Department (in this case, the State). Individuals and families apply for Medicaid benefits at their local county departments of human/social services, designated MA sites, or online through the Department’s Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, reviewing the PEAK system for application data, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility based on program criteria. Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits (also known as redetermination). States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at the time, either from the beneficiary’s case file or other electronic data sources, like PEAK and CBMS, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. Once the renewal forms are completed and returned to the Department for processing, the caseworker enters the applicant’s information into CBMS, and, once all required information is entered, they can mark the application as complete. At that point, CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services that they provide to Medicaid beneficiaries. The Department pays for Medicaid services through one of two reimbursement methods: (1) fee-for-service (FFS) payments for specific services rendered or (2) capitation payments, monthly fixed payments that are paid to managed care entities (MCEs). Once a beneficiary is determined eligible, then they determine whether to enroll in FFS or an MCE. FFS reimbursements are paid directly to providers for services rendered. Capitation payments are paid to MCEs, which are groups or organizations of medical service providers who contract with a network of providers for services. The Department pays monthly capitation payments to MCEs on behalf of beneficiaries based on the number of eligible beneficiaries enrolled in its plan. These payments are made to the MCE regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that it only provides Medicaid payments to eligible providers for providing allowable services on behalf of Medicaid-eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had appropriate internal controls over and complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to ensure local counties and MA site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. The Department planned to implement this recommendation by January 2025. During our audit, we performed testing related to the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2025. In addition, we performed specific testing on a random nonstatistical sample of 125 beneficiaries to determine if they were properly deemed eligible for and received Medicaid benefits during Fiscal Year 2025. Our sampling methodology, including the strata and sample sizes, was developed based on our risk assessment procedures and included the following procedures: *We obtained a listing of Medicaid FFS claims that were submitted by providers and paid by the Department during Fiscal Year 2025 and a listing of capitation payments made to MCEs on behalf of Medicaid-eligible individuals during Fiscal Year 2025. The Department pulled this data from the Colorado interChange claims system. • We summarized each listing by Medicaid ID numbers (ID), and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in two populations: (1) a population of capitation payments totaling $2,156,417,706, made on behalf of 1,398,794 individual beneficiaries, and (2) a population of FFS claims totaling $10,553,035,025, made on behalf of 1,018,911 individual beneficiaries. • We stratified our population, as shown in the following table, into six strata defined by the total amount of payments for each unique ID. As part of our analysis, we noted FFS beneficiaries represented 42 percent of the total number of individual beneficiaries who had payments made on their behalf during Fiscal Year 2025, and beneficiaries with capitation payments represented 58 percent of the total number of individual beneficiaries who had capitation payments made on their behalf during Fiscal Year 2025. Although FFS claims represented only 42 percent of the total number of individual beneficiaries, they represented 83 percent of the total dollar amount of all claims and individual capitation payments made during Fiscal Year 2025. As such, we stratified the data with two strata for capitation payments and four strata for FFS payments. We selected 26 capitation samples and 99 FFS samples from the strata for a total sample of 125 payments for beneficiaries. • For each sampled ID, we tested eligibility covering the dates of service for every Fiscal Year 2025 payment made on the beneficiary’s behalf. See " Schedule of Findings and Questioned Costs" for table/chart. Our testing included reviewing each payment’s supporting documentation, which included case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents that supported eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? Based on the testwork performed, we determined that the Department is still in the process of fully implementing our Fiscal Year 2023 recommendation. While we did not identify any errors related to processing beneficiary applications within the required timeframes, we continued to identify issues related to missing case file documentation and income calculations. We identified at least one error in 7 of the 125 Medicaid case files tested (6 percent). These errors resulted in a total of $240,606 in known federal and state questioned costs for Fiscal Year 2025 ($120,302 in federal costs and $120,304 in state costs). Specifically, we found the following: • Missing Case File Documentation. In three cases, we determined the case file did not have documentation to support income and/or resources, such as wage stubs or bank statements, which are necessary to support the Medicaid eligibility determination, as required by federal and state regulations. This resulted in known questioned costs of $237,745 ($118,872 in federal costs and $118,873 in state costs). Federal regulation [420 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.4.B] notes that income may be self-attested by an applicant or member and verified through an electronic data source. If the self-attested income cannot be verified electronically, the applicant must provide documentation of income. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. State regulation [10 CCR 2505-10, 8.100.7.A] notes that applicants receiving long-term case services under the 300% Institutionalized Special Income category must conform with the regulations regarding resource limits and exemptions set forth in section 10 CCR 2505-10, 8- 100.5, which notes that the resource limit for these long-term care individuals is $2,000. State regulation [10 CCR 2505-10, 8.100.5.M] notes that the resource limit for individuals receiving Home and Community Based Services assistance is $2,000. • Issues with Income Calculations. In four cases, we identified issues with the income calculation used to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, we found the following: III-8 Colorado Office of the State Auditor In two cases, the incorrect number of household members was entered into CBMS, which caused the incorrect income threshold to be used in the income calculation. In addition, one of these cases also incorrectly excluded reportable income in the member’s income calculation. These issues resulted in known questioned costs of $725 ($362 in federal costs and $363 in state costs). In two cases, out-of-date income information was used in the calculation. We noted in both instances, CBMS had current income information that was not used in the income calculation. For one of those cases, if the correct income was used in the calculation, the members’ total income would have been over the eligibility limit. This resulted in known questioned costs of $2,136 ($1,068 in federal costs and $1,068 in state costs). Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.G.4] notes that adults applying for medical assistance shall be determined financially eligible for medical assistance as long as their total household income does not exceed 133% of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.C] notes that the financial eligibility of applicants for medical assistance shall be determined based on current or previous monthly household income and family size. The Modified Adjusted Gross Income calculation for the purposes of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. Why did these problems occur? We determined that the Department’s existing internal controls over the income calculations and income and resource documentation requirements, which are necessary for Medicaid eligibility determinations, did not ensure caseworkers were determining eligibility appropriately, and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that (1) the required documentation to support the income calculation was maintained within the case file, (2) current income and resource information is used when calculating monthly income and resource amounts, and (3) the correct household composition is used when determining eligibility. Why do these problems matter? As the state department responsible for ensuring that all Medicaid expenditures are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See " Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-034 The Department of Health Care Policy and Financing should strengthen its internal controls over the income calculation and income and resource documentation requirements that are necessary for Medicaid eligibility determinations to ensure eligibility is determined appropriately and in accordance with federal and state regulations. This should include ensuring that (1) local counties and Medical Assistance site caseworkers are sufficiently trained to maintain the required documentation to support eligibility in the case file, (2) current income and resource information is used when calculating monthly income and resource amounts, and (3) the correct household composition is used when determining eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2027 The Department agrees with the recommendation and will strengthen internal controls over Medicaid eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring the development and implementation of Department-approved Corrective Action Plans. These plans will be required to address root causes related to income and resource calculation, documentation of eligibility determinations, and household composition, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are appropriately addressed.
The Department agrees with the recommendation and will strengthen internal controls over Medicaid eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring the development and implementation of Department-approved Corrective Action Plans. These plans will be required to address root causes related to income and resource calculation, documentation of eligibility determinations, and household composition, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are appropriately addressed.
2024-034, 2024-036
Finding 2025-035 Compliance with Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Eligibility for Children’s Basic Health Plan The Department is responsible for ensuring that all federal Children’s Health Insurance Plan (CHIP) [ALN 93.767] expenditures are appropriate, and that the State complies with federal and state program requirements. CBHP, Colorado’s state-administered children’s health plan, is partially funded with federal CHIP dollars. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the Department. For CBHP, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. After an individual is determined eligible for CBHP, the individual is enrolled into an MCE plan. The specific MCE plan the individual is enrolled in is based on the county the individual lives in. The Department provides all county, MA site, and Department eligibility staff with copies of its Department-prepared policy and operational training documents and guides for reference. These documents are meant to provide eligibility staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with MCEs, which are groups or organizations of medical service providers that furnish services to CBHP members under capitated reimbursement agreements. Under these agreements, MCEs contract with a network of providers to provide services to CBHP members. The CBMS eligibility data feeds into the Department’s medical claims system, Colorado interChange, which is programmed to pay MCEs in lump-sum monthly payments (capitation payments) for the services that they provide on behalf of CBHP beneficiaries. Colorado interChange makes these payments based on eligibility information received from CBMS and requirements specified in federal and state regulations. The Department pays MCEs based on the number of eligible beneficiaries enrolled in its plan. Capitation payments are paid to the MCE regardless of whether the providers serve beneficiaries during the month or not. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to ensure local counties and MA site caseworkers are appropriately trained and held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and maintaining the required documentation to support eligibility in the case file. The Department planned to implement this recommendation by January 2025. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2025. In addition, we performed testing on a random nonstatistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2025. We obtained a listing of CBHP capitation payments totaling $256,524,048, that were submitted by MCEs and paid by the Department during Fiscal Year 2025 on behalf of 156,430 individual beneficiaries. From that listing, we selected 60 beneficiaries to determine whether those individual’s CBHP eligibility determinations were appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? Based on the testwork performed, we determined the Department is still in the process of fully implementing our Fiscal Year 2023 recommendation. While we did not identify any errors related to processing beneficiary applications within the required timeframes or eligibility requirements related to applicants with other health insurance, we continued to identify issues with missing case file documentation. We identified errors in 7 of the 60 CBHP case files tested (12 percent). These errors resulted in a total of $7,154 in known federal and state questioned costs for Fiscal Year 2025 ($4,650 in federal costs and $2,504 in state costs). Specifically, we found the following: • Missing Case File Documentation. In two cases, we determined the case file did not have documentation to support income, such as wage stubs, which is necessary to support the CBHP eligibility determination, as required by federal and state regulations. This resulted in known questioned costs of $2,553 ($1,659 in federal costs and $894 in state costs). Federal regulation [42 CFR 457.965] notes that the state must include in each applicant’s record facts to support the state’s determination of the applicant’s eligibility for CHIP. State regulation [10 CCR 2505-3, 130] notes that, to be eligible for CBHP, an applicant shall provide minimal verification as required in 10 CCR 2505-10-8.100.4.B. At minimum, applicants seeking medical assistance shall provide all of the following: social security number, verification of citizenship and identity and/or legal immigrant status, and support for earned and unearned income. State regulation [10 CCR 2505-10, 8.100.4.B] notes that income may be self-attested by an applicant or member and verified through an electronic data source. If the self-attested income cannot be verified electronically, the applicant must provide income documentation. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. • Issues with Income Calculations. In five cases, we identified issues with the income calculation used to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, we found the following: In 1 case, the incorrect number of household members was entered into CBMS, which caused the incorrect income threshold to be used in the income calculation. If the correct number of household members was used in the calculation, the member’s total income would have been over the eligibility limit. This resulted in known questioned costs of $2,037 ($1,324 in federal costs and $713 in state costs). In 3 cases, out-of-date income information was used in the calculation. In 2 of those cases, if the correct income was used in the calculation, the members’ total income would have been over the eligibility limit. This resulted in known questioned costs of $1,423 ($925 in federal costs and $498 in state costs). In 1 case for a self-employed individual, an incorrect expense amount was used in the member’s income calculation, which caused total income to be understated in the calculation. If the correct expense amount was used in the calculation, the member’s total income would have been over the eligibility limit. This resulted in known questioned costs of $1,141 ($741 in federal costs and $400 in state costs). State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the CBHP, an eligible person shall have a household income greater than 142 percent, but not exceeding 260 percent of the federal poverty level, adjusted for household size for children younger than age 19. State regulation [10 CCR 2505-3, 150.1] notes that the income calculation for the CBHP shall be determined by following the Medicaid Modified Adjusted Gross Income Methodology for income calculation, which is defined in 10 CCR 2505-10-8-100.4.C. State regulation [10 CCR 2505-10, 8.100.4.C] notes that the financial eligibility of applicants for medical assistance shall be determined based on current or previous monthly household income and family size. The Modified Adjusted Gross Income calculation for the purpose of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. State regulation [10 CCR 2505-10, 8.100.3.K.9] notes that in order to determine the net profit (or income) of a self-employed applicant, the cost of doing business (expenses) should be deducted from gross income. Why did these problems occur? We determined that the Department’s existing internal controls over CBHP eligibility determinations did not consistently ensure caseworkers were determining eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that the required documentation to support the income calculation was maintained within the case file, and that the correct income and income thresholds were used when determining eligibility. Why do these problems matter? As the state department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for the CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-035 The Department of Health Care Policy and Financing should strengthen its internal controls over the Children’s Basic Health Plan eligibility requirements to ensure eligibility is determined appropriately and in accordance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local county and Medical Assistance site caseworkers are appropriately trained on and comply with requirements to maintain appropriate income documentation to support eligibility in the case file, and comply with requirements to use the correct income and income thresholds when determining eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2027 The Department agrees with the recommendation and will strengthen internal controls over Children’s Basic Health Plan eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring Department-approved Corrective Action Plans. These plans will be required to address root causes related to income documentation, application of correct income thresholds, and compliance with CBHP eligibility requirements, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are addressed.
Show full finding ▾Hide full finding ▴Finding 2025-035 Compliance with Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Eligibility for Children’s Basic Health Plan The Department is responsible for ensuring that all federal Children’s Health Insurance Plan (CHIP) [ALN 93.767] expenditures are appropriate, and that the State complies with federal and state program requirements. CBHP, Colorado’s state-administered children’s health plan, is partially funded with federal CHIP dollars. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the Department. For CBHP, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. After an individual is determined eligible for CBHP, the individual is enrolled into an MCE plan. The specific MCE plan the individual is enrolled in is based on the county the individual lives in. The Department provides all county, MA site, and Department eligibility staff with copies of its Department-prepared policy and operational training documents and guides for reference. These documents are meant to provide eligibility staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with MCEs, which are groups or organizations of medical service providers that furnish services to CBHP members under capitated reimbursement agreements. Under these agreements, MCEs contract with a network of providers to provide services to CBHP members. The CBMS eligibility data feeds into the Department’s medical claims system, Colorado interChange, which is programmed to pay MCEs in lump-sum monthly payments (capitation payments) for the services that they provide on behalf of CBHP beneficiaries. Colorado interChange makes these payments based on eligibility information received from CBMS and requirements specified in federal and state regulations. The Department pays MCEs based on the number of eligible beneficiaries enrolled in its plan. Capitation payments are paid to the MCE regardless of whether the providers serve beneficiaries during the month or not. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to ensure local counties and MA site caseworkers are appropriately trained and held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and maintaining the required documentation to support eligibility in the case file. The Department planned to implement this recommendation by January 2025. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2025. In addition, we performed testing on a random nonstatistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2025. We obtained a listing of CBHP capitation payments totaling $256,524,048, that were submitted by MCEs and paid by the Department during Fiscal Year 2025 on behalf of 156,430 individual beneficiaries. From that listing, we selected 60 beneficiaries to determine whether those individual’s CBHP eligibility determinations were appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? Based on the testwork performed, we determined the Department is still in the process of fully implementing our Fiscal Year 2023 recommendation. While we did not identify any errors related to processing beneficiary applications within the required timeframes or eligibility requirements related to applicants with other health insurance, we continued to identify issues with missing case file documentation. We identified errors in 7 of the 60 CBHP case files tested (12 percent). These errors resulted in a total of $7,154 in known federal and state questioned costs for Fiscal Year 2025 ($4,650 in federal costs and $2,504 in state costs). Specifically, we found the following: • Missing Case File Documentation. In two cases, we determined the case file did not have documentation to support income, such as wage stubs, which is necessary to support the CBHP eligibility determination, as required by federal and state regulations. This resulted in known questioned costs of $2,553 ($1,659 in federal costs and $894 in state costs). Federal regulation [42 CFR 457.965] notes that the state must include in each applicant’s record facts to support the state’s determination of the applicant’s eligibility for CHIP. State regulation [10 CCR 2505-3, 130] notes that, to be eligible for CBHP, an applicant shall provide minimal verification as required in 10 CCR 2505-10-8.100.4.B. At minimum, applicants seeking medical assistance shall provide all of the following: social security number, verification of citizenship and identity and/or legal immigrant status, and support for earned and unearned income. State regulation [10 CCR 2505-10, 8.100.4.B] notes that income may be self-attested by an applicant or member and verified through an electronic data source. If the self-attested income cannot be verified electronically, the applicant must provide income documentation. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. • Issues with Income Calculations. In five cases, we identified issues with the income calculation used to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, we found the following: In 1 case, the incorrect number of household members was entered into CBMS, which caused the incorrect income threshold to be used in the income calculation. If the correct number of household members was used in the calculation, the member’s total income would have been over the eligibility limit. This resulted in known questioned costs of $2,037 ($1,324 in federal costs and $713 in state costs). In 3 cases, out-of-date income information was used in the calculation. In 2 of those cases, if the correct income was used in the calculation, the members’ total income would have been over the eligibility limit. This resulted in known questioned costs of $1,423 ($925 in federal costs and $498 in state costs). In 1 case for a self-employed individual, an incorrect expense amount was used in the member’s income calculation, which caused total income to be understated in the calculation. If the correct expense amount was used in the calculation, the member’s total income would have been over the eligibility limit. This resulted in known questioned costs of $1,141 ($741 in federal costs and $400 in state costs). State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the CBHP, an eligible person shall have a household income greater than 142 percent, but not exceeding 260 percent of the federal poverty level, adjusted for household size for children younger than age 19. State regulation [10 CCR 2505-3, 150.1] notes that the income calculation for the CBHP shall be determined by following the Medicaid Modified Adjusted Gross Income Methodology for income calculation, which is defined in 10 CCR 2505-10-8-100.4.C. State regulation [10 CCR 2505-10, 8.100.4.C] notes that the financial eligibility of applicants for medical assistance shall be determined based on current or previous monthly household income and family size. The Modified Adjusted Gross Income calculation for the purpose of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. State regulation [10 CCR 2505-10, 8.100.3.K.9] notes that in order to determine the net profit (or income) of a self-employed applicant, the cost of doing business (expenses) should be deducted from gross income. Why did these problems occur? We determined that the Department’s existing internal controls over CBHP eligibility determinations did not consistently ensure caseworkers were determining eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that the required documentation to support the income calculation was maintained within the case file, and that the correct income and income thresholds were used when determining eligibility. Why do these problems matter? As the state department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for the CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-035 The Department of Health Care Policy and Financing should strengthen its internal controls over the Children’s Basic Health Plan eligibility requirements to ensure eligibility is determined appropriately and in accordance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local county and Medical Assistance site caseworkers are appropriately trained on and comply with requirements to maintain appropriate income documentation to support eligibility in the case file, and comply with requirements to use the correct income and income thresholds when determining eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2027 The Department agrees with the recommendation and will strengthen internal controls over Children’s Basic Health Plan eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring Department-approved Corrective Action Plans. These plans will be required to address root causes related to income documentation, application of correct income thresholds, and compliance with CBHP eligibility requirements, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are addressed.
The Department agrees with the recommendation and will strengthen internal controls over Children’s Basic Health Plan eligibility determinations to ensure compliance with federal and state regulations. The Department will issue formal Management Decision Letters to the identified counties requiring Department-approved Corrective Action Plans. These plans will be required to address root causes related to income documentation, application of correct income thresholds, and compliance with CBHP eligibility requirements, including any necessary training or guidance for county and Medical Assistance site caseworkers. The Department will review, approve, and monitor corrective actions to ensure deficiencies are addressed.
2024-035, 2024-037
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2025 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Disposition of Prior Audit Recommendations of this report. See "Schedule of Findings and Questioned Costs" for table/chart. Finding 2024-032 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Medicaid Medicaid Claims Payments The Department reimburses medical providers, pharmacies, and medical equipment providers for claims submitted to the Department for services provided to eligible beneficiaries in the Medicaid program. To be allowable, Medicaid costs for services must be (1) covered by the CMS-approved state plan or the CMS-approved waivers; (2) reviewed by the Department consistent with the Department’s documented procedures and system for determining the medical necessity of claims; (3) properly coded; and (4) paid at the rate allowed by the state plan. A Medicaid state plan is a formal, written agreement between a state and the federal government describing how a state administers its Medicaid program, which includes both the basic requirements of the program and individualized content that reflects the characteristics of the state’s program [42 CFR 430.10]. The state plan is written by the state and must be approved by CMS in order for the State to access federal Medicaid funds. The Department uses Colorado interChange as its medical claims system. Colorado interChange is programmed to make Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. During Fiscal Year 2024, the Department contracted with a fiscal agent, Gainwell Technologies (Gainwell), to manage Colorado interChange. A fiscal agent is a contractor that acts on behalf of the Department in respect to claims processing activities, including evaluating and approving or rejecting claims payments in accordance with established Department policies. Although Gainwell receives and processes all claims, the Department is ultimately responsible for ensuring that the claims are paid in accordance with federal and state regulations. Providers are responsible for preparing and submitting Medicaid claims to Gainwell for processing in compliance with the Department’s claim filing requirements. All provider claims must include a diagnosis code, procedure code, and the provider’s usual and customary charges for payment (Provider Rate). Procedure codes are dependent on the type of service and claim type. Colorado interChange is programmed with CMS-approved rates for each procedure code. Gainwell will use the claims information received by the provider, including the specific procedure codes and Provider Rate, to process and pay the claims in Colorado interChange. Providers are advised by the Department to bill their usual and customary charges for services, and the Colorado interChange system pays the lower of either (1) the Provider Rate, or (2) the Department’s CMS-approved rates. If needed, all claims may be adjusted for increased payment, decreased payment, or recovery without repayment. Adjustments that increase or decrease the original payment amount are processed as a two-part transaction in Colorado interChange—the first piece of the transaction reverses the previously made payment, and the second piece of the transaction repays the claim at the corrected rate. If a previously paid claim is adjusted to pay less than the original amount, the adjustment will result in a retraction of the difference between the original payment and the corrected payment amount. If a previously paid claim is adjusted to pay more than the original amount, depending on if the provider billed usual and customary rates, the adjustment will result in an additional payment to the provider. The Department authorizes updates to the rate tables in Colorado interChange whenever there are changes in the claims rates. All provider rate increases are subject to CMS approval prior to implementation of an increase. Rate changes are generally made at the beginning of each fiscal year, but can be made anytime an update is required, such as when CMS issues a rate change that is based on the federal fiscal year (which begins on October 1). To make a change in the rate tables, Department staff fill out a change request form (Update Form) including the purpose of the request, instructions on the specific information that needs updating, and any other special instructions related to the request. The Department must include specific instructions on the Update Form if any claims have to be reprocessed as part of the request. A reprocessing request is needed if the actual rate change is made after the effective date of the change. For example, if a rate change was effective at the beginning of the fiscal year (July 1) but processed on July 15, the Update Form should include a specific request to reprocess claims with dates of service from July 1 to July 15, which would ensure the claims are paid at the correct rates. Once complete, Department staff send the Update Form to Gainwell for processing in Colorado interChange. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid claims payment process and to determine whether payments were processed and paid in accordance with state and federal regulations during Fiscal Year 2024. During our audit, we obtained a list of all Medicaid claims that were paid by the Department during Fiscal Year 2024, which included 77,824,795 individual Medicaid claims totaling $11,542,679,377. We performed testing on a randomly selected sample of 40 Medicaid claims paid during Fiscal Year 2024 totaling $4,486,936 to determine whether the claim (1) matched the claims information that was reported in Colorado interChange; (2) was paid at the rate allowed by the state plan; and (3) beneficiary was eligible for the Medicaid program at the time of service. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [45 CFR 75.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to Generally Accepted Accounting Principles (GAAP); not be used for cost sharing of other programs; and be adequately documented. Section 25.5-4-301(2), C.R.S., states that any overpayment to a provider is recoverable, regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider. Federal regulations [45 CFR 75.303] state that recipients of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with “Standards for Internal Control in the Federal Government” (Green Book), published by the U.S. Government Accountability Office. Principles 3.09-3.10, Documentation of the Internal Control System, state that management is to develop and maintain documentation of its internal control system. This documentation should establish the who, what, when, where, and why of internal control execution to personnel. Documentation also provides a means to retain organizational knowledge and mitigate the risk of having that knowledge limited to a few personnel. What problem did the audit work identify? Based on our audit testwork, we determined that one of the 40 claims tested (2.5 percent) contained procedure codes that were paid at the incorrect rate for Fiscal Year 2024. Specifically, the claim selected for testing contained three specific procedures, two of which were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The third procedure code had the same rate for both Fiscal Year 2023 and 2024, so no difference was noted. The total known questioned costs for this claim were $137.20. See Schedule of Findings and Questioned Costs for chart/table. We provided the claim to Department staff to research, and they determined that this claim was part of a group of 2,423 individual claims with specific procedure codes that were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The total known questioned costs for this group of claims, including the sample tested above, was $189,015.98. Why did this problem occur? The Department does not have adequate internal controls, including formal policies and procedures, in place related to the rate updating process in Colorado interChange. Specifically, the Department lacked policies and procedures detailing how to complete the rate Update Form, requiring a secondary review process over the completed Update Form prior to submission to Gainwell, and requiring a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. On July 21, 2023, Department staff completed and submitted an Update Form to Gainwell to process the annual rate updates; the Department staff who processed the rate update had been trained on the process before, but this was the first time they completed the process independently and they overlooked including specific instructions to reprocess any claims with dates of service before the update (July 1, 2023 to July 21, 2023) at the new rate. This caused the Fiscal Year 2024 rate changes to take effect on July 21, 2023 instead of July 1, 2023 (the first day of the fiscal year). The Department did not have a review process in place to confirm that the Update Forms were completed accurately and included all necessary information, so the Department was unaware of the issue until it was identified during our audit. Once notified of the error, Department staff contacted Gainwell to initiate an adjustment to correct all claims with dates of service from July 1, 2023 to July 21, 2023 that were paid at the incorrect rate. The Department also notified all providers of the issue on the Department’s Provider Resources website and in the December 2024 Provider Bulletin. The adjustment was processed on November 22, 2024. Why does this problem matter? Strong internal controls over the Medicaid claims process—including documented policies and procedures detailing how to complete the Update Form and an effective review process—are necessary to ensure that Medicaid claims are paid at the correct rates approved by the state plan and in accordance with federal and state regulations. In addition, making payments over the specific rates can result in the Department having to repay the federal government for the federal portion of the overpayments. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-032 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Medicaid claims process by developing, documenting, and implementing formal policies and procedures over the rate updating process in Colorado interChange, the Department’s medical claims system. These policies and procedures should include details on how to complete the rate change request form (Update Form), require a secondary review process over the completed Update Form prior to submission to Gainwell Technologies—the Department’s contracted fiscal agent that manages Colorado interChange—and require a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. Response Department of Health Care Policy and Financing Agree Implementation Date: July 2025 The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2025 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Disposition of Prior Audit Recommendations of this report. See "Schedule of Findings and Questioned Costs" for table/chart. Finding 2024-032 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Medicaid Medicaid Claims Payments The Department reimburses medical providers, pharmacies, and medical equipment providers for claims submitted to the Department for services provided to eligible beneficiaries in the Medicaid program. To be allowable, Medicaid costs for services must be (1) covered by the CMS-approved state plan or the CMS-approved waivers; (2) reviewed by the Department consistent with the Department’s documented procedures and system for determining the medical necessity of claims; (3) properly coded; and (4) paid at the rate allowed by the state plan. A Medicaid state plan is a formal, written agreement between a state and the federal government describing how a state administers its Medicaid program, which includes both the basic requirements of the program and individualized content that reflects the characteristics of the state’s program [42 CFR 430.10]. The state plan is written by the state and must be approved by CMS in order for the State to access federal Medicaid funds. The Department uses Colorado interChange as its medical claims system. Colorado interChange is programmed to make Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. During Fiscal Year 2024, the Department contracted with a fiscal agent, Gainwell Technologies (Gainwell), to manage Colorado interChange. A fiscal agent is a contractor that acts on behalf of the Department in respect to claims processing activities, including evaluating and approving or rejecting claims payments in accordance with established Department policies. Although Gainwell receives and processes all claims, the Department is ultimately responsible for ensuring that the claims are paid in accordance with federal and state regulations. Providers are responsible for preparing and submitting Medicaid claims to Gainwell for processing in compliance with the Department’s claim filing requirements. All provider claims must include a diagnosis code, procedure code, and the provider’s usual and customary charges for payment (Provider Rate). Procedure codes are dependent on the type of service and claim type. Colorado interChange is programmed with CMS-approved rates for each procedure code. Gainwell will use the claims information received by the provider, including the specific procedure codes and Provider Rate, to process and pay the claims in Colorado interChange. Providers are advised by the Department to bill their usual and customary charges for services, and the Colorado interChange system pays the lower of either (1) the Provider Rate, or (2) the Department’s CMS-approved rates. If needed, all claims may be adjusted for increased payment, decreased payment, or recovery without repayment. Adjustments that increase or decrease the original payment amount are processed as a two-part transaction in Colorado interChange—the first piece of the transaction reverses the previously made payment, and the second piece of the transaction repays the claim at the corrected rate. If a previously paid claim is adjusted to pay less than the original amount, the adjustment will result in a retraction of the difference between the original payment and the corrected payment amount. If a previously paid claim is adjusted to pay more than the original amount, depending on if the provider billed usual and customary rates, the adjustment will result in an additional payment to the provider. The Department authorizes updates to the rate tables in Colorado interChange whenever there are changes in the claims rates. All provider rate increases are subject to CMS approval prior to implementation of an increase. Rate changes are generally made at the beginning of each fiscal year, but can be made anytime an update is required, such as when CMS issues a rate change that is based on the federal fiscal year (which begins on October 1). To make a change in the rate tables, Department staff fill out a change request form (Update Form) including the purpose of the request, instructions on the specific information that needs updating, and any other special instructions related to the request. The Department must include specific instructions on the Update Form if any claims have to be reprocessed as part of the request. A reprocessing request is needed if the actual rate change is made after the effective date of the change. For example, if a rate change was effective at the beginning of the fiscal year (July 1) but processed on July 15, the Update Form should include a specific request to reprocess claims with dates of service from July 1 to July 15, which would ensure the claims are paid at the correct rates. Once complete, Department staff send the Update Form to Gainwell for processing in Colorado interChange. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid claims payment process and to determine whether payments were processed and paid in accordance with state and federal regulations during Fiscal Year 2024. During our audit, we obtained a list of all Medicaid claims that were paid by the Department during Fiscal Year 2024, which included 77,824,795 individual Medicaid claims totaling $11,542,679,377. We performed testing on a randomly selected sample of 40 Medicaid claims paid during Fiscal Year 2024 totaling $4,486,936 to determine whether the claim (1) matched the claims information that was reported in Colorado interChange; (2) was paid at the rate allowed by the state plan; and (3) beneficiary was eligible for the Medicaid program at the time of service. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [45 CFR 75.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to Generally Accepted Accounting Principles (GAAP); not be used for cost sharing of other programs; and be adequately documented. Section 25.5-4-301(2), C.R.S., states that any overpayment to a provider is recoverable, regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider. Federal regulations [45 CFR 75.303] state that recipients of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with “Standards for Internal Control in the Federal Government” (Green Book), published by the U.S. Government Accountability Office. Principles 3.09-3.10, Documentation of the Internal Control System, state that management is to develop and maintain documentation of its internal control system. This documentation should establish the who, what, when, where, and why of internal control execution to personnel. Documentation also provides a means to retain organizational knowledge and mitigate the risk of having that knowledge limited to a few personnel. What problem did the audit work identify? Based on our audit testwork, we determined that one of the 40 claims tested (2.5 percent) contained procedure codes that were paid at the incorrect rate for Fiscal Year 2024. Specifically, the claim selected for testing contained three specific procedures, two of which were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The third procedure code had the same rate for both Fiscal Year 2023 and 2024, so no difference was noted. The total known questioned costs for this claim were $137.20. See Schedule of Findings and Questioned Costs for chart/table. We provided the claim to Department staff to research, and they determined that this claim was part of a group of 2,423 individual claims with specific procedure codes that were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The total known questioned costs for this group of claims, including the sample tested above, was $189,015.98. Why did this problem occur? The Department does not have adequate internal controls, including formal policies and procedures, in place related to the rate updating process in Colorado interChange. Specifically, the Department lacked policies and procedures detailing how to complete the rate Update Form, requiring a secondary review process over the completed Update Form prior to submission to Gainwell, and requiring a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. On July 21, 2023, Department staff completed and submitted an Update Form to Gainwell to process the annual rate updates; the Department staff who processed the rate update had been trained on the process before, but this was the first time they completed the process independently and they overlooked including specific instructions to reprocess any claims with dates of service before the update (July 1, 2023 to July 21, 2023) at the new rate. This caused the Fiscal Year 2024 rate changes to take effect on July 21, 2023 instead of July 1, 2023 (the first day of the fiscal year). The Department did not have a review process in place to confirm that the Update Forms were completed accurately and included all necessary information, so the Department was unaware of the issue until it was identified during our audit. Once notified of the error, Department staff contacted Gainwell to initiate an adjustment to correct all claims with dates of service from July 1, 2023 to July 21, 2023 that were paid at the incorrect rate. The Department also notified all providers of the issue on the Department’s Provider Resources website and in the December 2024 Provider Bulletin. The adjustment was processed on November 22, 2024. Why does this problem matter? Strong internal controls over the Medicaid claims process—including documented policies and procedures detailing how to complete the Update Form and an effective review process—are necessary to ensure that Medicaid claims are paid at the correct rates approved by the state plan and in accordance with federal and state regulations. In addition, making payments over the specific rates can result in the Department having to repay the federal government for the federal portion of the overpayments. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-032 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Medicaid claims process by developing, documenting, and implementing formal policies and procedures over the rate updating process in Colorado interChange, the Department’s medical claims system. These policies and procedures should include details on how to complete the rate change request form (Update Form), require a secondary review process over the completed Update Form prior to submission to Gainwell Technologies—the Department’s contracted fiscal agent that manages Colorado interChange—and require a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. Response Department of Health Care Policy and Financing Agree Implementation Date: July 2025 The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
2024-032
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2025 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Disposition of Prior Audit Recommendations of this report. See "Schedule of Findings and Questioned Costs" for table/chart. Finding 2024-033 Compliance with Eligibility for Medicaid and CBHP Ex Parte Renewal Process Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits. States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at that time, either from the beneficiary’s case file or other electronic data sources, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid and CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid and CBHP eligibility requirements during Fiscal Year 2024. During our audit, we inquired with the Department on the ex parte renewal process for Medicaid and CBHP beneficiaries. How were the results of the audit work measured? We measured the results of our audit work against the following: Federal regulations require states to complete a redetermination of eligibility based on available information for each individual in the household, regardless of the eligibility of others in the household unit. Specifically, these regulations require that states complete a redetermination of eligibility for all beneficiaries without requiring information from the individual if able to do so based on reliable information contained in the individual’s case file or more current information available to the state (ex parte basis) [42 CFR 435.916(b)(2) and 457.343]. If they are unable to do so, the state must provide the individual with a pre-populated renewal form and give them at least 30 calendar days to respond and provide any necessary information [42 CFR 435.916(b)(2)]. Federal regulations [42 CFR 435.952(d) and 457.380(f)] specify that states may not terminate eligibility or reduce benefits on the basis of information obtained through the ex parte renewal process without first contacting the beneficiary and offering them an opportunity to provide new information. What problem did the audit work identify? The Department reported to us that they were not in compliance with eligibility requirements related to the ex parte renewal process during Fiscal Year 2024. As CMS worked with individual states on their COVID-19 unwinding plans, they identified 29 states that were not in compliance with certain ex parte renewal requirements for Medicaid and CBHP beneficiaries, including Colorado. The Department was inappropriately conducting ex parte renewals at the household level rather than individual level, without using individually-specific eligibility statutes and income thresholds for individuals within the household. Specifically, if eligibility could not be renewed on an ex parte basis for at least one member of a household, renewal forms were sent to the entire household. If the renewal forms were returned, the appropriate eligibility determinations were made and those who are eligible were approved. If the renewal forms were not returned, the Department’s eligibility system, the Colorado Benefits Management System (CBMS), would disenroll all individuals in the household, including any who may have been determined to be eligible through the ex parte process. Why did this problem occur? In August 2023, CMS instructed all states to review their ex parte renewal process to assess compliance with federal requirements to complete eligibility redeterminations based on the available information for each individual in the household, regardless of the eligibility of others in the household unit. States that identified any areas of noncompliance were required to (1) pause terminations for any ex parte renewal processes that are not compliant with federal guidance and whose coverage may be terminated inappropriately; (2) reinstate coverage for all affected individuals who have been disenrolled due to a failure to complete redeterminations based on the available information for each individual in the household; (3) fix the state’s systems and processes to ensure that redeterminations are conducted appropriately; and (4) implement a mitigation strategy to prevent continued inappropriate terminations until the state has fixed all systems and processes to be in compliance with federal renewal requirements. States were required to submit the state’s plan and timeline for remediation to CMS. In September 2023, the Department reported to CMS that it was not fully in compliance with the federal requirements for determining eligibility for each individual in the household, and it submitted a mitigation plan and timeline to fix the CBMS system and Department’s processes to ensure that redeterminations were conducted appropriately in the future. As part of the Department’s mitigation plan, automatic terminations of any households who did not return a renewal form were temporarily paused until a short-term system fix was put in place. In October 2023, a CBMS fix was put into place for households that did not return their renewal forms. CBMS continued to send renewal forms to households requesting additional information; however, for any multi-member household that did not return its form, the Department started reviewing eligibility for all members of the household individually. This short-term system fix brought the Department into compliance with federal ex parte renewal requirements. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with targeted implementation by December 2026. Why does this problem matter? When the Department is out of compliance with federal requirements, such as Medicaid requirements, the Department risks sanctions and/or other penalties. After CMS identified the Department’s noncompliance related to the Medicaid ex parte renewal issue, the Department researched the issue and identified 7,510 individuals who were incorrectly disenrolled from Medicaid or CBHP during the period May 2023 to October 2023. In November 2023, the Department retroactively reinstated these individuals’ eligibility back to the date at which their household was terminated, without a gap in coverage. In addition, the individuals were notified that their coverage had been reinstated and provided information on how to obtain payment for unpaid medical bills and/or ensure that any eligible service during the period that the individual was disenrolled were covered. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-033 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by continuing to implement the Colorado Benefits Management System change related to the ex parte eligibility process to ensure that eligibility is determined on an individual rather than household basis, as required. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2025 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Disposition of Prior Audit Recommendations of this report. See "Schedule of Findings and Questioned Costs" for table/chart. Finding 2024-033 Compliance with Eligibility for Medicaid and CBHP Ex Parte Renewal Process Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits. States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at that time, either from the beneficiary’s case file or other electronic data sources, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid and CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid and CBHP eligibility requirements during Fiscal Year 2024. During our audit, we inquired with the Department on the ex parte renewal process for Medicaid and CBHP beneficiaries. How were the results of the audit work measured? We measured the results of our audit work against the following: Federal regulations require states to complete a redetermination of eligibility based on available information for each individual in the household, regardless of the eligibility of others in the household unit. Specifically, these regulations require that states complete a redetermination of eligibility for all beneficiaries without requiring information from the individual if able to do so based on reliable information contained in the individual’s case file or more current information available to the state (ex parte basis) [42 CFR 435.916(b)(2) and 457.343]. If they are unable to do so, the state must provide the individual with a pre-populated renewal form and give them at least 30 calendar days to respond and provide any necessary information [42 CFR 435.916(b)(2)]. Federal regulations [42 CFR 435.952(d) and 457.380(f)] specify that states may not terminate eligibility or reduce benefits on the basis of information obtained through the ex parte renewal process without first contacting the beneficiary and offering them an opportunity to provide new information. What problem did the audit work identify? The Department reported to us that they were not in compliance with eligibility requirements related to the ex parte renewal process during Fiscal Year 2024. As CMS worked with individual states on their COVID-19 unwinding plans, they identified 29 states that were not in compliance with certain ex parte renewal requirements for Medicaid and CBHP beneficiaries, including Colorado. The Department was inappropriately conducting ex parte renewals at the household level rather than individual level, without using individually-specific eligibility statutes and income thresholds for individuals within the household. Specifically, if eligibility could not be renewed on an ex parte basis for at least one member of a household, renewal forms were sent to the entire household. If the renewal forms were returned, the appropriate eligibility determinations were made and those who are eligible were approved. If the renewal forms were not returned, the Department’s eligibility system, the Colorado Benefits Management System (CBMS), would disenroll all individuals in the household, including any who may have been determined to be eligible through the ex parte process. Why did this problem occur? In August 2023, CMS instructed all states to review their ex parte renewal process to assess compliance with federal requirements to complete eligibility redeterminations based on the available information for each individual in the household, regardless of the eligibility of others in the household unit. States that identified any areas of noncompliance were required to (1) pause terminations for any ex parte renewal processes that are not compliant with federal guidance and whose coverage may be terminated inappropriately; (2) reinstate coverage for all affected individuals who have been disenrolled due to a failure to complete redeterminations based on the available information for each individual in the household; (3) fix the state’s systems and processes to ensure that redeterminations are conducted appropriately; and (4) implement a mitigation strategy to prevent continued inappropriate terminations until the state has fixed all systems and processes to be in compliance with federal renewal requirements. States were required to submit the state’s plan and timeline for remediation to CMS. In September 2023, the Department reported to CMS that it was not fully in compliance with the federal requirements for determining eligibility for each individual in the household, and it submitted a mitigation plan and timeline to fix the CBMS system and Department’s processes to ensure that redeterminations were conducted appropriately in the future. As part of the Department’s mitigation plan, automatic terminations of any households who did not return a renewal form were temporarily paused until a short-term system fix was put in place. In October 2023, a CBMS fix was put into place for households that did not return their renewal forms. CBMS continued to send renewal forms to households requesting additional information; however, for any multi-member household that did not return its form, the Department started reviewing eligibility for all members of the household individually. This short-term system fix brought the Department into compliance with federal ex parte renewal requirements. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with targeted implementation by December 2026. Why does this problem matter? When the Department is out of compliance with federal requirements, such as Medicaid requirements, the Department risks sanctions and/or other penalties. After CMS identified the Department’s noncompliance related to the Medicaid ex parte renewal issue, the Department researched the issue and identified 7,510 individuals who were incorrectly disenrolled from Medicaid or CBHP during the period May 2023 to October 2023. In November 2023, the Department retroactively reinstated these individuals’ eligibility back to the date at which their household was terminated, without a gap in coverage. In addition, the individuals were notified that their coverage had been reinstated and provided information on how to obtain payment for unpaid medical bills and/or ensure that any eligible service during the period that the individual was disenrolled were covered. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-033 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by continuing to implement the Colorado Benefits Management System change related to the ex parte eligibility process to ensure that eligibility is determined on an individual rather than household basis, as required. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
2024-033
Finding 2025-038 Internal Controls and Compliance over Student Financial Assistance Cluster – NSLDS Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Title IV Student Financial Assistance funds (Title IV) to report student enrollment information within specified timeframes to the USDE through its central database for student financial assistance, the National Student Loan Data System (NSLDS). Enrollment reporting, including the submission of student roster files and enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of the Student Financial Assistance Cluster. In accordance with federal requirements, each campus within the Colorado State University – System (CSU-System)—Colorado State University, Colorado State University – Pueblo and Colorado State University – Global Campus—submits student roster files to NSLDS via a thirdparty servicer, the National Student Clearinghouse (Clearinghouse), and each roster file is then uploaded by the Clearinghouse directly to NSLDS. The Registrar’s Office at each campus of the CSU-System compiles the student roster files to report details such as the campus-level enrollment and program attendance for the students who have received federal Title IV aid at the CSU-System. Each campus performs an initial review of participating students’ enrollment information during each semester’s census, which is typically during the second week of the semester, for reporting to USDE through the NSLDS. The initial review of participating students’ enrollment information is performed using enrollment information generated by each campus’s Financial Aid system (reporting system). After the census date each semester, the Registrar Office’s staff prepare student roster files of enrollment status that include information on reductions or increases in attendance levels, graduation, withdrawals, and/or students who have been accepted for enrollment but never attended. The Registrar’s Office prepares this through a manual comparison of applicable students’ enrollment status at the census date to the current enrollment status per each campus’s reporting system. During Fiscal Year 2025, the CSU-System issued approximately $306.0 million of federal Title IV aid during the year, which included approximately $64.6 million and $238.0 million of Pell Grant and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether each campus within the CSU-System had adequate internal controls over and complied with federal Title IV Student Financial Assistance enrollment reporting requirements regarding the student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2025. As part of our Fiscal Year 2025 testwork, we reviewed a total random sample of 40 student’s enrollment status change information, consisting of 26 students at Colorado State University, 10 students at Colorado State University – Global Campus, and 4 students at Colorado State University – Pueblo, that was required to be reported to USDE through NSLDS during Fiscal Year 2025 The sample consisted of enrollment status changes that occurred during the Fall 2024 and Spring 2025 semesters. For each student in our sample, we compared information within the CSU-System’s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal, graduation, or a change in enrolled credit hours, to determine if the information was reported accurately and within the federally required timelines. How were the results of the audit work measured? We measured the results of our audit work against the following: Under the federal Pell Grant and Direct Loan program requirements, 34 CFR 690.83(b)(2) and 34 CFR 685.309(b)(2), an institution must report any enrollment status changes, including the date of the change, per the institution’s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student’s enrollment status to NSLDS when there is a (a) reduction or increase in the student’s attendance levels, (b) graduation, (c) withdrawal, and/or (d) a student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against the USDE-required 60-day timeframe for submission of student roster files. What problems did the audit work identify? We found that the Colorado State University and Colorado State University – Pueblo campuses did not timely report the student enrollment status changes to the USDE through NSLDS for 2 out of the 40 (5 percent) students we tested during the Fall 2024 and Spring 2025 semesters. Specifically, one student’s enrollment status information during the Fall 2024 semester at Colorado State University was submitted 166 days beyond the federal reporting requirement and one student’s enrollment status information during the Fall 2024 semester at Colorado State University – Pueblo was submitted 18 days beyond the federal reporting requirement. Why did these problems occur? The Colorado State University and Colorado State University – Pueblo campuses did not have adequate review processes in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Assistance program. For both instances, the Student Financial Assistance Office staff at each campus indicated that the student enrollment status was not reported timely because the new students, who were first enrolled at their respective campus during the Fall 2024 semester, were not included in the student roster files used to compare each students’ enrollment status at the census date to the current status in the reporting system due to the reports used to perform the manual comparison not being correctly configured to capture all student enrollment status of students who first enrolled during the Fall 2024 semester. Additionally, the review process failed to adequately ensure the completeness of the prepared student roster files. As a result, those changes were not included in the enrollment status report submitted by the Clearinghouse to NSLDS within the required federal reporting timeframe. Why do these problems matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the CSUSystem campuses fail to meet the required reporting timelines, the borrower’s repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-038 The Colorado State University and Colorado State University – Pueblo campuses should strengthen their internal controls over reporting Student Financial Assistance Pell Grants and Direct Loan Program’s student enrollment to the U.S. Department of Education (USDE) to ensure student enrollment status changes are submitted by the National Student Clearinghouse to USDE’s National Student Loan Data System within 60-days of any enrollment change. This should include improving their review processes over the preparation and completeness of the student roster files used to compare each student’s enrollment status at the census date to current enrollment status in the reporting system to ensure that the student roster files include all students that are newly enrolled at the campus. Response Colorado State University System Agree Implementation Date: June 2026 The Colorado State University and Colorado State University – Pueblo campuses will strengthen their internal controls to ensure enrollment changes are reported within the required 60-day timeline for newly enrolled students. Additionally, the Colorado State University and Colorado State University – Pueblo campuses will improve the documentation provided as part of compliance testing as both students referenced within the finding were unique situations. In both instances referenced, additional context was not provided during compliance testing for both students that was not captured on the provided National Student Loan Data System Campus Enrollment Details webpage that showed the appearance of reporting an enrollment status change outside of the 60-day requirement. For the Colorado State University, the student was reported with an effective date of the beginning of the Fall 2024 Semester but did not complete verification procedures until February 2025 and was then disbursed the Fall 2024 portion of their Pell Grant. For Colorado State University – Pueblo, the student was reported with an effective date of the beginning of the Fall 2024 Semester, but corrections were required on the student’s FAFSA before federal student financial aid could be disbursed. The campuses will improve documentation provided during compliance testing for when these unique situations with enrollment reporting occur.
Show full finding ▾Hide full finding ▴Finding 2025-038 Internal Controls and Compliance over Student Financial Assistance Cluster – NSLDS Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Title IV Student Financial Assistance funds (Title IV) to report student enrollment information within specified timeframes to the USDE through its central database for student financial assistance, the National Student Loan Data System (NSLDS). Enrollment reporting, including the submission of student roster files and enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of the Student Financial Assistance Cluster. In accordance with federal requirements, each campus within the Colorado State University – System (CSU-System)—Colorado State University, Colorado State University – Pueblo and Colorado State University – Global Campus—submits student roster files to NSLDS via a thirdparty servicer, the National Student Clearinghouse (Clearinghouse), and each roster file is then uploaded by the Clearinghouse directly to NSLDS. The Registrar’s Office at each campus of the CSU-System compiles the student roster files to report details such as the campus-level enrollment and program attendance for the students who have received federal Title IV aid at the CSU-System. Each campus performs an initial review of participating students’ enrollment information during each semester’s census, which is typically during the second week of the semester, for reporting to USDE through the NSLDS. The initial review of participating students’ enrollment information is performed using enrollment information generated by each campus’s Financial Aid system (reporting system). After the census date each semester, the Registrar Office’s staff prepare student roster files of enrollment status that include information on reductions or increases in attendance levels, graduation, withdrawals, and/or students who have been accepted for enrollment but never attended. The Registrar’s Office prepares this through a manual comparison of applicable students’ enrollment status at the census date to the current enrollment status per each campus’s reporting system. During Fiscal Year 2025, the CSU-System issued approximately $306.0 million of federal Title IV aid during the year, which included approximately $64.6 million and $238.0 million of Pell Grant and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether each campus within the CSU-System had adequate internal controls over and complied with federal Title IV Student Financial Assistance enrollment reporting requirements regarding the student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2025. As part of our Fiscal Year 2025 testwork, we reviewed a total random sample of 40 student’s enrollment status change information, consisting of 26 students at Colorado State University, 10 students at Colorado State University – Global Campus, and 4 students at Colorado State University – Pueblo, that was required to be reported to USDE through NSLDS during Fiscal Year 2025 The sample consisted of enrollment status changes that occurred during the Fall 2024 and Spring 2025 semesters. For each student in our sample, we compared information within the CSU-System’s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal, graduation, or a change in enrolled credit hours, to determine if the information was reported accurately and within the federally required timelines. How were the results of the audit work measured? We measured the results of our audit work against the following: Under the federal Pell Grant and Direct Loan program requirements, 34 CFR 690.83(b)(2) and 34 CFR 685.309(b)(2), an institution must report any enrollment status changes, including the date of the change, per the institution’s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student’s enrollment status to NSLDS when there is a (a) reduction or increase in the student’s attendance levels, (b) graduation, (c) withdrawal, and/or (d) a student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against the USDE-required 60-day timeframe for submission of student roster files. What problems did the audit work identify? We found that the Colorado State University and Colorado State University – Pueblo campuses did not timely report the student enrollment status changes to the USDE through NSLDS for 2 out of the 40 (5 percent) students we tested during the Fall 2024 and Spring 2025 semesters. Specifically, one student’s enrollment status information during the Fall 2024 semester at Colorado State University was submitted 166 days beyond the federal reporting requirement and one student’s enrollment status information during the Fall 2024 semester at Colorado State University – Pueblo was submitted 18 days beyond the federal reporting requirement. Why did these problems occur? The Colorado State University and Colorado State University – Pueblo campuses did not have adequate review processes in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Assistance program. For both instances, the Student Financial Assistance Office staff at each campus indicated that the student enrollment status was not reported timely because the new students, who were first enrolled at their respective campus during the Fall 2024 semester, were not included in the student roster files used to compare each students’ enrollment status at the census date to the current status in the reporting system due to the reports used to perform the manual comparison not being correctly configured to capture all student enrollment status of students who first enrolled during the Fall 2024 semester. Additionally, the review process failed to adequately ensure the completeness of the prepared student roster files. As a result, those changes were not included in the enrollment status report submitted by the Clearinghouse to NSLDS within the required federal reporting timeframe. Why do these problems matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the CSUSystem campuses fail to meet the required reporting timelines, the borrower’s repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-038 The Colorado State University and Colorado State University – Pueblo campuses should strengthen their internal controls over reporting Student Financial Assistance Pell Grants and Direct Loan Program’s student enrollment to the U.S. Department of Education (USDE) to ensure student enrollment status changes are submitted by the National Student Clearinghouse to USDE’s National Student Loan Data System within 60-days of any enrollment change. This should include improving their review processes over the preparation and completeness of the student roster files used to compare each student’s enrollment status at the census date to current enrollment status in the reporting system to ensure that the student roster files include all students that are newly enrolled at the campus. Response Colorado State University System Agree Implementation Date: June 2026 The Colorado State University and Colorado State University – Pueblo campuses will strengthen their internal controls to ensure enrollment changes are reported within the required 60-day timeline for newly enrolled students. Additionally, the Colorado State University and Colorado State University – Pueblo campuses will improve the documentation provided as part of compliance testing as both students referenced within the finding were unique situations. In both instances referenced, additional context was not provided during compliance testing for both students that was not captured on the provided National Student Loan Data System Campus Enrollment Details webpage that showed the appearance of reporting an enrollment status change outside of the 60-day requirement. For the Colorado State University, the student was reported with an effective date of the beginning of the Fall 2024 Semester but did not complete verification procedures until February 2025 and was then disbursed the Fall 2024 portion of their Pell Grant. For Colorado State University – Pueblo, the student was reported with an effective date of the beginning of the Fall 2024 Semester, but corrections were required on the student’s FAFSA before federal student financial aid could be disbursed. The campuses will improve documentation provided during compliance testing for when these unique situations with enrollment reporting occur.
The Colorado State University and Colorado State University – Pueblo campuses will strengthen their internal controls to ensure enrollment changes are reported within the required 60-day timeline for newly enrolled students. Additionally, the Colorado State University and Colorado State University – Pueblo campuses will improve the documentation provided as part of compliance testing as both students referenced within the finding were unique situations. In both instances referenced, additional context was not provided during compliance testing for both students that was not captured on the provided National Student Loan Data System Campus Enrollment Details webpage that showed the appearance of reporting an enrollment status change outside of the 60-day requirement. For the Colorado State University, the student was reported with an effective date of the beginning of the Fall 2024 Semester but did not complete verification procedures until February 2025 and was then disbursed the Fall 2024 portion of their Pell Grant. For Colorado State University – Pueblo, the student was reported with an effective date of the beginning of the Fall 2024 Semester, but corrections were required on the student’s FAFSA before federal student financial aid could be disbursed. The campuses will improve documentation provided during compliance testing for when these unique situations with enrollment reporting occur.
Finding 2025-039 Internal Controls and Compliance with Special Tests and Provisions for Student Financial Assistance Metropolitan State University of Denver (MSU-Denver) receives funding from the federal Department of Education’s (USDE) Title IV Student Financial Assistance (Student Financial Aid) program, which requires MSU-Denver to obtain sensitive data from students. For example, MSUDenver obtains personally identifiable financial and tax information from students in order to administer its federal Student Financial Aid program. As a result, MSU-Denver’s Information Technology Services (ITS) department is responsible for ensuring compliance with the federal Gramm-Leach-Bliley Act (GLBA). The GLBA, which was enacted in 1999, mandates that financial institutions disclose their information-sharing practices and provide consumers with opt-out options for their personal data. It also established the Financial Privacy Rule, which requires institutions to protect sensitive customer information and provide clear privacy notices to customers. Before MSU-Denver receives federal Student Financial Aid from USDE, MSU-Denver agrees to adhere to compliance requirements within a Program Participation Agreement (PPA), and a Student Aid Internet Gateway Agreement (SAIGA). One of the compliance requirements MSU-Denver agrees to within the PPA and SAIGA is the GLBA, which requires MSU-Denver to explain their information-sharing practices with their students and safeguard sensitive data, with particular attention to information provided to MSU-Denver by the USDE or otherwise obtained in support of the administration of MSU-Denver’s Student Financial Aid program. The GLBA requirements are codified in Title 16, Part 314, Section 4 of the Code of Federal Regulations (16 CFR 314.4), and requires MSU-Denver to develop, implement, and maintain a comprehensive written information security program (WISP) in one or more readily accessible parts. This federal regulation also specifies the elements and safeguards that MSU-Denver’s WISP needs to include for the protection of students’ financial aid information. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review MSU-Denver’s internal controls over its WISP, and determine if it included the minimum elements and safeguards required by the GLBA during Fiscal Year 2025. Our review included obtaining MSU-Denver’s WISP and performing the following procedures: • We met with MSU-Denver’s ITS management to determine how it developed, implemented, and maintained its WISP. • We compared MSU-Denver’s WISP to the elements and safeguards required by the GLBA. • We reviewed the ITS’ policies and procedures to determine if MSU-Denver had suitably designed and implemented the GLBA required elements and safeguards during Fiscal Year 2025. How were the results of the audit work measured? We measured the results of our audit against federal regulation 16 CFR 314.4, which states that an institution’s WISP, at a minimum, must include the seven following elements that include eight minimum safeguards: 1. Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 2. Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 3. Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment. At a minimum, the following are the eight safeguards that a WISP must address: i. Implement and periodically review access controls. ii. Conduct a periodic inventory of data, noting where it is collected, stored, or transmitted. iii. Encrypt customer information on the institution’s system and when it is in transit. iv. Assess applications developed by the institution. v. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. vi. Dispose of customer information securely. vii. Anticipate and evaluate changes to the information system or network. viii. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. 4. Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. 5. Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program. 6. Address how the institution will oversee its information system service providers. 7. Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows has reason to know may have a material impact on the institution’s information security program. What problem did the audit work identify? Based on our audit work, we determined that MSU-Denver’s WISP addressed some, but not all, of the elements that institutions must address. Specifically, the WISP did not address the three following elements: 1. Design and implementation of the three following safeguards: i. Conducting a periodic inventory of data, noting where it is collected, stored, or transmitted. ii. Assessing applications developed by the institution. iii. Implementing multi-factor authentication for anyone accessing customer information on the institution’s system. 2. Regular testing or monitoring the effectiveness of the safeguards MSU-Denver implemented. 3. Evaluation and adjustment of MSU-Denver’s WISP in light of the results of the required testing and monitoring. Why did this problem occur? MSU-Denver did not have adequate internal controls in place to ensure that its WISP fully complied with the requirements of federal regulation 16 CFR 314.4 because its WISP was only in draft form and the ITS department did not have a proper process in place to review its WISP and update it to reflect current federal requirements. MSU-Denver’s ITS management indicated that a WISP that meets these federal requirements is being developed and, once approved by MSU-Denver leadership, will become an official policy. Why does this problem matter? Protecting students’ sensitive data is a critical compliance requirement for institutions participating in the USDE’s Student Financial Aid program. Without the proper development, implementation, and maintenance of a WISP to ensure that MSU-Denver addresses all of the required elements and safeguards specified in federal regulation 16 CFR 314.4, MSU-Denver increases its exposure to potential data breaches, loss of data, or other fraudulent acts that could occur. Additionally, failure to comply with the GLBA increases MSU-Denver’s risk of material noncompliance with the USDE’s Student Financial Aid program requirements. See " Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-039 The Metropolitan State University of Denver’s (MSU-Denver) Information Technology Services (ITS) department should strengthen its internal controls over information security by establishing, implementing, and maintaining a comprehensive written information security program (WISP) that reflects the current federal requirements of the Gramm-Leach-Bliley Act. This should include processes for ITS to test and monitor its information security to determine when adjustments are needed to the MSU-Denver WISP, and to obtain a formal review and approval of the WISP from MSU-Denver’s leadership. Response Metropolitan State University of Denver Agree Implementation Date: June 2026 MSU Denver IT Security will update its written information security program to address the necessary requirements of the Gramm-Leach-Bliley Act. The WISP will be reviewed and updated at least once each year, with updates being based on risk assessments, audits, changes to the environment, and any incidents which indicate a need for changes to the WISP. The updated WISP will include existing policies as well as new policies that describe standards for: • Periodic inventory of data • Multi-Factor Authentication, Single Sign-On, and passwords • Assessment of applications developed by the institution • Testing our safeguards The updated WISP will be formally reviewed and approved by the Chief Financial Officer by June 30, 2026.
Show full finding ▾Hide full finding ▴Finding 2025-039 Internal Controls and Compliance with Special Tests and Provisions for Student Financial Assistance Metropolitan State University of Denver (MSU-Denver) receives funding from the federal Department of Education’s (USDE) Title IV Student Financial Assistance (Student Financial Aid) program, which requires MSU-Denver to obtain sensitive data from students. For example, MSUDenver obtains personally identifiable financial and tax information from students in order to administer its federal Student Financial Aid program. As a result, MSU-Denver’s Information Technology Services (ITS) department is responsible for ensuring compliance with the federal Gramm-Leach-Bliley Act (GLBA). The GLBA, which was enacted in 1999, mandates that financial institutions disclose their information-sharing practices and provide consumers with opt-out options for their personal data. It also established the Financial Privacy Rule, which requires institutions to protect sensitive customer information and provide clear privacy notices to customers. Before MSU-Denver receives federal Student Financial Aid from USDE, MSU-Denver agrees to adhere to compliance requirements within a Program Participation Agreement (PPA), and a Student Aid Internet Gateway Agreement (SAIGA). One of the compliance requirements MSU-Denver agrees to within the PPA and SAIGA is the GLBA, which requires MSU-Denver to explain their information-sharing practices with their students and safeguard sensitive data, with particular attention to information provided to MSU-Denver by the USDE or otherwise obtained in support of the administration of MSU-Denver’s Student Financial Aid program. The GLBA requirements are codified in Title 16, Part 314, Section 4 of the Code of Federal Regulations (16 CFR 314.4), and requires MSU-Denver to develop, implement, and maintain a comprehensive written information security program (WISP) in one or more readily accessible parts. This federal regulation also specifies the elements and safeguards that MSU-Denver’s WISP needs to include for the protection of students’ financial aid information. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review MSU-Denver’s internal controls over its WISP, and determine if it included the minimum elements and safeguards required by the GLBA during Fiscal Year 2025. Our review included obtaining MSU-Denver’s WISP and performing the following procedures: • We met with MSU-Denver’s ITS management to determine how it developed, implemented, and maintained its WISP. • We compared MSU-Denver’s WISP to the elements and safeguards required by the GLBA. • We reviewed the ITS’ policies and procedures to determine if MSU-Denver had suitably designed and implemented the GLBA required elements and safeguards during Fiscal Year 2025. How were the results of the audit work measured? We measured the results of our audit against federal regulation 16 CFR 314.4, which states that an institution’s WISP, at a minimum, must include the seven following elements that include eight minimum safeguards: 1. Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 2. Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 3. Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment. At a minimum, the following are the eight safeguards that a WISP must address: i. Implement and periodically review access controls. ii. Conduct a periodic inventory of data, noting where it is collected, stored, or transmitted. iii. Encrypt customer information on the institution’s system and when it is in transit. iv. Assess applications developed by the institution. v. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. vi. Dispose of customer information securely. vii. Anticipate and evaluate changes to the information system or network. viii. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. 4. Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. 5. Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program. 6. Address how the institution will oversee its information system service providers. 7. Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows has reason to know may have a material impact on the institution’s information security program. What problem did the audit work identify? Based on our audit work, we determined that MSU-Denver’s WISP addressed some, but not all, of the elements that institutions must address. Specifically, the WISP did not address the three following elements: 1. Design and implementation of the three following safeguards: i. Conducting a periodic inventory of data, noting where it is collected, stored, or transmitted. ii. Assessing applications developed by the institution. iii. Implementing multi-factor authentication for anyone accessing customer information on the institution’s system. 2. Regular testing or monitoring the effectiveness of the safeguards MSU-Denver implemented. 3. Evaluation and adjustment of MSU-Denver’s WISP in light of the results of the required testing and monitoring. Why did this problem occur? MSU-Denver did not have adequate internal controls in place to ensure that its WISP fully complied with the requirements of federal regulation 16 CFR 314.4 because its WISP was only in draft form and the ITS department did not have a proper process in place to review its WISP and update it to reflect current federal requirements. MSU-Denver’s ITS management indicated that a WISP that meets these federal requirements is being developed and, once approved by MSU-Denver leadership, will become an official policy. Why does this problem matter? Protecting students’ sensitive data is a critical compliance requirement for institutions participating in the USDE’s Student Financial Aid program. Without the proper development, implementation, and maintenance of a WISP to ensure that MSU-Denver addresses all of the required elements and safeguards specified in federal regulation 16 CFR 314.4, MSU-Denver increases its exposure to potential data breaches, loss of data, or other fraudulent acts that could occur. Additionally, failure to comply with the GLBA increases MSU-Denver’s risk of material noncompliance with the USDE’s Student Financial Aid program requirements. See " Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-039 The Metropolitan State University of Denver’s (MSU-Denver) Information Technology Services (ITS) department should strengthen its internal controls over information security by establishing, implementing, and maintaining a comprehensive written information security program (WISP) that reflects the current federal requirements of the Gramm-Leach-Bliley Act. This should include processes for ITS to test and monitor its information security to determine when adjustments are needed to the MSU-Denver WISP, and to obtain a formal review and approval of the WISP from MSU-Denver’s leadership. Response Metropolitan State University of Denver Agree Implementation Date: June 2026 MSU Denver IT Security will update its written information security program to address the necessary requirements of the Gramm-Leach-Bliley Act. The WISP will be reviewed and updated at least once each year, with updates being based on risk assessments, audits, changes to the environment, and any incidents which indicate a need for changes to the WISP. The updated WISP will include existing policies as well as new policies that describe standards for: • Periodic inventory of data • Multi-Factor Authentication, Single Sign-On, and passwords • Assessment of applications developed by the institution • Testing our safeguards The updated WISP will be formally reviewed and approved by the Chief Financial Officer by June 30, 2026.
MSU Denver IT Security will update its written information security program to address the necessary requirements of the Gramm-Leach-Bliley Act. The WISP will be reviewed and updated at least once each year, with updates being based on risk assessments, audits, changes to the environment, and any incidents which indicate a need for changes to the WISP. The updated WISP will include existing policies as well as new policies that describe standards for: • Periodic inventory of data • Multi-Factor Authentication, Single Sign-On, and passwords • Assessment of applications developed by the institution • Testing our safeguards The updated WISP will be formally reviewed and approved by the Chief Financial Officer by June 30, 2026.
Finding 2025-040 Internal Controls and Compliance Over Student Financial Assistance Cluster – NSLDS Reporting The federal Department of Education (USDE) requires institutions of higher education that receive Title IV Student Financial Assistance (Student Financial Aid) funds to report enrollment information within specified timeframes to the USDE through its central database for student assistance, the National Student Loan Data System (NSLDS). Enrollment reporting, through the submission of student roster files with enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Metropolitan State University of Denver (MSUDenver) submits student roster files with enrollment status changes to the National Student Clearinghouse (Clearinghouse), a third-party service provider. The Clearinghouse uploads MSUDenver’s student roster files with enrollment status changes directly to NSLDS. MSU-Denver’s Registrar’s Office (Registrar’s Office) compiles the student roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Student Financial Aid at MSU-Denver. The Registrar’s Office performs an initial review of participating students’ enrollment information during the census, which is typically during the second week of the semester, for reporting to NSLDS. After the census date each semester, the Registrar’s Office staff prepare student roster files of enrollment status changes, such as a withdrawal, graduation, or a change in enrolled credit hours, through a manual comparison of applicable students’ enrollment status at the census date to the current enrollment status on MSUDenver’s reporting system, Banner. During Fiscal Year 2025, MSU-Denver issued approximately $95.1 million in federal Student Financial Aid to its enrolled students during the year, which included approximately $40.5 million and $52.7 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether MSU-Denver had adequate internal controls over, and complied with, requirements for reporting enrollment status changes to the USDE for Pell Grants and Direct Loan programs during Fiscal Year 2025. As part of our Fiscal Year 2025 testwork, we reviewed enrollment information that MSU-Denver was required to report to USDE via NSLDS during Fiscal Year 2025 for a random sample of 40 students. For each student in our sample, we compared information within MSU-Denver’s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal, graduation, or a change in enrolled credit hours, to determine if MSU-Denver reported the information accurately and no later than USDE’s deadlines. How were the results of the audit work measured? We measured the results of our audit work against the following: Under the federal Pell Grant and Direct Loan program requirements, 34 CFR 690.83(b)(2) and 34 CFR 685.309(b)(2), an institution must report any enrollment status changes through student roster files, including the date of the change, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student’s enrollment status to NSLDS when there is a (a) reduction or increase in the student’s attendance levels, (b) graduation, (c) withdrawal, or (d) a student accepted for enrollment but never attended. Institutions are responsible for submitting their enrollment status reporting no later than the required federal deadlines regardless of whether they report directly through NSLDS or via a third-party servicer. We measured the results of our testing against the USDE’s 60-day timeframe for submitted roster files. What problem did the audit work identify? We found that MSU-Denver did not report enrollment status changes to the USDE by the required federal deadlines for 14 of the 40 (35 percent) students we tested. Specifically, MSU-Denver reported enrollment status changes for these 14 students between 18 to 53 days after USDE’s 60- day enrollment status change reporting requirement. These delays occurred between December 2024 and April 2025 and related to the following enrollment status changes: 12 of the students we tested graduated from MSU-Denver, one of the students we tested withdrew from MSU-Denver, and one of the students we tested had a change in enrolled credit hours. Why did this problem occur? MSU-Denver did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Student Financial Aid program. The Registrar’s Office staff indicated that the student roster files prepared from Banner that were submitted to the Clearinghouse were rejected by the Clearinghouse due to errors within the configuration of student roster files. This technical issue required the Registrar’s Office to reconfigure the student roster files that are prepared for submission to the Clearinghouse. The timing of when the Clearinghouse notified the Registrar’s Office of the rejections of the student roster files, and the reconfiguration that was required, resulted in MSU-Denver not reporting enrollment status changes within USDE’s required timeframe. Why does this problem matter? Enrollment reporting is a critical compliance requirement for institutions participating in the federal Student Financial Aid program. For recipients of Pell Grants, timely enrollment reporting by institutions assists with their eligibility, future disbursement amounts, and continued access to Student Financial Aid. For borrowers of Direct Loans, timely enrollment reporting by institutions assists the USDE in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Failure to meet the USDE’s required enrollment status change reporting timelines increases MSU-Denver’s risk of material noncompliance with federal Student Financial Aid program requirements. See " Schedule of Findings and Questioned Costs" for chart/table. Recommendation 2025-040 The Metropolitan State University of Denver (MSU-Denver) should strengthen its internal controls over enrollment reporting to the federal Department of Education (USDE) for students who receive Title IV Student Financial Assistance through Pell Grants or the Direct Loan Program. This should include preparing student roster files in the correct configuration to ensure that these changes are submitted by the National Student Clearinghouse (NSC) to USDE’s National Student Loan Data System within 60-days of the enrollment change, as required by federal regulations. Response Metropolitan State University of Denver Agree Implementation Date: June 2026 MSU Denver manages enrollment reporting within the Office of the Registrar. We develop a schedule each calendar year and semester with NSC to identify scheduled reporting dates for each term in alignment with critical semester dates (start, end, drop, etc.). In Fiscal Year 2025, there was a technical issue in which we had to work with our ERP vendor, Ellucian, to provide a solution. The Office of the Registrar will strengthen its internal controls to ensure enrollment changes are reported within the required 60-day timeline.
Show full finding ▾Hide full finding ▴Finding 2025-040 Internal Controls and Compliance Over Student Financial Assistance Cluster – NSLDS Reporting The federal Department of Education (USDE) requires institutions of higher education that receive Title IV Student Financial Assistance (Student Financial Aid) funds to report enrollment information within specified timeframes to the USDE through its central database for student assistance, the National Student Loan Data System (NSLDS). Enrollment reporting, through the submission of student roster files with enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Metropolitan State University of Denver (MSUDenver) submits student roster files with enrollment status changes to the National Student Clearinghouse (Clearinghouse), a third-party service provider. The Clearinghouse uploads MSUDenver’s student roster files with enrollment status changes directly to NSLDS. MSU-Denver’s Registrar’s Office (Registrar’s Office) compiles the student roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Student Financial Aid at MSU-Denver. The Registrar’s Office performs an initial review of participating students’ enrollment information during the census, which is typically during the second week of the semester, for reporting to NSLDS. After the census date each semester, the Registrar’s Office staff prepare student roster files of enrollment status changes, such as a withdrawal, graduation, or a change in enrolled credit hours, through a manual comparison of applicable students’ enrollment status at the census date to the current enrollment status on MSUDenver’s reporting system, Banner. During Fiscal Year 2025, MSU-Denver issued approximately $95.1 million in federal Student Financial Aid to its enrolled students during the year, which included approximately $40.5 million and $52.7 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether MSU-Denver had adequate internal controls over, and complied with, requirements for reporting enrollment status changes to the USDE for Pell Grants and Direct Loan programs during Fiscal Year 2025. As part of our Fiscal Year 2025 testwork, we reviewed enrollment information that MSU-Denver was required to report to USDE via NSLDS during Fiscal Year 2025 for a random sample of 40 students. For each student in our sample, we compared information within MSU-Denver’s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal, graduation, or a change in enrolled credit hours, to determine if MSU-Denver reported the information accurately and no later than USDE’s deadlines. How were the results of the audit work measured? We measured the results of our audit work against the following: Under the federal Pell Grant and Direct Loan program requirements, 34 CFR 690.83(b)(2) and 34 CFR 685.309(b)(2), an institution must report any enrollment status changes through student roster files, including the date of the change, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student’s enrollment status to NSLDS when there is a (a) reduction or increase in the student’s attendance levels, (b) graduation, (c) withdrawal, or (d) a student accepted for enrollment but never attended. Institutions are responsible for submitting their enrollment status reporting no later than the required federal deadlines regardless of whether they report directly through NSLDS or via a third-party servicer. We measured the results of our testing against the USDE’s 60-day timeframe for submitted roster files. What problem did the audit work identify? We found that MSU-Denver did not report enrollment status changes to the USDE by the required federal deadlines for 14 of the 40 (35 percent) students we tested. Specifically, MSU-Denver reported enrollment status changes for these 14 students between 18 to 53 days after USDE’s 60- day enrollment status change reporting requirement. These delays occurred between December 2024 and April 2025 and related to the following enrollment status changes: 12 of the students we tested graduated from MSU-Denver, one of the students we tested withdrew from MSU-Denver, and one of the students we tested had a change in enrolled credit hours. Why did this problem occur? MSU-Denver did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Student Financial Aid program. The Registrar’s Office staff indicated that the student roster files prepared from Banner that were submitted to the Clearinghouse were rejected by the Clearinghouse due to errors within the configuration of student roster files. This technical issue required the Registrar’s Office to reconfigure the student roster files that are prepared for submission to the Clearinghouse. The timing of when the Clearinghouse notified the Registrar’s Office of the rejections of the student roster files, and the reconfiguration that was required, resulted in MSU-Denver not reporting enrollment status changes within USDE’s required timeframe. Why does this problem matter? Enrollment reporting is a critical compliance requirement for institutions participating in the federal Student Financial Aid program. For recipients of Pell Grants, timely enrollment reporting by institutions assists with their eligibility, future disbursement amounts, and continued access to Student Financial Aid. For borrowers of Direct Loans, timely enrollment reporting by institutions assists the USDE in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Failure to meet the USDE’s required enrollment status change reporting timelines increases MSU-Denver’s risk of material noncompliance with federal Student Financial Aid program requirements. See " Schedule of Findings and Questioned Costs" for chart/table. Recommendation 2025-040 The Metropolitan State University of Denver (MSU-Denver) should strengthen its internal controls over enrollment reporting to the federal Department of Education (USDE) for students who receive Title IV Student Financial Assistance through Pell Grants or the Direct Loan Program. This should include preparing student roster files in the correct configuration to ensure that these changes are submitted by the National Student Clearinghouse (NSC) to USDE’s National Student Loan Data System within 60-days of the enrollment change, as required by federal regulations. Response Metropolitan State University of Denver Agree Implementation Date: June 2026 MSU Denver manages enrollment reporting within the Office of the Registrar. We develop a schedule each calendar year and semester with NSC to identify scheduled reporting dates for each term in alignment with critical semester dates (start, end, drop, etc.). In Fiscal Year 2025, there was a technical issue in which we had to work with our ERP vendor, Ellucian, to provide a solution. The Office of the Registrar will strengthen its internal controls to ensure enrollment changes are reported within the required 60-day timeline.
MSU Denver manages enrollment reporting within the Office of the Registrar. We develop a schedule each calendar year and semester with NSC to identify scheduled reporting dates for each term in alignment with critical semester dates (start, end, drop, etc.). In Fiscal Year 2025, there was a technical issue in which we had to work with our ERP vendor, Ellucian, to provide a solution. The Office of the Registrar will strengthen its internal controls to ensure enrollment changes are reported within the required 60-day timeline.
Finding 2025-041 AWARE – Information Security and Change Management Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department of Labor and Employment’s Division of Vocational Rehabilitation administers the federal Rehabilitation Services – Vocational Rehabilitation Grants to States [ALN 84.126] (Vocational Rehabilitation) program and relies on its Accessible Web-Based Activity and Reporting Environment (AWARE) IT system to aid with management of the program and to track expenditures. The AWARE system is a configurable, off-the-shelf (COTS) system that is managed and hosted by the Department’s third-party IT service provider, Alliance Enterprises (Alliance). Department staff access the system via a secure Web portal. Program information is stored on servers and databases managed by Alliance. Alliance developed the AWARE system specifically to meet federal requirements for Vocational Rehabilitation program services and is used by multiple states. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also includes information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details of how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security and access management. The Department has policies that define the rules for various software systems based on the Department’s needs and security requirements; and the AWARE System Security Plan (SSP), which lists security requirements and describes the controls that must be in place to ensure all the security policy requirements are met. Once policies and procedures have been formalized and communicated to responsible staff and the Department’s contractor, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to gain an understanding of, and determine whether the Department had designed and implemented IT general controls, specifically information security and change management controls, over the AWARE system. Our audit work consisted of inquiries to the Department to gain an understanding of these IT general control areas, along with a review of related documentation provided by the Department staff. How were the results of the audit work measured? We applied the following criteria when evaluating the design effectiveness of the IT general controls: • The Governor’s Office of Information Technology (OIT)’s Colorado Information Security Policies (Security Policies). • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls, including IT general controls, over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office (GAO), is a leading industry internal control framework. The Office of the State Controller (OSC) has adopted the Green Book as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraphs 3.09, Documentation of the Internal Control System, and 12.02, Documentation of Responsibilities through Policies, requires that management develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Green Book, Paragraph 12.05, Periodic Review of Control Activities, also requires that management periodically review policies and procedures for continued relevance and effectiveness in achieving the entity’s objectives or addressing related risks. If there is a significant change in an entity’s process, management should review this process in a timely manner after the change to verify that the control activities are designed and implemented appropriately. • Green Book, Paragraph 14.03, Communication throughout the Entity, prescribes that management should communicate quality information to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management should assign the internal control responsibilities for key roles. What problems did the audit work identify? During Fiscal Year 2025, we identified problems with the Department’s information security and change management IT general controls for the AWARE system. Why did these problems occur? According to the Department, it is in the final stages of modernizing a new case management system that will replace its current AWARE system and, therefore, did not update its SSP or policies and procedures for AWARE during Fiscal Year 2025. Department staff indicated that they expected AWARE to be decommissioned prior to the end of Fiscal Year 2025, and therefore determined it was not feasible to update the AWARE SSP during Fiscal Year 2025 to comply with OIT’s Security Policies. However, deployment of the new system was delayed due to the Department working through the new system’s User Acceptance Testing. The Department indicated that it will develop policies for the new case management system during the modernization process, which it expects to be finalized with the decommissioning of AWARE in January 2026. Why do these problems matter? It is important for the Department to have an effective system of internal controls in place in order to meet its objectives and comply with federal requirements for the Vocation Rehabilitation program. Without an effective internal control system, the reliability of the data processed, stored, and reported on by the Department’s IT system for the Vocational Rehabilitation program can be adversely impacted. When IT policies and procedures are not maintained, updated, and communicated, Department staff, and others who are subject to the requirements and processes, may not be able to adequately manage or consistently apply IT policy requirements and processes to meet management’s objectives and expectations, respond to risks appropriately, and ensure the confidentiality, integrity, and availability of the Department’s information systems. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-041 The Department of Labor and Employment should improve its overall IT governance and information security IT general controls for the information system used for the Rehabilitation Services – Vocational Rehabilitation Grants to States program by: A. Implementing recommendation Part A as noted in the confidential finding. B. Implementing recommendation Part B as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2026 The Department will implement Part A of the confidential finding. B. Agree Implementation Date: July 2026 The Department will implement Part B of the confidential finding.
Show full finding ▾Hide full finding ▴Finding 2025-041 AWARE – Information Security and Change Management Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department of Labor and Employment’s Division of Vocational Rehabilitation administers the federal Rehabilitation Services – Vocational Rehabilitation Grants to States [ALN 84.126] (Vocational Rehabilitation) program and relies on its Accessible Web-Based Activity and Reporting Environment (AWARE) IT system to aid with management of the program and to track expenditures. The AWARE system is a configurable, off-the-shelf (COTS) system that is managed and hosted by the Department’s third-party IT service provider, Alliance Enterprises (Alliance). Department staff access the system via a secure Web portal. Program information is stored on servers and databases managed by Alliance. Alliance developed the AWARE system specifically to meet federal requirements for Vocational Rehabilitation program services and is used by multiple states. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also includes information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details of how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security and access management. The Department has policies that define the rules for various software systems based on the Department’s needs and security requirements; and the AWARE System Security Plan (SSP), which lists security requirements and describes the controls that must be in place to ensure all the security policy requirements are met. Once policies and procedures have been formalized and communicated to responsible staff and the Department’s contractor, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to gain an understanding of, and determine whether the Department had designed and implemented IT general controls, specifically information security and change management controls, over the AWARE system. Our audit work consisted of inquiries to the Department to gain an understanding of these IT general control areas, along with a review of related documentation provided by the Department staff. How were the results of the audit work measured? We applied the following criteria when evaluating the design effectiveness of the IT general controls: • The Governor’s Office of Information Technology (OIT)’s Colorado Information Security Policies (Security Policies). • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls, including IT general controls, over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office (GAO), is a leading industry internal control framework. The Office of the State Controller (OSC) has adopted the Green Book as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraphs 3.09, Documentation of the Internal Control System, and 12.02, Documentation of Responsibilities through Policies, requires that management develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Green Book, Paragraph 12.05, Periodic Review of Control Activities, also requires that management periodically review policies and procedures for continued relevance and effectiveness in achieving the entity’s objectives or addressing related risks. If there is a significant change in an entity’s process, management should review this process in a timely manner after the change to verify that the control activities are designed and implemented appropriately. • Green Book, Paragraph 14.03, Communication throughout the Entity, prescribes that management should communicate quality information to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management should assign the internal control responsibilities for key roles. What problems did the audit work identify? During Fiscal Year 2025, we identified problems with the Department’s information security and change management IT general controls for the AWARE system. Why did these problems occur? According to the Department, it is in the final stages of modernizing a new case management system that will replace its current AWARE system and, therefore, did not update its SSP or policies and procedures for AWARE during Fiscal Year 2025. Department staff indicated that they expected AWARE to be decommissioned prior to the end of Fiscal Year 2025, and therefore determined it was not feasible to update the AWARE SSP during Fiscal Year 2025 to comply with OIT’s Security Policies. However, deployment of the new system was delayed due to the Department working through the new system’s User Acceptance Testing. The Department indicated that it will develop policies for the new case management system during the modernization process, which it expects to be finalized with the decommissioning of AWARE in January 2026. Why do these problems matter? It is important for the Department to have an effective system of internal controls in place in order to meet its objectives and comply with federal requirements for the Vocation Rehabilitation program. Without an effective internal control system, the reliability of the data processed, stored, and reported on by the Department’s IT system for the Vocational Rehabilitation program can be adversely impacted. When IT policies and procedures are not maintained, updated, and communicated, Department staff, and others who are subject to the requirements and processes, may not be able to adequately manage or consistently apply IT policy requirements and processes to meet management’s objectives and expectations, respond to risks appropriately, and ensure the confidentiality, integrity, and availability of the Department’s information systems. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-041 The Department of Labor and Employment should improve its overall IT governance and information security IT general controls for the information system used for the Rehabilitation Services – Vocational Rehabilitation Grants to States program by: A. Implementing recommendation Part A as noted in the confidential finding. B. Implementing recommendation Part B as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2026 The Department will implement Part A of the confidential finding. B. Agree Implementation Date: July 2026 The Department will implement Part B of the confidential finding.
The Department will implement Part B of the confidential finding.
Finding 2025-042 MyUI+ – IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance (UI) program, and relies on its IT system, MyUI+, to aid with determining applicants’ eligibility for the UI program and to provide data necessary for federal reporting to the U.S. Department of Labor for the UI program. The Department is the business owner of the MyUI+ system and works with OIT and the Department’s external IT service provider to manage MyUI+. The OSC has adopted the GAO’s Green Book as the State’s standard for internal controls, which all state agencies must follow. For the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security, for example controls related to issuing new user credentials. Once the Department has formalized and communicated its policies and procedures to responsible staff, specific internal control activities can be implemented and operationalized. OIT has promulgated the Security Policies that apply to the Department and its systems, and outline specific business owner IT requirements with which the Department must comply. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations related to MyUI+. As part of our recommendations, we recommended that the Department should improve its IT governance for the MyUI+ system by: • Formalizing and communicating IT procedures guidance to Department staff and the Department’s IT service provider performing IT general control activities, including a Department-defined periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules align with the most current version of the Security Policies. • Implementing the recommendation as noted in the confidential finding. The Department agreed with these recommendations and planned to implement them by June 2025. Our audit work consisted of assessing the design and implementation of the Department’s IT policies and procedures, through inquiry with Department staff and inspection of supporting documentation. How were the results of the audit work measured? We measured the results of our audit work against the following: • OIT Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, including the Department, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems. OIT Security Policies also indicate that the Department, as the business owner for MyUI+, is responsible for following and adhering to all identified business owner requirements. • OIT Security Policies and IRS Publication 1075, Tax Information Security Guidelines for Federal State and Local Agencies. Department management stated that it aligns with IRS Publication 1075 for its systems even though MyUI+ does not contain Federal Tax Information, which is the focus of Publication 1075’s security requirements. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls, including IT general controls, over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Green Book, Paragraphs 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, states that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraphs 11.06 and 11.07, Design Appropriate Types of Control Activities, state that management should design appropriate types of control activities in the entity's information system, including information system general controls that facilitate the proper operation of the entity’s systems. What problems did the audit work identify? The Department did not fully implement our prior audit recommendations to improve its IT governance related to MyUI+ during Fiscal Year 2025. Specifically: • The Department took steps to implement the recommendation by beginning to formalize IT procedures for MyUI+, including those that defined a required periodic review of OIT’s Security Policies; however, the Department did not have the formalized procedures in place nor had it communicated the procedures to employees or its IT service provider by the end of Fiscal Year 2025. • We found that the Department did not fully implement the confidential prior audit recommendation during Fiscal Year 2025, which put the Department at risk for not complying with Publication 1075. Why did these problems occur? According to the Department, the review, updating, and communication process of its procedures did not occur by the end of Fiscal Year 2025 due to turnover and contract renegotiations, resulting in partial implementation of the recommendations by fiscal year end. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable for meeting management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. Without policies and procedures, staff may not perform processes and controls in a consistent manner. The identified deficiencies increase the risk of system compromise and can affect the confidentiality, integrity, and availability of the MyUI+ system, as well as adversely impact the reliability of data that is processed, stored, and generated by the system. Additionally, if the MyUI+ information security processes and controls are not appropriately implemented and operating effectively, the Department may not be able to ensure compliance with federal requirements, OIT’s Security Policies, and Publication 1075. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-042 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service provider, as applicable, for the MyUI+ information system by: A. Prioritizing staffing to complete and communicate the formalized IT procedures, including a required Department-defined periodic review process of the Colorado Information Security Policies, developed and published by the Governor’s Office of Information Technology, to Department staff and the Department’s IT service provider performing IT general control activities for MyUI+. B. Implementing recommendation Part B as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: April 2026 The Department will complete and communicate formalized IT procedures to staff and IT service providers for IT general control activities for MyUI+ by April 2026. B. Agree Implementation Date: April 2026 The Department will implement Part B of the confidential finding.
Show full finding ▾Hide full finding ▴Finding 2025-042 MyUI+ – IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance (UI) program, and relies on its IT system, MyUI+, to aid with determining applicants’ eligibility for the UI program and to provide data necessary for federal reporting to the U.S. Department of Labor for the UI program. The Department is the business owner of the MyUI+ system and works with OIT and the Department’s external IT service provider to manage MyUI+. The OSC has adopted the GAO’s Green Book as the State’s standard for internal controls, which all state agencies must follow. For the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security, for example controls related to issuing new user credentials. Once the Department has formalized and communicated its policies and procedures to responsible staff, specific internal control activities can be implemented and operationalized. OIT has promulgated the Security Policies that apply to the Department and its systems, and outline specific business owner IT requirements with which the Department must comply. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations related to MyUI+. As part of our recommendations, we recommended that the Department should improve its IT governance for the MyUI+ system by: • Formalizing and communicating IT procedures guidance to Department staff and the Department’s IT service provider performing IT general control activities, including a Department-defined periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules align with the most current version of the Security Policies. • Implementing the recommendation as noted in the confidential finding. The Department agreed with these recommendations and planned to implement them by June 2025. Our audit work consisted of assessing the design and implementation of the Department’s IT policies and procedures, through inquiry with Department staff and inspection of supporting documentation. How were the results of the audit work measured? We measured the results of our audit work against the following: • OIT Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, including the Department, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems. OIT Security Policies also indicate that the Department, as the business owner for MyUI+, is responsible for following and adhering to all identified business owner requirements. • OIT Security Policies and IRS Publication 1075, Tax Information Security Guidelines for Federal State and Local Agencies. Department management stated that it aligns with IRS Publication 1075 for its systems even though MyUI+ does not contain Federal Tax Information, which is the focus of Publication 1075’s security requirements. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls, including IT general controls, over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Green Book, Paragraphs 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, states that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraphs 11.06 and 11.07, Design Appropriate Types of Control Activities, state that management should design appropriate types of control activities in the entity's information system, including information system general controls that facilitate the proper operation of the entity’s systems. What problems did the audit work identify? The Department did not fully implement our prior audit recommendations to improve its IT governance related to MyUI+ during Fiscal Year 2025. Specifically: • The Department took steps to implement the recommendation by beginning to formalize IT procedures for MyUI+, including those that defined a required periodic review of OIT’s Security Policies; however, the Department did not have the formalized procedures in place nor had it communicated the procedures to employees or its IT service provider by the end of Fiscal Year 2025. • We found that the Department did not fully implement the confidential prior audit recommendation during Fiscal Year 2025, which put the Department at risk for not complying with Publication 1075. Why did these problems occur? According to the Department, the review, updating, and communication process of its procedures did not occur by the end of Fiscal Year 2025 due to turnover and contract renegotiations, resulting in partial implementation of the recommendations by fiscal year end. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable for meeting management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. Without policies and procedures, staff may not perform processes and controls in a consistent manner. The identified deficiencies increase the risk of system compromise and can affect the confidentiality, integrity, and availability of the MyUI+ system, as well as adversely impact the reliability of data that is processed, stored, and generated by the system. Additionally, if the MyUI+ information security processes and controls are not appropriately implemented and operating effectively, the Department may not be able to ensure compliance with federal requirements, OIT’s Security Policies, and Publication 1075. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-042 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service provider, as applicable, for the MyUI+ information system by: A. Prioritizing staffing to complete and communicate the formalized IT procedures, including a required Department-defined periodic review process of the Colorado Information Security Policies, developed and published by the Governor’s Office of Information Technology, to Department staff and the Department’s IT service provider performing IT general control activities for MyUI+. B. Implementing recommendation Part B as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: April 2026 The Department will complete and communicate formalized IT procedures to staff and IT service providers for IT general control activities for MyUI+ by April 2026. B. Agree Implementation Date: April 2026 The Department will implement Part B of the confidential finding.
The Department will implement Part B of the confidential finding.
2024-047
Finding 2025-043 Compliance with Reporting for Community Development Block Grant program The Department administers the federal Community Development Block Grant/State’s program and Non-Entitlement Grants in Hawaii (Community Development Block Grant or CDBG) [ALN 14.228] for non-entitlement municipalities and counties to carry out community development activities. The federal government splits the Department’s CDBG program into sub-programs related to the CARES Act (CDBG-CV), Disaster Recovery (CDBG-DR), and the Neighborhood Stabilization Program (CDBG-NSP). The CARES (Coronavirus Aid, Relief, and Economic Security) Act, enacted March 27, 2020, appropriated $5.0 billion in CDBG-CV funds to be allocated to about 1,250 states, local governments, and insular areas to fund activities to prevent, prepare for, and respond to Coronavirus. CDBG-CV and CDBG grants are a flexible source of funding that can be used to pay costs that are not covered by other sources of assistance, particularly to benefit persons of low and moderate income. The primary objective for CDBG-DR is to provide disaster relief, long-term recovery, restoration of infrastructure and housing, and economic revitalization in the most impacted and distressed areas resulting from a major disaster, declared pursuant to the Robert T. Stafford Disaster Relief and Emergency Assistance Act of 1974. The objectives of the CDBG-NSP are to: (1) stabilize property values, (2) arrest neighborhood decline, (3) assist in preventing neighborhood blight, and (4) stabilize communities across America hardest hit by residential foreclosures and abandonment. These objectives have been achieved through the purchase and redevelopment of foreclosed and abandoned homes and residential properties that allows those properties to turn into useful, safe and sanitary housing. The grants are to be considered CDBG funds. The Department is required to submit financial information electronically to the federal Housing and Urban Development (HUD) Exchange IT system on an annual basis. The Department is required to submit various reports that include the following: • Performance reports titled, Performance and Evaluation Financial Summary Reports (PR28), are required to list all of the financial activity related to the CDBG program and CDBG-CV subprogram. • Quarterly Performance Reports for the CDBG-DR program and CDBG-NSP. The Quarterly Performance Reports include the Department’s activities related to the CDBG grant for these sub-programs on a quarterly basis. The Department is also required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its CDBG awards. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards, including information about amounts passed through to subrecipients, or subawards, given to other governments or nonprofit organizations, available to the public. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. The Department is required to submit FFATA information through the FFATA Subaward Reporting System (formerly FSRS)—the System for Award Management (SAM.gov). Once the Department submits a report to SAM.gov, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department made 25 CDBG subawards to 18 subrecipients totaling $10.2 million that were subject to FFATA reporting. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to identify and review the operational effectiveness of the Department’s internal controls and compliance over the federal reporting process for the CDBG program, and determine whether the reports were prepared and submitted in accordance with state and federal regulations. During our audit, we reviewed two PR28 Performance and Evaluation Financial Summary Reports—one for CDBG overall and one for the CDBG-CV sub-program filed by the Department during Fiscal Year 2025—and the related supporting documentation. We also reviewed eight Quarterly Performance Reports—four reports for each of the CDBG-DR and CDBG-NSP subprograms filed by the Department for Fiscal Year 2025—and the related supporting documentation. Additionally, we received the Department’s sub-awardee report submitted to SAM.gov for FFATA reporting for Fiscal Year 2025 for the CDBG grant and tested 7 of the 25 subawards listed on the report. We used both performance and sub-awardee reports to determine if the financial activity in these reports could be traced to the expenditures recorded within the Colorado Operations Resource Engine (CORE), the State’s accounting system, for the CDBG grant program for Fiscal Year 2025. We also performed testwork to determine if the performance and sub-awardee reports were reviewed and approved internally, submitted in a timely manner, and approved by HUD. How were the results of the audit work measured? For the CDBG program, we measured the results of our audit work against the following requirements: • As noted previously, the Department is required to submit certain financial information electronically to HUD through its HUD Exchange system on an annual basis. HUD requires that the reports be prepared in accordance with Generally Accepted Accounting Principles (GAAP). Per the federal Office of Management and Budget’s (OMB) Compliance Supplement, the various reports that the Department must submit include the following: PR28 Performance and Evaluation Financial Summary Reports for the CDBG program and CDBG-CV sub-program. This report is required to list all of the financial activity related to the CDBG program, such as the overall benefit to low- and moderate-income persons, the maximum allowable costs for administration, technical assistance, and overall planning, management and administration, and must be submitted quarterly, 30 days after the reporting period end date. Quarterly Performance Reports for the CDBG-DR program and CDBG-NSP. The Quarterly Performance Reports must cover all expenditures on the cooperative agreement from the start date of the reporting period to the reporting period end date related to the CDBG grant for these sub-programs and must be submitted on a quarterly basis. • In accordance with federal regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if it made an award or supplemental award equal to or greater than $30,000 in April 2025. • Federal regulations [2 CFR 200.303] state that recipients of federal funds must establish and maintain effective internal controls over their federal awards which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Green Book states in Paragraphs 3.09 and 3.10 that management is to develop and maintain documentation of its internal control system, establishing the who, what, when, where, and why of internal control execution to personnel. What problems did the audit work identify? We identified problems in all of the Department’s reports for CDBG that we tested for Fiscal Year 2025. Specifically: • We identified issues in both of the two (100 percent) PR28 performance reports we reviewed. Specifically, we could not tie disbursement amounts for the CDBG program and CDBG-CV sub program totaling approximately $15,000 and $21.7 million, respectively, contained on the two PR28 performance reports to the Department’s accounting records. Additionally, the Department could not provide evidence that Department staff reviewed and approved the reports internally prior to submission to the federal government. • We identified issues in 7 of the 8 (88 percent) Quarterly Performance Reports we reviewed. The following table reflects quarterly amounts expended that could not be tied out for each programmatic report: See "Schedule of Findings and Questioned Costs" for table/chart. *The Department did not submit 4 of the 7 (57 percent) FFATA reports to SAM.gov within the required time period. We specifically noted that the Department submitted these four subawards to SAM.gov after the close of Fiscal Year 2025 in October 2025, which caused them to be out of compliance by up to 14 months. Why did these problems occur? The Department did not have adequate internal controls over its federal reporting processes, such as supervisory review and approval of the PR28 and FFATA reports prior to submission and publication. In addition, the Department failed to maintain adequate records of submissions and accounting support due to a lack of internal monitoring and review processes necessary for tracking report submissions and ensuring reports are submitted timely and are complete. The Department stated that the delay in the submission of the FFATA reports was due to technical difficulties experienced by the Department when the federal government switched from requiring the use of the previous FSRS system to SAM.gov on March 8, 2025. Why do these problems matter? By not providing accurate information to HUD or maintaining support for the Department’s performance reports, it is not meeting federal requirements. Further, the Department may not be addressing CDBG regulatory requirements that are intended to result in an overall benefit to lowand moderate-income persons and an overall benefit to the public. Additionally, inaccurate reporting could result in actual costs exceeding the maximum allowable costs for technical assistance, and overall planning, management and administration. By failing to report the subawards to SAM.gov in a timely manner, as required under FFATA, the Department is out of compliance with federal reporting requirements and risks federal sanctions. Additionally, by not reporting the relevant information—including subrecipient name, subrecipient Data Universal Numbering System number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, subrecipient names, and compensation of highly compensated officers—the Department is failing to meet the federal intent of transparency for federal program spending. Furthermore, the Department not maintaining documentation of the review and approval of its federal reports can lead to a lack of accountability, making it difficult to verify compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-043 The Department of Local Affairs should strengthen its internal controls over federal reporting for its Community Development Block Grant/State’s program and Non-Entitlement Grants in Hawaii, including the Federal Funding Accountability and Transparency Act (FFATA) reporting, and ensure that its reporting meets federal requirements by: A. Ensuring that FFATA reporting occurs as required for subawards of $30,000 or more in the System for Award Management, SAM.gov, by the end of the month following the month the subawards are made. B. Documenting and implementing internal monitoring policies and procedures, including the performance of reconciliations of reports, to ensure that the required Performance and Evaluation Financial Summary Reports (PR28) and Quarterly Performance Reports are accurate and complete. This should include maintaining documentation of evidence of the review and approval of each report prior to its submission to the federal government. Response Department of Local Affairs A. Agree Implementation Date: April 2026 The Department will strengthen its internal controls over federal reporting by implementing policies and procedures that include a monitoring process to ensure that FFATA reporting occurs as required for subawards of $30,000 or more in SAM.gov by the end of the month following the month the subawards are made. B. Agree Implementation Date: April 2026 The Department will document and implement internal monitoring policies and procedures, including the performance of reconciliations of reports, to ensure that the required PR28 and Quarterly Performance Reports are accurate and complete. This will include maintaining documentation of evidence of the review and approval of each report prior to its submission to the federal government.
Show full finding ▾Hide full finding ▴Finding 2025-043 Compliance with Reporting for Community Development Block Grant program The Department administers the federal Community Development Block Grant/State’s program and Non-Entitlement Grants in Hawaii (Community Development Block Grant or CDBG) [ALN 14.228] for non-entitlement municipalities and counties to carry out community development activities. The federal government splits the Department’s CDBG program into sub-programs related to the CARES Act (CDBG-CV), Disaster Recovery (CDBG-DR), and the Neighborhood Stabilization Program (CDBG-NSP). The CARES (Coronavirus Aid, Relief, and Economic Security) Act, enacted March 27, 2020, appropriated $5.0 billion in CDBG-CV funds to be allocated to about 1,250 states, local governments, and insular areas to fund activities to prevent, prepare for, and respond to Coronavirus. CDBG-CV and CDBG grants are a flexible source of funding that can be used to pay costs that are not covered by other sources of assistance, particularly to benefit persons of low and moderate income. The primary objective for CDBG-DR is to provide disaster relief, long-term recovery, restoration of infrastructure and housing, and economic revitalization in the most impacted and distressed areas resulting from a major disaster, declared pursuant to the Robert T. Stafford Disaster Relief and Emergency Assistance Act of 1974. The objectives of the CDBG-NSP are to: (1) stabilize property values, (2) arrest neighborhood decline, (3) assist in preventing neighborhood blight, and (4) stabilize communities across America hardest hit by residential foreclosures and abandonment. These objectives have been achieved through the purchase and redevelopment of foreclosed and abandoned homes and residential properties that allows those properties to turn into useful, safe and sanitary housing. The grants are to be considered CDBG funds. The Department is required to submit financial information electronically to the federal Housing and Urban Development (HUD) Exchange IT system on an annual basis. The Department is required to submit various reports that include the following: • Performance reports titled, Performance and Evaluation Financial Summary Reports (PR28), are required to list all of the financial activity related to the CDBG program and CDBG-CV subprogram. • Quarterly Performance Reports for the CDBG-DR program and CDBG-NSP. The Quarterly Performance Reports include the Department’s activities related to the CDBG grant for these sub-programs on a quarterly basis. The Department is also required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its CDBG awards. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards, including information about amounts passed through to subrecipients, or subawards, given to other governments or nonprofit organizations, available to the public. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. The Department is required to submit FFATA information through the FFATA Subaward Reporting System (formerly FSRS)—the System for Award Management (SAM.gov). Once the Department submits a report to SAM.gov, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department made 25 CDBG subawards to 18 subrecipients totaling $10.2 million that were subject to FFATA reporting. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to identify and review the operational effectiveness of the Department’s internal controls and compliance over the federal reporting process for the CDBG program, and determine whether the reports were prepared and submitted in accordance with state and federal regulations. During our audit, we reviewed two PR28 Performance and Evaluation Financial Summary Reports—one for CDBG overall and one for the CDBG-CV sub-program filed by the Department during Fiscal Year 2025—and the related supporting documentation. We also reviewed eight Quarterly Performance Reports—four reports for each of the CDBG-DR and CDBG-NSP subprograms filed by the Department for Fiscal Year 2025—and the related supporting documentation. Additionally, we received the Department’s sub-awardee report submitted to SAM.gov for FFATA reporting for Fiscal Year 2025 for the CDBG grant and tested 7 of the 25 subawards listed on the report. We used both performance and sub-awardee reports to determine if the financial activity in these reports could be traced to the expenditures recorded within the Colorado Operations Resource Engine (CORE), the State’s accounting system, for the CDBG grant program for Fiscal Year 2025. We also performed testwork to determine if the performance and sub-awardee reports were reviewed and approved internally, submitted in a timely manner, and approved by HUD. How were the results of the audit work measured? For the CDBG program, we measured the results of our audit work against the following requirements: • As noted previously, the Department is required to submit certain financial information electronically to HUD through its HUD Exchange system on an annual basis. HUD requires that the reports be prepared in accordance with Generally Accepted Accounting Principles (GAAP). Per the federal Office of Management and Budget’s (OMB) Compliance Supplement, the various reports that the Department must submit include the following: PR28 Performance and Evaluation Financial Summary Reports for the CDBG program and CDBG-CV sub-program. This report is required to list all of the financial activity related to the CDBG program, such as the overall benefit to low- and moderate-income persons, the maximum allowable costs for administration, technical assistance, and overall planning, management and administration, and must be submitted quarterly, 30 days after the reporting period end date. Quarterly Performance Reports for the CDBG-DR program and CDBG-NSP. The Quarterly Performance Reports must cover all expenditures on the cooperative agreement from the start date of the reporting period to the reporting period end date related to the CDBG grant for these sub-programs and must be submitted on a quarterly basis. • In accordance with federal regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if it made an award or supplemental award equal to or greater than $30,000 in April 2025. • Federal regulations [2 CFR 200.303] state that recipients of federal funds must establish and maintain effective internal controls over their federal awards which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Green Book states in Paragraphs 3.09 and 3.10 that management is to develop and maintain documentation of its internal control system, establishing the who, what, when, where, and why of internal control execution to personnel. What problems did the audit work identify? We identified problems in all of the Department’s reports for CDBG that we tested for Fiscal Year 2025. Specifically: • We identified issues in both of the two (100 percent) PR28 performance reports we reviewed. Specifically, we could not tie disbursement amounts for the CDBG program and CDBG-CV sub program totaling approximately $15,000 and $21.7 million, respectively, contained on the two PR28 performance reports to the Department’s accounting records. Additionally, the Department could not provide evidence that Department staff reviewed and approved the reports internally prior to submission to the federal government. • We identified issues in 7 of the 8 (88 percent) Quarterly Performance Reports we reviewed. The following table reflects quarterly amounts expended that could not be tied out for each programmatic report: See "Schedule of Findings and Questioned Costs" for table/chart. *The Department did not submit 4 of the 7 (57 percent) FFATA reports to SAM.gov within the required time period. We specifically noted that the Department submitted these four subawards to SAM.gov after the close of Fiscal Year 2025 in October 2025, which caused them to be out of compliance by up to 14 months. Why did these problems occur? The Department did not have adequate internal controls over its federal reporting processes, such as supervisory review and approval of the PR28 and FFATA reports prior to submission and publication. In addition, the Department failed to maintain adequate records of submissions and accounting support due to a lack of internal monitoring and review processes necessary for tracking report submissions and ensuring reports are submitted timely and are complete. The Department stated that the delay in the submission of the FFATA reports was due to technical difficulties experienced by the Department when the federal government switched from requiring the use of the previous FSRS system to SAM.gov on March 8, 2025. Why do these problems matter? By not providing accurate information to HUD or maintaining support for the Department’s performance reports, it is not meeting federal requirements. Further, the Department may not be addressing CDBG regulatory requirements that are intended to result in an overall benefit to lowand moderate-income persons and an overall benefit to the public. Additionally, inaccurate reporting could result in actual costs exceeding the maximum allowable costs for technical assistance, and overall planning, management and administration. By failing to report the subawards to SAM.gov in a timely manner, as required under FFATA, the Department is out of compliance with federal reporting requirements and risks federal sanctions. Additionally, by not reporting the relevant information—including subrecipient name, subrecipient Data Universal Numbering System number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, subrecipient names, and compensation of highly compensated officers—the Department is failing to meet the federal intent of transparency for federal program spending. Furthermore, the Department not maintaining documentation of the review and approval of its federal reports can lead to a lack of accountability, making it difficult to verify compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-043 The Department of Local Affairs should strengthen its internal controls over federal reporting for its Community Development Block Grant/State’s program and Non-Entitlement Grants in Hawaii, including the Federal Funding Accountability and Transparency Act (FFATA) reporting, and ensure that its reporting meets federal requirements by: A. Ensuring that FFATA reporting occurs as required for subawards of $30,000 or more in the System for Award Management, SAM.gov, by the end of the month following the month the subawards are made. B. Documenting and implementing internal monitoring policies and procedures, including the performance of reconciliations of reports, to ensure that the required Performance and Evaluation Financial Summary Reports (PR28) and Quarterly Performance Reports are accurate and complete. This should include maintaining documentation of evidence of the review and approval of each report prior to its submission to the federal government. Response Department of Local Affairs A. Agree Implementation Date: April 2026 The Department will strengthen its internal controls over federal reporting by implementing policies and procedures that include a monitoring process to ensure that FFATA reporting occurs as required for subawards of $30,000 or more in SAM.gov by the end of the month following the month the subawards are made. B. Agree Implementation Date: April 2026 The Department will document and implement internal monitoring policies and procedures, including the performance of reconciliations of reports, to ensure that the required PR28 and Quarterly Performance Reports are accurate and complete. This will include maintaining documentation of evidence of the review and approval of each report prior to its submission to the federal government.
The Department will document and implement internal monitoring policies and procedures, including the performance of reconciliations of reports, to ensure that the required PR28 and Quarterly Performance Reports are accurate and complete. This will include maintaining documentation of evidence of the review and approval of each report prior to its submission to the federal government.
Finding 2025-044 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for the Coronavirus Capital Projects Fund The Department administers the federal Coronavirus Capital Projects Fund program (CCPF) [ALN 21.029] for non-entitlement municipalities, counties, and subcontractors to carry out capital development and infrastructure activities related to increasing awareness, education, and monitoring of the Coronavirus emergency by developing broadband infrastructure. Examples of activities related to CCPF include the development of fiber-optic broadband infrastructure and investments in improving broadband infrastructure within a municipality, addressing affordability and access to broadband infrastructure, and the development and improvement of buildings that directly enables work related to the education and monitoring of the Coronavirus emergency. The Department’s accounting section records all financial transactions within CORE and must ensure the accurate reporting of federal award expenditures and reimbursements and maintain adequate supporting documentation related to transactions recorded in CORE. The Department’s accounting section is also responsible for providing information through the submission of exhibits to the Office of the State Controller (OSC) to assist in preparation of the State’s financial statements, required note disclosures, and the State’s Schedule of Expenditures of Federal Awards (SEFA). For Fiscal Year 2025, the Department reported $33.7 million in expenditures for CCPF. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the CCPF payment processes and to determine whether payments were processed and paid in accordance with state regulations and federal “allowable cost” requirements during Fiscal Year 2025. As part of our audit work, we obtained from the Department the Fiscal Year 2025 expenditures listing for CCPF, comprised of eight transactions. We tested five transactions as part of our testing of the Department’s compliance with federal allowable cost requirements for the CCPF program. We also reviewed the Department’s Exhibit K1, Schedule of Federal Assistance, which it submitted to the OSC for Fiscal Year 2025 year-end reporting, and the related supporting documentation, including CORE transaction detail for revenues and expenditures associated with CCPF, to determine whether Department accounting staff prepared the exhibit in accordance with the OSC’s Fiscal Procedures Manual (Manual), and to determine whether the Exhibit K1 was accurate and complete. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to GAAP; not be used for cost sharing of other programs; and be adequately documented. • Federal regulations [2 CFR 200.302] require that recipients must expend and account for the federal award in accordance with State laws and procedures for expending and accounting for the State’s funds. All recipients’ financial management systems, including records documenting compliance with federal statutes, regulations, and the terms and conditions of the federal award, must be sufficient to permit the preparation of reports required by the terms and conditions; and tracking expenditures to establish that funds have been used in accordance with federal statutes, regulations, and the terms and conditions of the federal award. • The OSC’s Manual contains instructions for the completion of exhibits. Specifically, the Exhibit K1 is used to report federal expenditure information to the OSC for inclusion in the State’s SEFA. • Federal regulations [2 CFR 200.303] state that each recipient of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. The OSC has adopted the Green Book as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraphs 3.09 and 3.10, states that management is to develop and maintain documentation of its internal control system, establishing the who, what, when, where, and why of internal control execution to personnel. What problem did the audit work identify? Through our audit testwork, we identified an error with 1 of the 5 expenditures (20 percent) tested. Specifically, the Department recorded the expenditure transaction, which totaled $3,266,662, twice in CORE. Further, because CORE is programmed to automatically record earned federal revenue when a federal expenditure is recorded, the Department also recorded federal revenue in CORE to match the duplicate federal expenditure. As a result, the Department overstated both revenues and expenditures for CCPF by $3,266,662. In addition, the Department overstated its Fiscal Year 2025 CCPF expenditures on its Exhibit K1 by $3,266,662. After we notified Department staff of the errors, they provided a corrected Exhibit K1 to the OSC. The Department passed on correcting the overstated expenditures and revenues in CORE because, based on discussions with the auditors, the amount was not material. Why did this problem occur? The Department lacked sufficient internal controls during Fiscal Year 2025 over its financial management and federal allowable cost compliance requirements for the CCPF program. Specifically, the Department lacked sufficient training over the calculation of its year-end accrued liabilities. The Department incorrectly calculated and recorded the year-end accrual entry in CORE, and lacked adequate internal review processes, including a supervisory review process, to ensure the program’s accrued expenditures—and ultimately amounts reported on the Exhibit K1—were accurate and complete. Why does this problem matter? By failing to have strong internal controls over the recording and monitoring of federal expenditures and revenues, the Department cannot ensure that financial records are accurate, complete, and recorded in a timely manner. Internal review and approval processes reduce the risk of material misstatements affecting federal awards. Additionally, insufficient controls over federal program requirements can lead to a lack of accountability, making it difficult to demonstrate compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. Finally, failing to properly report expenditures of federal funds on its Exhibit K1, if uncorrected, could cause the State’s overall SEFA to be inaccurate and out of compliance with federal regulations. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-044 The Department of Local Affairs should strengthen its internal controls over the financial management of federal Coronavirus Capital Projects Fund grant expenditures by implementing an adequate supervisory review process and training for staff over year-end estimates/accruals to ensure transactions are accurately recorded in the Colorado Operations Resource Engine (CORE), the State’s accounting system; and that the Exhibit K1, Schedule of Federal Assistance, is accurate and complete. Response Department of Local Affairs Agree Implementation Date: April 2026 The Department of Local Affairs (Department) agrees with the recommendation to strengthen internal controls over the financial management of federal Coronavirus Capital Projects Fund grant expenditures and the accuracy and completeness of the Exhibit K1, Schedule of Federal Assistance. The Department will develop a corrective action plan that includes enhanced procedures for the performance of year-end estimates/accruals. The Department will create and implement staff training for staff that are responsible for preparing and reviewing the estimates/accruals, the Exhibit K1, grant transactions and enhancements.
Show full finding ▾Hide full finding ▴Finding 2025-044 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for the Coronavirus Capital Projects Fund The Department administers the federal Coronavirus Capital Projects Fund program (CCPF) [ALN 21.029] for non-entitlement municipalities, counties, and subcontractors to carry out capital development and infrastructure activities related to increasing awareness, education, and monitoring of the Coronavirus emergency by developing broadband infrastructure. Examples of activities related to CCPF include the development of fiber-optic broadband infrastructure and investments in improving broadband infrastructure within a municipality, addressing affordability and access to broadband infrastructure, and the development and improvement of buildings that directly enables work related to the education and monitoring of the Coronavirus emergency. The Department’s accounting section records all financial transactions within CORE and must ensure the accurate reporting of federal award expenditures and reimbursements and maintain adequate supporting documentation related to transactions recorded in CORE. The Department’s accounting section is also responsible for providing information through the submission of exhibits to the Office of the State Controller (OSC) to assist in preparation of the State’s financial statements, required note disclosures, and the State’s Schedule of Expenditures of Federal Awards (SEFA). For Fiscal Year 2025, the Department reported $33.7 million in expenditures for CCPF. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the CCPF payment processes and to determine whether payments were processed and paid in accordance with state regulations and federal “allowable cost” requirements during Fiscal Year 2025. As part of our audit work, we obtained from the Department the Fiscal Year 2025 expenditures listing for CCPF, comprised of eight transactions. We tested five transactions as part of our testing of the Department’s compliance with federal allowable cost requirements for the CCPF program. We also reviewed the Department’s Exhibit K1, Schedule of Federal Assistance, which it submitted to the OSC for Fiscal Year 2025 year-end reporting, and the related supporting documentation, including CORE transaction detail for revenues and expenditures associated with CCPF, to determine whether Department accounting staff prepared the exhibit in accordance with the OSC’s Fiscal Procedures Manual (Manual), and to determine whether the Exhibit K1 was accurate and complete. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to GAAP; not be used for cost sharing of other programs; and be adequately documented. • Federal regulations [2 CFR 200.302] require that recipients must expend and account for the federal award in accordance with State laws and procedures for expending and accounting for the State’s funds. All recipients’ financial management systems, including records documenting compliance with federal statutes, regulations, and the terms and conditions of the federal award, must be sufficient to permit the preparation of reports required by the terms and conditions; and tracking expenditures to establish that funds have been used in accordance with federal statutes, regulations, and the terms and conditions of the federal award. • The OSC’s Manual contains instructions for the completion of exhibits. Specifically, the Exhibit K1 is used to report federal expenditure information to the OSC for inclusion in the State’s SEFA. • Federal regulations [2 CFR 200.303] state that each recipient of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. The OSC has adopted the Green Book as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraphs 3.09 and 3.10, states that management is to develop and maintain documentation of its internal control system, establishing the who, what, when, where, and why of internal control execution to personnel. What problem did the audit work identify? Through our audit testwork, we identified an error with 1 of the 5 expenditures (20 percent) tested. Specifically, the Department recorded the expenditure transaction, which totaled $3,266,662, twice in CORE. Further, because CORE is programmed to automatically record earned federal revenue when a federal expenditure is recorded, the Department also recorded federal revenue in CORE to match the duplicate federal expenditure. As a result, the Department overstated both revenues and expenditures for CCPF by $3,266,662. In addition, the Department overstated its Fiscal Year 2025 CCPF expenditures on its Exhibit K1 by $3,266,662. After we notified Department staff of the errors, they provided a corrected Exhibit K1 to the OSC. The Department passed on correcting the overstated expenditures and revenues in CORE because, based on discussions with the auditors, the amount was not material. Why did this problem occur? The Department lacked sufficient internal controls during Fiscal Year 2025 over its financial management and federal allowable cost compliance requirements for the CCPF program. Specifically, the Department lacked sufficient training over the calculation of its year-end accrued liabilities. The Department incorrectly calculated and recorded the year-end accrual entry in CORE, and lacked adequate internal review processes, including a supervisory review process, to ensure the program’s accrued expenditures—and ultimately amounts reported on the Exhibit K1—were accurate and complete. Why does this problem matter? By failing to have strong internal controls over the recording and monitoring of federal expenditures and revenues, the Department cannot ensure that financial records are accurate, complete, and recorded in a timely manner. Internal review and approval processes reduce the risk of material misstatements affecting federal awards. Additionally, insufficient controls over federal program requirements can lead to a lack of accountability, making it difficult to demonstrate compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. Finally, failing to properly report expenditures of federal funds on its Exhibit K1, if uncorrected, could cause the State’s overall SEFA to be inaccurate and out of compliance with federal regulations. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-044 The Department of Local Affairs should strengthen its internal controls over the financial management of federal Coronavirus Capital Projects Fund grant expenditures by implementing an adequate supervisory review process and training for staff over year-end estimates/accruals to ensure transactions are accurately recorded in the Colorado Operations Resource Engine (CORE), the State’s accounting system; and that the Exhibit K1, Schedule of Federal Assistance, is accurate and complete. Response Department of Local Affairs Agree Implementation Date: April 2026 The Department of Local Affairs (Department) agrees with the recommendation to strengthen internal controls over the financial management of federal Coronavirus Capital Projects Fund grant expenditures and the accuracy and completeness of the Exhibit K1, Schedule of Federal Assistance. The Department will develop a corrective action plan that includes enhanced procedures for the performance of year-end estimates/accruals. The Department will create and implement staff training for staff that are responsible for preparing and reviewing the estimates/accruals, the Exhibit K1, grant transactions and enhancements.
The Department of Local Affairs (Department) agrees with the recommendation to strengthen internal controls over the financial management of federal Coronavirus Capital Projects Fund grant expenditures and the accuracy and completeness of the Exhibit K1, Schedule of Federal Assistance. The Department will develop a corrective action plan that includes enhanced procedures for the performance of year-end estimates/accruals. The Department will create and implement staff training for staff that are responsible for preparing and reviewing the estimates/accruals, the Exhibit K1, grant transactions and enhancements.
Finding 2025-045 Compliance with Reporting for Immunization Cooperative Agreements – FFATA Reporting The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Immunization Cooperative Agreements program [ALN 93.268] (Program). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency. The Department is required to submit FFATA information through the federal government’s System for Award Management website, SAM.gov. Once the Department submits a report to SAM.gov, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department reported $112.0 million in total Program expenditures. Of this amount, the Department issued $15.8 million in subawards under the Program. The Department had 70 subrecipients with subawards for which it was required to submit FFATA information through SAM.gov during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Program during Fiscal Year 2025. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and a list of all subrecipients for the Program during Fiscal Year 2025. We also inquired with Department staff about its internal control processes related to FFATA reporting. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with federal regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if it made an award or supplemental award equal to or greater than $30,000 in April 2025. Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The Department’s policies and procedures related to FFATA reporting state that its grants accountant is responsible for performing monthly FFATA reporting. What problem did the audit work identify? We determined that the Department did not comply with FFATA reporting requirements for the Program during Fiscal Year 2025. Specifically, the Department did not submit any FFATA reports to SAM.gov for the Program’s subawards issued during Fiscal Year 2025 and, as a result, did not report approximately $15.2 million in subawards for Fiscal Year 2025. Why did this problem occur? The Department did not have adequate internal controls over federal reporting requirements in place for the Program during Fiscal Year 2025. Specifically, the Department’s existing policies and procedures were not detailed enough to ensure that FFATA reporting was completed in accordance with federal requirements. The procedures in place designated one individual who was responsible for the FFATA reporting process, but did not include procedures to identify when FFATA reporting was required for subawards or to ensure that appropriate reporting was completed when required. Additionally, the Department’s procedures did not include any secondary review process over FFATA reporting or a process to ensure that FFATA reporting had been completed as required. Why does this problem matter? By failing to properly report FFATA subawards through SAM.gov, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-045 The Department of Public Health and Environment should strengthen its internal controls over, and ensure it complies with, the Federal Funding Accountability and Transparency Act of 2006 (FFATA) reporting requirements for its Immunization Cooperative Agreements program. This should include updating its existing policies and procedures to include a monthly review of all subawards in order to identify those required to be reported each month and a secondary review process of the FFATA reports and submissions to ensure that FFATA reporting has been completed as required. Response Department of Public Health and Environment Agree Implementation Date: July 2026 CDPHE fiscal procedures have been updated to reflect changes to the reporting process, specifically noting the recent federal website change and adding the requirement of a secondary level of review. By July 31, 2026, all outstanding FFATA reports will be filed with the federal government and the monthly review process in the updated fiscal procedures will be implemented.
Show full finding ▾Hide full finding ▴Finding 2025-045 Compliance with Reporting for Immunization Cooperative Agreements – FFATA Reporting The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Immunization Cooperative Agreements program [ALN 93.268] (Program). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency. The Department is required to submit FFATA information through the federal government’s System for Award Management website, SAM.gov. Once the Department submits a report to SAM.gov, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department reported $112.0 million in total Program expenditures. Of this amount, the Department issued $15.8 million in subawards under the Program. The Department had 70 subrecipients with subawards for which it was required to submit FFATA information through SAM.gov during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Program during Fiscal Year 2025. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and a list of all subrecipients for the Program during Fiscal Year 2025. We also inquired with Department staff about its internal control processes related to FFATA reporting. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with federal regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if it made an award or supplemental award equal to or greater than $30,000 in April 2025. Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The Department’s policies and procedures related to FFATA reporting state that its grants accountant is responsible for performing monthly FFATA reporting. What problem did the audit work identify? We determined that the Department did not comply with FFATA reporting requirements for the Program during Fiscal Year 2025. Specifically, the Department did not submit any FFATA reports to SAM.gov for the Program’s subawards issued during Fiscal Year 2025 and, as a result, did not report approximately $15.2 million in subawards for Fiscal Year 2025. Why did this problem occur? The Department did not have adequate internal controls over federal reporting requirements in place for the Program during Fiscal Year 2025. Specifically, the Department’s existing policies and procedures were not detailed enough to ensure that FFATA reporting was completed in accordance with federal requirements. The procedures in place designated one individual who was responsible for the FFATA reporting process, but did not include procedures to identify when FFATA reporting was required for subawards or to ensure that appropriate reporting was completed when required. Additionally, the Department’s procedures did not include any secondary review process over FFATA reporting or a process to ensure that FFATA reporting had been completed as required. Why does this problem matter? By failing to properly report FFATA subawards through SAM.gov, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-045 The Department of Public Health and Environment should strengthen its internal controls over, and ensure it complies with, the Federal Funding Accountability and Transparency Act of 2006 (FFATA) reporting requirements for its Immunization Cooperative Agreements program. This should include updating its existing policies and procedures to include a monthly review of all subawards in order to identify those required to be reported each month and a secondary review process of the FFATA reports and submissions to ensure that FFATA reporting has been completed as required. Response Department of Public Health and Environment Agree Implementation Date: July 2026 CDPHE fiscal procedures have been updated to reflect changes to the reporting process, specifically noting the recent federal website change and adding the requirement of a secondary level of review. By July 31, 2026, all outstanding FFATA reports will be filed with the federal government and the monthly review process in the updated fiscal procedures will be implemented.
CDPHE fiscal procedures have been updated to reflect changes to the reporting process, specifically noting the recent federal website change and adding the requirement of a secondary level of review. By July 31, 2026, all outstanding FFATA reports will be filed with the federal government and the monthly review process in the updated fiscal procedures will be implemented.
Finding 2025-046 Compliance with Subrecipient Monitoring for Disaster Grants The Federal Emergency Management Agency (FEMA) Disaster Grants program [ALN 97.036] provides supplemental assistance to recipients to assist communities with responding to and recovering from major disasters or emergencies. The program also provides funding for hazard mitigation measures to help communities implement hazard mitigation projects that can protect them from future disasters. The Disaster Grants program is based on a partnership between FEMA, the recipient (in this case, the Department), and, as applicable, the subrecipient (local governments). FEMA is responsible for managing the Disaster Grants program, approving grants, and providing technical assistance to the state, local, tribal, and territorial governments. The Department, as a recipient of Disaster Grants program funds, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. A subrecipient is defined in federal regulations [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity (such as the Department) to an entity (subrecipient) to carry out part of a federal grant award received by the pass-through entity. Specifically for this program, the subrecipient is expected to request assistance, as needed; identify the damaged facilities; provide information to support its funding requests; maintain accurate documentation; and perform other work, as necessary. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its subrecipient monitoring activities. The risk assessment should include considerations of financial risk factors, such as financial implications of operational and compliance failures; operational risk factors, such as risks resulting from inadequate internal controls; and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient underwent a Single Audit, if applicable, and whether that audit has been reviewed by Department staff and any resulting management decisions issued by those staff to the subrecipient, if applicable, that address the Department’s assessment and planned actions to address any findings or issues identified in the audit During Fiscal Year 2025, the Department passed approximately $76.0 million to 66 subrecipients for responses to various disasters covered by the Department’s Disaster Grants program. In addition, the Department reported that it approved no new subawards during Fiscal Year 2025. All funds passed through to subrecipients by the Department were related to reimbursements for prior period expenses. In total, the Department reported that it had passed through Disaster Grant funding to another 68 subrecipients in prior years who did not receive funding passed through from the Department during Fiscal Year 2025; many of these subrecipients had multiple open projects that had been completed in prior years but were awaiting final approval and close-out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over, and complied with, subrecipient monitoring requirements over the Disaster Grants program during Fiscal Year 2025. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendation to review all subrecipients’ federally-required Single Audit reports, as required. The Department agreed with the recommendation and planned to implement it by June 2025. As part of our audit work, we performed testwork to determine whether the Department obtained its subrecipients’ Single Audit reports and issued a management decision, if applicable. We also determined whether the Department performed risk assessments on the subrecipients as required by federal regulations. Finally, we performed this testing over a random sample of 9 of 68 subrecipients that received pass-through funding in the current year. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.332] require the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate level of subrecipient monitoring based on the Department’s assessment of risk posed by the subrecipients. Additionally, it requires the Department to verify that every subrecipient is audited as required by 2 CFR 200, Subpart F, Audit Requirements, which sets forth the federal regulations around Single Audit threshold requirements for subrecipients. It also covers the federal regulations to consider whether the results of the subrecipient’s audits indicates conditions that necessitate adjustment to the passthrough entity’s—in this case, the Department’s—own records. Further, federal regulations [2 CFR 200.521] require the Department to issue a management decision, which is defined as the Department’s written determination of the adequacy of the subrecipient’s proposed corrective action to address any findings in the subrecipient’s Single Audit reports within 6 months of the federal audit clearinghouse’s acceptance of the audit report. • The Department’s Division of Homeland Security and Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that it “…will perform an annual evaluation of Subrecipient’s risks prior to the start of each State fiscal year, analyzing active awards and assessing Subrecipients for the upcoming year to determine the financial status of each Subrecipient and which subrecipients will receive on-site monitoring which may include desk reviews.” The policy further goes on to indicate that each subrecipient will receive an overall risk score that is used to determine which subrecipients will undergo monitoring review during the fiscal year based on the quantitative and qualitative data used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy also states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” • Federal regulations [2 CFR 200.329] stipulate that the non-federal award recipient—in this case the Department—is responsible for oversight of the operations of its federal award-supported activities. The regulations further state that the “non-federal entity” must monitor its activities under federal awards to assure that compliance with applicable federal requirements and performance expectations is being achieved. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully implement our prior audit recommendation by its planned implementation date of June 30, 2025, and did not complete required subrecipient monitoring activities for its Disaster Grants program. Specifically, we found that the Department did update the risk assessment policies for the 2025 risk assessment and fully assessed risks for subrecipients for Fiscal Year 2025. However, there was one subrecipient that had not yet issued a finalized audit report and, therefore, the Department’s subrecipient monitoring process was pending completion. Why did these problems occur? Although the Department designated staff to obtain and review Single Audit reports for all of its subrecipients, Department staff stated that they were not able to complete their reviews of previously unreviewed Single Audit reports during Fiscal Year 2025, as letters were still being processed for execution and distribution under the updated policies. The Department also subsequently stated that some of these reviews were incomplete due to the subrecipients not yet finalizing their Single Audits with their auditors. Why do these problems matter? By failing to complete all of its reviews of subrecipients’ Single Audit reports, the Department is out of compliance with both federal requirements and with its policy to complete monitoring reviews for each subrecipient. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions, as applicable, to its monitoring risk assessment for the subrecipient. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-046 The Department of Public Safety (Department) should continue to implement its subrecipient monitoring policy and ensure the Department is in compliance with federal regulations to review all subrecipients’ Single Audit reports in a timely manner. This should also include the Department completing its reviews of the subrecipients’ prior year’s Single Audit reports and issuing the management decision letters for those reports. Response Department of Public Safety Agree Implementation Date: June 2026 The Department will continue to follow the current Policy and Procedure related to the Single Audit reviews and has allocated an individual to review the Single Audits. This includes issuing a management decision letter if required, in accordance with the timeline established in federal guidance.
Show full finding ▾Hide full finding ▴Finding 2025-046 Compliance with Subrecipient Monitoring for Disaster Grants The Federal Emergency Management Agency (FEMA) Disaster Grants program [ALN 97.036] provides supplemental assistance to recipients to assist communities with responding to and recovering from major disasters or emergencies. The program also provides funding for hazard mitigation measures to help communities implement hazard mitigation projects that can protect them from future disasters. The Disaster Grants program is based on a partnership between FEMA, the recipient (in this case, the Department), and, as applicable, the subrecipient (local governments). FEMA is responsible for managing the Disaster Grants program, approving grants, and providing technical assistance to the state, local, tribal, and territorial governments. The Department, as a recipient of Disaster Grants program funds, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. A subrecipient is defined in federal regulations [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity (such as the Department) to an entity (subrecipient) to carry out part of a federal grant award received by the pass-through entity. Specifically for this program, the subrecipient is expected to request assistance, as needed; identify the damaged facilities; provide information to support its funding requests; maintain accurate documentation; and perform other work, as necessary. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its subrecipient monitoring activities. The risk assessment should include considerations of financial risk factors, such as financial implications of operational and compliance failures; operational risk factors, such as risks resulting from inadequate internal controls; and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient underwent a Single Audit, if applicable, and whether that audit has been reviewed by Department staff and any resulting management decisions issued by those staff to the subrecipient, if applicable, that address the Department’s assessment and planned actions to address any findings or issues identified in the audit During Fiscal Year 2025, the Department passed approximately $76.0 million to 66 subrecipients for responses to various disasters covered by the Department’s Disaster Grants program. In addition, the Department reported that it approved no new subawards during Fiscal Year 2025. All funds passed through to subrecipients by the Department were related to reimbursements for prior period expenses. In total, the Department reported that it had passed through Disaster Grant funding to another 68 subrecipients in prior years who did not receive funding passed through from the Department during Fiscal Year 2025; many of these subrecipients had multiple open projects that had been completed in prior years but were awaiting final approval and close-out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over, and complied with, subrecipient monitoring requirements over the Disaster Grants program during Fiscal Year 2025. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendation to review all subrecipients’ federally-required Single Audit reports, as required. The Department agreed with the recommendation and planned to implement it by June 2025. As part of our audit work, we performed testwork to determine whether the Department obtained its subrecipients’ Single Audit reports and issued a management decision, if applicable. We also determined whether the Department performed risk assessments on the subrecipients as required by federal regulations. Finally, we performed this testing over a random sample of 9 of 68 subrecipients that received pass-through funding in the current year. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.332] require the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate level of subrecipient monitoring based on the Department’s assessment of risk posed by the subrecipients. Additionally, it requires the Department to verify that every subrecipient is audited as required by 2 CFR 200, Subpart F, Audit Requirements, which sets forth the federal regulations around Single Audit threshold requirements for subrecipients. It also covers the federal regulations to consider whether the results of the subrecipient’s audits indicates conditions that necessitate adjustment to the passthrough entity’s—in this case, the Department’s—own records. Further, federal regulations [2 CFR 200.521] require the Department to issue a management decision, which is defined as the Department’s written determination of the adequacy of the subrecipient’s proposed corrective action to address any findings in the subrecipient’s Single Audit reports within 6 months of the federal audit clearinghouse’s acceptance of the audit report. • The Department’s Division of Homeland Security and Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that it “…will perform an annual evaluation of Subrecipient’s risks prior to the start of each State fiscal year, analyzing active awards and assessing Subrecipients for the upcoming year to determine the financial status of each Subrecipient and which subrecipients will receive on-site monitoring which may include desk reviews.” The policy further goes on to indicate that each subrecipient will receive an overall risk score that is used to determine which subrecipients will undergo monitoring review during the fiscal year based on the quantitative and qualitative data used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy also states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” • Federal regulations [2 CFR 200.329] stipulate that the non-federal award recipient—in this case the Department—is responsible for oversight of the operations of its federal award-supported activities. The regulations further state that the “non-federal entity” must monitor its activities under federal awards to assure that compliance with applicable federal requirements and performance expectations is being achieved. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully implement our prior audit recommendation by its planned implementation date of June 30, 2025, and did not complete required subrecipient monitoring activities for its Disaster Grants program. Specifically, we found that the Department did update the risk assessment policies for the 2025 risk assessment and fully assessed risks for subrecipients for Fiscal Year 2025. However, there was one subrecipient that had not yet issued a finalized audit report and, therefore, the Department’s subrecipient monitoring process was pending completion. Why did these problems occur? Although the Department designated staff to obtain and review Single Audit reports for all of its subrecipients, Department staff stated that they were not able to complete their reviews of previously unreviewed Single Audit reports during Fiscal Year 2025, as letters were still being processed for execution and distribution under the updated policies. The Department also subsequently stated that some of these reviews were incomplete due to the subrecipients not yet finalizing their Single Audits with their auditors. Why do these problems matter? By failing to complete all of its reviews of subrecipients’ Single Audit reports, the Department is out of compliance with both federal requirements and with its policy to complete monitoring reviews for each subrecipient. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions, as applicable, to its monitoring risk assessment for the subrecipient. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-046 The Department of Public Safety (Department) should continue to implement its subrecipient monitoring policy and ensure the Department is in compliance with federal regulations to review all subrecipients’ Single Audit reports in a timely manner. This should also include the Department completing its reviews of the subrecipients’ prior year’s Single Audit reports and issuing the management decision letters for those reports. Response Department of Public Safety Agree Implementation Date: June 2026 The Department will continue to follow the current Policy and Procedure related to the Single Audit reviews and has allocated an individual to review the Single Audits. This includes issuing a management decision letter if required, in accordance with the timeline established in federal guidance.
The Department will continue to follow the current Policy and Procedure related to the Single Audit reviews and has allocated an individual to review the Single Audits. This includes issuing a management decision letter if required, in accordance with the timeline established in federal guidance.
2024-054
Finding 2025-047 Compliance with Reporting for the Highway Safety Cluster The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Highway Safety Cluster programs, specifically the State and Community Highway Safety [ALN 20.600] and National Priority Safety Programs [ALN 20.616] (Programs). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. The Department is required to file FFATA reports through the System for Award Management website, SAM.gov. Once the Department submits a report to SAM.gov, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department reported approximately $12.9 million in total for the Programs’ expenditures. Of this amount, the Department issued about $6.8 million in subawards under the Programs. The Department had 70 subrecipients with subawards it was required to submit FFATA information for through SAM.gov during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Highway Safety Cluster Programs during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations to strengthen its internal controls over and to ensure it complies with FFATA reporting requirements for the Highway Safety Cluster Programs. The Department agreed with these recommendations and planned to implement them by June 2025. As part of our audit work, we selected 24 Fiscal Year 2025 subrecipient expenditure transactions out of a total of 70 subrecipient transactions for which FFATA reporting was required for these Programs. We obtained copies of the FFATA reports that the Department uploaded to SAM.gov and obtained subaward agreements and purchase orders for each sample. We compared the Department’s subaward information to the information the Department submitted to SAM.gov to determine whether the Department reported accurate information. In addition, we performed testwork to determine whether the Department submitted the FFATA reports within the month following the month it made the subaward, as required by federal regulations. We also tested the Department’s progress in implementing our prior audit recommendations by reviewing their updated policies and procedures. How were the results of the audit work measured? We measured the results of our audit work against the following: • Federal regulations [2 CFR 170] require direct recipients of federal grants to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if an award or supplemental award equal to or greater than $30,000 was made in April 2025. Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the unique entity identifier, the Assistance Listing Number, the federal award date, and the federal award identification number. What problem did the audit work identify? Based on our audit work, we determined that the Department did not fully comply with FFATA reporting requirements for the Programs during Fiscal Year 2025 and did not fully implement our prior audit recommendations. Of the 24 subaward reports selected for testing, we identified issues on 5 subaward reports (21 percent). Specifically, we identified the following issues: • The Department was unable to provide documentation demonstrating that two subaward FFATA reports related to Fiscal Year 2024 awards had been submitted in SAM.gov. These submissions could not be located in SAM.gov. The amount of the subawards not submitted was $375,553. We further noted that these two reports had still not been submitted during Fiscal Year 2025. • For three subawards totaling $771,258, the Department did not maintain adequate documentation to support the amounts reported in SAM.gov. Specifically, the Department reported amounts of $537,573 for the three subawards, which did not agree to the Department’s subaward records, and represented a difference of $233,684. In addition, the Department did not meet the required FFATA reporting timelines for these subawards. Specifically, one subaward was reported 271 days late and two were reported 301 days late. Why did this problem occur? The Department did not have adequate internal controls in place related to FFATA reporting for the Highway Safety Cluster during Fiscal Year 2025 that ensured that reporting occurred as required for subawards of $30,000 or more in SAM.gov by the end of the month following the month the subawards are made. The Department implemented policies and procedures related to FFATA reporting during the fiscal year; however, Department staff indicated that staff were still being trained on these new procedures. In addition, the Department did not have procedures in place to ensure that, when an unsubmitted FFATA report is identified, the report is subsequently filed in SAM.gov, even if the submission is late. Why does this problem matter? By failing to properly report FFATA subawards through SAM.gov, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-047 The Department of Transportation (Department) should strengthen its internal controls over and ensure it complies with Federal Funding Accountability and Transparency Act (FFATA) reporting requirements for the Highway Safety Cluster by: A. Ensuring that FFATA reporting occurs as required for subawards of $30,000 or more by the end of the month following the month the subawards are made and, if an unsubmitted FFATA report is identified, subsequently filing the report as soon as possible through SAM.gov, even if the submission is late. B. Providing training to Department staff to follow FFATA reporting policies and procedures. C. Ensuring Department staff follow the Department’s FFATA policies and procedures to ensure that FFATA reports are accurate and complete. Response Department of Transportation A. Agree Implementation Date: June 2026 The Department agrees with the recommendation. The Department will review, assess, and, where necessary, update existing procedures for FFATA reporting relating to the requirement that state subawards for $30,000+ be submitted within 30 days of committed budget. This will include ensuring that the confirmation date is documented. This process will be a coordinated effort between the Office Transportation Safety (OTS) and the Center for Accounting. This will include updating our reconciliation process to include additional data, reviewing and updating reconciliation and review procedures as needed, and reconciling Grants awarded in prior fiscal years that are still active and ensuring they have been appropriately reported. The findings related to this recommendation are in part the result of a federal reporting system limitation, and a federal system conversion. The legacy reporting system, FSRS, had a system limitation, which prevented the full amount of the award being reported in the case of three awards. Additionally, this conversion resulted in some data conversion issues impacting one additional award B. Agree Implementation Date: June 2026 The Department agrees with this finding and will provide any training needed to staff members to ensure that all components of the FFATA are completed accurately, timely and with proper reviews. This training will include leadership reviewing NHTSA/Federal guidelines and SAM.Gov training on FFATA reporting and requirements, documenting controls and ensuring the approvers have access to all supporting schedules, forms and systems and that they understand the subawards, and process for late submissions if needed. C. Agree Implementation Date: June 2026 The Department agrees with the finding and will ensure that staff follow all internal policies and procedures to maintain accurate and complete FFATA reporting. To achieve this, staff will review existing procedures and make any necessary updates regarding report compilation. Additionally, we will review control points to ensure they are consistently followed and approved by the team supervisor or team manager.
Show full finding ▾Hide full finding ▴Finding 2025-047 Compliance with Reporting for the Highway Safety Cluster The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Highway Safety Cluster programs, specifically the State and Community Highway Safety [ALN 20.600] and National Priority Safety Programs [ALN 20.616] (Programs). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. The Department is required to file FFATA reports through the System for Award Management website, SAM.gov. Once the Department submits a report to SAM.gov, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department reported approximately $12.9 million in total for the Programs’ expenditures. Of this amount, the Department issued about $6.8 million in subawards under the Programs. The Department had 70 subrecipients with subawards it was required to submit FFATA information for through SAM.gov during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Highway Safety Cluster Programs during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations to strengthen its internal controls over and to ensure it complies with FFATA reporting requirements for the Highway Safety Cluster Programs. The Department agreed with these recommendations and planned to implement them by June 2025. As part of our audit work, we selected 24 Fiscal Year 2025 subrecipient expenditure transactions out of a total of 70 subrecipient transactions for which FFATA reporting was required for these Programs. We obtained copies of the FFATA reports that the Department uploaded to SAM.gov and obtained subaward agreements and purchase orders for each sample. We compared the Department’s subaward information to the information the Department submitted to SAM.gov to determine whether the Department reported accurate information. In addition, we performed testwork to determine whether the Department submitted the FFATA reports within the month following the month it made the subaward, as required by federal regulations. We also tested the Department’s progress in implementing our prior audit recommendations by reviewing their updated policies and procedures. How were the results of the audit work measured? We measured the results of our audit work against the following: • Federal regulations [2 CFR 170] require direct recipients of federal grants to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if an award or supplemental award equal to or greater than $30,000 was made in April 2025. Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the unique entity identifier, the Assistance Listing Number, the federal award date, and the federal award identification number. What problem did the audit work identify? Based on our audit work, we determined that the Department did not fully comply with FFATA reporting requirements for the Programs during Fiscal Year 2025 and did not fully implement our prior audit recommendations. Of the 24 subaward reports selected for testing, we identified issues on 5 subaward reports (21 percent). Specifically, we identified the following issues: • The Department was unable to provide documentation demonstrating that two subaward FFATA reports related to Fiscal Year 2024 awards had been submitted in SAM.gov. These submissions could not be located in SAM.gov. The amount of the subawards not submitted was $375,553. We further noted that these two reports had still not been submitted during Fiscal Year 2025. • For three subawards totaling $771,258, the Department did not maintain adequate documentation to support the amounts reported in SAM.gov. Specifically, the Department reported amounts of $537,573 for the three subawards, which did not agree to the Department’s subaward records, and represented a difference of $233,684. In addition, the Department did not meet the required FFATA reporting timelines for these subawards. Specifically, one subaward was reported 271 days late and two were reported 301 days late. Why did this problem occur? The Department did not have adequate internal controls in place related to FFATA reporting for the Highway Safety Cluster during Fiscal Year 2025 that ensured that reporting occurred as required for subawards of $30,000 or more in SAM.gov by the end of the month following the month the subawards are made. The Department implemented policies and procedures related to FFATA reporting during the fiscal year; however, Department staff indicated that staff were still being trained on these new procedures. In addition, the Department did not have procedures in place to ensure that, when an unsubmitted FFATA report is identified, the report is subsequently filed in SAM.gov, even if the submission is late. Why does this problem matter? By failing to properly report FFATA subawards through SAM.gov, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-047 The Department of Transportation (Department) should strengthen its internal controls over and ensure it complies with Federal Funding Accountability and Transparency Act (FFATA) reporting requirements for the Highway Safety Cluster by: A. Ensuring that FFATA reporting occurs as required for subawards of $30,000 or more by the end of the month following the month the subawards are made and, if an unsubmitted FFATA report is identified, subsequently filing the report as soon as possible through SAM.gov, even if the submission is late. B. Providing training to Department staff to follow FFATA reporting policies and procedures. C. Ensuring Department staff follow the Department’s FFATA policies and procedures to ensure that FFATA reports are accurate and complete. Response Department of Transportation A. Agree Implementation Date: June 2026 The Department agrees with the recommendation. The Department will review, assess, and, where necessary, update existing procedures for FFATA reporting relating to the requirement that state subawards for $30,000+ be submitted within 30 days of committed budget. This will include ensuring that the confirmation date is documented. This process will be a coordinated effort between the Office Transportation Safety (OTS) and the Center for Accounting. This will include updating our reconciliation process to include additional data, reviewing and updating reconciliation and review procedures as needed, and reconciling Grants awarded in prior fiscal years that are still active and ensuring they have been appropriately reported. The findings related to this recommendation are in part the result of a federal reporting system limitation, and a federal system conversion. The legacy reporting system, FSRS, had a system limitation, which prevented the full amount of the award being reported in the case of three awards. Additionally, this conversion resulted in some data conversion issues impacting one additional award B. Agree Implementation Date: June 2026 The Department agrees with this finding and will provide any training needed to staff members to ensure that all components of the FFATA are completed accurately, timely and with proper reviews. This training will include leadership reviewing NHTSA/Federal guidelines and SAM.Gov training on FFATA reporting and requirements, documenting controls and ensuring the approvers have access to all supporting schedules, forms and systems and that they understand the subawards, and process for late submissions if needed. C. Agree Implementation Date: June 2026 The Department agrees with the finding and will ensure that staff follow all internal policies and procedures to maintain accurate and complete FFATA reporting. To achieve this, staff will review existing procedures and make any necessary updates regarding report compilation. Additionally, we will review control points to ensure they are consistently followed and approved by the team supervisor or team manager.
The Department agrees with the finding and will ensure that staff follow all internal policies and procedures to maintain accurate and complete FFATA reporting. To achieve this, staff will review existing procedures and make any necessary updates regarding report compilation. Additionally, we will review control points to ensure they are consistently followed and approved by the team supervisor and team manager.
2024-056
Finding 2025-048 Compliance with Period of Performance for the Highway Safety Cluster The objective of the federal National Highway Traffic Safety Administration’s Highway Traffic Safety Grant Programs (Highway Safety Cluster) is to provide a coordinated national highway safety program to reduce traffic crashes, deaths, injuries, and property damage. Non-federal entities apply for federal Highway Safety Cluster funds to add or improve safety features on highways and roads around the country. A condition of receiving these federal dollars is that the recipient must comply with various rules on how and when the money can be spent. The recipient must also establish and maintain effective internal controls to ensure compliance with federal statutes, regulations, and the terms and conditions of the federal award. One of these requirements is that the Department must spend the funds within the period of performance identified in the grant award. For Fiscal Year 2025, the periods of performance for the Department’s grant awards for this program were each 4-year periods, as follows: October 1, 2022 through September 30, 2026; October 1, 2023 through September 30, 2027; and October 1, 2024 through September 30, 2028; depending on the year of grant funding. The Department requires a minimum of two staff that are a different reviewer and approver for all costs charged to the grant. Expenditures charged to the grant are reviewed and entered into the Department’s enterprise resource planning system, Systems, Applications, and Products in Data Processing (SAP), by grant coordinators, and then reviewed and approved by the Department’s headquarters business office staff. Grant coordinators that provide a first-level review of the grant expenditures entered into SAP and the Department’s headquarters business office staff should all be knowledgeable in allowable costs and period of performance requirements for the Highway Safety Cluster. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether: the Department had adequate internal controls over federal period of performance requirements for the Highway Safety Cluster; the Department recorded Highway Safety Cluster expenditures during the approved period of performance for the Highway Safety Cluster during Fiscal Year 2025; and costs were allowable under the grant. As part of our audit work, we selected all seven expenditure transactions charged to the Highway Safety Cluster grant during the first 30 calendar days of the period of performance for the four grant awards in place during Fiscal Year 2025. For example, for the Fiscal Year 2025 grant awards, the beginning date of the period of performance was October 1, 2024, so we reviewed expenditures charged to the grant from October 1 through October 30, 2024. We reviewed the Department’s supporting documentation to support the date each expense was incurred and evidence of internal controls related to approval of the expense. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations to: • Enforce its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include monitoring to ensure that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance; adjustments should be made for any expenditures charged to an award outside the proper period of performance. • Provide additional training to Department personnel on period of performance compliance requirements. The Department agreed with these recommendations and planned to implement them by June 2025. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.308, 200.309, and 200.403(h)] state that a non-federal entity may charge only allowable costs incurred during the approved budget period of a federal award’s period of performance and any costs incurred before the federal awarding agency or passthrough entity made the federal award that were authorized by the federal awarding agency or pass-through entity. A period of performance may contain one or more budget periods. A budget period represents the specific time frame approved by the federal awarding agency for using grant funds. • The Department’s internal control procedures over federal expenditure approval and processing require that all federal grant expenditures must have adequate supporting documentation, such as an invoice, purchase order, or reimbursement request, included with the transaction and the supporting documentation must be reviewed for allowability under the applicable federal grant program by two individuals. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully comply with the period of performance requirements for the Highway Safety Cluster during Fiscal Year 2025 and did not fully implement our prior audit recommendations. Based on our audit testwork, 2 of the 7 transactions selected for testing (29 percent) had expenses recorded to the grant that were incurred outside the period of performance; each expense was incurred one day prior to the start of the period of performance. We further verified with the Department that the expenditures were not specifically authorized by the federal awarding agency to be charged to the grant. These errors resulted in questioned costs totaling $347. Why did these problems occur? This problem occurred because the Department’s internal controls were not operating effectively to ensure that expenditures charged to the Highway Safety Cluster were incurred within the award’s period of performance. Specifically, the Department’s reviewers of the transactions for which the problems occurred did not ensure the transactions were fully within the period of performance. Both transactions related to employee reimbursements of travel expenses for the period September 30, 2024 through October 4, 2024. The Department’s reviewers did not identify that the expenses for September 30, 2024 should have been charged to a different grant award, and the Department did not split the invoice into two transactions to allocate the expenses to the appropriate grant award based on the period of performance of those grant awards. Department personnel did not appear to be sufficiently trained on the Highway Safety Cluster’s period of performance compliance requirements. Why do these problems matter? By failing to properly record expenditures to the Highway Safety Cluster within the grant award’s period of performance, the Department risks its costs being deemed unallowable by the federal awarding agency. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-048 The Department of Transportation (Department) should ensure that it complies with federal Highway Safety Cluster grant period of performance requirements by: A. Enforcing its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include ensuring that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance and making adjustments for any expenditures charged to an award outside the proper period of performance. B. Providing training to Department personnel to ensure that staff understand and can apply the period of performance requirements. Response Department of Transportation A. Agree Implementation Date: April 2026 The Department agrees with the recommendation. The Center for Accounting (CFA) and the Office of Transportation Safety (OTS) have coordinated to implement updated reviews and controls. This implementation involves reviewing current processes to ensure supporting documentation is vetted and grant compliance is verified prior to payment. It also includes assessing the need for increased monitoring to ensure initial program reviews are complete and accurate. This remediation effort was finalized on June 30, 2025, following the September 2024 transaction in question. Additionally, the Department plans to review the remediation plan with all relevant staff again this season. This will ensure that all supporting documentation is thoroughly vetted and that expenditures comply with the applicable award period of performance B. Agree Implementation Date: April 2026 The Colorado Department of Transportation (CDOT) agrees with the recommendation. The Center for Accounting (CFA) and the Office of Transportation Safety (OTS) have coordinated on its implementation. The Department has assessed and updated training for staff responsible for reviewing and approving invoices for Highway Safety Cluster grants, with a specific focus on the period of performance. This training plan will be revisited and reviewed with all staff involved by April 2026.
Show full finding ▾Hide full finding ▴Finding 2025-048 Compliance with Period of Performance for the Highway Safety Cluster The objective of the federal National Highway Traffic Safety Administration’s Highway Traffic Safety Grant Programs (Highway Safety Cluster) is to provide a coordinated national highway safety program to reduce traffic crashes, deaths, injuries, and property damage. Non-federal entities apply for federal Highway Safety Cluster funds to add or improve safety features on highways and roads around the country. A condition of receiving these federal dollars is that the recipient must comply with various rules on how and when the money can be spent. The recipient must also establish and maintain effective internal controls to ensure compliance with federal statutes, regulations, and the terms and conditions of the federal award. One of these requirements is that the Department must spend the funds within the period of performance identified in the grant award. For Fiscal Year 2025, the periods of performance for the Department’s grant awards for this program were each 4-year periods, as follows: October 1, 2022 through September 30, 2026; October 1, 2023 through September 30, 2027; and October 1, 2024 through September 30, 2028; depending on the year of grant funding. The Department requires a minimum of two staff that are a different reviewer and approver for all costs charged to the grant. Expenditures charged to the grant are reviewed and entered into the Department’s enterprise resource planning system, Systems, Applications, and Products in Data Processing (SAP), by grant coordinators, and then reviewed and approved by the Department’s headquarters business office staff. Grant coordinators that provide a first-level review of the grant expenditures entered into SAP and the Department’s headquarters business office staff should all be knowledgeable in allowable costs and period of performance requirements for the Highway Safety Cluster. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether: the Department had adequate internal controls over federal period of performance requirements for the Highway Safety Cluster; the Department recorded Highway Safety Cluster expenditures during the approved period of performance for the Highway Safety Cluster during Fiscal Year 2025; and costs were allowable under the grant. As part of our audit work, we selected all seven expenditure transactions charged to the Highway Safety Cluster grant during the first 30 calendar days of the period of performance for the four grant awards in place during Fiscal Year 2025. For example, for the Fiscal Year 2025 grant awards, the beginning date of the period of performance was October 1, 2024, so we reviewed expenditures charged to the grant from October 1 through October 30, 2024. We reviewed the Department’s supporting documentation to support the date each expense was incurred and evidence of internal controls related to approval of the expense. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations to: • Enforce its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include monitoring to ensure that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance; adjustments should be made for any expenditures charged to an award outside the proper period of performance. • Provide additional training to Department personnel on period of performance compliance requirements. The Department agreed with these recommendations and planned to implement them by June 2025. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.308, 200.309, and 200.403(h)] state that a non-federal entity may charge only allowable costs incurred during the approved budget period of a federal award’s period of performance and any costs incurred before the federal awarding agency or passthrough entity made the federal award that were authorized by the federal awarding agency or pass-through entity. A period of performance may contain one or more budget periods. A budget period represents the specific time frame approved by the federal awarding agency for using grant funds. • The Department’s internal control procedures over federal expenditure approval and processing require that all federal grant expenditures must have adequate supporting documentation, such as an invoice, purchase order, or reimbursement request, included with the transaction and the supporting documentation must be reviewed for allowability under the applicable federal grant program by two individuals. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully comply with the period of performance requirements for the Highway Safety Cluster during Fiscal Year 2025 and did not fully implement our prior audit recommendations. Based on our audit testwork, 2 of the 7 transactions selected for testing (29 percent) had expenses recorded to the grant that were incurred outside the period of performance; each expense was incurred one day prior to the start of the period of performance. We further verified with the Department that the expenditures were not specifically authorized by the federal awarding agency to be charged to the grant. These errors resulted in questioned costs totaling $347. Why did these problems occur? This problem occurred because the Department’s internal controls were not operating effectively to ensure that expenditures charged to the Highway Safety Cluster were incurred within the award’s period of performance. Specifically, the Department’s reviewers of the transactions for which the problems occurred did not ensure the transactions were fully within the period of performance. Both transactions related to employee reimbursements of travel expenses for the period September 30, 2024 through October 4, 2024. The Department’s reviewers did not identify that the expenses for September 30, 2024 should have been charged to a different grant award, and the Department did not split the invoice into two transactions to allocate the expenses to the appropriate grant award based on the period of performance of those grant awards. Department personnel did not appear to be sufficiently trained on the Highway Safety Cluster’s period of performance compliance requirements. Why do these problems matter? By failing to properly record expenditures to the Highway Safety Cluster within the grant award’s period of performance, the Department risks its costs being deemed unallowable by the federal awarding agency. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-048 The Department of Transportation (Department) should ensure that it complies with federal Highway Safety Cluster grant period of performance requirements by: A. Enforcing its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include ensuring that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance and making adjustments for any expenditures charged to an award outside the proper period of performance. B. Providing training to Department personnel to ensure that staff understand and can apply the period of performance requirements. Response Department of Transportation A. Agree Implementation Date: April 2026 The Department agrees with the recommendation. The Center for Accounting (CFA) and the Office of Transportation Safety (OTS) have coordinated to implement updated reviews and controls. This implementation involves reviewing current processes to ensure supporting documentation is vetted and grant compliance is verified prior to payment. It also includes assessing the need for increased monitoring to ensure initial program reviews are complete and accurate. This remediation effort was finalized on June 30, 2025, following the September 2024 transaction in question. Additionally, the Department plans to review the remediation plan with all relevant staff again this season. This will ensure that all supporting documentation is thoroughly vetted and that expenditures comply with the applicable award period of performance B. Agree Implementation Date: April 2026 The Colorado Department of Transportation (CDOT) agrees with the recommendation. The Center for Accounting (CFA) and the Office of Transportation Safety (OTS) have coordinated on its implementation. The Department has assessed and updated training for staff responsible for reviewing and approving invoices for Highway Safety Cluster grants, with a specific focus on the period of performance. This training plan will be revisited and reviewed with all staff involved by April 2026.
The Colorado Department of Transportation (CDOT) agrees with the recommendation. The Center for Accounting (CFA) and the Office of Transportation Safety (OTS) have coordinated on its implementation. The Department has assessed and updated training for staff responsible for reviewing and approving invoices for Highway Safety Cluster grants, with a specific focus on the period of performance. This training plan will be revisited and reviewed with all staff involved by April 2026.
2024-055
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2025 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Disposition of Prior Audit Recommendations of this report. Finding 2024-058 Compliance with Subrecipient Monitoring for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and SLFRF The Department receives federal grant funds directly from the federal government for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. For Fiscal Year 2024, the Department had the following transactions that were subject to subrecipient monitoring testing: • Formula Grants for Rural Areas and Tribal Transit Program – 783 subrecipient transactions totaling $23,075,270. • Highway Safety Cluster – 829 subrecipient transactions totaling $5,669,865. • SLFRF – 232 subrecipient transactions totaling $38,321,493. For the SLFRF program, Intergovernmental Agreements are executed between the Department and subrecipients to communicate all relevant federal award information. For both the Formula Grants for Rural Areas and Tribal Transit Program and Highway Safety Cluster, Subaward Agreements (subawards) are executed between the Department and subrecipients to communicate all relevant federal award information. Intergovernmental Agreements and subawards are signed by authorized State personnel, generally the State Controller and the Department’s Chief Engineer. The Department includes a “Subrecipient Risk Assessment” tool with its Intergovernmental Agreements or subawards, which must be completed by Department staff prior to making the award. The Department’s subrecipient monitoring procedures are dependent on the assessed risk level noted in the Subrecipient Risk Assessment tool. Federal regulations [2 CFR Part 200 Section F] state that a non-federal entity that expends $1,000,000 or more in federal awards during the non-federal entity’s fiscal year must have a Single Audit conducted in accordance with 2 CFR 200.514. The Department’s Internal Audit Division staff tracks and receives Single Audit reports from its subrecipients. As part of the Department’s monitoring procedures, the Internal Audit Division personnel complete a “Single Audit Report Review Summary” form to show they reviewed the subrecipient’s Single Audit report, summarized any findings, and concluded on any risks presented to the Department and any related future actions to be taken. The form is signed by a Department preparer and a Department reviewer. For those subrecipients not required to file a Single Audit, an “Audit Division Single Audit Certification Form” must still be submitted by the subrecipients to the Department. These forms note that the entity was exempt from a Single Audit. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine if the Department complied with federal requirements for subrecipient monitoring during Fiscal Year 2024 for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the SLFRF program and to determine whether the Department had adequate internal controls over subrecipient monitoring. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring and tested the Department’s compliance with federal subrecipient monitoring requirements. Specifically, we performed the following testwork related to each of the following federal programs: • Formula Grants for Rural Areas and Tribal Transit Program—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • Highway Safety Cluster—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • SLFRF—We selected and reviewed a random sample of 29 subrecipient payment transactions. We reviewed Intergovernmental Agreements, amendments, and other supporting documentation provided by the Department. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the ALN, the Federal Award Date, and the FAIN. • Federal regulation [2 CFR 200.331] states that a pass-through entity, in this case the Department, must make case-by-case determinations as to whether each agreement it makes for the disbursement of federal program funds represents a payment of funds to a subrecipient or a contractor, depending on the role the entity plays. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements during Fiscal Year 2024. Specifically, we noted the following: • Formula Grants for Rural Areas and Tribal Transit Program o For 10 of 40 (25 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement, as required. The 10 transactions totaled $7,432,248 in subrecipient awards. • Highway Safety Cluster o For 1 of 40 (3 percent) subrecipient payment transactions selected for testing, we determined that the subrecipient should have been classified as a contractor, not a subrecipient. The transaction totaled $75,325. The Department had not made an adjusting entry in CORE to reclassify the transaction and correct this error by the end of our audit testwork. o For 5 of 40 (13 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement. The 5 transactions totaled $25,100 in subrecipient awards. • SLFRF o For 2 of 29 (7 percent) subrecipient payment transactions selected for testing, we determined that the Intergovernmental Agreement did not include the FAIN and Federal Award Dates. The 2 transactions totaled $3,277,779 in subrecipient awards. o For 1 of 29 (3 percent) subrecipient payment transactions selected for testing, we determined the transaction did not include the ALN. This transaction totaled $1,851,279 in subrecipient awards. Why did these problems occur? The Department’s procedures and internal controls were not sufficient to ensure that Intergovernmental Agreements and subawards included all the required information to be included in the subaward, and internal controls did not prevent or detect errors. Department staff were not aware that this information was needed for the subaward to be in compliance with federal regulations. In some situations, the FAIN was only provided to the Department from the U.S. Department of Transportation subsequent to when the subaward was made. In these instances, the Department was not aware that they were required to provide the FAIN to their subrecipients once it was determined by the U.S. Department of Transportation. The Department’s procedures and internal controls were not sufficient to ensure that payments were properly classified as general disbursements or subrecipient payments, and internal controls did not prevent or detect errors. Department staff lacked the appropriate knowledge of the difference in contractors and subrecipients to ensure the proper classification of expenditures. The Department’s reviewers did not complete a sufficient review of the expense classifications to be able to identify the misclassification and propose a subsequent correction. Why do these problems matter? Based on the issues we identified, the Department is out of compliance with federal subrecipient requirements and could face sanctions or other penalties. In addition, by failing to properly report the required federal grant award information at the time of subaward issuance, subrecipients may be uninformed about what funding the subaward related to. This could result in misclassification of subaward information on the subrecipients’ Schedules of Expenditures of Federal Awards (SEFA) and the subrecipient may not know what federal requirements they need to follow as part of receiving the federal award funds. The Department’s improper classification of expenses as general disbursements versus subrecipient payments could lead to misstatements in the amounts reported on the SEFA, both for the State as a whole and at the subrecipient level. See "Schedule of Findings and Questioned Costs" for chart/table. Recommendation 2024-058 The Department of Transportation (Department) should strengthen its internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Formula Grants for Rural Areas and Tribal Transit Program, the Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds. Specifically, the Department should ensure that all required information is included in subawards or intergovernmental agreements or provide amendments to the subawards or intergovernmental once the Department receives the necessary information from the federal government, and that Department staff are sufficiently aware of the difference in subrecipients and contractors and properly classify general disbursements versus subrecipient payments. Response Department of Transportation Agree Implementation Date: June 2026 Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2025 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Disposition of Prior Audit Recommendations of this report. Finding 2024-058 Compliance with Subrecipient Monitoring for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and SLFRF The Department receives federal grant funds directly from the federal government for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. For Fiscal Year 2024, the Department had the following transactions that were subject to subrecipient monitoring testing: • Formula Grants for Rural Areas and Tribal Transit Program – 783 subrecipient transactions totaling $23,075,270. • Highway Safety Cluster – 829 subrecipient transactions totaling $5,669,865. • SLFRF – 232 subrecipient transactions totaling $38,321,493. For the SLFRF program, Intergovernmental Agreements are executed between the Department and subrecipients to communicate all relevant federal award information. For both the Formula Grants for Rural Areas and Tribal Transit Program and Highway Safety Cluster, Subaward Agreements (subawards) are executed between the Department and subrecipients to communicate all relevant federal award information. Intergovernmental Agreements and subawards are signed by authorized State personnel, generally the State Controller and the Department’s Chief Engineer. The Department includes a “Subrecipient Risk Assessment” tool with its Intergovernmental Agreements or subawards, which must be completed by Department staff prior to making the award. The Department’s subrecipient monitoring procedures are dependent on the assessed risk level noted in the Subrecipient Risk Assessment tool. Federal regulations [2 CFR Part 200 Section F] state that a non-federal entity that expends $1,000,000 or more in federal awards during the non-federal entity’s fiscal year must have a Single Audit conducted in accordance with 2 CFR 200.514. The Department’s Internal Audit Division staff tracks and receives Single Audit reports from its subrecipients. As part of the Department’s monitoring procedures, the Internal Audit Division personnel complete a “Single Audit Report Review Summary” form to show they reviewed the subrecipient’s Single Audit report, summarized any findings, and concluded on any risks presented to the Department and any related future actions to be taken. The form is signed by a Department preparer and a Department reviewer. For those subrecipients not required to file a Single Audit, an “Audit Division Single Audit Certification Form” must still be submitted by the subrecipients to the Department. These forms note that the entity was exempt from a Single Audit. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine if the Department complied with federal requirements for subrecipient monitoring during Fiscal Year 2024 for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the SLFRF program and to determine whether the Department had adequate internal controls over subrecipient monitoring. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring and tested the Department’s compliance with federal subrecipient monitoring requirements. Specifically, we performed the following testwork related to each of the following federal programs: • Formula Grants for Rural Areas and Tribal Transit Program—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • Highway Safety Cluster—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • SLFRF—We selected and reviewed a random sample of 29 subrecipient payment transactions. We reviewed Intergovernmental Agreements, amendments, and other supporting documentation provided by the Department. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the ALN, the Federal Award Date, and the FAIN. • Federal regulation [2 CFR 200.331] states that a pass-through entity, in this case the Department, must make case-by-case determinations as to whether each agreement it makes for the disbursement of federal program funds represents a payment of funds to a subrecipient or a contractor, depending on the role the entity plays. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements during Fiscal Year 2024. Specifically, we noted the following: • Formula Grants for Rural Areas and Tribal Transit Program o For 10 of 40 (25 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement, as required. The 10 transactions totaled $7,432,248 in subrecipient awards. • Highway Safety Cluster o For 1 of 40 (3 percent) subrecipient payment transactions selected for testing, we determined that the subrecipient should have been classified as a contractor, not a subrecipient. The transaction totaled $75,325. The Department had not made an adjusting entry in CORE to reclassify the transaction and correct this error by the end of our audit testwork. o For 5 of 40 (13 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement. The 5 transactions totaled $25,100 in subrecipient awards. • SLFRF o For 2 of 29 (7 percent) subrecipient payment transactions selected for testing, we determined that the Intergovernmental Agreement did not include the FAIN and Federal Award Dates. The 2 transactions totaled $3,277,779 in subrecipient awards. o For 1 of 29 (3 percent) subrecipient payment transactions selected for testing, we determined the transaction did not include the ALN. This transaction totaled $1,851,279 in subrecipient awards. Why did these problems occur? The Department’s procedures and internal controls were not sufficient to ensure that Intergovernmental Agreements and subawards included all the required information to be included in the subaward, and internal controls did not prevent or detect errors. Department staff were not aware that this information was needed for the subaward to be in compliance with federal regulations. In some situations, the FAIN was only provided to the Department from the U.S. Department of Transportation subsequent to when the subaward was made. In these instances, the Department was not aware that they were required to provide the FAIN to their subrecipients once it was determined by the U.S. Department of Transportation. The Department’s procedures and internal controls were not sufficient to ensure that payments were properly classified as general disbursements or subrecipient payments, and internal controls did not prevent or detect errors. Department staff lacked the appropriate knowledge of the difference in contractors and subrecipients to ensure the proper classification of expenditures. The Department’s reviewers did not complete a sufficient review of the expense classifications to be able to identify the misclassification and propose a subsequent correction. Why do these problems matter? Based on the issues we identified, the Department is out of compliance with federal subrecipient requirements and could face sanctions or other penalties. In addition, by failing to properly report the required federal grant award information at the time of subaward issuance, subrecipients may be uninformed about what funding the subaward related to. This could result in misclassification of subaward information on the subrecipients’ Schedules of Expenditures of Federal Awards (SEFA) and the subrecipient may not know what federal requirements they need to follow as part of receiving the federal award funds. The Department’s improper classification of expenses as general disbursements versus subrecipient payments could lead to misstatements in the amounts reported on the SEFA, both for the State as a whole and at the subrecipient level. See "Schedule of Findings and Questioned Costs" for chart/table. Recommendation 2024-058 The Department of Transportation (Department) should strengthen its internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Formula Grants for Rural Areas and Tribal Transit Program, the Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds. Specifically, the Department should ensure that all required information is included in subawards or intergovernmental agreements or provide amendments to the subawards or intergovernmental once the Department receives the necessary information from the federal government, and that Department staff are sufficiently aware of the difference in subrecipients and contractors and properly classify general disbursements versus subrecipient payments. Response Department of Transportation Agree Implementation Date: June 2026 Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
2024-058
FAC accepted this audit on March 27, 2025 — management decision was due September 27, 2025.
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-050 Colorado Child Care Assistance Program The Department is responsible for monitoring each county’s administration of CCCAP. County caseworkers enter a CCCAP adult caretaker’s application information, including household employment and income, household size, and the names and number of children needing care, into the Department’s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker’s household income must not exceed 85 percent of the State’s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker. In addition to families that apply for child care assistance, CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient. During Fiscal Year 2023, the Department provided approximately $133.2 million in child care benefits through CCCAP for 24,592 children. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over CCCAP enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s internal controls over CCCAP that were in place during Fiscal Year 2023. In addition, we performed testing of a sample of 60 children who were deemed eligible for child care services through CCCAP and received $348,581 in CCCAP benefits during Fiscal Year 2023 to determine whether the children’s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with determining the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. How were the results of the audit work measured? We measured the results of our audit work against the following: • According to federal regulation [45 CFR 98.11], the Department “has broad authority to administer the program through other governmental or non-governmental agencies”, such as county departments of human/social services. In addition, the regulation states that the Department “shall retain overall responsibility for the administration of the program” including monitoring programs and services, and ensuring that the departments of human/social services “operate according to the rules established for the program.” • State regulation [8 CCR 1403-1, 3.103.YYY] defines a parent fee or copayment as the “household’s contribution to the total cost of child care paid directly to the child care provider(s) prior to any state/county child care funds being expended.” • State regulation [8 CCR 1403-01, 3.124.A] states that “parent fees are based on gross countable income for the child care household compared to the household size, taking the number of children in care into account.” What problems did the audit work identify? We found that the Department did not fully comply with federal and state CCCAP requirements during Fiscal Year 2023. Specifically, we identified errors in 2 of the 60 case files (3 percent) that we tested, resulting in a total of $1,543 in known questioned costs. Specifically, we identified the following: In two cases, the caseworker incorrectly entered information into CHATS when determining eligibility, which resulted in the adult caretakers being charged an incorrect parent fee. In one case, the caseworker entered the adult caretaker’s income incorrectly as $2,125 instead of the correct amount of $2,215, which caused the parent fee to be incorrectly calculated as $848 instead of the correct amount of $879. In the other case, the caseworker incorrectly entered the number of hours worked by the adult caretaker when calculating the caretaker’s income, which resulted in the income being incorrectly calculated as $1,974 instead of the correct amount of $3,637, which caused the parent fee to be incorrectly calculated as $352 instead of the correct amount of $551. Because parent fees are required to be paid before CCCAP benefits are paid, the errors in these two case files resulted in $1,543 in known questioned costs. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with federal and state requirements for CCCAP during Fiscal Year 2023. The program was previously administered by the DHS, and this is the first year that the Department was in charge of the program. Program staff reported that they are working to implement effective internal controls, including policies and procedures requiring that Department CCCAP staff adequately monitor the county departments of human/social services to ensure the counties are conducting a secondary review over child care case files. Why do these problems matter? It is essential for the Department to ensure that child care eligibility is properly determined in accordance with state and federal regulations. Inaccurate processing of case file information for eligibility determination can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2023-050 The Department of Early Childhood (Department) should strengthen its internal controls over, and ensure it complies with, requirements for the federal Child Care and Development Fund Cluster grant by monitoring the county departments of human/social services to ensure they are performing supervisory and/or secondary reviews over case files after eligibility is determined in order to ensure eligibility is appropriately determined and that parent fees are accurate, and to address the issues identified in the audit. Response Department of Early Childhood Agree Implementation Date: December 2024 In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-050 Colorado Child Care Assistance Program The Department is responsible for monitoring each county’s administration of CCCAP. County caseworkers enter a CCCAP adult caretaker’s application information, including household employment and income, household size, and the names and number of children needing care, into the Department’s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker’s household income must not exceed 85 percent of the State’s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker. In addition to families that apply for child care assistance, CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient. During Fiscal Year 2023, the Department provided approximately $133.2 million in child care benefits through CCCAP for 24,592 children. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over CCCAP enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s internal controls over CCCAP that were in place during Fiscal Year 2023. In addition, we performed testing of a sample of 60 children who were deemed eligible for child care services through CCCAP and received $348,581 in CCCAP benefits during Fiscal Year 2023 to determine whether the children’s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with determining the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. How were the results of the audit work measured? We measured the results of our audit work against the following: • According to federal regulation [45 CFR 98.11], the Department “has broad authority to administer the program through other governmental or non-governmental agencies”, such as county departments of human/social services. In addition, the regulation states that the Department “shall retain overall responsibility for the administration of the program” including monitoring programs and services, and ensuring that the departments of human/social services “operate according to the rules established for the program.” • State regulation [8 CCR 1403-1, 3.103.YYY] defines a parent fee or copayment as the “household’s contribution to the total cost of child care paid directly to the child care provider(s) prior to any state/county child care funds being expended.” • State regulation [8 CCR 1403-01, 3.124.A] states that “parent fees are based on gross countable income for the child care household compared to the household size, taking the number of children in care into account.” What problems did the audit work identify? We found that the Department did not fully comply with federal and state CCCAP requirements during Fiscal Year 2023. Specifically, we identified errors in 2 of the 60 case files (3 percent) that we tested, resulting in a total of $1,543 in known questioned costs. Specifically, we identified the following: In two cases, the caseworker incorrectly entered information into CHATS when determining eligibility, which resulted in the adult caretakers being charged an incorrect parent fee. In one case, the caseworker entered the adult caretaker’s income incorrectly as $2,125 instead of the correct amount of $2,215, which caused the parent fee to be incorrectly calculated as $848 instead of the correct amount of $879. In the other case, the caseworker incorrectly entered the number of hours worked by the adult caretaker when calculating the caretaker’s income, which resulted in the income being incorrectly calculated as $1,974 instead of the correct amount of $3,637, which caused the parent fee to be incorrectly calculated as $352 instead of the correct amount of $551. Because parent fees are required to be paid before CCCAP benefits are paid, the errors in these two case files resulted in $1,543 in known questioned costs. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with federal and state requirements for CCCAP during Fiscal Year 2023. The program was previously administered by the DHS, and this is the first year that the Department was in charge of the program. Program staff reported that they are working to implement effective internal controls, including policies and procedures requiring that Department CCCAP staff adequately monitor the county departments of human/social services to ensure the counties are conducting a secondary review over child care case files. Why do these problems matter? It is essential for the Department to ensure that child care eligibility is properly determined in accordance with state and federal regulations. Inaccurate processing of case file information for eligibility determination can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2023-050 The Department of Early Childhood (Department) should strengthen its internal controls over, and ensure it complies with, requirements for the federal Child Care and Development Fund Cluster grant by monitoring the county departments of human/social services to ensure they are performing supervisory and/or secondary reviews over case files after eligibility is determined in order to ensure eligibility is appropriately determined and that parent fees are accurate, and to address the issues identified in the audit. Response Department of Early Childhood Agree Implementation Date: December 2024 In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
2023-050
Finding 2024-031 Trails – Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response and addendum, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding, response, and addendum have been provided to OIT in a separate, confidential memorandum. The Department of Human Services (Department), as the business owner, utilizes a statewide automated child welfare information system, known as Trails, to aid in administering a number of federally-funded child welfare programs, including the federal Foster Care Title IV-E program [ALN 93.658] (Program). Trails went live in 2001, and in Fiscal Year 2017, the Department and OIT—the Trails IT service provider—began a multi-phase and multi-year modernization project that continued during Fiscal Year 2024. OIT, working closely with the Department’s Trails Security Administrators, is responsible for certain access management procedures related to Trails. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine the disposition of our Fiscal Year 2023 audit recommendation where we recommended that OIT improve access management IT general controls over Trails. Our audit work was performed through interviews conducted of OIT staff and reviewing supporting documentation. OIT agreed with this recommendation and provided a June 2024 implementation date. How were the results of the audit work measured? We measured the results of our audit work against Colorado Information Security Policies, which are developed and published by OIT. What problem did the audit work identify? During our Fiscal Year 2024 audit, OIT reported that it did not implement our prior audit recommendation related to access management IT general controls for Trails. Why did this problem occur? OIT communicated that it was still in the process of working with the Department to ensure controls are properly implemented. Why does this problem matter? When access management IT general controls are lacking, management may not be able to ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of the Trails system. See schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-031 The Governor’s Office of Information Technology should improve access management IT general controls over the Trails system by implementing the recommendation noted in the confidential finding. Response Office of the Governor Agree Implementation Date: February 2025 The Governor’s Office of Information Technology agrees with this recommendation and will remediate the finding by February 2025.
Show full finding ▾Hide full finding ▴Finding 2024-031 Trails – Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response and addendum, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding, response, and addendum have been provided to OIT in a separate, confidential memorandum. The Department of Human Services (Department), as the business owner, utilizes a statewide automated child welfare information system, known as Trails, to aid in administering a number of federally-funded child welfare programs, including the federal Foster Care Title IV-E program [ALN 93.658] (Program). Trails went live in 2001, and in Fiscal Year 2017, the Department and OIT—the Trails IT service provider—began a multi-phase and multi-year modernization project that continued during Fiscal Year 2024. OIT, working closely with the Department’s Trails Security Administrators, is responsible for certain access management procedures related to Trails. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine the disposition of our Fiscal Year 2023 audit recommendation where we recommended that OIT improve access management IT general controls over Trails. Our audit work was performed through interviews conducted of OIT staff and reviewing supporting documentation. OIT agreed with this recommendation and provided a June 2024 implementation date. How were the results of the audit work measured? We measured the results of our audit work against Colorado Information Security Policies, which are developed and published by OIT. What problem did the audit work identify? During our Fiscal Year 2024 audit, OIT reported that it did not implement our prior audit recommendation related to access management IT general controls for Trails. Why did this problem occur? OIT communicated that it was still in the process of working with the Department to ensure controls are properly implemented. Why does this problem matter? When access management IT general controls are lacking, management may not be able to ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of the Trails system. See schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-031 The Governor’s Office of Information Technology should improve access management IT general controls over the Trails system by implementing the recommendation noted in the confidential finding. Response Office of the Governor Agree Implementation Date: February 2025 The Governor’s Office of Information Technology agrees with this recommendation and will remediate the finding by February 2025.
The Governor’s Office of Information Technology agrees with this recommendation and will remediate the finding by February 2025.
2023-052
Finding 2024-032 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Medicaid Medicaid Claims Payments The Department reimburses medical providers, pharmacies, and medical equipment providers for claims submitted to the Department for services provided to eligible beneficiaries in the Medicaid program. To be allowable, Medicaid costs for services must be (1) covered by the CMS-approved state plan or the CMS-approved waivers; (2) reviewed by the Department consistent with the Department’s documented procedures and system for determining the medical necessity of claims; (3) properly coded; and (4) paid at the rate allowed by the state plan. A Medicaid state plan is a formal, written agreement between a state and the federal government describing how a state administers its Medicaid program, which includes both the basic requirements of the program and individualized content that reflects the characteristics of the state’s program [42 CFR 430.10]. The state plan is written by the state and must be approved by CMS in order for the State to access federal Medicaid funds. The Department uses Colorado interChange as its medical claims system. Colorado interChange is programmed to make Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. During Fiscal Year 2024, the Department contracted with a fiscal agent, Gainwell Technologies (Gainwell), to manage Colorado interChange. A fiscal agent is a contractor that acts on behalf of the Department in respect to claims processing activities, including evaluating and approving or rejecting claims payments in accordance with established Department policies. Although Gainwell receives and processes all claims, the Department is ultimately responsible for ensuring that the claims are paid in accordance with federal and state regulations. Providers are responsible for preparing and submitting Medicaid claims to Gainwell for processing in compliance with the Department’s claim filing requirements. All provider claims must include a diagnosis code, procedure code, and the provider’s usual and customary charges for payment (Provider Rate). Procedure codes are dependent on the type of service and claim type. Colorado interChange is programmed with CMS-approved rates for each procedure code. Gainwell will use the claims information received by the provider, including the specific procedure codes and Provider Rate, to process and pay the claims in Colorado interChange. Providers are advised by the Department to bill their usual and customary charges for services, and the Colorado interChange system pays the lower of either (1) the Provider Rate, or (2) the Department’s CMS-approved rates. If needed, all claims may be adjusted for increased payment, decreased payment, or recovery without repayment. Adjustments that increase or decrease the original payment amount are processed as a two-part transaction in Colorado interChange—the first piece of the transaction reverses the previously made payment, and the second piece of the transaction repays the claim at the corrected rate. If a previously paid claim is adjusted to pay less than the original amount, the adjustment will result in a retraction of the difference between the original payment and the corrected payment amount. If a previously paid claim is adjusted to pay more than the original amount, depending on if the provider billed usual and customary rates, the adjustment will result in an additional payment to the provider. The Department authorizes updates to the rate tables in Colorado interChange whenever there are changes in the claims rates. All provider rate increases are subject to CMS approval prior to implementation of an increase. Rate changes are generally made at the beginning of each fiscal year, but can be made anytime an update is required, such as when CMS issues a rate change that is based on the federal fiscal year (which begins on October 1). To make a change in the rate tables, Department staff fill out a change request form (Update Form) including the purpose of the request, instructions on the specific information that needs updating, and any other special instructions related to the request. The Department must include specific instructions on the Update Form if any claims have to be reprocessed as part of the request. A reprocessing request is needed if the actual rate change is made after the effective date of the change. For example, if a rate change was effective at the beginning of the fiscal year (July 1) but processed on July 15, the Update Form should include a specific request to reprocess claims with dates of service from July 1 to July 15, which would ensure the claims are paid at the correct rates. Once complete, Department staff send the Update Form to Gainwell for processing in Colorado interChange. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid claims payment process and to determine whether payments were processed and paid in accordance with state and federal regulations during Fiscal Year 2024. During our audit, we obtained a list of all Medicaid claims that were paid by the Department during Fiscal Year 2024, which included 77,824,795 individual Medicaid claims totaling $11,542,679,377. We performed testing on a randomly selected sample of 40 Medicaid claims paid during Fiscal Year 2024 totaling $4,486,936 to determine whether the claim (1) matched the claims information that was reported in Colorado interChange; (2) was paid at the rate allowed by the state plan; and (3) beneficiary was eligible for the Medicaid program at the time of service. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [45 CFR 75.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to Generally Accepted Accounting Principles (GAAP); not be used for cost sharing of other programs; and be adequately documented. Section 25.5-4-301(2), C.R.S., states that any overpayment to a provider is recoverable, regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider. Federal regulations [45 CFR 75.303] state that recipients of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with “Standards for Internal Control in the Federal Government” (Green Book), published by the U.S. Government Accountability Office. Principles 3.09-3.10, Documentation of the Internal Control System, state that management is to develop and maintain documentation of its internal control system. This documentation should establish the who, what, when, where, and why of internal control execution to personnel. Documentation also provides a means to retain organizational knowledge and mitigate the risk of having that knowledge limited to a few personnel. What problem did the audit work identify? Based on our audit testwork, we determined that one of the 40 claims tested (2.5 percent) contained procedure codes that were paid at the incorrect rate for Fiscal Year 2024. Specifically, the claim selected for testing contained three specific procedures, two of which were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The third procedure code had the same rate for both Fiscal Year 2023 and 2024, so no difference was noted. The total known questioned costs for this claim were $137.20. See Schedule of Findings and Questioned Costs for chart/table. We provided the claim to Department staff to research, and they determined that this claim was part of a group of 2,423 individual claims with specific procedure codes that were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The total known questioned costs for this group of claims, including the sample tested above, was $189,015.98. Why did this problem occur? The Department does not have adequate internal controls, including formal policies and procedures, in place related to the rate updating process in Colorado interChange. Specifically, the Department lacked policies and procedures detailing how to complete the rate Update Form, requiring a secondary review process over the completed Update Form prior to submission to Gainwell, and requiring a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. On July 21, 2023, Department staff completed and submitted an Update Form to Gainwell to process the annual rate updates; the Department staff who processed the rate update had been trained on the process before, but this was the first time they completed the process independently and they overlooked including specific instructions to reprocess any claims with dates of service before the update (July 1, 2023 to July 21, 2023) at the new rate. This caused the Fiscal Year 2024 rate changes to take effect on July 21, 2023 instead of July 1, 2023 (the first day of the fiscal year). The Department did not have a review process in place to confirm that the Update Forms were completed accurately and included all necessary information, so the Department was unaware of the issue until it was identified during our audit. Once notified of the error, Department staff contacted Gainwell to initiate an adjustment to correct all claims with dates of service from July 1, 2023 to July 21, 2023 that were paid at the incorrect rate. The Department also notified all providers of the issue on the Department’s Provider Resources website and in the December 2024 Provider Bulletin. The adjustment was processed on November 22, 2024. Why does this problem matter? Strong internal controls over the Medicaid claims process—including documented policies and procedures detailing how to complete the Update Form and an effective review process—are necessary to ensure that Medicaid claims are paid at the correct rates approved by the state plan and in accordance with federal and state regulations. In addition, making payments over the specific rates can result in the Department having to repay the federal government for the federal portion of the overpayments. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-032 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Medicaid claims process by developing, documenting, and implementing formal policies and procedures over the rate updating process in Colorado interChange, the Department’s medical claims system. These policies and procedures should include details on how to complete the rate change request form (Update Form), require a secondary review process over the completed Update Form prior to submission to Gainwell Technologies—the Department’s contracted fiscal agent that manages Colorado interChange—and require a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. Response Department of Health Care Policy and Financing Agree Implementation Date: July 2025 The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
Show full finding ▾Hide full finding ▴Finding 2024-032 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Medicaid Medicaid Claims Payments The Department reimburses medical providers, pharmacies, and medical equipment providers for claims submitted to the Department for services provided to eligible beneficiaries in the Medicaid program. To be allowable, Medicaid costs for services must be (1) covered by the CMS-approved state plan or the CMS-approved waivers; (2) reviewed by the Department consistent with the Department’s documented procedures and system for determining the medical necessity of claims; (3) properly coded; and (4) paid at the rate allowed by the state plan. A Medicaid state plan is a formal, written agreement between a state and the federal government describing how a state administers its Medicaid program, which includes both the basic requirements of the program and individualized content that reflects the characteristics of the state’s program [42 CFR 430.10]. The state plan is written by the state and must be approved by CMS in order for the State to access federal Medicaid funds. The Department uses Colorado interChange as its medical claims system. Colorado interChange is programmed to make Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. During Fiscal Year 2024, the Department contracted with a fiscal agent, Gainwell Technologies (Gainwell), to manage Colorado interChange. A fiscal agent is a contractor that acts on behalf of the Department in respect to claims processing activities, including evaluating and approving or rejecting claims payments in accordance with established Department policies. Although Gainwell receives and processes all claims, the Department is ultimately responsible for ensuring that the claims are paid in accordance with federal and state regulations. Providers are responsible for preparing and submitting Medicaid claims to Gainwell for processing in compliance with the Department’s claim filing requirements. All provider claims must include a diagnosis code, procedure code, and the provider’s usual and customary charges for payment (Provider Rate). Procedure codes are dependent on the type of service and claim type. Colorado interChange is programmed with CMS-approved rates for each procedure code. Gainwell will use the claims information received by the provider, including the specific procedure codes and Provider Rate, to process and pay the claims in Colorado interChange. Providers are advised by the Department to bill their usual and customary charges for services, and the Colorado interChange system pays the lower of either (1) the Provider Rate, or (2) the Department’s CMS-approved rates. If needed, all claims may be adjusted for increased payment, decreased payment, or recovery without repayment. Adjustments that increase or decrease the original payment amount are processed as a two-part transaction in Colorado interChange—the first piece of the transaction reverses the previously made payment, and the second piece of the transaction repays the claim at the corrected rate. If a previously paid claim is adjusted to pay less than the original amount, the adjustment will result in a retraction of the difference between the original payment and the corrected payment amount. If a previously paid claim is adjusted to pay more than the original amount, depending on if the provider billed usual and customary rates, the adjustment will result in an additional payment to the provider. The Department authorizes updates to the rate tables in Colorado interChange whenever there are changes in the claims rates. All provider rate increases are subject to CMS approval prior to implementation of an increase. Rate changes are generally made at the beginning of each fiscal year, but can be made anytime an update is required, such as when CMS issues a rate change that is based on the federal fiscal year (which begins on October 1). To make a change in the rate tables, Department staff fill out a change request form (Update Form) including the purpose of the request, instructions on the specific information that needs updating, and any other special instructions related to the request. The Department must include specific instructions on the Update Form if any claims have to be reprocessed as part of the request. A reprocessing request is needed if the actual rate change is made after the effective date of the change. For example, if a rate change was effective at the beginning of the fiscal year (July 1) but processed on July 15, the Update Form should include a specific request to reprocess claims with dates of service from July 1 to July 15, which would ensure the claims are paid at the correct rates. Once complete, Department staff send the Update Form to Gainwell for processing in Colorado interChange. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid claims payment process and to determine whether payments were processed and paid in accordance with state and federal regulations during Fiscal Year 2024. During our audit, we obtained a list of all Medicaid claims that were paid by the Department during Fiscal Year 2024, which included 77,824,795 individual Medicaid claims totaling $11,542,679,377. We performed testing on a randomly selected sample of 40 Medicaid claims paid during Fiscal Year 2024 totaling $4,486,936 to determine whether the claim (1) matched the claims information that was reported in Colorado interChange; (2) was paid at the rate allowed by the state plan; and (3) beneficiary was eligible for the Medicaid program at the time of service. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [45 CFR 75.403] require that costs under federal awards must be necessary, reasonable, and allocable; conform to any limitations or exclusions; be consistent with policies and procedures; receive consistent treatment; adhere to Generally Accepted Accounting Principles (GAAP); not be used for cost sharing of other programs; and be adequately documented. Section 25.5-4-301(2), C.R.S., states that any overpayment to a provider is recoverable, regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider. Federal regulations [45 CFR 75.303] state that recipients of federal funds must establish and maintain effective internal controls over its federal awards, which provide reasonable assurance that the recipient is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with “Standards for Internal Control in the Federal Government” (Green Book), published by the U.S. Government Accountability Office. Principles 3.09-3.10, Documentation of the Internal Control System, state that management is to develop and maintain documentation of its internal control system. This documentation should establish the who, what, when, where, and why of internal control execution to personnel. Documentation also provides a means to retain organizational knowledge and mitigate the risk of having that knowledge limited to a few personnel. What problem did the audit work identify? Based on our audit testwork, we determined that one of the 40 claims tested (2.5 percent) contained procedure codes that were paid at the incorrect rate for Fiscal Year 2024. Specifically, the claim selected for testing contained three specific procedures, two of which were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The third procedure code had the same rate for both Fiscal Year 2023 and 2024, so no difference was noted. The total known questioned costs for this claim were $137.20. See Schedule of Findings and Questioned Costs for chart/table. We provided the claim to Department staff to research, and they determined that this claim was part of a group of 2,423 individual claims with specific procedure codes that were paid at the rate in effect during Fiscal Year 2023 instead of the correct Fiscal Year 2024 rate. The total known questioned costs for this group of claims, including the sample tested above, was $189,015.98. Why did this problem occur? The Department does not have adequate internal controls, including formal policies and procedures, in place related to the rate updating process in Colorado interChange. Specifically, the Department lacked policies and procedures detailing how to complete the rate Update Form, requiring a secondary review process over the completed Update Form prior to submission to Gainwell, and requiring a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. On July 21, 2023, Department staff completed and submitted an Update Form to Gainwell to process the annual rate updates; the Department staff who processed the rate update had been trained on the process before, but this was the first time they completed the process independently and they overlooked including specific instructions to reprocess any claims with dates of service before the update (July 1, 2023 to July 21, 2023) at the new rate. This caused the Fiscal Year 2024 rate changes to take effect on July 21, 2023 instead of July 1, 2023 (the first day of the fiscal year). The Department did not have a review process in place to confirm that the Update Forms were completed accurately and included all necessary information, so the Department was unaware of the issue until it was identified during our audit. Once notified of the error, Department staff contacted Gainwell to initiate an adjustment to correct all claims with dates of service from July 1, 2023 to July 21, 2023 that were paid at the incorrect rate. The Department also notified all providers of the issue on the Department’s Provider Resources website and in the December 2024 Provider Bulletin. The adjustment was processed on November 22, 2024. Why does this problem matter? Strong internal controls over the Medicaid claims process—including documented policies and procedures detailing how to complete the Update Form and an effective review process—are necessary to ensure that Medicaid claims are paid at the correct rates approved by the state plan and in accordance with federal and state regulations. In addition, making payments over the specific rates can result in the Department having to repay the federal government for the federal portion of the overpayments. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-032 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Medicaid claims process by developing, documenting, and implementing formal policies and procedures over the rate updating process in Colorado interChange, the Department’s medical claims system. These policies and procedures should include details on how to complete the rate change request form (Update Form), require a secondary review process over the completed Update Form prior to submission to Gainwell Technologies—the Department’s contracted fiscal agent that manages Colorado interChange—and require a post-implementation review of the rate changes made in Colorado interChange to confirm they were correctly made by Gainwell. Response Department of Health Care Policy and Financing Agree Implementation Date: July 2025 The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
The Department of Health Care Policy and Financing has examined rate maintenance practices since FY2024 to determine the best course of action to strengthen internal controls to subsequently develop formal policies and procedures. The Waiver and Fee Schedule Rates section will develop a formal, recorded training and corresponding training materials based on current, informal processes on completion of the rate update form to be submitted to the Department's fiscal agent, Gainwell Technologies. Since FY2024, the Waiver and Fee Schedule Rates section has implemented a multilevel secondary review process prior to any rate change submission to ensure accuracy in rate update submissions. The Rates section has also worked closely with other internal partners to formalize informal update processes for quality assurance and maintenance of a minimal error percentage. The Rates section has also implemented a post-implementation data analysis review of all rate update submissions to ensure the update was implemented as directed and expected to ensure accountability on behalf of the Department's fiscal agent Gainwell Technologies. The Rates section is currently in process of documenting and formalizing all rate update processes and policies for future training and process maintenance.
Finding 2024-033 Compliance with Eligibility for Medicaid and CBHP Ex Parte Renewal Process Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits. States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at that time, either from the beneficiary’s case file or other electronic data sources, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid and CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid and CBHP eligibility requirements during Fiscal Year 2024. During our audit, we inquired with the Department on the ex parte renewal process for Medicaid and CBHP beneficiaries. How were the results of the audit work measured? We measured the results of our audit work against the following: Federal regulations require states to complete a redetermination of eligibility based on available information for each individual in the household, regardless of the eligibility of others in the household unit. Specifically, these regulations require that states complete a redetermination of eligibility for all beneficiaries without requiring information from the individual if able to do so based on reliable information contained in the individual’s case file or more current information available to the state (ex parte basis) [42 CFR 435.916(b)(2) and 457.343]. If they are unable to do so, the state must provide the individual with a pre-populated renewal form and give them at least 30 calendar days to respond and provide any necessary information [42 CFR 435.916(b)(2)]. Federal regulations [42 CFR 435.952(d) and 457.380(f)] specify that states may not terminate eligibility or reduce benefits on the basis of information obtained through the ex parte renewal process without first contacting the beneficiary and offering them an opportunity to provide new information. What problem did the audit work identify? The Department reported to us that they were not in compliance with eligibility requirements related to the ex parte renewal process during Fiscal Year 2024. As CMS worked with individual states on their COVID-19 unwinding plans, they identified 29 states that were not in compliance with certain ex parte renewal requirements for Medicaid and CBHP beneficiaries, including Colorado. The Department was inappropriately conducting ex parte renewals at the household level rather than individual level, without using individually-specific eligibility statutes and income thresholds for individuals within the household. Specifically, if eligibility could not be renewed on an ex parte basis for at least one member of a household, renewal forms were sent to the entire household. If the renewal forms were returned, the appropriate eligibility determinations were made and those who are eligible were approved. If the renewal forms were not returned, the Department’s eligibility system, the Colorado Benefits Management System (CBMS), would disenroll all individuals in the household, including any who may have been determined to be eligible through the ex parte process. Why did this problem occur? In August 2023, CMS instructed all states to review their ex parte renewal process to assess compliance with federal requirements to complete eligibility redeterminations based on the available information for each individual in the household, regardless of the eligibility of others in the household unit. States that identified any areas of noncompliance were required to (1) pause terminations for any ex parte renewal processes that are not compliant with federal guidance and whose coverage may be terminated inappropriately; (2) reinstate coverage for all affected individuals who have been disenrolled due to a failure to complete redeterminations based on the available information for each individual in the household; (3) fix the state’s systems and processes to ensure that redeterminations are conducted appropriately; and (4) implement a mitigation strategy to prevent continued inappropriate terminations until the state has fixed all systems and processes to be in compliance with federal renewal requirements. States were required to submit the state’s plan and timeline for remediation to CMS. In September 2023, the Department reported to CMS that it was not fully in compliance with the federal requirements for determining eligibility for each individual in the household, and it submitted a mitigation plan and timeline to fix the CBMS system and Department’s processes to ensure that redeterminations were conducted appropriately in the future. As part of the Department’s mitigation plan, automatic terminations of any households who did not return a renewal form were temporarily paused until a short-term system fix was put in place. In October 2023, a CBMS fix was put into place for households that did not return their renewal forms. CBMS continued to send renewal forms to households requesting additional information; however, for any multi-member household that did not return its form, the Department started reviewing eligibility for all members of the household individually. This short-term system fix brought the Department into compliance with federal ex parte renewal requirements. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with targeted implementation by December 2026. Why does this problem matter? When the Department is out of compliance with federal requirements, such as Medicaid requirements, the Department risks sanctions and/or other penalties. After CMS identified the Department’s noncompliance related to the Medicaid ex parte renewal issue, the Department researched the issue and identified 7,510 individuals who were incorrectly disenrolled from Medicaid or CBHP during the period May 2023 to October 2023. In November 2023, the Department retroactively reinstated these individuals’ eligibility back to the date at which their household was terminated, without a gap in coverage. In addition, the individuals were notified that their coverage had been reinstated and provided information on how to obtain payment for unpaid medical bills and/or ensure that any eligible service during the period that the individual was disenrolled were covered. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-033 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by continuing to implement the Colorado Benefits Management System change related to the ex parte eligibility process to ensure that eligibility is determined on an individual rather than household basis, as required. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
Show full finding ▾Hide full finding ▴Finding 2024-033 Compliance with Eligibility for Medicaid and CBHP Ex Parte Renewal Process Federal regulations require state medical assistance programs to renew a beneficiary’s eligibility once every 12 months to determine whether the beneficiary continues to qualify for benefits. States must first attempt to redetermine the beneficiary’s eligibility based on information the Department has available at that time, either from the beneficiary’s case file or other electronic data sources, without requiring information from the beneficiary. This is called an “ex parte” renewal. If sufficient information is available, the Department can renew eligibility on an ex parte basis and notify the beneficiary that their coverage has been renewed. If sufficient information is not available, the Department will provide the beneficiary with a renewal form and request any additional documentation needed to determine eligibility. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid and CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid and CBHP eligibility requirements during Fiscal Year 2024. During our audit, we inquired with the Department on the ex parte renewal process for Medicaid and CBHP beneficiaries. How were the results of the audit work measured? We measured the results of our audit work against the following: Federal regulations require states to complete a redetermination of eligibility based on available information for each individual in the household, regardless of the eligibility of others in the household unit. Specifically, these regulations require that states complete a redetermination of eligibility for all beneficiaries without requiring information from the individual if able to do so based on reliable information contained in the individual’s case file or more current information available to the state (ex parte basis) [42 CFR 435.916(b)(2) and 457.343]. If they are unable to do so, the state must provide the individual with a pre-populated renewal form and give them at least 30 calendar days to respond and provide any necessary information [42 CFR 435.916(b)(2)]. Federal regulations [42 CFR 435.952(d) and 457.380(f)] specify that states may not terminate eligibility or reduce benefits on the basis of information obtained through the ex parte renewal process without first contacting the beneficiary and offering them an opportunity to provide new information. What problem did the audit work identify? The Department reported to us that they were not in compliance with eligibility requirements related to the ex parte renewal process during Fiscal Year 2024. As CMS worked with individual states on their COVID-19 unwinding plans, they identified 29 states that were not in compliance with certain ex parte renewal requirements for Medicaid and CBHP beneficiaries, including Colorado. The Department was inappropriately conducting ex parte renewals at the household level rather than individual level, without using individually-specific eligibility statutes and income thresholds for individuals within the household. Specifically, if eligibility could not be renewed on an ex parte basis for at least one member of a household, renewal forms were sent to the entire household. If the renewal forms were returned, the appropriate eligibility determinations were made and those who are eligible were approved. If the renewal forms were not returned, the Department’s eligibility system, the Colorado Benefits Management System (CBMS), would disenroll all individuals in the household, including any who may have been determined to be eligible through the ex parte process. Why did this problem occur? In August 2023, CMS instructed all states to review their ex parte renewal process to assess compliance with federal requirements to complete eligibility redeterminations based on the available information for each individual in the household, regardless of the eligibility of others in the household unit. States that identified any areas of noncompliance were required to (1) pause terminations for any ex parte renewal processes that are not compliant with federal guidance and whose coverage may be terminated inappropriately; (2) reinstate coverage for all affected individuals who have been disenrolled due to a failure to complete redeterminations based on the available information for each individual in the household; (3) fix the state’s systems and processes to ensure that redeterminations are conducted appropriately; and (4) implement a mitigation strategy to prevent continued inappropriate terminations until the state has fixed all systems and processes to be in compliance with federal renewal requirements. States were required to submit the state’s plan and timeline for remediation to CMS. In September 2023, the Department reported to CMS that it was not fully in compliance with the federal requirements for determining eligibility for each individual in the household, and it submitted a mitigation plan and timeline to fix the CBMS system and Department’s processes to ensure that redeterminations were conducted appropriately in the future. As part of the Department’s mitigation plan, automatic terminations of any households who did not return a renewal form were temporarily paused until a short-term system fix was put in place. In October 2023, a CBMS fix was put into place for households that did not return their renewal forms. CBMS continued to send renewal forms to households requesting additional information; however, for any multi-member household that did not return its form, the Department started reviewing eligibility for all members of the household individually. This short-term system fix brought the Department into compliance with federal ex parte renewal requirements. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with targeted implementation by December 2026. Why does this problem matter? When the Department is out of compliance with federal requirements, such as Medicaid requirements, the Department risks sanctions and/or other penalties. After CMS identified the Department’s noncompliance related to the Medicaid ex parte renewal issue, the Department researched the issue and identified 7,510 individuals who were incorrectly disenrolled from Medicaid or CBHP during the period May 2023 to October 2023. In November 2023, the Department retroactively reinstated these individuals’ eligibility back to the date at which their household was terminated, without a gap in coverage. In addition, the individuals were notified that their coverage had been reinstated and provided information on how to obtain payment for unpaid medical bills and/or ensure that any eligible service during the period that the individual was disenrolled were covered. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-033 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by continuing to implement the Colorado Benefits Management System change related to the ex parte eligibility process to ensure that eligibility is determined on an individual rather than household basis, as required. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations. Colorado will continue its approved Centers for Medicare and Medicaid mitigation plan to ensure that eligibility is determined on an individual rather than a household basis. The Department will continue to conduct ex parte reviews to determine eligibility for all household members based on available information. Those members identified as eligible at ex parte will be approved, regardless if others in the household continue to need verifications or are no longer eligible. The Department is currently working on a permanent system change for CBMS that will only send out renewal forms for individuals not eligible through the ex parte process, with implementation by December 2026.
Finding 2024-034 Compliance with Eligibility for Medicaid The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to Medicaid beneficiaries. The caseworker enters the applicant’s information into CBMS and, once all required information is entered, they can mark the application as complete. At that point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2024. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2024. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2024. We obtained a listing of Medicaid claims, totaling $11,542,679,377, that were submitted by providers and paid by the Department during Fiscal Year 2024 on behalf of 2,906,773 individual beneficiaries. From that listing we selected 60 beneficiaries to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? We identified errors in 7 of the 60 Medicaid case files tested (12 percent). These errors resulted in a total of $328 in known questioned costs for Fiscal Year 2024, as follows: Details of Errors Identified. Specifically, we found the following: • Timely Processing. In 1 case, the caseworker processed the application in 141 days, or 96 days after the required timeframe of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. State regulation [10 CCR 2505-10, 8.100.3.D] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination and 45 days for all other applications. • Income and/or Resource Issues. We identified the following 4 income and/or resource-related issues: o In 1 case, the caseworker excluded resources when they should have been included when determining eligibility. This individual was requesting eligibility for the Home and Community Based Services (HCBS) program, which has a $2,000 resource limit. No questioned costs were identified in this instance because the correct income threshold was still within federal and state guidelines. o In 1 case, reportable income was incorrectly excluded when determining the beneficiary’s eligibility. No questioned costs were identified in this instance because the beneficiary’s eligibility was still within federal and state guidelines. o In 1 case, the resource threshold was left blank in the beneficiary’s resource verification. The individual was requesting eligibility for the HCBS program, which has a $2,000 resource limit. No questioned costs were identified in this instance because the correct resource amounts were still within federal and state guidelines. o In 1 case, the incorrect income threshold was used when determining eligibility. Specifically, the income standard used in the calculation was effective for Fiscal Year 2023 instead of the updated Fiscal Year 2024 income standard. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. Federal regulations [42 CFR 435.119] require household income to be at or below 133 percent threshold of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.G.4] notes adults applying for medical assistance shall be determined financially eligible for medical assistance as long as their total household income does not exceed 133% of the federal poverty level. State regulation [10 CCR 2505-10, 8-100.5.M] notes that the resource limit for individuals receiving Home and Community Based Services assistance is $2,000. • Missing Case File Documentation. In 3 cases, we determined the case file did not have at least 1 piece of documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations, including the following: o In 2 cases, documentation to support the applicant’s completed application for assistance was missing. No questioned costs were identified in this instance because the individuals did not have any claims after the eligibility determination was made. o In 1 case, documentation to support the applicant’s resource calculation was missing. No questioned costs were identified in this instance because the Department was ultimately able to provide support confirming the applicant was below the resource threshold. o In 1 case, documentation used to support income and/or resources, such as wage stubs or bank statements, was missing. This resulted in known questioned costs of $328. Federal regulation [420 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. State regulation [10 CCR 2505-10-8.100.4.B] further specifies that applicants seeking Medical Assistance shall provide a Social Security Number, as well as verification of citizenship and identity. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. Why did these problems occur? We determined that the Department did not have adequate internal controls over Medicaid eligibility to ensure caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for processing applications timely, using the correct income and resource thresholds to determine eligibility, and ensuring that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-034 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income and resource thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department-approved Corrective Action Plan that identifies and addresses the root causes of each finding. The Department is also facilitating a change to our current HCPF county administration rules that sets standards that require adequate internal training for system access, state-identified ongoing, mandatory trainings, the certification of county trainers by the state and pre-approval of county training materials. These rule changes have an effective date of July 2025 and will help all counties to improve the accuracy and reduce variability of eligibility determination performance. Additionally, the Joint Agency Interoperability project, which procures a single, unified workload and document management system for all counties, is on track for implementation in 2026-2027. This system will help ensure the appropriate documentation for eligibility determination is retained.
Show full finding ▾Hide full finding ▴Finding 2024-034 Compliance with Eligibility for Medicaid The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to Medicaid beneficiaries. The caseworker enters the applicant’s information into CBMS and, once all required information is entered, they can mark the application as complete. At that point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2024. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2024. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2024. We obtained a listing of Medicaid claims, totaling $11,542,679,377, that were submitted by providers and paid by the Department during Fiscal Year 2024 on behalf of 2,906,773 individual beneficiaries. From that listing we selected 60 beneficiaries to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? We identified errors in 7 of the 60 Medicaid case files tested (12 percent). These errors resulted in a total of $328 in known questioned costs for Fiscal Year 2024, as follows: Details of Errors Identified. Specifically, we found the following: • Timely Processing. In 1 case, the caseworker processed the application in 141 days, or 96 days after the required timeframe of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. State regulation [10 CCR 2505-10, 8.100.3.D] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination and 45 days for all other applications. • Income and/or Resource Issues. We identified the following 4 income and/or resource-related issues: o In 1 case, the caseworker excluded resources when they should have been included when determining eligibility. This individual was requesting eligibility for the Home and Community Based Services (HCBS) program, which has a $2,000 resource limit. No questioned costs were identified in this instance because the correct income threshold was still within federal and state guidelines. o In 1 case, reportable income was incorrectly excluded when determining the beneficiary’s eligibility. No questioned costs were identified in this instance because the beneficiary’s eligibility was still within federal and state guidelines. o In 1 case, the resource threshold was left blank in the beneficiary’s resource verification. The individual was requesting eligibility for the HCBS program, which has a $2,000 resource limit. No questioned costs were identified in this instance because the correct resource amounts were still within federal and state guidelines. o In 1 case, the incorrect income threshold was used when determining eligibility. Specifically, the income standard used in the calculation was effective for Fiscal Year 2023 instead of the updated Fiscal Year 2024 income standard. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. Federal regulations [42 CFR 435.119] require household income to be at or below 133 percent threshold of the federal poverty level. State regulation [10 CCR 2505-10, 8.100.4.G.4] notes adults applying for medical assistance shall be determined financially eligible for medical assistance as long as their total household income does not exceed 133% of the federal poverty level. State regulation [10 CCR 2505-10, 8-100.5.M] notes that the resource limit for individuals receiving Home and Community Based Services assistance is $2,000. • Missing Case File Documentation. In 3 cases, we determined the case file did not have at least 1 piece of documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations, including the following: o In 2 cases, documentation to support the applicant’s completed application for assistance was missing. No questioned costs were identified in this instance because the individuals did not have any claims after the eligibility determination was made. o In 1 case, documentation to support the applicant’s resource calculation was missing. No questioned costs were identified in this instance because the Department was ultimately able to provide support confirming the applicant was below the resource threshold. o In 1 case, documentation used to support income and/or resources, such as wage stubs or bank statements, was missing. This resulted in known questioned costs of $328. Federal regulation [420 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. State regulation [10 CCR 2505-10-8.100.4.B] further specifies that applicants seeking Medical Assistance shall provide a Social Security Number, as well as verification of citizenship and identity. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. Why did these problems occur? We determined that the Department did not have adequate internal controls over Medicaid eligibility to ensure caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for processing applications timely, using the correct income and resource thresholds to determine eligibility, and ensuring that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-034 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income and resource thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2026 The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department-approved Corrective Action Plan that identifies and addresses the root causes of each finding. The Department is also facilitating a change to our current HCPF county administration rules that sets standards that require adequate internal training for system access, state-identified ongoing, mandatory trainings, the certification of county trainers by the state and pre-approval of county training materials. These rule changes have an effective date of July 2025 and will help all counties to improve the accuracy and reduce variability of eligibility determination performance. Additionally, the Joint Agency Interoperability project, which procures a single, unified workload and document management system for all counties, is on track for implementation in 2026-2027. This system will help ensure the appropriate documentation for eligibility determination is retained.
The Department agrees to strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department approved Corrective Action Plan that identifies and addresses the root causes of each finding. The Department is also facilitating a change to our current HCPF county administration rules that sets standards that require adequate internal training for system access, state-identified ongoing, mandatory trainings, the certification of county trainers by the state and pre-approval of county training materials. These rule changes have an effective date of July 2025 and will help all counties to improve the accuracy and reduce variability of eligibility determination performance. Additionally, the Joint Agency Interoperability project, which procures a single, unified workload and document management system for all counties, is on track for implementation in 2026-2027. This system will help ensure the appropriate documentation for eligibility determination is retained.
Finding 2024-035 Compliance with Eligibility for CBHP The Department is responsible for ensuring that all federal Children’s Health Insurance Plan (CHIP) expenditures are appropriate, and that the State complies with federal and state program requirements. Colorado’s state-run children’s health plan, the Children’s Basic Health Plan (CBHP), is partially funded with federal CHIP dollars. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff with copies of its Department-prepared policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities (MCEs), which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. All CBHP members are enrolled into an MCE plan as soon as the member’s eligibility determination is made. The specific MCE plan is based on the county the member lives in. Capitation payments are lump-sum monthly payments made to MCEs based on the number of eligible beneficiaries enrolled in its plan; the MCEs then contract with a network of providers to provide Medicaid and CBHP services. The service providers are then paid by the MCE. Capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2024. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2024. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving CBHP benefits during Fiscal Year 2024. We obtained a listing of CBHP claims, totaling $176,890,370, that were submitted by providers and paid by the Department during Fiscal Year 2024 on behalf of 148,009 individual beneficiaries. From that listing we selected 60 beneficiaries to determine whether those individuals’ CBHP eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? We identified at least one error in 8 of the 60 CBHP case files tested (13 percent). These errors resulted in a total of $1,083 in known questioned costs for Fiscal Year 2024. Specifically, we found the following: • Missing Case File Documentation. In 5 cases, we determined the case file did not have at least 1 piece of documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations, including the following: o In 1 case, documentation to support the applicant’s completed application for assistance was missing. No questioned costs were identified in this instance because the individual did not have any claims after the eligibility determination was made. o In 4 cases, documentation to support income, such as wage stubs, was missing. This resulted in known questioned costs of $919. o In 1 case, documentation to support citizenship, such as a birth certificate or other allowable records, was missing. This resulted in known questioned costs of $164. Federal regulations [42 CFR 457.965] note that the state must include in each applicant’s record facts to support the state’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the Children’s Basic Health Plan, an eligible person shall have a household income greater than 142 percent but not exceeding 260 percent of the Federal Poverty Level, adjusted for household size for children under the age of 19. State regulation [10 CCR 2505-3.130] notes that, to be eligible for the Children’s Basic Health Plan, an applicant shall provide minimal verification as required in 10 CCR 2505-10-8.100.4.B. State regulation [10 CCR 2505-10-8.100.4.B] further specifies that applicants seeking Medical Assistance (Medicaid or Children’s Basic Health Plan services) shall provide a Social Security Number, as well as verification of citizenship and identity. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. • Incorrect Income Threshold or Income Calculation. In 3 cases, we determined that the incorrect income threshold was used or the incorrect income amount was calculated for the beneficiary’s eligibility determinations. Specifically, we found the following: o In 1 case, the income threshold was left blank in the beneficiary’s income verification. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. o In 1 case, the incorrect income threshold was used because the incorrect number of household members was entered into CBMS. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. o In 1 case, reportable income was incorrectly excluded when determining the beneficiary’s eligibility. No questioned costs were identified in this instance because the beneficiaries’ income was still within federal and state guidelines. State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the Children’s Basic Health Plan, an eligible person shall have a household income greater than 142 percent but not exceeding 260 percent of the Federal Poverty Level, adjusted for household size for children under the age of 19. State regulation [10 CCR 2505-3.150.1] notes that the calculation of income for the Children’s Basic Health Plan shall be determined as required in 10 CCR 2505-10-8-100.4.C. State regulation [10 CCR 2505-8.100.4.C] notes that the Modified Adjusted Gross Income calculation for the purposes of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. Why did these problems occur? We determined that the Department did not have adequate internal controls over CBHP eligibility to ensure caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that the required documentation to support eligibility was maintained within the case file, and that the correct income thresholds were used to determine eligibility. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-035 The Department of Health Care Policy and Financing should strengthen its internal controls over the Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained to maintain the required documentation to support eligibility in the case file and use the correct income thresholds to determine eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2026 The Department agrees to strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department-approved Corrective Action Plan that identifies and addresses the root causes of each finding.
Show full finding ▾Hide full finding ▴Finding 2024-035 Compliance with Eligibility for CBHP The Department is responsible for ensuring that all federal Children’s Health Insurance Plan (CHIP) expenditures are appropriate, and that the State complies with federal and state program requirements. Colorado’s state-run children’s health plan, the Children’s Basic Health Plan (CBHP), is partially funded with federal CHIP dollars. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying an applicant’s eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff with copies of its Department-prepared policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities (MCEs), which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. All CBHP members are enrolled into an MCE plan as soon as the member’s eligibility determination is made. The specific MCE plan is based on the county the member lives in. Capitation payments are lump-sum monthly payments made to MCEs based on the number of eligible beneficiaries enrolled in its plan; the MCEs then contract with a network of providers to provide Medicaid and CBHP services. The service providers are then paid by the MCE. Capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process, as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2024. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2024. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving CBHP benefits during Fiscal Year 2024. We obtained a listing of CBHP claims, totaling $176,890,370, that were submitted by providers and paid by the Department during Fiscal Year 2024 on behalf of 148,009 individual beneficiaries. From that listing we selected 60 beneficiaries to determine whether those individuals’ CBHP eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. What problems did the audit work identify and how were the results measured? We identified at least one error in 8 of the 60 CBHP case files tested (13 percent). These errors resulted in a total of $1,083 in known questioned costs for Fiscal Year 2024. Specifically, we found the following: • Missing Case File Documentation. In 5 cases, we determined the case file did not have at least 1 piece of documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations, including the following: o In 1 case, documentation to support the applicant’s completed application for assistance was missing. No questioned costs were identified in this instance because the individual did not have any claims after the eligibility determination was made. o In 4 cases, documentation to support income, such as wage stubs, was missing. This resulted in known questioned costs of $919. o In 1 case, documentation to support citizenship, such as a birth certificate or other allowable records, was missing. This resulted in known questioned costs of $164. Federal regulations [42 CFR 457.965] note that the state must include in each applicant’s record facts to support the state’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the Children’s Basic Health Plan, an eligible person shall have a household income greater than 142 percent but not exceeding 260 percent of the Federal Poverty Level, adjusted for household size for children under the age of 19. State regulation [10 CCR 2505-3.130] notes that, to be eligible for the Children’s Basic Health Plan, an applicant shall provide minimal verification as required in 10 CCR 2505-10-8.100.4.B. State regulation [10 CCR 2505-10-8.100.4.B] further specifies that applicants seeking Medical Assistance (Medicaid or Children’s Basic Health Plan services) shall provide a Social Security Number, as well as verification of citizenship and identity. Earned income must be verified by wage stubs, tax documents, written documentation from the employer stating the employee’s gross income, or through a telephone call to an employer. • Incorrect Income Threshold or Income Calculation. In 3 cases, we determined that the incorrect income threshold was used or the incorrect income amount was calculated for the beneficiary’s eligibility determinations. Specifically, we found the following: o In 1 case, the income threshold was left blank in the beneficiary’s income verification. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. o In 1 case, the incorrect income threshold was used because the incorrect number of household members was entered into CBMS. No questioned costs were identified in this instance because the beneficiary’s income was less than the corrected income threshold. o In 1 case, reportable income was incorrectly excluded when determining the beneficiary’s eligibility. No questioned costs were identified in this instance because the beneficiaries’ income was still within federal and state guidelines. State regulation [10 CCR 2505-3.110.1.E] notes that, to be eligible for the Children’s Basic Health Plan, an eligible person shall have a household income greater than 142 percent but not exceeding 260 percent of the Federal Poverty Level, adjusted for household size for children under the age of 19. State regulation [10 CCR 2505-3.150.1] notes that the calculation of income for the Children’s Basic Health Plan shall be determined as required in 10 CCR 2505-10-8-100.4.C. State regulation [10 CCR 2505-8.100.4.C] notes that the Modified Adjusted Gross Income calculation for the purposes of determining a household’s financial eligibility shall consist of, but is not limited to, earned income in the form of wages, salaries, and tips. Why did these problems occur? We determined that the Department did not have adequate internal controls over CBHP eligibility to ensure caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers were not adequately trained or held accountable for ensuring that the required documentation to support eligibility was maintained within the case file, and that the correct income thresholds were used to determine eligibility. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-035 The Department of Health Care Policy and Financing should strengthen its internal controls over the Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained to maintain the required documentation to support eligibility in the case file and use the correct income thresholds to determine eligibility. Response Department of Health Care Policy and Financing Agree Implementation Date: February 2026 The Department agrees to strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department-approved Corrective Action Plan that identifies and addresses the root causes of each finding.
The Department agrees to strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the findings identified in the audit. The Department will issue formal Management Decision Letters for the identified counties. The Management Decision Letters require the counties to develop and implement a Department-approved Corrective Action Plan that identifies and addresses the root causes of each finding.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-053 Medicaid Controls Over Eligibility Determinations The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. If the application is complete, the caseworker enters the information into CBMS, at which point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a listing of 106,314 beneficiaries who were determined to be newly eligible and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 63 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the first 3 quarters of the fiscal year. From that listing we selected 38 beneficiaries (63 percent of the total sample) to determine whether those individuals’ Medicaid eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 62,296 beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 37 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the last quarter of the fiscal year. From that list, we selected 22 beneficiaries (37 percent of the total sample), to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our Fiscal Year 2020 audit recommendation related to Medicaid eligibility. During the prior audit, we recommended the Department strengthen its internal controls over Medicaid by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 3 of the 60 Medicaid case files tested (5 percent). These errors resulted in a total of $95 in known questioned costs for Fiscal Year 2023, as shown below. Details of Errors Identified. Specifically, we found the following: • Timely Processing. In one case, the caseworker processed the application in 73 days, or 28 days after the required time frame of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. o State regulation [10 CCR 2505-10, 8.100.3.D.] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination, and 45 days for all other applications. • Incorrect Income Threshold. In one case, CBMS used the incorrect income threshold for the beneficiary’s eligibility determination. Specifically, CBMS used the income standard that was effective for Fiscal Year 2022 instead of the updated Fiscal Year 2023 income standard. The beneficiary’s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. o Federal regulation [42 USC 1395w-114] requires an individual to meet income limits in order to receive Medicaid benefits. • Missing Case File Documentation. In one case, we determined the case file did not have the documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, the case file was missing a copy of the beneficiary’s birth certificate, or other evidence that the individual was a qualified non-citizen when processing the application. This resulted in known questioned costs of $95. o Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. o State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, use the correct income thresholds to determine eligibility, and ensure that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-053 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-053 Medicaid Controls Over Eligibility Determinations The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. If the application is complete, the caseworker enters the information into CBMS, at which point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a listing of 106,314 beneficiaries who were determined to be newly eligible and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 63 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the first 3 quarters of the fiscal year. From that listing we selected 38 beneficiaries (63 percent of the total sample) to determine whether those individuals’ Medicaid eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 62,296 beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 37 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the last quarter of the fiscal year. From that list, we selected 22 beneficiaries (37 percent of the total sample), to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our Fiscal Year 2020 audit recommendation related to Medicaid eligibility. During the prior audit, we recommended the Department strengthen its internal controls over Medicaid by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 3 of the 60 Medicaid case files tested (5 percent). These errors resulted in a total of $95 in known questioned costs for Fiscal Year 2023, as shown below. Details of Errors Identified. Specifically, we found the following: • Timely Processing. In one case, the caseworker processed the application in 73 days, or 28 days after the required time frame of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. o State regulation [10 CCR 2505-10, 8.100.3.D.] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination, and 45 days for all other applications. • Incorrect Income Threshold. In one case, CBMS used the incorrect income threshold for the beneficiary’s eligibility determination. Specifically, CBMS used the income standard that was effective for Fiscal Year 2022 instead of the updated Fiscal Year 2023 income standard. The beneficiary’s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. o Federal regulation [42 USC 1395w-114] requires an individual to meet income limits in order to receive Medicaid benefits. • Missing Case File Documentation. In one case, we determined the case file did not have the documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, the case file was missing a copy of the beneficiary’s birth certificate, or other evidence that the individual was a qualified non-citizen when processing the application. This resulted in known questioned costs of $95. o Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. o State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, use the correct income thresholds to determine eligibility, and ensure that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-053 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file.
Mesa County participates in the State Electronic Document imaging system to save and retain case file documentation. In the monthly monitoring performed from May to December 2024, Mesa had 9 cases reviewed and was only cited with one error impacting eligibility. Implemented January 2025.
2023-053
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-054 Children’s Basic Health Plan Controls Over Eligibility Determinations The Department is responsible for ensuring that all federal CBHP expenditures are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits in person at their local county departments of human/social services and designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants’ eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff copies of all policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. Capitation payments are lump-sum monthly payments made to managed care entities, which contract with providers for services. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. During the COVID-19 PHE, the State was required to maintain continuous enrollment for CBHP- eligible beneficiaries enrolled as of March 1, 2020. The CCA—enacted December 2022 and taking effect April 1, 2023—ended the continuous enrollment condition on March 31, 2023, which meant the State could begin the unwinding process, returning to normal eligibility and enrollment operations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random, non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a list from the Department of 7,978 beneficiaries who were determined to be newly-eligible for CBHP during this period and who had a capitation payment made on their behalf to a CBHP provider between July 1, 2022 and March 31, 2023. From that listing we selected 45 beneficiaries (75 percent of the total sample) to determine whether those individuals’ CBHP eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 3,006 existing CBHP beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a capitation payment made on their behalf to a CBHP provider between April 1, 2023 and June 30, 2023. From that list, we selected 15 beneficiaries (25 percent of the total sample)—whose eligibility was ultimately reapproved during the renewal unwinding process—to determine whether those individuals’ CBHP eligibility determination or redetermination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to CBHP eligibility. During our Fiscal Year 2020 audit, we reported that the Department lacked sufficient internal controls to ensure that it complied with federal and state eligibility requirements. At that time, we recommended that the Department strengthen its internal controls over CBHP by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 6 of the 60 CBHP case files tested (10 percent). These errors resulted in a total of $7,912 in known questioned costs for Fiscal Year 2023. Specifically, we found the following: • Timely Processing. In 3 cases, the caseworkers did not process the application within the 45-day requirement. One case was processed 48 days late, one case was 34 days late, and the third case was 4 days late. No questioned costs were identified in these instances because the beneficiaries were appropriately approved for benefits. o State regulation [10 CCR 2505-3, 170.4] notes that eligibility sites shall make an eligibility determination within 45 days from the date of the application. • Ineligible for Program. In two cases, beneficiaries with third-party health insurance at the time of application were not determined ineligible, as required. This error resulted in known questioned costs of $6,361. o State regulation [10 CCR 2505-3, 120.1.A] notes that in order to be eligible for the CBHP program, an eligible person shall not be covered under a group health plan or under health insurance coverage, excluding coverage under the Consolidated Omnibus Budget Reconciliation Act (COBRA). • Missing Case Documentation. One case file was missing documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, the case file was missing support for the applicant’s income. This error resulted in known questioned costs of $1,551. o Federal regulation [42 CFR 457.965] notes the state must include in each applicant’s record facts to support the State’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. o State regulation [10 CCR 2505-3, 110.1] requires all individuals who apply for CBHP to have a household income not exceeding 260 percent of the Federal Poverty Level, adjusted for household size. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, confirm that applicants were not covered under other health insurance, and ensure that the required eligibility documentation was maintained within the case file. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that processing of information used to determine CBHP eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or eligible individuals being denied benefits. Ultimately, the federal government may disallow federal funds for CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-054 The Department of Health Care Policy and Financing should strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-054 Children’s Basic Health Plan Controls Over Eligibility Determinations The Department is responsible for ensuring that all federal CBHP expenditures are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits in person at their local county departments of human/social services and designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants’ eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff copies of all policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. Capitation payments are lump-sum monthly payments made to managed care entities, which contract with providers for services. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. During the COVID-19 PHE, the State was required to maintain continuous enrollment for CBHP- eligible beneficiaries enrolled as of March 1, 2020. The CCA—enacted December 2022 and taking effect April 1, 2023—ended the continuous enrollment condition on March 31, 2023, which meant the State could begin the unwinding process, returning to normal eligibility and enrollment operations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random, non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a list from the Department of 7,978 beneficiaries who were determined to be newly-eligible for CBHP during this period and who had a capitation payment made on their behalf to a CBHP provider between July 1, 2022 and March 31, 2023. From that listing we selected 45 beneficiaries (75 percent of the total sample) to determine whether those individuals’ CBHP eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 3,006 existing CBHP beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a capitation payment made on their behalf to a CBHP provider between April 1, 2023 and June 30, 2023. From that list, we selected 15 beneficiaries (25 percent of the total sample)—whose eligibility was ultimately reapproved during the renewal unwinding process—to determine whether those individuals’ CBHP eligibility determination or redetermination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to CBHP eligibility. During our Fiscal Year 2020 audit, we reported that the Department lacked sufficient internal controls to ensure that it complied with federal and state eligibility requirements. At that time, we recommended that the Department strengthen its internal controls over CBHP by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 6 of the 60 CBHP case files tested (10 percent). These errors resulted in a total of $7,912 in known questioned costs for Fiscal Year 2023. Specifically, we found the following: • Timely Processing. In 3 cases, the caseworkers did not process the application within the 45-day requirement. One case was processed 48 days late, one case was 34 days late, and the third case was 4 days late. No questioned costs were identified in these instances because the beneficiaries were appropriately approved for benefits. o State regulation [10 CCR 2505-3, 170.4] notes that eligibility sites shall make an eligibility determination within 45 days from the date of the application. • Ineligible for Program. In two cases, beneficiaries with third-party health insurance at the time of application were not determined ineligible, as required. This error resulted in known questioned costs of $6,361. o State regulation [10 CCR 2505-3, 120.1.A] notes that in order to be eligible for the CBHP program, an eligible person shall not be covered under a group health plan or under health insurance coverage, excluding coverage under the Consolidated Omnibus Budget Reconciliation Act (COBRA). • Missing Case Documentation. One case file was missing documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, the case file was missing support for the applicant’s income. This error resulted in known questioned costs of $1,551. o Federal regulation [42 CFR 457.965] notes the state must include in each applicant’s record facts to support the State’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. o State regulation [10 CCR 2505-3, 110.1] requires all individuals who apply for CBHP to have a household income not exceeding 260 percent of the Federal Poverty Level, adjusted for household size. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, confirm that applicants were not covered under other health insurance, and ensure that the required eligibility documentation was maintained within the case file. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that processing of information used to determine CBHP eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or eligible individuals being denied benefits. Ultimately, the federal government may disallow federal funds for CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-054 The Department of Health Care Policy and Financing should strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file.
The Department worked with each Eligibility site to resolve these errors and assist with the implementation. Effective July 2022, the Connect for Health Colorado phone application attestation recording is saved within Salesforce and held for perpetuity. Montrose and Routte counties participate in the State Electronic Document imaging system to save and retain case file documentation. Denver County internally trains its staff when errors are found and uses its in-house Electronic Document Management System. In the monthly monitoring performed from May to December 2024, Routte had 6 cases reviewed and Montrose one case reviewed and both were cited with zero errors impacting eligibility and Denver had 16 cases reviewed and was cited with four errors impacting eligibility. Implemented January 2025.
2023-054
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-055 Medicaid Eligibility—Social Security Numbers Associated with Multiple State IDs Each beneficiary’s Medicaid application must contain specific information, including the beneficiary’s Social Security Number (SSN), a copy of their birth certificate, and support for their income in order for a caseworker to determine their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS and approving or denying an applicant’s eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD)—managed by the Governor’s Office of Information Technology (OIT)—assigns a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary’s eligibility status or termination of benefits. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary’s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating a SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including determining the Department’s progress in implementing our Fiscal Year 2021 audit recommendation related to this area. At that time, we recommended the Department ensure only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. Specifically, we recommended the Department improve its internal controls in this area by continuing to develop a report that can be used to identify SSNs associated with multiple State IDs, and then establishing and implementing written policies and procedures to outline how the Department will use the report to effectively monitor and correct those discrepancies. As part of our testing, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. We requested a list of all Medicaid claims that were submitted by providers and paid by the Department for the fiscal year, including the beneficiaries’ names, SSNs, and State IDs. The Department provided a list that included approximately 1.4 million beneficiaries who received benefits during the fiscal year. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries for Fiscal Year 2023. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires that the Department obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within 1 year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b], states have up to 1 year from the date of the overpayment discovery to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities for its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation to improve its internal controls over Medicaid eligibility to ensure it is monitoring and correcting any instances of multiple State IDs associated with the same SSN. During our testing, we identified 200 unique SSNs that each appeared to be inappropriately associated with two State IDs; in total, the 200 SSNs were tied to 400 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN. Specifically, we found the following: • 108 SSNs were tied to 2 separate State IDs (representing 216 potential beneficiaries) that appeared to be for different people based on the names and/or dates of birth. These could represent invalid claims payments on behalf of ineligible beneficiaries. • 92 SSNs were tied to two separate State IDs (representing 184 potential beneficiaries) that had the same name and date of birth. These SSNs could be valid, but with more than 1 State ID, a provider could submit and have a claim paid for the same services under both State IDs. We did not identify any instances of individual SSNs being tied to more than 2 State IDs. These issues affected a total of 400 Medicaid State IDs that had not been corrected as of June 30, 2023, and represented a total of $71,441 Medicaid claims paid through Colorado interChange for Fiscal Year 2023. We selected a random, non-statistical sample of 12 SSN pairs (24 different State IDs) identified in our testing, representing $6,050 in Medicaid claims, and provided the sample to the Department to research. The Department determined, and we confirmed, that as of the end of our audit in December 2023, payments made for 9 of the 12 SSN pairs were made on behalf of eligible beneficiaries. Of the 9 pairs, 4 had instances where an individual had incorrect information entered into CBMS. The remaining 5 SSN pairs each represented a single beneficiary, but with 2 separate Medicaid IDs that need to be merged within CBMS so that each beneficiary only has one unique Medicaid ID. In total, these 9 sample pairs represented $2,224 of the $6,050 sample. The other 3 SSN pairs in our sample, totaling $3,826, had at least 1 instance of a SSN not being verified when input into CBMS; therefore, we consider these amounts to be known questioned costs. Of these costs, $2,105 were paid with federal grant funds. We were unable to determine whether the payments in the remaining 188 SSNs that were each tied to 2 State IDs were made on behalf of eligible Medicaid beneficiaries; therefore, we consider the entire $65,391 in Medicaid claims payments to be likely questioned costs. Of these costs, $36,604 were paid with federal grant funds. The breakdown of costs we questioned are shown in the following table: A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards] (Uniform Guidance), is “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation….” We have identified these questioned costs as “known questioned costs” that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place to prevent or detect and correct all instances of multiple State IDs associated with a single SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. In addition, we determined that the Department did not fully implement our prior audit recommendation related to developing a report to identify single SSNs associated with multiple State IDs, and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. Specifically, the Department deployed a dashboard report in April 2023, but it did not provide enough detail for caseworkers to be able to effectively monitor and correct SSN and State ID discrepancies. In addition, Department staff reported they have not yet finalized written guidance on how to use the dashboard report at either the Department or county and MA-site level to identify and resolve discrepancies. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to instances in which multiple State IDs are associated with a single SSN. For example, without adequate controls in place to prevent multiple State IDs from being created or to identify and correct these instances, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-055 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Colorado’s Medicaid Program eligibility by: A. Researching the remaining questioned claims payments that were identified during our audit to determine whether the local counties or Medical Assistance (MA) sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate—in accordance with federal regulation at the time the payments were made—and repaying the federal government for any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify instances of single SSNs associated with multiple State IDs that, once complete, can be used to monitor that caseworkers are addressing any identified discrepancies in a timely manner. C. Continuing to establish and implement written policies and procedures outlining how the Department and MA sites will use the report to effectively monitor and correct SSN and State ID discrepancies. The Department’s policies and procedures should include information on the report itself, such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, and how to identify when additional training may be needed for local counties and MA sites; the MA site policies and procedures should include information on how to read and use the report to identify and correct discrepancies. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department’s system, that provider is guaranteed payment if they render an authorized service. Auditor’s Addendum The Department is responsible for ensuring that only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount, and must be repaid to the federal government within 1 year. Eligibility errors include ineligible individuals who were authorized as eligible when they received services [42 CFR 431.960d(2)(i)]. B. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. C. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. The Department will issue guidance such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, how to identify when additional training may be needed for local counties and MA sites and information on how to read and use the report and identify and correct discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-055 Medicaid Eligibility—Social Security Numbers Associated with Multiple State IDs Each beneficiary’s Medicaid application must contain specific information, including the beneficiary’s Social Security Number (SSN), a copy of their birth certificate, and support for their income in order for a caseworker to determine their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS and approving or denying an applicant’s eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD)—managed by the Governor’s Office of Information Technology (OIT)—assigns a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary’s eligibility status or termination of benefits. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary’s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating a SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including determining the Department’s progress in implementing our Fiscal Year 2021 audit recommendation related to this area. At that time, we recommended the Department ensure only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. Specifically, we recommended the Department improve its internal controls in this area by continuing to develop a report that can be used to identify SSNs associated with multiple State IDs, and then establishing and implementing written policies and procedures to outline how the Department will use the report to effectively monitor and correct those discrepancies. As part of our testing, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. We requested a list of all Medicaid claims that were submitted by providers and paid by the Department for the fiscal year, including the beneficiaries’ names, SSNs, and State IDs. The Department provided a list that included approximately 1.4 million beneficiaries who received benefits during the fiscal year. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries for Fiscal Year 2023. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires that the Department obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within 1 year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b], states have up to 1 year from the date of the overpayment discovery to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities for its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation to improve its internal controls over Medicaid eligibility to ensure it is monitoring and correcting any instances of multiple State IDs associated with the same SSN. During our testing, we identified 200 unique SSNs that each appeared to be inappropriately associated with two State IDs; in total, the 200 SSNs were tied to 400 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN. Specifically, we found the following: • 108 SSNs were tied to 2 separate State IDs (representing 216 potential beneficiaries) that appeared to be for different people based on the names and/or dates of birth. These could represent invalid claims payments on behalf of ineligible beneficiaries. • 92 SSNs were tied to two separate State IDs (representing 184 potential beneficiaries) that had the same name and date of birth. These SSNs could be valid, but with more than 1 State ID, a provider could submit and have a claim paid for the same services under both State IDs. We did not identify any instances of individual SSNs being tied to more than 2 State IDs. These issues affected a total of 400 Medicaid State IDs that had not been corrected as of June 30, 2023, and represented a total of $71,441 Medicaid claims paid through Colorado interChange for Fiscal Year 2023. We selected a random, non-statistical sample of 12 SSN pairs (24 different State IDs) identified in our testing, representing $6,050 in Medicaid claims, and provided the sample to the Department to research. The Department determined, and we confirmed, that as of the end of our audit in December 2023, payments made for 9 of the 12 SSN pairs were made on behalf of eligible beneficiaries. Of the 9 pairs, 4 had instances where an individual had incorrect information entered into CBMS. The remaining 5 SSN pairs each represented a single beneficiary, but with 2 separate Medicaid IDs that need to be merged within CBMS so that each beneficiary only has one unique Medicaid ID. In total, these 9 sample pairs represented $2,224 of the $6,050 sample. The other 3 SSN pairs in our sample, totaling $3,826, had at least 1 instance of a SSN not being verified when input into CBMS; therefore, we consider these amounts to be known questioned costs. Of these costs, $2,105 were paid with federal grant funds. We were unable to determine whether the payments in the remaining 188 SSNs that were each tied to 2 State IDs were made on behalf of eligible Medicaid beneficiaries; therefore, we consider the entire $65,391 in Medicaid claims payments to be likely questioned costs. Of these costs, $36,604 were paid with federal grant funds. The breakdown of costs we questioned are shown in the following table: A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards] (Uniform Guidance), is “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation….” We have identified these questioned costs as “known questioned costs” that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place to prevent or detect and correct all instances of multiple State IDs associated with a single SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. In addition, we determined that the Department did not fully implement our prior audit recommendation related to developing a report to identify single SSNs associated with multiple State IDs, and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. Specifically, the Department deployed a dashboard report in April 2023, but it did not provide enough detail for caseworkers to be able to effectively monitor and correct SSN and State ID discrepancies. In addition, Department staff reported they have not yet finalized written guidance on how to use the dashboard report at either the Department or county and MA-site level to identify and resolve discrepancies. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to instances in which multiple State IDs are associated with a single SSN. For example, without adequate controls in place to prevent multiple State IDs from being created or to identify and correct these instances, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-055 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Colorado’s Medicaid Program eligibility by: A. Researching the remaining questioned claims payments that were identified during our audit to determine whether the local counties or Medical Assistance (MA) sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate—in accordance with federal regulation at the time the payments were made—and repaying the federal government for any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify instances of single SSNs associated with multiple State IDs that, once complete, can be used to monitor that caseworkers are addressing any identified discrepancies in a timely manner. C. Continuing to establish and implement written policies and procedures outlining how the Department and MA sites will use the report to effectively monitor and correct SSN and State ID discrepancies. The Department’s policies and procedures should include information on the report itself, such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, and how to identify when additional training may be needed for local counties and MA sites; the MA site policies and procedures should include information on how to read and use the report to identify and correct discrepancies. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department’s system, that provider is guaranteed payment if they render an authorized service. Auditor’s Addendum The Department is responsible for ensuring that only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount, and must be repaid to the federal government within 1 year. Eligibility errors include ineligible individuals who were authorized as eligible when they received services [42 CFR 431.960d(2)(i)]. B. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. C. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. The Department will issue guidance such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, how to identify when additional training may be needed for local counties and MA sites and information on how to read and use the report and identify and correct discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024.
The Department meets with counties, The Colorado Department of Human Services, and the Governor's Office of Information and Technology staff in a weekly Duplicate Social Security Workgroup. The purpose of the group is to resolve duplicate Social Security Numbers by discussing duplicate Social Security reports, answering questions, training, and best practices, and providing written guidance if appropriate for the shared eligibility system (Colorado Benefits Management System). Implemented January 2025.
2023-055
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-056 Presumptive Eligibility for Medicaid and CBHP Colorado’s Medicaid and CBHP presumptive eligibility program is designed to provide eligible individuals—such as children under the age of 19 and pregnant people—immediate, temporary medical coverage of up to 45 days while they wait for caseworkers to process their regular Medicaid or CBHP application and determine their eligibility status. Although there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application and appear eligible to receive temporary benefits while a caseworker is processing their application. The Department works with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE Site) to help manage the application process for individuals needing access to immediate temporary medical coverage. To be certified as a PE Site, the entity must be an existing provider, or have an affiliation with an existing provider, and complete the Presumptive Eligibility General Information Form (Form), which serves as the entity’s application to become a PE Site. Once an entity completes and submits a Form, Department staff review and either approve or deny the application. Final notice of acceptance or denial as an approved PE Site is then sent to the contact person listed on the Form. The PE Site is in charge of helping individuals complete an application and ensuring that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE Site collects the minimum information needed to determine presumptive eligibility, including the applicant’s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which is used to assist the caseworker in determining whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant’s reported information is not in compliance with federal and state requirements, CBMS is programmed to deny the eligibility and mark the applicant’s eligibility as “fail” within CBMS. As a result, the applicant would not be eligible for the payment of services to providers on their behalf through Colorado interChange. Once an applicant’s presumptive eligibility has been determined, the PE Site is required to submit the application along with a transmittal form detailing the beneficiary’s reported information to the appropriate local county or designated MA site within 5 business days, at which point the county or MA site would complete the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. The county or MA site must then make a final eligibility determination within 45 days of the application date. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual’s presumptive eligibility benefits should end. All PE Sites must be certified by the Department to make presumptive eligibility determinations. PE Sites must also recertify with the Department every 2 years to maintain their active status as a certified PE Site. As part of the recertification process, Department staff will audit 5 percent of the applications the PE Site processed during the previous year to confirm that the applicant’s information was correctly entered into CBMS and that the PE Site followed the appropriate guidance when making presumptive eligibility decisions. If the PE Site fails the audit, the Department requires PE Site staff to undergo customized Department training for the areas they failed within 6 months of the review. As of June 30, 2023, there were 50 certified PE Sites. During Fiscal Year 2023, 17 of those PE Sites determined presumptive eligibility for 531 Medicaid cases and 155 CBHP cases. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2023. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to internal controls over presumptive eligibility. Specifically, during the Fiscal Year 2020 audit, we identified problems with the Department’s compliance with applicable federal and state requirements, and recommended that the Department strengthen its internal controls over Medicaid and CBHP presumptive eligibility by developing and implementing (1) a tracking mechanism for monitoring PE Sites; (2) written policies and procedures detailing the requirements for completion of PE Site reviews, timely training for PE Site staff, and timely recertification of PE Sites; and (3) resolving CBMS programming and system issues to appropriately terminate presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP program and ensuring CBMS displays consistent applicant information between various screens. As part of our Fiscal Year 2023 audit, we reviewed the Department’s tracking mechanism for monitoring PE Sites, as well as the Department’s updated policies and procedures for completion of PE Site reviews, training for PE Site staff, and timely recertification of PE Sites. In addition, we inquired with the Department about the CBMS programming issues identified during the audit. Department staff reported they implemented changes within CBMS that would address the programming and system issues identified. As part of our Fiscal Year 2023 audit, we made inquiries with Department staff regarding the policies and procedures for applying to be a PE Site, recertification requirements, and Department site monitoring. During our internal controls testing, we reviewed a listing of all 50 PE Sites and noted that 40 sites were due for recertification in Fiscal Year 2023. We selected six PE Sites that were due for recertification and performed testing to determine whether the sites were appropriately recertified by the Department by performing the following procedures: • We confirmed that the Department had performed the recertification and reviewed the related case file support for all 6 PE Sites in our sample. • We noted that 4 of 6 PE Sites tested passed their recertification. We reviewed the Department’s case file support and confirmed the sites were appropriately recertified and mailed recertification letters from the Department. • The eligibility status for the remaining two PE Sites in our sample was terminated by the Department as part of its recertification review. One site did not complete the required paperwork for the recertification and the other did not have a need to provide PE Site services anymore. We reviewed Department correspondence to these sites to confirm the Department notified them that their PE Site status was terminated. In addition, we randomly selected a sample of 40 Medicaid and 37 CBHP cases for individuals who were deemed presumptively eligible at a PE Site during Fiscal Year 2023 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The Department’s process for presumptive eligibility determinations is the same for both Medicaid and CBHP and, therefore, our testing was used to determine compliance for both programs. What problems did the audit work identify and how were the results measured? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2023. Overall, we identified 8 instances of non-compliance with federal and state regulations over presumptive eligibility requirements at 4 separate PE Sites. Specifically, we identified the following: • Untimely End of Presumptive Eligibility. In 4 of 40 Medicaid (10 percent) and 3 of 37 CBHP cases (8 percent), we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. In these cases, the beneficiary’s presumptive eligibility did not end until between 6 and 31 days after the beneficiary was determined to be eligible for regular Medicaid and CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. • Timeliness of Transmittal Letters. In 1 of 40 Medicaid cases (3 percent), we found that the PE Site determining eligibility did not notify the county within five business days that the applicant was presumptively eligible, as required by state regulation. In this case, notification was made 1 day late. State regulation [10 CCR 2505-10, 8.100.4.F.4)] states that the presumptive eligibility sites are required to notify the local county within 5 business days that the client is presumptively eligible. Why did these problems occur? We determined that the Department’s changes to CBMS to address the programing and system issues identified in our prior audit recommendation did not appropriately terminate beneficiaries’ presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, the Department lacked sufficient internal controls to ensure that it complied with federal and state presumptive eligibility requirements during Fiscal Year 2023. Specifically, the Department did not adequately train PE Site staff on presumptive eligibility requirements and, as a result, they did not properly end presumptive eligibility and process transmittal letters in a timely manner. Why do these problems matter? As the State’s medical assistance agency, it is essential for the Department to ensure that PE Sites’ eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that presumptive eligibility determinations are made correctly and do not result in Medicaid or CBHP benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-056 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Colorado’s Medicaid Program (Medicaid) and the Children’s Basic Health Plan (CBHP) presumptive eligibility by: A. Resolving Colorado Benefits Management System (CBMS) programming and system issues to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP. B. Providing training to presumptive eligibility site staff to emphasize issues that were identified during our audit or that the Department identifies during its ongoing monitoring, including the importance of properly ending presumptive eligibility benefits when the beneficiary is determined to be ineligible for Medicaid and CBHP benefits and processing applications timely. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2023 The Colorado Benefits Management System (CBMS) programming and system discrepancies to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or Children’s Basic Health Plan program was corrected with a data fix in July 2023. The Department found after further research that it is permissible for Presumptive Eligibility Medical Spans and Medical Assistance Medical spans to overlap as these are two separate High level Program groups. Department staff will continue to monitor for future discrepancies. B. Agree Implementation Date: August 2024 The Department will continue to train presumptive eligibility site staff on the errors identified during this audit including processing applications timely, and those errors that the Department identifies during ongoing monitoring. The Colorado Benefits Management System (CBMS) automatically populates benefit end dates when the Eligibility site worker authorizes the Medicaid and CBHP benefits. The Department staff will continue to monitor for these discrepancies and work with the individual Eligibility sites on their application processing timeliness.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-056 Presumptive Eligibility for Medicaid and CBHP Colorado’s Medicaid and CBHP presumptive eligibility program is designed to provide eligible individuals—such as children under the age of 19 and pregnant people—immediate, temporary medical coverage of up to 45 days while they wait for caseworkers to process their regular Medicaid or CBHP application and determine their eligibility status. Although there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application and appear eligible to receive temporary benefits while a caseworker is processing their application. The Department works with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE Site) to help manage the application process for individuals needing access to immediate temporary medical coverage. To be certified as a PE Site, the entity must be an existing provider, or have an affiliation with an existing provider, and complete the Presumptive Eligibility General Information Form (Form), which serves as the entity’s application to become a PE Site. Once an entity completes and submits a Form, Department staff review and either approve or deny the application. Final notice of acceptance or denial as an approved PE Site is then sent to the contact person listed on the Form. The PE Site is in charge of helping individuals complete an application and ensuring that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE Site collects the minimum information needed to determine presumptive eligibility, including the applicant’s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which is used to assist the caseworker in determining whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant’s reported information is not in compliance with federal and state requirements, CBMS is programmed to deny the eligibility and mark the applicant’s eligibility as “fail” within CBMS. As a result, the applicant would not be eligible for the payment of services to providers on their behalf through Colorado interChange. Once an applicant’s presumptive eligibility has been determined, the PE Site is required to submit the application along with a transmittal form detailing the beneficiary’s reported information to the appropriate local county or designated MA site within 5 business days, at which point the county or MA site would complete the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. The county or MA site must then make a final eligibility determination within 45 days of the application date. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual’s presumptive eligibility benefits should end. All PE Sites must be certified by the Department to make presumptive eligibility determinations. PE Sites must also recertify with the Department every 2 years to maintain their active status as a certified PE Site. As part of the recertification process, Department staff will audit 5 percent of the applications the PE Site processed during the previous year to confirm that the applicant’s information was correctly entered into CBMS and that the PE Site followed the appropriate guidance when making presumptive eligibility decisions. If the PE Site fails the audit, the Department requires PE Site staff to undergo customized Department training for the areas they failed within 6 months of the review. As of June 30, 2023, there were 50 certified PE Sites. During Fiscal Year 2023, 17 of those PE Sites determined presumptive eligibility for 531 Medicaid cases and 155 CBHP cases. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2023. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to internal controls over presumptive eligibility. Specifically, during the Fiscal Year 2020 audit, we identified problems with the Department’s compliance with applicable federal and state requirements, and recommended that the Department strengthen its internal controls over Medicaid and CBHP presumptive eligibility by developing and implementing (1) a tracking mechanism for monitoring PE Sites; (2) written policies and procedures detailing the requirements for completion of PE Site reviews, timely training for PE Site staff, and timely recertification of PE Sites; and (3) resolving CBMS programming and system issues to appropriately terminate presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP program and ensuring CBMS displays consistent applicant information between various screens. As part of our Fiscal Year 2023 audit, we reviewed the Department’s tracking mechanism for monitoring PE Sites, as well as the Department’s updated policies and procedures for completion of PE Site reviews, training for PE Site staff, and timely recertification of PE Sites. In addition, we inquired with the Department about the CBMS programming issues identified during the audit. Department staff reported they implemented changes within CBMS that would address the programming and system issues identified. As part of our Fiscal Year 2023 audit, we made inquiries with Department staff regarding the policies and procedures for applying to be a PE Site, recertification requirements, and Department site monitoring. During our internal controls testing, we reviewed a listing of all 50 PE Sites and noted that 40 sites were due for recertification in Fiscal Year 2023. We selected six PE Sites that were due for recertification and performed testing to determine whether the sites were appropriately recertified by the Department by performing the following procedures: • We confirmed that the Department had performed the recertification and reviewed the related case file support for all 6 PE Sites in our sample. • We noted that 4 of 6 PE Sites tested passed their recertification. We reviewed the Department’s case file support and confirmed the sites were appropriately recertified and mailed recertification letters from the Department. • The eligibility status for the remaining two PE Sites in our sample was terminated by the Department as part of its recertification review. One site did not complete the required paperwork for the recertification and the other did not have a need to provide PE Site services anymore. We reviewed Department correspondence to these sites to confirm the Department notified them that their PE Site status was terminated. In addition, we randomly selected a sample of 40 Medicaid and 37 CBHP cases for individuals who were deemed presumptively eligible at a PE Site during Fiscal Year 2023 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The Department’s process for presumptive eligibility determinations is the same for both Medicaid and CBHP and, therefore, our testing was used to determine compliance for both programs. What problems did the audit work identify and how were the results measured? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2023. Overall, we identified 8 instances of non-compliance with federal and state regulations over presumptive eligibility requirements at 4 separate PE Sites. Specifically, we identified the following: • Untimely End of Presumptive Eligibility. In 4 of 40 Medicaid (10 percent) and 3 of 37 CBHP cases (8 percent), we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. In these cases, the beneficiary’s presumptive eligibility did not end until between 6 and 31 days after the beneficiary was determined to be eligible for regular Medicaid and CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. • Timeliness of Transmittal Letters. In 1 of 40 Medicaid cases (3 percent), we found that the PE Site determining eligibility did not notify the county within five business days that the applicant was presumptively eligible, as required by state regulation. In this case, notification was made 1 day late. State regulation [10 CCR 2505-10, 8.100.4.F.4)] states that the presumptive eligibility sites are required to notify the local county within 5 business days that the client is presumptively eligible. Why did these problems occur? We determined that the Department’s changes to CBMS to address the programing and system issues identified in our prior audit recommendation did not appropriately terminate beneficiaries’ presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, the Department lacked sufficient internal controls to ensure that it complied with federal and state presumptive eligibility requirements during Fiscal Year 2023. Specifically, the Department did not adequately train PE Site staff on presumptive eligibility requirements and, as a result, they did not properly end presumptive eligibility and process transmittal letters in a timely manner. Why do these problems matter? As the State’s medical assistance agency, it is essential for the Department to ensure that PE Sites’ eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that presumptive eligibility determinations are made correctly and do not result in Medicaid or CBHP benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-056 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Colorado’s Medicaid Program (Medicaid) and the Children’s Basic Health Plan (CBHP) presumptive eligibility by: A. Resolving Colorado Benefits Management System (CBMS) programming and system issues to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP. B. Providing training to presumptive eligibility site staff to emphasize issues that were identified during our audit or that the Department identifies during its ongoing monitoring, including the importance of properly ending presumptive eligibility benefits when the beneficiary is determined to be ineligible for Medicaid and CBHP benefits and processing applications timely. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2023 The Colorado Benefits Management System (CBMS) programming and system discrepancies to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or Children’s Basic Health Plan program was corrected with a data fix in July 2023. The Department found after further research that it is permissible for Presumptive Eligibility Medical Spans and Medical Assistance Medical spans to overlap as these are two separate High level Program groups. Department staff will continue to monitor for future discrepancies. B. Agree Implementation Date: August 2024 The Department will continue to train presumptive eligibility site staff on the errors identified during this audit including processing applications timely, and those errors that the Department identifies during ongoing monitoring. The Colorado Benefits Management System (CBMS) automatically populates benefit end dates when the Eligibility site worker authorizes the Medicaid and CBHP benefits. The Department staff will continue to monitor for these discrepancies and work with the individual Eligibility sites on their application processing timeliness.
The Department holds standard ongoing training for presumptive eligibility site staff. This training addresses errors identified during audits and ongoing monitoring. The overlapping medical spans discrepancy was corrected in June 2024.
2023-056
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-057 Payments for Non-Emergent Medical Transportation Claims Non-emergent medical transportation (NEMT) is a federally-required Medicaid benefit intended to provide recipients prompt, efficient, and medically-necessary transportation services to and from their Medicaid medical services [Section 42 USC 1396a(a)]. NEMT cannot be used as a convenience to the recipient, such as for a trip to a grocery store, or be used by non-recipients unless they are an escort for a recipient who is a child or an at-risk adult [10 CCR 2505-10 8.014.5.D.1]. NEMT is available to all individuals enrolled in Medicaid. Federal law allows states to provide NEMT services through state-designated entities, such as contracted brokers, as long as the brokers provide cost-effective administration and delivery of services for Medicaid recipients [Section 42 USC 1396a(a)(70)]. Brokers are generally responsible for verifying recipient eligibility for NEMT services, scheduling recipient transportation with ride providers, paying the providers for services, submitting Medicaid claims to the Department through Colorado interChange to cover the cost of services, and retaining supporting documentation for each Medicaid claim. Over the years, NEMT services in Colorado have been brokered in the following ways: • Prior to July 2020. For 55 counties, various county offices brokered NEMT services for Medicaid recipients. In the remaining nine counties, the Department contracted with IntelliRide to serve as the broker for NEMT services in those areas. IntelliRide is a division of TransDev North America and manages NEMT, demand response transportation, and paratransit programs across the country. • July 1, 2020 to August 31, 2021. For all 64 counties, the Department contracted with IntelliRide to be the broker for NEMT services; however, our 2021 audits found that the Department also paid about $3.5 million in NEMT claims directly to 66 providers who brokered their own services during the prior audit review period of July 2020 through February 2021. • September 1, 2021 to Present. The Department returned to having 55 counties broker NEMT services in their areas, and contracting with IntelliRide to serve as the NEMT broker in the remaining nine counties. For rides brokered by IntelliRide, providers upload trip information into IntelliRide’s EcoLane transportation scheduling system, which maintains information on recipients’ requests for rides; the names of the recipient and driver; and trip information, such as the trip date, scheduled pick-up time, and destination. In our Fiscal Year 2021 Statewide audit and 2021 NEMT performance audit, we identified $291,597 in known questioned costs and about $5.2 million in likely questioned costs related to NEMT services that did not comply with federal and state Medicaid requirements. We recommended that the Department investigate each questioned claim to recover any payments determined to be inappropriate, and repay the federal portion, as appropriate. Federal regulations define known questioned costs as questioned costs that are specifically identified by the auditor and define likely questioned costs as the auditor’s best estimate of total questioned costs [45 CFR 75.516]. Known and likely questioned costs should be investigated by the Department, inappropriate payments should be recovered, and those payments should be repaid to the federal government as appropriate; Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We also recommended that the Department implement controls to ensure taxi claims are paid in accordance with established requirements and rates. The Department agreed to implement these audit recommendations by December 2022. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s implementation of the Fiscal Year 2021 audit recommendations to (1) investigate the known and likely questioned costs identified by the audits, recover inappropriate payments, and repay the federal portion, as appropriate, and (2) implement controls to ensure taxi claims are paid in accordance with established requirements and rates. We reviewed documentation of the Department’s efforts to investigate and recover the known questioned costs identified in the prior audits, and repay the federal portion of the claims. We interviewed Department staff to understand the extent to which steps had been taken to investigate, recover, and repay the likely questioned costs identified. We reviewed Department documentation and interviewed Department staff to understand the internal controls that were implemented to help ensure taxi claims are paid in line with requirements and rates. We also reviewed Department documentation and online information about NEMT fraud schemes that the Department identified starting in Summer 2023. How were the results of the audit work measured? The Department must investigate questioned costs related to NEMT claims, recover inappropriate payments, and repay the federal portion, as appropriate. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls that provide reasonable assurance that the Department is managing federal funds in compliance with federal statutes, regulations, and federal program terms and conditions. A questioned cost is defined in Uniform Guidance [45 CFR 75.2] as “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.…” Questioned costs can result in the misappropriation of federal and state funds. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments “are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....” According to federal law, states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share (also known as Federal Financial Participation or FFP) must be refunded to CMS, regardless of whether a recovery is made from the provider [42 USC 1396b]. The Department must have internal controls to pay claims based on accurate service rates and trip mileage. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which is generally based on trip mileage. According to the Department’s NEMT Billing Manual and rate schedule for 2021, taxi claims should have been paid at the rate set by the PUC. What problems did the audit work identify? The Department has not investigated and recovered as appropriate, the $5.2 million in likely questioned costs related to NEMT claims, or repaid the federal portion. Based on our testwork, we determined that the Department has not fully implemented the Statewide audit and performance audit recommendations from 2021 because it has not investigated the about $5.2 million in likely questioned costs identified by the audits, or attempted to recover and repay the federal portion of those questioned costs. As of June 30, 2023, the Department had investigated and recovered the $291,597 in known questioned costs and repaid the federal portion. In addition, the Department has not fully implemented internal controls to help ensure taxi claims are paid appropriately. The issues we identified in our 2021 Statewide and performance audits, which resulted in the likely questioned costs between July 2020 and February 2021(the prior audit period), are summarized below: • About $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC approved per-mile rate, as required by the Department’s NEMT Billing Manual and rate schedule. These claims were submitted directly to the Department by 10 PUC-permitted taxi providers. For example, the Department paid $4,000 to one taxi provider for what appeared to be four 400-mile one-way trips that were given to one recipient within a single day, which did not appear possible and was not paid based on taxi rates. The Department only required taxi providers to submit claims showing only the number of one-way trips driven, not the mileage, and paid the claims as long as they were not more than $1,000 per one-way trip. As a result, the Department lacked internal controls to ensure taxi claims were paid at the correct rates. After the 2021 audits, the Department lowered the maximum per one-way taxi trip within Colorado interChange from $1,000 to $500, but the Department did not implement other internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. • $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis, as required by the NEMT Billing Manual and rate schedule. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. After the 2021 audits, the Department implemented an internal control to help ensure providers submitting NEMT taxi claims are permitted to operate as taxis. • $4,718 paid for trips that may not have been to attend medical services. Our 2021 audits found that 13 of a sample of 22 NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips, and 6 of these 13 claims were for recipients who had both Medicaid and other types of medical insurance, such as Medicare. Department staff told us that it was possible that medical providers had not yet submitted medical claims yet, and that the six recipients may have used NEMT trips to access medical services but those services were paid by other insurance, as allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. After the 2021 audits, the Department implemented an internal control to help ensure NEMT services are used to attend medical appointments. • $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims in the 2021 OSA audit timeframe, the scheduled trips were not marked as complete in IntelliRide’s EcoLane transportation scheduling system, so we could not determine whether they had been completed. After the 2021 audits, the Department worked with IntelliRide to help ensure its system began maintaining complete information on rides. The Department is currently in the process of investigating NEMT fraud schemes. According to the Department, in Summer 2023 it uncovered an “unprecedented fraud scheme” occurring in the NEMT benefit, affecting “tens of thousands” of NEMT claims. For example, the Department identified an increase in suspicious NEMT billings and program violations, such as recipients receiving inappropriately long trips. The Department informed the OSA that, as of October 2023, it had issued 50 cease and desist letters to NEMT providers, placed 390 providers on pre-payment review, sent letters to providers with concerns of fraudulent behavior and steps taken, placed a moratorium on new NEMT provider applications—with approval of CMS—and, as a result, denied 632 NEMT provider applications. The Department told us that in addition to fraud schemes among NEMT providers, it is analyzing whether similar issues are occurring in different Medicaid provider types. The Department also informed the OSA that it is working with a number of entities, such as the Colorado Attorney General’s Office and its Medicaid Fraud Control Unit, the Colorado Department of Public Safety, county departments of human services, IntelliRide, CMS, the Office of the Inspector General, the Federal Bureau of Investigations, and other states experiencing NEMT fraud. The Department has posted alerts on its NEMT website to inform Medicaid members of potentially fraudulent NEMT practices. Why did these problems occur? The Department lacked sufficient internal controls to investigate questioned costs and to detect improper claims, payments, and provider applications. The Department did not investigate the $5.2 million in likely questioned costs identified by our 2021 audits by December 2022, as it stated it would do within its responses to the prior audit recommendation, demonstrating that the Department did not have sufficient processes in place to implement the recommendation in a timely manner. The Department also reported to us that due to the recent detection of fraud schemes by NEMT providers, the Department does not “have the resources to investigate the likely questioned costs identified in the report” and “is currently unable to follow through on the previous agreement.” The Department stated that once it completes activities related to the recently detected NEMT fraud schemes, it “will go back and review post-payment, if resources allow” that “may include the likely questioned costs.” The Department’s process will need to include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. Regarding the recent surge in NEMT fraud, the Department indicated that it has developed stronger internal controls to process applications from those seeking to provide NEMT services and to manage billing practices. For example, according to the Department, it is “updating [its NEMT] provider credentialing and billing processes” and conducting reviews to determine whether services and billing are in compliance with federal and state law. The Department stated that if its reviews reveal evidence of non-compliance or intentional fraud, the Department “will initiate additional actions, including but not limited to, referrals to law enforcement.” In the event that the Department identifies improper or overpayments to NEMT providers, it will need to recover those payments and repay the federal portion. Why do these problems matter? For the approximately $5.2 million in likely questioned costs identified in our 2021 Statewide and performance audits, the Department paid the NEMT claims, yet there was no supporting documentation or data from IntelliRide, ride providers, or the Department to substantiate that the costs of the claims were accurate, or that the rides complied with federal and state requirements. As such, there was a significant risk of misappropriation of federal and state funds by providers and/or recipients. While we did not identify confirmed fraud by providers or recipients at that time, due to the lack of supporting documentation for these claims, the problems identified by the prior audits demonstrate a potential waste of public funds and abuse of the Medicaid program. When the Department does not have sufficient internal controls in place to take timely action to investigate questionable claims, this can result in misuse of federal and state Medicaid funds. If the Department had started the recommended investigation in 2021 and completed it by the end of 2022, it may have been able to identify aspects of the NEMT provider fraud scheme and improper payments sooner than Summer 2023. Recommendation 2023-057 The Department of Health Care Policy and Financing (Department) should comply with federal and state requirements for administering the non-emergent medical transportation (NEMT) benefit, and for paying Colorado Medicaid Program claims by: A. Investigating the payments that the OSA’s 2021 Statewide and performance audits identified that resulted in likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. This process should include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. B. Continuing to investigate the overpayments and inappropriate payments that the Department identifies through its fraud investigations and that result in known or likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: August 2024 HCPF disagrees with the likely questioned costs identified and that it should review these claims. Because supporting documents were not available, the OSA had nothing to review for these claims and so determined that they were likely questioned costs. Of the claims the OSA had documentation to review, though, the documentation supported the claim and so the Department believes it is likely the missing documentation would support the claims as well. HCPF isn’t required to have the documentation up front, and it is the normal practice to pay claims and require the providers maintain the documentation, so this standard process should not create a presumption that the payments were in error. To review all these claims, HCPF would have to request each record from the provider, and the average review of an NEMT claim once the records have been received takes 15-30 minutes, so it would take an estimated 7,262.25-14,524.5 hours to review 29,049 claims. HCPF does it have existing resources to complete this review. HPCF agrees to review the claims where the OSA reviewed the records and determined that the claims were not paid properly. If an overpayment is identified, FFP will be returned as appropriate. We expect this project to be completed by 8/31/24. HCPF agrees with the taxi rate problem and is implementing internal controls to ensure taxi providers are paid appropriately by discontinuing the specific rate for taxi services and replacing it with the generic mileage rate. This will prevent inaccurate payments. HCPF is no longer required to pay taxi providers the rate stipulated by their individual PUC rate. We expect this project to be completed by 7/31/24. Auditor’s Addendum As noted in the audit finding, the Department, its NEMT contractor (IntelliRide), and ride providers did not have data or documentation to support $5.2 million in paid claims for NEMT services, as required. These unsupported payments resulted in likely questioned costs that the Department should investigate, in order to recover inappropriate payments and repay the federal portion, as appropriate. Further, the Department's response describing the audit work and results is incorrect. During the audit, the OSA reviewed all data and documentation that the Department, its NEMT contractor, and ride providers provided to the OSA, and identified $291,597 in known questioned costs for 4,503 claims because the amounts paid were not supported or the claims did not comply with federal or state requirements. For an additional about 29,100 NEMT claims totaling $5.2 million, audit analysis determined that the paid claims appeared noncompliant, and the Department reported that neither it, nor its NEMT contractor or ride providers, could provide support for these claims, which resulted in the likely questioned costs. In 2021 and 2022, the Department agreed that the lack of documentation to support the paid claims was a problem, and agreed to investigate. B. Partially Agree Implementation Date: July 2024 As the Department previously responded to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program. The Department has returned the FFP on the known questioned costs. As to the likely questioned costs, as mentioned in Part A, the Department cannot review every claim, however as previously stated the Department plans to conduct post-payment reviews on identified providers and service types that are suspected of having a high risk of improper payments, if resources allow, which may include reviewing claims identified by the OSA as likely questioned costs. Should the department identify an overpayment during said reviews, the department will return the FPP. Auditor’s Addendum As noted in the audit finding, the Department has reported a recent surge in NEMT fraud that the Department is investigating. In the event that the Department's investigations identify improper payments or overpayments that result in additional known or likely questioned costs besides those identified by the prior audit, the Department will need to recover those payments and repay the federal portion, as appropriate.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-057 Payments for Non-Emergent Medical Transportation Claims Non-emergent medical transportation (NEMT) is a federally-required Medicaid benefit intended to provide recipients prompt, efficient, and medically-necessary transportation services to and from their Medicaid medical services [Section 42 USC 1396a(a)]. NEMT cannot be used as a convenience to the recipient, such as for a trip to a grocery store, or be used by non-recipients unless they are an escort for a recipient who is a child or an at-risk adult [10 CCR 2505-10 8.014.5.D.1]. NEMT is available to all individuals enrolled in Medicaid. Federal law allows states to provide NEMT services through state-designated entities, such as contracted brokers, as long as the brokers provide cost-effective administration and delivery of services for Medicaid recipients [Section 42 USC 1396a(a)(70)]. Brokers are generally responsible for verifying recipient eligibility for NEMT services, scheduling recipient transportation with ride providers, paying the providers for services, submitting Medicaid claims to the Department through Colorado interChange to cover the cost of services, and retaining supporting documentation for each Medicaid claim. Over the years, NEMT services in Colorado have been brokered in the following ways: • Prior to July 2020. For 55 counties, various county offices brokered NEMT services for Medicaid recipients. In the remaining nine counties, the Department contracted with IntelliRide to serve as the broker for NEMT services in those areas. IntelliRide is a division of TransDev North America and manages NEMT, demand response transportation, and paratransit programs across the country. • July 1, 2020 to August 31, 2021. For all 64 counties, the Department contracted with IntelliRide to be the broker for NEMT services; however, our 2021 audits found that the Department also paid about $3.5 million in NEMT claims directly to 66 providers who brokered their own services during the prior audit review period of July 2020 through February 2021. • September 1, 2021 to Present. The Department returned to having 55 counties broker NEMT services in their areas, and contracting with IntelliRide to serve as the NEMT broker in the remaining nine counties. For rides brokered by IntelliRide, providers upload trip information into IntelliRide’s EcoLane transportation scheduling system, which maintains information on recipients’ requests for rides; the names of the recipient and driver; and trip information, such as the trip date, scheduled pick-up time, and destination. In our Fiscal Year 2021 Statewide audit and 2021 NEMT performance audit, we identified $291,597 in known questioned costs and about $5.2 million in likely questioned costs related to NEMT services that did not comply with federal and state Medicaid requirements. We recommended that the Department investigate each questioned claim to recover any payments determined to be inappropriate, and repay the federal portion, as appropriate. Federal regulations define known questioned costs as questioned costs that are specifically identified by the auditor and define likely questioned costs as the auditor’s best estimate of total questioned costs [45 CFR 75.516]. Known and likely questioned costs should be investigated by the Department, inappropriate payments should be recovered, and those payments should be repaid to the federal government as appropriate; Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We also recommended that the Department implement controls to ensure taxi claims are paid in accordance with established requirements and rates. The Department agreed to implement these audit recommendations by December 2022. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s implementation of the Fiscal Year 2021 audit recommendations to (1) investigate the known and likely questioned costs identified by the audits, recover inappropriate payments, and repay the federal portion, as appropriate, and (2) implement controls to ensure taxi claims are paid in accordance with established requirements and rates. We reviewed documentation of the Department’s efforts to investigate and recover the known questioned costs identified in the prior audits, and repay the federal portion of the claims. We interviewed Department staff to understand the extent to which steps had been taken to investigate, recover, and repay the likely questioned costs identified. We reviewed Department documentation and interviewed Department staff to understand the internal controls that were implemented to help ensure taxi claims are paid in line with requirements and rates. We also reviewed Department documentation and online information about NEMT fraud schemes that the Department identified starting in Summer 2023. How were the results of the audit work measured? The Department must investigate questioned costs related to NEMT claims, recover inappropriate payments, and repay the federal portion, as appropriate. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls that provide reasonable assurance that the Department is managing federal funds in compliance with federal statutes, regulations, and federal program terms and conditions. A questioned cost is defined in Uniform Guidance [45 CFR 75.2] as “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.…” Questioned costs can result in the misappropriation of federal and state funds. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments “are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....” According to federal law, states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share (also known as Federal Financial Participation or FFP) must be refunded to CMS, regardless of whether a recovery is made from the provider [42 USC 1396b]. The Department must have internal controls to pay claims based on accurate service rates and trip mileage. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which is generally based on trip mileage. According to the Department’s NEMT Billing Manual and rate schedule for 2021, taxi claims should have been paid at the rate set by the PUC. What problems did the audit work identify? The Department has not investigated and recovered as appropriate, the $5.2 million in likely questioned costs related to NEMT claims, or repaid the federal portion. Based on our testwork, we determined that the Department has not fully implemented the Statewide audit and performance audit recommendations from 2021 because it has not investigated the about $5.2 million in likely questioned costs identified by the audits, or attempted to recover and repay the federal portion of those questioned costs. As of June 30, 2023, the Department had investigated and recovered the $291,597 in known questioned costs and repaid the federal portion. In addition, the Department has not fully implemented internal controls to help ensure taxi claims are paid appropriately. The issues we identified in our 2021 Statewide and performance audits, which resulted in the likely questioned costs between July 2020 and February 2021(the prior audit period), are summarized below: • About $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC approved per-mile rate, as required by the Department’s NEMT Billing Manual and rate schedule. These claims were submitted directly to the Department by 10 PUC-permitted taxi providers. For example, the Department paid $4,000 to one taxi provider for what appeared to be four 400-mile one-way trips that were given to one recipient within a single day, which did not appear possible and was not paid based on taxi rates. The Department only required taxi providers to submit claims showing only the number of one-way trips driven, not the mileage, and paid the claims as long as they were not more than $1,000 per one-way trip. As a result, the Department lacked internal controls to ensure taxi claims were paid at the correct rates. After the 2021 audits, the Department lowered the maximum per one-way taxi trip within Colorado interChange from $1,000 to $500, but the Department did not implement other internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. • $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis, as required by the NEMT Billing Manual and rate schedule. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. After the 2021 audits, the Department implemented an internal control to help ensure providers submitting NEMT taxi claims are permitted to operate as taxis. • $4,718 paid for trips that may not have been to attend medical services. Our 2021 audits found that 13 of a sample of 22 NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips, and 6 of these 13 claims were for recipients who had both Medicaid and other types of medical insurance, such as Medicare. Department staff told us that it was possible that medical providers had not yet submitted medical claims yet, and that the six recipients may have used NEMT trips to access medical services but those services were paid by other insurance, as allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. After the 2021 audits, the Department implemented an internal control to help ensure NEMT services are used to attend medical appointments. • $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims in the 2021 OSA audit timeframe, the scheduled trips were not marked as complete in IntelliRide’s EcoLane transportation scheduling system, so we could not determine whether they had been completed. After the 2021 audits, the Department worked with IntelliRide to help ensure its system began maintaining complete information on rides. The Department is currently in the process of investigating NEMT fraud schemes. According to the Department, in Summer 2023 it uncovered an “unprecedented fraud scheme” occurring in the NEMT benefit, affecting “tens of thousands” of NEMT claims. For example, the Department identified an increase in suspicious NEMT billings and program violations, such as recipients receiving inappropriately long trips. The Department informed the OSA that, as of October 2023, it had issued 50 cease and desist letters to NEMT providers, placed 390 providers on pre-payment review, sent letters to providers with concerns of fraudulent behavior and steps taken, placed a moratorium on new NEMT provider applications—with approval of CMS—and, as a result, denied 632 NEMT provider applications. The Department told us that in addition to fraud schemes among NEMT providers, it is analyzing whether similar issues are occurring in different Medicaid provider types. The Department also informed the OSA that it is working with a number of entities, such as the Colorado Attorney General’s Office and its Medicaid Fraud Control Unit, the Colorado Department of Public Safety, county departments of human services, IntelliRide, CMS, the Office of the Inspector General, the Federal Bureau of Investigations, and other states experiencing NEMT fraud. The Department has posted alerts on its NEMT website to inform Medicaid members of potentially fraudulent NEMT practices. Why did these problems occur? The Department lacked sufficient internal controls to investigate questioned costs and to detect improper claims, payments, and provider applications. The Department did not investigate the $5.2 million in likely questioned costs identified by our 2021 audits by December 2022, as it stated it would do within its responses to the prior audit recommendation, demonstrating that the Department did not have sufficient processes in place to implement the recommendation in a timely manner. The Department also reported to us that due to the recent detection of fraud schemes by NEMT providers, the Department does not “have the resources to investigate the likely questioned costs identified in the report” and “is currently unable to follow through on the previous agreement.” The Department stated that once it completes activities related to the recently detected NEMT fraud schemes, it “will go back and review post-payment, if resources allow” that “may include the likely questioned costs.” The Department’s process will need to include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. Regarding the recent surge in NEMT fraud, the Department indicated that it has developed stronger internal controls to process applications from those seeking to provide NEMT services and to manage billing practices. For example, according to the Department, it is “updating [its NEMT] provider credentialing and billing processes” and conducting reviews to determine whether services and billing are in compliance with federal and state law. The Department stated that if its reviews reveal evidence of non-compliance or intentional fraud, the Department “will initiate additional actions, including but not limited to, referrals to law enforcement.” In the event that the Department identifies improper or overpayments to NEMT providers, it will need to recover those payments and repay the federal portion. Why do these problems matter? For the approximately $5.2 million in likely questioned costs identified in our 2021 Statewide and performance audits, the Department paid the NEMT claims, yet there was no supporting documentation or data from IntelliRide, ride providers, or the Department to substantiate that the costs of the claims were accurate, or that the rides complied with federal and state requirements. As such, there was a significant risk of misappropriation of federal and state funds by providers and/or recipients. While we did not identify confirmed fraud by providers or recipients at that time, due to the lack of supporting documentation for these claims, the problems identified by the prior audits demonstrate a potential waste of public funds and abuse of the Medicaid program. When the Department does not have sufficient internal controls in place to take timely action to investigate questionable claims, this can result in misuse of federal and state Medicaid funds. If the Department had started the recommended investigation in 2021 and completed it by the end of 2022, it may have been able to identify aspects of the NEMT provider fraud scheme and improper payments sooner than Summer 2023. Recommendation 2023-057 The Department of Health Care Policy and Financing (Department) should comply with federal and state requirements for administering the non-emergent medical transportation (NEMT) benefit, and for paying Colorado Medicaid Program claims by: A. Investigating the payments that the OSA’s 2021 Statewide and performance audits identified that resulted in likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. This process should include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. B. Continuing to investigate the overpayments and inappropriate payments that the Department identifies through its fraud investigations and that result in known or likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: August 2024 HCPF disagrees with the likely questioned costs identified and that it should review these claims. Because supporting documents were not available, the OSA had nothing to review for these claims and so determined that they were likely questioned costs. Of the claims the OSA had documentation to review, though, the documentation supported the claim and so the Department believes it is likely the missing documentation would support the claims as well. HCPF isn’t required to have the documentation up front, and it is the normal practice to pay claims and require the providers maintain the documentation, so this standard process should not create a presumption that the payments were in error. To review all these claims, HCPF would have to request each record from the provider, and the average review of an NEMT claim once the records have been received takes 15-30 minutes, so it would take an estimated 7,262.25-14,524.5 hours to review 29,049 claims. HCPF does it have existing resources to complete this review. HPCF agrees to review the claims where the OSA reviewed the records and determined that the claims were not paid properly. If an overpayment is identified, FFP will be returned as appropriate. We expect this project to be completed by 8/31/24. HCPF agrees with the taxi rate problem and is implementing internal controls to ensure taxi providers are paid appropriately by discontinuing the specific rate for taxi services and replacing it with the generic mileage rate. This will prevent inaccurate payments. HCPF is no longer required to pay taxi providers the rate stipulated by their individual PUC rate. We expect this project to be completed by 7/31/24. Auditor’s Addendum As noted in the audit finding, the Department, its NEMT contractor (IntelliRide), and ride providers did not have data or documentation to support $5.2 million in paid claims for NEMT services, as required. These unsupported payments resulted in likely questioned costs that the Department should investigate, in order to recover inappropriate payments and repay the federal portion, as appropriate. Further, the Department's response describing the audit work and results is incorrect. During the audit, the OSA reviewed all data and documentation that the Department, its NEMT contractor, and ride providers provided to the OSA, and identified $291,597 in known questioned costs for 4,503 claims because the amounts paid were not supported or the claims did not comply with federal or state requirements. For an additional about 29,100 NEMT claims totaling $5.2 million, audit analysis determined that the paid claims appeared noncompliant, and the Department reported that neither it, nor its NEMT contractor or ride providers, could provide support for these claims, which resulted in the likely questioned costs. In 2021 and 2022, the Department agreed that the lack of documentation to support the paid claims was a problem, and agreed to investigate. B. Partially Agree Implementation Date: July 2024 As the Department previously responded to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program. The Department has returned the FFP on the known questioned costs. As to the likely questioned costs, as mentioned in Part A, the Department cannot review every claim, however as previously stated the Department plans to conduct post-payment reviews on identified providers and service types that are suspected of having a high risk of improper payments, if resources allow, which may include reviewing claims identified by the OSA as likely questioned costs. Should the department identify an overpayment during said reviews, the department will return the FPP. Auditor’s Addendum As noted in the audit finding, the Department has reported a recent surge in NEMT fraud that the Department is investigating. In the event that the Department's investigations identify improper payments or overpayments that result in additional known or likely questioned costs besides those identified by the prior audit, the Department will need to recover those payments and repay the federal portion, as appropriate.
As stated in the response to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program.
2023-057
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-064 The Department of Health Care Policy and Financing (HCPF) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for HCPF through interagency agreements with the Governor’s Office of Information Technology and Department of Human Services. Response Department of Health Care Policy and Financing Partially Agree Implementation Date: November 2024 HCPF does not agree that the late delivery of the CBMS SOC report justifies this recommendation. As identified in Inter-agency Agreements between OIT and the Department and CDHS and OIT, the SOC report for CBMS compliance was owned by the OIT prior to 2022 and CDHS Product Manager currently. CBMS is a multi-agency system owned by CDHS, HCPF, and OIT and as a result OIT, CDHS, and the Department agreed to Inter-agency agreements specifically identifying OIT as the responsible party for reviewing and complying with CBMS SOC requirements. However, HCPF does agree that establishing the roles and responsibilities for HCPF, OIT, and CDHS is important to its internal controls over CBMS. HCPF will work with CDHS and OIT to establish, document, and formalize the roles and responsibilities. Auditor’s Addendum As discussed in the finding, the Department is responsible for ensuring they have effective internal controls over their federal programs, which includes maintaining responsibility for the performance of processes assigned to service organizations [Green Book Paragraph OV4.01]. By not reviewing the CBMS SOC report until almost 7 months after fiscal year end, the Department was unable to determine if any issues were identified in the report, or if any actions were needed to correct the issues identified.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2024 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Finding and Questioned Costs for chart/table. Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-064 The Department of Health Care Policy and Financing (HCPF) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for HCPF through interagency agreements with the Governor’s Office of Information Technology and Department of Human Services. Response Department of Health Care Policy and Financing Partially Agree Implementation Date: November 2024 HCPF does not agree that the late delivery of the CBMS SOC report justifies this recommendation. As identified in Inter-agency Agreements between OIT and the Department and CDHS and OIT, the SOC report for CBMS compliance was owned by the OIT prior to 2022 and CDHS Product Manager currently. CBMS is a multi-agency system owned by CDHS, HCPF, and OIT and as a result OIT, CDHS, and the Department agreed to Inter-agency agreements specifically identifying OIT as the responsible party for reviewing and complying with CBMS SOC requirements. However, HCPF does agree that establishing the roles and responsibilities for HCPF, OIT, and CDHS is important to its internal controls over CBMS. HCPF will work with CDHS and OIT to establish, document, and formalize the roles and responsibilities. Auditor’s Addendum As discussed in the finding, the Department is responsible for ensuring they have effective internal controls over their federal programs, which includes maintaining responsibility for the performance of processes assigned to service organizations [Green Book Paragraph OV4.01]. By not reviewing the CBMS SOC report until almost 7 months after fiscal year end, the Department was unable to determine if any issues were identified in the report, or if any actions were needed to correct the issues identified.
The Department in partnership with OIT and CDHS signed the Realignment Agreement to establish roles and responsibilities of CBMS amongst the three agencies effective July 2024. The agencies reviewed and revised processes in October 2024 to align with the executed Realignment Agreement.
2023-064
Finding 2024-042 Compliance with Reporting for Foster Care, SSBG, and MHBG Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (FFATA or Transparency Act) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as “subrecipients”). Federal regulations [2 CFR 200.1] define a “subaward” as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file Transparency Act reports (also known as FFATA reports) through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2024 included information on the MHBG, SSBG, and Foster Care programs. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: MHBG funds to 46 subrecipients, SSBG funds to 64 subrecipients, and Foster Care funds to 64 subrecipients. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for MHBG, SSBG, and Foster Care during Fiscal Year 2024. We also determined the disposition of our Fiscal Year 2022 prior audit recommendation where we recommended the Department ensure that it complies with FFATA for the Foster Care program, including working with the federal government to obtain documented approval for its current approach or report its subawards in accordance with FFATA regulations. The Department agreed with this recommendation and planned to implement it by December 2023. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and the FFATA reports it submitted for MHBG, SSBG, and Foster Care for Fiscal Year 2024. We randomly selected 8 out of 46 county reports submitted for MHBG and compared amounts reported by the Department for subawards in FSRS to the underlying financial records in CORE, and inquired about differences. Additionally, we reviewed the Department’s MHBG subawards and related federal expenditures in Fiscal Year 2024 to determine if the Department reported Transparency Act information through FSRS within the required month following the subaward. We also inquired with Department staff about their internal control processes related to FFATA reporting, including supervisory reviews. We inquired with the Department on whether they submitted FFATA reports for the 64 counties that received SSBG and Foster Care subawards. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with FFATA regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if it made an award or supplemental award equal to or greater than $30,000 in April 2024. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient Data Universal Numbering System (DUNS) number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, subrecipient names, and compensation of highly compensated officers. The Department’s FFATA Quick Reference Guide, available to program staff, requires that program staff report these key data elements in eClearance, a document depository utilized by the Department, whenever the Department makes a subaward. Program staff are to enter the subaward information into eClearance via an online form called an eForm. Each day, the Department’s accounting manager exports the subaward data that is accumulated in eClearance into a daily report. At the end of the month, the accounting manager combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report’s accuracy. The accounting manager uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. Although not explicitly stated in the guide, evidence of review and approval should be documented prior to submission. What problems did the audit work identify? We identified problems with the Department’s FFATA reporting for MHBG, SSBG, and Foster Care programs for Fiscal Year 2024. Based on our audit testwork, we determined that the Department did report its subawards in FSRS for MHBG for Fiscal Year 2024. However, for MHBG, the Department failed to provide evidence showing review and approval over the FFATA reports for two out of the eight (25 percent) reports tested. For the other two federal programs— SSBG and Foster Care—the Department failed to report any of the 64 (100 percent) counties’ subawards in FSRS. The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, timeliness of report unable to be determined, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table. Why did these problems occur? For MHBG, the Department did not have adequate internal controls in place related to FFATA reporting, such as an appropriate supervisory review process to ensure that the Transparency Act reporting is completed in accordance with federal requirements. Specifically, the Department’s FFATA Quick Reference Guide did not indicate which documentation Department staff need to maintain to provide evidence of supervisory review. During our Fiscal Year 2022 audit, the Department stated that it believed the FFATA regulations did not apply to the SSBG and Foster Care programs because both programs are primarily administered by the counties and therefore, the counties should be considered part of the State for FFATA reporting purposes instead of subrecipients. However, the Department could not provide any information from the federal government to support this conclusion. The Department subsequently determined during Fiscal Year 2024 that, because the SSBG and Foster Care funds are awarded to 64 Colorado counties that are subrecipients, and the FFATA regulations specify that the Department “must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a subrecipient,” FFATA reporting is required for subawards under both programs. However, the Department did not report these subawards during Fiscal Year 2024. Why do these problems matter? By failing to properly report the subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, by not reporting the relevant information, it is failing to meet the federal intent of transparency for federal program spending. Furthermore, not maintaining documentation of the review and approval of the reports can lead to a lack of accountability, making it difficult to verify compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-042 The Department of Human Services (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (FFATA) reporting for the Block Grants for Community Mental Health Services, the Social Services Block Grant, and the Foster Care Title IV-E program, and ensure that its reporting meets federal requirements by ensuring that reporting occurs as required for subawards of $30,000 or more in the FFATA Subaward Reporting System by the end of the month following the month the subawards are made. The Department should also revise the FFATA Quick Reference Guide to include what documentation needs to be maintained to show evidence of review, approval, and submission, and ensure that this evidence is consistently documented and retained. Response Department of Human Services Agree Implementation Date: February 2025 The Department agrees with the recommendation to have a digital signature process on each submitted FFATA reports to maintain evidence on when the reports were submitted. We also implemented a process of sending a monthly email to the supervisor with the screenshot of completed reports with the path as of Jan 2024. In addition, the Department will implement the FFATA reporting of the county allocations that are provided through the county year end Federal Financial Award (FFA) report. CDHS utilizes the FFA report established in the calendar year which counties use to report on their SEFA (Schedule of Expenditures of Federal Awards). Therefore, CDHS considers the 30 days due date after Period 6 closes in CORE and plans to submit all the reports in February 2025. In addition, the Department agrees to revise the Quick Reference Guide to include what documentation needs to be maintained to show evidence of review, approval, and submission, and ensure that this evidence is consistently documented and retained.
Show full finding ▾Hide full finding ▴Finding 2024-042 Compliance with Reporting for Foster Care, SSBG, and MHBG Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (FFATA or Transparency Act) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as “subrecipients”). Federal regulations [2 CFR 200.1] define a “subaward” as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file Transparency Act reports (also known as FFATA reports) through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2024 included information on the MHBG, SSBG, and Foster Care programs. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: MHBG funds to 46 subrecipients, SSBG funds to 64 subrecipients, and Foster Care funds to 64 subrecipients. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for MHBG, SSBG, and Foster Care during Fiscal Year 2024. We also determined the disposition of our Fiscal Year 2022 prior audit recommendation where we recommended the Department ensure that it complies with FFATA for the Foster Care program, including working with the federal government to obtain documented approval for its current approach or report its subawards in accordance with FFATA regulations. The Department agreed with this recommendation and planned to implement it by December 2023. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and the FFATA reports it submitted for MHBG, SSBG, and Foster Care for Fiscal Year 2024. We randomly selected 8 out of 46 county reports submitted for MHBG and compared amounts reported by the Department for subawards in FSRS to the underlying financial records in CORE, and inquired about differences. Additionally, we reviewed the Department’s MHBG subawards and related federal expenditures in Fiscal Year 2024 to determine if the Department reported Transparency Act information through FSRS within the required month following the subaward. We also inquired with Department staff about their internal control processes related to FFATA reporting, including supervisory reviews. We inquired with the Department on whether they submitted FFATA reports for the 64 counties that received SSBG and Foster Care subawards. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with FFATA regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if it made an award or supplemental award equal to or greater than $30,000 in April 2024. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient Data Universal Numbering System (DUNS) number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, subrecipient names, and compensation of highly compensated officers. The Department’s FFATA Quick Reference Guide, available to program staff, requires that program staff report these key data elements in eClearance, a document depository utilized by the Department, whenever the Department makes a subaward. Program staff are to enter the subaward information into eClearance via an online form called an eForm. Each day, the Department’s accounting manager exports the subaward data that is accumulated in eClearance into a daily report. At the end of the month, the accounting manager combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report’s accuracy. The accounting manager uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. Although not explicitly stated in the guide, evidence of review and approval should be documented prior to submission. What problems did the audit work identify? We identified problems with the Department’s FFATA reporting for MHBG, SSBG, and Foster Care programs for Fiscal Year 2024. Based on our audit testwork, we determined that the Department did report its subawards in FSRS for MHBG for Fiscal Year 2024. However, for MHBG, the Department failed to provide evidence showing review and approval over the FFATA reports for two out of the eight (25 percent) reports tested. For the other two federal programs— SSBG and Foster Care—the Department failed to report any of the 64 (100 percent) counties’ subawards in FSRS. The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, timeliness of report unable to be determined, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table. Why did these problems occur? For MHBG, the Department did not have adequate internal controls in place related to FFATA reporting, such as an appropriate supervisory review process to ensure that the Transparency Act reporting is completed in accordance with federal requirements. Specifically, the Department’s FFATA Quick Reference Guide did not indicate which documentation Department staff need to maintain to provide evidence of supervisory review. During our Fiscal Year 2022 audit, the Department stated that it believed the FFATA regulations did not apply to the SSBG and Foster Care programs because both programs are primarily administered by the counties and therefore, the counties should be considered part of the State for FFATA reporting purposes instead of subrecipients. However, the Department could not provide any information from the federal government to support this conclusion. The Department subsequently determined during Fiscal Year 2024 that, because the SSBG and Foster Care funds are awarded to 64 Colorado counties that are subrecipients, and the FFATA regulations specify that the Department “must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a subrecipient,” FFATA reporting is required for subawards under both programs. However, the Department did not report these subawards during Fiscal Year 2024. Why do these problems matter? By failing to properly report the subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, by not reporting the relevant information, it is failing to meet the federal intent of transparency for federal program spending. Furthermore, not maintaining documentation of the review and approval of the reports can lead to a lack of accountability, making it difficult to verify compliance and potentially resulting in further scrutiny or penalties from federal oversight bodies. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-042 The Department of Human Services (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (FFATA) reporting for the Block Grants for Community Mental Health Services, the Social Services Block Grant, and the Foster Care Title IV-E program, and ensure that its reporting meets federal requirements by ensuring that reporting occurs as required for subawards of $30,000 or more in the FFATA Subaward Reporting System by the end of the month following the month the subawards are made. The Department should also revise the FFATA Quick Reference Guide to include what documentation needs to be maintained to show evidence of review, approval, and submission, and ensure that this evidence is consistently documented and retained. Response Department of Human Services Agree Implementation Date: February 2025 The Department agrees with the recommendation to have a digital signature process on each submitted FFATA reports to maintain evidence on when the reports were submitted. We also implemented a process of sending a monthly email to the supervisor with the screenshot of completed reports with the path as of Jan 2024. In addition, the Department will implement the FFATA reporting of the county allocations that are provided through the county year end Federal Financial Award (FFA) report. CDHS utilizes the FFA report established in the calendar year which counties use to report on their SEFA (Schedule of Expenditures of Federal Awards). Therefore, CDHS considers the 30 days due date after Period 6 closes in CORE and plans to submit all the reports in February 2025. In addition, the Department agrees to revise the Quick Reference Guide to include what documentation needs to be maintained to show evidence of review, approval, and submission, and ensure that this evidence is consistently documented and retained.
The Department agrees with the recommendation to have a digital signature process on each submitted FFATA reports to maintain evidence on when the reports were submitted. We also implemented a process of sending a monthly email to the supervisor with the screenshot of completed reports with the path as of Jan 2024. In addition, the Department will implement the FFATA reporting of the county allocations that are provided through the county year end Federal Financial Award (FFA) report. CDHS utilizes the FFA report established in the calendar year which counties use to report on their SEFA (Schedule of Expenditures of Federal Awards). Therefore, CDHS considers the 30 days due date after Period 6 closes in CORE and plans to submit all the reports in February 2025. In addition, the Department agrees to revise the Quick Reference Guide to include what documentation needs to be maintained to show evidence of review, approval, and submission, and ensure that this evidence is consistently documented and retained.
2023-067
Finding 2024-043 Compliance with Eligibility and Special Tests and Provisions for Foster Care The Foster Care program was enacted under Title IV-E of the Social Security Act and is overseen at the federal level by the Department of Health and Human Services. The purpose of this program is to help States provide proper care for eligible children who need placement outside of their homes. A child may be removed from a home either by a court order or a voluntary placement agreement and may be placed with a relative, a foster family home, a residential child care facility, or a group home. In Colorado, the county departments of human/social services administer the Foster Care program, which includes determining a child’s eligibility to be funded under the program, and the Department supervises and monitors the counties. When a child is removed from the home, the county caseworkers gather necessary information to open a program case for that child. County caseworkers enter the information on a prescribed form for initial determination and redetermination for the program, including date of birth, whether the removal was voluntary or court ordered, household demographics, family income, and how the child was deprived of parental support. This information is also entered into the Department’s case management system, Trails, to document the child’s eligibility for the program. The population of all children funded by the Foster Care program is maintained within the Trails system. The State mandates specific requirements for the certification and eligibility determination of foster care providers to ensure the safety and well-being of children in the foster care system. Prospective foster homes must complete a state-approved training program, pass comprehensive background checks including fingerprinting and criminal history reviews, and undergo a thorough home study conducted by a licensed child placement agency. This home study includes interviews, home inspections, and assessments of the family's ability to provide a nurturing environment. Additionally, applicants must provide proof of good physical and mental health, demonstrate financial stability, and obtain CPR and first aid certification. Personal references are also required to further validate the suitability of the foster care providers. The population of all providers funded by the Foster Care program is maintained within Trails. Program funds are sent to eligible providers to support the care for eligible children. Another requirement for foster care providers is to complete a rate request form if they need foster care maintenance payments that exceed the amount set by the State. The rate request form is then required to be approved by the Department. In Fiscal Year 2024, the Department’s expenditures for the Foster Care program were approximately $93.5 million. The Department had 2,245 children and 1,451 providers in the program in Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the Foster Care program’s eligibility determination process, as well as to determine whether the Department complied with applicable eligibility determination requirements during Fiscal Year 2024. We reviewed a sample of 60 of the Department’s program case files for children who were determined eligible for the program and resided with a provider who received program payments for providing foster care for the child during Fiscal Year 2024. We also reviewed a sample of 60 of the Department’s program provider files for providers who were determined eligible for the program. Our testing included reviewing supporting documentation included in the case files as well as data entered into Trails related to eligibility determinations/redeterminations, and certifications of providers. How were the results of the audit work measured? We applied the following criteria during our testing: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • State regulation [12 CCR 2509-7.601.71(D)(3)] requires, as part of a child’s eligibility determination, that a county calculate the determination of need in which (1) the income and resources of the household members of the home the child is removed from must be less than $10,000 in countable resources and (2) the household income after Aid to Families with Dependent Children income tests are applied must be less than the need standard for the household. • State regulation [12 CCR 2509-7.601.71(J)(2)] requires that the redetermination of Title IV-E Eligibility Requirements be made within 12 months of the date the child enters foster care, and every 12 months thereafter while the child remains in out-of-home care. • 42 U.S. Code § 672(c)(1) notes that “the term “foster family home” means the home of an individual or family that is licensed or approved by the State in which it is situated as a foster family home that meets the standards established for the licensing or approval; and in which a child in foster care has been placed in the care of an individual, who resides with the child and who has been licensed or approved by the State to be a foster parent…” • 42 U.S. Code § 672(c)(2) notes that in general, “the term “child-care institution” means a private child-care institution, or a public child-care institution which accommodates no more than 25 children, which is licensed by the State in which it is situated or has been approved by the agency of the State responsible for licensing or approval of institutions of this type as meeting the standards established for the licensing…” • 42 U.S. Code § 671(a)(20)(A) and (B) notes that procedures for criminal records checks, including fingerprint-based checks of national crime information databases, for any prospective foster or adoptive parent must be completed before the foster or adoptive parent may finally be approved for placement of a child…and the State shall check any child abuse and neglect registry maintained by the State for information on any prospective foster or adoptive parent and on any other adult living in the home of such a prospective parent. • 42 U.S. Code § 671(a)(11) notes the need for a “periodic review…[over] amounts paid as foster care maintenance payments…to assure their continuing appropriateness.” What problems did the audit work identify? For Foster Care program eligibility of children, we identified a problem in 1 of the 60 case files tested (2 percent). Specifically, we identified the following: • One child whose removal home’s income exceeded the limit to be Title IV-E eligible for payments through the program. This was found during the audit process and the total questioned costs were $9,167 in Fiscal Year 2024. For eligibility and payment rate setting and application testing over providers—a special tests and provisions requirement for the program—we identified problems in 2 of the 60 case files tested (3 percent). These problems resulted in questioned costs of $1,764. Specifically, we identified the following: • Two providers in which the rate request and approval was not in the case file. This request and approval is required per 42 U.S. Code § 671(a)(11) when the rates paid to providers is not in-line with the approved daily rates. • Two providers had a rate calculated by county staff and paid to them that exceeded the approved rates, and no rate request documentation, including approvals, was contained in the case file. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with eligibility and special tests and provisions requirements for the Foster Care program during Fiscal Year 2024. For example, the Department did not require the counties to complete a checklist to ensure they comply with all program rules and regulations. In addition, while the Department does have a monitoring process over the counties that includes a quarterly administrative review of the counties’ compliance and data over Child Welfare, this monitoring does not regularly review the counties’ eligibility processes. The Department communicated that the counties administering the program continue to experience significant turnover in caseworker positions. This turnover results in new, inexperienced county caseworkers determining program eligibility, which further heightens the need for frequent, detailed training and an effective quality review process. Currently, the Department provides annual training to each county; however, the ongoing turnover underscores the necessity for more frequent and comprehensive training sessions to ensure all caseworkers are well-equipped to manage program requirements. Why do these problems matter? It is essential for the Department to ensure that a child’s eligibility and provider’s certifications for the Foster Care program are properly determined, documented, and in accordance with state and federal regulations. Furthermore, providing continuous and effective training on eligibility determinations and redetermination will aid in reducing errors and omissions of required documentation. Inaccurate processing of case file information used to determine eligibility can result in counties improperly granting program benefits to ineligible individuals or denying benefits to eligible individuals. Ensuring case file information includes proper payment rate supporting documentation is also required to meet federal regulations around special tests and provisions compliance requirements. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use general funds to cover the expenditures. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-043 The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Foster Care Title IV-E program eligibility and special tests and provisions requirements by: A. Ensuring that county caseworkers are appropriately trained on program requirements. This should include training all caseworkers who work on the program at a frequency that ensures that new caseworkers receive comprehensive training within a reasonable timeframe after hire and requiring at least one representative from each county to attend Department-provided training. B. Implementing a checklist that the counties must complete for each case to ensure compliance with laws and regulations. C. Enhancing the Department’s county review process to regularly review the counties’ eligibility processes, which should include a review of the counties’ use of the checklist. Response Department of Human Services A. Agree Implementation Date: June 2025 The Department currently provides quarterly training for both new workers and quarterly meetings. The department will require at least one representative from each county to attend a minimum of one training per fiscal year. New workers will still be required to attend a new worker training prior to gaining access to the IV-E module in Trails. B. Disagree Implementation Date: Not Applicable The Department currently uses the Trails system as a checklist for eligibility workers. Counties are required to utilize this system for their initial determinations. The department will monitor compliance and provide training to ensure adherence to applicable laws and requirements. Auditor’s Addendum Federal regulations require the Department to have internal controls in place to ensure compliance with the Foster Care program requirements. The audit found that the Department’s current internal controls are not effective in ensuring that the Department is in compliance with these requirements. Therefore, the Department should develop a checklist outside of the Trails system to further address caseworker responsibilities and provide a guide for their daily work to complement the Trails system. C. Partially Agree Implementation Date: June 2025 The Department will review the counties’ eligibility process during their IV-E review entrance meeting and ensure that their processes align with complying to laws and regulations. The department will include this process review in their review finding letter that is sent after each review. Auditor’s Addendum Federal regulations require the Department to have internal controls in place to ensure compliance with the Foster Care program requirements. The audit found that the Department’s current internal controls are not effective in ensuring that the Department is in compliance with these requirements. Therefore, the Department should enhance its monitoring and training processes by implementing a checklist outside of the Trails system itself to assist with caseworker knowledge of program requirements and related monitoring by counties’ of these requirements.
Show full finding ▾Hide full finding ▴Finding 2024-043 Compliance with Eligibility and Special Tests and Provisions for Foster Care The Foster Care program was enacted under Title IV-E of the Social Security Act and is overseen at the federal level by the Department of Health and Human Services. The purpose of this program is to help States provide proper care for eligible children who need placement outside of their homes. A child may be removed from a home either by a court order or a voluntary placement agreement and may be placed with a relative, a foster family home, a residential child care facility, or a group home. In Colorado, the county departments of human/social services administer the Foster Care program, which includes determining a child’s eligibility to be funded under the program, and the Department supervises and monitors the counties. When a child is removed from the home, the county caseworkers gather necessary information to open a program case for that child. County caseworkers enter the information on a prescribed form for initial determination and redetermination for the program, including date of birth, whether the removal was voluntary or court ordered, household demographics, family income, and how the child was deprived of parental support. This information is also entered into the Department’s case management system, Trails, to document the child’s eligibility for the program. The population of all children funded by the Foster Care program is maintained within the Trails system. The State mandates specific requirements for the certification and eligibility determination of foster care providers to ensure the safety and well-being of children in the foster care system. Prospective foster homes must complete a state-approved training program, pass comprehensive background checks including fingerprinting and criminal history reviews, and undergo a thorough home study conducted by a licensed child placement agency. This home study includes interviews, home inspections, and assessments of the family's ability to provide a nurturing environment. Additionally, applicants must provide proof of good physical and mental health, demonstrate financial stability, and obtain CPR and first aid certification. Personal references are also required to further validate the suitability of the foster care providers. The population of all providers funded by the Foster Care program is maintained within Trails. Program funds are sent to eligible providers to support the care for eligible children. Another requirement for foster care providers is to complete a rate request form if they need foster care maintenance payments that exceed the amount set by the State. The rate request form is then required to be approved by the Department. In Fiscal Year 2024, the Department’s expenditures for the Foster Care program were approximately $93.5 million. The Department had 2,245 children and 1,451 providers in the program in Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the Foster Care program’s eligibility determination process, as well as to determine whether the Department complied with applicable eligibility determination requirements during Fiscal Year 2024. We reviewed a sample of 60 of the Department’s program case files for children who were determined eligible for the program and resided with a provider who received program payments for providing foster care for the child during Fiscal Year 2024. We also reviewed a sample of 60 of the Department’s program provider files for providers who were determined eligible for the program. Our testing included reviewing supporting documentation included in the case files as well as data entered into Trails related to eligibility determinations/redeterminations, and certifications of providers. How were the results of the audit work measured? We applied the following criteria during our testing: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • State regulation [12 CCR 2509-7.601.71(D)(3)] requires, as part of a child’s eligibility determination, that a county calculate the determination of need in which (1) the income and resources of the household members of the home the child is removed from must be less than $10,000 in countable resources and (2) the household income after Aid to Families with Dependent Children income tests are applied must be less than the need standard for the household. • State regulation [12 CCR 2509-7.601.71(J)(2)] requires that the redetermination of Title IV-E Eligibility Requirements be made within 12 months of the date the child enters foster care, and every 12 months thereafter while the child remains in out-of-home care. • 42 U.S. Code § 672(c)(1) notes that “the term “foster family home” means the home of an individual or family that is licensed or approved by the State in which it is situated as a foster family home that meets the standards established for the licensing or approval; and in which a child in foster care has been placed in the care of an individual, who resides with the child and who has been licensed or approved by the State to be a foster parent…” • 42 U.S. Code § 672(c)(2) notes that in general, “the term “child-care institution” means a private child-care institution, or a public child-care institution which accommodates no more than 25 children, which is licensed by the State in which it is situated or has been approved by the agency of the State responsible for licensing or approval of institutions of this type as meeting the standards established for the licensing…” • 42 U.S. Code § 671(a)(20)(A) and (B) notes that procedures for criminal records checks, including fingerprint-based checks of national crime information databases, for any prospective foster or adoptive parent must be completed before the foster or adoptive parent may finally be approved for placement of a child…and the State shall check any child abuse and neglect registry maintained by the State for information on any prospective foster or adoptive parent and on any other adult living in the home of such a prospective parent. • 42 U.S. Code § 671(a)(11) notes the need for a “periodic review…[over] amounts paid as foster care maintenance payments…to assure their continuing appropriateness.” What problems did the audit work identify? For Foster Care program eligibility of children, we identified a problem in 1 of the 60 case files tested (2 percent). Specifically, we identified the following: • One child whose removal home’s income exceeded the limit to be Title IV-E eligible for payments through the program. This was found during the audit process and the total questioned costs were $9,167 in Fiscal Year 2024. For eligibility and payment rate setting and application testing over providers—a special tests and provisions requirement for the program—we identified problems in 2 of the 60 case files tested (3 percent). These problems resulted in questioned costs of $1,764. Specifically, we identified the following: • Two providers in which the rate request and approval was not in the case file. This request and approval is required per 42 U.S. Code § 671(a)(11) when the rates paid to providers is not in-line with the approved daily rates. • Two providers had a rate calculated by county staff and paid to them that exceeded the approved rates, and no rate request documentation, including approvals, was contained in the case file. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with eligibility and special tests and provisions requirements for the Foster Care program during Fiscal Year 2024. For example, the Department did not require the counties to complete a checklist to ensure they comply with all program rules and regulations. In addition, while the Department does have a monitoring process over the counties that includes a quarterly administrative review of the counties’ compliance and data over Child Welfare, this monitoring does not regularly review the counties’ eligibility processes. The Department communicated that the counties administering the program continue to experience significant turnover in caseworker positions. This turnover results in new, inexperienced county caseworkers determining program eligibility, which further heightens the need for frequent, detailed training and an effective quality review process. Currently, the Department provides annual training to each county; however, the ongoing turnover underscores the necessity for more frequent and comprehensive training sessions to ensure all caseworkers are well-equipped to manage program requirements. Why do these problems matter? It is essential for the Department to ensure that a child’s eligibility and provider’s certifications for the Foster Care program are properly determined, documented, and in accordance with state and federal regulations. Furthermore, providing continuous and effective training on eligibility determinations and redetermination will aid in reducing errors and omissions of required documentation. Inaccurate processing of case file information used to determine eligibility can result in counties improperly granting program benefits to ineligible individuals or denying benefits to eligible individuals. Ensuring case file information includes proper payment rate supporting documentation is also required to meet federal regulations around special tests and provisions compliance requirements. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use general funds to cover the expenditures. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-043 The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Foster Care Title IV-E program eligibility and special tests and provisions requirements by: A. Ensuring that county caseworkers are appropriately trained on program requirements. This should include training all caseworkers who work on the program at a frequency that ensures that new caseworkers receive comprehensive training within a reasonable timeframe after hire and requiring at least one representative from each county to attend Department-provided training. B. Implementing a checklist that the counties must complete for each case to ensure compliance with laws and regulations. C. Enhancing the Department’s county review process to regularly review the counties’ eligibility processes, which should include a review of the counties’ use of the checklist. Response Department of Human Services A. Agree Implementation Date: June 2025 The Department currently provides quarterly training for both new workers and quarterly meetings. The department will require at least one representative from each county to attend a minimum of one training per fiscal year. New workers will still be required to attend a new worker training prior to gaining access to the IV-E module in Trails. B. Disagree Implementation Date: Not Applicable The Department currently uses the Trails system as a checklist for eligibility workers. Counties are required to utilize this system for their initial determinations. The department will monitor compliance and provide training to ensure adherence to applicable laws and requirements. Auditor’s Addendum Federal regulations require the Department to have internal controls in place to ensure compliance with the Foster Care program requirements. The audit found that the Department’s current internal controls are not effective in ensuring that the Department is in compliance with these requirements. Therefore, the Department should develop a checklist outside of the Trails system to further address caseworker responsibilities and provide a guide for their daily work to complement the Trails system. C. Partially Agree Implementation Date: June 2025 The Department will review the counties’ eligibility process during their IV-E review entrance meeting and ensure that their processes align with complying to laws and regulations. The department will include this process review in their review finding letter that is sent after each review. Auditor’s Addendum Federal regulations require the Department to have internal controls in place to ensure compliance with the Foster Care program requirements. The audit found that the Department’s current internal controls are not effective in ensuring that the Department is in compliance with these requirements. Therefore, the Department should enhance its monitoring and training processes by implementing a checklist outside of the Trails system itself to assist with caseworker knowledge of program requirements and related monitoring by counties’ of these requirements.
The Department will review the counties’ eligibility process during their IV-E review entrance meeting and ensure that their processes align with complying to laws and regulations. The department will include this process review in their review finding letter that is sent after each review.
2023-066
Finding 2024-044 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for CSS and MHBG The objective of the MHBG program is to provide funds to states and territories to enable them to carry out their respective plans for providing comprehensive community-based mental health services for adults with serious mental illness and children with serious emotional disturbances. To ensure creative and cost-effective delivery of services, states are encouraged to develop solutions to address the specific mental health concerns of their local communities. The objectives of the Child Support Services (CSS) program are to (1) locate absent parents, (2) establish paternity, (3) obtain child and spousal support, and (4) enforce support obligations owed by noncustodial parents. The Department is responsible for monitoring its costs and activities charged to both federal programs for allowability, specifically to ensure costs and activities are permitted under federal regulations and grant agreements. MHBG allowable activities include services provided through qualified community programs, such as mental health centers, outpatient services, emergency care, day treatment, and patient screening for state mental health facilities. Unallowable activities include providing inpatient hospital services, making cash payments to recipients, purchasing or improving land or major medical equipment, satisfying nonfederal funding requirements, and providing financial assistance to entities other than public or nonprofit entities. CSS allowable activities include parent locator services, paternity and support services, program administration, and establishing agreements with other agencies and private providers. State programs can also fund support services for individuals with assigned support rights, necessary and reasonable services and activities, minor transportation expenses, pro se access to adjudicative processes, and educational outreach activities. Unallowable activities include administering other Social Security Act titles, construction and major renovations, reimbursed expenditures, jailing parents, and costs of counsel or guardians ad litem in Title IV-D actions. Title IV-D refers to a section of the Social Security Act that deals with child support and establishment of paternity. State programs cannot fund: • Education and training programs outside Title IV-D agency staff. • Any expenditures related to carrying out an agreement under federal regulation [45 CFR 303.15] (i.e. agreements to use the Federal Parent Locator Service in parental kidnapping and child custody visitation cases). • Caseworker costs. • Medical support enforcement under cooperative arrangements, costs associated with agreements with courts and law enforcement officials (i.e. service of process and court filing fees, unless the court or law enforcement agency would normally be required to pay the costs; costs of compensation of judges and staff of judges; costs of training and travel related to the judicial determination process incurred by judges; and office-related costs), and support enforcement services which are not secured in accordance with Federal Financial Participation. The Department has established controls that require invoices to be reviewed and approved by different personnel than those requesting the disbursement. In addition, backup documentation must be reviewed for accuracy and allowability before a payment is approved. For Fiscal Year 2024, the MHBG program had 1,177 general disbursement transactions totaling $3,539,878, and the CSS program had 4,321 general disbursement transactions totaling $2,894,463. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over federal allowable activities and allowable cost requirements for the MHBG and CSS programs, and to determine whether the Department complied with federal allowable costs requirements for the two programs during Fiscal Year 2024. As part of our audit work, we randomly selected 40 cash disbursements for each of the two programs, which consisted of general disbursement transactions. We reviewed supporting documentation provided by the Department for allowability and evidence of internal controls through documented approvals of the expenditures. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR section 200.403] requires that costs under Federal awards must be necessary, reasonable, and allocable, conform to limitations, be consistent with policies, receive consistent treatment, adhere to Generally Accepted Accounting Principles, not be used for cost sharing of other programs, and be adequately documented. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice or purchase order, included with the transaction, and the supporting documentation must be reviewed for accuracy and allowability under the applicable federal grant program by two individuals. What problems did the audit work identify? Based on our audit test work, we determined that the Department did not ensure that costs charged to either federal grant were allowable, and there was not proper evidence of internal control procedures. Specifically, we identified the following: • MHBG—For 1 of 40 (3 percent) general disbursement transactions selected for testing, the Department could not provide evidence of Department staff’s review and approval of the transaction. Additionally, this transaction was erroneously charged to the grant. This resulted in questioned costs of $6. • CSS—For 5 of 40 (13 percent) general disbursement transactions selected for testing, the Department could not provide evidence of Department staff’s review and approval of the transaction. This resulted in questioned costs of $192. Why did these problems occur? Per the Department’s policies and procedures, Department staff must obtain documented approval over grant expenditures. However, the Department did not maintain supporting documentation to demonstrate approval of these expenditures because these expenditures involved multiple State entities. The Department did not have procedures in place to obtain documentation of the approvals of these types of expenditures for grant purposes. Why do these problems matter? By failing to properly review and approve transactions charged to its federal grants, unallowable costs were charged to both programs. Ultimately, if the Department fails to comply with federal grant requirements, the federal government may disallow the Department’s grant expenditures and the Department would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-044 The Department of Human Services (Department) should improve its internal controls over and ensure compliance with federal Block Grants for Community Mental Health Services and Child Support Services programs to ensure costs charged to these grant programs are allowable. Specifically, the Department should update its written procedure to require documented review and approval over all grant expenditures, including those that involve other State entities. Response Department of Human Services Partially Agree Implementation Date: April 2025 The Department partially agrees with the recommendation. The Department agrees to inform program staff at the currently set fiscal meetings to review for correct coding related to internally initiated expenditures. The Department disagrees with the recommendation around transactions (IET1) that are automated uploads directly from DPA (Department of Program Administration). The charges do not come through in the CDHS cabinet’s Doc ID. Therefore, we’re unable to review and approve before the automatic posting. Auditor’s Addendum As discussed in our finding, the Department is responsible for maintaining documentation of internal controls to evidence review for accuracy and allowability of federal grant program expenditures. Specifically, the Department did not provide evidence that demonstrated approval over these grant expenditures in accordance with their internal control procedures. For transactions that are initiated or processed by other State departments, the Department is still responsible to evidence review for accuracy and allowability of federal grant expenditures. The Department should update its written procedures to address cases where grant expenditures are processed by other State departments to ensure that Department staff knowledgeable about allowability of grant expenditures are reviewing for these requirements. The Department is still ultimately responsible for the allowability of all federal grant expenditures for this Program, regardless of which State Department initiates transactions.
Show full finding ▾Hide full finding ▴Finding 2024-044 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for CSS and MHBG The objective of the MHBG program is to provide funds to states and territories to enable them to carry out their respective plans for providing comprehensive community-based mental health services for adults with serious mental illness and children with serious emotional disturbances. To ensure creative and cost-effective delivery of services, states are encouraged to develop solutions to address the specific mental health concerns of their local communities. The objectives of the Child Support Services (CSS) program are to (1) locate absent parents, (2) establish paternity, (3) obtain child and spousal support, and (4) enforce support obligations owed by noncustodial parents. The Department is responsible for monitoring its costs and activities charged to both federal programs for allowability, specifically to ensure costs and activities are permitted under federal regulations and grant agreements. MHBG allowable activities include services provided through qualified community programs, such as mental health centers, outpatient services, emergency care, day treatment, and patient screening for state mental health facilities. Unallowable activities include providing inpatient hospital services, making cash payments to recipients, purchasing or improving land or major medical equipment, satisfying nonfederal funding requirements, and providing financial assistance to entities other than public or nonprofit entities. CSS allowable activities include parent locator services, paternity and support services, program administration, and establishing agreements with other agencies and private providers. State programs can also fund support services for individuals with assigned support rights, necessary and reasonable services and activities, minor transportation expenses, pro se access to adjudicative processes, and educational outreach activities. Unallowable activities include administering other Social Security Act titles, construction and major renovations, reimbursed expenditures, jailing parents, and costs of counsel or guardians ad litem in Title IV-D actions. Title IV-D refers to a section of the Social Security Act that deals with child support and establishment of paternity. State programs cannot fund: • Education and training programs outside Title IV-D agency staff. • Any expenditures related to carrying out an agreement under federal regulation [45 CFR 303.15] (i.e. agreements to use the Federal Parent Locator Service in parental kidnapping and child custody visitation cases). • Caseworker costs. • Medical support enforcement under cooperative arrangements, costs associated with agreements with courts and law enforcement officials (i.e. service of process and court filing fees, unless the court or law enforcement agency would normally be required to pay the costs; costs of compensation of judges and staff of judges; costs of training and travel related to the judicial determination process incurred by judges; and office-related costs), and support enforcement services which are not secured in accordance with Federal Financial Participation. The Department has established controls that require invoices to be reviewed and approved by different personnel than those requesting the disbursement. In addition, backup documentation must be reviewed for accuracy and allowability before a payment is approved. For Fiscal Year 2024, the MHBG program had 1,177 general disbursement transactions totaling $3,539,878, and the CSS program had 4,321 general disbursement transactions totaling $2,894,463. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over federal allowable activities and allowable cost requirements for the MHBG and CSS programs, and to determine whether the Department complied with federal allowable costs requirements for the two programs during Fiscal Year 2024. As part of our audit work, we randomly selected 40 cash disbursements for each of the two programs, which consisted of general disbursement transactions. We reviewed supporting documentation provided by the Department for allowability and evidence of internal controls through documented approvals of the expenditures. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR section 200.403] requires that costs under Federal awards must be necessary, reasonable, and allocable, conform to limitations, be consistent with policies, receive consistent treatment, adhere to Generally Accepted Accounting Principles, not be used for cost sharing of other programs, and be adequately documented. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice or purchase order, included with the transaction, and the supporting documentation must be reviewed for accuracy and allowability under the applicable federal grant program by two individuals. What problems did the audit work identify? Based on our audit test work, we determined that the Department did not ensure that costs charged to either federal grant were allowable, and there was not proper evidence of internal control procedures. Specifically, we identified the following: • MHBG—For 1 of 40 (3 percent) general disbursement transactions selected for testing, the Department could not provide evidence of Department staff’s review and approval of the transaction. Additionally, this transaction was erroneously charged to the grant. This resulted in questioned costs of $6. • CSS—For 5 of 40 (13 percent) general disbursement transactions selected for testing, the Department could not provide evidence of Department staff’s review and approval of the transaction. This resulted in questioned costs of $192. Why did these problems occur? Per the Department’s policies and procedures, Department staff must obtain documented approval over grant expenditures. However, the Department did not maintain supporting documentation to demonstrate approval of these expenditures because these expenditures involved multiple State entities. The Department did not have procedures in place to obtain documentation of the approvals of these types of expenditures for grant purposes. Why do these problems matter? By failing to properly review and approve transactions charged to its federal grants, unallowable costs were charged to both programs. Ultimately, if the Department fails to comply with federal grant requirements, the federal government may disallow the Department’s grant expenditures and the Department would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-044 The Department of Human Services (Department) should improve its internal controls over and ensure compliance with federal Block Grants for Community Mental Health Services and Child Support Services programs to ensure costs charged to these grant programs are allowable. Specifically, the Department should update its written procedure to require documented review and approval over all grant expenditures, including those that involve other State entities. Response Department of Human Services Partially Agree Implementation Date: April 2025 The Department partially agrees with the recommendation. The Department agrees to inform program staff at the currently set fiscal meetings to review for correct coding related to internally initiated expenditures. The Department disagrees with the recommendation around transactions (IET1) that are automated uploads directly from DPA (Department of Program Administration). The charges do not come through in the CDHS cabinet’s Doc ID. Therefore, we’re unable to review and approve before the automatic posting. Auditor’s Addendum As discussed in our finding, the Department is responsible for maintaining documentation of internal controls to evidence review for accuracy and allowability of federal grant program expenditures. Specifically, the Department did not provide evidence that demonstrated approval over these grant expenditures in accordance with their internal control procedures. For transactions that are initiated or processed by other State departments, the Department is still responsible to evidence review for accuracy and allowability of federal grant expenditures. The Department should update its written procedures to address cases where grant expenditures are processed by other State departments to ensure that Department staff knowledgeable about allowability of grant expenditures are reviewing for these requirements. The Department is still ultimately responsible for the allowability of all federal grant expenditures for this Program, regardless of which State Department initiates transactions.
The Department partially agrees with the recommendation. The Department agrees to inform program staff at the currently set fiscal meetings to review for correct coding related to internally initiated expenditures. The Department disagrees with the recommendation around transactions (IET1) that are automated uploads directly from DPA (Department of Program Administration). The charges do not come through in the CDHS cabinet’s Doc ID. Therefore, we’re unable to review and approve before the automatic posting.
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Human Services (Department) in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-063 The Department of Human Services (Department) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for the Department through interagency agreements with the Governor’s Office of Information Technology and Department of Health Care Policy and Financing. Response Department of Human Services Agree Implementation Date: September 2024 The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Human Services (Department) in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-063 The Department of Human Services (Department) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for the Department through interagency agreements with the Governor’s Office of Information Technology and Department of Health Care Policy and Financing. Response Department of Human Services Agree Implementation Date: September 2024 The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
2023-063
Finding 2024-046 Compliance with Special Tests and Provisions for Unemployment Insurance Employer Experience Rating The Department’s UI Division (Division) is responsible for the administration and monitoring of Colorado’s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits paid to ensure the payments were appropriate. Employer-paid premiums are the primary source of funding for UI benefits. Federal regulations [26 U.S.C. § 3301] outline the process the Division must use to determine a new employer’s initial UI premium rate that is applied to the employers’ total annual wages to calculate its UI premiums, as well as the process the Division must use to make subsequent changes to the employer’s rate over time. New employers begin at a standard rate depending on their type of business activity. This initial rate will subsequently change based upon the amount of UI benefits that are paid to the employer’s former employees—UI claimants—by the Department and subsequently charged to the employer’s account. Thus, the more charges against the account, the higher the employer’s rate; and similarly, the fewer charges against the account, the lower the employer’s rate. This is referred to as the “employer experience rating.” The purpose of the ratings process is to ensure an equitable distribution of costs of the UI program among the employers. Annually, the Division multiplies this calculated rate by the employer’s total wages to determine the amount of premiums that the employer is required to pay. For example, the Division calculates the employer’s rate for Calendar Year 2025 during Fiscal Year 2024, using Fiscal Year 2024 wage information. According to Division staff, they switched from using their prior UI system, CATS, to MyUI+, the Department’s new UI system, for the first time in Fiscal Year 2023 to calculate the Calendar Year 2024 rates. The rate for employers (who are not a new employer) is primarily a function of three components: • Premiums Paid: All contributions made by the employer over the time the employer is paying premiums into the UI program. • Benefits Charged: All benefits charged to the employer in total during the time period the employer has paid premiums into the UI program. • Average Annual Payroll: The average annual wages the employer reported during the previous three state fiscal years (July-June). Wages are reported by employers through MyUI+. The Division uses MyUI+ to calculate each employer’s “Percent of Excess,” which determines the rate assigned to employers and is calculated using the formula noted in the following example: See Schedule of Finding and Questioned Costs for chart/table. If the Division calculates a higher Percent of Excess for an employer, a lower rate is assigned to the employer, and if the Division calculates a lower Percent of Excess (including negative excess), then a higher rate is assigned to the employer. According to information provided by the Department, the Department calculated Calendar Year 2024 UI premium rates for 221,271 employers during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Division’s internal controls over and the calculation of the UI employer experience rate to determine whether MyUI+ is calculating the rate correctly, and whether the Department was in compliance with federal regulations related to the UI employer experience rating during Fiscal Year 2024. As part of our audit work, we met with the Division to review a sample of one employer to gain an understanding of the process for calculating an employer rate, and determine whether MyUI+ calculated the Calendar Year 2024 employer rates correctly during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit against the following: • Federal regulations require that the Division use an experience rating system when calculating employer UI premium rates if permitted by state law. Specifically, 26 United States Code 3303(a)(1), Conditions of Additional Allowance, states that a “taxpayer shall be allowed an additional credit with respect to any reduced rate of contributions permitted by a State law, only if the Secretary of Labor finds that under such law no reduced rate of contributions to a pooled fund or to a partially pooled account is permitted to a person (or group of persons) having individuals in his (or their) employ except on the basis of his (or their) experience with respect to unemployment or other factors bearing a direct relation to unemployment risk during not less than the 3 consecutive years immediately preceding the computation date.” • Section 8-76-102.5(3)(a), C.R.S., states that “the total of an employer’s premiums paid, designated, and deposited into the unemployment compensation fund on the employer’s behalf on or before thirty-one days immediately after the computation date and the total benefits that were chargeable to the employer's account and were paid before the computation date, with respect to weeks, or any established payroll period of unemployment, beginning before the computation date, is used to compute the employer’s premium rate for the following calendar year.” This statutory section also defines Percent of Excess as the percentage resulting from dividing the excess of premiums paid over benefits charged by the average chargeable payroll, computed to the nearest one percent. • Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. What problem did the audit work identify? Based on our audit testwork, we determined that MyUI+ did not calculate the employer rate correctly for the employer we reviewed. Specifically, for the one employer we reviewed, MyUI+ calculated the rate as 3.635 percent instead of the correct rate of 2.545 percent; this rate error resulted in the employer’s premiums being calculated as $1,640 instead of the correct amount of $1,148. After additional inquiry, the Department indicated that they identified approximately 30,000 employers whose Calendar Year 2024 rates were calculated incorrectly by MyUI+, which resulted in employers overpaying approximately $5.0 million in premiums. As of the end of our audit, the Department had not communicated the error to the employers or repaid any employer overpayments. The Department indicated that the error primarily resulted in employer premium overpayments, but in some cases it could have resulted in employer premium underpayments. Why did this problem occur? According to the Department, the issue identified through our testing occurred due to a system issue in MyUI+. Specifically, Department staff indicated that a programming error in MyUI+ resulted in MyUI+ calculating the Average Annual Payroll incorrectly for some employers, which ultimately affected the employer rate. In addition, Division staff indicated that they have not drafted updated policies and procedures for calculating rates in MyUI+, so staff did not attempt to recalculate any employer rates and did not, therefore, identify the programming error. Why does this problem matter? These problems matter because the Department improperly calculated an employer’s rate, which primarily resulted in the employers overpaying their UI premiums for 2024. Ultimately, the Department is out of compliance with federal regulations and penalizing employers unfairly if the rate is too high, or giving them an undeserved benefit if it is too low. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-046 The Department of Labor and Employment should ensure that the Unemployment Insurance Division staff take steps to resolve the MyUI+ system programming issue identified in our audit that affected employer unemployment rates and premium payments. This should include identifying all of the employers affected by the issue, making the necessary adjustments to their current and prior rates and calculated premiums, and refunding or collecting any overpayments and underpayments, respectively, as applicable. Response Department of Labor and Employment Agree Implementation Date: December 2024 The Department of Labor and Employment has ensured that the Unemployment Division staff has taken all necessary steps to resolve the MyUI+ system programming issue identified in the audit that affected employer unemployment rates and premium payments. The Division identified all of the employers affected, immediately made the necessary adjustments to their rates, recalculated premiums, and established credits or adjusted amounts owed for all totals as a result of these updates as applicable. This has been facilitated by providing a credit for any overpayments, which the employer may elect to have refunded or applied to future premiums due. Employers who have any balance attributed to unpaid premiums from previous years have had the credit applied to those outstanding balances. All changes and corrections were implemented as of December 23, 2024. The defect will have no impact on rates or calculations for 2025 and beyond.
Show full finding ▾Hide full finding ▴Finding 2024-046 Compliance with Special Tests and Provisions for Unemployment Insurance Employer Experience Rating The Department’s UI Division (Division) is responsible for the administration and monitoring of Colorado’s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits paid to ensure the payments were appropriate. Employer-paid premiums are the primary source of funding for UI benefits. Federal regulations [26 U.S.C. § 3301] outline the process the Division must use to determine a new employer’s initial UI premium rate that is applied to the employers’ total annual wages to calculate its UI premiums, as well as the process the Division must use to make subsequent changes to the employer’s rate over time. New employers begin at a standard rate depending on their type of business activity. This initial rate will subsequently change based upon the amount of UI benefits that are paid to the employer’s former employees—UI claimants—by the Department and subsequently charged to the employer’s account. Thus, the more charges against the account, the higher the employer’s rate; and similarly, the fewer charges against the account, the lower the employer’s rate. This is referred to as the “employer experience rating.” The purpose of the ratings process is to ensure an equitable distribution of costs of the UI program among the employers. Annually, the Division multiplies this calculated rate by the employer’s total wages to determine the amount of premiums that the employer is required to pay. For example, the Division calculates the employer’s rate for Calendar Year 2025 during Fiscal Year 2024, using Fiscal Year 2024 wage information. According to Division staff, they switched from using their prior UI system, CATS, to MyUI+, the Department’s new UI system, for the first time in Fiscal Year 2023 to calculate the Calendar Year 2024 rates. The rate for employers (who are not a new employer) is primarily a function of three components: • Premiums Paid: All contributions made by the employer over the time the employer is paying premiums into the UI program. • Benefits Charged: All benefits charged to the employer in total during the time period the employer has paid premiums into the UI program. • Average Annual Payroll: The average annual wages the employer reported during the previous three state fiscal years (July-June). Wages are reported by employers through MyUI+. The Division uses MyUI+ to calculate each employer’s “Percent of Excess,” which determines the rate assigned to employers and is calculated using the formula noted in the following example: See Schedule of Finding and Questioned Costs for chart/table. If the Division calculates a higher Percent of Excess for an employer, a lower rate is assigned to the employer, and if the Division calculates a lower Percent of Excess (including negative excess), then a higher rate is assigned to the employer. According to information provided by the Department, the Department calculated Calendar Year 2024 UI premium rates for 221,271 employers during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Division’s internal controls over and the calculation of the UI employer experience rate to determine whether MyUI+ is calculating the rate correctly, and whether the Department was in compliance with federal regulations related to the UI employer experience rating during Fiscal Year 2024. As part of our audit work, we met with the Division to review a sample of one employer to gain an understanding of the process for calculating an employer rate, and determine whether MyUI+ calculated the Calendar Year 2024 employer rates correctly during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit against the following: • Federal regulations require that the Division use an experience rating system when calculating employer UI premium rates if permitted by state law. Specifically, 26 United States Code 3303(a)(1), Conditions of Additional Allowance, states that a “taxpayer shall be allowed an additional credit with respect to any reduced rate of contributions permitted by a State law, only if the Secretary of Labor finds that under such law no reduced rate of contributions to a pooled fund or to a partially pooled account is permitted to a person (or group of persons) having individuals in his (or their) employ except on the basis of his (or their) experience with respect to unemployment or other factors bearing a direct relation to unemployment risk during not less than the 3 consecutive years immediately preceding the computation date.” • Section 8-76-102.5(3)(a), C.R.S., states that “the total of an employer’s premiums paid, designated, and deposited into the unemployment compensation fund on the employer’s behalf on or before thirty-one days immediately after the computation date and the total benefits that were chargeable to the employer's account and were paid before the computation date, with respect to weeks, or any established payroll period of unemployment, beginning before the computation date, is used to compute the employer’s premium rate for the following calendar year.” This statutory section also defines Percent of Excess as the percentage resulting from dividing the excess of premiums paid over benefits charged by the average chargeable payroll, computed to the nearest one percent. • Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. What problem did the audit work identify? Based on our audit testwork, we determined that MyUI+ did not calculate the employer rate correctly for the employer we reviewed. Specifically, for the one employer we reviewed, MyUI+ calculated the rate as 3.635 percent instead of the correct rate of 2.545 percent; this rate error resulted in the employer’s premiums being calculated as $1,640 instead of the correct amount of $1,148. After additional inquiry, the Department indicated that they identified approximately 30,000 employers whose Calendar Year 2024 rates were calculated incorrectly by MyUI+, which resulted in employers overpaying approximately $5.0 million in premiums. As of the end of our audit, the Department had not communicated the error to the employers or repaid any employer overpayments. The Department indicated that the error primarily resulted in employer premium overpayments, but in some cases it could have resulted in employer premium underpayments. Why did this problem occur? According to the Department, the issue identified through our testing occurred due to a system issue in MyUI+. Specifically, Department staff indicated that a programming error in MyUI+ resulted in MyUI+ calculating the Average Annual Payroll incorrectly for some employers, which ultimately affected the employer rate. In addition, Division staff indicated that they have not drafted updated policies and procedures for calculating rates in MyUI+, so staff did not attempt to recalculate any employer rates and did not, therefore, identify the programming error. Why does this problem matter? These problems matter because the Department improperly calculated an employer’s rate, which primarily resulted in the employers overpaying their UI premiums for 2024. Ultimately, the Department is out of compliance with federal regulations and penalizing employers unfairly if the rate is too high, or giving them an undeserved benefit if it is too low. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-046 The Department of Labor and Employment should ensure that the Unemployment Insurance Division staff take steps to resolve the MyUI+ system programming issue identified in our audit that affected employer unemployment rates and premium payments. This should include identifying all of the employers affected by the issue, making the necessary adjustments to their current and prior rates and calculated premiums, and refunding or collecting any overpayments and underpayments, respectively, as applicable. Response Department of Labor and Employment Agree Implementation Date: December 2024 The Department of Labor and Employment has ensured that the Unemployment Division staff has taken all necessary steps to resolve the MyUI+ system programming issue identified in the audit that affected employer unemployment rates and premium payments. The Division identified all of the employers affected, immediately made the necessary adjustments to their rates, recalculated premiums, and established credits or adjusted amounts owed for all totals as a result of these updates as applicable. This has been facilitated by providing a credit for any overpayments, which the employer may elect to have refunded or applied to future premiums due. Employers who have any balance attributed to unpaid premiums from previous years have had the credit applied to those outstanding balances. All changes and corrections were implemented as of December 23, 2024. The defect will have no impact on rates or calculations for 2025 and beyond.
The Department of Labor and Employment has ensured that the Unemployment Division staff has taken all necessary steps to resolve the MyUI+ system programming issue identified in the audit that affected employer unemployment rates and premium payments. The Division identified all of the employers affected, immediately made the necessary adjustments to their rates, recalculated premiums, and established credits or adjusted amounts owed for all totals as a result of these updates as applicable. This has been facilitated by providing a credit for any overpayments, which the employer may elect to have refunded or applied to future premiums due. Employers who have any balance attributed to unpaid premiums from previous years have had the credit applied to those outstanding balances. All changes and corrections were implemented as of December 23, 2024. The defect will have no impact on rates or calculations for 2025 and beyond.
Finding 2024-047 MyUI+ — IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal UI program, and the Department relies on the IT system, MyUI+, to aid with determining applicants’ eligibility for the program and to provide information necessary to meet federal reporting requirements. The Department is the business owner and works with the Governor’s Office of Information Technology (OIT) and its external IT service provider to manage MyUI+. The MyUI+ system determines UI eligibility determinations and calculates UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ provided data necessary for federal reporting to the U.S. Department of Labor for the UI program. The Department stated that, in October 2024, to modernize its Colorado Automated Tax System (CATS), which was its system used to track and report unemployment premium payments made by employers, it updated MyUI+ and added this functionality that was previously within CATS. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to responsible staff, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2024 audit work was to determine whether the Department implemented two of our Fiscal Year 2023 recommendations: (1) Recommendation 2023-073 relating to MyUI+, and (2) Recommendation 2023-028, relating to CATS. Specifically, at that time, we recommended that the Department should: For Recommendation 2023-073, improve its overall IT governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ system by: • Recommendation Part A—Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the business owner requirements listed within the OIT’s March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. • Recommendation Part B—Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. • Recommendation Part C—Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. • Implementing recommendation Part D as noted in the confidential finding. For Recommendation 2023-028, reprioritize staff, as applicable, to improve information security controls over CATS by: • Implementing recommendation Part E as noted in the confidential finding. • Implementing recommendation Part F as noted in the confidential finding. Our audit work was performed through inquiries of Department management and staff and review of the supporting documentation. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2024, we found that the Department did not fully implement our prior audit recommendations for MyUI+. For Recommendation 2023-073, we noted the following for each recommendation: • Recommendation Part A—Although the Department formally adopted OIT’s Security Policies as the Department’s IT policy framework and communicated the adoption to Department staff, this communication did not extend to or include its IT service providers. • Recommendation Part B—Although the Department provided certain MyUI+ access control procedures, the Department stated that it had not yet formalized or drafted other standard operating procedures for MyUI+ to ensure alignment with the formally adopted IT policies noted in recommendation Part A. Also, although the Department drafted a review process for updating all IT policies, it did not formalize this or specify the frequency of the review. The Green Book states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part C—Although the Department formalized a vendor management process to ensure Department staff hold the Department’s IT service providers accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B, the Department had not formalized procedures around contract reviews to determine whether amendments to those contracts are necessary. In addition, and as stated above in recommendation Part A, the Department also did not communicate the IT policy framework adoption to its IT service providers. Security Policies state that IT service providers—which are defined as OIT and/or external service providers—must follow the Security Policy requirements. Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department’s contract with the MyUI+ IT service provider stating that the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor’s Office of Information Technology. The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. Further, Principle 15.03, Communication with External Parties states, that management communicates quality information externally so that external parties, such as contractors or service providers, help the Department achieve its objectives and address related risks. • Recommendation Part D—The Department did not fully implement the prior audit recommendation. We measured the results of our work against Security Policies and the IRS’s Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies November Revision. For Recommendation 2023-028, we noted the following for each recommendation: • Recommendation Part E—Although the Department and its external IT service provider had partially implemented the prior audit recommendation for MyUI+, no documentation was provided to verify that the Department and its external IT service provider formalized certain procedures associated with the confidential finding. The Green Book states in Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part F—We found through our audit work on Recommendation 2023-073A-D and 2023-028E above that these prior recommendations were not fully implemented because the Department failed to fully comply with Security Policies and Publication 1075. Why did these problems occur? Department staff stated that they continue to work to implement prior audit Recommendation 2023-073. However, the Department did not provide specific reasons for why the prior audit recommendation has not been implemented for the second consecutive year, as the recommendation dates back to Fiscal Year 2022. Department staff reported that the prior audit Recommendation 2023-028 is no longer valid because the Department misinterpreted our recommendations. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security controls are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately, could impact data reliability of the data stored and processed within MyUI+. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-047 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ information system by: A. Formalizing and communicating to the Department’s IT service providers the adoption of the Governor’s Office of Information Technology’s (OIT) Colorado Information Security Policies (Security Policies). B. Continuing to formalize and communicate IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. In addition, the Department should work with its external IT service provider to formalize procedures as noted in recommendation Part B of the confidential finding for MyUI+. C. Formalizing within the Department’s vendor management process a review of the Department’s current external IT service providers’ contracts and a process to determine whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Accurately interpreting audit recommendations to ensure that management addresses them and the associated IT risks appropriately, in accordance with expectations and risk tolerance. Response Department of Labor and Employment A. Agree Implementation Date: March 2025 The Department agrees and will formally document/memorialize our processes and protocols to ensure the Department’s IT service providers are formally communicated the current Department IT policies and when the Department updates its IT policies, based on notifications from the Governor’s Office of Information Technology that Colorado Information Security Policies have been revised and published. B. Agree Implementation Date: June 2025 The Department agrees and will formalize and communicate to Department staff the Department’s draft IT policy and procedures review process to ensure it defines that the review will occur on an annual basis and that the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Colorado Information Security Policies. In addition, the Department will continue to formalize and communicate with Department staff and its IT service providers the IT procedures for MyUI+ that further implement Department IT policies, which will also include working with the MyUI+ IT service provider to formalize procedures noted in the confidential finding. C. Agree Implementation Date: June 2025 The Department agrees and will formalize within our vendor management process a review of our current vendors/IT service providers’ contracts and determining whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Agree Implementation Date: June 2025 The Department agrees and will implement the recommendation as noted in the confidential finding. E. Agree Implementation Date: June 2025 The Department agrees. The Department will ensure audit recommendations are accurately interpreted to ensure that management addresses them and the associated IT risks appropriately, in accordance with expectations and risk tolerance.
Show full finding ▾Hide full finding ▴Finding 2024-047 MyUI+ — IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal UI program, and the Department relies on the IT system, MyUI+, to aid with determining applicants’ eligibility for the program and to provide information necessary to meet federal reporting requirements. The Department is the business owner and works with the Governor’s Office of Information Technology (OIT) and its external IT service provider to manage MyUI+. The MyUI+ system determines UI eligibility determinations and calculates UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ provided data necessary for federal reporting to the U.S. Department of Labor for the UI program. The Department stated that, in October 2024, to modernize its Colorado Automated Tax System (CATS), which was its system used to track and report unemployment premium payments made by employers, it updated MyUI+ and added this functionality that was previously within CATS. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to responsible staff, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2024 audit work was to determine whether the Department implemented two of our Fiscal Year 2023 recommendations: (1) Recommendation 2023-073 relating to MyUI+, and (2) Recommendation 2023-028, relating to CATS. Specifically, at that time, we recommended that the Department should: For Recommendation 2023-073, improve its overall IT governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ system by: • Recommendation Part A—Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the business owner requirements listed within the OIT’s March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. • Recommendation Part B—Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. • Recommendation Part C—Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. • Implementing recommendation Part D as noted in the confidential finding. For Recommendation 2023-028, reprioritize staff, as applicable, to improve information security controls over CATS by: • Implementing recommendation Part E as noted in the confidential finding. • Implementing recommendation Part F as noted in the confidential finding. Our audit work was performed through inquiries of Department management and staff and review of the supporting documentation. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2024, we found that the Department did not fully implement our prior audit recommendations for MyUI+. For Recommendation 2023-073, we noted the following for each recommendation: • Recommendation Part A—Although the Department formally adopted OIT’s Security Policies as the Department’s IT policy framework and communicated the adoption to Department staff, this communication did not extend to or include its IT service providers. • Recommendation Part B—Although the Department provided certain MyUI+ access control procedures, the Department stated that it had not yet formalized or drafted other standard operating procedures for MyUI+ to ensure alignment with the formally adopted IT policies noted in recommendation Part A. Also, although the Department drafted a review process for updating all IT policies, it did not formalize this or specify the frequency of the review. The Green Book states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part C—Although the Department formalized a vendor management process to ensure Department staff hold the Department’s IT service providers accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B, the Department had not formalized procedures around contract reviews to determine whether amendments to those contracts are necessary. In addition, and as stated above in recommendation Part A, the Department also did not communicate the IT policy framework adoption to its IT service providers. Security Policies state that IT service providers—which are defined as OIT and/or external service providers—must follow the Security Policy requirements. Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department’s contract with the MyUI+ IT service provider stating that the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor’s Office of Information Technology. The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. Further, Principle 15.03, Communication with External Parties states, that management communicates quality information externally so that external parties, such as contractors or service providers, help the Department achieve its objectives and address related risks. • Recommendation Part D—The Department did not fully implement the prior audit recommendation. We measured the results of our work against Security Policies and the IRS’s Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies November Revision. For Recommendation 2023-028, we noted the following for each recommendation: • Recommendation Part E—Although the Department and its external IT service provider had partially implemented the prior audit recommendation for MyUI+, no documentation was provided to verify that the Department and its external IT service provider formalized certain procedures associated with the confidential finding. The Green Book states in Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part F—We found through our audit work on Recommendation 2023-073A-D and 2023-028E above that these prior recommendations were not fully implemented because the Department failed to fully comply with Security Policies and Publication 1075. Why did these problems occur? Department staff stated that they continue to work to implement prior audit Recommendation 2023-073. However, the Department did not provide specific reasons for why the prior audit recommendation has not been implemented for the second consecutive year, as the recommendation dates back to Fiscal Year 2022. Department staff reported that the prior audit Recommendation 2023-028 is no longer valid because the Department misinterpreted our recommendations. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security controls are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately, could impact data reliability of the data stored and processed within MyUI+. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-047 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ information system by: A. Formalizing and communicating to the Department’s IT service providers the adoption of the Governor’s Office of Information Technology’s (OIT) Colorado Information Security Policies (Security Policies). B. Continuing to formalize and communicate IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. In addition, the Department should work with its external IT service provider to formalize procedures as noted in recommendation Part B of the confidential finding for MyUI+. C. Formalizing within the Department’s vendor management process a review of the Department’s current external IT service providers’ contracts and a process to determine whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Accurately interpreting audit recommendations to ensure that management addresses them and the associated IT risks appropriately, in accordance with expectations and risk tolerance. Response Department of Labor and Employment A. Agree Implementation Date: March 2025 The Department agrees and will formally document/memorialize our processes and protocols to ensure the Department’s IT service providers are formally communicated the current Department IT policies and when the Department updates its IT policies, based on notifications from the Governor’s Office of Information Technology that Colorado Information Security Policies have been revised and published. B. Agree Implementation Date: June 2025 The Department agrees and will formalize and communicate to Department staff the Department’s draft IT policy and procedures review process to ensure it defines that the review will occur on an annual basis and that the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Colorado Information Security Policies. In addition, the Department will continue to formalize and communicate with Department staff and its IT service providers the IT procedures for MyUI+ that further implement Department IT policies, which will also include working with the MyUI+ IT service provider to formalize procedures noted in the confidential finding. C. Agree Implementation Date: June 2025 The Department agrees and will formalize within our vendor management process a review of our current vendors/IT service providers’ contracts and determining whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Agree Implementation Date: June 2025 The Department agrees and will implement the recommendation as noted in the confidential finding. E. Agree Implementation Date: June 2025 The Department agrees. The Department will ensure audit recommendations are accurately interpreted to ensure that management addresses them and the associated IT risks appropriately, in accordance with expectations and risk tolerance.
The Department agrees. The Department will ensure audit recommendations are accurately interpreted to ensure that management addresses them and the associated IT risks appropriately, in accordance with expectations and risk tolerance.
2023-073
Finding 2024-048 Connecting Colorado—IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Employment Service Cluster programs, and the Department relies on its IT system, Connecting Colorado, to aid with determining applicants’ eligibility for the program, and to provide information necessary to meet federal reporting requirements. The Department is the business owner and works with OIT and an external IT service provider to manage Connecting Colorado. Connecting Colorado is the Department’s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to responsible staff, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2024 audit work was to determine whether the Department implemented our Fiscal Year 2023 recommendations for Connecting Colorado. Specifically, at that time, we recommended that the Department should improve its overall IT governance and information security IT general controls, and work with its IT service provider for the Connecting Colorado system by: • Recommendation Part A—Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the business owner requirements listed within the OIT’s March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. • Recommendation Part B—Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. • Recommendation Part C—Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. • Recommendation Part E—Implementing recommendation Part E as noted in the confidential finding. Our audit work was performed through inquiries of Department management and staff and review of the supporting documentation. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2024, we found that the Department did not fully implement our prior audit recommendations for Connecting Colorado. Specifically, we noted the following for each recommendation: • Recommendation Part A—Although the Department formally adopted OIT’s Security Policies as the Department’s IT policy framework and communicated the adoption to Department staff, this communication did not extend to or include its Connecting Colorado IT service provider. • Recommendation Part B—The Department stated that it had not yet formalized or drafted standard operating procedures for Connecting Colorado to ensure alignment with the formally adopted IT policies noted in recommendation Part A. Also, although the Department drafted a review process for updating all IT policies, it did not formalize this or specify the frequency of the review. The Green Book states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part C—Although the Department formalized a vendor management process to ensure Department staff hold the Department’s IT service providers accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B, the Department had not formalized procedures around contract reviews to determine whether amendments to those contracts are necessary. In addition, and as stated above in recommendation Part A, the Department also did not communicate the IT policy framework adoption to its IT service providers. Security Policies state that IT service providers—which are defined as OIT and/or external service providers—must follow the Security Policy requirements. Section C.iii. (Legal Authority – Contractor Signatory, Information Technology Specific) of the Department’s contract with the Connecting Colorado IT service provider stating that the contractor warrants that it will at all times comply with all Security Policies. The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. Further, Principle 15.03, Communication with External Parties states, that management communicates quality information externally so that external parties, such as contractors or service providers, help the Department achieve its objectives and address related risks. • Recommendation Part E—The Department did not fully implement the prior year recommendation. We measured our audit work against Security Policies. Why did these problems occur? Department staff stated that they continue to work to implement prior audit recommendations. However, the Department did not provide specific reasons for why the prior audit recommendation has not been implemented for the second consecutive year, as the recommendation dates back to Fiscal Year 2022. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security controls are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately, could impact data reliability of the data stored and processed within Connecting Colorado. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-048 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service provider, as applicable, for the Connecting Colorado information system by: A. Formalizing and communicating to the Department’s IT service providers the adoption of the Governor’s Office of Information Technology’s (OIT) Colorado Information Security Policies (Security Policies). B. Continuing to formalize and communicate IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing within the Department’s vendor management process a review of the Department’s current external IT service providers’ contracts and a process to determine whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted within the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: March 2025 The Department agrees and will formally document/memorialize our processes and protocols to ensure the Department’s IT service providers are formally communicated the current Department IT policies and when the Department updates its IT policies, based on notifications from the Governor’s Office of Information Technology that Colorado Information Security Policies have been revised and published. B. Agree Implementation Date: June 2025 The Department agrees and will formalize and communicate to Department staff the Department’s draft IT policy and procedures review process to ensure the process defines that the review will occur on an annual basis and that the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Colorado Information Security Policies. In addition, the Department will continue to formalize and communicate with Department staff and its IT service providers the IT procedures for Connecting Colorado that further implement the Department’s IT policies. C. Agree Implementation Date: June 2025 The Department agrees and will formalize within our vendor management process a review of our current vendors/IT service providers’ contracts and determining whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Agree Implementation Date: June 2025 The Department agrees and will implement the recommendation as noted in the confidential finding.
Show full finding ▾Hide full finding ▴Finding 2024-048 Connecting Colorado—IT Governance and Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Employment Service Cluster programs, and the Department relies on its IT system, Connecting Colorado, to aid with determining applicants’ eligibility for the program, and to provide information necessary to meet federal reporting requirements. The Department is the business owner and works with OIT and an external IT service provider to manage Connecting Colorado. Connecting Colorado is the Department’s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to responsible staff, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2024 audit work was to determine whether the Department implemented our Fiscal Year 2023 recommendations for Connecting Colorado. Specifically, at that time, we recommended that the Department should improve its overall IT governance and information security IT general controls, and work with its IT service provider for the Connecting Colorado system by: • Recommendation Part A—Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the business owner requirements listed within the OIT’s March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. • Recommendation Part B—Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. • Recommendation Part C—Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. • Recommendation Part E—Implementing recommendation Part E as noted in the confidential finding. Our audit work was performed through inquiries of Department management and staff and review of the supporting documentation. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2024, we found that the Department did not fully implement our prior audit recommendations for Connecting Colorado. Specifically, we noted the following for each recommendation: • Recommendation Part A—Although the Department formally adopted OIT’s Security Policies as the Department’s IT policy framework and communicated the adoption to Department staff, this communication did not extend to or include its Connecting Colorado IT service provider. • Recommendation Part B—The Department stated that it had not yet formalized or drafted standard operating procedures for Connecting Colorado to ensure alignment with the formally adopted IT policies noted in recommendation Part A. Also, although the Department drafted a review process for updating all IT policies, it did not formalize this or specify the frequency of the review. The Green Book states in Principle 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Principles 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. Security Policies that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy section and the General Responsibilities section, specifically 8.3.1 and 8.3.2 for business owners, that all agencies, except for the institutions of higher education and the general assembly, including the Department, each as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for their systems, and they are responsible for following and adhering to all identified business owner requirements. • Recommendation Part C—Although the Department formalized a vendor management process to ensure Department staff hold the Department’s IT service providers accountable to contract provisions requiring compliance with Security Policies and IT policies and procedures formalized in recommendation Parts A and B, the Department had not formalized procedures around contract reviews to determine whether amendments to those contracts are necessary. In addition, and as stated above in recommendation Part A, the Department also did not communicate the IT policy framework adoption to its IT service providers. Security Policies state that IT service providers—which are defined as OIT and/or external service providers—must follow the Security Policy requirements. Section C.iii. (Legal Authority – Contractor Signatory, Information Technology Specific) of the Department’s contract with the Connecting Colorado IT service provider stating that the contractor warrants that it will at all times comply with all Security Policies. The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. Further, Principle 15.03, Communication with External Parties states, that management communicates quality information externally so that external parties, such as contractors or service providers, help the Department achieve its objectives and address related risks. • Recommendation Part E—The Department did not fully implement the prior year recommendation. We measured our audit work against Security Policies. Why did these problems occur? Department staff stated that they continue to work to implement prior audit recommendations. However, the Department did not provide specific reasons for why the prior audit recommendation has not been implemented for the second consecutive year, as the recommendation dates back to Fiscal Year 2022. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security controls are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately, could impact data reliability of the data stored and processed within Connecting Colorado. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-048 The Department of Labor and Employment (Department) should improve its overall IT governance and information security IT general controls, and work with its IT service provider, as applicable, for the Connecting Colorado information system by: A. Formalizing and communicating to the Department’s IT service providers the adoption of the Governor’s Office of Information Technology’s (OIT) Colorado Information Security Policies (Security Policies). B. Continuing to formalize and communicate IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing within the Department’s vendor management process a review of the Department’s current external IT service providers’ contracts and a process to determine whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted within the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: March 2025 The Department agrees and will formally document/memorialize our processes and protocols to ensure the Department’s IT service providers are formally communicated the current Department IT policies and when the Department updates its IT policies, based on notifications from the Governor’s Office of Information Technology that Colorado Information Security Policies have been revised and published. B. Agree Implementation Date: June 2025 The Department agrees and will formalize and communicate to Department staff the Department’s draft IT policy and procedures review process to ensure the process defines that the review will occur on an annual basis and that the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Colorado Information Security Policies. In addition, the Department will continue to formalize and communicate with Department staff and its IT service providers the IT procedures for Connecting Colorado that further implement the Department’s IT policies. C. Agree Implementation Date: June 2025 The Department agrees and will formalize within our vendor management process a review of our current vendors/IT service providers’ contracts and determining whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Agree Implementation Date: June 2025 The Department agrees and will implement the recommendation as noted in the confidential finding.
The Department agrees and will implement the recommendation as noted in the confidential finding.
2023-073
The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-071 Rehabilitation Services – Vocational Rehabilitation Grants to States—Federal Reporting The Department is responsible for administering the federal Rehabilitation Services -Vocational Rehabilitation Grants to States (VR) program [ALN 84.126]. The program’s overall purpose is to assist individuals whose disabilities result in barriers to employment with attaining and maintaining employment. At any of the 25 field and satellite offices located throughout the State, rehabilitation counselors work with individuals to assess their needs and identify appropriate vocational rehabilitation services. The Department’s Division of Vocational Rehabilitation (Division) is responsible for completing the RSA-17, Vocational Rehabilitation Financial Report, a quarterly, federally-required report for the VR program for all VR grants open during the fiscal year. It is also responsible for the data used to complete the reports and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Department’s Finance Office provides the Division with reports from CORE and creates a workbook with the applicable financial information that the Division uses to complete the reports. Division staff run reports from its electronic case management system, the Accessible Web-Based Activity and Reporting Environment (AWARE)— the system Division program staff use to track expenditures—and use some of this information to help complete the reports. The Department had three open grants during Fiscal Year 2023 and was, therefore, required to submit one quarterly report for each grant for as long as the grant was open during the year, resulting in a total of 8 reports submitted during the fiscal year. During Fiscal Year 2023, the Department expended approximately $51.4 million for the VR program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Division had adequate internal controls in place over and complied with federal reporting requirements for the VR program during Fiscal Year 2023. As part of our audit work, we gained an understanding of the Division’s procedures that were in place during Fiscal Year 2023 to prepare the federal reports. In addition, we reviewed four RSA-17 reports—two related to the quarter ended September 30, 2022 and two related to the quarter ended June 30, 2023—submitted to the federal government for Fiscal Year 2023 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Division’s policies and procedures related to RSA-17 report completion, as well as the supporting documentation for the reports we selected for testing. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the Office of the State Controller’s policy, Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity’s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The federal Rehabilitation Services Administration provides instructions for completing the RSA-17, as well as a template. The template provided in the instructions requires the Division to select the method of accounting used to prepare the reports, and requires the Division to maintain supporting documentation to substantiate the data reported in the report. The instructions also state that the Division is responsible for having internal controls necessary to ensure the reports are accurate and reliable. What problems did the audit work identify? We identified at least one issue with all four (100 percent) of the RSA-17 reports we tested. For example, the Division could not provide documentation to support information for a total of over $25 million in expenditures reported by the Division. Specifically, we found the following: • Reports for the quarter ended September 30, 2022: o For one report, the Division could not provide documentation to support information on the following two lines of the report: Administrative Expenditures—$21.5 million American Job Center Infrastructure Expenditures—$467,083 o In the other report, the Division could not provide documentation to support a $3.1 million amount noted for the American Job Center Infrastructure Expenditures line on the report. • Reports for the quarter ended June 30, 2023: o In one report, the Division could not provide documentation for $7,315 of the $8.6 million reported in the Administrative Expenditures line. Additionally, it did not include $913,166 in expenditures from the month of June and, therefore, underreported, the following lines: Administrative Expenditures - Reported—The Division reported $8.6 million instead of the correct amount of $9.5 million. Expenditures incurred for the Provision of Pre-Employment Transition Services by Agency Staff Only - Reported—The Division reported $96,903 instead of the correct amount of $115,511. o In the other report, the Division could not provide documentation for $22,707 of the $8.5 million reported in the Administrative Expenditures line. Why did these problems occur? The Division did not have sufficient internal controls in place to ensure that its federal RSA-17 reports were accurate and complete, and that the associated documentation was maintained during Fiscal Year 2023. Although the Division has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement to reconcile information that Division program staff obtains from AWARE to CORE to ensure the expenditures agree in both systems and that any differences are identified and corrected, as appropriate. Additionally, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to staff inputting the wrong information into the reports, which a review could have caught and corrected prior to submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including documented policies with adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause report users to rely on incorrect information. This could have a negative impact on the Department’s future federal program funding. Recommendation 2023-071 The Department of Labor and Employment’s (Department) Division of Vocational Rehabilitation (Division) should strengthen its internal controls over, and ensure compliance with, federal reporting for the Rehabilitation Services-Vocational Rehabilitation Grants to States program by developing, documenting, and implementing policies for completing its federal reports. These policies should require the Division to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE) it receives from the Department’s Finance Section, and to ensure that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: October 2024 DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2024 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-071 Rehabilitation Services – Vocational Rehabilitation Grants to States—Federal Reporting The Department is responsible for administering the federal Rehabilitation Services -Vocational Rehabilitation Grants to States (VR) program [ALN 84.126]. The program’s overall purpose is to assist individuals whose disabilities result in barriers to employment with attaining and maintaining employment. At any of the 25 field and satellite offices located throughout the State, rehabilitation counselors work with individuals to assess their needs and identify appropriate vocational rehabilitation services. The Department’s Division of Vocational Rehabilitation (Division) is responsible for completing the RSA-17, Vocational Rehabilitation Financial Report, a quarterly, federally-required report for the VR program for all VR grants open during the fiscal year. It is also responsible for the data used to complete the reports and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Department’s Finance Office provides the Division with reports from CORE and creates a workbook with the applicable financial information that the Division uses to complete the reports. Division staff run reports from its electronic case management system, the Accessible Web-Based Activity and Reporting Environment (AWARE)— the system Division program staff use to track expenditures—and use some of this information to help complete the reports. The Department had three open grants during Fiscal Year 2023 and was, therefore, required to submit one quarterly report for each grant for as long as the grant was open during the year, resulting in a total of 8 reports submitted during the fiscal year. During Fiscal Year 2023, the Department expended approximately $51.4 million for the VR program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Division had adequate internal controls in place over and complied with federal reporting requirements for the VR program during Fiscal Year 2023. As part of our audit work, we gained an understanding of the Division’s procedures that were in place during Fiscal Year 2023 to prepare the federal reports. In addition, we reviewed four RSA-17 reports—two related to the quarter ended September 30, 2022 and two related to the quarter ended June 30, 2023—submitted to the federal government for Fiscal Year 2023 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Division’s policies and procedures related to RSA-17 report completion, as well as the supporting documentation for the reports we selected for testing. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the Office of the State Controller’s policy, Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity’s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The federal Rehabilitation Services Administration provides instructions for completing the RSA-17, as well as a template. The template provided in the instructions requires the Division to select the method of accounting used to prepare the reports, and requires the Division to maintain supporting documentation to substantiate the data reported in the report. The instructions also state that the Division is responsible for having internal controls necessary to ensure the reports are accurate and reliable. What problems did the audit work identify? We identified at least one issue with all four (100 percent) of the RSA-17 reports we tested. For example, the Division could not provide documentation to support information for a total of over $25 million in expenditures reported by the Division. Specifically, we found the following: • Reports for the quarter ended September 30, 2022: o For one report, the Division could not provide documentation to support information on the following two lines of the report: Administrative Expenditures—$21.5 million American Job Center Infrastructure Expenditures—$467,083 o In the other report, the Division could not provide documentation to support a $3.1 million amount noted for the American Job Center Infrastructure Expenditures line on the report. • Reports for the quarter ended June 30, 2023: o In one report, the Division could not provide documentation for $7,315 of the $8.6 million reported in the Administrative Expenditures line. Additionally, it did not include $913,166 in expenditures from the month of June and, therefore, underreported, the following lines: Administrative Expenditures - Reported—The Division reported $8.6 million instead of the correct amount of $9.5 million. Expenditures incurred for the Provision of Pre-Employment Transition Services by Agency Staff Only - Reported—The Division reported $96,903 instead of the correct amount of $115,511. o In the other report, the Division could not provide documentation for $22,707 of the $8.5 million reported in the Administrative Expenditures line. Why did these problems occur? The Division did not have sufficient internal controls in place to ensure that its federal RSA-17 reports were accurate and complete, and that the associated documentation was maintained during Fiscal Year 2023. Although the Division has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement to reconcile information that Division program staff obtains from AWARE to CORE to ensure the expenditures agree in both systems and that any differences are identified and corrected, as appropriate. Additionally, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to staff inputting the wrong information into the reports, which a review could have caught and corrected prior to submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including documented policies with adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause report users to rely on incorrect information. This could have a negative impact on the Department’s future federal program funding. Recommendation 2023-071 The Department of Labor and Employment’s (Department) Division of Vocational Rehabilitation (Division) should strengthen its internal controls over, and ensure compliance with, federal reporting for the Rehabilitation Services-Vocational Rehabilitation Grants to States program by developing, documenting, and implementing policies for completing its federal reports. These policies should require the Division to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE) it receives from the Department’s Finance Section, and to ensure that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: October 2024 DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
2023-071
Finding 2024-050 Compliance with Reporting for Section 8 Housing Choice Vouchers and Mainstream Vouchers The Department is responsible for administering two programs as part of the Housing Voucher Cluster program (Program): Section 8 Housing Choice Vouchers [ALN 14.871] and Mainstream Vouchers [ALN 14.879]. The Department receives advance payments annually from the federal government for the Program to provide tenant-based subsidies for rent paid by low-income households. The Department pays a housing subsidy directly to a landlord on behalf of the Program’s participants. During Fiscal Year 2024, the Department expended approximately $97.9 million for the Program—$89.9 million for Section 8 Housing Choice Vouchers and $8.0 million for Mainstream Vouchers. The Department submits financial information (financial report), audited and unaudited, prepared in accordance with Generally Accepted Accounting Principles (GAAP), electronically to Housing and Urban Development (HUD) through the Financial Assessment Sub-System (FASS-PH) on an annual basis. The FASS-PH system is one of HUD’s main monitoring and oversight systems for the Program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had effective internal controls over, and complied with, federal regulations for the Program’s financial reporting during Fiscal Year 2024. As part of our audit work, we reviewed policies and procedures, and obtained the financial report (and supporting documentation for the financial report) that the Department submitted for Fiscal Year 2024. We tested the financial report to determine whether the Department submitted the financial report in a timely manner and in accordance with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [24 CFR 902.33(c)] require the Department to submit unaudited financial information to HUD annually, no later than 2 months after the Department’s fiscal year end, with no penalty applying until the 16th day of the third month after the Department’s fiscal year end. For the Department, the due date for the Fiscal Year 2024 unaudited financial information was August 31, 2024. • Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, we determined that the Department was not in compliance with certain Fiscal Year 2024 federal reporting requirements. Specifically, the Department did not submit the required unaudited financial report to HUD until December 10, 2024—101 days after the due date. Why did this problem occur? The problem occurred because the Department does not have adequate internal controls over financial reporting for the Program. Specifically, the Department experienced turnover in some key accounting positions and did not cross-train other employees on how to complete the financial report. Additionally, the Department did not have documented policies and procedures to provide adequate guidance to Department staff for completing the financial report, along with submitting it on time to HUD. Why does this problem matter? By failing to properly submit federal reports to HUD in a timely manner, the Department may receive less federal funding for the Program. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-050 The Department of Local Affairs (Department) should strengthen its internal controls over the Housing Voucher Cluster Program (Program) to ensure it complies with federal regulations and submits the Program’s financial report to the federal Department of Housing and Urban Development by the federally established due date by: A. Creating, documenting, and implementing policies and procedures to provide adequate guidance to Department staff for completing the Program’s financial report. B. Cross-training Department personnel on the completion of the financial report so that, in the event of staff turnover, controls will continue to operate as designed. Response Department of Local Affairs A. Agree Implementation Date: June 2025 The Department will ensure it complies with federal regulations by creating, documenting and implementing policies and procedures to provide adequate guidance to Department staff for completing the Program’s financial report. B. Agree Implementation Date: June 2025 The Department will cross-train Department personnel on the completion of the financial report so that, in the event of staff turnover, controls will continue to operate as designed.
Show full finding ▾Hide full finding ▴Finding 2024-050 Compliance with Reporting for Section 8 Housing Choice Vouchers and Mainstream Vouchers The Department is responsible for administering two programs as part of the Housing Voucher Cluster program (Program): Section 8 Housing Choice Vouchers [ALN 14.871] and Mainstream Vouchers [ALN 14.879]. The Department receives advance payments annually from the federal government for the Program to provide tenant-based subsidies for rent paid by low-income households. The Department pays a housing subsidy directly to a landlord on behalf of the Program’s participants. During Fiscal Year 2024, the Department expended approximately $97.9 million for the Program—$89.9 million for Section 8 Housing Choice Vouchers and $8.0 million for Mainstream Vouchers. The Department submits financial information (financial report), audited and unaudited, prepared in accordance with Generally Accepted Accounting Principles (GAAP), electronically to Housing and Urban Development (HUD) through the Financial Assessment Sub-System (FASS-PH) on an annual basis. The FASS-PH system is one of HUD’s main monitoring and oversight systems for the Program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had effective internal controls over, and complied with, federal regulations for the Program’s financial reporting during Fiscal Year 2024. As part of our audit work, we reviewed policies and procedures, and obtained the financial report (and supporting documentation for the financial report) that the Department submitted for Fiscal Year 2024. We tested the financial report to determine whether the Department submitted the financial report in a timely manner and in accordance with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [24 CFR 902.33(c)] require the Department to submit unaudited financial information to HUD annually, no later than 2 months after the Department’s fiscal year end, with no penalty applying until the 16th day of the third month after the Department’s fiscal year end. For the Department, the due date for the Fiscal Year 2024 unaudited financial information was August 31, 2024. • Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, we determined that the Department was not in compliance with certain Fiscal Year 2024 federal reporting requirements. Specifically, the Department did not submit the required unaudited financial report to HUD until December 10, 2024—101 days after the due date. Why did this problem occur? The problem occurred because the Department does not have adequate internal controls over financial reporting for the Program. Specifically, the Department experienced turnover in some key accounting positions and did not cross-train other employees on how to complete the financial report. Additionally, the Department did not have documented policies and procedures to provide adequate guidance to Department staff for completing the financial report, along with submitting it on time to HUD. Why does this problem matter? By failing to properly submit federal reports to HUD in a timely manner, the Department may receive less federal funding for the Program. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-050 The Department of Local Affairs (Department) should strengthen its internal controls over the Housing Voucher Cluster Program (Program) to ensure it complies with federal regulations and submits the Program’s financial report to the federal Department of Housing and Urban Development by the federally established due date by: A. Creating, documenting, and implementing policies and procedures to provide adequate guidance to Department staff for completing the Program’s financial report. B. Cross-training Department personnel on the completion of the financial report so that, in the event of staff turnover, controls will continue to operate as designed. Response Department of Local Affairs A. Agree Implementation Date: June 2025 The Department will ensure it complies with federal regulations by creating, documenting and implementing policies and procedures to provide adequate guidance to Department staff for completing the Program’s financial report. B. Agree Implementation Date: June 2025 The Department will cross-train Department personnel on the completion of the financial report so that, in the event of staff turnover, controls will continue to operate as designed.
The Department will cross-train Department personnel on the completion of the financial report so that, in the event of staff turnover, controls will continue to operate as designed.
Findings 2024-051 and 2024-052 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Disaster Grants Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the Department of Homeland Security, awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2024, the Department received funding through the following Disaster Grants federal awards: • FEMA-4145-DR for the 2013 Severe Storms, Flooding, Landslides, and Mudslides • FEMA-4429-DR-CO for the 2015 Severe Storms, Tornadoes, Flooding, Landslides and Mudslides • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 Wildfires incident • FEMA-4634-DR for the 2021 Wildfires and Straight-Line Winds incident • FEMA-4731 DR for the 2023 Severe Storms, Flooding and Tornadoes The Department’s FEMA Disaster Grants program awards are on a reimbursement basis, which means the Department requests reimbursement from FEMA for approved allowable costs, even some of those that are passed on to other state agencies or departments. The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and the OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments and institutions of higher education through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides some additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments and institutions of higher education prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should typically be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards included funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in Fiscal Year 2024 were for expenditures incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE submits FEMA Disaster Grants program expenditures information to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, before it disburses reimbursement payments to CDPHE. The point in time from when FEMA approves a project to when CDPHE requests reimbursement from the Department for CDPHE’s allowable expenditures may cross fiscal years, and during that time CDPHE may revise its previous specific identification of FEMA Disaster Grants program expenditures. Reasons for revising allowable expenditures may include not meeting FEMA’s specific documentation requirements or identifying additional allowable costs that were not previously identified. Therefore, it is important for both the Department and CDPHE to have processes in place to ensure that expenditures are reported in CORE and on the Department’s Exhibit K1 in the correct amount and year. For Fiscal Year 2024, CDPHE provided the Department with transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that had not yet been submitted for reimbursement through an interdepartmental transaction. Prior to Fiscal Year 2024, CDPHE only provided the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years. Department staff reviewed the transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that were incurred by CDPHE. Based on the June 30, 2024 inception-to-date transactional detail provided by CDPHE for unreimbursed FEMA Disaster Grants expenditures, the Department recognized an interdepartmental payable to CDPHE in CORE, along with the corresponding federal receivable. Additionally, the Department recognized the change in the CDPHE accrual from the prior fiscal year end—net of current year reimbursements to CPDHE—in CORE as federal expenditures and federal revenues for Fiscal Year 2024; specifically, the Department recorded $11.2 million in total Fiscal Year 2024 FEMA Disaster Grants program expenditures incurred and revenues earned by CDPHE. Overall, the change in the CDPHE accrual from the prior year end, represented a decrease of $90.2 million in expenditures and revenues, net of current year reimbursements to CDPHE of $101.4 million. Ultimately, the Department is responsible for the appropriate review and approval of all federal FEMA expenditures within FEMA’s grant tracking software, EMGrants, and for appropriately reporting the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2024, the Department reported $194.2 million in total FEMA Disaster Grants program expenditures. Of this amount, as noted above, $11.2 million (6 percent) of those program expenditures reported by the Department represented CDPHE’s FEMA Disaster Grants program expenditures during Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department complied with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether the Department had proper internal controls in place over the FEMA Disaster Grants program during Fiscal Year 2024. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting for, and financial reporting of, the FEMA Disaster Grants program activities in CORE and the Department’s Exhibit K1, along with determining whether the Department complied with applicable accounting standards during Fiscal Year 2024. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures requiring Department staff to obtain and maintain sufficiently-detailed supporting documentation from CDPHE for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department—as well as requiring that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1. The Department planned to implement these recommendations by September 2024. Further, the purpose of our audit work was to determine whether CDPHE implemented our Fiscal Year 2023 audit recommendation to ensure all Disaster Grants program expenditures are properly supported with appropriate documentation, and to expand CDPHE’s existing policies and procedures that staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department—which the Department reports on the Department’s Exhibit K1 and reconciling interdepartmental reimbursements. Lastly, we recommended that CDPHE provide training to its staff responsible for the Disaster Grants program on the updated policies and procedures. CDPHE planned to implement these recommendations by June 2024. As part of our audit work, we tested the Department’s and CDPHE’s progress on implementing our prior audit recommendations by reviewing their updated policies and procedures and training performed. Additionally, we obtained an understanding of the Department’s internal controls, including policies and procedures, related to account balances, financial processes, and fiscal year-end close processes for the Disaster Grants program. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented CDPHE’s expenditures of FEMA Disaster Grants program’s pass-through expenditures from the Department during the fiscal year, which totaled $11.2 million. • Requested that the Department provide transactional level detail to support the $11.2 million in Fiscal Year 2024 FEMA Disaster Grants program’s pass-through expenditures at CDPHE that were reported by the Department on its Exhibit K1. In addition, we inquired whether and how the Department reconciled the Fiscal Year 2024 transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 70 of the Department’s FEMA Disaster Grants program expenditures, excluding CDPHE expenditures, totaling approximately $104.4 million, that the Department reported were incurred during Fiscal Year 2024, to test the Department’s internal controls and compliance. We performed testing on the 70 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-1 (6.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system which includes controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 200.403(g)] require that costs be adequately documented. • The 2024 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? Based on our audit work, we determined that the Department and CDPHE did not fully implement our Fiscal Year 2023 recommendations by their planned implementation dates of June 2024 and September 2024. While the Department and CDPHE improved their processes for reconciling the June 2024 interdepartmental accrual for cumulative to date Disaster Grants program federal expenditures, we determined that the Department and CDPHE did not comply with applicable state and federal regulations during Fiscal Year 2024. Specifically, • The Department could not provide sufficient supporting documentation for $11.1 million of the $11.2 million (99 percent) in FEMA Disaster Grants program fund expenditures that it reported on its Exhibit K1 that represented CDPHE expenditures during the fiscal year. Department staff indicated that CDPHE did not provide the Department with adequate transactional detail to support CDPHE’s pass-through expenditures incurred for the program for Fiscal Year 2024. As a result, the Department relied on other data, including the amount of the total change in the interdepartmental payable to CDPHE for program expenditures and current year reimbursements to CDPHE, as the basis for its Exhibit K1 reporting. • Additionally, we identified an issue with 1 of the 70 (1 percent) expenditures reported on the Department’s Exhibit K1 that we selected for testing. Specifically, the Department incorrectly recorded and paid a federal expenditure in the amount of $1,488,695 instead of the correct amount of $1,448,695. As a result of the overpayment, the Department also overstated the total FEMA Disaster Grants program expenditures on its Exhibit K1 and was required to adjust this total from $194,279,466 to $194,239,466, which resulted in known questioned costs of $40,000. The Department corrected the error after we notified them of the issue we identified. Why did these problems occur? These problems occurred because the Department did not fully implement our prior audit recommendations. The Department and CDPHE were unable to sufficiently reconcile and verify CDPHE’s Fiscal Year 2024 federal expenditures because of the length of time that the grant has been effective and insufficient financial records from prior fiscal years that were not available. Rather, the Department and CDPHE placed more reliance on reconciling the current year reimbursements and the June 30, 2024 inception-to-date unreimbursed expenditures. The Department did enhance its communication with CDPHE surrounding the necessary detail for the year-end accrual reconciliation as of June 30, 2024; however, these additional communications did not sufficiently address the proper recording and reporting of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures on the Department’s Exhibit K1. We also found that while CDPHE developed and implemented procedures and provided training to its staff, those procedures did not sufficiently address the proper reconciliation of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures. CDPHE staff stated that they experienced turnover during the fiscal year, which resulted in the inability for CDPHE staff to properly identify individual transactions that made up the prior fiscal year’s—Fiscal Year 2023’s—unreimbursed expenditures. As a result of not being able to identify individual transactions that made up the prior Fiscal Year 2023’s unreimbursed expenditures, CDPHE staff were unable to identify Fiscal Year 2024 expenditures because they could not determine whether any of the reimbursements received in Fiscal Year 2024 were for expenditures included in the prior fiscal-year accrual, whether any prior fiscal year accrued expenditures were reclassified to a non-FEMA Disaster Grant program expenditure, or whether any prior fiscal year expenditures were identified as being eligible for the FEMA Disaster Grant program in the current fiscal year. Additionally, the Department did not reconcile the Fiscal Year 2024 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2023’s or other prior year’s expenditures to ensure the expenditures were reported in the appropriate fiscal year. As a result of the lack of reconciliation of current year expenditures, we were unable to determine the full extent to which the Department’s FEMA Disaster Grants program expenditures in CORE or on the Exhibit K1 ultimately were overstated or understated. Lastly, the overpayment of expenditures was the result of a data entry error by the Department’s staff when processing the payment. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements—including an appropriate reconciliation and review of allowable expenditures—the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment by the Department to the federal granting agency. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-051 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Continuing to develop, document, and implement policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year recorded by the Department and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that Department staff complete a reconciliation on at least an annual basis of detailed amounts of interagency expenditures reported on the Exhibit K1 for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year. The Department should also resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Continuing to develop, document, and implement policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. C. Sufficiently reviewing supporting documentation when approving transactions for payment to ensure the review identifies any data entry errors. Response Department of Public Safety A. Agree Implementation Date: June 2025 We have developed procedures requiring adequate and detailed support be received before recording interagency accruals. We will continue to apply those procedures and will continue to reconcile any new interagency expenditures prior to reporting on the K1. B. Agree Implementation Date: June 2025 We have developed procedures to requiring adequate and detailed support is received before recording interagency accruals. We will continue to apply those procedures and will continue to review expenditures to ensure they are reported in the proper period on the K1. We will review a sample of accrual expenditure details to verify expenditures are allowable under the federal program. C. Agree Implementation Date: June 2025 We will work with staff to remind them the importance of thorough reviews to ensure transactional accuracy. We will ensure desk procedures include adequate review steps. Recommendation 2024-052 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants program expenditures and ensure that all FEMA Disaster Grants program expenditures reported to the Department of Public Safety for reporting on the Department of Public Safety’s Exhibit K1, Schedule of Federal Assistance, are accurately supported by continuing to develop, document, and implement policies and procedures to require that CDPHE staff obtain and maintain sufficiently-detailed supporting documentation for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that CDPHE staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred but not yet reimbursed by the Department of Public Safety as of fiscal year end; reimbursement amounts requested by CDPHE from the Department of Public Safety for the FEMA Disaster Grants program during the year; and reimbursement payments received by the CDPHE from the Department of Public Safety during the year. CDPHE should also resolve any reconciling differences prior to reporting CDPHE FEMA Disaster Grants program expenditures to the Department of Public Safety. Response Department of Public Health and Environment Partially Agree Implementation Date: September 2025 CDPHE fully implemented the FY23 audit recommendation as written and updated our processes in conjunction with CDPS to ensure proper documentation was obtained for all claims in FY24. CDPHE and CDPS met regularly through FY24 to discuss these updates and verified every invoice processed with the applicable backup. CDPHE does not charge or draw any funds from CDPS until approval is received regarding FEMA eligibility. Copies of these approvals are included every time CDPHE draws funds from CDPS. The FY23 audit finding was related to the CDPHE year-end estimate to CDPS since CDPHE was not able to provide all needed supporting documentation to fully justify it. For FY24, instead of using an estimate, we based the FY24 accruals on approvals that were not paid during FY24, so were able to tie this out completely. For actual reimbursement FY24 requests, we tied out all expenses related to each reimbursement request. The procedure documentation was updated to reflect these new processes. Going forward, we are continuing to follow the same updated procedures to ensure that future reimbursement requests are accurate and have appropriate documentation attached. CDPHE verified that the amount listed was only reported on the CDPS K1 and not on both agencies K1s. To reflect the new addition on the FY24 recommendation, CDPHE has updated our procedures to add the full fiscal year reconciliation at the end of each fiscal year for all federal expenses, including expenditures incurred but not yet reimbursed by CDPS as of fiscal year-end, reimbursement requested by CDPHE from CDPS, reimbursements received by CDPHE during the fiscal year, and a resolution for any reconciling differences. Auditor’s Addendum As noted in the finding, we found that CDPHE did not fully implement the Fiscal Year 2023 recommendation and could not provide sufficient support for $11.1 million of the Fiscal Year 2024 FEMA Disaster Grant expenditures reported on the Department of Public Safety’s Exhibit K1. CDPHE should ensure it maintains complete documentation for its FEMA Disaster Grant expenditures and that it completes a reconciliation on an annual basis of the detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year.
Show full finding ▾Hide full finding ▴Findings 2024-051 and 2024-052 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Disaster Grants Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the Department of Homeland Security, awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2024, the Department received funding through the following Disaster Grants federal awards: • FEMA-4145-DR for the 2013 Severe Storms, Flooding, Landslides, and Mudslides • FEMA-4429-DR-CO for the 2015 Severe Storms, Tornadoes, Flooding, Landslides and Mudslides • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 Wildfires incident • FEMA-4634-DR for the 2021 Wildfires and Straight-Line Winds incident • FEMA-4731 DR for the 2023 Severe Storms, Flooding and Tornadoes The Department’s FEMA Disaster Grants program awards are on a reimbursement basis, which means the Department requests reimbursement from FEMA for approved allowable costs, even some of those that are passed on to other state agencies or departments. The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and the OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments and institutions of higher education through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides some additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments and institutions of higher education prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should typically be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards included funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in Fiscal Year 2024 were for expenditures incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE submits FEMA Disaster Grants program expenditures information to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, before it disburses reimbursement payments to CDPHE. The point in time from when FEMA approves a project to when CDPHE requests reimbursement from the Department for CDPHE’s allowable expenditures may cross fiscal years, and during that time CDPHE may revise its previous specific identification of FEMA Disaster Grants program expenditures. Reasons for revising allowable expenditures may include not meeting FEMA’s specific documentation requirements or identifying additional allowable costs that were not previously identified. Therefore, it is important for both the Department and CDPHE to have processes in place to ensure that expenditures are reported in CORE and on the Department’s Exhibit K1 in the correct amount and year. For Fiscal Year 2024, CDPHE provided the Department with transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that had not yet been submitted for reimbursement through an interdepartmental transaction. Prior to Fiscal Year 2024, CDPHE only provided the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years. Department staff reviewed the transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that were incurred by CDPHE. Based on the June 30, 2024 inception-to-date transactional detail provided by CDPHE for unreimbursed FEMA Disaster Grants expenditures, the Department recognized an interdepartmental payable to CDPHE in CORE, along with the corresponding federal receivable. Additionally, the Department recognized the change in the CDPHE accrual from the prior fiscal year end—net of current year reimbursements to CPDHE—in CORE as federal expenditures and federal revenues for Fiscal Year 2024; specifically, the Department recorded $11.2 million in total Fiscal Year 2024 FEMA Disaster Grants program expenditures incurred and revenues earned by CDPHE. Overall, the change in the CDPHE accrual from the prior year end, represented a decrease of $90.2 million in expenditures and revenues, net of current year reimbursements to CDPHE of $101.4 million. Ultimately, the Department is responsible for the appropriate review and approval of all federal FEMA expenditures within FEMA’s grant tracking software, EMGrants, and for appropriately reporting the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2024, the Department reported $194.2 million in total FEMA Disaster Grants program expenditures. Of this amount, as noted above, $11.2 million (6 percent) of those program expenditures reported by the Department represented CDPHE’s FEMA Disaster Grants program expenditures during Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department complied with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether the Department had proper internal controls in place over the FEMA Disaster Grants program during Fiscal Year 2024. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting for, and financial reporting of, the FEMA Disaster Grants program activities in CORE and the Department’s Exhibit K1, along with determining whether the Department complied with applicable accounting standards during Fiscal Year 2024. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures requiring Department staff to obtain and maintain sufficiently-detailed supporting documentation from CDPHE for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department—as well as requiring that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1. The Department planned to implement these recommendations by September 2024. Further, the purpose of our audit work was to determine whether CDPHE implemented our Fiscal Year 2023 audit recommendation to ensure all Disaster Grants program expenditures are properly supported with appropriate documentation, and to expand CDPHE’s existing policies and procedures that staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department—which the Department reports on the Department’s Exhibit K1 and reconciling interdepartmental reimbursements. Lastly, we recommended that CDPHE provide training to its staff responsible for the Disaster Grants program on the updated policies and procedures. CDPHE planned to implement these recommendations by June 2024. As part of our audit work, we tested the Department’s and CDPHE’s progress on implementing our prior audit recommendations by reviewing their updated policies and procedures and training performed. Additionally, we obtained an understanding of the Department’s internal controls, including policies and procedures, related to account balances, financial processes, and fiscal year-end close processes for the Disaster Grants program. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented CDPHE’s expenditures of FEMA Disaster Grants program’s pass-through expenditures from the Department during the fiscal year, which totaled $11.2 million. • Requested that the Department provide transactional level detail to support the $11.2 million in Fiscal Year 2024 FEMA Disaster Grants program’s pass-through expenditures at CDPHE that were reported by the Department on its Exhibit K1. In addition, we inquired whether and how the Department reconciled the Fiscal Year 2024 transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 70 of the Department’s FEMA Disaster Grants program expenditures, excluding CDPHE expenditures, totaling approximately $104.4 million, that the Department reported were incurred during Fiscal Year 2024, to test the Department’s internal controls and compliance. We performed testing on the 70 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-1 (6.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system which includes controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 200.403(g)] require that costs be adequately documented. • The 2024 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? Based on our audit work, we determined that the Department and CDPHE did not fully implement our Fiscal Year 2023 recommendations by their planned implementation dates of June 2024 and September 2024. While the Department and CDPHE improved their processes for reconciling the June 2024 interdepartmental accrual for cumulative to date Disaster Grants program federal expenditures, we determined that the Department and CDPHE did not comply with applicable state and federal regulations during Fiscal Year 2024. Specifically, • The Department could not provide sufficient supporting documentation for $11.1 million of the $11.2 million (99 percent) in FEMA Disaster Grants program fund expenditures that it reported on its Exhibit K1 that represented CDPHE expenditures during the fiscal year. Department staff indicated that CDPHE did not provide the Department with adequate transactional detail to support CDPHE’s pass-through expenditures incurred for the program for Fiscal Year 2024. As a result, the Department relied on other data, including the amount of the total change in the interdepartmental payable to CDPHE for program expenditures and current year reimbursements to CDPHE, as the basis for its Exhibit K1 reporting. • Additionally, we identified an issue with 1 of the 70 (1 percent) expenditures reported on the Department’s Exhibit K1 that we selected for testing. Specifically, the Department incorrectly recorded and paid a federal expenditure in the amount of $1,488,695 instead of the correct amount of $1,448,695. As a result of the overpayment, the Department also overstated the total FEMA Disaster Grants program expenditures on its Exhibit K1 and was required to adjust this total from $194,279,466 to $194,239,466, which resulted in known questioned costs of $40,000. The Department corrected the error after we notified them of the issue we identified. Why did these problems occur? These problems occurred because the Department did not fully implement our prior audit recommendations. The Department and CDPHE were unable to sufficiently reconcile and verify CDPHE’s Fiscal Year 2024 federal expenditures because of the length of time that the grant has been effective and insufficient financial records from prior fiscal years that were not available. Rather, the Department and CDPHE placed more reliance on reconciling the current year reimbursements and the June 30, 2024 inception-to-date unreimbursed expenditures. The Department did enhance its communication with CDPHE surrounding the necessary detail for the year-end accrual reconciliation as of June 30, 2024; however, these additional communications did not sufficiently address the proper recording and reporting of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures on the Department’s Exhibit K1. We also found that while CDPHE developed and implemented procedures and provided training to its staff, those procedures did not sufficiently address the proper reconciliation of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures. CDPHE staff stated that they experienced turnover during the fiscal year, which resulted in the inability for CDPHE staff to properly identify individual transactions that made up the prior fiscal year’s—Fiscal Year 2023’s—unreimbursed expenditures. As a result of not being able to identify individual transactions that made up the prior Fiscal Year 2023’s unreimbursed expenditures, CDPHE staff were unable to identify Fiscal Year 2024 expenditures because they could not determine whether any of the reimbursements received in Fiscal Year 2024 were for expenditures included in the prior fiscal-year accrual, whether any prior fiscal year accrued expenditures were reclassified to a non-FEMA Disaster Grant program expenditure, or whether any prior fiscal year expenditures were identified as being eligible for the FEMA Disaster Grant program in the current fiscal year. Additionally, the Department did not reconcile the Fiscal Year 2024 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2023’s or other prior year’s expenditures to ensure the expenditures were reported in the appropriate fiscal year. As a result of the lack of reconciliation of current year expenditures, we were unable to determine the full extent to which the Department’s FEMA Disaster Grants program expenditures in CORE or on the Exhibit K1 ultimately were overstated or understated. Lastly, the overpayment of expenditures was the result of a data entry error by the Department’s staff when processing the payment. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements—including an appropriate reconciliation and review of allowable expenditures—the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment by the Department to the federal granting agency. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-051 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Continuing to develop, document, and implement policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year recorded by the Department and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that Department staff complete a reconciliation on at least an annual basis of detailed amounts of interagency expenditures reported on the Exhibit K1 for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year. The Department should also resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Continuing to develop, document, and implement policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. C. Sufficiently reviewing supporting documentation when approving transactions for payment to ensure the review identifies any data entry errors. Response Department of Public Safety A. Agree Implementation Date: June 2025 We have developed procedures requiring adequate and detailed support be received before recording interagency accruals. We will continue to apply those procedures and will continue to reconcile any new interagency expenditures prior to reporting on the K1. B. Agree Implementation Date: June 2025 We have developed procedures to requiring adequate and detailed support is received before recording interagency accruals. We will continue to apply those procedures and will continue to review expenditures to ensure they are reported in the proper period on the K1. We will review a sample of accrual expenditure details to verify expenditures are allowable under the federal program. C. Agree Implementation Date: June 2025 We will work with staff to remind them the importance of thorough reviews to ensure transactional accuracy. We will ensure desk procedures include adequate review steps. Recommendation 2024-052 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants program expenditures and ensure that all FEMA Disaster Grants program expenditures reported to the Department of Public Safety for reporting on the Department of Public Safety’s Exhibit K1, Schedule of Federal Assistance, are accurately supported by continuing to develop, document, and implement policies and procedures to require that CDPHE staff obtain and maintain sufficiently-detailed supporting documentation for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that CDPHE staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred but not yet reimbursed by the Department of Public Safety as of fiscal year end; reimbursement amounts requested by CDPHE from the Department of Public Safety for the FEMA Disaster Grants program during the year; and reimbursement payments received by the CDPHE from the Department of Public Safety during the year. CDPHE should also resolve any reconciling differences prior to reporting CDPHE FEMA Disaster Grants program expenditures to the Department of Public Safety. Response Department of Public Health and Environment Partially Agree Implementation Date: September 2025 CDPHE fully implemented the FY23 audit recommendation as written and updated our processes in conjunction with CDPS to ensure proper documentation was obtained for all claims in FY24. CDPHE and CDPS met regularly through FY24 to discuss these updates and verified every invoice processed with the applicable backup. CDPHE does not charge or draw any funds from CDPS until approval is received regarding FEMA eligibility. Copies of these approvals are included every time CDPHE draws funds from CDPS. The FY23 audit finding was related to the CDPHE year-end estimate to CDPS since CDPHE was not able to provide all needed supporting documentation to fully justify it. For FY24, instead of using an estimate, we based the FY24 accruals on approvals that were not paid during FY24, so were able to tie this out completely. For actual reimbursement FY24 requests, we tied out all expenses related to each reimbursement request. The procedure documentation was updated to reflect these new processes. Going forward, we are continuing to follow the same updated procedures to ensure that future reimbursement requests are accurate and have appropriate documentation attached. CDPHE verified that the amount listed was only reported on the CDPS K1 and not on both agencies K1s. To reflect the new addition on the FY24 recommendation, CDPHE has updated our procedures to add the full fiscal year reconciliation at the end of each fiscal year for all federal expenses, including expenditures incurred but not yet reimbursed by CDPS as of fiscal year-end, reimbursement requested by CDPHE from CDPS, reimbursements received by CDPHE during the fiscal year, and a resolution for any reconciling differences. Auditor’s Addendum As noted in the finding, we found that CDPHE did not fully implement the Fiscal Year 2023 recommendation and could not provide sufficient support for $11.1 million of the Fiscal Year 2024 FEMA Disaster Grant expenditures reported on the Department of Public Safety’s Exhibit K1. CDPHE should ensure it maintains complete documentation for its FEMA Disaster Grant expenditures and that it completes a reconciliation on an annual basis of the detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year.
We will work with staff to remind them the importance of thorough reviews to ensure transactional accuracy. We will ensure desk procedures include adequate review steps.
2023-076, 2023-077
During Fiscal Year 2024, we conducted audit work that resulted in a finding and recommendation addressed jointly to the Department and the Department of Public Safety related to internal controls over the Department of Public Safety’s Federal Emergency Management Agency (FEMA) Disaster Grants program. Expenditures for this program are partially comprised of Department expenditures that are submitted to the Department of Public Safety through interdepartmental transactions and requests for reimbursement. This finding and recommendation, and the responses of these agencies, are included within the Department of Public Safety’s chapter within Section III: Federal Awards Findings of this report. See Recommendation 2024-052. This recommendation is classified as a Material Weakness. Findings 2024-051 and 2024-052 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Disaster Grants Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the Department of Homeland Security, awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2024, the Department received funding through the following Disaster Grants federal awards: • FEMA-4145-DR for the 2013 Severe Storms, Flooding, Landslides, and Mudslides • FEMA-4429-DR-CO for the 2015 Severe Storms, Tornadoes, Flooding, Landslides and Mudslides • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 Wildfires incident • FEMA-4634-DR for the 2021 Wildfires and Straight-Line Winds incident • FEMA-4731 DR for the 2023 Severe Storms, Flooding and Tornadoes The Department’s FEMA Disaster Grants program awards are on a reimbursement basis, which means the Department requests reimbursement from FEMA for approved allowable costs, even some of those that are passed on to other state agencies or departments. The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and the OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments and institutions of higher education through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides some additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments and institutions of higher education prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should typically be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards included funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in Fiscal Year 2024 were for expenditures incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE submits FEMA Disaster Grants program expenditures information to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, before it disburses reimbursement payments to CDPHE. The point in time from when FEMA approves a project to when CDPHE requests reimbursement from the Department for CDPHE’s allowable expenditures may cross fiscal years, and during that time CDPHE may revise its previous specific identification of FEMA Disaster Grants program expenditures. Reasons for revising allowable expenditures may include not meeting FEMA’s specific documentation requirements or identifying additional allowable costs that were not previously identified. Therefore, it is important for both the Department and CDPHE to have processes in place to ensure that expenditures are reported in CORE and on the Department’s Exhibit K1 in the correct amount and year. For Fiscal Year 2024, CDPHE provided the Department with transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that had not yet been submitted for reimbursement through an interdepartmental transaction. Prior to Fiscal Year 2024, CDPHE only provided the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years. Department staff reviewed the transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that were incurred by CDPHE. Based on the June 30, 2024 inception-to-date transactional detail provided by CDPHE for unreimbursed FEMA Disaster Grants expenditures, the Department recognized an interdepartmental payable to CDPHE in CORE, along with the corresponding federal receivable. Additionally, the Department recognized the change in the CDPHE accrual from the prior fiscal year end—net of current year reimbursements to CPDHE—in CORE as federal expenditures and federal revenues for Fiscal Year 2024; specifically, the Department recorded $11.2 million in total Fiscal Year 2024 FEMA Disaster Grants program expenditures incurred and revenues earned by CDPHE. Overall, the change in the CDPHE accrual from the prior year end, represented a decrease of $90.2 million in expenditures and revenues, net of current year reimbursements to CDPHE of $101.4 million. Ultimately, the Department is responsible for the appropriate review and approval of all federal FEMA expenditures within FEMA’s grant tracking software, EMGrants, and for appropriately reporting the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2024, the Department reported $194.2 million in total FEMA Disaster Grants program expenditures. Of this amount, as noted above, $11.2 million (6 percent) of those program expenditures reported by the Department represented CDPHE’s FEMA Disaster Grants program expenditures during Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department complied with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether the Department had proper internal controls in place over the FEMA Disaster Grants program during Fiscal Year 2024. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting for, and financial reporting of, the FEMA Disaster Grants program activities in CORE and the Department’s Exhibit K1, along with determining whether the Department complied with applicable accounting standards during Fiscal Year 2024. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures requiring Department staff to obtain and maintain sufficiently-detailed supporting documentation from CDPHE for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department—as well as requiring that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1. The Department planned to implement these recommendations by September 2024. Further, the purpose of our audit work was to determine whether CDPHE implemented our Fiscal Year 2023 audit recommendation to ensure all Disaster Grants program expenditures are properly supported with appropriate documentation, and to expand CDPHE’s existing policies and procedures that staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department—which the Department reports on the Department’s Exhibit K1 and reconciling interdepartmental reimbursements. Lastly, we recommended that CDPHE provide training to its staff responsible for the Disaster Grants program on the updated policies and procedures. CDPHE planned to implement these recommendations by June 2024. As part of our audit work, we tested the Department’s and CDPHE’s progress on implementing our prior audit recommendations by reviewing their updated policies and procedures and training performed. Additionally, we obtained an understanding of the Department’s internal controls, including policies and procedures, related to account balances, financial processes, and fiscal year-end close processes for the Disaster Grants program. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented CDPHE’s expenditures of FEMA Disaster Grants program’s pass-through expenditures from the Department during the fiscal year, which totaled $11.2 million. • Requested that the Department provide transactional level detail to support the $11.2 million in Fiscal Year 2024 FEMA Disaster Grants program’s pass-through expenditures at CDPHE that were reported by the Department on its Exhibit K1. In addition, we inquired whether and how the Department reconciled the Fiscal Year 2024 transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 70 of the Department’s FEMA Disaster Grants program expenditures, excluding CDPHE expenditures, totaling approximately $104.4 million, that the Department reported were incurred during Fiscal Year 2024, to test the Department’s internal controls and compliance. We performed testing on the 70 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-1 (6.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system which includes controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 200.403(g)] require that costs be adequately documented. • The 2024 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? Based on our audit work, we determined that the Department and CDPHE did not fully implement our Fiscal Year 2023 recommendations by their planned implementation dates of June 2024 and September 2024. While the Department and CDPHE improved their processes for reconciling the June 2024 interdepartmental accrual for cumulative to date Disaster Grants program federal expenditures, we determined that the Department and CDPHE did not comply with applicable state and federal regulations during Fiscal Year 2024. Specifically, • The Department could not provide sufficient supporting documentation for $11.1 million of the $11.2 million (99 percent) in FEMA Disaster Grants program fund expenditures that it reported on its Exhibit K1 that represented CDPHE expenditures during the fiscal year. Department staff indicated that CDPHE did not provide the Department with adequate transactional detail to support CDPHE’s pass-through expenditures incurred for the program for Fiscal Year 2024. As a result, the Department relied on other data, including the amount of the total change in the interdepartmental payable to CDPHE for program expenditures and current year reimbursements to CDPHE, as the basis for its Exhibit K1 reporting. • Additionally, we identified an issue with 1 of the 70 (1 percent) expenditures reported on the Department’s Exhibit K1 that we selected for testing. Specifically, the Department incorrectly recorded and paid a federal expenditure in the amount of $1,488,695 instead of the correct amount of $1,448,695. As a result of the overpayment, the Department also overstated the total FEMA Disaster Grants program expenditures on its Exhibit K1 and was required to adjust this total from $194,279,466 to $194,239,466, which resulted in known questioned costs of $40,000. The Department corrected the error after we notified them of the issue we identified. Why did these problems occur? These problems occurred because the Department did not fully implement our prior audit recommendations. The Department and CDPHE were unable to sufficiently reconcile and verify CDPHE’s Fiscal Year 2024 federal expenditures because of the length of time that the grant has been effective and insufficient financial records from prior fiscal years that were not available. Rather, the Department and CDPHE placed more reliance on reconciling the current year reimbursements and the June 30, 2024 inception-to-date unreimbursed expenditures. The Department did enhance its communication with CDPHE surrounding the necessary detail for the year-end accrual reconciliation as of June 30, 2024; however, these additional communications did not sufficiently address the proper recording and reporting of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures on the Department’s Exhibit K1. We also found that while CDPHE developed and implemented procedures and provided training to its staff, those procedures did not sufficiently address the proper reconciliation of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures. CDPHE staff stated that they experienced turnover during the fiscal year, which resulted in the inability for CDPHE staff to properly identify individual transactions that made up the prior fiscal year’s—Fiscal Year 2023’s—unreimbursed expenditures. As a result of not being able to identify individual transactions that made up the prior Fiscal Year 2023’s unreimbursed expenditures, CDPHE staff were unable to identify Fiscal Year 2024 expenditures because they could not determine whether any of the reimbursements received in Fiscal Year 2024 were for expenditures included in the prior fiscal-year accrual, whether any prior fiscal year accrued expenditures were reclassified to a non-FEMA Disaster Grant program expenditure, or whether any prior fiscal year expenditures were identified as being eligible for the FEMA Disaster Grant program in the current fiscal year. Additionally, the Department did not reconcile the Fiscal Year 2024 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2023’s or other prior year’s expenditures to ensure the expenditures were reported in the appropriate fiscal year. As a result of the lack of reconciliation of current year expenditures, we were unable to determine the full extent to which the Department’s FEMA Disaster Grants program expenditures in CORE or on the Exhibit K1 ultimately were overstated or understated. Lastly, the overpayment of expenditures was the result of a data entry error by the Department’s staff when processing the payment. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements—including an appropriate reconciliation and review of allowable expenditures—the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment by the Department to the federal granting agency. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-051 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Continuing to develop, document, and implement policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year recorded by the Department and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that Department staff complete a reconciliation on at least an annual basis of detailed amounts of interagency expenditures reported on the Exhibit K1 for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year. The Department should also resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Continuing to develop, document, and implement policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. C. Sufficiently reviewing supporting documentation when approving transactions for payment to ensure the review identifies any data entry errors. Response Department of Public Safety A. Agree Implementation Date: June 2025 We have developed procedures requiring adequate and detailed support be received before recording interagency accruals. We will continue to apply those procedures and will continue to reconcile any new interagency expenditures prior to reporting on the K1. B. Agree Implementation Date: June 2025 We have developed procedures to requiring adequate and detailed support is received before recording interagency accruals. We will continue to apply those procedures and will continue to review expenditures to ensure they are reported in the proper period on the K1. We will review a sample of accrual expenditure details to verify expenditures are allowable under the federal program. C. Agree Implementation Date: June 2025 We will work with staff to remind them the importance of thorough reviews to ensure transactional accuracy. We will ensure desk procedures include adequate review steps. Recommendation 2024-052 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants program expenditures and ensure that all FEMA Disaster Grants program expenditures reported to the Department of Public Safety for reporting on the Department of Public Safety’s Exhibit K1, Schedule of Federal Assistance, are accurately supported by continuing to develop, document, and implement policies and procedures to require that CDPHE staff obtain and maintain sufficiently-detailed supporting documentation for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that CDPHE staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred but not yet reimbursed by the Department of Public Safety as of fiscal year end; reimbursement amounts requested by CDPHE from the Department of Public Safety for the FEMA Disaster Grants program during the year; and reimbursement payments received by the CDPHE from the Department of Public Safety during the year. CDPHE should also resolve any reconciling differences prior to reporting CDPHE FEMA Disaster Grants program expenditures to the Department of Public Safety. Response Department of Public Health and Environment Partially Agree Implementation Date: September 2025 CDPHE fully implemented the FY23 audit recommendation as written and updated our processes in conjunction with CDPS to ensure proper documentation was obtained for all claims in FY24. CDPHE and CDPS met regularly through FY24 to discuss these updates and verified every invoice processed with the applicable backup. CDPHE does not charge or draw any funds from CDPS until approval is received regarding FEMA eligibility. Copies of these approvals are included every time CDPHE draws funds from CDPS. The FY23 audit finding was related to the CDPHE year-end estimate to CDPS since CDPHE was not able to provide all needed supporting documentation to fully justify it. For FY24, instead of using an estimate, we based the FY24 accruals on approvals that were not paid during FY24, so were able to tie this out completely. For actual reimbursement FY24 requests, we tied out all expenses related to each reimbursement request. The procedure documentation was updated to reflect these new processes. Going forward, we are continuing to follow the same updated procedures to ensure that future reimbursement requests are accurate and have appropriate documentation attached. CDPHE verified that the amount listed was only reported on the CDPS K1 and not on both agencies K1s. To reflect the new addition on the FY24 recommendation, CDPHE has updated our procedures to add the full fiscal year reconciliation at the end of each fiscal year for all federal expenses, including expenditures incurred but not yet reimbursed by CDPS as of fiscal year-end, reimbursement requested by CDPHE from CDPS, reimbursements received by CDPHE during the fiscal year, and a resolution for any reconciling differences. Auditor’s Addendum As noted in the finding, we found that CDPHE did not fully implement the Fiscal Year 2023 recommendation and could not provide sufficient support for $11.1 million of the Fiscal Year 2024 FEMA Disaster Grant expenditures reported on the Department of Public Safety’s Exhibit K1. CDPHE should ensure it maintains complete documentation for its FEMA Disaster Grant expenditures and that it completes a reconciliation on an annual basis of the detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year.
Show full finding ▾Hide full finding ▴During Fiscal Year 2024, we conducted audit work that resulted in a finding and recommendation addressed jointly to the Department and the Department of Public Safety related to internal controls over the Department of Public Safety’s Federal Emergency Management Agency (FEMA) Disaster Grants program. Expenditures for this program are partially comprised of Department expenditures that are submitted to the Department of Public Safety through interdepartmental transactions and requests for reimbursement. This finding and recommendation, and the responses of these agencies, are included within the Department of Public Safety’s chapter within Section III: Federal Awards Findings of this report. See Recommendation 2024-052. This recommendation is classified as a Material Weakness. Findings 2024-051 and 2024-052 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Disaster Grants Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the Department of Homeland Security, awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2024, the Department received funding through the following Disaster Grants federal awards: • FEMA-4145-DR for the 2013 Severe Storms, Flooding, Landslides, and Mudslides • FEMA-4429-DR-CO for the 2015 Severe Storms, Tornadoes, Flooding, Landslides and Mudslides • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 Wildfires incident • FEMA-4634-DR for the 2021 Wildfires and Straight-Line Winds incident • FEMA-4731 DR for the 2023 Severe Storms, Flooding and Tornadoes The Department’s FEMA Disaster Grants program awards are on a reimbursement basis, which means the Department requests reimbursement from FEMA for approved allowable costs, even some of those that are passed on to other state agencies or departments. The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and the OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments and institutions of higher education through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides some additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments and institutions of higher education prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should typically be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards included funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in Fiscal Year 2024 were for expenditures incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE submits FEMA Disaster Grants program expenditures information to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, before it disburses reimbursement payments to CDPHE. The point in time from when FEMA approves a project to when CDPHE requests reimbursement from the Department for CDPHE’s allowable expenditures may cross fiscal years, and during that time CDPHE may revise its previous specific identification of FEMA Disaster Grants program expenditures. Reasons for revising allowable expenditures may include not meeting FEMA’s specific documentation requirements or identifying additional allowable costs that were not previously identified. Therefore, it is important for both the Department and CDPHE to have processes in place to ensure that expenditures are reported in CORE and on the Department’s Exhibit K1 in the correct amount and year. For Fiscal Year 2024, CDPHE provided the Department with transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that had not yet been submitted for reimbursement through an interdepartmental transaction. Prior to Fiscal Year 2024, CDPHE only provided the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years. Department staff reviewed the transactional detail of cumulative-to-date FEMA Disaster Grants program expenditures that were incurred by CDPHE. Based on the June 30, 2024 inception-to-date transactional detail provided by CDPHE for unreimbursed FEMA Disaster Grants expenditures, the Department recognized an interdepartmental payable to CDPHE in CORE, along with the corresponding federal receivable. Additionally, the Department recognized the change in the CDPHE accrual from the prior fiscal year end—net of current year reimbursements to CPDHE—in CORE as federal expenditures and federal revenues for Fiscal Year 2024; specifically, the Department recorded $11.2 million in total Fiscal Year 2024 FEMA Disaster Grants program expenditures incurred and revenues earned by CDPHE. Overall, the change in the CDPHE accrual from the prior year end, represented a decrease of $90.2 million in expenditures and revenues, net of current year reimbursements to CDPHE of $101.4 million. Ultimately, the Department is responsible for the appropriate review and approval of all federal FEMA expenditures within FEMA’s grant tracking software, EMGrants, and for appropriately reporting the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2024, the Department reported $194.2 million in total FEMA Disaster Grants program expenditures. Of this amount, as noted above, $11.2 million (6 percent) of those program expenditures reported by the Department represented CDPHE’s FEMA Disaster Grants program expenditures during Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department complied with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether the Department had proper internal controls in place over the FEMA Disaster Grants program during Fiscal Year 2024. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting for, and financial reporting of, the FEMA Disaster Grants program activities in CORE and the Department’s Exhibit K1, along with determining whether the Department complied with applicable accounting standards during Fiscal Year 2024. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures requiring Department staff to obtain and maintain sufficiently-detailed supporting documentation from CDPHE for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department—as well as requiring that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1. The Department planned to implement these recommendations by September 2024. Further, the purpose of our audit work was to determine whether CDPHE implemented our Fiscal Year 2023 audit recommendation to ensure all Disaster Grants program expenditures are properly supported with appropriate documentation, and to expand CDPHE’s existing policies and procedures that staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department—which the Department reports on the Department’s Exhibit K1 and reconciling interdepartmental reimbursements. Lastly, we recommended that CDPHE provide training to its staff responsible for the Disaster Grants program on the updated policies and procedures. CDPHE planned to implement these recommendations by June 2024. As part of our audit work, we tested the Department’s and CDPHE’s progress on implementing our prior audit recommendations by reviewing their updated policies and procedures and training performed. Additionally, we obtained an understanding of the Department’s internal controls, including policies and procedures, related to account balances, financial processes, and fiscal year-end close processes for the Disaster Grants program. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented CDPHE’s expenditures of FEMA Disaster Grants program’s pass-through expenditures from the Department during the fiscal year, which totaled $11.2 million. • Requested that the Department provide transactional level detail to support the $11.2 million in Fiscal Year 2024 FEMA Disaster Grants program’s pass-through expenditures at CDPHE that were reported by the Department on its Exhibit K1. In addition, we inquired whether and how the Department reconciled the Fiscal Year 2024 transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 70 of the Department’s FEMA Disaster Grants program expenditures, excluding CDPHE expenditures, totaling approximately $104.4 million, that the Department reported were incurred during Fiscal Year 2024, to test the Department’s internal controls and compliance. We performed testing on the 70 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-1 (6.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system which includes controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 200.403(g)] require that costs be adequately documented. • The 2024 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? Based on our audit work, we determined that the Department and CDPHE did not fully implement our Fiscal Year 2023 recommendations by their planned implementation dates of June 2024 and September 2024. While the Department and CDPHE improved their processes for reconciling the June 2024 interdepartmental accrual for cumulative to date Disaster Grants program federal expenditures, we determined that the Department and CDPHE did not comply with applicable state and federal regulations during Fiscal Year 2024. Specifically, • The Department could not provide sufficient supporting documentation for $11.1 million of the $11.2 million (99 percent) in FEMA Disaster Grants program fund expenditures that it reported on its Exhibit K1 that represented CDPHE expenditures during the fiscal year. Department staff indicated that CDPHE did not provide the Department with adequate transactional detail to support CDPHE’s pass-through expenditures incurred for the program for Fiscal Year 2024. As a result, the Department relied on other data, including the amount of the total change in the interdepartmental payable to CDPHE for program expenditures and current year reimbursements to CDPHE, as the basis for its Exhibit K1 reporting. • Additionally, we identified an issue with 1 of the 70 (1 percent) expenditures reported on the Department’s Exhibit K1 that we selected for testing. Specifically, the Department incorrectly recorded and paid a federal expenditure in the amount of $1,488,695 instead of the correct amount of $1,448,695. As a result of the overpayment, the Department also overstated the total FEMA Disaster Grants program expenditures on its Exhibit K1 and was required to adjust this total from $194,279,466 to $194,239,466, which resulted in known questioned costs of $40,000. The Department corrected the error after we notified them of the issue we identified. Why did these problems occur? These problems occurred because the Department did not fully implement our prior audit recommendations. The Department and CDPHE were unable to sufficiently reconcile and verify CDPHE’s Fiscal Year 2024 federal expenditures because of the length of time that the grant has been effective and insufficient financial records from prior fiscal years that were not available. Rather, the Department and CDPHE placed more reliance on reconciling the current year reimbursements and the June 30, 2024 inception-to-date unreimbursed expenditures. The Department did enhance its communication with CDPHE surrounding the necessary detail for the year-end accrual reconciliation as of June 30, 2024; however, these additional communications did not sufficiently address the proper recording and reporting of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures on the Department’s Exhibit K1. We also found that while CDPHE developed and implemented procedures and provided training to its staff, those procedures did not sufficiently address the proper reconciliation of Fiscal Year 2024 CDPHE FEMA Disaster Grants program expenditures. CDPHE staff stated that they experienced turnover during the fiscal year, which resulted in the inability for CDPHE staff to properly identify individual transactions that made up the prior fiscal year’s—Fiscal Year 2023’s—unreimbursed expenditures. As a result of not being able to identify individual transactions that made up the prior Fiscal Year 2023’s unreimbursed expenditures, CDPHE staff were unable to identify Fiscal Year 2024 expenditures because they could not determine whether any of the reimbursements received in Fiscal Year 2024 were for expenditures included in the prior fiscal-year accrual, whether any prior fiscal year accrued expenditures were reclassified to a non-FEMA Disaster Grant program expenditure, or whether any prior fiscal year expenditures were identified as being eligible for the FEMA Disaster Grant program in the current fiscal year. Additionally, the Department did not reconcile the Fiscal Year 2024 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2023’s or other prior year’s expenditures to ensure the expenditures were reported in the appropriate fiscal year. As a result of the lack of reconciliation of current year expenditures, we were unable to determine the full extent to which the Department’s FEMA Disaster Grants program expenditures in CORE or on the Exhibit K1 ultimately were overstated or understated. Lastly, the overpayment of expenditures was the result of a data entry error by the Department’s staff when processing the payment. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements—including an appropriate reconciliation and review of allowable expenditures—the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment by the Department to the federal granting agency. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-051 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Continuing to develop, document, and implement policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year recorded by the Department and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that Department staff complete a reconciliation on at least an annual basis of detailed amounts of interagency expenditures reported on the Exhibit K1 for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year. The Department should also resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Continuing to develop, document, and implement policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. C. Sufficiently reviewing supporting documentation when approving transactions for payment to ensure the review identifies any data entry errors. Response Department of Public Safety A. Agree Implementation Date: June 2025 We have developed procedures requiring adequate and detailed support be received before recording interagency accruals. We will continue to apply those procedures and will continue to reconcile any new interagency expenditures prior to reporting on the K1. B. Agree Implementation Date: June 2025 We have developed procedures to requiring adequate and detailed support is received before recording interagency accruals. We will continue to apply those procedures and will continue to review expenditures to ensure they are reported in the proper period on the K1. We will review a sample of accrual expenditure details to verify expenditures are allowable under the federal program. C. Agree Implementation Date: June 2025 We will work with staff to remind them the importance of thorough reviews to ensure transactional accuracy. We will ensure desk procedures include adequate review steps. Recommendation 2024-052 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants program expenditures and ensure that all FEMA Disaster Grants program expenditures reported to the Department of Public Safety for reporting on the Department of Public Safety’s Exhibit K1, Schedule of Federal Assistance, are accurately supported by continuing to develop, document, and implement policies and procedures to require that CDPHE staff obtain and maintain sufficiently-detailed supporting documentation for CDPHE’s expenditure of FEMA’s Disaster Grants program funds by fiscal year and perform reconciliations of the information to underlying transactional data on a go-forward basis. This should include requiring that CDPHE staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred but not yet reimbursed by the Department of Public Safety as of fiscal year end; reimbursement amounts requested by CDPHE from the Department of Public Safety for the FEMA Disaster Grants program during the year; and reimbursement payments received by the CDPHE from the Department of Public Safety during the year. CDPHE should also resolve any reconciling differences prior to reporting CDPHE FEMA Disaster Grants program expenditures to the Department of Public Safety. Response Department of Public Health and Environment Partially Agree Implementation Date: September 2025 CDPHE fully implemented the FY23 audit recommendation as written and updated our processes in conjunction with CDPS to ensure proper documentation was obtained for all claims in FY24. CDPHE and CDPS met regularly through FY24 to discuss these updates and verified every invoice processed with the applicable backup. CDPHE does not charge or draw any funds from CDPS until approval is received regarding FEMA eligibility. Copies of these approvals are included every time CDPHE draws funds from CDPS. The FY23 audit finding was related to the CDPHE year-end estimate to CDPS since CDPHE was not able to provide all needed supporting documentation to fully justify it. For FY24, instead of using an estimate, we based the FY24 accruals on approvals that were not paid during FY24, so were able to tie this out completely. For actual reimbursement FY24 requests, we tied out all expenses related to each reimbursement request. The procedure documentation was updated to reflect these new processes. Going forward, we are continuing to follow the same updated procedures to ensure that future reimbursement requests are accurate and have appropriate documentation attached. CDPHE verified that the amount listed was only reported on the CDPS K1 and not on both agencies K1s. To reflect the new addition on the FY24 recommendation, CDPHE has updated our procedures to add the full fiscal year reconciliation at the end of each fiscal year for all federal expenses, including expenditures incurred but not yet reimbursed by CDPS as of fiscal year-end, reimbursement requested by CDPHE from CDPS, reimbursements received by CDPHE during the fiscal year, and a resolution for any reconciling differences. Auditor’s Addendum As noted in the finding, we found that CDPHE did not fully implement the Fiscal Year 2023 recommendation and could not provide sufficient support for $11.1 million of the Fiscal Year 2024 FEMA Disaster Grant expenditures reported on the Department of Public Safety’s Exhibit K1. CDPHE should ensure it maintains complete documentation for its FEMA Disaster Grant expenditures and that it completes a reconciliation on an annual basis of the detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year.
CDPHE fully implemented the FY23 audit recommendation as written and updated our processes in conjunction with CDPS to ensure proper documentation was obtained for all claims in FY24. CDPHE and CDPS met regularly through FY24 to discuss these updates and verified every invoice processed with the applicable backup. CDPHE does not charge or draw any funds from CDPS until approval is received regarding FEMA eligibility. Copies of these approvals are included every time CDPHE draws funds from CDPS. The FY23 audit finding was related to the CDPHE year-end estimate to CDPS since CDPHE was not able to provide all needed supporting documentation to fully justify it. For FY24, instead of using an estimate, we based the FY24 accruals on approvals that were not paid during FY24, so were able to tie this out completely. For actual reimbursement FY24 requests, we tied out all expenses related to each reimbursement request. The procedure documentation was updated to reflect these new processes. Going forward, we are continuing to follow the same updated procedures to ensure that future reimbursement requests are accurate and have appropriate documentation attached. CDPHE verified that the amount listed was only reported on the CDPS K1 and not on both agencies K1s. To reflect the new addition on the FY24 recommendation, CDPHE has updated our procedures to add the full fiscal year reconciliation at the end of each fiscal year for all federal expenses, including expenditures incurred but not yet reimbursed by CDPS as of fiscal year-end, reimbursement requested by CDPHE from CDPS, reimbursements received by CDPHE during the fiscal year, and a resolution for any reconciling differences.
2023-076, 2023-077
Finding 2024-053 Compliance with Reporting for Disaster Grants Following a presidential declaration of a major disaster or an emergency, FEMA awards grants to assist SLTTs and certain PNP entities to respond to and recover from disasters. The Department receives FEMA grant awards and is required to follow reporting requirements as specifically identified in the various grant award agreements. The Department allocates funds received from these federal awards to subrecipients (local governments or PNPs) and the Department is responsible for the reporting of the payments made to its subrecipients. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Disaster Grants. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards, including information about amounts passed through to subrecipients, available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to submit FFATA information through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. The necessary information to support the required FFATA reporting elements is retained in the Department’s grants management information system, EMGrants. In Fiscal Year 2024, the Department made 75 subawards that were subject to FFATA reporting, which totaled $78.0 million to 32 subrecipients for its Disaster Grants. As a result, the Department was required to submit 75 FFATA reports for its Disaster Grants for Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over, and complied with, reporting requirements for its federal Disaster Grants for Fiscal Year 2024. In addition, the purpose of our audit work was to determine whether the information in these reports was accurate and complete, and submitted in accordance with federal regulations. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures for timely reporting within FSRS. The Department planned to implement this recommendation by June 2024. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting, and a list of all subawards made by the Department during Fiscal Year 2024. From the listing of 75 FFATA subawards, we selected a sample of 15 Disaster Grants subawards and requested verification that the Department submitted FFATA information through the FSRS for Fiscal Year 2024 to determine if the Department submitted FFATA information as required, and whether the information reported contained accurate and complete information. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 170.330.1(a)] require the Department to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if an award or supplemental award equal to or greater than $30,000 was made in April 2024. What problems did the audit work identify? Based on the testwork performed, we identified that the Department did not implement the Fiscal Year 2023 recommendation by its planned implementation date of June 2024 and did not comply with FFATA reporting requirements during Fiscal Year 2024. Specifically, the Department did not report approximately $16.3 million in subawards issued during Fiscal Year 2024 or $55.1 million in subawards issued in prior years that it had failed to report. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Finding and Questioned Costs for chart/table. Why did these problems occur? The Department did not have adequate internal controls over federal reporting requirements in place for its Disaster Grants during Fiscal Year 2024. Specifically, the Department failed to file FFATA reports for its Disaster Grants because, while it drafted policies and procedures for FFATA reporting during Fiscal Year 2024, it had not finalized the policies and procedures by fiscal year end and specifically, the policies and procedures did not designate responsibilities over FSRS reporting between fiscal staff and program staff. Further, the Department has been unsuccessful at obtaining a report from EMGrants with all of the required FFATA reporting elements that is in an appropriate format that allows the Department to submit bulk data, consisting of data that includes information such as subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, and the Department’s grant award identification number, of all subawards issued to FSRS. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-053 The Department of Public Safety (Department) should improve its internal controls over, and ensure it complies with, federal reporting requirements for its Disaster Grants – Public Assistance (Presidentially Declared Disasters) (Disaster Grants) by: A. Continuing to develop and implement policies and procedures to ensure that staff, as applicable, are aware of, and comply with, requirements under the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for its Disaster Grants. This should include improving the Department’s process for determining the timing of reporting within the FFATA Subaward Reporting System and appropriately allocating staff resources for FFATA reporting responsibilities. B. Creating a report in EMGrants, the Department’s grants management system, that contains all of the required FFTAA reporting elements, or identifying an alternate method that allows the Department to submit data to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). C. Submitting all required reports to FSRS that have yet to be filed, or obtaining documented approval from the federal government waiving this requirement for past due reports. Response Department of Public Safety A. Agree Implementation Date: June 2025 The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) has implemented FFATA reporting for our awards going forward and continues to work on past due reporting. However, the Federal Government has announced that the current reporting website (FSRS) will be decommissioned and a new process will be created through SAM.GOV. The change of systems will require a rewrite to our procedures and a review of the resources committed to the effort. B. Agree Implementation Date: June 2025 DHSEM will continue to work with our vendor (CIVIX) to create a report in EMGrants that works for our state. However, if it becomes apparent that EMGrants cannot offer a timely solution, we will implement other methods to ensure all reporting requirements are met. C. Agree Implementation Date: June 2025 DHSEM has implemented FFATA reporting for our awards going forward and continues to work on past due reporting. If this is possible we will do so, however, as FSRS is being decommissioned, we may not have the ability to file past reports.
Show full finding ▾Hide full finding ▴Finding 2024-053 Compliance with Reporting for Disaster Grants Following a presidential declaration of a major disaster or an emergency, FEMA awards grants to assist SLTTs and certain PNP entities to respond to and recover from disasters. The Department receives FEMA grant awards and is required to follow reporting requirements as specifically identified in the various grant award agreements. The Department allocates funds received from these federal awards to subrecipients (local governments or PNPs) and the Department is responsible for the reporting of the payments made to its subrecipients. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Disaster Grants. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards, including information about amounts passed through to subrecipients, available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to submit FFATA information through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. The necessary information to support the required FFATA reporting elements is retained in the Department’s grants management information system, EMGrants. In Fiscal Year 2024, the Department made 75 subawards that were subject to FFATA reporting, which totaled $78.0 million to 32 subrecipients for its Disaster Grants. As a result, the Department was required to submit 75 FFATA reports for its Disaster Grants for Fiscal Year 2024. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over, and complied with, reporting requirements for its federal Disaster Grants for Fiscal Year 2024. In addition, the purpose of our audit work was to determine whether the information in these reports was accurate and complete, and submitted in accordance with federal regulations. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to develop, document, and implement policies and procedures for timely reporting within FSRS. The Department planned to implement this recommendation by June 2024. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting, and a list of all subawards made by the Department during Fiscal Year 2024. From the listing of 75 FFATA subawards, we selected a sample of 15 Disaster Grants subawards and requested verification that the Department submitted FFATA information through the FSRS for Fiscal Year 2024 to determine if the Department submitted FFATA information as required, and whether the information reported contained accurate and complete information. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.303] require the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulations [2 CFR 200.334] require the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulations [2 CFR 170.330.1(a)] require the Department to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if an award or supplemental award equal to or greater than $30,000 was made in April 2024. What problems did the audit work identify? Based on the testwork performed, we identified that the Department did not implement the Fiscal Year 2023 recommendation by its planned implementation date of June 2024 and did not comply with FFATA reporting requirements during Fiscal Year 2024. Specifically, the Department did not report approximately $16.3 million in subawards issued during Fiscal Year 2024 or $55.1 million in subawards issued in prior years that it had failed to report. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Finding and Questioned Costs for chart/table. Why did these problems occur? The Department did not have adequate internal controls over federal reporting requirements in place for its Disaster Grants during Fiscal Year 2024. Specifically, the Department failed to file FFATA reports for its Disaster Grants because, while it drafted policies and procedures for FFATA reporting during Fiscal Year 2024, it had not finalized the policies and procedures by fiscal year end and specifically, the policies and procedures did not designate responsibilities over FSRS reporting between fiscal staff and program staff. Further, the Department has been unsuccessful at obtaining a report from EMGrants with all of the required FFATA reporting elements that is in an appropriate format that allows the Department to submit bulk data, consisting of data that includes information such as subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, and the Department’s grant award identification number, of all subawards issued to FSRS. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-053 The Department of Public Safety (Department) should improve its internal controls over, and ensure it complies with, federal reporting requirements for its Disaster Grants – Public Assistance (Presidentially Declared Disasters) (Disaster Grants) by: A. Continuing to develop and implement policies and procedures to ensure that staff, as applicable, are aware of, and comply with, requirements under the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for its Disaster Grants. This should include improving the Department’s process for determining the timing of reporting within the FFATA Subaward Reporting System and appropriately allocating staff resources for FFATA reporting responsibilities. B. Creating a report in EMGrants, the Department’s grants management system, that contains all of the required FFTAA reporting elements, or identifying an alternate method that allows the Department to submit data to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). C. Submitting all required reports to FSRS that have yet to be filed, or obtaining documented approval from the federal government waiving this requirement for past due reports. Response Department of Public Safety A. Agree Implementation Date: June 2025 The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) has implemented FFATA reporting for our awards going forward and continues to work on past due reporting. However, the Federal Government has announced that the current reporting website (FSRS) will be decommissioned and a new process will be created through SAM.GOV. The change of systems will require a rewrite to our procedures and a review of the resources committed to the effort. B. Agree Implementation Date: June 2025 DHSEM will continue to work with our vendor (CIVIX) to create a report in EMGrants that works for our state. However, if it becomes apparent that EMGrants cannot offer a timely solution, we will implement other methods to ensure all reporting requirements are met. C. Agree Implementation Date: June 2025 DHSEM has implemented FFATA reporting for our awards going forward and continues to work on past due reporting. If this is possible we will do so, however, as FSRS is being decommissioned, we may not have the ability to file past reports.
DHSEM has implemented FFATA reporting for our awards going forward and continues to work on past due reporting. If this is possible we will do so, however, as FSRS is being decommissioned, we may not have the ability to file past reports.
2023-078
Finding 2024-054 Compliance with Subrecipient Monitoring for Disaster Grants The Disaster Grants program is based on a partnership between FEMA; the recipient, which in these instances is the Department; and, as applicable, the subrecipient (local governments or PNPs). FEMA is responsible for managing the program, approving grants, and providing technical assistance to the SLTT. The Department, as a recipient of Disaster Grants program funds, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. A subrecipient is defined in federal regulations [2 CFR 200.1] as, “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity (such as the Department) to an entity (subrecipient) to carry out part of a federal grant award received by the pass-through entity. The subrecipient is expected to request assistance, as needed; identify the damaged facilities; provide information to support its funding requests; maintain accurate documentation; and perform other work, as necessary. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its subrecipient monitoring. The risk assessment should include considerations of financial risk factors, such as financial implications of operational and compliance failures; operational risk factors, such as risks resulting from inadequate internal controls; and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed and management decisions issued, if applicable. During Fiscal Year 2024, the Department passed approximately $180.2 million to 61 subrecipients for responses to various disasters covered by the Department’s Disaster Grants. In addition, the Department reported that it approved 103 new subawards during Fiscal Year 2024. In total, the Department reported that it had approximately 137 total subrecipients, including 76 subrecipients who did not receive funding passed through from the Department during Fiscal Year 2024; many of these subrecipients had multiple open projects that had been completed but were awaiting final approval and close out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over, and complied with, subrecipient monitoring requirements over the federal Disaster Grants program during Fiscal Year 2024. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to update the Department’s current policies to address considerations specific to all subrecipients with open subawards in the subrecipients’ risk assessments, and to update the subrecipient monitoring policy to be in compliance with federal regulations requiring management decisions to be issued within 6 months of acceptance of the subrecipient’s audit report by the Federal Audit Clearinghouse. The Department planned to implement these recommendations by June 2024. Further, we also recommended that the Department review all subrecipients’ Single Audit reports, as required, which the Department planned to implement by March 2024. As part of our audit work, we tested 28 of 137 (20 percent) of the Department’s subrecipients who received approximately $57.2 million of Disaster Grant funding during Fiscal Year 2024 to determine whether the Department performed risk assessments on the subrecipients, as required by federal regulations. We also requested the Department’s annual Risk Assessment package to determine whether the subrecipients’ risk assessments were appropriate and in accordance with federal regulations, and to determine whether the Department completed its onsite monitoring for those subrecipients that met the risk criteria for onsite monitoring. In addition, we performed testwork to determine whether the Department obtained the subrecipients’ Single Audit reports, and issued a management decision, if applicable. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.303] require the Department, as a federal award recipient, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that it is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. • Federal regulations [2 CFR 200.332] require the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring. Additionally, it requires the Department to verify that every subrecipient is audited as required by 2 CFR 200, Subpart F, and to consider whether the results of the subrecipient’s audits indicate conditions that necessitate adjustment to the pass-through entity’s—in this case, the Department’s—own records. • The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that it “…will perform an annual evaluation of Subrecipients’ risks prior to the start of each State fiscal year, analyzing active awards and assessing Subrecipients for the upcoming year to determine the financial status of each Subrecipient and which subrecipients will receive on-site monitoring.” The policy further goes on to indicate that each subrecipient will receive an overall risk score based on the quantitative and qualitative dated used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy also states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” • Federal regulations [2 CFR 200.329] stipulate that the Department is responsible for oversight of the operations of the federal award supported activities. The regulations further say that the “non-federal entity” must monitor its activities under federal awards to assure compliance with applicable federal requirements and performance expectations are being achieved. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully implement our Fiscal Year 2023 recommendation by its planned implementation dates of March 2024 and June 2024. The Department updated its policies by the stated implementation date of June 2024, completed its Fiscal Year 2024 subrecipient risk assessments in July 2023 to determine which subrecipients it would monitor during Fiscal Year 2024; however, we determined the Department did not comply with federal regulations related to subrecipient monitoring during Fiscal Year 2024. Specifically, we identified issues with 23 of the 28 (82 percent) subrecipients we tested, as follows: • The Department did not document risk assessments for 23 of the subrecipients we selected for testing. Specifically, the Department did not document risk assessments for the following Disaster Grant subrecipients: o 7 subrecipients of the 2013 Floods incident (FEMA-4145-DR) o 12 subrecipients for the COVID-19 incident (FEMA-4498-DR) o 4 subrecipients for other small projects The Department subsequently provided its reasons for why these subrecipients were deemed to have low to no subrecipient risk based on the nature of the specific FEMA subawards, such as that the projects were complete but waiting on final FEMA approval or had undergone a detailed approval process by FEMA prior to funds being obligated; however, the specific risk assessment for these subrecipients were not documented. Because of the risk assessment omissions that we identified in our sample, we expanded our testing to the Department’s full population of 61 subrecipients that received payments from the Department during Fiscal Year 2024. We determined that, in total, 51 of the 61 (84 percent) subrecipients did not have a risk assessment documented. These subrecipients accounted for approximately $92.2 million of the total $180.2 million (51 percent) of the total payments made by the Department to subrecipients during the current year. • The Department did not monitor whether 7 of the 28 (25 percent) subrecipients we tested were required to have a Single Audit, and if applicable, review the subrecipient’s Single Audit report and issue a management decision on findings. Why did these problems occur? The Department did not implement its written policies to address requirements for documenting risk assessments until the end of the fiscal year, or June 30, 2024. As a result, the Department did not have adequate internal controls in place during the fiscal year to ensure it complied with subrecipient requirements or that staff followed the Department’s own policies during Fiscal Year 2024. Specifically: • Department staff followed the Department’s former policies for documenting subrecipient risk assessments, which allowed staff to choose to not document formal risk assessments for subrecipients they deemed as having little risk of noncompliance based on reporting that had occurred up until that point in time. As a result, Department staff indicated that they excluded subawards related to the 2013 floods incident, 2015 floods incident, COVID-19 incident, small awards, and awards written at 100 percent. • The Department designated a staff to obtain and review Single Audit reports for all of its subrecipients; however, the Department did not allocate sufficient resources to ensure its staff were able to catch up on their reviews of previously unreviewed Single Audit reports during Fiscal Year 2024. Why do these problems matter? The issues we found are important because of the following: • By failing to properly document assessed risk of subrecipients, the Department is out of compliance with federal requirements and with its policy to assess risk for each subrecipient. This could result in the Department not timely identifying risks for subrecipients and modifying the extent of its monitoring activities to ensure the subrecipient has proper accountability and resources to be able to meet the program requirements. • By failing to verify that all subrecipients are audited as required by 2 CFR 200, Subpart F, the Department is out of compliance with federal requirements and its internal policies. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions, as applicable, to the monitoring risk assessment for the subrecipient. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-054 The Department of Public Safety (Department) should strengthen its internal controls over, and ensure it complies with, federal Disaster Grants – Public Assistance (Presidentially Declared Disasters) program requirements for subrecipient monitoring by: A. Following its current policy to address considerations specific to subrecipients with open subawards that were waiting final approval or had undergone a detailed approval by the Federal Emergency Management Agency (FEMA) prior to funds being obligated. B. Allocating sufficient staff resources to review subrecipient Single Audit reports to ensure the Department is in compliance with the Department’s policy and federal regulations to review all subrecipients’ Single Audit reports timely. Response Department of Public Safety A. Agree Implementation Date: June 2025 The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) will continue to follow the Policy and Procedure that was approved in June 2024. When this recommendation from the Fiscal Year 2023 audit was implemented, the new procedures were applied to those in-progress grants for that are effective for Fiscal Year 2025. At the time we agreed to implement, the Fiscal Year 2024 risk assessment was already completed. Our response of implemented is based on applying the updated risk assessment to the Fiscal Year 2025 awards. B. Agree Implementation Date: June 2025 DHSEM will allocate an individual to assist with reviewing the Single Audits per the Subrecipient Policy and Procedure.
Show full finding ▾Hide full finding ▴Finding 2024-054 Compliance with Subrecipient Monitoring for Disaster Grants The Disaster Grants program is based on a partnership between FEMA; the recipient, which in these instances is the Department; and, as applicable, the subrecipient (local governments or PNPs). FEMA is responsible for managing the program, approving grants, and providing technical assistance to the SLTT. The Department, as a recipient of Disaster Grants program funds, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. A subrecipient is defined in federal regulations [2 CFR 200.1] as, “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity (such as the Department) to an entity (subrecipient) to carry out part of a federal grant award received by the pass-through entity. The subrecipient is expected to request assistance, as needed; identify the damaged facilities; provide information to support its funding requests; maintain accurate documentation; and perform other work, as necessary. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its subrecipient monitoring. The risk assessment should include considerations of financial risk factors, such as financial implications of operational and compliance failures; operational risk factors, such as risks resulting from inadequate internal controls; and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed and management decisions issued, if applicable. During Fiscal Year 2024, the Department passed approximately $180.2 million to 61 subrecipients for responses to various disasters covered by the Department’s Disaster Grants. In addition, the Department reported that it approved 103 new subawards during Fiscal Year 2024. In total, the Department reported that it had approximately 137 total subrecipients, including 76 subrecipients who did not receive funding passed through from the Department during Fiscal Year 2024; many of these subrecipients had multiple open projects that had been completed but were awaiting final approval and close out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over, and complied with, subrecipient monitoring requirements over the federal Disaster Grants program during Fiscal Year 2024. Another purpose of the audit work was to determine whether the Department implemented our Fiscal Year 2023 audit recommendation to update the Department’s current policies to address considerations specific to all subrecipients with open subawards in the subrecipients’ risk assessments, and to update the subrecipient monitoring policy to be in compliance with federal regulations requiring management decisions to be issued within 6 months of acceptance of the subrecipient’s audit report by the Federal Audit Clearinghouse. The Department planned to implement these recommendations by June 2024. Further, we also recommended that the Department review all subrecipients’ Single Audit reports, as required, which the Department planned to implement by March 2024. As part of our audit work, we tested 28 of 137 (20 percent) of the Department’s subrecipients who received approximately $57.2 million of Disaster Grant funding during Fiscal Year 2024 to determine whether the Department performed risk assessments on the subrecipients, as required by federal regulations. We also requested the Department’s annual Risk Assessment package to determine whether the subrecipients’ risk assessments were appropriate and in accordance with federal regulations, and to determine whether the Department completed its onsite monitoring for those subrecipients that met the risk criteria for onsite monitoring. In addition, we performed testwork to determine whether the Department obtained the subrecipients’ Single Audit reports, and issued a management decision, if applicable. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulations [2 CFR 200.303] require the Department, as a federal award recipient, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that it is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. • Federal regulations [2 CFR 200.332] require the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring. Additionally, it requires the Department to verify that every subrecipient is audited as required by 2 CFR 200, Subpart F, and to consider whether the results of the subrecipient’s audits indicate conditions that necessitate adjustment to the pass-through entity’s—in this case, the Department’s—own records. • The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that it “…will perform an annual evaluation of Subrecipients’ risks prior to the start of each State fiscal year, analyzing active awards and assessing Subrecipients for the upcoming year to determine the financial status of each Subrecipient and which subrecipients will receive on-site monitoring.” The policy further goes on to indicate that each subrecipient will receive an overall risk score based on the quantitative and qualitative dated used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy also states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” • Federal regulations [2 CFR 200.329] stipulate that the Department is responsible for oversight of the operations of the federal award supported activities. The regulations further say that the “non-federal entity” must monitor its activities under federal awards to assure compliance with applicable federal requirements and performance expectations are being achieved. What problems did the audit work identify? Based on our audit work, we determined that the Department did not fully implement our Fiscal Year 2023 recommendation by its planned implementation dates of March 2024 and June 2024. The Department updated its policies by the stated implementation date of June 2024, completed its Fiscal Year 2024 subrecipient risk assessments in July 2023 to determine which subrecipients it would monitor during Fiscal Year 2024; however, we determined the Department did not comply with federal regulations related to subrecipient monitoring during Fiscal Year 2024. Specifically, we identified issues with 23 of the 28 (82 percent) subrecipients we tested, as follows: • The Department did not document risk assessments for 23 of the subrecipients we selected for testing. Specifically, the Department did not document risk assessments for the following Disaster Grant subrecipients: o 7 subrecipients of the 2013 Floods incident (FEMA-4145-DR) o 12 subrecipients for the COVID-19 incident (FEMA-4498-DR) o 4 subrecipients for other small projects The Department subsequently provided its reasons for why these subrecipients were deemed to have low to no subrecipient risk based on the nature of the specific FEMA subawards, such as that the projects were complete but waiting on final FEMA approval or had undergone a detailed approval process by FEMA prior to funds being obligated; however, the specific risk assessment for these subrecipients were not documented. Because of the risk assessment omissions that we identified in our sample, we expanded our testing to the Department’s full population of 61 subrecipients that received payments from the Department during Fiscal Year 2024. We determined that, in total, 51 of the 61 (84 percent) subrecipients did not have a risk assessment documented. These subrecipients accounted for approximately $92.2 million of the total $180.2 million (51 percent) of the total payments made by the Department to subrecipients during the current year. • The Department did not monitor whether 7 of the 28 (25 percent) subrecipients we tested were required to have a Single Audit, and if applicable, review the subrecipient’s Single Audit report and issue a management decision on findings. Why did these problems occur? The Department did not implement its written policies to address requirements for documenting risk assessments until the end of the fiscal year, or June 30, 2024. As a result, the Department did not have adequate internal controls in place during the fiscal year to ensure it complied with subrecipient requirements or that staff followed the Department’s own policies during Fiscal Year 2024. Specifically: • Department staff followed the Department’s former policies for documenting subrecipient risk assessments, which allowed staff to choose to not document formal risk assessments for subrecipients they deemed as having little risk of noncompliance based on reporting that had occurred up until that point in time. As a result, Department staff indicated that they excluded subawards related to the 2013 floods incident, 2015 floods incident, COVID-19 incident, small awards, and awards written at 100 percent. • The Department designated a staff to obtain and review Single Audit reports for all of its subrecipients; however, the Department did not allocate sufficient resources to ensure its staff were able to catch up on their reviews of previously unreviewed Single Audit reports during Fiscal Year 2024. Why do these problems matter? The issues we found are important because of the following: • By failing to properly document assessed risk of subrecipients, the Department is out of compliance with federal requirements and with its policy to assess risk for each subrecipient. This could result in the Department not timely identifying risks for subrecipients and modifying the extent of its monitoring activities to ensure the subrecipient has proper accountability and resources to be able to meet the program requirements. • By failing to verify that all subrecipients are audited as required by 2 CFR 200, Subpart F, the Department is out of compliance with federal requirements and its internal policies. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions, as applicable, to the monitoring risk assessment for the subrecipient. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-054 The Department of Public Safety (Department) should strengthen its internal controls over, and ensure it complies with, federal Disaster Grants – Public Assistance (Presidentially Declared Disasters) program requirements for subrecipient monitoring by: A. Following its current policy to address considerations specific to subrecipients with open subawards that were waiting final approval or had undergone a detailed approval by the Federal Emergency Management Agency (FEMA) prior to funds being obligated. B. Allocating sufficient staff resources to review subrecipient Single Audit reports to ensure the Department is in compliance with the Department’s policy and federal regulations to review all subrecipients’ Single Audit reports timely. Response Department of Public Safety A. Agree Implementation Date: June 2025 The Department’s Division of Homeland Security & Emergency Management’s (DHSEM) will continue to follow the Policy and Procedure that was approved in June 2024. When this recommendation from the Fiscal Year 2023 audit was implemented, the new procedures were applied to those in-progress grants for that are effective for Fiscal Year 2025. At the time we agreed to implement, the Fiscal Year 2024 risk assessment was already completed. Our response of implemented is based on applying the updated risk assessment to the Fiscal Year 2025 awards. B. Agree Implementation Date: June 2025 DHSEM will allocate an individual to assist with reviewing the Single Audits per the Subrecipient Policy and Procedure.
DHSEM will allocate an individual to assist with reviewing the Single Audits per the Subrecipient Policy and Procedure.
2023-075
Finding 2024-055 Compliance with Period of Performance for the Highway Safety Cluster The objective of the Highway Traffic Safety Grant Programs (Highway Safety Cluster) is to provide a coordinated, national highway safety program to reduce traffic crashes, deaths, injuries, and property damage. During Fiscal Year 2024, the Department received a total of $11,697,388 in federal Highway Safety Cluster [ALNs 20.600, 20.616] grants with a period of performance beginning October 1, 2023 and ending September 30, 2027. In order to ensure that federal funds are used only during the authorized period of performance, the Department requires a minimum of two different reviews and approvals of the costs. Costs are reviewed and entered into SAP, the Department’s enterprise resource planning system, by grant coordinators then reviewed and approved by the Department’s Headquarters (HQ) Business Office staff and/or HQ personnel. The costs are then interfaced with the Colorado Operations Resource Engine (CORE), the State’s accounting system. Grant coordinators providing first-level review, Regional Business Office staff, and Department HQ staff are all expected to be knowledgeable in allowable costs requirements for the Highway Safety Cluster. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls related to period of performance requirements for the Highway Safety Cluster, and whether the Department complied with period of performance requirements by recording Highway Safety Cluster expenditures appropriately during the approved budget period of the Highway Safety Cluster’s period of performance during Fiscal Year 2024. To determine whether costs were charged only during the authorized period of performance, we sampled from a population of all costs recorded during the beginning (first 30 calendar days) of the period of performance of these grants, or between October 1 and October 30, 2023. Twenty-one transactions were subject to sampling, totaling $7,423. We randomly selected six transactions charged to the grant between October 1 and October 30, 2023. We reviewed supporting documentation provided by the Department to support the date the expense was incurred and evidence of internal controls related to approval of the expense. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following requirements: • Federal regulations [2 CFR sections 200.308, 200.309, and 200.403(h)] state that a non-federal entity—in this case the Department—may charge only allowable costs incurred during the approved budget period of a federal award’s period of performance and any costs incurred before the federal awarding agency made the federal award that were authorized by the federal awarding agency. A period of performance may contain one or more budget periods. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice, purchase order, or reimbursement request, included with the transaction and that the supporting documentation must be reviewed for allowability under the applicable federal grant program by at least two individuals. What problem did the audit work identify? We determined that the Department did not fully comply with the period of performance requirements for the Highway Safety Cluster. Based on our audit testwork, we found that the Department recorded 4 of 6 transactions selected for testing (67 percent) outside the period of performance, ranging from 1 day to 23 days prior to October 1, 2023, the start of the period of performance. This resulted in questioned costs totaling $4,367. Why did this problem occur? The Department’s procedures and internal controls were not operating effectively to ensure that expenditures charged to the program were incurred within the award’s period of performance. The Department’s preparers and reviewers of the costs charged to the grant neglected to ensure that the costs being charged were incurred during the allowable award period. Department personnel did not appear to be aware of the period of performance compliance requirements. Why does this problem matter? By failing to properly record expenditures to the program within the award’s period of performance, resulting in expenditures being charged that were outside the allowable period of performance, the Department is out of compliance with federal period of performance requirements. Costs could be deemed unallowable by the awarding agency and funds may be required to be returned by the State. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-055 The Department of Transportation (Department) should ensure that it complies with federal Highway Safety Cluster grant period of performance requirements by: A. Enforcing its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include monitoring to ensure that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance; adjustments should be made for any expenditures charged to an award outside the proper period of performance. B. Providing additional training to Department personnel on period of performance compliance requirements, as deemed necessary. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review the current process and consider if any updates are needed to ensure supporting documentation is reviewed and compliance with grant requirements is verified prior to payment. This will include assessing the need for increased monitoring and review to ensure the initial program review is III-4 Colorado Office of the State Auditor complete and accurate. The Department will also review, assess, and, where necessary, update existing policies and procedures related to payment processing. B. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will assess, and update as necessary, training for staff responsible for reviewing and approving invoices for the Highway Safety Cluster grants, with a focus on period of performance.
Show full finding ▾Hide full finding ▴Finding 2024-055 Compliance with Period of Performance for the Highway Safety Cluster The objective of the Highway Traffic Safety Grant Programs (Highway Safety Cluster) is to provide a coordinated, national highway safety program to reduce traffic crashes, deaths, injuries, and property damage. During Fiscal Year 2024, the Department received a total of $11,697,388 in federal Highway Safety Cluster [ALNs 20.600, 20.616] grants with a period of performance beginning October 1, 2023 and ending September 30, 2027. In order to ensure that federal funds are used only during the authorized period of performance, the Department requires a minimum of two different reviews and approvals of the costs. Costs are reviewed and entered into SAP, the Department’s enterprise resource planning system, by grant coordinators then reviewed and approved by the Department’s Headquarters (HQ) Business Office staff and/or HQ personnel. The costs are then interfaced with the Colorado Operations Resource Engine (CORE), the State’s accounting system. Grant coordinators providing first-level review, Regional Business Office staff, and Department HQ staff are all expected to be knowledgeable in allowable costs requirements for the Highway Safety Cluster. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls related to period of performance requirements for the Highway Safety Cluster, and whether the Department complied with period of performance requirements by recording Highway Safety Cluster expenditures appropriately during the approved budget period of the Highway Safety Cluster’s period of performance during Fiscal Year 2024. To determine whether costs were charged only during the authorized period of performance, we sampled from a population of all costs recorded during the beginning (first 30 calendar days) of the period of performance of these grants, or between October 1 and October 30, 2023. Twenty-one transactions were subject to sampling, totaling $7,423. We randomly selected six transactions charged to the grant between October 1 and October 30, 2023. We reviewed supporting documentation provided by the Department to support the date the expense was incurred and evidence of internal controls related to approval of the expense. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following requirements: • Federal regulations [2 CFR sections 200.308, 200.309, and 200.403(h)] state that a non-federal entity—in this case the Department—may charge only allowable costs incurred during the approved budget period of a federal award’s period of performance and any costs incurred before the federal awarding agency made the federal award that were authorized by the federal awarding agency. A period of performance may contain one or more budget periods. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice, purchase order, or reimbursement request, included with the transaction and that the supporting documentation must be reviewed for allowability under the applicable federal grant program by at least two individuals. What problem did the audit work identify? We determined that the Department did not fully comply with the period of performance requirements for the Highway Safety Cluster. Based on our audit testwork, we found that the Department recorded 4 of 6 transactions selected for testing (67 percent) outside the period of performance, ranging from 1 day to 23 days prior to October 1, 2023, the start of the period of performance. This resulted in questioned costs totaling $4,367. Why did this problem occur? The Department’s procedures and internal controls were not operating effectively to ensure that expenditures charged to the program were incurred within the award’s period of performance. The Department’s preparers and reviewers of the costs charged to the grant neglected to ensure that the costs being charged were incurred during the allowable award period. Department personnel did not appear to be aware of the period of performance compliance requirements. Why does this problem matter? By failing to properly record expenditures to the program within the award’s period of performance, resulting in expenditures being charged that were outside the allowable period of performance, the Department is out of compliance with federal period of performance requirements. Costs could be deemed unallowable by the awarding agency and funds may be required to be returned by the State. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-055 The Department of Transportation (Department) should ensure that it complies with federal Highway Safety Cluster grant period of performance requirements by: A. Enforcing its existing policies and procedures that require that grant expenditures be allowable, and that two individuals review the related supporting documentation for compliance with grant requirements. This should include monitoring to ensure that Department personnel performing the reviews review the related supporting documentation for incurred dates in order to verify that expenditures comply with the applicable award period of performance; adjustments should be made for any expenditures charged to an award outside the proper period of performance. B. Providing additional training to Department personnel on period of performance compliance requirements, as deemed necessary. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review the current process and consider if any updates are needed to ensure supporting documentation is reviewed and compliance with grant requirements is verified prior to payment. This will include assessing the need for increased monitoring and review to ensure the initial program review is III-4 Colorado Office of the State Auditor complete and accurate. The Department will also review, assess, and, where necessary, update existing policies and procedures related to payment processing. B. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will assess, and update as necessary, training for staff responsible for reviewing and approving invoices for the Highway Safety Cluster grants, with a focus on period of performance.
The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will assess, and update as necessary, training for staff responsible for reviewing and approving invoices for the Highway Safety Cluster grants, with a focus on period of performance.
Finding 2024-056 Compliance with Reporting for the Highway Safety Cluster FFATA The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public; in order to obtain this information, the federal government has established federal reporting requirements for states and other governments who expend federal funds. The Department is required to report information about subgrants, or subawards, of federal grants that it gives to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity—in this case the Department—to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2024 included information on the federal Highway Safety Cluster, specifically the State and Community Highway Safety grant [ALN 20.600] and National Priority Safety Programs [ALN 20.616]. FFATA reporting was required because the Department passed through funds in excess of $30,000 to one or more subrecipients for each of the two programs. The Department made 955 payments to subrecipients, totaling $5,669,865 during Fiscal Year 2024 for which FFATA reporting applies. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Highway Safety Cluster during Fiscal Year 2024. As part of our audit work, we selected 40 subrecipient transactions totaling $540,050 and requested copies of the related FFATA reports that were uploaded to the FSRS system. We compared the amounts and dates reported by the Department for subawards in FSRS to the underlying support provided by the Department. In addition, we performed testwork to determine whether the Department submitted the FFATA reports within the month following the month the subaward was made, as required by federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following: • Federal regulations [2 CFR 170] specify that direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if an award or supplemental award equal to or greater than $30,000 was made in April 2024. • Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the unique entity identifier, the Assistance Listing Number (ALN), the Federal Award Date, and the Federal Award Identification Number (FAIN). What problems did the audit work identify? Based on our audit work, we determined the Department did not report its subawards in FSRS for the Highway Safety Cluster accurately. We identified issues with 40 of the 40 subrecipient transactions (100 percent) we tested, as follows: • 22 instances in which the Department did not have accurate documentation to support amounts reported in FSRS. Of these 22 instances, there were 12 instances where the Department reported amounts in FSRS that did not tie back to the Department’s subaward documentation. In 1 of these 12 instances, the Department did not have an amendment to the subaward agreement to support the amount reported, and the Department did not have a reconciliation to support the amount reported in FSRS. • 10 instances in which the Department did not have evidence the subaward was filed in FSRS. • 19 instances in which the Department did not report the subawards in FSRS within the required federal timeline. Specifically, the Department reported 5 subawards 1 day late, 2 subawards 335 days late, 2 subawards 366 days late, and it failed to report 10 subawards at all. • 31 instances in which the Department’s subaward date reported in FSRS did not match the date of the Department’s subaward. • 1 instance in which the Department inaccurately reported 1 subaward in FSRS as 2 separate awards. • For all 40 reports, the Department did not have formal evidence of review and approval prior to the FFATA report submission. In addition to the issues noted previously, the Department did not have a comprehensive list of subaward agreements and amendments to subaward agreements for Fiscal Year 2024. This resulted in the Department not having a complete population of agreements that the Department was required to file in FSRS for Fiscal Year 2024. The following table summarizes the results of our testing and groups each issue noted into the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Finding and Questioned Costs for chart/table. Why did these problems occur? The Department did not have adequate internal controls—including documented policies and procedures—in place during Fiscal Year 2024 related to FFATA reporting for the Highway Safety Cluster that ensures reporting occurs as required for subawards of $30,000 or more in FSRS by the end of the month following the month the subawards are made and that evidence is maintained to demonstrate when the reports were submitted. Specifically, the Department does not have policies and procedures for FFATA reporting that include requirements for the method in which Department staff must track funds passed to subrecipients, reconciliation procedures to identify subawards that need to be reported each month, reconciliation of amounts reported in the FSRS to amounts on subawards, if different, and evidence of review and approval. In addition, the Department did not have a reconciliation with supporting schedules to support amounts reported in FSRS. Further, the Department did not have documentation showing where the amounts reported in FSRS were compiled from, since the amounts did not agree to the subaward documents. The Department also did not have a control in place, such as a reconciliation or review process, to identify subawards that went unreported during the fiscal year and did not have a process to compile a comprehensive list of subawards and amendments that the Department awarded during the fiscal year. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-056 The Department of Transportation (Department) should strengthen its internal controls over and ensure it complies with requirements under the Federal Funding Accountability and Transparency Act (FFATA) reporting for the Highway Safety Cluster by: A. Developing and implementing policies and procedures for FFATA reporting to include requirements for the method in which Department staff must track funds passed to subrecipients, reconciliation procedures to identify subawards that need to be reported each month, reconciliation of amounts reported in the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) to amounts on subawards, if different, and evidence of review and approval. The reconciliation procedures should include maintenance of supporting schedules to support amounts reported in FSRS. B. Ensuring that reporting occurs as required for subawards of $30,000 or more in FSRS by the end of the month following the month the subawards are made and maintaining evidence to demonstrate when the reports were submitted. C. Creating a listing of all subawards by program that are awarded during the fiscal year, so that a complete population can be determined for Single Audit purposes and for the Department to accurately track the status of subawards made to subrecipients. This listing should also include any subaward amendments. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing policies and procedures on FFATA reporting. This will include new procedures to review and verify reporting data provided by the OTS prior to submission in the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS), as well as new procedures relating to the maintenance of supporting schedules. This process will be moving to a new federal system, SAM.gov in the Spring of 2025. The CFA will also work with the OTS to implement improvements to the tracking system for highway safety funds and subawards while ensuring evidence of review and approval. B. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing procedures for FFATA reporting relating to the requirement that state sub awards for $30,000+ be submitted within 30 days of committed budget. This will include ensuring that the confirmation date is documented. This process will be a coordinated effort between the OTS and the CAF. The coordination will include a shared google sheet. The OTS will update monthly and the CFA will review and submit new sub awards in FFATA for alignment. C. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing procedures relating to the tracking of subawards made to subrecipients and their status. OTS will modify their listings of subawards by program to include all amendments and new subawards and update it monthly. CFA will review the listing to ensure the accuracy of reporting submittals. The listing of subawards will be reconciled monthly. In addition, the FSRS system for FFATA reporting will be replaced with SAM.gov in Spring 2025. The new system includes improvements which will allow for more accurate tracking, and modifications to prior entries to support reconciliation which the prior system did not.
Show full finding ▾Hide full finding ▴Finding 2024-056 Compliance with Reporting for the Highway Safety Cluster FFATA The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public; in order to obtain this information, the federal government has established federal reporting requirements for states and other governments who expend federal funds. The Department is required to report information about subgrants, or subawards, of federal grants that it gives to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity—in this case the Department—to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2024 included information on the federal Highway Safety Cluster, specifically the State and Community Highway Safety grant [ALN 20.600] and National Priority Safety Programs [ALN 20.616]. FFATA reporting was required because the Department passed through funds in excess of $30,000 to one or more subrecipients for each of the two programs. The Department made 955 payments to subrecipients, totaling $5,669,865 during Fiscal Year 2024 for which FFATA reporting applies. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Highway Safety Cluster during Fiscal Year 2024. As part of our audit work, we selected 40 subrecipient transactions totaling $540,050 and requested copies of the related FFATA reports that were uploaded to the FSRS system. We compared the amounts and dates reported by the Department for subawards in FSRS to the underlying support provided by the Department. In addition, we performed testwork to determine whether the Department submitted the FFATA reports within the month following the month the subaward was made, as required by federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following: • Federal regulations [2 CFR 170] specify that direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2024 if an award or supplemental award equal to or greater than $30,000 was made in April 2024. • Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the unique entity identifier, the Assistance Listing Number (ALN), the Federal Award Date, and the Federal Award Identification Number (FAIN). What problems did the audit work identify? Based on our audit work, we determined the Department did not report its subawards in FSRS for the Highway Safety Cluster accurately. We identified issues with 40 of the 40 subrecipient transactions (100 percent) we tested, as follows: • 22 instances in which the Department did not have accurate documentation to support amounts reported in FSRS. Of these 22 instances, there were 12 instances where the Department reported amounts in FSRS that did not tie back to the Department’s subaward documentation. In 1 of these 12 instances, the Department did not have an amendment to the subaward agreement to support the amount reported, and the Department did not have a reconciliation to support the amount reported in FSRS. • 10 instances in which the Department did not have evidence the subaward was filed in FSRS. • 19 instances in which the Department did not report the subawards in FSRS within the required federal timeline. Specifically, the Department reported 5 subawards 1 day late, 2 subawards 335 days late, 2 subawards 366 days late, and it failed to report 10 subawards at all. • 31 instances in which the Department’s subaward date reported in FSRS did not match the date of the Department’s subaward. • 1 instance in which the Department inaccurately reported 1 subaward in FSRS as 2 separate awards. • For all 40 reports, the Department did not have formal evidence of review and approval prior to the FFATA report submission. In addition to the issues noted previously, the Department did not have a comprehensive list of subaward agreements and amendments to subaward agreements for Fiscal Year 2024. This resulted in the Department not having a complete population of agreements that the Department was required to file in FSRS for Fiscal Year 2024. The following table summarizes the results of our testing and groups each issue noted into the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Finding and Questioned Costs for chart/table. Why did these problems occur? The Department did not have adequate internal controls—including documented policies and procedures—in place during Fiscal Year 2024 related to FFATA reporting for the Highway Safety Cluster that ensures reporting occurs as required for subawards of $30,000 or more in FSRS by the end of the month following the month the subawards are made and that evidence is maintained to demonstrate when the reports were submitted. Specifically, the Department does not have policies and procedures for FFATA reporting that include requirements for the method in which Department staff must track funds passed to subrecipients, reconciliation procedures to identify subawards that need to be reported each month, reconciliation of amounts reported in the FSRS to amounts on subawards, if different, and evidence of review and approval. In addition, the Department did not have a reconciliation with supporting schedules to support amounts reported in FSRS. Further, the Department did not have documentation showing where the amounts reported in FSRS were compiled from, since the amounts did not agree to the subaward documents. The Department also did not have a control in place, such as a reconciliation or review process, to identify subawards that went unreported during the fiscal year and did not have a process to compile a comprehensive list of subawards and amendments that the Department awarded during the fiscal year. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-056 The Department of Transportation (Department) should strengthen its internal controls over and ensure it complies with requirements under the Federal Funding Accountability and Transparency Act (FFATA) reporting for the Highway Safety Cluster by: A. Developing and implementing policies and procedures for FFATA reporting to include requirements for the method in which Department staff must track funds passed to subrecipients, reconciliation procedures to identify subawards that need to be reported each month, reconciliation of amounts reported in the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) to amounts on subawards, if different, and evidence of review and approval. The reconciliation procedures should include maintenance of supporting schedules to support amounts reported in FSRS. B. Ensuring that reporting occurs as required for subawards of $30,000 or more in FSRS by the end of the month following the month the subawards are made and maintaining evidence to demonstrate when the reports were submitted. C. Creating a listing of all subawards by program that are awarded during the fiscal year, so that a complete population can be determined for Single Audit purposes and for the Department to accurately track the status of subawards made to subrecipients. This listing should also include any subaward amendments. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing policies and procedures on FFATA reporting. This will include new procedures to review and verify reporting data provided by the OTS prior to submission in the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS), as well as new procedures relating to the maintenance of supporting schedules. This process will be moving to a new federal system, SAM.gov in the Spring of 2025. The CFA will also work with the OTS to implement improvements to the tracking system for highway safety funds and subawards while ensuring evidence of review and approval. B. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing procedures for FFATA reporting relating to the requirement that state sub awards for $30,000+ be submitted within 30 days of committed budget. This will include ensuring that the confirmation date is documented. This process will be a coordinated effort between the OTS and the CAF. The coordination will include a shared google sheet. The OTS will update monthly and the CFA will review and submit new sub awards in FFATA for alignment. C. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing procedures relating to the tracking of subawards made to subrecipients and their status. OTS will modify their listings of subawards by program to include all amendments and new subawards and update it monthly. CFA will review the listing to ensure the accuracy of reporting submittals. The listing of subawards will be reconciled monthly. In addition, the FSRS system for FFATA reporting will be replaced with SAM.gov in Spring 2025. The new system includes improvements which will allow for more accurate tracking, and modifications to prior entries to support reconciliation which the prior system did not.
The Department agrees with the recommendation. The Center for Accounting (CFA) and Office of Transportation Safety (OTS) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing procedures relating to the tracking of subawards made to subrecipients and their status. OTS will modify their listings of subawards by program to include all amendments and new subawards and update it monthly. CFA will review the listing to ensure the accuracy of reporting submittals. The listing of subawards will be reconciled monthly. In addition, the FSRS system for FFATA reporting will be replaced with SAM.gov in Spring 2025. The new system includes improvements which will allow for more accurate tracking, and modifications to prior entries to support reconciliation which the prior system did not.
Finding 2024-057 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Formula Grants for Rural Areas and Tribal Transit Program The objectives of the federal Formula Grants for Rural Areas and Tribal Transit Program (Program) [ALN 20.509] are to initiate, improve, or continue public transportation service in rural areas by providing financial assistance for operating expenses, planning, and administrative expenses; and the acquisition, construction, and improvement of facilities and equipment. The Program is authorized by 49 U.S. Code Section 5311; specifically, 49 U.S. Code Section 5311(f) provides for the support of rural intercity bus service. As a grant recipient of funds under the Program, the Department is responsible for monitoring Program costs and activities for allowability, specifically to ensure that costs incurred and activities funded by the Program are permitted under the Program’s federal regulations and the Department’s grant agreements for the Program. The Program’s allowable activities, as identified in the U.S. Code, generally include the following: • Local transportation service in a rural area. • Support of intercity bus transportation. • Coordination of public transportation with transportation service assisted by other U.S. government sources. • Planning activities for the needs of rural areas, operating costs of equipment and facilities for the use in rural areas public transportation, and rural areas public transportation capital projects. • Job access and reverse commute projects, and the acquisition of public transportation services, including service agreements with private providers of public transportation. • Training, technical assistance, research, and related support services for providers of rural public transit and related services. The Department receives federal grant funds directly from the federal government for the Program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or vendor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A vendor, or contractor, is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The Department has established controls that require management and/or supervisory level approvals on all invoices before they are paid. The Department’s project managers and business management review invoices and reimbursement requests to ensure expenditures are allowable. The Division of Transit and Rail within the Department is responsible for reviewing all invoices associated with the Program. For the Fiscal Year 2024, the Program had general disbursement expenditures of $554,550, which was made up of 87 transactions, and subrecipient expenditures of $23,075,270, which was made up of 1,061 subrecipient transactions. General disbursement transactions include payments or costs incurred for the Program that do not meet the definition of any of the other cost categories, such as equipment and real property purchases, loan distributions, indirect costs, payments to program participants, or subrecipient payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over federal allowable activities and allowable cost requirements for the Program, and to determine whether the Department complied with the federal requirements during Fiscal Year 2024. As part of our audit work, we randomly selected 40 cash disbursements, which included 11 general disbursement transactions and 29 subrecipient transactions. We reviewed the related supporting documentation provided by the Department for allowability and evidence of internal controls related to expenditure approvals. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.403] requires that costs under federal awards must be necessary, reasonable, and allocable, conform to limitations, be consistent with policies, receive consistent treatment, adhere to Generally Accepted Accounting Principles, not be used for cost sharing of other programs, and be adequately documented. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice or purchase order, included with the transaction and the supporting documentation must be reviewed for allowability under the applicable federal grant program by two individuals. Subrecipients must submit a reimbursement request and supporting documentation, such as invoices, purchase orders, and internal accounting documents. Two Department personnel are required to review and approve the reimbursement requests and supporting documents before the reimbursement is paid. What problems did the audit work identify? Based on our audit testwork, we determined the Department did not ensure that costs charged to the grant were allowable. Specifically, we identified errors in 2 of the 40 samples (5 percent) selected as discussed in the following section: • In 1 of 40 cash disbursements selected for testing (3 percent), we found that the Department did not pay a vendor’s monthly invoice in a timely manner and ultimately made an erroneous duplicate payment to the vendor. Specifically, after the Department failed to initially pay the vendor invoice totaling $3,012, the vendor submitted an invoice in the following month that included the current and prior months’ unpaid expenses. The Department then inappropriately paid the vendor for the amounts listed on both invoices. This resulted in a net overpayment and questioned costs of $3,012. • In 1 of 40 cash disbursements selected for testing (3 percent), we found that the Department made a payment to a subrecipient before it received adequate supporting documentation for the amount requested. Specifically, the Department did not receive proof of purchase or backup for $15,549 in purchased transit service expenses. This resulted in questioned costs of $15,549. Why did these problems occur? The Department’s internal controls were not sufficient to ensure that invoices were reviewed for appropriate supporting documentation and approved prior to issuance of the related payment. In addition, the overpayment of expenses occurred in part due to the Department’s failure to pay the vendor invoice in a timely manner; the Department’s policies in place did not provide proper guidance to staff for how to treat payment of invoices that were late or when an invoice received included unpaid charges from a prior invoice and time period. Additionally, the Department’s review process did not properly identify the overpayment or the lack of supporting documentation. Why do these problems matter? As the Department is responsible for ensuring that all expenditures charged to the Program are appropriately supported, it is essential for the Department to ensure that all expenditures charged to the Program have the appropriate supporting documents and that payments are accurately calculated based on invoices received. The overpayment of expenses and improper payment of unsupported subrecipient payments resulted in unallowable costs being charged to the Program. Ultimately, the federal government may disallow federal funds for inappropriate payments, including overpayments, and the Department would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-057 The Department of Transportation (Department) should improve its internal controls for the Formula Grants for Rural Areas and Tribal Transit Program (Program) to ensure that costs charged to this Program are allowable. This should include: A. Implementing policies and procedures regarding the Program’s payment processing to ensure that, prior to charging expenditures to the Program, the expenditures and any related invoices are reviewed for appropriateness and adequate supporting documentation. In circumstances where such supporting documentation is missing, payment should not be made. B. Ensuring staff are appropriately trained to follow current procedures to ensure the Department pays the current balance of monthly invoices and not any prior amounts. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and the Division of Transit and Rail (DTR) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing policies and procedures related to payment processing, with a specific focus on transit payments. Additionally, the Department will also assess the need for additional training and/or other resources (i.e. review checklists) to improve compliance with payment processing policies and procedures. The CFA and the Headquarters Business Office will provide guidance and training to appropriate staff, including the DTR Operations Team to ensure that current invoices are being paid and if proper supporting documentation is not submitted the payment will not be made. B. Agree Implementation Date: June 2024 The Department agrees with the recommendation and will review, assess, and update, where necessary, existing policies and procedures related to payment processing to improve duplicate payment controls. The Center for Accounting and the Headquarters Business Office will provide guidance and training to appropriate staff, including the DTR Operations Team. Current controls on duplicate payments include a review of the invoice number and amounts compared to prior payments in the system to verify that the payment has not already been made. The CFA and the Headquarters Business Office will provide guidance and training to the responsible staff members to follow the current desk procedure specifically on paying the current invoice. Additionally, the department utilizes the Diligent platform of analytics to identify potential duplicate payments and to prevent fraud. The duplicate payment analytic identifies possible duplicates to the same vendor for the same amount. Any identified duplicates are reported to the Director of Accounting and Controller for further investigation. These items are investigated on a monthly basis and handled accordingly.
Show full finding ▾Hide full finding ▴Finding 2024-057 Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles for Formula Grants for Rural Areas and Tribal Transit Program The objectives of the federal Formula Grants for Rural Areas and Tribal Transit Program (Program) [ALN 20.509] are to initiate, improve, or continue public transportation service in rural areas by providing financial assistance for operating expenses, planning, and administrative expenses; and the acquisition, construction, and improvement of facilities and equipment. The Program is authorized by 49 U.S. Code Section 5311; specifically, 49 U.S. Code Section 5311(f) provides for the support of rural intercity bus service. As a grant recipient of funds under the Program, the Department is responsible for monitoring Program costs and activities for allowability, specifically to ensure that costs incurred and activities funded by the Program are permitted under the Program’s federal regulations and the Department’s grant agreements for the Program. The Program’s allowable activities, as identified in the U.S. Code, generally include the following: • Local transportation service in a rural area. • Support of intercity bus transportation. • Coordination of public transportation with transportation service assisted by other U.S. government sources. • Planning activities for the needs of rural areas, operating costs of equipment and facilities for the use in rural areas public transportation, and rural areas public transportation capital projects. • Job access and reverse commute projects, and the acquisition of public transportation services, including service agreements with private providers of public transportation. • Training, technical assistance, research, and related support services for providers of rural public transit and related services. The Department receives federal grant funds directly from the federal government for the Program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or vendor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A vendor, or contractor, is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The Department has established controls that require management and/or supervisory level approvals on all invoices before they are paid. The Department’s project managers and business management review invoices and reimbursement requests to ensure expenditures are allowable. The Division of Transit and Rail within the Department is responsible for reviewing all invoices associated with the Program. For the Fiscal Year 2024, the Program had general disbursement expenditures of $554,550, which was made up of 87 transactions, and subrecipient expenditures of $23,075,270, which was made up of 1,061 subrecipient transactions. General disbursement transactions include payments or costs incurred for the Program that do not meet the definition of any of the other cost categories, such as equipment and real property purchases, loan distributions, indirect costs, payments to program participants, or subrecipient payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over federal allowable activities and allowable cost requirements for the Program, and to determine whether the Department complied with the federal requirements during Fiscal Year 2024. As part of our audit work, we randomly selected 40 cash disbursements, which included 11 general disbursement transactions and 29 subrecipient transactions. We reviewed the related supporting documentation provided by the Department for allowability and evidence of internal controls related to expenditure approvals. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the Department must “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.403] requires that costs under federal awards must be necessary, reasonable, and allocable, conform to limitations, be consistent with policies, receive consistent treatment, adhere to Generally Accepted Accounting Principles, not be used for cost sharing of other programs, and be adequately documented. • The Department’s internal control procedures require that all federal grant expenditures must have adequate supporting documentation, such as an invoice or purchase order, included with the transaction and the supporting documentation must be reviewed for allowability under the applicable federal grant program by two individuals. Subrecipients must submit a reimbursement request and supporting documentation, such as invoices, purchase orders, and internal accounting documents. Two Department personnel are required to review and approve the reimbursement requests and supporting documents before the reimbursement is paid. What problems did the audit work identify? Based on our audit testwork, we determined the Department did not ensure that costs charged to the grant were allowable. Specifically, we identified errors in 2 of the 40 samples (5 percent) selected as discussed in the following section: • In 1 of 40 cash disbursements selected for testing (3 percent), we found that the Department did not pay a vendor’s monthly invoice in a timely manner and ultimately made an erroneous duplicate payment to the vendor. Specifically, after the Department failed to initially pay the vendor invoice totaling $3,012, the vendor submitted an invoice in the following month that included the current and prior months’ unpaid expenses. The Department then inappropriately paid the vendor for the amounts listed on both invoices. This resulted in a net overpayment and questioned costs of $3,012. • In 1 of 40 cash disbursements selected for testing (3 percent), we found that the Department made a payment to a subrecipient before it received adequate supporting documentation for the amount requested. Specifically, the Department did not receive proof of purchase or backup for $15,549 in purchased transit service expenses. This resulted in questioned costs of $15,549. Why did these problems occur? The Department’s internal controls were not sufficient to ensure that invoices were reviewed for appropriate supporting documentation and approved prior to issuance of the related payment. In addition, the overpayment of expenses occurred in part due to the Department’s failure to pay the vendor invoice in a timely manner; the Department’s policies in place did not provide proper guidance to staff for how to treat payment of invoices that were late or when an invoice received included unpaid charges from a prior invoice and time period. Additionally, the Department’s review process did not properly identify the overpayment or the lack of supporting documentation. Why do these problems matter? As the Department is responsible for ensuring that all expenditures charged to the Program are appropriately supported, it is essential for the Department to ensure that all expenditures charged to the Program have the appropriate supporting documents and that payments are accurately calculated based on invoices received. The overpayment of expenses and improper payment of unsupported subrecipient payments resulted in unallowable costs being charged to the Program. Ultimately, the federal government may disallow federal funds for inappropriate payments, including overpayments, and the Department would be required to bear the cost of these errors. See Schedule of Finding and Questioned Costs for chart/table. Recommendation 2024-057 The Department of Transportation (Department) should improve its internal controls for the Formula Grants for Rural Areas and Tribal Transit Program (Program) to ensure that costs charged to this Program are allowable. This should include: A. Implementing policies and procedures regarding the Program’s payment processing to ensure that, prior to charging expenditures to the Program, the expenditures and any related invoices are reviewed for appropriateness and adequate supporting documentation. In circumstances where such supporting documentation is missing, payment should not be made. B. Ensuring staff are appropriately trained to follow current procedures to ensure the Department pays the current balance of monthly invoices and not any prior amounts. Response Department of Transportation A. Agree Implementation Date: June 2025 The Department agrees with the recommendation. The Center for Accounting (CFA) and the Division of Transit and Rail (DTR) will coordinate on implementation. The Department will review, assess, and, where necessary, update existing policies and procedures related to payment processing, with a specific focus on transit payments. Additionally, the Department will also assess the need for additional training and/or other resources (i.e. review checklists) to improve compliance with payment processing policies and procedures. The CFA and the Headquarters Business Office will provide guidance and training to appropriate staff, including the DTR Operations Team to ensure that current invoices are being paid and if proper supporting documentation is not submitted the payment will not be made. B. Agree Implementation Date: June 2024 The Department agrees with the recommendation and will review, assess, and update, where necessary, existing policies and procedures related to payment processing to improve duplicate payment controls. The Center for Accounting and the Headquarters Business Office will provide guidance and training to appropriate staff, including the DTR Operations Team. Current controls on duplicate payments include a review of the invoice number and amounts compared to prior payments in the system to verify that the payment has not already been made. The CFA and the Headquarters Business Office will provide guidance and training to the responsible staff members to follow the current desk procedure specifically on paying the current invoice. Additionally, the department utilizes the Diligent platform of analytics to identify potential duplicate payments and to prevent fraud. The duplicate payment analytic identifies possible duplicates to the same vendor for the same amount. Any identified duplicates are reported to the Director of Accounting and Controller for further investigation. These items are investigated on a monthly basis and handled accordingly.
The Department agrees with the recommendation and will review, assess, and update, where necessary, existing policies and procedures related to payment processing to improve duplicate payment controls. The Center for Accounting and the Headquarters Business Office will provide guidance and training to appropriate staff, including the DTR Operations Team. Current controls on duplicate payments include a review of the invoice number and amounts compared to prior payments in the system to verify that the payment has not already been made. The CFA and the Headquarters Business Office will provide guidance and training to the responsible staff members to follow the current desk procedure specifically on paying the current invoice. Additionally, the department utilizes the Diligent platform of analytics to identify potential duplicate payments and to prevent fraud. The duplicate payment analytic identifies possible duplicates to the same vendor for the same amount. Any identified duplicates are reported to the Director of Accounting and Controller for further investigation. These items are investigated on a monthly basis and handled accordingly.
Finding 2024-058 Compliance with Subrecipient Monitoring for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and SLFRF The Department receives federal grant funds directly from the federal government for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. For Fiscal Year 2024, the Department had the following transactions that were subject to subrecipient monitoring testing: • Formula Grants for Rural Areas and Tribal Transit Program – 783 subrecipient transactions totaling $23,075,270. • Highway Safety Cluster – 829 subrecipient transactions totaling $5,669,865. • SLFRF – 232 subrecipient transactions totaling $38,321,493. For the SLFRF program, Intergovernmental Agreements are executed between the Department and subrecipients to communicate all relevant federal award information. For both the Formula Grants for Rural Areas and Tribal Transit Program and Highway Safety Cluster, Subaward Agreements (subawards) are executed between the Department and subrecipients to communicate all relevant federal award information. Intergovernmental Agreements and subawards are signed by authorized State personnel, generally the State Controller and the Department’s Chief Engineer. The Department includes a “Subrecipient Risk Assessment” tool with its Intergovernmental Agreements or subawards, which must be completed by Department staff prior to making the award. The Department’s subrecipient monitoring procedures are dependent on the assessed risk level noted in the Subrecipient Risk Assessment tool. Federal regulations [2 CFR Part 200 Section F] state that a non-federal entity that expends $1,000,000 or more in federal awards during the non-federal entity’s fiscal year must have a Single Audit conducted in accordance with 2 CFR 200.514. The Department’s Internal Audit Division staff tracks and receives Single Audit reports from its subrecipients. As part of the Department’s monitoring procedures, the Internal Audit Division personnel complete a “Single Audit Report Review Summary” form to show they reviewed the subrecipient’s Single Audit report, summarized any findings, and concluded on any risks presented to the Department and any related future actions to be taken. The form is signed by a Department preparer and a Department reviewer. For those subrecipients not required to file a Single Audit, an “Audit Division Single Audit Certification Form” must still be submitted by the subrecipients to the Department. These forms note that the entity was exempt from a Single Audit. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine if the Department complied with federal requirements for subrecipient monitoring during Fiscal Year 2024 for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the SLFRF program and to determine whether the Department had adequate internal controls over subrecipient monitoring. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring and tested the Department’s compliance with federal subrecipient monitoring requirements. Specifically, we performed the following testwork related to each of the following federal programs: • Formula Grants for Rural Areas and Tribal Transit Program—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • Highway Safety Cluster—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • SLFRF—We selected and reviewed a random sample of 29 subrecipient payment transactions. We reviewed Intergovernmental Agreements, amendments, and other supporting documentation provided by the Department. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the ALN, the Federal Award Date, and the FAIN. • Federal regulation [2 CFR 200.331] states that a pass-through entity, in this case the Department, must make case-by-case determinations as to whether each agreement it makes for the disbursement of federal program funds represents a payment of funds to a subrecipient or a contractor, depending on the role the entity plays. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements during Fiscal Year 2024. Specifically, we noted the following: • Formula Grants for Rural Areas and Tribal Transit Program o For 10 of 40 (25 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement, as required. The 10 transactions totaled $7,432,248 in subrecipient awards. • Highway Safety Cluster o For 1 of 40 (3 percent) subrecipient payment transactions selected for testing, we determined that the subrecipient should have been classified as a contractor, not a subrecipient. The transaction totaled $75,325. The Department had not made an adjusting entry in CORE to reclassify the transaction and correct this error by the end of our audit testwork. o For 5 of 40 (13 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement. The 5 transactions totaled $25,100 in subrecipient awards. • SLFRF o For 2 of 29 (7 percent) subrecipient payment transactions selected for testing, we determined that the Intergovernmental Agreement did not include the FAIN and Federal Award Dates. The 2 transactions totaled $3,277,779 in subrecipient awards. o For 1 of 29 (3 percent) subrecipient payment transactions selected for testing, we determined the transaction did not include the ALN. This transaction totaled $1,851,279 in subrecipient awards. Why did these problems occur? The Department’s procedures and internal controls were not sufficient to ensure that Intergovernmental Agreements and subawards included all the required information to be included in the subaward, and internal controls did not prevent or detect errors. Department staff were not aware that this information was needed for the subaward to be in compliance with federal regulations. In some situations, the FAIN was only provided to the Department from the U.S. Department of Transportation subsequent to when the subaward was made. In these instances, the Department was not aware that they were required to provide the FAIN to their subrecipients once it was determined by the U.S. Department of Transportation. The Department’s procedures and internal controls were not sufficient to ensure that payments were properly classified as general disbursements or subrecipient payments, and internal controls did not prevent or detect errors. Department staff lacked the appropriate knowledge of the difference in contractors and subrecipients to ensure the proper classification of expenditures. The Department’s reviewers did not complete a sufficient review of the expense classifications to be able to identify the misclassification and propose a subsequent correction. Why do these problems matter? Based on the issues we identified, the Department is out of compliance with federal subrecipient requirements and could face sanctions or other penalties. In addition, by failing to properly report the required federal grant award information at the time of subaward issuance, subrecipients may be uninformed about what funding the subaward related to. This could result in misclassification of subaward information on the subrecipients’ Schedules of Expenditures of Federal Awards (SEFA) and the subrecipient may not know what federal requirements they need to follow as part of receiving the federal award funds. The Department’s improper classification of expenses as general disbursements versus subrecipient payments could lead to misstatements in the amounts reported on the SEFA, both for the State as a whole and at the subrecipient level. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-058 The Department of Transportation (Department) should strengthen its internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Formula Grants for Rural Areas and Tribal Transit Program, the Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds. Specifically, the Department should ensure that all required information is included in subawards or intergovernmental agreements or provide amendments to the subawards or intergovernmental once the Department receives the necessary information from the federal government, and that Department staff are sufficiently aware of the difference in subrecipients and contractors and properly classify general disbursements versus subrecipient payments. Response Department of Transportation Agree Implementation Date: June 2026 Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
Show full finding ▾Hide full finding ▴Finding 2024-058 Compliance with Subrecipient Monitoring for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and SLFRF The Department receives federal grant funds directly from the federal government for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. For Fiscal Year 2024, the Department had the following transactions that were subject to subrecipient monitoring testing: • Formula Grants for Rural Areas and Tribal Transit Program – 783 subrecipient transactions totaling $23,075,270. • Highway Safety Cluster – 829 subrecipient transactions totaling $5,669,865. • SLFRF – 232 subrecipient transactions totaling $38,321,493. For the SLFRF program, Intergovernmental Agreements are executed between the Department and subrecipients to communicate all relevant federal award information. For both the Formula Grants for Rural Areas and Tribal Transit Program and Highway Safety Cluster, Subaward Agreements (subawards) are executed between the Department and subrecipients to communicate all relevant federal award information. Intergovernmental Agreements and subawards are signed by authorized State personnel, generally the State Controller and the Department’s Chief Engineer. The Department includes a “Subrecipient Risk Assessment” tool with its Intergovernmental Agreements or subawards, which must be completed by Department staff prior to making the award. The Department’s subrecipient monitoring procedures are dependent on the assessed risk level noted in the Subrecipient Risk Assessment tool. Federal regulations [2 CFR Part 200 Section F] state that a non-federal entity that expends $1,000,000 or more in federal awards during the non-federal entity’s fiscal year must have a Single Audit conducted in accordance with 2 CFR 200.514. The Department’s Internal Audit Division staff tracks and receives Single Audit reports from its subrecipients. As part of the Department’s monitoring procedures, the Internal Audit Division personnel complete a “Single Audit Report Review Summary” form to show they reviewed the subrecipient’s Single Audit report, summarized any findings, and concluded on any risks presented to the Department and any related future actions to be taken. The form is signed by a Department preparer and a Department reviewer. For those subrecipients not required to file a Single Audit, an “Audit Division Single Audit Certification Form” must still be submitted by the subrecipients to the Department. These forms note that the entity was exempt from a Single Audit. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine if the Department complied with federal requirements for subrecipient monitoring during Fiscal Year 2024 for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the SLFRF program and to determine whether the Department had adequate internal controls over subrecipient monitoring. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring and tested the Department’s compliance with federal subrecipient monitoring requirements. Specifically, we performed the following testwork related to each of the following federal programs: • Formula Grants for Rural Areas and Tribal Transit Program—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • Highway Safety Cluster—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • SLFRF—We selected and reviewed a random sample of 29 subrecipient payment transactions. We reviewed Intergovernmental Agreements, amendments, and other supporting documentation provided by the Department. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the ALN, the Federal Award Date, and the FAIN. • Federal regulation [2 CFR 200.331] states that a pass-through entity, in this case the Department, must make case-by-case determinations as to whether each agreement it makes for the disbursement of federal program funds represents a payment of funds to a subrecipient or a contractor, depending on the role the entity plays. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements during Fiscal Year 2024. Specifically, we noted the following: • Formula Grants for Rural Areas and Tribal Transit Program o For 10 of 40 (25 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement, as required. The 10 transactions totaled $7,432,248 in subrecipient awards. • Highway Safety Cluster o For 1 of 40 (3 percent) subrecipient payment transactions selected for testing, we determined that the subrecipient should have been classified as a contractor, not a subrecipient. The transaction totaled $75,325. The Department had not made an adjusting entry in CORE to reclassify the transaction and correct this error by the end of our audit testwork. o For 5 of 40 (13 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement. The 5 transactions totaled $25,100 in subrecipient awards. • SLFRF o For 2 of 29 (7 percent) subrecipient payment transactions selected for testing, we determined that the Intergovernmental Agreement did not include the FAIN and Federal Award Dates. The 2 transactions totaled $3,277,779 in subrecipient awards. o For 1 of 29 (3 percent) subrecipient payment transactions selected for testing, we determined the transaction did not include the ALN. This transaction totaled $1,851,279 in subrecipient awards. Why did these problems occur? The Department’s procedures and internal controls were not sufficient to ensure that Intergovernmental Agreements and subawards included all the required information to be included in the subaward, and internal controls did not prevent or detect errors. Department staff were not aware that this information was needed for the subaward to be in compliance with federal regulations. In some situations, the FAIN was only provided to the Department from the U.S. Department of Transportation subsequent to when the subaward was made. In these instances, the Department was not aware that they were required to provide the FAIN to their subrecipients once it was determined by the U.S. Department of Transportation. The Department’s procedures and internal controls were not sufficient to ensure that payments were properly classified as general disbursements or subrecipient payments, and internal controls did not prevent or detect errors. Department staff lacked the appropriate knowledge of the difference in contractors and subrecipients to ensure the proper classification of expenditures. The Department’s reviewers did not complete a sufficient review of the expense classifications to be able to identify the misclassification and propose a subsequent correction. Why do these problems matter? Based on the issues we identified, the Department is out of compliance with federal subrecipient requirements and could face sanctions or other penalties. In addition, by failing to properly report the required federal grant award information at the time of subaward issuance, subrecipients may be uninformed about what funding the subaward related to. This could result in misclassification of subaward information on the subrecipients’ Schedules of Expenditures of Federal Awards (SEFA) and the subrecipient may not know what federal requirements they need to follow as part of receiving the federal award funds. The Department’s improper classification of expenses as general disbursements versus subrecipient payments could lead to misstatements in the amounts reported on the SEFA, both for the State as a whole and at the subrecipient level. See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2024-058 The Department of Transportation (Department) should strengthen its internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Formula Grants for Rural Areas and Tribal Transit Program, the Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds. Specifically, the Department should ensure that all required information is included in subawards or intergovernmental agreements or provide amendments to the subawards or intergovernmental once the Department receives the necessary information from the federal government, and that Department staff are sufficiently aware of the difference in subrecipients and contractors and properly classify general disbursements versus subrecipient payments. Response Department of Transportation Agree Implementation Date: June 2026 Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.
The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to Treasury in the previous year and has not been remediated as of June 30, 2024 because the original implementation dates provided by Treasury were in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-081 Minerals Leasing Act—Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state’s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Minerals Leasing Act Program (Program) funds to Treasury, which passes through Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments may use Program funds for “…planning; construction and maintenance of public facilities; and provision of public services.” During Fiscal Year 2023, ONRR distributed approximately $173.0 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $68.9 million of the $72.3 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.4 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2023. As part of our testing, we reviewed Treasury’s progress in implementing our Fiscal Year 2022 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. As a result of our testwork, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, and dollar amount made available to subrecipients, and the related federal requirements. As part of our testing, we conducted interviews with Treasury staff regarding its process over the monitoring of Program funds during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. The Minerals Leasing Act of 1920, as amended in 1976, states that Program funds should be provided to those subdivisions socially or economically impacted by the development of minerals leased for planning, construction, and maintenance of public facilities. Federal regulations [2 CFR 200.331] require a pass-through entity to make case-by-case determinations regarding whether each agreement it makes for the disbursement of federal program funds casts the party receiving the funds in the role of a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The following paragraphs detail requirements for subrecipients. Federal regulations [2 CFR 200.332 (a)(1)(2) and (3)] require that Treasury, as the primary recipient of Program funds, ensure that every pass-through of federal funds it makes clearly identify all requirements that Treasury imposed on the subrecipient so that the federal award is used in accordance with federal statutes, regulations, and the terms and conditions of the award, as well as specify any additional requirements that Treasury imposes on the subrecipient in order for Treasury to meet its own responsibility for the federal award (e.g., financial, performance, and special reports). In addition, regulations require that Treasury, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury, or DOLA, provides specific information about the Program to the subrecipients, including, but not limited to, the following: • Assistance Listing Number • Name of the program, name of the federal awarding agency, and name of the department awarding the Program funds • Contact information for Treasury • Dollar amount made available to the subrecipient • Reporting requirements Federal regulation [2 CFR 200.332(b)] requires that Treasury, as the primary recipient of Program funds, ensure DOLA staff conducts risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the Treasury should ensure that DOLA staff use the risk assessments to determine the appropriate level of subrecipient monitoring that DOLA staff should perform on each subrecipient. Specifically, federal regulations [2 CFR 200.332(d)-(e)] require that Treasury, as the primary recipient of Program funds, ensure that DOLA staff monitor the subrecipient activities as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: • Reviewing financial performance reports. • Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. • Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity’s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulation [2 CFR 200.332(f)] require that Treasury, as the primary recipient of the Program funds, ensure or communicate to DOLA that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFA and, if applicable, undergo a Single Audit. The Exhibit K1, Schedule of Federal Assistance, is used by the State’s departments and institutions of higher education to report federal expenditure information to the Office of the State Controller (OSC) to aid the OSC in preparing the State’s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the various Exhibits in preparing the SEFA each year. What problems did the audit work identify? We found that Treasury did not implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2023. Specifically, we identified the following: • Treasury reported that DOLA did not perform a subrecipient versus contractor determination to ensure proper compliance with the subaward requirement and reporting of information to Treasury for its federal reporting. • Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury staff reported that they continue working with DOLA to ensure that required information is communicated to all subrecipients in compliance with state and federal regulations. In addition, Treasury reported that they are working with the Attorney General’s Office toward the implementation of an interagency agreement that will establish expectations for DOLA. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. • Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, Treasury did not ensure that DOLA used the risk assessments to determine the appropriate level of subrecipient monitoring on each subrecipient. • Treasury did not have a process in place to ensure that DOLA monitors the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. • Further, Treasury, as the primary recipient of Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2023 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. Why did these problems occur? Overall, Treasury did not have adequate internal controls in place during Fiscal Year 2023 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff indicated that DOLA determined during Fiscal Year 2023 that it does not have any Program subrecipients, but Treasury did not obtain and review any subrecipient versus contractor determinations from DOLA to verify the appropriateness of the determinations. Alternatively, Treasury did not perform its own assessment of subrecipient versus contractor status for the Program payments or obtain clarification from the Attorney General, as necessary, regarding the determination. Treasury also did not have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds—including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2023 were required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In addition, Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. Neither Treasury or DOLA monitored the activities of the subrecipients, as necessary, to ensure that the subawards are used for authorized purposes, comply with the terms and conditions of the subawards, and achieve performance goals. Why do these problems matter? The subrecipient versus contractor determinations help Treasury or DOLA to assess specific federal requirements that have to be followed, and ensure the proper reporting on Treasury’s Exhibit K1. Because the OSC uses the Exhibit K1 to prepare the State’s SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds that Treasury pays annually to its subrecipients. By continuing to fail to fulfill the Program’s subrecipient monitoring requirements, Treasury, and the State as a whole, are out of compliance with the provisions of Program awards. Ultimately, insufficient monitoring of Program subrecipients could result in future federal funding being reduced. If Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could result in local governments not undergoing Single Audits, as required. Further, without evaluating its subrecipients’ risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, Treasury does not have assurance that it appropriately monitors its subrecipients and identifies issues. Recommendation 2023-081 The Department of Treasury (Treasury) should strengthen its internal controls related to, and ensure it complies with, federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act Program (Program) by: A. Requiring other State agencies, including the Department of Local Affairs, to whom Treasury subgrants Program funds, to perform subrecipient versus contractor determinations to identify Program subrecipients and to perform appropriate subrecipient monitoring procedures. As needed, this should include obtaining clarification from the Attorney General as to whether parties to whom Treasury or its subgrantor state agencies send Program funds are subrecipients or vendors. B. Ensuring that it reports Program funds properly on its Exhibit K1, Schedule of Federal Assistance, including that expenditures are accurately presented as direct or pass-through subrecipient expenditures. C. Developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount, are made available to the subrecipient, the related federal requirements are communicated to Program subrecipients, and the subrecipients report the funds on their respective annual Schedule of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. This should include communicating all requirements imposed by the grantor agency on the subrecipient so Program funds are used in accordance with federal statutes, regulations, and the terms and conditions of the subaward, and that Treasury meets its own responsibility for the federal award. D. Developing an effective monitoring process to ensure risk assessments of subrecipients and monitoring of subrecipients are performed. Response Department of the Treasury A. Agree Implementation Date: December 2026 Treasury has been working with the Department of Local Affairs (DOLA) on a pilot program for monitoring and compliance of fund recipients and was in the process of instituting an Interagency Agreement with DOLA on this matter. Treasury will pursue further guidance from the Attorney General's office on federal rules interpretation regarding subrecipients. Treasury plans to continue to work with DOLA to aid in determining what financial resources and FTE may be necessary to ensure monitoring and compliance is successful. B. Agree Implementation Date: December 2026 The Department will seek guidance from the Attorney General's Office regarding federal rules interpretation to ensure distributions are properly identified. DOLA distributes the funds once received from Treasury, and therefore Treasury will work with DOLA as well to ensure there is agreement on subrecipient identification. C. and D. Agree Implementation Date: December 2026 As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to Treasury in the previous year and has not been remediated as of June 30, 2024 because the original implementation dates provided by Treasury were in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2023-081 Minerals Leasing Act—Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state’s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Minerals Leasing Act Program (Program) funds to Treasury, which passes through Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments may use Program funds for “…planning; construction and maintenance of public facilities; and provision of public services.” During Fiscal Year 2023, ONRR distributed approximately $173.0 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $68.9 million of the $72.3 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.4 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2023. As part of our testing, we reviewed Treasury’s progress in implementing our Fiscal Year 2022 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. As a result of our testwork, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, and dollar amount made available to subrecipients, and the related federal requirements. As part of our testing, we conducted interviews with Treasury staff regarding its process over the monitoring of Program funds during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. The Minerals Leasing Act of 1920, as amended in 1976, states that Program funds should be provided to those subdivisions socially or economically impacted by the development of minerals leased for planning, construction, and maintenance of public facilities. Federal regulations [2 CFR 200.331] require a pass-through entity to make case-by-case determinations regarding whether each agreement it makes for the disbursement of federal program funds casts the party receiving the funds in the role of a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The following paragraphs detail requirements for subrecipients. Federal regulations [2 CFR 200.332 (a)(1)(2) and (3)] require that Treasury, as the primary recipient of Program funds, ensure that every pass-through of federal funds it makes clearly identify all requirements that Treasury imposed on the subrecipient so that the federal award is used in accordance with federal statutes, regulations, and the terms and conditions of the award, as well as specify any additional requirements that Treasury imposes on the subrecipient in order for Treasury to meet its own responsibility for the federal award (e.g., financial, performance, and special reports). In addition, regulations require that Treasury, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury, or DOLA, provides specific information about the Program to the subrecipients, including, but not limited to, the following: • Assistance Listing Number • Name of the program, name of the federal awarding agency, and name of the department awarding the Program funds • Contact information for Treasury • Dollar amount made available to the subrecipient • Reporting requirements Federal regulation [2 CFR 200.332(b)] requires that Treasury, as the primary recipient of Program funds, ensure DOLA staff conducts risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the Treasury should ensure that DOLA staff use the risk assessments to determine the appropriate level of subrecipient monitoring that DOLA staff should perform on each subrecipient. Specifically, federal regulations [2 CFR 200.332(d)-(e)] require that Treasury, as the primary recipient of Program funds, ensure that DOLA staff monitor the subrecipient activities as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: • Reviewing financial performance reports. • Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. • Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity’s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulation [2 CFR 200.332(f)] require that Treasury, as the primary recipient of the Program funds, ensure or communicate to DOLA that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFA and, if applicable, undergo a Single Audit. The Exhibit K1, Schedule of Federal Assistance, is used by the State’s departments and institutions of higher education to report federal expenditure information to the Office of the State Controller (OSC) to aid the OSC in preparing the State’s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the various Exhibits in preparing the SEFA each year. What problems did the audit work identify? We found that Treasury did not implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2023. Specifically, we identified the following: • Treasury reported that DOLA did not perform a subrecipient versus contractor determination to ensure proper compliance with the subaward requirement and reporting of information to Treasury for its federal reporting. • Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury staff reported that they continue working with DOLA to ensure that required information is communicated to all subrecipients in compliance with state and federal regulations. In addition, Treasury reported that they are working with the Attorney General’s Office toward the implementation of an interagency agreement that will establish expectations for DOLA. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. • Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, Treasury did not ensure that DOLA used the risk assessments to determine the appropriate level of subrecipient monitoring on each subrecipient. • Treasury did not have a process in place to ensure that DOLA monitors the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. • Further, Treasury, as the primary recipient of Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2023 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. Why did these problems occur? Overall, Treasury did not have adequate internal controls in place during Fiscal Year 2023 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff indicated that DOLA determined during Fiscal Year 2023 that it does not have any Program subrecipients, but Treasury did not obtain and review any subrecipient versus contractor determinations from DOLA to verify the appropriateness of the determinations. Alternatively, Treasury did not perform its own assessment of subrecipient versus contractor status for the Program payments or obtain clarification from the Attorney General, as necessary, regarding the determination. Treasury also did not have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds—including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2023 were required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In addition, Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. Neither Treasury or DOLA monitored the activities of the subrecipients, as necessary, to ensure that the subawards are used for authorized purposes, comply with the terms and conditions of the subawards, and achieve performance goals. Why do these problems matter? The subrecipient versus contractor determinations help Treasury or DOLA to assess specific federal requirements that have to be followed, and ensure the proper reporting on Treasury’s Exhibit K1. Because the OSC uses the Exhibit K1 to prepare the State’s SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds that Treasury pays annually to its subrecipients. By continuing to fail to fulfill the Program’s subrecipient monitoring requirements, Treasury, and the State as a whole, are out of compliance with the provisions of Program awards. Ultimately, insufficient monitoring of Program subrecipients could result in future federal funding being reduced. If Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could result in local governments not undergoing Single Audits, as required. Further, without evaluating its subrecipients’ risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, Treasury does not have assurance that it appropriately monitors its subrecipients and identifies issues. Recommendation 2023-081 The Department of Treasury (Treasury) should strengthen its internal controls related to, and ensure it complies with, federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act Program (Program) by: A. Requiring other State agencies, including the Department of Local Affairs, to whom Treasury subgrants Program funds, to perform subrecipient versus contractor determinations to identify Program subrecipients and to perform appropriate subrecipient monitoring procedures. As needed, this should include obtaining clarification from the Attorney General as to whether parties to whom Treasury or its subgrantor state agencies send Program funds are subrecipients or vendors. B. Ensuring that it reports Program funds properly on its Exhibit K1, Schedule of Federal Assistance, including that expenditures are accurately presented as direct or pass-through subrecipient expenditures. C. Developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount, are made available to the subrecipient, the related federal requirements are communicated to Program subrecipients, and the subrecipients report the funds on their respective annual Schedule of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. This should include communicating all requirements imposed by the grantor agency on the subrecipient so Program funds are used in accordance with federal statutes, regulations, and the terms and conditions of the subaward, and that Treasury meets its own responsibility for the federal award. D. Developing an effective monitoring process to ensure risk assessments of subrecipients and monitoring of subrecipients are performed. Response Department of the Treasury A. Agree Implementation Date: December 2026 Treasury has been working with the Department of Local Affairs (DOLA) on a pilot program for monitoring and compliance of fund recipients and was in the process of instituting an Interagency Agreement with DOLA on this matter. Treasury will pursue further guidance from the Attorney General's office on federal rules interpretation regarding subrecipients. Treasury plans to continue to work with DOLA to aid in determining what financial resources and FTE may be necessary to ensure monitoring and compliance is successful. B. Agree Implementation Date: December 2026 The Department will seek guidance from the Attorney General's Office regarding federal rules interpretation to ensure distributions are properly identified. DOLA distributes the funds once received from Treasury, and therefore Treasury will work with DOLA as well to ensure there is agreement on subrecipient identification. C. and D. Agree Implementation Date: December 2026 As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
2023-081
FAC accepted this audit on March 22, 2024 — management decision was due September 22, 2024.
Finding 2023-049 Federal Funding Accountability and Transparency Act The federal Child Care and Development Fund Cluster (CCDF) [ALN 93.575, Child Care and Development Block Grant; and ALN 93.596, Child Care Mandatory and Matching Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents or adult caretakers of the children are working, or attending training or educational programs. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP). The Department is responsible for overseeing CCCAP and ensuring that it complies with the program’s requirements. CCCAP is administered at the local level by the county departments of human/social services, and the Department is responsible for monitoring the counties’ administration of CCCAP. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for CCDF. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department submitted 19 FFATA reports, totaling approximately $15.7 million for 15 subrecipients for the Child Care and Development Block Grant [ALN 93.575]. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the CCDF during Fiscal Year 2023. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting, the 19 FFATA reports submitted by the Department in Fiscal Year 2023, supporting documentation for the reports, and a list of all subawards made by the Department during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following: In accordance with federal regulation [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. Federal regulation [2 CFR 200.303] requires the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, the Department did not provide us with the subawards it awarded to its subrecipients, and we could not determine if the Department submitted all of the reports required for CCDF for Fiscal Year 2023. Additionally, while the Department provided supporting spreadsheets for the reports submitted, including dates each report was submitted, the Department did not provide evidence of that date, such as a screen shot in FSRS, or any other evidence to show, that the reports they did submit were made in a timely manner and in accordance with federal regulations. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did this problem occur? CCDF was previously administered by the Department of Human Services (DHS), and this is the first year that the Department was in charge of the program. According to the Department, DHS performed FFATA reporting for Fiscal Year 2023 for CCDF, and the Department could not obtain the subaward documents made to the subrecipients from DHS or evidence that the reports were submitted on time. CCDF staff reported that they are working to implement effective internal controls, including policies and procedures to ensure they maintain the appropriate documentation, to ensure compliance with FFATA requirements. Why does this problem matter? By failing to obtain and maintain appropriate documentation, the Department cannot demonstrate that it complied with federal requirements to properly report subawards to FSRS, and, therefore, risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-049 The Department of Early Childhood (Department) should implement internal controls for the Child Care and Development Fund Cluster by developing policies and procedures to ensure that it complies with requirements under the Federal Funding Accountability and Transparency Act. These procedures should include requirements to maintain supporting documentation, including evidence of timely submission and subaward documentation for awards made to subrecipients, as required. Response Department of Early Childhood Agree Implementation Date: March 2024 The Department of Early Childhood agrees with this recommendation. HB 21-1304, created the new state Department of Early Childhood beginning July 1, 2022. Previously, programs and services related to early childhood were primarily located in the Colorado Department of Human Services. The Department of Early Childhood has been transitioning out of the Colorado Department of Human Services and the operational support inter-agency agreement requiring CDHS to provide administrative support for CDEC, including Federal Funding Accountability and Transparency Act (FFATA) reporting, ended 12/31/23. CDEC is currently developing and implementing procedures to validate financial data used to compile FFATA reporting, this process will include steps to resolve identified discrepancies quickly to ensure that reports are submitted timely as required.
Show full finding ▾Hide full finding ▴Finding 2023-049 Federal Funding Accountability and Transparency Act The federal Child Care and Development Fund Cluster (CCDF) [ALN 93.575, Child Care and Development Block Grant; and ALN 93.596, Child Care Mandatory and Matching Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents or adult caretakers of the children are working, or attending training or educational programs. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP). The Department is responsible for overseeing CCCAP and ensuring that it complies with the program’s requirements. CCCAP is administered at the local level by the county departments of human/social services, and the Department is responsible for monitoring the counties’ administration of CCCAP. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for CCDF. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department submitted 19 FFATA reports, totaling approximately $15.7 million for 15 subrecipients for the Child Care and Development Block Grant [ALN 93.575]. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the CCDF during Fiscal Year 2023. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting, the 19 FFATA reports submitted by the Department in Fiscal Year 2023, supporting documentation for the reports, and a list of all subawards made by the Department during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following: In accordance with federal regulation [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. Federal regulation [2 CFR 200.303] requires the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, the Department did not provide us with the subawards it awarded to its subrecipients, and we could not determine if the Department submitted all of the reports required for CCDF for Fiscal Year 2023. Additionally, while the Department provided supporting spreadsheets for the reports submitted, including dates each report was submitted, the Department did not provide evidence of that date, such as a screen shot in FSRS, or any other evidence to show, that the reports they did submit were made in a timely manner and in accordance with federal regulations. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did this problem occur? CCDF was previously administered by the Department of Human Services (DHS), and this is the first year that the Department was in charge of the program. According to the Department, DHS performed FFATA reporting for Fiscal Year 2023 for CCDF, and the Department could not obtain the subaward documents made to the subrecipients from DHS or evidence that the reports were submitted on time. CCDF staff reported that they are working to implement effective internal controls, including policies and procedures to ensure they maintain the appropriate documentation, to ensure compliance with FFATA requirements. Why does this problem matter? By failing to obtain and maintain appropriate documentation, the Department cannot demonstrate that it complied with federal requirements to properly report subawards to FSRS, and, therefore, risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-049 The Department of Early Childhood (Department) should implement internal controls for the Child Care and Development Fund Cluster by developing policies and procedures to ensure that it complies with requirements under the Federal Funding Accountability and Transparency Act. These procedures should include requirements to maintain supporting documentation, including evidence of timely submission and subaward documentation for awards made to subrecipients, as required. Response Department of Early Childhood Agree Implementation Date: March 2024 The Department of Early Childhood agrees with this recommendation. HB 21-1304, created the new state Department of Early Childhood beginning July 1, 2022. Previously, programs and services related to early childhood were primarily located in the Colorado Department of Human Services. The Department of Early Childhood has been transitioning out of the Colorado Department of Human Services and the operational support inter-agency agreement requiring CDHS to provide administrative support for CDEC, including Federal Funding Accountability and Transparency Act (FFATA) reporting, ended 12/31/23. CDEC is currently developing and implementing procedures to validate financial data used to compile FFATA reporting, this process will include steps to resolve identified discrepancies quickly to ensure that reports are submitted timely as required.
The Department of Early Childhood agrees with this recommendation. HB 21-1304, created the new state Department of Early Childhood beginning July 1, 2022. Previously, programs and services related to early childhood were primarily located in the Colorado Department of Human Services. The Department of Early Childhood has been transitioning out of the Colorado Department of Human Services and the operational support inter-agency agreement requiring CDHS to provide administrative support for CDEC, including Federal Funding Accountability and Transparency Act (FFATA) reporting, ended 12/31/23. CDEC is currently developing and implementing procedures to validate financial data used to compile FFATA reporting, this process will include steps to resolve identified discrepancies quickly to ensure that reports are submitted timely as required.
Finding 2023-050 Colorado Child Care Assistance Program The Department is responsible for monitoring each county’s administration of CCCAP. County caseworkers enter a CCCAP adult caretaker’s application information, including household employment and income, household size, and the names and number of children needing care, into the Department’s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker’s household income must not exceed 85 percent of the State’s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker. In addition to families that apply for child care assistance, CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient. During Fiscal Year 2023, the Department provided approximately $133.2 million in child care benefits through CCCAP for 24,592 children. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over CCCAP enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s internal controls over CCCAP that were in place during Fiscal Year 2023. In addition, we performed testing of a sample of 60 children who were deemed eligible for child care services through CCCAP and received $348,581 in CCCAP benefits during Fiscal Year 2023 to determine whether the children’s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with determining the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. How were the results of the audit work measured? We measured the results of our audit work against the following: • According to federal regulation [45 CFR 98.11], the Department “has broad authority to administer the program through other governmental or non-governmental agencies”, such as county departments of human/social services. In addition, the regulation states that the Department “shall retain overall responsibility for the administration of the program” including monitoring programs and services, and ensuring that the departments of human/social services “operate according to the rules established for the program.” • State regulation [8 CCR 1403-1, 3.103.YYY] defines a parent fee or copayment as the “household’s contribution to the total cost of child care paid directly to the child care provider(s) prior to any state/county child care funds being expended.” • State regulation [8 CCR 1403-01, 3.124.A] states that “parent fees are based on gross countable income for the child care household compared to the household size, taking the number of children in care into account.” What problems did the audit work identify? We found that the Department did not fully comply with federal and state CCCAP requirements during Fiscal Year 2023. Specifically, we identified errors in 2 of the 60 case files (3 percent) that we tested, resulting in a total of $1,543 in known questioned costs. Specifically, we identified the following: In two cases, the caseworker incorrectly entered information into CHATS when determining eligibility, which resulted in the adult caretakers being charged an incorrect parent fee. In one case, the caseworker entered the adult caretaker’s income incorrectly as $2,125 instead of the correct amount of $2,215, which caused the parent fee to be incorrectly calculated as $848 instead of the correct amount of $879. In the other case, the caseworker incorrectly entered the number of hours worked by the adult caretaker when calculating the caretaker’s income, which resulted in the income being incorrectly calculated as $1,974 instead of the correct amount of $3,637, which caused the parent fee to be incorrectly calculated as $352 instead of the correct amount of $551. Because parent fees are required to be paid before CCCAP benefits are paid, the errors in these two case files resulted in $1,543 in known questioned costs. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with federal and state requirements for CCCAP during Fiscal Year 2023. The program was previously administered by the DHS, and this is the first year that the Department was in charge of the program. Program staff reported that they are working to implement effective internal controls, including policies and procedures requiring that Department CCCAP staff adequately monitor the county departments of human/social services to ensure the counties are conducting a secondary review over child care case files. Why do these problems matter? It is essential for the Department to ensure that child care eligibility is properly determined in accordance with state and federal regulations. Inaccurate processing of case file information for eligibility determination can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2023-050 The Department of Early Childhood (Department) should strengthen its internal controls over, and ensure it complies with, requirements for the federal Child Care and Development Fund Cluster grant by monitoring the county departments of human/social services to ensure they are performing supervisory and/or secondary reviews over case files after eligibility is determined in order to ensure eligibility is appropriately determined and that parent fees are accurate, and to address the issues identified in the audit. Response Department of Early Childhood Agree Implementation Date: December 2024 In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
Show full finding ▾Hide full finding ▴Finding 2023-050 Colorado Child Care Assistance Program The Department is responsible for monitoring each county’s administration of CCCAP. County caseworkers enter a CCCAP adult caretaker’s application information, including household employment and income, household size, and the names and number of children needing care, into the Department’s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker’s household income must not exceed 85 percent of the State’s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker. In addition to families that apply for child care assistance, CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient. During Fiscal Year 2023, the Department provided approximately $133.2 million in child care benefits through CCCAP for 24,592 children. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over CCCAP enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s internal controls over CCCAP that were in place during Fiscal Year 2023. In addition, we performed testing of a sample of 60 children who were deemed eligible for child care services through CCCAP and received $348,581 in CCCAP benefits during Fiscal Year 2023 to determine whether the children’s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with determining the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. How were the results of the audit work measured? We measured the results of our audit work against the following: • According to federal regulation [45 CFR 98.11], the Department “has broad authority to administer the program through other governmental or non-governmental agencies”, such as county departments of human/social services. In addition, the regulation states that the Department “shall retain overall responsibility for the administration of the program” including monitoring programs and services, and ensuring that the departments of human/social services “operate according to the rules established for the program.” • State regulation [8 CCR 1403-1, 3.103.YYY] defines a parent fee or copayment as the “household’s contribution to the total cost of child care paid directly to the child care provider(s) prior to any state/county child care funds being expended.” • State regulation [8 CCR 1403-01, 3.124.A] states that “parent fees are based on gross countable income for the child care household compared to the household size, taking the number of children in care into account.” What problems did the audit work identify? We found that the Department did not fully comply with federal and state CCCAP requirements during Fiscal Year 2023. Specifically, we identified errors in 2 of the 60 case files (3 percent) that we tested, resulting in a total of $1,543 in known questioned costs. Specifically, we identified the following: In two cases, the caseworker incorrectly entered information into CHATS when determining eligibility, which resulted in the adult caretakers being charged an incorrect parent fee. In one case, the caseworker entered the adult caretaker’s income incorrectly as $2,125 instead of the correct amount of $2,215, which caused the parent fee to be incorrectly calculated as $848 instead of the correct amount of $879. In the other case, the caseworker incorrectly entered the number of hours worked by the adult caretaker when calculating the caretaker’s income, which resulted in the income being incorrectly calculated as $1,974 instead of the correct amount of $3,637, which caused the parent fee to be incorrectly calculated as $352 instead of the correct amount of $551. Because parent fees are required to be paid before CCCAP benefits are paid, the errors in these two case files resulted in $1,543 in known questioned costs. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with federal and state requirements for CCCAP during Fiscal Year 2023. The program was previously administered by the DHS, and this is the first year that the Department was in charge of the program. Program staff reported that they are working to implement effective internal controls, including policies and procedures requiring that Department CCCAP staff adequately monitor the county departments of human/social services to ensure the counties are conducting a secondary review over child care case files. Why do these problems matter? It is essential for the Department to ensure that child care eligibility is properly determined in accordance with state and federal regulations. Inaccurate processing of case file information for eligibility determination can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2023-050 The Department of Early Childhood (Department) should strengthen its internal controls over, and ensure it complies with, requirements for the federal Child Care and Development Fund Cluster grant by monitoring the county departments of human/social services to ensure they are performing supervisory and/or secondary reviews over case files after eligibility is determined in order to ensure eligibility is appropriately determined and that parent fees are accurate, and to address the issues identified in the audit. Response Department of Early Childhood Agree Implementation Date: December 2024 In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
In December 2023, CCCAP automated case reviews in CHATS and required counties to submit reviews monthly. The results of the reviews are included in the performance monitoring process. The information gathered from the reviews will be used to target policy and system improvements and identify future training needs. Policy and system improvements to identify future training needs will be completed by December 2024.
Finding 2023-051 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In order to obtain this information, grant recipients are required to provide certain information to the federal government. For example, the federal Department of Education (DOE) requires the Department to report information about subgrants, or subawards, it gives to other governments or to nonprofit organizations (also referred to as subrecipients) from the DOE grants it receives. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is specifically required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. The Department is required to file a FFATA report in the following circumstances: • If the initial award is equal to or more than $30,000; • If subsequent grant modifications result in a total award equal to or more than $30,000; • If the initial award is equal to or more than $30,000, but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department’s required FFATA reports for Fiscal Year 2023 included information on the COVID-19 Education Stabilization Fund (ESF) [ALN 84.425], specifically the Elementary and Secondary School Emergency Relief (ESSER) Fund [ALN 84.425D] and the American Rescue Plan ― Elementary and Secondary School Emergency Relief (ARP ESSER) [ALN 84.425U]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for both programs in excess of $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, during Fiscal Year 2023, it was required to submit 562 FFATA reports for ESF. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over FFATA reporting during Fiscal Year 2023 and whether the information in the Department’s submitted FFATA reports was accurate and submitted in a timely manner. Another purpose of the audit work was to follow up on our Fiscal Year 2022 audit recommendation to improve the Department’s process for determining the timing of reporting within FSRS, and, additionally, to continue developing and implementing FFATA reconciliation procedures to identify subawards that went unreported during the fiscal year. The Department planned to implement this recommendation by December 2022. During the Fiscal Year 2023 audit, we requested a list of all ESF subawards the Department made during Fiscal Year 2023. We then selected a sample of 25 ESF subawards and requested copies of the FFATA reports that the Department uploaded to the FSRS system. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. Once the Department provided copies of the uploaded reports, we then reviewed the FFATA reports within FSRS for each subaward selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with federal regulations [2 CFR 170], direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, we determined that the Department partially implemented the Fiscal Year 2022 recommendation by its planned implementation date of December 2022. While the Department improved its process for determining the timing of reporting within FSRS, for the Fiscal Year 2023 sample we tested, we determined that the Department was late in reporting 11 of 25 ESF subawards (44 percent) by approximately 2 to 7 months. Collectively, these subawards totaled about $160.3 million for Fiscal Year 2023. The following table summarizes the results of our testing. Why did this problem occur? During part of Fiscal Year 2023, the Department did not have a control, such as a reconciliation, to help identify subawards that went unreported during the fiscal year. Further, when attempted submissions resulted in errors, the Department did not have a process in place to document the failed submission attempt. Why does this problem matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-051 The Department of Education should strengthen its internal controls over and ensure it complies with requirements under the Federal Funding Accountability and Transparency Act reporting for the COVID-19 Education Stabilization Fund by: A. Continuing to develop and implement reconciliation procedures to identify subawards that need to be reported each month. B. Developing procedures for documenting submission attempts that were unsuccessful and documenting any and all resubmission attempts until final acceptance is achieved. Response Department of Education A. Agree Implementation Date: August 2023 The process improvement was implemented in January 2023. As such, there was ‘catch up’ to be completed over the following months as we re-reconciled all of our federal awards against our allocation database and USASpend.gov. This represents a portion of the uncompliant reports. The other portion would be made up of several awardees whose profiles in FSRS would not accept any uploaded allocations. As of August 30, 2023, the reconciliation process is occurring much more consistently, on a monthly basis. B. Agree Implementation Date: August 2023 It is worth noting that in FY22 and into FY23 the General Services Administration (GSA) made changes to the congressional district field in the FFATA upload process, which did finally allow some of the these that errored out, to finally post. In addition, some of these that we were able to finally post, as a result of our reconciliation, would only be accepted through the FSRS system if they were keyed individually, creating a tremendous burden. Currently, we have a process in place to save ‘error’ files when this occurs, as evidence of the timely submission, although failing in FSRS through no fault of our own.
Show full finding ▾Hide full finding ▴Finding 2023-051 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In order to obtain this information, grant recipients are required to provide certain information to the federal government. For example, the federal Department of Education (DOE) requires the Department to report information about subgrants, or subawards, it gives to other governments or to nonprofit organizations (also referred to as subrecipients) from the DOE grants it receives. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is specifically required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. The Department is required to file a FFATA report in the following circumstances: • If the initial award is equal to or more than $30,000; • If subsequent grant modifications result in a total award equal to or more than $30,000; • If the initial award is equal to or more than $30,000, but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department’s required FFATA reports for Fiscal Year 2023 included information on the COVID-19 Education Stabilization Fund (ESF) [ALN 84.425], specifically the Elementary and Secondary School Emergency Relief (ESSER) Fund [ALN 84.425D] and the American Rescue Plan ― Elementary and Secondary School Emergency Relief (ARP ESSER) [ALN 84.425U]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for both programs in excess of $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, during Fiscal Year 2023, it was required to submit 562 FFATA reports for ESF. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over FFATA reporting during Fiscal Year 2023 and whether the information in the Department’s submitted FFATA reports was accurate and submitted in a timely manner. Another purpose of the audit work was to follow up on our Fiscal Year 2022 audit recommendation to improve the Department’s process for determining the timing of reporting within FSRS, and, additionally, to continue developing and implementing FFATA reconciliation procedures to identify subawards that went unreported during the fiscal year. The Department planned to implement this recommendation by December 2022. During the Fiscal Year 2023 audit, we requested a list of all ESF subawards the Department made during Fiscal Year 2023. We then selected a sample of 25 ESF subawards and requested copies of the FFATA reports that the Department uploaded to the FSRS system. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. Once the Department provided copies of the uploaded reports, we then reviewed the FFATA reports within FSRS for each subaward selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: In accordance with federal regulations [2 CFR 170], direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. What problem did the audit work identify? Based on our audit work, we determined that the Department partially implemented the Fiscal Year 2022 recommendation by its planned implementation date of December 2022. While the Department improved its process for determining the timing of reporting within FSRS, for the Fiscal Year 2023 sample we tested, we determined that the Department was late in reporting 11 of 25 ESF subawards (44 percent) by approximately 2 to 7 months. Collectively, these subawards totaled about $160.3 million for Fiscal Year 2023. The following table summarizes the results of our testing. Why did this problem occur? During part of Fiscal Year 2023, the Department did not have a control, such as a reconciliation, to help identify subawards that went unreported during the fiscal year. Further, when attempted submissions resulted in errors, the Department did not have a process in place to document the failed submission attempt. Why does this problem matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-051 The Department of Education should strengthen its internal controls over and ensure it complies with requirements under the Federal Funding Accountability and Transparency Act reporting for the COVID-19 Education Stabilization Fund by: A. Continuing to develop and implement reconciliation procedures to identify subawards that need to be reported each month. B. Developing procedures for documenting submission attempts that were unsuccessful and documenting any and all resubmission attempts until final acceptance is achieved. Response Department of Education A. Agree Implementation Date: August 2023 The process improvement was implemented in January 2023. As such, there was ‘catch up’ to be completed over the following months as we re-reconciled all of our federal awards against our allocation database and USASpend.gov. This represents a portion of the uncompliant reports. The other portion would be made up of several awardees whose profiles in FSRS would not accept any uploaded allocations. As of August 30, 2023, the reconciliation process is occurring much more consistently, on a monthly basis. B. Agree Implementation Date: August 2023 It is worth noting that in FY22 and into FY23 the General Services Administration (GSA) made changes to the congressional district field in the FFATA upload process, which did finally allow some of the these that errored out, to finally post. In addition, some of these that we were able to finally post, as a result of our reconciliation, would only be accepted through the FSRS system if they were keyed individually, creating a tremendous burden. Currently, we have a process in place to save ‘error’ files when this occurs, as evidence of the timely submission, although failing in FSRS through no fault of our own.
It is worth noting that, in FY22 and into FY23, the General Services Administration (GSA) made changes to the congressional district field in the FFATA upload process, which did finally allow some of the these that errored out to finally post. In addition, some of these that we were able to finally post, as a result of our reconciliation, would only be accepted through the FSRS system if they were keyed individually, creating a tremendous burden. Currently, we have a process in place to save ‘error’ files when this occurs, as evidence of the timely submission, although failing in FSRS through no fault of our own. Several helpdesk tickets were submitted to the GSA/FSRS helpdesk over 2 years ago, to assist in these submission errors. These errors were completely out of the department's control, with the federal reporting helpdesk providing no guidance or tools to correct consistently. It is worth noting that in February 2024, we received a response to a helpdesk ticket for the congressional district issue, however, the ticket was submitted over 2 years ago, which only solidifies that some of the issues noted in this particular finding, are completely out of the department's control.
2022-042
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Office of the Governor’s Office of Information Technology (OIT) in the previous year and has not been remediated as of June 30, 2023 because the original implementation date provided by OIT was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-083 and 2022-084 Trails—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the responses, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and responses have been provided to the Department and OIT in a separate, confidential memorandum. The Department utilizes Trails, its statewide automated child welfare information system, to aid in administering a number of federally-funded child welfare programs, including the Program. Trails went live in 2001 and, in Fiscal Year 2017, the Department and the Governor’s Office of Information Technology (OIT) began a multi-phase and multi-year modernization project that continued during Fiscal Year 2022. The Department is the business owner and is responsible for designing information security processes for the Trails application. To meet management’s IT expectations, the role of Trails Security Administrator was established to conduct Trails application access management procedures. OIT, as the IT service provider, works closely with the Department and is also responsible for conducting certain access management procedures. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department and OIT designed effective procedures for and configured Trails to address risks associated with information security. Our audit work was performed through interviews conducted of Department and OIT staff and reviewing supporting documentation. How were the results of the audit work measured? We measured the results of our audit work using the following criteria: • Colorado Information Security Policies (Security Policies), which are developed and published by OIT. • Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO). What problems did the audit work identify? Based on our Fiscal Year 2022 audit work, we identified problems with information security, access management, IT general controls for Trails at both the Department and OIT. Why did these problems occur? Department staff did not provide explanations for why the identified access management problems occurred. OIT staff provided an explanation for one of the identified access management problems, but not all of the problems. Why do these problems matter? When access management IT general controls are lacking, management cannot ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of Trails. Recommendation 2022-084 Governor’s Office of Information Technology The Governor’s Office of Information Technology should improve access management IT general controls over Trails, its statewide automated child welfare information system, by: A. Implementing the recommendation noted in Part A of the confidential finding. B. Implementing the recommendation noted in Part B of the confidential finding. C. Implementing the recommendation noted in Part C of the confidential finding. Response Governor’s Office of Information Technology A. Agree Implementation Date: June 2024 OIT will work on implementing recommendations for Part A. B. Agree Implementation Date: December 2023 OIT will work to implement the recommendation in Part B. C. Agree Implementation Date: December 2023 OIT will work to implement the recommendations in Part C.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Office of the Governor’s Office of Information Technology (OIT) in the previous year and has not been remediated as of June 30, 2023 because the original implementation date provided by OIT was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-083 and 2022-084 Trails—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the responses, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and responses have been provided to the Department and OIT in a separate, confidential memorandum. The Department utilizes Trails, its statewide automated child welfare information system, to aid in administering a number of federally-funded child welfare programs, including the Program. Trails went live in 2001 and, in Fiscal Year 2017, the Department and the Governor’s Office of Information Technology (OIT) began a multi-phase and multi-year modernization project that continued during Fiscal Year 2022. The Department is the business owner and is responsible for designing information security processes for the Trails application. To meet management’s IT expectations, the role of Trails Security Administrator was established to conduct Trails application access management procedures. OIT, as the IT service provider, works closely with the Department and is also responsible for conducting certain access management procedures. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department and OIT designed effective procedures for and configured Trails to address risks associated with information security. Our audit work was performed through interviews conducted of Department and OIT staff and reviewing supporting documentation. How were the results of the audit work measured? We measured the results of our audit work using the following criteria: • Colorado Information Security Policies (Security Policies), which are developed and published by OIT. • Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO). What problems did the audit work identify? Based on our Fiscal Year 2022 audit work, we identified problems with information security, access management, IT general controls for Trails at both the Department and OIT. Why did these problems occur? Department staff did not provide explanations for why the identified access management problems occurred. OIT staff provided an explanation for one of the identified access management problems, but not all of the problems. Why do these problems matter? When access management IT general controls are lacking, management cannot ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of Trails. Recommendation 2022-084 Governor’s Office of Information Technology The Governor’s Office of Information Technology should improve access management IT general controls over Trails, its statewide automated child welfare information system, by: A. Implementing the recommendation noted in Part A of the confidential finding. B. Implementing the recommendation noted in Part B of the confidential finding. C. Implementing the recommendation noted in Part C of the confidential finding. Response Governor’s Office of Information Technology A. Agree Implementation Date: June 2024 OIT will work on implementing recommendations for Part A. B. Agree Implementation Date: December 2023 OIT will work to implement the recommendation in Part B. C. Agree Implementation Date: December 2023 OIT will work to implement the recommendations in Part C.
OIT will work on implementing recommendations for Part C.
2022-084
Finding 2023-053 Medicaid Controls Over Eligibility Determinations The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. If the application is complete, the caseworker enters the information into CBMS, at which point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a listing of 106,314 beneficiaries who were determined to be newly eligible and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 63 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the first 3 quarters of the fiscal year. From that listing we selected 38 beneficiaries (63 percent of the total sample) to determine whether those individuals’ Medicaid eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 62,296 beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 37 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the last quarter of the fiscal year. From that list, we selected 22 beneficiaries (37 percent of the total sample), to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our Fiscal Year 2020 audit recommendation related to Medicaid eligibility. During the prior audit, we recommended the Department strengthen its internal controls over Medicaid by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 3 of the 60 Medicaid case files tested (5 percent). These errors resulted in a total of $95 in known questioned costs for Fiscal Year 2023, as shown below. Details of Errors Identified. Specifically, we found the following: • Timely Processing. In one case, the caseworker processed the application in 73 days, or 28 days after the required time frame of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. o State regulation [10 CCR 2505-10, 8.100.3.D.] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination, and 45 days for all other applications. • Incorrect Income Threshold. In one case, CBMS used the incorrect income threshold for the beneficiary’s eligibility determination. Specifically, CBMS used the income standard that was effective for Fiscal Year 2022 instead of the updated Fiscal Year 2023 income standard. The beneficiary’s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. o Federal regulation [42 USC 1395w-114] requires an individual to meet income limits in order to receive Medicaid benefits. • Missing Case File Documentation. In one case, we determined the case file did not have the documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, the case file was missing a copy of the beneficiary’s birth certificate, or other evidence that the individual was a qualified non-citizen when processing the application. This resulted in known questioned costs of $95. o Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. o State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, use the correct income thresholds to determine eligibility, and ensure that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-053 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file.
Show full finding ▾Hide full finding ▴Finding 2023-053 Medicaid Controls Over Eligibility Determinations The Department is responsible for ensuring that all expenditures under Medicaid are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for Medicaid program benefits is shared between local counties, designated Medical Assistance eligibility sites (MA sites), and the State. For Medicaid, individuals and families apply for benefits at their local county departments of human/social services, designated MA sites, or online through the Program Eligibility and Application Kit (PEAK) system. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into the Colorado Benefits Management System (CBMS), and approving or denying an applicant’s eligibility. An eligible beneficiary’s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as “fail” if the applicant’s reported income exceeds the limit. The CBMS eligibility data feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. If the application is complete, the caseworker enters the information into CBMS, at which point CBMS determines the applicant’s eligibility based on the information entered. If the application is incomplete, a caseworker is responsible for contacting the individual to assist with completing their application. The Department is responsible for supervising and monitoring the local counties’ and MA sites’ administration of Medicaid eligibility determinations. The Department is also responsible for ensuring that only eligible providers receive reimbursement for their costs of providing allowable services on behalf of eligible individuals. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and receiving Medicaid benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a listing of 106,314 beneficiaries who were determined to be newly eligible and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 63 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the first 3 quarters of the fiscal year. From that listing we selected 38 beneficiaries (63 percent of the total sample) to determine whether those individuals’ Medicaid eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 62,296 beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a payment made on their behalf to a Medicaid provider during this period. We noted approximately 37 percent of all beneficiaries that received benefits during Fiscal Year 2023 had claims during the last quarter of the fiscal year. From that list, we selected 22 beneficiaries (37 percent of the total sample), to determine whether those individuals’ Medicaid eligibility determination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our Fiscal Year 2020 audit recommendation related to Medicaid eligibility. During the prior audit, we recommended the Department strengthen its internal controls over Medicaid by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 3 of the 60 Medicaid case files tested (5 percent). These errors resulted in a total of $95 in known questioned costs for Fiscal Year 2023, as shown below. Details of Errors Identified. Specifically, we found the following: • Timely Processing. In one case, the caseworker processed the application in 73 days, or 28 days after the required time frame of 45 days. No questioned costs were identified in this instance because the beneficiary was appropriately approved for benefits. o State regulation [10 CCR 2505-10, 8.100.3.D.] notes that eligibility sites shall process an application for benefits within 90 days for persons who require a disability determination, and 45 days for all other applications. • Incorrect Income Threshold. In one case, CBMS used the incorrect income threshold for the beneficiary’s eligibility determination. Specifically, CBMS used the income standard that was effective for Fiscal Year 2022 instead of the updated Fiscal Year 2023 income standard. The beneficiary’s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. o Federal regulation [42 USC 1395w-114] requires an individual to meet income limits in order to receive Medicaid benefits. • Missing Case File Documentation. In one case, we determined the case file did not have the documentation necessary to support the Medicaid eligibility determination, as required by federal and state regulations. Specifically, the case file was missing a copy of the beneficiary’s birth certificate, or other evidence that the individual was a qualified non-citizen when processing the application. This resulted in known questioned costs of $95. o Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. o State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, use the correct income thresholds to determine eligibility, and ensure that the required documentation to support eligibility was maintained within the case file. Why do these problems matter? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals, or that eligible individuals are denied benefits. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-053 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file.
The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, using the correct income thresholds to determine eligibility, and maintaining the required documentation to support eligibility in the case file.
2022-048
Finding 2023-054 Children’s Basic Health Plan Controls Over Eligibility Determinations The Department is responsible for ensuring that all federal CBHP expenditures are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits in person at their local county departments of human/social services and designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants’ eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff copies of all policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. Capitation payments are lump-sum monthly payments made to managed care entities, which contract with providers for services. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. During the COVID-19 PHE, the State was required to maintain continuous enrollment for CBHP- eligible beneficiaries enrolled as of March 1, 2020. The CCA—enacted December 2022 and taking effect April 1, 2023—ended the continuous enrollment condition on March 31, 2023, which meant the State could begin the unwinding process, returning to normal eligibility and enrollment operations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random, non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a list from the Department of 7,978 beneficiaries who were determined to be newly-eligible for CBHP during this period and who had a capitation payment made on their behalf to a CBHP provider between July 1, 2022 and March 31, 2023. From that listing we selected 45 beneficiaries (75 percent of the total sample) to determine whether those individuals’ CBHP eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 3,006 existing CBHP beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a capitation payment made on their behalf to a CBHP provider between April 1, 2023 and June 30, 2023. From that list, we selected 15 beneficiaries (25 percent of the total sample)—whose eligibility was ultimately reapproved during the renewal unwinding process—to determine whether those individuals’ CBHP eligibility determination or redetermination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to CBHP eligibility. During our Fiscal Year 2020 audit, we reported that the Department lacked sufficient internal controls to ensure that it complied with federal and state eligibility requirements. At that time, we recommended that the Department strengthen its internal controls over CBHP by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 6 of the 60 CBHP case files tested (10 percent). These errors resulted in a total of $7,912 in known questioned costs for Fiscal Year 2023. Specifically, we found the following: • Timely Processing. In 3 cases, the caseworkers did not process the application within the 45-day requirement. One case was processed 48 days late, one case was 34 days late, and the third case was 4 days late. No questioned costs were identified in these instances because the beneficiaries were appropriately approved for benefits. o State regulation [10 CCR 2505-3, 170.4] notes that eligibility sites shall make an eligibility determination within 45 days from the date of the application. • Ineligible for Program. In two cases, beneficiaries with third-party health insurance at the time of application were not determined ineligible, as required. This error resulted in known questioned costs of $6,361. o State regulation [10 CCR 2505-3, 120.1.A] notes that in order to be eligible for the CBHP program, an eligible person shall not be covered under a group health plan or under health insurance coverage, excluding coverage under the Consolidated Omnibus Budget Reconciliation Act (COBRA). • Missing Case Documentation. One case file was missing documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, the case file was missing support for the applicant’s income. This error resulted in known questioned costs of $1,551. o Federal regulation [42 CFR 457.965] notes the state must include in each applicant’s record facts to support the State’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. o State regulation [10 CCR 2505-3, 110.1] requires all individuals who apply for CBHP to have a household income not exceeding 260 percent of the Federal Poverty Level, adjusted for household size. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, confirm that applicants were not covered under other health insurance, and ensure that the required eligibility documentation was maintained within the case file. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that processing of information used to determine CBHP eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or eligible individuals being denied benefits. Ultimately, the federal government may disallow federal funds for CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-054 The Department of Health Care Policy and Financing should strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file.
Show full finding ▾Hide full finding ▴Finding 2023-054 Children’s Basic Health Plan Controls Over Eligibility Determinations The Department is responsible for ensuring that all federal CBHP expenditures are appropriate, and that the State complies with federal and state program requirements. In Colorado, the responsibility for determining recipient eligibility for CBHP program benefits is shared between local counties, designated MA sites, and the State. For CBHP, individuals and families apply for benefits in person at their local county departments of human/social services and designated MA sites, or online through the PEAK system. When applying in person, the local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants’ eligibility. The CBMS eligibility data feeds into Colorado interChange, which pays providers for the services that they provide to CBHP beneficiaries. Once eligibility is determined, the county or MA site is responsible for maintaining records on each applicant in a case file, and then retaining those case files for the periods required by federal and state laws. The Department provides eligibility staff copies of all policy and operational training documents and guides for reference. These documents are meant to provide staff with consistent and accurate program information, and are posted online for all county and MA sites to use. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries, to provide capitation payments to CBHP providers. Capitation payments are lump-sum monthly payments made to managed care entities, which contract with providers for services. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange, based on eligibility information received from CBMS and requirements specified in federal and state regulations. During the COVID-19 PHE, the State was required to maintain continuous enrollment for CBHP- eligible beneficiaries enrolled as of March 1, 2020. The CCA—enacted December 2022 and taking effect April 1, 2023—ended the continuous enrollment condition on March 31, 2023, which meant the State could begin the unwinding process, returning to normal eligibility and enrollment operations. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the CBHP eligibility determination process as well as to determine whether the Department complied with applicable federal and state CBHP eligibility requirements during Fiscal Year 2023. During our audit, we reviewed the Department’s CBHP eligibility internal controls in place during Fiscal Year 2023. In addition, we performed testing on a random, non-statistical sample of 60 beneficiaries to determine if they were properly determined eligible and received CBHP benefits during Fiscal Year 2023. The Department operated under the continuous enrollment condition from July 1, 2022 to March 31, 2023, or 75 percent of the fiscal year. We obtained a list from the Department of 7,978 beneficiaries who were determined to be newly-eligible for CBHP during this period and who had a capitation payment made on their behalf to a CBHP provider between July 1, 2022 and March 31, 2023. From that listing we selected 45 beneficiaries (75 percent of the total sample) to determine whether those individuals’ CBHP eligibility determination was appropriate. The Department started its unwinding process in April 2023 and continued the process through June 2023 (25 percent of the fiscal year). We obtained a list of 3,006 existing CBHP beneficiaries whose eligibility was reviewed as part of the Department’s renewal unwinding process and who had a capitation payment made on their behalf to a CBHP provider between April 1, 2023 and June 30, 2023. From that list, we selected 15 beneficiaries (25 percent of the total sample)—whose eligibility was ultimately reapproved during the renewal unwinding process—to determine whether those individuals’ CBHP eligibility determination or redetermination was appropriate. Our testing included reviewing supporting documentation, including case files, information in CBMS data fields related to eligibility determination/redetermination, and CBHP payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers obtained and maintained the required documents supporting eligibility determinations in the case files, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to CBHP eligibility. During our Fiscal Year 2020 audit, we reported that the Department lacked sufficient internal controls to ensure that it complied with federal and state eligibility requirements. At that time, we recommended that the Department strengthen its internal controls over CBHP by providing adequate training to caseworkers to ensure they properly determine eligibility when processing beneficiary applications. What problems did the audit work identify and how were the results measured? We identified at least 1 error in 6 of the 60 CBHP case files tested (10 percent). These errors resulted in a total of $7,912 in known questioned costs for Fiscal Year 2023. Specifically, we found the following: • Timely Processing. In 3 cases, the caseworkers did not process the application within the 45-day requirement. One case was processed 48 days late, one case was 34 days late, and the third case was 4 days late. No questioned costs were identified in these instances because the beneficiaries were appropriately approved for benefits. o State regulation [10 CCR 2505-3, 170.4] notes that eligibility sites shall make an eligibility determination within 45 days from the date of the application. • Ineligible for Program. In two cases, beneficiaries with third-party health insurance at the time of application were not determined ineligible, as required. This error resulted in known questioned costs of $6,361. o State regulation [10 CCR 2505-3, 120.1.A] notes that in order to be eligible for the CBHP program, an eligible person shall not be covered under a group health plan or under health insurance coverage, excluding coverage under the Consolidated Omnibus Budget Reconciliation Act (COBRA). • Missing Case Documentation. One case file was missing documentation necessary to support the CBHP eligibility determination, as required by federal and state regulations. Specifically, the case file was missing support for the applicant’s income. This error resulted in known questioned costs of $1,551. o Federal regulation [42 CFR 457.965] notes the state must include in each applicant’s record facts to support the State’s determination of the applicant’s eligibility for the Children’s Health Insurance Program. o State regulation [10 CCR 2505-3, 110.1] requires all individuals who apply for CBHP to have a household income not exceeding 260 percent of the Federal Poverty Level, adjusted for household size. Why did these problems occur? We determined that the Department did not fully implement our prior audit recommendation related to ensuring caseworkers determine eligibility appropriately and in accordance with federal and state regulations. Specifically, caseworkers did not process applications timely, confirm that applicants were not covered under other health insurance, and ensure that the required eligibility documentation was maintained within the case file. Why do these problems matter? As the State department responsible for ensuring that all expenditures under CBHP are appropriate, it is essential for the Department to ensure that eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that processing of information used to determine CBHP eligibility does not result in CBHP benefits being provided to, and paid on behalf of, ineligible individuals, or eligible individuals being denied benefits. Ultimately, the federal government may disallow federal funds for CBHP program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-054 The Department of Health Care Policy and Financing should strengthen its internal controls over Children’s Basic Health Plan eligibility to ensure compliance with federal and state regulations by addressing the issues identified in the audit. This should include ensuring that local counties and Medical Assistance site caseworkers are appropriately trained and are held to required timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file. Response Department of Health Care Policy and Financing Agree Implementation Date: January 2025 The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file.
The Department recognizes that the training already exists so the Department will work with the individual eligibility sites to develop a Corrective Action plan for timelines for processing beneficiary applications, eligibility requirements related to applicants that have other health insurance, and requirements for maintaining the required documentation to support eligibility in the case file.
2022-050
Finding 2023-055 Medicaid Eligibility—Social Security Numbers Associated with Multiple State IDs Each beneficiary’s Medicaid application must contain specific information, including the beneficiary’s Social Security Number (SSN), a copy of their birth certificate, and support for their income in order for a caseworker to determine their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS and approving or denying an applicant’s eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD)—managed by the Governor’s Office of Information Technology (OIT)—assigns a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary’s eligibility status or termination of benefits. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary’s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating a SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including determining the Department’s progress in implementing our Fiscal Year 2021 audit recommendation related to this area. At that time, we recommended the Department ensure only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. Specifically, we recommended the Department improve its internal controls in this area by continuing to develop a report that can be used to identify SSNs associated with multiple State IDs, and then establishing and implementing written policies and procedures to outline how the Department will use the report to effectively monitor and correct those discrepancies. As part of our testing, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. We requested a list of all Medicaid claims that were submitted by providers and paid by the Department for the fiscal year, including the beneficiaries’ names, SSNs, and State IDs. The Department provided a list that included approximately 1.4 million beneficiaries who received benefits during the fiscal year. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries for Fiscal Year 2023. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires that the Department obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within 1 year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b], states have up to 1 year from the date of the overpayment discovery to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities for its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation to improve its internal controls over Medicaid eligibility to ensure it is monitoring and correcting any instances of multiple State IDs associated with the same SSN. During our testing, we identified 200 unique SSNs that each appeared to be inappropriately associated with two State IDs; in total, the 200 SSNs were tied to 400 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN. Specifically, we found the following: • 108 SSNs were tied to 2 separate State IDs (representing 216 potential beneficiaries) that appeared to be for different people based on the names and/or dates of birth. These could represent invalid claims payments on behalf of ineligible beneficiaries. • 92 SSNs were tied to two separate State IDs (representing 184 potential beneficiaries) that had the same name and date of birth. These SSNs could be valid, but with more than 1 State ID, a provider could submit and have a claim paid for the same services under both State IDs. We did not identify any instances of individual SSNs being tied to more than 2 State IDs. These issues affected a total of 400 Medicaid State IDs that had not been corrected as of June 30, 2023, and represented a total of $71,441 Medicaid claims paid through Colorado interChange for Fiscal Year 2023. We selected a random, non-statistical sample of 12 SSN pairs (24 different State IDs) identified in our testing, representing $6,050 in Medicaid claims, and provided the sample to the Department to research. The Department determined, and we confirmed, that as of the end of our audit in December 2023, payments made for 9 of the 12 SSN pairs were made on behalf of eligible beneficiaries. Of the 9 pairs, 4 had instances where an individual had incorrect information entered into CBMS. The remaining 5 SSN pairs each represented a single beneficiary, but with 2 separate Medicaid IDs that need to be merged within CBMS so that each beneficiary only has one unique Medicaid ID. In total, these 9 sample pairs represented $2,224 of the $6,050 sample. The other 3 SSN pairs in our sample, totaling $3,826, had at least 1 instance of a SSN not being verified when input into CBMS; therefore, we consider these amounts to be known questioned costs. Of these costs, $2,105 were paid with federal grant funds. We were unable to determine whether the payments in the remaining 188 SSNs that were each tied to 2 State IDs were made on behalf of eligible Medicaid beneficiaries; therefore, we consider the entire $65,391 in Medicaid claims payments to be likely questioned costs. Of these costs, $36,604 were paid with federal grant funds. The breakdown of costs we questioned are shown in the following table: A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards] (Uniform Guidance), is “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation….” We have identified these questioned costs as “known questioned costs” that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place to prevent or detect and correct all instances of multiple State IDs associated with a single SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. In addition, we determined that the Department did not fully implement our prior audit recommendation related to developing a report to identify single SSNs associated with multiple State IDs, and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. Specifically, the Department deployed a dashboard report in April 2023, but it did not provide enough detail for caseworkers to be able to effectively monitor and correct SSN and State ID discrepancies. In addition, Department staff reported they have not yet finalized written guidance on how to use the dashboard report at either the Department or county and MA-site level to identify and resolve discrepancies. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to instances in which multiple State IDs are associated with a single SSN. For example, without adequate controls in place to prevent multiple State IDs from being created or to identify and correct these instances, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-055 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Colorado’s Medicaid Program eligibility by: A. Researching the remaining questioned claims payments that were identified during our audit to determine whether the local counties or Medical Assistance (MA) sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate—in accordance with federal regulation at the time the payments were made—and repaying the federal government for any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify instances of single SSNs associated with multiple State IDs that, once complete, can be used to monitor that caseworkers are addressing any identified discrepancies in a timely manner. C. Continuing to establish and implement written policies and procedures outlining how the Department and MA sites will use the report to effectively monitor and correct SSN and State ID discrepancies. The Department’s policies and procedures should include information on the report itself, such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, and how to identify when additional training may be needed for local counties and MA sites; the MA site policies and procedures should include information on how to read and use the report to identify and correct discrepancies. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department’s system, that provider is guaranteed payment if they render an authorized service. Auditor’s Addendum The Department is responsible for ensuring that only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount, and must be repaid to the federal government within 1 year. Eligibility errors include ineligible individuals who were authorized as eligible when they received services [42 CFR 431.960d(2)(i)]. B. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. C. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. The Department will issue guidance such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, how to identify when additional training may be needed for local counties and MA sites and information on how to read and use the report and identify and correct discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024.
Show full finding ▾Hide full finding ▴Finding 2023-055 Medicaid Eligibility—Social Security Numbers Associated with Multiple State IDs Each beneficiary’s Medicaid application must contain specific information, including the beneficiary’s Social Security Number (SSN), a copy of their birth certificate, and support for their income in order for a caseworker to determine their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS and approving or denying an applicant’s eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD)—managed by the Governor’s Office of Information Technology (OIT)—assigns a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary’s eligibility status or termination of benefits. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary’s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating a SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including determining the Department’s progress in implementing our Fiscal Year 2021 audit recommendation related to this area. At that time, we recommended the Department ensure only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. Specifically, we recommended the Department improve its internal controls in this area by continuing to develop a report that can be used to identify SSNs associated with multiple State IDs, and then establishing and implementing written policies and procedures to outline how the Department will use the report to effectively monitor and correct those discrepancies. As part of our testing, we reviewed the Department’s Medicaid eligibility internal controls in place during Fiscal Year 2023. We requested a list of all Medicaid claims that were submitted by providers and paid by the Department for the fiscal year, including the beneficiaries’ names, SSNs, and State IDs. The Department provided a list that included approximately 1.4 million beneficiaries who received benefits during the fiscal year. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries for Fiscal Year 2023. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires that the Department obtain and maintain documentation to support each beneficiary’s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within 1 year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b], states have up to 1 year from the date of the overpayment discovery to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities for its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation to improve its internal controls over Medicaid eligibility to ensure it is monitoring and correcting any instances of multiple State IDs associated with the same SSN. During our testing, we identified 200 unique SSNs that each appeared to be inappropriately associated with two State IDs; in total, the 200 SSNs were tied to 400 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN. Specifically, we found the following: • 108 SSNs were tied to 2 separate State IDs (representing 216 potential beneficiaries) that appeared to be for different people based on the names and/or dates of birth. These could represent invalid claims payments on behalf of ineligible beneficiaries. • 92 SSNs were tied to two separate State IDs (representing 184 potential beneficiaries) that had the same name and date of birth. These SSNs could be valid, but with more than 1 State ID, a provider could submit and have a claim paid for the same services under both State IDs. We did not identify any instances of individual SSNs being tied to more than 2 State IDs. These issues affected a total of 400 Medicaid State IDs that had not been corrected as of June 30, 2023, and represented a total of $71,441 Medicaid claims paid through Colorado interChange for Fiscal Year 2023. We selected a random, non-statistical sample of 12 SSN pairs (24 different State IDs) identified in our testing, representing $6,050 in Medicaid claims, and provided the sample to the Department to research. The Department determined, and we confirmed, that as of the end of our audit in December 2023, payments made for 9 of the 12 SSN pairs were made on behalf of eligible beneficiaries. Of the 9 pairs, 4 had instances where an individual had incorrect information entered into CBMS. The remaining 5 SSN pairs each represented a single beneficiary, but with 2 separate Medicaid IDs that need to be merged within CBMS so that each beneficiary only has one unique Medicaid ID. In total, these 9 sample pairs represented $2,224 of the $6,050 sample. The other 3 SSN pairs in our sample, totaling $3,826, had at least 1 instance of a SSN not being verified when input into CBMS; therefore, we consider these amounts to be known questioned costs. Of these costs, $2,105 were paid with federal grant funds. We were unable to determine whether the payments in the remaining 188 SSNs that were each tied to 2 State IDs were made on behalf of eligible Medicaid beneficiaries; therefore, we consider the entire $65,391 in Medicaid claims payments to be likely questioned costs. Of these costs, $36,604 were paid with federal grant funds. The breakdown of costs we questioned are shown in the following table: A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards] (Uniform Guidance), is “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation….” We have identified these questioned costs as “known questioned costs” that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place to prevent or detect and correct all instances of multiple State IDs associated with a single SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. In addition, we determined that the Department did not fully implement our prior audit recommendation related to developing a report to identify single SSNs associated with multiple State IDs, and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. Specifically, the Department deployed a dashboard report in April 2023, but it did not provide enough detail for caseworkers to be able to effectively monitor and correct SSN and State ID discrepancies. In addition, Department staff reported they have not yet finalized written guidance on how to use the dashboard report at either the Department or county and MA-site level to identify and resolve discrepancies. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to instances in which multiple State IDs are associated with a single SSN. For example, without adequate controls in place to prevent multiple State IDs from being created or to identify and correct these instances, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-055 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Colorado’s Medicaid Program eligibility by: A. Researching the remaining questioned claims payments that were identified during our audit to determine whether the local counties or Medical Assistance (MA) sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate—in accordance with federal regulation at the time the payments were made—and repaying the federal government for any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify instances of single SSNs associated with multiple State IDs that, once complete, can be used to monitor that caseworkers are addressing any identified discrepancies in a timely manner. C. Continuing to establish and implement written policies and procedures outlining how the Department and MA sites will use the report to effectively monitor and correct SSN and State ID discrepancies. The Department’s policies and procedures should include information on the report itself, such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, and how to identify when additional training may be needed for local counties and MA sites; the MA site policies and procedures should include information on how to read and use the report to identify and correct discrepancies. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department’s system, that provider is guaranteed payment if they render an authorized service. Auditor’s Addendum The Department is responsible for ensuring that only eligible beneficiaries receive Medicaid benefits by monitoring and correcting any instances of multiple State IDs associated with the same SSN. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount, and must be repaid to the federal government within 1 year. Eligibility errors include ineligible individuals who were authorized as eligible when they received services [42 CFR 431.960d(2)(i)]. B. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024. C. Agree Implementation Date: December 2024 The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. The Department will issue guidance such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, how to identify when additional training may be needed for local counties and MA sites and information on how to read and use the report and identify and correct discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024.
The Department implemented Social Security number (SSN) discrepancy reports within the Monitoring Dashboards in April 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor, research, and correct SSN and State ID discrepancies. The Department will issue guidance such as the frequency and timing of when Department staff should generate and review the report, how to monitor caseworkers to ensure that discrepancies are being identified and corrected in a timely manner, how to identify when additional training may be needed for local counties and MA sites and information on how to read and use the report and identify and correct discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSN's with an implementation date of December 2024.
2022-044
Finding 2023-056 Presumptive Eligibility for Medicaid and CBHP Colorado’s Medicaid and CBHP presumptive eligibility program is designed to provide eligible individuals—such as children under the age of 19 and pregnant people—immediate, temporary medical coverage of up to 45 days while they wait for caseworkers to process their regular Medicaid or CBHP application and determine their eligibility status. Although there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application and appear eligible to receive temporary benefits while a caseworker is processing their application. The Department works with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE Site) to help manage the application process for individuals needing access to immediate temporary medical coverage. To be certified as a PE Site, the entity must be an existing provider, or have an affiliation with an existing provider, and complete the Presumptive Eligibility General Information Form (Form), which serves as the entity’s application to become a PE Site. Once an entity completes and submits a Form, Department staff review and either approve or deny the application. Final notice of acceptance or denial as an approved PE Site is then sent to the contact person listed on the Form. The PE Site is in charge of helping individuals complete an application and ensuring that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE Site collects the minimum information needed to determine presumptive eligibility, including the applicant’s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which is used to assist the caseworker in determining whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant’s reported information is not in compliance with federal and state requirements, CBMS is programmed to deny the eligibility and mark the applicant’s eligibility as “fail” within CBMS. As a result, the applicant would not be eligible for the payment of services to providers on their behalf through Colorado interChange. Once an applicant’s presumptive eligibility has been determined, the PE Site is required to submit the application along with a transmittal form detailing the beneficiary’s reported information to the appropriate local county or designated MA site within 5 business days, at which point the county or MA site would complete the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. The county or MA site must then make a final eligibility determination within 45 days of the application date. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual’s presumptive eligibility benefits should end. All PE Sites must be certified by the Department to make presumptive eligibility determinations. PE Sites must also recertify with the Department every 2 years to maintain their active status as a certified PE Site. As part of the recertification process, Department staff will audit 5 percent of the applications the PE Site processed during the previous year to confirm that the applicant’s information was correctly entered into CBMS and that the PE Site followed the appropriate guidance when making presumptive eligibility decisions. If the PE Site fails the audit, the Department requires PE Site staff to undergo customized Department training for the areas they failed within 6 months of the review. As of June 30, 2023, there were 50 certified PE Sites. During Fiscal Year 2023, 17 of those PE Sites determined presumptive eligibility for 531 Medicaid cases and 155 CBHP cases. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2023. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to internal controls over presumptive eligibility. Specifically, during the Fiscal Year 2020 audit, we identified problems with the Department’s compliance with applicable federal and state requirements, and recommended that the Department strengthen its internal controls over Medicaid and CBHP presumptive eligibility by developing and implementing (1) a tracking mechanism for monitoring PE Sites; (2) written policies and procedures detailing the requirements for completion of PE Site reviews, timely training for PE Site staff, and timely recertification of PE Sites; and (3) resolving CBMS programming and system issues to appropriately terminate presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP program and ensuring CBMS displays consistent applicant information between various screens. As part of our Fiscal Year 2023 audit, we reviewed the Department’s tracking mechanism for monitoring PE Sites, as well as the Department’s updated policies and procedures for completion of PE Site reviews, training for PE Site staff, and timely recertification of PE Sites. In addition, we inquired with the Department about the CBMS programming issues identified during the audit. Department staff reported they implemented changes within CBMS that would address the programming and system issues identified. As part of our Fiscal Year 2023 audit, we made inquiries with Department staff regarding the policies and procedures for applying to be a PE Site, recertification requirements, and Department site monitoring. During our internal controls testing, we reviewed a listing of all 50 PE Sites and noted that 40 sites were due for recertification in Fiscal Year 2023. We selected six PE Sites that were due for recertification and performed testing to determine whether the sites were appropriately recertified by the Department by performing the following procedures: • We confirmed that the Department had performed the recertification and reviewed the related case file support for all 6 PE Sites in our sample. • We noted that 4 of 6 PE Sites tested passed their recertification. We reviewed the Department’s case file support and confirmed the sites were appropriately recertified and mailed recertification letters from the Department. • The eligibility status for the remaining two PE Sites in our sample was terminated by the Department as part of its recertification review. One site did not complete the required paperwork for the recertification and the other did not have a need to provide PE Site services anymore. We reviewed Department correspondence to these sites to confirm the Department notified them that their PE Site status was terminated. In addition, we randomly selected a sample of 40 Medicaid and 37 CBHP cases for individuals who were deemed presumptively eligible at a PE Site during Fiscal Year 2023 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The Department’s process for presumptive eligibility determinations is the same for both Medicaid and CBHP and, therefore, our testing was used to determine compliance for both programs. What problems did the audit work identify and how were the results measured? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2023. Overall, we identified 8 instances of non-compliance with federal and state regulations over presumptive eligibility requirements at 4 separate PE Sites. Specifically, we identified the following: • Untimely End of Presumptive Eligibility. In 4 of 40 Medicaid (10 percent) and 3 of 37 CBHP cases (8 percent), we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. In these cases, the beneficiary’s presumptive eligibility did not end until between 6 and 31 days after the beneficiary was determined to be eligible for regular Medicaid and CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. • Timeliness of Transmittal Letters. In 1 of 40 Medicaid cases (3 percent), we found that the PE Site determining eligibility did not notify the county within five business days that the applicant was presumptively eligible, as required by state regulation. In this case, notification was made 1 day late. State regulation [10 CCR 2505-10, 8.100.4.F.4)] states that the presumptive eligibility sites are required to notify the local county within 5 business days that the client is presumptively eligible. Why did these problems occur? We determined that the Department’s changes to CBMS to address the programing and system issues identified in our prior audit recommendation did not appropriately terminate beneficiaries’ presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, the Department lacked sufficient internal controls to ensure that it complied with federal and state presumptive eligibility requirements during Fiscal Year 2023. Specifically, the Department did not adequately train PE Site staff on presumptive eligibility requirements and, as a result, they did not properly end presumptive eligibility and process transmittal letters in a timely manner. Why do these problems matter? As the State’s medical assistance agency, it is essential for the Department to ensure that PE Sites’ eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that presumptive eligibility determinations are made correctly and do not result in Medicaid or CBHP benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-056 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Colorado’s Medicaid Program (Medicaid) and the Children’s Basic Health Plan (CBHP) presumptive eligibility by: A. Resolving Colorado Benefits Management System (CBMS) programming and system issues to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP. B. Providing training to presumptive eligibility site staff to emphasize issues that were identified during our audit or that the Department identifies during its ongoing monitoring, including the importance of properly ending presumptive eligibility benefits when the beneficiary is determined to be ineligible for Medicaid and CBHP benefits and processing applications timely. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2023 The Colorado Benefits Management System (CBMS) programming and system discrepancies to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or Children’s Basic Health Plan program was corrected with a data fix in July 2023. The Department found after further research that it is permissible for Presumptive Eligibility Medical Spans and Medical Assistance Medical spans to overlap as these are two separate High level Program groups. Department staff will continue to monitor for future discrepancies. B. Agree Implementation Date: August 2024 The Department will continue to train presumptive eligibility site staff on the errors identified during this audit including processing applications timely, and those errors that the Department identifies during ongoing monitoring. The Colorado Benefits Management System (CBMS) automatically populates benefit end dates when the Eligibility site worker authorizes the Medicaid and CBHP benefits. The Department staff will continue to monitor for these discrepancies and work with the individual Eligibility sites on their application processing timeliness.
Show full finding ▾Hide full finding ▴Finding 2023-056 Presumptive Eligibility for Medicaid and CBHP Colorado’s Medicaid and CBHP presumptive eligibility program is designed to provide eligible individuals—such as children under the age of 19 and pregnant people—immediate, temporary medical coverage of up to 45 days while they wait for caseworkers to process their regular Medicaid or CBHP application and determine their eligibility status. Although there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application and appear eligible to receive temporary benefits while a caseworker is processing their application. The Department works with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE Site) to help manage the application process for individuals needing access to immediate temporary medical coverage. To be certified as a PE Site, the entity must be an existing provider, or have an affiliation with an existing provider, and complete the Presumptive Eligibility General Information Form (Form), which serves as the entity’s application to become a PE Site. Once an entity completes and submits a Form, Department staff review and either approve or deny the application. Final notice of acceptance or denial as an approved PE Site is then sent to the contact person listed on the Form. The PE Site is in charge of helping individuals complete an application and ensuring that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE Site collects the minimum information needed to determine presumptive eligibility, including the applicant’s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which is used to assist the caseworker in determining whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant’s reported information is not in compliance with federal and state requirements, CBMS is programmed to deny the eligibility and mark the applicant’s eligibility as “fail” within CBMS. As a result, the applicant would not be eligible for the payment of services to providers on their behalf through Colorado interChange. Once an applicant’s presumptive eligibility has been determined, the PE Site is required to submit the application along with a transmittal form detailing the beneficiary’s reported information to the appropriate local county or designated MA site within 5 business days, at which point the county or MA site would complete the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. The county or MA site must then make a final eligibility determination within 45 days of the application date. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual’s presumptive eligibility benefits should end. All PE Sites must be certified by the Department to make presumptive eligibility determinations. PE Sites must also recertify with the Department every 2 years to maintain their active status as a certified PE Site. As part of the recertification process, Department staff will audit 5 percent of the applications the PE Site processed during the previous year to confirm that the applicant’s information was correctly entered into CBMS and that the PE Site followed the appropriate guidance when making presumptive eligibility decisions. If the PE Site fails the audit, the Department requires PE Site staff to undergo customized Department training for the areas they failed within 6 months of the review. As of June 30, 2023, there were 50 certified PE Sites. During Fiscal Year 2023, 17 of those PE Sites determined presumptive eligibility for 531 Medicaid cases and 155 CBHP cases. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2023. Additionally, we reviewed the Department’s progress in implementing our prior audit recommendation related to internal controls over presumptive eligibility. Specifically, during the Fiscal Year 2020 audit, we identified problems with the Department’s compliance with applicable federal and state requirements, and recommended that the Department strengthen its internal controls over Medicaid and CBHP presumptive eligibility by developing and implementing (1) a tracking mechanism for monitoring PE Sites; (2) written policies and procedures detailing the requirements for completion of PE Site reviews, timely training for PE Site staff, and timely recertification of PE Sites; and (3) resolving CBMS programming and system issues to appropriately terminate presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP program and ensuring CBMS displays consistent applicant information between various screens. As part of our Fiscal Year 2023 audit, we reviewed the Department’s tracking mechanism for monitoring PE Sites, as well as the Department’s updated policies and procedures for completion of PE Site reviews, training for PE Site staff, and timely recertification of PE Sites. In addition, we inquired with the Department about the CBMS programming issues identified during the audit. Department staff reported they implemented changes within CBMS that would address the programming and system issues identified. As part of our Fiscal Year 2023 audit, we made inquiries with Department staff regarding the policies and procedures for applying to be a PE Site, recertification requirements, and Department site monitoring. During our internal controls testing, we reviewed a listing of all 50 PE Sites and noted that 40 sites were due for recertification in Fiscal Year 2023. We selected six PE Sites that were due for recertification and performed testing to determine whether the sites were appropriately recertified by the Department by performing the following procedures: • We confirmed that the Department had performed the recertification and reviewed the related case file support for all 6 PE Sites in our sample. • We noted that 4 of 6 PE Sites tested passed their recertification. We reviewed the Department’s case file support and confirmed the sites were appropriately recertified and mailed recertification letters from the Department. • The eligibility status for the remaining two PE Sites in our sample was terminated by the Department as part of its recertification review. One site did not complete the required paperwork for the recertification and the other did not have a need to provide PE Site services anymore. We reviewed Department correspondence to these sites to confirm the Department notified them that their PE Site status was terminated. In addition, we randomly selected a sample of 40 Medicaid and 37 CBHP cases for individuals who were deemed presumptively eligible at a PE Site during Fiscal Year 2023 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The Department’s process for presumptive eligibility determinations is the same for both Medicaid and CBHP and, therefore, our testing was used to determine compliance for both programs. What problems did the audit work identify and how were the results measured? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2023. Overall, we identified 8 instances of non-compliance with federal and state regulations over presumptive eligibility requirements at 4 separate PE Sites. Specifically, we identified the following: • Untimely End of Presumptive Eligibility. In 4 of 40 Medicaid (10 percent) and 3 of 37 CBHP cases (8 percent), we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. In these cases, the beneficiary’s presumptive eligibility did not end until between 6 and 31 days after the beneficiary was determined to be eligible for regular Medicaid and CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. • Timeliness of Transmittal Letters. In 1 of 40 Medicaid cases (3 percent), we found that the PE Site determining eligibility did not notify the county within five business days that the applicant was presumptively eligible, as required by state regulation. In this case, notification was made 1 day late. State regulation [10 CCR 2505-10, 8.100.4.F.4)] states that the presumptive eligibility sites are required to notify the local county within 5 business days that the client is presumptively eligible. Why did these problems occur? We determined that the Department’s changes to CBMS to address the programing and system issues identified in our prior audit recommendation did not appropriately terminate beneficiaries’ presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, the Department lacked sufficient internal controls to ensure that it complied with federal and state presumptive eligibility requirements during Fiscal Year 2023. Specifically, the Department did not adequately train PE Site staff on presumptive eligibility requirements and, as a result, they did not properly end presumptive eligibility and process transmittal letters in a timely manner. Why do these problems matter? As the State’s medical assistance agency, it is essential for the Department to ensure that PE Sites’ eligibility determinations are made appropriately and in accordance with federal and state regulations. This includes ensuring that presumptive eligibility determinations are made correctly and do not result in Medicaid or CBHP benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2023-056 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Colorado’s Medicaid Program (Medicaid) and the Children’s Basic Health Plan (CBHP) presumptive eligibility by: A. Resolving Colorado Benefits Management System (CBMS) programming and system issues to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or CBHP. B. Providing training to presumptive eligibility site staff to emphasize issues that were identified during our audit or that the Department identifies during its ongoing monitoring, including the importance of properly ending presumptive eligibility benefits when the beneficiary is determined to be ineligible for Medicaid and CBHP benefits and processing applications timely. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2023 The Colorado Benefits Management System (CBMS) programming and system discrepancies to appropriately terminate applicants’ presumptive eligibility when the beneficiaries are enrolled in the regular Medicaid or Children’s Basic Health Plan program was corrected with a data fix in July 2023. The Department found after further research that it is permissible for Presumptive Eligibility Medical Spans and Medical Assistance Medical spans to overlap as these are two separate High level Program groups. Department staff will continue to monitor for future discrepancies. B. Agree Implementation Date: August 2024 The Department will continue to train presumptive eligibility site staff on the errors identified during this audit including processing applications timely, and those errors that the Department identifies during ongoing monitoring. The Colorado Benefits Management System (CBMS) automatically populates benefit end dates when the Eligibility site worker authorizes the Medicaid and CBHP benefits. The Department staff will continue to monitor for these discrepancies and work with the individual Eligibility sites on their application processing timeliness.
The Department will continue to train presumptive eligibility site staff on the errors identified during this audit including processing applications timely, and those errors that the Department identifies during ongoing monitoring. The Colorado Benefits Management System (CBMS) automatically populates benefit end dates when the Eligibility site worker authorizes the Medicaid and CBHP benefits. The Department staff will continue to monitor for these discrepancies and work with the individual Eligibility sites on their application processing timeliness.
2022-052
Finding 2023-057 Payments for Non-Emergent Medical Transportation Claims Non-emergent medical transportation (NEMT) is a federally-required Medicaid benefit intended to provide recipients prompt, efficient, and medically-necessary transportation services to and from their Medicaid medical services [Section 42 USC 1396a(a)]. NEMT cannot be used as a convenience to the recipient, such as for a trip to a grocery store, or be used by non-recipients unless they are an escort for a recipient who is a child or an at-risk adult [10 CCR 2505-10 8.014.5.D.1]. NEMT is available to all individuals enrolled in Medicaid. Federal law allows states to provide NEMT services through state-designated entities, such as contracted brokers, as long as the brokers provide cost-effective administration and delivery of services for Medicaid recipients [Section 42 USC 1396a(a)(70)]. Brokers are generally responsible for verifying recipient eligibility for NEMT services, scheduling recipient transportation with ride providers, paying the providers for services, submitting Medicaid claims to the Department through Colorado interChange to cover the cost of services, and retaining supporting documentation for each Medicaid claim. Over the years, NEMT services in Colorado have been brokered in the following ways: • Prior to July 2020. For 55 counties, various county offices brokered NEMT services for Medicaid recipients. In the remaining nine counties, the Department contracted with IntelliRide to serve as the broker for NEMT services in those areas. IntelliRide is a division of TransDev North America and manages NEMT, demand response transportation, and paratransit programs across the country. • July 1, 2020 to August 31, 2021. For all 64 counties, the Department contracted with IntelliRide to be the broker for NEMT services; however, our 2021 audits found that the Department also paid about $3.5 million in NEMT claims directly to 66 providers who brokered their own services during the prior audit review period of July 2020 through February 2021. • September 1, 2021 to Present. The Department returned to having 55 counties broker NEMT services in their areas, and contracting with IntelliRide to serve as the NEMT broker in the remaining nine counties. For rides brokered by IntelliRide, providers upload trip information into IntelliRide’s EcoLane transportation scheduling system, which maintains information on recipients’ requests for rides; the names of the recipient and driver; and trip information, such as the trip date, scheduled pick-up time, and destination. In our Fiscal Year 2021 Statewide audit and 2021 NEMT performance audit, we identified $291,597 in known questioned costs and about $5.2 million in likely questioned costs related to NEMT services that did not comply with federal and state Medicaid requirements. We recommended that the Department investigate each questioned claim to recover any payments determined to be inappropriate, and repay the federal portion, as appropriate. Federal regulations define known questioned costs as questioned costs that are specifically identified by the auditor and define likely questioned costs as the auditor’s best estimate of total questioned costs [45 CFR 75.516]. Known and likely questioned costs should be investigated by the Department, inappropriate payments should be recovered, and those payments should be repaid to the federal government as appropriate; Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We also recommended that the Department implement controls to ensure taxi claims are paid in accordance with established requirements and rates. The Department agreed to implement these audit recommendations by December 2022. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s implementation of the Fiscal Year 2021 audit recommendations to (1) investigate the known and likely questioned costs identified by the audits, recover inappropriate payments, and repay the federal portion, as appropriate, and (2) implement controls to ensure taxi claims are paid in accordance with established requirements and rates. We reviewed documentation of the Department’s efforts to investigate and recover the known questioned costs identified in the prior audits, and repay the federal portion of the claims. We interviewed Department staff to understand the extent to which steps had been taken to investigate, recover, and repay the likely questioned costs identified. We reviewed Department documentation and interviewed Department staff to understand the internal controls that were implemented to help ensure taxi claims are paid in line with requirements and rates. We also reviewed Department documentation and online information about NEMT fraud schemes that the Department identified starting in Summer 2023. How were the results of the audit work measured? The Department must investigate questioned costs related to NEMT claims, recover inappropriate payments, and repay the federal portion, as appropriate. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls that provide reasonable assurance that the Department is managing federal funds in compliance with federal statutes, regulations, and federal program terms and conditions. A questioned cost is defined in Uniform Guidance [45 CFR 75.2] as “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.…” Questioned costs can result in the misappropriation of federal and state funds. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments “are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....” According to federal law, states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share (also known as Federal Financial Participation or FFP) must be refunded to CMS, regardless of whether a recovery is made from the provider [42 USC 1396b]. The Department must have internal controls to pay claims based on accurate service rates and trip mileage. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which is generally based on trip mileage. According to the Department’s NEMT Billing Manual and rate schedule for 2021, taxi claims should have been paid at the rate set by the PUC. What problems did the audit work identify? The Department has not investigated and recovered as appropriate, the $5.2 million in likely questioned costs related to NEMT claims, or repaid the federal portion. Based on our testwork, we determined that the Department has not fully implemented the Statewide audit and performance audit recommendations from 2021 because it has not investigated the about $5.2 million in likely questioned costs identified by the audits, or attempted to recover and repay the federal portion of those questioned costs. As of June 30, 2023, the Department had investigated and recovered the $291,597 in known questioned costs and repaid the federal portion. In addition, the Department has not fully implemented internal controls to help ensure taxi claims are paid appropriately. The issues we identified in our 2021 Statewide and performance audits, which resulted in the likely questioned costs between July 2020 and February 2021(the prior audit period), are summarized below: • About $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC approved per-mile rate, as required by the Department’s NEMT Billing Manual and rate schedule. These claims were submitted directly to the Department by 10 PUC-permitted taxi providers. For example, the Department paid $4,000 to one taxi provider for what appeared to be four 400-mile one-way trips that were given to one recipient within a single day, which did not appear possible and was not paid based on taxi rates. The Department only required taxi providers to submit claims showing only the number of one-way trips driven, not the mileage, and paid the claims as long as they were not more than $1,000 per one-way trip. As a result, the Department lacked internal controls to ensure taxi claims were paid at the correct rates. After the 2021 audits, the Department lowered the maximum per one-way taxi trip within Colorado interChange from $1,000 to $500, but the Department did not implement other internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. • $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis, as required by the NEMT Billing Manual and rate schedule. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. After the 2021 audits, the Department implemented an internal control to help ensure providers submitting NEMT taxi claims are permitted to operate as taxis. • $4,718 paid for trips that may not have been to attend medical services. Our 2021 audits found that 13 of a sample of 22 NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips, and 6 of these 13 claims were for recipients who had both Medicaid and other types of medical insurance, such as Medicare. Department staff told us that it was possible that medical providers had not yet submitted medical claims yet, and that the six recipients may have used NEMT trips to access medical services but those services were paid by other insurance, as allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. After the 2021 audits, the Department implemented an internal control to help ensure NEMT services are used to attend medical appointments. • $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims in the 2021 OSA audit timeframe, the scheduled trips were not marked as complete in IntelliRide’s EcoLane transportation scheduling system, so we could not determine whether they had been completed. After the 2021 audits, the Department worked with IntelliRide to help ensure its system began maintaining complete information on rides. The Department is currently in the process of investigating NEMT fraud schemes. According to the Department, in Summer 2023 it uncovered an “unprecedented fraud scheme” occurring in the NEMT benefit, affecting “tens of thousands” of NEMT claims. For example, the Department identified an increase in suspicious NEMT billings and program violations, such as recipients receiving inappropriately long trips. The Department informed the OSA that, as of October 2023, it had issued 50 cease and desist letters to NEMT providers, placed 390 providers on pre-payment review, sent letters to providers with concerns of fraudulent behavior and steps taken, placed a moratorium on new NEMT provider applications—with approval of CMS—and, as a result, denied 632 NEMT provider applications. The Department told us that in addition to fraud schemes among NEMT providers, it is analyzing whether similar issues are occurring in different Medicaid provider types. The Department also informed the OSA that it is working with a number of entities, such as the Colorado Attorney General’s Office and its Medicaid Fraud Control Unit, the Colorado Department of Public Safety, county departments of human services, IntelliRide, CMS, the Office of the Inspector General, the Federal Bureau of Investigations, and other states experiencing NEMT fraud. The Department has posted alerts on its NEMT website to inform Medicaid members of potentially fraudulent NEMT practices. Why did these problems occur? The Department lacked sufficient internal controls to investigate questioned costs and to detect improper claims, payments, and provider applications. The Department did not investigate the $5.2 million in likely questioned costs identified by our 2021 audits by December 2022, as it stated it would do within its responses to the prior audit recommendation, demonstrating that the Department did not have sufficient processes in place to implement the recommendation in a timely manner. The Department also reported to us that due to the recent detection of fraud schemes by NEMT providers, the Department does not “have the resources to investigate the likely questioned costs identified in the report” and “is currently unable to follow through on the previous agreement.” The Department stated that once it completes activities related to the recently detected NEMT fraud schemes, it “will go back and review post-payment, if resources allow” that “may include the likely questioned costs.” The Department’s process will need to include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. Regarding the recent surge in NEMT fraud, the Department indicated that it has developed stronger internal controls to process applications from those seeking to provide NEMT services and to manage billing practices. For example, according to the Department, it is “updating [its NEMT] provider credentialing and billing processes” and conducting reviews to determine whether services and billing are in compliance with federal and state law. The Department stated that if its reviews reveal evidence of non-compliance or intentional fraud, the Department “will initiate additional actions, including but not limited to, referrals to law enforcement.” In the event that the Department identifies improper or overpayments to NEMT providers, it will need to recover those payments and repay the federal portion. Why do these problems matter? For the approximately $5.2 million in likely questioned costs identified in our 2021 Statewide and performance audits, the Department paid the NEMT claims, yet there was no supporting documentation or data from IntelliRide, ride providers, or the Department to substantiate that the costs of the claims were accurate, or that the rides complied with federal and state requirements. As such, there was a significant risk of misappropriation of federal and state funds by providers and/or recipients. While we did not identify confirmed fraud by providers or recipients at that time, due to the lack of supporting documentation for these claims, the problems identified by the prior audits demonstrate a potential waste of public funds and abuse of the Medicaid program. When the Department does not have sufficient internal controls in place to take timely action to investigate questionable claims, this can result in misuse of federal and state Medicaid funds. If the Department had started the recommended investigation in 2021 and completed it by the end of 2022, it may have been able to identify aspects of the NEMT provider fraud scheme and improper payments sooner than Summer 2023. Recommendation 2023-057 The Department of Health Care Policy and Financing (Department) should comply with federal and state requirements for administering the non-emergent medical transportation (NEMT) benefit, and for paying Colorado Medicaid Program claims by: A. Investigating the payments that the OSA’s 2021 Statewide and performance audits identified that resulted in likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. This process should include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. B. Continuing to investigate the overpayments and inappropriate payments that the Department identifies through its fraud investigations and that result in known or likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: August 2024 HCPF disagrees with the likely questioned costs identified and that it should review these claims. Because supporting documents were not available, the OSA had nothing to review for these claims and so determined that they were likely questioned costs. Of the claims the OSA had documentation to review, though, the documentation supported the claim and so the Department believes it is likely the missing documentation would support the claims as well. HCPF isn’t required to have the documentation up front, and it is the normal practice to pay claims and require the providers maintain the documentation, so this standard process should not create a presumption that the payments were in error. To review all these claims, HCPF would have to request each record from the provider, and the average review of an NEMT claim once the records have been received takes 15-30 minutes, so it would take an estimated 7,262.25-14,524.5 hours to review 29,049 claims. HCPF does it have existing resources to complete this review. HPCF agrees to review the claims where the OSA reviewed the records and determined that the claims were not paid properly. If an overpayment is identified, FFP will be returned as appropriate. We expect this project to be completed by 8/31/24. HCPF agrees with the taxi rate problem and is implementing internal controls to ensure taxi providers are paid appropriately by discontinuing the specific rate for taxi services and replacing it with the generic mileage rate. This will prevent inaccurate payments. HCPF is no longer required to pay taxi providers the rate stipulated by their individual PUC rate. We expect this project to be completed by 7/31/24. Auditor’s Addendum As noted in the audit finding, the Department, its NEMT contractor (IntelliRide), and ride providers did not have data or documentation to support $5.2 million in paid claims for NEMT services, as required. These unsupported payments resulted in likely questioned costs that the Department should investigate, in order to recover inappropriate payments and repay the federal portion, as appropriate. Further, the Department's response describing the audit work and results is incorrect. During the audit, the OSA reviewed all data and documentation that the Department, its NEMT contractor, and ride providers provided to the OSA, and identified $291,597 in known questioned costs for 4,503 claims because the amounts paid were not supported or the claims did not comply with federal or state requirements. For an additional about 29,100 NEMT claims totaling $5.2 million, audit analysis determined that the paid claims appeared noncompliant, and the Department reported that neither it, nor its NEMT contractor or ride providers, could provide support for these claims, which resulted in the likely questioned costs. In 2021 and 2022, the Department agreed that the lack of documentation to support the paid claims was a problem, and agreed to investigate. B. Partially Agree Implementation Date: July 2024 As the Department previously responded to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program. The Department has returned the FFP on the known questioned costs. As to the likely questioned costs, as mentioned in Part A, the Department cannot review every claim, however as previously stated the Department plans to conduct post-payment reviews on identified providers and service types that are suspected of having a high risk of improper payments, if resources allow, which may include reviewing claims identified by the OSA as likely questioned costs. Should the department identify an overpayment during said reviews, the department will return the FPP. Auditor’s Addendum As noted in the audit finding, the Department has reported a recent surge in NEMT fraud that the Department is investigating. In the event that the Department's investigations identify improper payments or overpayments that result in additional known or likely questioned costs besides those identified by the prior audit, the Department will need to recover those payments and repay the federal portion, as appropriate.
Show full finding ▾Hide full finding ▴Finding 2023-057 Payments for Non-Emergent Medical Transportation Claims Non-emergent medical transportation (NEMT) is a federally-required Medicaid benefit intended to provide recipients prompt, efficient, and medically-necessary transportation services to and from their Medicaid medical services [Section 42 USC 1396a(a)]. NEMT cannot be used as a convenience to the recipient, such as for a trip to a grocery store, or be used by non-recipients unless they are an escort for a recipient who is a child or an at-risk adult [10 CCR 2505-10 8.014.5.D.1]. NEMT is available to all individuals enrolled in Medicaid. Federal law allows states to provide NEMT services through state-designated entities, such as contracted brokers, as long as the brokers provide cost-effective administration and delivery of services for Medicaid recipients [Section 42 USC 1396a(a)(70)]. Brokers are generally responsible for verifying recipient eligibility for NEMT services, scheduling recipient transportation with ride providers, paying the providers for services, submitting Medicaid claims to the Department through Colorado interChange to cover the cost of services, and retaining supporting documentation for each Medicaid claim. Over the years, NEMT services in Colorado have been brokered in the following ways: • Prior to July 2020. For 55 counties, various county offices brokered NEMT services for Medicaid recipients. In the remaining nine counties, the Department contracted with IntelliRide to serve as the broker for NEMT services in those areas. IntelliRide is a division of TransDev North America and manages NEMT, demand response transportation, and paratransit programs across the country. • July 1, 2020 to August 31, 2021. For all 64 counties, the Department contracted with IntelliRide to be the broker for NEMT services; however, our 2021 audits found that the Department also paid about $3.5 million in NEMT claims directly to 66 providers who brokered their own services during the prior audit review period of July 2020 through February 2021. • September 1, 2021 to Present. The Department returned to having 55 counties broker NEMT services in their areas, and contracting with IntelliRide to serve as the NEMT broker in the remaining nine counties. For rides brokered by IntelliRide, providers upload trip information into IntelliRide’s EcoLane transportation scheduling system, which maintains information on recipients’ requests for rides; the names of the recipient and driver; and trip information, such as the trip date, scheduled pick-up time, and destination. In our Fiscal Year 2021 Statewide audit and 2021 NEMT performance audit, we identified $291,597 in known questioned costs and about $5.2 million in likely questioned costs related to NEMT services that did not comply with federal and state Medicaid requirements. We recommended that the Department investigate each questioned claim to recover any payments determined to be inappropriate, and repay the federal portion, as appropriate. Federal regulations define known questioned costs as questioned costs that are specifically identified by the auditor and define likely questioned costs as the auditor’s best estimate of total questioned costs [45 CFR 75.516]. Known and likely questioned costs should be investigated by the Department, inappropriate payments should be recovered, and those payments should be repaid to the federal government as appropriate; Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We also recommended that the Department implement controls to ensure taxi claims are paid in accordance with established requirements and rates. The Department agreed to implement these audit recommendations by December 2022. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department’s implementation of the Fiscal Year 2021 audit recommendations to (1) investigate the known and likely questioned costs identified by the audits, recover inappropriate payments, and repay the federal portion, as appropriate, and (2) implement controls to ensure taxi claims are paid in accordance with established requirements and rates. We reviewed documentation of the Department’s efforts to investigate and recover the known questioned costs identified in the prior audits, and repay the federal portion of the claims. We interviewed Department staff to understand the extent to which steps had been taken to investigate, recover, and repay the likely questioned costs identified. We reviewed Department documentation and interviewed Department staff to understand the internal controls that were implemented to help ensure taxi claims are paid in line with requirements and rates. We also reviewed Department documentation and online information about NEMT fraud schemes that the Department identified starting in Summer 2023. How were the results of the audit work measured? The Department must investigate questioned costs related to NEMT claims, recover inappropriate payments, and repay the federal portion, as appropriate. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls that provide reasonable assurance that the Department is managing federal funds in compliance with federal statutes, regulations, and federal program terms and conditions. A questioned cost is defined in Uniform Guidance [45 CFR 75.2] as “a cost that is questioned by the auditor … (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.…” Questioned costs can result in the misappropriation of federal and state funds. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments “are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....” According to federal law, states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share (also known as Federal Financial Participation or FFP) must be refunded to CMS, regardless of whether a recovery is made from the provider [42 USC 1396b]. The Department must have internal controls to pay claims based on accurate service rates and trip mileage. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which is generally based on trip mileage. According to the Department’s NEMT Billing Manual and rate schedule for 2021, taxi claims should have been paid at the rate set by the PUC. What problems did the audit work identify? The Department has not investigated and recovered as appropriate, the $5.2 million in likely questioned costs related to NEMT claims, or repaid the federal portion. Based on our testwork, we determined that the Department has not fully implemented the Statewide audit and performance audit recommendations from 2021 because it has not investigated the about $5.2 million in likely questioned costs identified by the audits, or attempted to recover and repay the federal portion of those questioned costs. As of June 30, 2023, the Department had investigated and recovered the $291,597 in known questioned costs and repaid the federal portion. In addition, the Department has not fully implemented internal controls to help ensure taxi claims are paid appropriately. The issues we identified in our 2021 Statewide and performance audits, which resulted in the likely questioned costs between July 2020 and February 2021(the prior audit period), are summarized below: • About $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC approved per-mile rate, as required by the Department’s NEMT Billing Manual and rate schedule. These claims were submitted directly to the Department by 10 PUC-permitted taxi providers. For example, the Department paid $4,000 to one taxi provider for what appeared to be four 400-mile one-way trips that were given to one recipient within a single day, which did not appear possible and was not paid based on taxi rates. The Department only required taxi providers to submit claims showing only the number of one-way trips driven, not the mileage, and paid the claims as long as they were not more than $1,000 per one-way trip. As a result, the Department lacked internal controls to ensure taxi claims were paid at the correct rates. After the 2021 audits, the Department lowered the maximum per one-way taxi trip within Colorado interChange from $1,000 to $500, but the Department did not implement other internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. • $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis, as required by the NEMT Billing Manual and rate schedule. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. After the 2021 audits, the Department implemented an internal control to help ensure providers submitting NEMT taxi claims are permitted to operate as taxis. • $4,718 paid for trips that may not have been to attend medical services. Our 2021 audits found that 13 of a sample of 22 NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips, and 6 of these 13 claims were for recipients who had both Medicaid and other types of medical insurance, such as Medicare. Department staff told us that it was possible that medical providers had not yet submitted medical claims yet, and that the six recipients may have used NEMT trips to access medical services but those services were paid by other insurance, as allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. After the 2021 audits, the Department implemented an internal control to help ensure NEMT services are used to attend medical appointments. • $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims in the 2021 OSA audit timeframe, the scheduled trips were not marked as complete in IntelliRide’s EcoLane transportation scheduling system, so we could not determine whether they had been completed. After the 2021 audits, the Department worked with IntelliRide to help ensure its system began maintaining complete information on rides. The Department is currently in the process of investigating NEMT fraud schemes. According to the Department, in Summer 2023 it uncovered an “unprecedented fraud scheme” occurring in the NEMT benefit, affecting “tens of thousands” of NEMT claims. For example, the Department identified an increase in suspicious NEMT billings and program violations, such as recipients receiving inappropriately long trips. The Department informed the OSA that, as of October 2023, it had issued 50 cease and desist letters to NEMT providers, placed 390 providers on pre-payment review, sent letters to providers with concerns of fraudulent behavior and steps taken, placed a moratorium on new NEMT provider applications—with approval of CMS—and, as a result, denied 632 NEMT provider applications. The Department told us that in addition to fraud schemes among NEMT providers, it is analyzing whether similar issues are occurring in different Medicaid provider types. The Department also informed the OSA that it is working with a number of entities, such as the Colorado Attorney General’s Office and its Medicaid Fraud Control Unit, the Colorado Department of Public Safety, county departments of human services, IntelliRide, CMS, the Office of the Inspector General, the Federal Bureau of Investigations, and other states experiencing NEMT fraud. The Department has posted alerts on its NEMT website to inform Medicaid members of potentially fraudulent NEMT practices. Why did these problems occur? The Department lacked sufficient internal controls to investigate questioned costs and to detect improper claims, payments, and provider applications. The Department did not investigate the $5.2 million in likely questioned costs identified by our 2021 audits by December 2022, as it stated it would do within its responses to the prior audit recommendation, demonstrating that the Department did not have sufficient processes in place to implement the recommendation in a timely manner. The Department also reported to us that due to the recent detection of fraud schemes by NEMT providers, the Department does not “have the resources to investigate the likely questioned costs identified in the report” and “is currently unable to follow through on the previous agreement.” The Department stated that once it completes activities related to the recently detected NEMT fraud schemes, it “will go back and review post-payment, if resources allow” that “may include the likely questioned costs.” The Department’s process will need to include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. Regarding the recent surge in NEMT fraud, the Department indicated that it has developed stronger internal controls to process applications from those seeking to provide NEMT services and to manage billing practices. For example, according to the Department, it is “updating [its NEMT] provider credentialing and billing processes” and conducting reviews to determine whether services and billing are in compliance with federal and state law. The Department stated that if its reviews reveal evidence of non-compliance or intentional fraud, the Department “will initiate additional actions, including but not limited to, referrals to law enforcement.” In the event that the Department identifies improper or overpayments to NEMT providers, it will need to recover those payments and repay the federal portion. Why do these problems matter? For the approximately $5.2 million in likely questioned costs identified in our 2021 Statewide and performance audits, the Department paid the NEMT claims, yet there was no supporting documentation or data from IntelliRide, ride providers, or the Department to substantiate that the costs of the claims were accurate, or that the rides complied with federal and state requirements. As such, there was a significant risk of misappropriation of federal and state funds by providers and/or recipients. While we did not identify confirmed fraud by providers or recipients at that time, due to the lack of supporting documentation for these claims, the problems identified by the prior audits demonstrate a potential waste of public funds and abuse of the Medicaid program. When the Department does not have sufficient internal controls in place to take timely action to investigate questionable claims, this can result in misuse of federal and state Medicaid funds. If the Department had started the recommended investigation in 2021 and completed it by the end of 2022, it may have been able to identify aspects of the NEMT provider fraud scheme and improper payments sooner than Summer 2023. Recommendation 2023-057 The Department of Health Care Policy and Financing (Department) should comply with federal and state requirements for administering the non-emergent medical transportation (NEMT) benefit, and for paying Colorado Medicaid Program claims by: A. Investigating the payments that the OSA’s 2021 Statewide and performance audits identified that resulted in likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. This process should include implementing internal controls to ensure taxi providers are paid based on their PUC-approved per-mile rates. B. Continuing to investigate the overpayments and inappropriate payments that the Department identifies through its fraud investigations and that result in known or likely questioned costs, recover inappropriate payments identified, and repay the federal portion, as appropriate. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: August 2024 HCPF disagrees with the likely questioned costs identified and that it should review these claims. Because supporting documents were not available, the OSA had nothing to review for these claims and so determined that they were likely questioned costs. Of the claims the OSA had documentation to review, though, the documentation supported the claim and so the Department believes it is likely the missing documentation would support the claims as well. HCPF isn’t required to have the documentation up front, and it is the normal practice to pay claims and require the providers maintain the documentation, so this standard process should not create a presumption that the payments were in error. To review all these claims, HCPF would have to request each record from the provider, and the average review of an NEMT claim once the records have been received takes 15-30 minutes, so it would take an estimated 7,262.25-14,524.5 hours to review 29,049 claims. HCPF does it have existing resources to complete this review. HPCF agrees to review the claims where the OSA reviewed the records and determined that the claims were not paid properly. If an overpayment is identified, FFP will be returned as appropriate. We expect this project to be completed by 8/31/24. HCPF agrees with the taxi rate problem and is implementing internal controls to ensure taxi providers are paid appropriately by discontinuing the specific rate for taxi services and replacing it with the generic mileage rate. This will prevent inaccurate payments. HCPF is no longer required to pay taxi providers the rate stipulated by their individual PUC rate. We expect this project to be completed by 7/31/24. Auditor’s Addendum As noted in the audit finding, the Department, its NEMT contractor (IntelliRide), and ride providers did not have data or documentation to support $5.2 million in paid claims for NEMT services, as required. These unsupported payments resulted in likely questioned costs that the Department should investigate, in order to recover inappropriate payments and repay the federal portion, as appropriate. Further, the Department's response describing the audit work and results is incorrect. During the audit, the OSA reviewed all data and documentation that the Department, its NEMT contractor, and ride providers provided to the OSA, and identified $291,597 in known questioned costs for 4,503 claims because the amounts paid were not supported or the claims did not comply with federal or state requirements. For an additional about 29,100 NEMT claims totaling $5.2 million, audit analysis determined that the paid claims appeared noncompliant, and the Department reported that neither it, nor its NEMT contractor or ride providers, could provide support for these claims, which resulted in the likely questioned costs. In 2021 and 2022, the Department agreed that the lack of documentation to support the paid claims was a problem, and agreed to investigate. B. Partially Agree Implementation Date: July 2024 As the Department previously responded to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program. The Department has returned the FFP on the known questioned costs. As to the likely questioned costs, as mentioned in Part A, the Department cannot review every claim, however as previously stated the Department plans to conduct post-payment reviews on identified providers and service types that are suspected of having a high risk of improper payments, if resources allow, which may include reviewing claims identified by the OSA as likely questioned costs. Should the department identify an overpayment during said reviews, the department will return the FPP. Auditor’s Addendum As noted in the audit finding, the Department has reported a recent surge in NEMT fraud that the Department is investigating. In the event that the Department's investigations identify improper payments or overpayments that result in additional known or likely questioned costs besides those identified by the prior audit, the Department will need to recover those payments and repay the federal portion, as appropriate.
As the Department previously responded to the OSA, the Department will continue to investigate NEMT billing and payments through pre-payment reviews and suspected fraud investigations, and it will further revise rules and policy as needed in order to avoid improper claims payments and to ensure there are improved controls over the NEMT program. The Department has returned the FFP on the known questioned costs. As to the likely questioned costs, as mentioned in Part A, the Department cannot review every claim, however as previously stated the Department plans to conduct post-payment reviews on identified providers and service types that are suspected of having a high risk of improper payments, if resources allow, which may include reviewing claims identified by the OSA as likely questioned costs. Should the department identify an overpayment during said reviews, the department will return the FPP.
2022-047
Finding 2023-058 and 2023-059 Higher Education Emergency Relief Fund (HEERF) Allowable Costs and Activities Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. The Department of Education (ED) provided institutions of higher education significant flexibilities in how the HEERF funding could be spent. ED issued guidance in the form of “Frequently Asked Questions” (FAQ) which describe the specifics of how the funds could be use and what types of costs are allowable under the program. The FAQ allows for the following types of expenditures to be applied to the Institutional portion: • Indirect Costs. Indirect costs are general management costs (i.e., activities for the direction and control of the organization as a whole). General management costs consist of costs for administrative activities necessary for the general operation of the agency, such as accounting, budgeting, payroll preparation, personnel services, purchasing, and centralized data processing. Conversely, direct costs are costs that provide measurable, direct benefits to a particular program or grant. Indirect costs are charged to a grant via the use of an indirect cost rate, which is the percentage of an organization’s indirect costs to its direct costs and is a standardized method of charging individual programs for their share of indirect costs. The indirect cost rate is established through either a federally negotiated rate or is outlined in the grant agreement. The indirect cost rate agreement establishes the base of direct costs that the indirect rate is to be applied. • Lost Revenue. Lost revenue refers to those revenues an institution of higher education otherwise expected but that were reduced or eliminated as a result of the COVID-19 pandemic. As such, lost revenues can only be estimated. Sources of lost revenue reimbursable under the program include both academic and auxiliary sources. ED provided guidelines and criteria around how institutions should calculate their estimated lost revenue. The FAQs do not specify how institutions are required to calculate their lost revenue. Accordingly, per the FAQ, institutions have flexibility to reasonably calculate their estimated lost revenue. Example baselines that an institution could use include: o A year-over-year comparison using the prior year; o A semester-over-semester comparison using the prior year semester (fall 2019 compared to fall 2020 or summer term 2019 compared to summer term 2020); o A comparison using a 3- or 5-year combined average revenue as baseline revenue; o A comparison to previously budgeted revenue or projected revenue for the period; or o A comparison with a baseline year of a fiscal year prior to the March 13, 2020 national emergency declaration, such as the fiscal year from July 1, 2018 – June 30, 2019. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023. In total, the System charged $42.7 million through 6,254 transactions to the HEERF grant during Fiscal Year 2023. As part of our audit work, we tested a random sample of 44 expenditure transactions charged to the HEERF program across eight schools totaling $15.2 million to determine whether the costs were allowable under the HEERF program and whether they complied with federal regulations. Specifically, we tested these transactions to determine whether the System used the proper indirect cost rate and whether it only applied the indirect cost rate to the direct cost base listed in the indirect cost rate agreement. In addition, we performed testing to determine whether the estimated lost revenues were calculated within the guidelines established by ED. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the System’s campuses, as federal grant recipients, must “establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.” • The System’s internal control procedure requires that all federal grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and the supporting documentation must be reviewed for appropriateness and allowability under the applicable federal grant program by two individuals. • The HEERF Lost Revenue Frequently Asked Questions (FAQ) published on March 19, 2021 established how lost revenues are to be calculated. Specifically, FAQ 9 states that, consistent with the cost principles of the Uniform Guidance (2 CFR part 200 subpart E), the calculation of lost revenues must: o Be accorded consistent treatment (e.g., if using the institution’s fiscal year as a baseline, the institution must estimate lost revenue over the course of a fiscal year); o Measure the amount of baseline revenue and lost revenue consistently (e.g., an apples-to-apples comparison); o Be consistent with policies and procedures that apply uniformly to federally-financed and other activities of the institution; o Not include the estimated amount of lost revenue for the HEERF programs in the calculation of lost revenue for another Federal program, such as the CARES Act Provider Relief Fund (i.e., no double-dipping); and o Not include any refunds previously provided to students in the institution’s estimate of lost revenue. • Within the Higher Education Emergency Relief Fund III Frequently Asked Questions published on May 11, 2021, FAQ 43 stated that indirect costs may be charged only to Institutional Portion awards, both new and supplemental, and may not be charged to any student grant awards because the student allocation represents an amount of funds that must be distributed to students. The allowed indirect cost rate will be the on-campus rate specified in an institution’s negotiated indirect cost rate agreement or, if an institution does not have a current negotiated indirect cost rate with its cognizant agency, it may use the de minimis rate of 10 percent as allowed by the Uniform Guidance. o Community College of Aurora (CCA) has an indirect cost rate agreement which allows an indirect cost rate of 25 percent to be applied to a base of direct salaries and wages including fringe benefits. What problems did the audit work identify? We identified two transactions out of the 44 expenditure transactions tested (5 percent) that did not meet the requirements of the HEERF grant. Specifically, we identified the following: • The Community College of Aurora (CCA) incorrectly applied its 25 percent indirect cost rate to its total operating costs of $431,633, rather than applying it only to the $254,807 salaries and benefits portion of its operating costs, as required by its indirect cost rate agreement. Therefore, CCA incorrectly recorded $107,908 as indirect costs to its HEERF grant, rather than $63,701. This resulted in a total of $44,207 in questioned costs. • Pueblo Community College (PCC) incorrectly calculated lost revenue associated with tuition. Specifically, PCC used the incorrect baseline of full-time-equivalent students to calculate lost revenue, which was inconsistent with PCC’s previous use of total tuition revenue as a baseline in its lost revenue calculation. Due to the error, PCC incorrectly calculated a lost revenue amount of $1,351,850 rather than $1,256,818. This error was caught by internal audit in a subsequent review of the HEERF program, but the error was not corrected by PCC until Fiscal Year 2024. This resulted in a total of $95,032 in questioned costs. Why did these problems occur? CCA and PCC did not have adequate internal controls over federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023 and did not perform an adequate review of the costs charged to the program. Specifically: • CCA did not adequately review transactions charged to the grant to ensure that the indirect cost rate was only applied to salaries and benefits as defined in its indirect cost rate agreement. • PCC did not adequately review the lost revenue calculation to ensure that the correct baseline for the calculation was used for Fiscal Year 2023. Why do these problems matter? CCA’s and PCC’s failure to ensure compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program. Recommendation 2023-058 The Community College of Aurora (CCA) should strengthen its internal controls over, and ensure it complies with, the Higher Education Emergency Relief Fund (HEERF) program requirements by performing adequate reviews over costs charged to the HEERF grant to ensure it applies the indirect cost rate only to salaries and benefits, as defined in its federal indirect cost rate agreement. Response Community College of Aurora Agree Implementation Date: November 2023 An adjusting entry was made to the grant in September 2023 to reduce costs incurred of $44,206.68, thus reducing the subsequent drawdown of grant funds by $44,206.68. CCA will ensure the Grant Director will review charges to this award and all our federal grants before each draw or at least on a quarterly basis. The review will be discussed with the Controller for additional assurance of propriety of allowability and accuracy of the calculations.
Show full finding ▾Hide full finding ▴Finding 2023-058 and 2023-059 Higher Education Emergency Relief Fund (HEERF) Allowable Costs and Activities Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. The Department of Education (ED) provided institutions of higher education significant flexibilities in how the HEERF funding could be spent. ED issued guidance in the form of “Frequently Asked Questions” (FAQ) which describe the specifics of how the funds could be use and what types of costs are allowable under the program. The FAQ allows for the following types of expenditures to be applied to the Institutional portion: • Indirect Costs. Indirect costs are general management costs (i.e., activities for the direction and control of the organization as a whole). General management costs consist of costs for administrative activities necessary for the general operation of the agency, such as accounting, budgeting, payroll preparation, personnel services, purchasing, and centralized data processing. Conversely, direct costs are costs that provide measurable, direct benefits to a particular program or grant. Indirect costs are charged to a grant via the use of an indirect cost rate, which is the percentage of an organization’s indirect costs to its direct costs and is a standardized method of charging individual programs for their share of indirect costs. The indirect cost rate is established through either a federally negotiated rate or is outlined in the grant agreement. The indirect cost rate agreement establishes the base of direct costs that the indirect rate is to be applied. • Lost Revenue. Lost revenue refers to those revenues an institution of higher education otherwise expected but that were reduced or eliminated as a result of the COVID-19 pandemic. As such, lost revenues can only be estimated. Sources of lost revenue reimbursable under the program include both academic and auxiliary sources. ED provided guidelines and criteria around how institutions should calculate their estimated lost revenue. The FAQs do not specify how institutions are required to calculate their lost revenue. Accordingly, per the FAQ, institutions have flexibility to reasonably calculate their estimated lost revenue. Example baselines that an institution could use include: o A year-over-year comparison using the prior year; o A semester-over-semester comparison using the prior year semester (fall 2019 compared to fall 2020 or summer term 2019 compared to summer term 2020); o A comparison using a 3- or 5-year combined average revenue as baseline revenue; o A comparison to previously budgeted revenue or projected revenue for the period; or o A comparison with a baseline year of a fiscal year prior to the March 13, 2020 national emergency declaration, such as the fiscal year from July 1, 2018 – June 30, 2019. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023. In total, the System charged $42.7 million through 6,254 transactions to the HEERF grant during Fiscal Year 2023. As part of our audit work, we tested a random sample of 44 expenditure transactions charged to the HEERF program across eight schools totaling $15.2 million to determine whether the costs were allowable under the HEERF program and whether they complied with federal regulations. Specifically, we tested these transactions to determine whether the System used the proper indirect cost rate and whether it only applied the indirect cost rate to the direct cost base listed in the indirect cost rate agreement. In addition, we performed testing to determine whether the estimated lost revenues were calculated within the guidelines established by ED. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the System’s campuses, as federal grant recipients, must “establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.” • The System’s internal control procedure requires that all federal grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and the supporting documentation must be reviewed for appropriateness and allowability under the applicable federal grant program by two individuals. • The HEERF Lost Revenue Frequently Asked Questions (FAQ) published on March 19, 2021 established how lost revenues are to be calculated. Specifically, FAQ 9 states that, consistent with the cost principles of the Uniform Guidance (2 CFR part 200 subpart E), the calculation of lost revenues must: o Be accorded consistent treatment (e.g., if using the institution’s fiscal year as a baseline, the institution must estimate lost revenue over the course of a fiscal year); o Measure the amount of baseline revenue and lost revenue consistently (e.g., an apples-to-apples comparison); o Be consistent with policies and procedures that apply uniformly to federally-financed and other activities of the institution; o Not include the estimated amount of lost revenue for the HEERF programs in the calculation of lost revenue for another Federal program, such as the CARES Act Provider Relief Fund (i.e., no double-dipping); and o Not include any refunds previously provided to students in the institution’s estimate of lost revenue. • Within the Higher Education Emergency Relief Fund III Frequently Asked Questions published on May 11, 2021, FAQ 43 stated that indirect costs may be charged only to Institutional Portion awards, both new and supplemental, and may not be charged to any student grant awards because the student allocation represents an amount of funds that must be distributed to students. The allowed indirect cost rate will be the on-campus rate specified in an institution’s negotiated indirect cost rate agreement or, if an institution does not have a current negotiated indirect cost rate with its cognizant agency, it may use the de minimis rate of 10 percent as allowed by the Uniform Guidance. o Community College of Aurora (CCA) has an indirect cost rate agreement which allows an indirect cost rate of 25 percent to be applied to a base of direct salaries and wages including fringe benefits. What problems did the audit work identify? We identified two transactions out of the 44 expenditure transactions tested (5 percent) that did not meet the requirements of the HEERF grant. Specifically, we identified the following: • The Community College of Aurora (CCA) incorrectly applied its 25 percent indirect cost rate to its total operating costs of $431,633, rather than applying it only to the $254,807 salaries and benefits portion of its operating costs, as required by its indirect cost rate agreement. Therefore, CCA incorrectly recorded $107,908 as indirect costs to its HEERF grant, rather than $63,701. This resulted in a total of $44,207 in questioned costs. • Pueblo Community College (PCC) incorrectly calculated lost revenue associated with tuition. Specifically, PCC used the incorrect baseline of full-time-equivalent students to calculate lost revenue, which was inconsistent with PCC’s previous use of total tuition revenue as a baseline in its lost revenue calculation. Due to the error, PCC incorrectly calculated a lost revenue amount of $1,351,850 rather than $1,256,818. This error was caught by internal audit in a subsequent review of the HEERF program, but the error was not corrected by PCC until Fiscal Year 2024. This resulted in a total of $95,032 in questioned costs. Why did these problems occur? CCA and PCC did not have adequate internal controls over federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023 and did not perform an adequate review of the costs charged to the program. Specifically: • CCA did not adequately review transactions charged to the grant to ensure that the indirect cost rate was only applied to salaries and benefits as defined in its indirect cost rate agreement. • PCC did not adequately review the lost revenue calculation to ensure that the correct baseline for the calculation was used for Fiscal Year 2023. Why do these problems matter? CCA’s and PCC’s failure to ensure compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program. Recommendation 2023-058 The Community College of Aurora (CCA) should strengthen its internal controls over, and ensure it complies with, the Higher Education Emergency Relief Fund (HEERF) program requirements by performing adequate reviews over costs charged to the HEERF grant to ensure it applies the indirect cost rate only to salaries and benefits, as defined in its federal indirect cost rate agreement. Response Community College of Aurora Agree Implementation Date: November 2023 An adjusting entry was made to the grant in September 2023 to reduce costs incurred of $44,206.68, thus reducing the subsequent drawdown of grant funds by $44,206.68. CCA will ensure the Grant Director will review charges to this award and all our federal grants before each draw or at least on a quarterly basis. The review will be discussed with the Controller for additional assurance of propriety of allowability and accuracy of the calculations.
An adjusting entry was made to the grant in September 2023 to reduce costs incurred of $44,206.68, thus reducing the subsequent drawdown of grant funds by $44,206.68. CCA will ensure the Grant Director will review charges to this award and all our federal grants before each draw or at least on a quarterly basis. The review will be discussed with the Controller for additional assurance of propriety of allowability and accuracy of the calculations.
Finding 2023-058 and 2023-059 Higher Education Emergency Relief Fund (HEERF) Allowable Costs and Activities Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. The Department of Education (ED) provided institutions of higher education significant flexibilities in how the HEERF funding could be spent. ED issued guidance in the form of “Frequently Asked Questions” (FAQ) which describe the specifics of how the funds could be use and what types of costs are allowable under the program. The FAQ allows for the following types of expenditures to be applied to the Institutional portion: • Indirect Costs. Indirect costs are general management costs (i.e., activities for the direction and control of the organization as a whole). General management costs consist of costs for administrative activities necessary for the general operation of the agency, such as accounting, budgeting, payroll preparation, personnel services, purchasing, and centralized data processing. Conversely, direct costs are costs that provide measurable, direct benefits to a particular program or grant. Indirect costs are charged to a grant via the use of an indirect cost rate, which is the percentage of an organization’s indirect costs to its direct costs and is a standardized method of charging individual programs for their share of indirect costs. The indirect cost rate is established through either a federally negotiated rate or is outlined in the grant agreement. The indirect cost rate agreement establishes the base of direct costs that the indirect rate is to be applied. • Lost Revenue. Lost revenue refers to those revenues an institution of higher education otherwise expected but that were reduced or eliminated as a result of the COVID-19 pandemic. As such, lost revenues can only be estimated. Sources of lost revenue reimbursable under the program include both academic and auxiliary sources. ED provided guidelines and criteria around how institutions should calculate their estimated lost revenue. The FAQs do not specify how institutions are required to calculate their lost revenue. Accordingly, per the FAQ, institutions have flexibility to reasonably calculate their estimated lost revenue. Example baselines that an institution could use include: o A year-over-year comparison using the prior year; o A semester-over-semester comparison using the prior year semester (fall 2019 compared to fall 2020 or summer term 2019 compared to summer term 2020); o A comparison using a 3- or 5-year combined average revenue as baseline revenue; o A comparison to previously budgeted revenue or projected revenue for the period; or o A comparison with a baseline year of a fiscal year prior to the March 13, 2020 national emergency declaration, such as the fiscal year from July 1, 2018 – June 30, 2019. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023. In total, the System charged $42.7 million through 6,254 transactions to the HEERF grant during Fiscal Year 2023. As part of our audit work, we tested a random sample of 44 expenditure transactions charged to the HEERF program across eight schools totaling $15.2 million to determine whether the costs were allowable under the HEERF program and whether they complied with federal regulations. Specifically, we tested these transactions to determine whether the System used the proper indirect cost rate and whether it only applied the indirect cost rate to the direct cost base listed in the indirect cost rate agreement. In addition, we performed testing to determine whether the estimated lost revenues were calculated within the guidelines established by ED. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the System’s campuses, as federal grant recipients, must “establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.” • The System’s internal control procedure requires that all federal grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and the supporting documentation must be reviewed for appropriateness and allowability under the applicable federal grant program by two individuals. • The HEERF Lost Revenue Frequently Asked Questions (FAQ) published on March 19, 2021 established how lost revenues are to be calculated. Specifically, FAQ 9 states that, consistent with the cost principles of the Uniform Guidance (2 CFR part 200 subpart E), the calculation of lost revenues must: o Be accorded consistent treatment (e.g., if using the institution’s fiscal year as a baseline, the institution must estimate lost revenue over the course of a fiscal year); o Measure the amount of baseline revenue and lost revenue consistently (e.g., an apples-to-apples comparison); o Be consistent with policies and procedures that apply uniformly to federally-financed and other activities of the institution; o Not include the estimated amount of lost revenue for the HEERF programs in the calculation of lost revenue for another Federal program, such as the CARES Act Provider Relief Fund (i.e., no double-dipping); and o Not include any refunds previously provided to students in the institution’s estimate of lost revenue. • Within the Higher Education Emergency Relief Fund III Frequently Asked Questions published on May 11, 2021, FAQ 43 stated that indirect costs may be charged only to Institutional Portion awards, both new and supplemental, and may not be charged to any student grant awards because the student allocation represents an amount of funds that must be distributed to students. The allowed indirect cost rate will be the on-campus rate specified in an institution’s negotiated indirect cost rate agreement or, if an institution does not have a current negotiated indirect cost rate with its cognizant agency, it may use the de minimis rate of 10 percent as allowed by the Uniform Guidance. o Community College of Aurora (CCA) has an indirect cost rate agreement which allows an indirect cost rate of 25 percent to be applied to a base of direct salaries and wages including fringe benefits. What problems did the audit work identify? We identified two transactions out of the 44 expenditure transactions tested (5 percent) that did not meet the requirements of the HEERF grant. Specifically, we identified the following: • The Community College of Aurora (CCA) incorrectly applied its 25 percent indirect cost rate to its total operating costs of $431,633, rather than applying it only to the $254,807 salaries and benefits portion of its operating costs, as required by its indirect cost rate agreement. Therefore, CCA incorrectly recorded $107,908 as indirect costs to its HEERF grant, rather than $63,701. This resulted in a total of $44,207 in questioned costs. • Pueblo Community College (PCC) incorrectly calculated lost revenue associated with tuition. Specifically, PCC used the incorrect baseline of full-time-equivalent students to calculate lost revenue, which was inconsistent with PCC’s previous use of total tuition revenue as a baseline in its lost revenue calculation. Due to the error, PCC incorrectly calculated a lost revenue amount of $1,351,850 rather than $1,256,818. This error was caught by internal audit in a subsequent review of the HEERF program, but the error was not corrected by PCC until Fiscal Year 2024. This resulted in a total of $95,032 in questioned costs. Why did these problems occur? CCA and PCC did not have adequate internal controls over federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023 and did not perform an adequate review of the costs charged to the program. Specifically: • CCA did not adequately review transactions charged to the grant to ensure that the indirect cost rate was only applied to salaries and benefits as defined in its indirect cost rate agreement. • PCC did not adequately review the lost revenue calculation to ensure that the correct baseline for the calculation was used for Fiscal Year 2023. Why do these problems matter? CCA’s and PCC’s failure to ensure compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program. Recommendation 2023-059 Pueblo Community College (PCC) should strengthen its internal controls over, and ensure it complies with, the Higher Education Emergency Relief Fund (HEERF) program requirements by performing adequate reviews over its lost revenue calculations to ensure it uses the appropriate base in all future calculations. Response Pueblo Community College Agree Implementation Date: June 2024 The Vice President of Finance and Administration will review all HEERF revenue recovery entries for propriety in methodology and accuracy. The Fiscal Year 2023 calculation that was overstated was revised in Fiscal Year 2024, and the federal draw will be reduced for the correction prior to June 30, 2024.
Show full finding ▾Hide full finding ▴Finding 2023-058 and 2023-059 Higher Education Emergency Relief Fund (HEERF) Allowable Costs and Activities Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. The Department of Education (ED) provided institutions of higher education significant flexibilities in how the HEERF funding could be spent. ED issued guidance in the form of “Frequently Asked Questions” (FAQ) which describe the specifics of how the funds could be use and what types of costs are allowable under the program. The FAQ allows for the following types of expenditures to be applied to the Institutional portion: • Indirect Costs. Indirect costs are general management costs (i.e., activities for the direction and control of the organization as a whole). General management costs consist of costs for administrative activities necessary for the general operation of the agency, such as accounting, budgeting, payroll preparation, personnel services, purchasing, and centralized data processing. Conversely, direct costs are costs that provide measurable, direct benefits to a particular program or grant. Indirect costs are charged to a grant via the use of an indirect cost rate, which is the percentage of an organization’s indirect costs to its direct costs and is a standardized method of charging individual programs for their share of indirect costs. The indirect cost rate is established through either a federally negotiated rate or is outlined in the grant agreement. The indirect cost rate agreement establishes the base of direct costs that the indirect rate is to be applied. • Lost Revenue. Lost revenue refers to those revenues an institution of higher education otherwise expected but that were reduced or eliminated as a result of the COVID-19 pandemic. As such, lost revenues can only be estimated. Sources of lost revenue reimbursable under the program include both academic and auxiliary sources. ED provided guidelines and criteria around how institutions should calculate their estimated lost revenue. The FAQs do not specify how institutions are required to calculate their lost revenue. Accordingly, per the FAQ, institutions have flexibility to reasonably calculate their estimated lost revenue. Example baselines that an institution could use include: o A year-over-year comparison using the prior year; o A semester-over-semester comparison using the prior year semester (fall 2019 compared to fall 2020 or summer term 2019 compared to summer term 2020); o A comparison using a 3- or 5-year combined average revenue as baseline revenue; o A comparison to previously budgeted revenue or projected revenue for the period; or o A comparison with a baseline year of a fiscal year prior to the March 13, 2020 national emergency declaration, such as the fiscal year from July 1, 2018 – June 30, 2019. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023. In total, the System charged $42.7 million through 6,254 transactions to the HEERF grant during Fiscal Year 2023. As part of our audit work, we tested a random sample of 44 expenditure transactions charged to the HEERF program across eight schools totaling $15.2 million to determine whether the costs were allowable under the HEERF program and whether they complied with federal regulations. Specifically, we tested these transactions to determine whether the System used the proper indirect cost rate and whether it only applied the indirect cost rate to the direct cost base listed in the indirect cost rate agreement. In addition, we performed testing to determine whether the estimated lost revenues were calculated within the guidelines established by ED. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] states that the System’s campuses, as federal grant recipients, must “establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.” • The System’s internal control procedure requires that all federal grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and the supporting documentation must be reviewed for appropriateness and allowability under the applicable federal grant program by two individuals. • The HEERF Lost Revenue Frequently Asked Questions (FAQ) published on March 19, 2021 established how lost revenues are to be calculated. Specifically, FAQ 9 states that, consistent with the cost principles of the Uniform Guidance (2 CFR part 200 subpart E), the calculation of lost revenues must: o Be accorded consistent treatment (e.g., if using the institution’s fiscal year as a baseline, the institution must estimate lost revenue over the course of a fiscal year); o Measure the amount of baseline revenue and lost revenue consistently (e.g., an apples-to-apples comparison); o Be consistent with policies and procedures that apply uniformly to federally-financed and other activities of the institution; o Not include the estimated amount of lost revenue for the HEERF programs in the calculation of lost revenue for another Federal program, such as the CARES Act Provider Relief Fund (i.e., no double-dipping); and o Not include any refunds previously provided to students in the institution’s estimate of lost revenue. • Within the Higher Education Emergency Relief Fund III Frequently Asked Questions published on May 11, 2021, FAQ 43 stated that indirect costs may be charged only to Institutional Portion awards, both new and supplemental, and may not be charged to any student grant awards because the student allocation represents an amount of funds that must be distributed to students. The allowed indirect cost rate will be the on-campus rate specified in an institution’s negotiated indirect cost rate agreement or, if an institution does not have a current negotiated indirect cost rate with its cognizant agency, it may use the de minimis rate of 10 percent as allowed by the Uniform Guidance. o Community College of Aurora (CCA) has an indirect cost rate agreement which allows an indirect cost rate of 25 percent to be applied to a base of direct salaries and wages including fringe benefits. What problems did the audit work identify? We identified two transactions out of the 44 expenditure transactions tested (5 percent) that did not meet the requirements of the HEERF grant. Specifically, we identified the following: • The Community College of Aurora (CCA) incorrectly applied its 25 percent indirect cost rate to its total operating costs of $431,633, rather than applying it only to the $254,807 salaries and benefits portion of its operating costs, as required by its indirect cost rate agreement. Therefore, CCA incorrectly recorded $107,908 as indirect costs to its HEERF grant, rather than $63,701. This resulted in a total of $44,207 in questioned costs. • Pueblo Community College (PCC) incorrectly calculated lost revenue associated with tuition. Specifically, PCC used the incorrect baseline of full-time-equivalent students to calculate lost revenue, which was inconsistent with PCC’s previous use of total tuition revenue as a baseline in its lost revenue calculation. Due to the error, PCC incorrectly calculated a lost revenue amount of $1,351,850 rather than $1,256,818. This error was caught by internal audit in a subsequent review of the HEERF program, but the error was not corrected by PCC until Fiscal Year 2024. This resulted in a total of $95,032 in questioned costs. Why did these problems occur? CCA and PCC did not have adequate internal controls over federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2023 and did not perform an adequate review of the costs charged to the program. Specifically: • CCA did not adequately review transactions charged to the grant to ensure that the indirect cost rate was only applied to salaries and benefits as defined in its indirect cost rate agreement. • PCC did not adequately review the lost revenue calculation to ensure that the correct baseline for the calculation was used for Fiscal Year 2023. Why do these problems matter? CCA’s and PCC’s failure to ensure compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program. Recommendation 2023-059 Pueblo Community College (PCC) should strengthen its internal controls over, and ensure it complies with, the Higher Education Emergency Relief Fund (HEERF) program requirements by performing adequate reviews over its lost revenue calculations to ensure it uses the appropriate base in all future calculations. Response Pueblo Community College Agree Implementation Date: June 2024 The Vice President of Finance and Administration will review all HEERF revenue recovery entries for propriety in methodology and accuracy. The Fiscal Year 2023 calculation that was overstated was revised in Fiscal Year 2024, and the federal draw will be reduced for the correction prior to June 30, 2024.
The Vice President of Finance and Administration will review all HEERF revenue recovery entries for propriety in methodology and accuracy. The Fiscal Year 2023 calculation that was overstated was revised in Fiscal Year 2024, and the federal draw will be reduced for the correction prior to June 30, 2024.
Finding 2023-060 Higher Education Emergency Relief Fund (HEERF) Suspension and Debarment Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion; of this amount, $10.4 million represented the System’s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. Each of the System’s 13 campuses separately signed an agreement titled the “Certification and Agreement” with the U.S. Department of Education (ED) to indicate each campus’ acceptance of the HEERF funding and the applicable terms and requirements. Under federal suspension and debarment regulations, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. “Covered transactions” include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the entity’s contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System’s campuses had effective internal controls in place over, and complied with, federal suspension and debarment requirements for the HEERF grant during Fiscal Year 2023. The System had 120 HEERF-related covered transactions totaling $10.4 million. As part of our audit work, we reviewed the campuses’ internal controls over the HEERF grant suspension and debarment requirements. In addition, we tested a sample of 40 covered transactions totaling $8.1 million of the campuses’ HEERF-related covered transactions, to determine whether the campuses’ contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing or certification obtained from the entity. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System’s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. What problem did the audit work identify? We identified errors in 9 of the 40 transactions tested (23 percent). Specifically, we identified the following: Community College of Denver (CCD), Front Range Community College (FRCC) and Pikes Peak State College (PPSC) could not provide documentation to support that suspension and debarment verification procedures were performed. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. Why did this problem occur? CCD, FRCC, and PPSC did not have documented policies and procedures for complying with suspension and debarment requirements. Specifically, they did not have a policy stating how they would comply with suspension and debarment requirements. Further, CCD, FRCC, and PPSC experienced staff turnover in key positions, and existing employees could not locate documentation that staff checked the SAM exclusion website, or that they obtained certification from their contracted entities. Why does this problem matter? CCD, FRCC, and PPSC’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-060 Community College of Denver (CCD), Front Range Community College (FRCC) and Pikes Peak State College (PPSC) should strengthen their internal controls over and ensure they comply with suspension and debarment requirements for the Higher Education Emergency Relief Fund (HEERF) grant by: A. Developing, documenting, and implementing a policy to comply with suspension and debarment using one of the three allowable methods: (1) checking the federal System of Award Management (SAM) website exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. B. Providing training and cross-training to existing employees over the new policies and procedures to reduce impacts of turnover. Response Community College of Denver Agree Implementation Date: December 2023 A. CCD will implement the following controls for monitoring the spending of the federal funds. 1) The Purchasing Coordinator will verify vendor suspension and debarment on the sam.gov website for purchases above $5,000. 2) Purchasing will attach the System of Award Management (SAM) verification to the purchase requisition packet of every requisition related to a grant fund. 3) Purchasing will ensure to include the grants manager as they send the purchase requisition for authorizing signatures, and 4) the Grants Manager will review the supporting documentation and confirm that the suspension/disbarment screenshot is included with the federal purchases. B. The Contracts and Procurement Manager and the Budget Director who supervises the purchasing will provide training to the purchasing staff and the grants personnel: Grants Manager, Sr. Grants Accountant and a Grant Accountant. The Controller will ensure that new policies and procedures are shared with the purchasing and grants staff, and new employees in those roles are trained accordingly. Response Front Range Community College Agree Implementation Date: December 2023 A. FRCC will implement the following controls for expending of federal funds. 1) When a purchase order greater than $25,000 is submitted, the grant accountant will cross check the vendor to the debarment list prior to approving the purchase order. The grant accountant will save a screenshot of the debarment check for documentation purposes. 2) During month end, the grant accountant will review all expenditures of federal funds greater than $25,000 and ensure that a debarment check has been completed and documentation has been maintained. B. Controller will review and train the Grant accountants (2), Grant Senior accountant (1) on the new policy and procedures. Response Pikes Peak State College Agree Implementation Date: December 2023 A. Regarding expenditures of federal funds at PPSC, Procurement Office will follow established internal guidelines regarding suspension and debarment regulations by checking the federal System of Award Management (SAM) website and documenting results with a screenshot. An additional step will be added to the current process, with Procurement staff verifying expenditures of federal funds through a review of federal grants and approved delegations. Controller will maintain a list of current federal grants and provide to Procurement Office. B. Director of Procurement and Contracts will provide training to Procurement Office staff and grant personnel on the new process step. Also, Controller will incorporate suspension and debarment requirements into training with grant personnel.
Show full finding ▾Hide full finding ▴Finding 2023-060 Higher Education Emergency Relief Fund (HEERF) Suspension and Debarment Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [Assistance Listing No. 84.425]. The HEERF program contains two portions: the Student Aid portion [Assistance Listing No. 84.425E] and the Institutional portion, which is made up of the following: • HEERF Institutional Aid Portion [Assistance Listing No. 84.425F]; • HEERF Minority Serving Institutions [Assistance Listing No. 84.425L]; • HEERF Strengthening Institutions Program [Assistance Listing No. 84.425M]; • Institutional Resilience and Expanded Postsecondary Opportunity [Assistance Listing No. 84.425P]; • HEERF Supplemental Assistance to Institutions of Higher Education program [Assistance Listing No. 84.425S]. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2023, the System spent a total of approximately $106.5 million for the HEERF program Student Aid portion and $148.9 million for the HEERF Institutional portion. During Fiscal Year 2023, the System spent $8.6 million for the Student Aid portion and $35.0 million for the Institutional portion; of this amount, $10.4 million represented the System’s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2024. Each of the System’s 13 campuses separately signed an agreement titled the “Certification and Agreement” with the U.S. Department of Education (ED) to indicate each campus’ acceptance of the HEERF funding and the applicable terms and requirements. Under federal suspension and debarment regulations, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. “Covered transactions” include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the entity’s contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System’s campuses had effective internal controls in place over, and complied with, federal suspension and debarment requirements for the HEERF grant during Fiscal Year 2023. The System had 120 HEERF-related covered transactions totaling $10.4 million. As part of our audit work, we reviewed the campuses’ internal controls over the HEERF grant suspension and debarment requirements. In addition, we tested a sample of 40 covered transactions totaling $8.1 million of the campuses’ HEERF-related covered transactions, to determine whether the campuses’ contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing or certification obtained from the entity. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System’s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. What problem did the audit work identify? We identified errors in 9 of the 40 transactions tested (23 percent). Specifically, we identified the following: Community College of Denver (CCD), Front Range Community College (FRCC) and Pikes Peak State College (PPSC) could not provide documentation to support that suspension and debarment verification procedures were performed. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. Why did this problem occur? CCD, FRCC, and PPSC did not have documented policies and procedures for complying with suspension and debarment requirements. Specifically, they did not have a policy stating how they would comply with suspension and debarment requirements. Further, CCD, FRCC, and PPSC experienced staff turnover in key positions, and existing employees could not locate documentation that staff checked the SAM exclusion website, or that they obtained certification from their contracted entities. Why does this problem matter? CCD, FRCC, and PPSC’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-060 Community College of Denver (CCD), Front Range Community College (FRCC) and Pikes Peak State College (PPSC) should strengthen their internal controls over and ensure they comply with suspension and debarment requirements for the Higher Education Emergency Relief Fund (HEERF) grant by: A. Developing, documenting, and implementing a policy to comply with suspension and debarment using one of the three allowable methods: (1) checking the federal System of Award Management (SAM) website exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. B. Providing training and cross-training to existing employees over the new policies and procedures to reduce impacts of turnover. Response Community College of Denver Agree Implementation Date: December 2023 A. CCD will implement the following controls for monitoring the spending of the federal funds. 1) The Purchasing Coordinator will verify vendor suspension and debarment on the sam.gov website for purchases above $5,000. 2) Purchasing will attach the System of Award Management (SAM) verification to the purchase requisition packet of every requisition related to a grant fund. 3) Purchasing will ensure to include the grants manager as they send the purchase requisition for authorizing signatures, and 4) the Grants Manager will review the supporting documentation and confirm that the suspension/disbarment screenshot is included with the federal purchases. B. The Contracts and Procurement Manager and the Budget Director who supervises the purchasing will provide training to the purchasing staff and the grants personnel: Grants Manager, Sr. Grants Accountant and a Grant Accountant. The Controller will ensure that new policies and procedures are shared with the purchasing and grants staff, and new employees in those roles are trained accordingly. Response Front Range Community College Agree Implementation Date: December 2023 A. FRCC will implement the following controls for expending of federal funds. 1) When a purchase order greater than $25,000 is submitted, the grant accountant will cross check the vendor to the debarment list prior to approving the purchase order. The grant accountant will save a screenshot of the debarment check for documentation purposes. 2) During month end, the grant accountant will review all expenditures of federal funds greater than $25,000 and ensure that a debarment check has been completed and documentation has been maintained. B. Controller will review and train the Grant accountants (2), Grant Senior accountant (1) on the new policy and procedures. Response Pikes Peak State College Agree Implementation Date: December 2023 A. Regarding expenditures of federal funds at PPSC, Procurement Office will follow established internal guidelines regarding suspension and debarment regulations by checking the federal System of Award Management (SAM) website and documenting results with a screenshot. An additional step will be added to the current process, with Procurement staff verifying expenditures of federal funds through a review of federal grants and approved delegations. Controller will maintain a list of current federal grants and provide to Procurement Office. B. Director of Procurement and Contracts will provide training to Procurement Office staff and grant personnel on the new process step. Also, Controller will incorporate suspension and debarment requirements into training with grant personnel.
CCD: The Contracts and Procurement Manager and the Budget Director who supervises the purchasing will provide training to the purchasing staff and the grants personnel: Grants Manager, Sr. Grants Accountant and a Grant Accountant. The Controller will ensure that new policies and procedures are shared with the purchasing and grants staff, and new employees in those roles are trained accordingly. FRCC: Controller will review and train the Grant accountants (2), Grant Senior accountant (1) on the new policy and procedures. PPCC: Director of Procurement and Contracts will provide training to Procurement Office staff and grant personnel on the new process step. Also, Controller will incorporate suspension and debarment requirements into training with grant personnel.
Finding 2023-061 Federal Funding Accountability and Transparency Act Reporting The Federal Funding Accountability and Transparency Act (Transparency Act) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file Transparency Act reports—also known as FFATA reports—through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2023 included information on the TANF [ALN 93.558]; Refugee [ALN 93.566]; LIHEAP [ALN 93.568]; and Substance Abuse [ALN 93.959] programs. FFATA reporting was required because the Department passed through funds to one or more subrecipients for each of the four programs in excess of $30,000, as follows: TANF funds to one subrecipient, Refugee funds to 27 subrecipients, LIHEAP funds to one subrecipient, and Substance Abuse funds to 21 subrecipients for Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department’s internal controls over the Transparency Act reporting and to determine whether the Department correctly and timely reported its subawards to the FSRS during Fiscal Year 2023. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the State’s accounting system, for the TANF, Refugee, LIHEAP, and Substance Abuse programs and inquired about any differences. We reviewed the Department’s subawards and related federal expenditures in Fiscal Year 2023 to determine if the Department reported Transparency Act information through FSRS within the month following the month the subaward was made, as required. In addition, we made inquiries of Department staff regarding its internal control processes related to FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: TANF had one sample, Refugee had seven samples, LIHEAP had one sample, and Substance Abuse had 13 samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made timely in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulation [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department’s FFATA Quick Reference Guide, which it makes available to program staff, requires that program staff report these key data elements to eClearance—a document depository used by the Department—whenever the Department makes a subaward. Program staff are to enter the subaward information into eClearance via an online form called an eForm. Each day, the Department’s accounting manager exports the subaward data that is accumulated in eClearance into a daily report. At the end of the month, the accounting manager combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report’s accuracy. The accounting manager uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did report its subawards in FSRS for all four federal grant programs we tested for Fiscal Year 2023—TANF, Refugee, LIHEAP, and Substance Abuse programs. However, for the four programs, the Department failed to provide evidence showing subawards were reported timely for our samples totaling about $10.9 million (approximately $42,000 for TANF, approximately $419,000 for Refugee, approximately $3.6 million for LIHEAP, and approximately $6.8 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, timeliness of report unable to be determined, subaward amount incorrect, and subaward missing key elements. In addition, the Department was unable to provide a complete population of subawards for our testing. Specifically, the Department provided the Fiscal Year 2023 actual payments/expenditures it made to its subrecipients, rather than subawards that it awarded to subrecipients. We, therefore, selected our samples based on actual expenditures rather than subawards made during Fiscal Year 2023. As a result, we were unable to determine if there were subawards made during Fiscal Year 2023 that were not included in our testing population. For instance, if the Department made a subaward in June 2023, but the Department did not make any payments under the subaward that month, then that subaward should have been included in our testing population, but would not have been included. Without a method for identifying subrecipient subawards, the Department will struggle to track the status of the subawards or subrecipients’ compliance with subaward requirements. Why did these problems occur? The Department does not have adequate internal controls in place related to FFATA reporting, such as requirements for staff training over Transparency Act reporting and an appropriate supervisory review process to ensure that the Transparency Act reporting is completed in accordance with the instructions included within the Department’s FFATA Quick Reference Guide, and that the reporting is completed in a timely manner. Specifically, because the FFATA reports do not contain a time identifier for when they were submitted and the Department does not have another procedure for documenting when reports are submitted, the Department was unable to demonstrate that its FSRS reporting was completed timely for each subaward. In addition, Department staff indicated that they did not keep a listing of all subawards that were made during Fiscal Year 2023 by program since they were relying on the FSRS reporting to document the population; however, the FSRS reporting does not indicate when a subaward was reported to FSRS. Also, if a subaward was required to be submitted to FSRS, but should have been, it would not be included in the testing population based on exclusion from FSRS. Why do these problems matter? By failing to provide evidence of timely subaward reporting through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, untimely reporting of the information could be misleading to the public, which fails to meet the federal intent of transparency for federal program spending. By failing to provide a complete population of subawards by program, it is difficult for the auditor to determine if there are additional subawards that should be included in the testing population and subject to sample selection. Further, the Department is not able to accurately track the status of subawards made to subrecipients due to the lack of a complete population of subawards by program. Recommendation 2023-061 The Department of Human Services (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act reporting and ensure its reporting meets federal requirements by: A. Ensuring that reporting occurs as required for subawards of $30,000 or more in the Federal Funding Accountability and Transparency Act Subaward Reporting System by the end of the month following the month the subawards are made, and maintaining evidence to demonstrate when the reports were submitted. B. Creating a listing of all subawards by program that are awarded during the fiscal year, so that a complete population can be determined for single audit purposes and for the Department to accurately track the status of subawards made to subrecipients. Response Department of Human Services A. Agree Implementation Date: March 2024 The Department agrees with the recommendation and will ensure monthly reporting of subaward information and will implement a digital signature process to maintain evidence when the reports are submitted. B. Agree Implementation Date: March 2024 The Department agrees with this recommendation and will implement a system to record the complete population of the original grants awarded to subrecipients.
Show full finding ▾Hide full finding ▴Finding 2023-061 Federal Funding Accountability and Transparency Act Reporting The Federal Funding Accountability and Transparency Act (Transparency Act) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” The Department is required to file Transparency Act reports—also known as FFATA reports—through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search. The Department’s required FFATA reports for Fiscal Year 2023 included information on the TANF [ALN 93.558]; Refugee [ALN 93.566]; LIHEAP [ALN 93.568]; and Substance Abuse [ALN 93.959] programs. FFATA reporting was required because the Department passed through funds to one or more subrecipients for each of the four programs in excess of $30,000, as follows: TANF funds to one subrecipient, Refugee funds to 27 subrecipients, LIHEAP funds to one subrecipient, and Substance Abuse funds to 21 subrecipients for Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department’s internal controls over the Transparency Act reporting and to determine whether the Department correctly and timely reported its subawards to the FSRS during Fiscal Year 2023. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the State’s accounting system, for the TANF, Refugee, LIHEAP, and Substance Abuse programs and inquired about any differences. We reviewed the Department’s subawards and related federal expenditures in Fiscal Year 2023 to determine if the Department reported Transparency Act information through FSRS within the month following the month the subaward was made, as required. In addition, we made inquiries of Department staff regarding its internal control processes related to FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: TANF had one sample, Refugee had seven samples, LIHEAP had one sample, and Substance Abuse had 13 samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made timely in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulation [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department’s FFATA Quick Reference Guide, which it makes available to program staff, requires that program staff report these key data elements to eClearance—a document depository used by the Department—whenever the Department makes a subaward. Program staff are to enter the subaward information into eClearance via an online form called an eForm. Each day, the Department’s accounting manager exports the subaward data that is accumulated in eClearance into a daily report. At the end of the month, the accounting manager combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report’s accuracy. The accounting manager uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did report its subawards in FSRS for all four federal grant programs we tested for Fiscal Year 2023—TANF, Refugee, LIHEAP, and Substance Abuse programs. However, for the four programs, the Department failed to provide evidence showing subawards were reported timely for our samples totaling about $10.9 million (approximately $42,000 for TANF, approximately $419,000 for Refugee, approximately $3.6 million for LIHEAP, and approximately $6.8 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, timeliness of report unable to be determined, subaward amount incorrect, and subaward missing key elements. In addition, the Department was unable to provide a complete population of subawards for our testing. Specifically, the Department provided the Fiscal Year 2023 actual payments/expenditures it made to its subrecipients, rather than subawards that it awarded to subrecipients. We, therefore, selected our samples based on actual expenditures rather than subawards made during Fiscal Year 2023. As a result, we were unable to determine if there were subawards made during Fiscal Year 2023 that were not included in our testing population. For instance, if the Department made a subaward in June 2023, but the Department did not make any payments under the subaward that month, then that subaward should have been included in our testing population, but would not have been included. Without a method for identifying subrecipient subawards, the Department will struggle to track the status of the subawards or subrecipients’ compliance with subaward requirements. Why did these problems occur? The Department does not have adequate internal controls in place related to FFATA reporting, such as requirements for staff training over Transparency Act reporting and an appropriate supervisory review process to ensure that the Transparency Act reporting is completed in accordance with the instructions included within the Department’s FFATA Quick Reference Guide, and that the reporting is completed in a timely manner. Specifically, because the FFATA reports do not contain a time identifier for when they were submitted and the Department does not have another procedure for documenting when reports are submitted, the Department was unable to demonstrate that its FSRS reporting was completed timely for each subaward. In addition, Department staff indicated that they did not keep a listing of all subawards that were made during Fiscal Year 2023 by program since they were relying on the FSRS reporting to document the population; however, the FSRS reporting does not indicate when a subaward was reported to FSRS. Also, if a subaward was required to be submitted to FSRS, but should have been, it would not be included in the testing population based on exclusion from FSRS. Why do these problems matter? By failing to provide evidence of timely subaward reporting through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, untimely reporting of the information could be misleading to the public, which fails to meet the federal intent of transparency for federal program spending. By failing to provide a complete population of subawards by program, it is difficult for the auditor to determine if there are additional subawards that should be included in the testing population and subject to sample selection. Further, the Department is not able to accurately track the status of subawards made to subrecipients due to the lack of a complete population of subawards by program. Recommendation 2023-061 The Department of Human Services (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act reporting and ensure its reporting meets federal requirements by: A. Ensuring that reporting occurs as required for subawards of $30,000 or more in the Federal Funding Accountability and Transparency Act Subaward Reporting System by the end of the month following the month the subawards are made, and maintaining evidence to demonstrate when the reports were submitted. B. Creating a listing of all subawards by program that are awarded during the fiscal year, so that a complete population can be determined for single audit purposes and for the Department to accurately track the status of subawards made to subrecipients. Response Department of Human Services A. Agree Implementation Date: March 2024 The Department agrees with the recommendation and will ensure monthly reporting of subaward information and will implement a digital signature process to maintain evidence when the reports are submitted. B. Agree Implementation Date: March 2024 The Department agrees with this recommendation and will implement a system to record the complete population of the original grants awarded to subrecipients.
The Department agrees with this recommendation and will implement a system to record the complete population of the original grants awarded to subrecipients.
Finding 2023-062 Internal Controls Over Exhibit K1, Schedule of Federal Assistance Each year, the Department is required to prepare an “exhibit” containing the Department’s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State’s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Schedule of Federal Assistance, or Exhibit K1. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State’s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Numbers (ALNs) related to the programs they support. The program accountants complete this review using a CORE report that the Department has created that pulls transaction detail-level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department’s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department’s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. For Fiscal Year 2023, the Department administered more than 80 federal programs and expended approximately $2.7 billion in federal funds. TANF and Substance Abuse were two of these federal programs administered by the Department during Fiscal Year 2023. The Department reported more than $159.0 million in federal expenditures for the TANF program and approximately $43.4 million in federal expenditures for Substance Abuse in Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department’s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2023 and to determine whether the Department correctly reported its Fiscal Year 2023 federal grant expenditures to the OSC on its Exhibit K1. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2023 Exhibit K1 to the underlying financial records in CORE for the TANF and Substance Abuse federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. How were the results of the audit work measured? The OSC is required to present the State’s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State’s expenditures of federal awards during the fiscal year. Federal regulation [2 CFR 200.38(b)] defines a federal award as, “The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance…” Federal regulations require that the SEFA must show both total federal awards expended for each individual federal program and the ALN [2 CFR 200.510(b)(3)], and the total amount passed through to subrecipients for each federal program [2 CFR 200.510(b)(4)]. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC’s Instructions for Exhibits Preparation include guidelines for completing the Exhibit K1, including defining “direct and indirect expenditures” as “all monetary and non-monetary direct and indirect Federal award expenditures,” and “pass-through expenditures” as “the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.” State Fiscal Rule 1-2, Internal Controls, requires that state departments “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” What problems did the audit work identify? Based on our audit work, we determined that for Fiscal Year 2023, the Department misreported federal expenditures for TANF and Substance Abuse programs. Specifically: • For TANF, $12.2 million of expenditures were incorrectly identified on the Exhibit K1 as indirect and direct expenditures rather than expenditures passed through to subrecipients. • For the Substance Abuse, $323,000 of expenditures were incorrectly identified on the Exhibit K1 as indirect and direct expenditures rather than expenditures passed through to subrecipients. The Department correctly reported total expenditures for both the programs. However, for the two programs, the Department misstated the allocation between expenditures passed through to subrecipients and indirect and direct expenditures on the Exhibit K1. Why did these problems occur? The Department does not have adequate internal controls, such as an appropriate supervisory review process, in place to ensure that the Exhibit K1 was completed in accordance with the instructions provided by the OSC. In addition, the Exhibit K1 was not reviewed for accuracy and compared to the underlying data. For the TANF program error, the Department did not exclude all revenue codes from the calculation of expenditures passed through to subrecipients. By including revenue codes with credit balances, expenditures passed through to subrecipients were understated. Indirect and direct expenditures were overstated as they are calculated using the difference between total TANF expenditures and the expenditures passed through to subrecipients. For the Substance Abuse error, the Department excluded an appropriation code from the calculation of expenditures passed through to subrecipients, resulting in indirect and direct expenditures being overstated and expenditures passed through to subrecipients being understated. For both programs, the Department did not have an adequate supervisory review process to endure that the analysis and review performed by program accountants was accurate. Why do these problems matter? By failing to properly report grant expenditures to the OSC, who ultimately then fails to properly report expenditures to the federal government on the State’s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, the Department could misstate its federal expenditure results for the fiscal year which results in an incorrect or unreliable picture of the grant’s overall status. Recommendation 2023-062 The Department of Human Services should strengthen its internal controls over its preparation of its Exhibit K1, Schedule of Federal Assistance, by improving the supervisory review process over the Exhibit K1 to ensure that the individual program analyses are accurate and complete prior to submitting the Exhibit K1 to the Office of the State Controller. Response Department of Human Services Agree Implementation Date: September 2024 The Department agrees with the recommendation and will implement a review process to ensure that the Exhibit K1 is accurate and complete.
Show full finding ▾Hide full finding ▴Finding 2023-062 Internal Controls Over Exhibit K1, Schedule of Federal Assistance Each year, the Department is required to prepare an “exhibit” containing the Department’s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State’s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Schedule of Federal Assistance, or Exhibit K1. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State’s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Numbers (ALNs) related to the programs they support. The program accountants complete this review using a CORE report that the Department has created that pulls transaction detail-level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department’s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department’s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. For Fiscal Year 2023, the Department administered more than 80 federal programs and expended approximately $2.7 billion in federal funds. TANF and Substance Abuse were two of these federal programs administered by the Department during Fiscal Year 2023. The Department reported more than $159.0 million in federal expenditures for the TANF program and approximately $43.4 million in federal expenditures for Substance Abuse in Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department’s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2023 and to determine whether the Department correctly reported its Fiscal Year 2023 federal grant expenditures to the OSC on its Exhibit K1. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2023 Exhibit K1 to the underlying financial records in CORE for the TANF and Substance Abuse federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. How were the results of the audit work measured? The OSC is required to present the State’s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State’s expenditures of federal awards during the fiscal year. Federal regulation [2 CFR 200.38(b)] defines a federal award as, “The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance…” Federal regulations require that the SEFA must show both total federal awards expended for each individual federal program and the ALN [2 CFR 200.510(b)(3)], and the total amount passed through to subrecipients for each federal program [2 CFR 200.510(b)(4)]. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC’s Instructions for Exhibits Preparation include guidelines for completing the Exhibit K1, including defining “direct and indirect expenditures” as “all monetary and non-monetary direct and indirect Federal award expenditures,” and “pass-through expenditures” as “the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.” State Fiscal Rule 1-2, Internal Controls, requires that state departments “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” What problems did the audit work identify? Based on our audit work, we determined that for Fiscal Year 2023, the Department misreported federal expenditures for TANF and Substance Abuse programs. Specifically: • For TANF, $12.2 million of expenditures were incorrectly identified on the Exhibit K1 as indirect and direct expenditures rather than expenditures passed through to subrecipients. • For the Substance Abuse, $323,000 of expenditures were incorrectly identified on the Exhibit K1 as indirect and direct expenditures rather than expenditures passed through to subrecipients. The Department correctly reported total expenditures for both the programs. However, for the two programs, the Department misstated the allocation between expenditures passed through to subrecipients and indirect and direct expenditures on the Exhibit K1. Why did these problems occur? The Department does not have adequate internal controls, such as an appropriate supervisory review process, in place to ensure that the Exhibit K1 was completed in accordance with the instructions provided by the OSC. In addition, the Exhibit K1 was not reviewed for accuracy and compared to the underlying data. For the TANF program error, the Department did not exclude all revenue codes from the calculation of expenditures passed through to subrecipients. By including revenue codes with credit balances, expenditures passed through to subrecipients were understated. Indirect and direct expenditures were overstated as they are calculated using the difference between total TANF expenditures and the expenditures passed through to subrecipients. For the Substance Abuse error, the Department excluded an appropriation code from the calculation of expenditures passed through to subrecipients, resulting in indirect and direct expenditures being overstated and expenditures passed through to subrecipients being understated. For both programs, the Department did not have an adequate supervisory review process to endure that the analysis and review performed by program accountants was accurate. Why do these problems matter? By failing to properly report grant expenditures to the OSC, who ultimately then fails to properly report expenditures to the federal government on the State’s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, the Department could misstate its federal expenditure results for the fiscal year which results in an incorrect or unreliable picture of the grant’s overall status. Recommendation 2023-062 The Department of Human Services should strengthen its internal controls over its preparation of its Exhibit K1, Schedule of Federal Assistance, by improving the supervisory review process over the Exhibit K1 to ensure that the individual program analyses are accurate and complete prior to submitting the Exhibit K1 to the Office of the State Controller. Response Department of Human Services Agree Implementation Date: September 2024 The Department agrees with the recommendation and will implement a review process to ensure that the Exhibit K1 is accurate and complete.
The Department agrees with the recommendation and will implement a review process to ensure that the Exhibit K1 is accurate and complete.
Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-063 The Department of Human Services (Department) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for the Department through interagency agreements with the Governor’s Office of Information Technology and Department of Health Care Policy and Financing. Response Department of Human Services Agree Implementation Date: September 2024 The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
Show full finding ▾Hide full finding ▴Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-063 The Department of Human Services (Department) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for the Department through interagency agreements with the Governor’s Office of Information Technology and Department of Health Care Policy and Financing. Response Department of Human Services Agree Implementation Date: September 2024 The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
The Department will be working with HCPF and OIT on a Delegation of Authority per C.R.S. 24-37.5-105.4 which will serve in the same capacity as an IA. The Delegation of Authority will outline the roles and responsibilities of each party/agency are in place prior to the start of the yearly SOC audit. In addition, the CBMS Team (CDHS BITS) will be working to hire a resource to fill a new position that will help facilitate the coordination of the yearly SOC audit. The new role will serve as the main point of contact for the SOC auditors to gather support requests in a timely manner and ensure the timeline is on track, while escalating to management at State CBMS, HCPF, vendors and OIT as needed. This position will also work with the CDHS Internal Audit Division to document an internal control process to ensure proper alignment with all internal and external stakeholders. The CBMS Team and SOC auditors will agree to a timeline that will meet the industry standards best practices of delivering a final report within four months of the end of each fiscal year. The timeline will include a review of the draft report for not only the CBMS Team but also CDHS, HCPF and OIT.
Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-064 The Department of Health Care Policy and Financing (HCPF) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for HCPF through interagency agreements with the Governor’s Office of Information Technology and Department of Human Services. Response Department of Health Care Policy and Financing Partially Agree Implementation Date: November 2024 HCPF does not agree that the late delivery of the CBMS SOC report justifies this recommendation. As identified in Inter-agency Agreements between OIT and the Department and CDHS and OIT, the SOC report for CBMS compliance was owned by the OIT prior to 2022 and CDHS Product Manager currently. CBMS is a multi-agency system owned by CDHS, HCPF, and OIT and as a result OIT, CDHS, and the Department agreed to Inter-agency agreements specifically identifying OIT as the responsible party for reviewing and complying with CBMS SOC requirements. However, HCPF does agree that establishing the roles and responsibilities for HCPF, OIT, and CDHS is important to its internal controls over CBMS. HCPF will work with CDHS and OIT to establish, document, and formalize the roles and responsibilities. Auditor’s Addendum As discussed in the finding, the Department is responsible for ensuring they have effective internal controls over their federal programs, which includes maintaining responsibility for the performance of processes assigned to service organizations [Green Book Paragraph OV4.01]. By not reviewing the CBMS SOC report until almost 7 months after fiscal year end, the Department was unable to determine if any issues were identified in the report, or if any actions were needed to correct the issues identified.
Show full finding ▾Hide full finding ▴Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-064 The Department of Health Care Policy and Financing (HCPF) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for HCPF through interagency agreements with the Governor’s Office of Information Technology and Department of Human Services. Response Department of Health Care Policy and Financing Partially Agree Implementation Date: November 2024 HCPF does not agree that the late delivery of the CBMS SOC report justifies this recommendation. As identified in Inter-agency Agreements between OIT and the Department and CDHS and OIT, the SOC report for CBMS compliance was owned by the OIT prior to 2022 and CDHS Product Manager currently. CBMS is a multi-agency system owned by CDHS, HCPF, and OIT and as a result OIT, CDHS, and the Department agreed to Inter-agency agreements specifically identifying OIT as the responsible party for reviewing and complying with CBMS SOC requirements. However, HCPF does agree that establishing the roles and responsibilities for HCPF, OIT, and CDHS is important to its internal controls over CBMS. HCPF will work with CDHS and OIT to establish, document, and formalize the roles and responsibilities. Auditor’s Addendum As discussed in the finding, the Department is responsible for ensuring they have effective internal controls over their federal programs, which includes maintaining responsibility for the performance of processes assigned to service organizations [Green Book Paragraph OV4.01]. By not reviewing the CBMS SOC report until almost 7 months after fiscal year end, the Department was unable to determine if any issues were identified in the report, or if any actions were needed to correct the issues identified.
HCPF does not agree that the late delivery of the CBMS SOC report justifies this recommendation. As identified in Inter-agency Agreements between OIT and the Department and CDHS and OIT, the SOC report for CBMS compliance was owned by the OIT prior to 2022 and CDHS Product Manager currently. CBMS is a multi-agency system owned by CDHS, HCPF, and OIT and as a result OIT, CDHS, and the Department agreed to Inter-agency agreements specifically identifying OIT as the responsible party for reviewing and complying with CBMS SOC requirements. However, HCPF does agree that establishing the roles and responsibilities for HCPF, OIT, and CDHS is important to its internal controls over CBMS. HCPF will work with CDHS and OIT to establish, document, and formalize the roles and responsibilities.
Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-065 The Governor’s Office of Information Technology (OIT) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for OIT through interagency agreements with the Department of Health Care Policy and Financing and Department of Human Services. Response Governor’s Office of Information Technology Agree Implementation Date: June 2024 OIT's roles and responsibilities related to the Colorado Benefits Management System (CBMS) are outlined in statute, C.R.S. 24-37.5-105. The "CBMS realignment" demonstrated OIT's commitment to focus on fulfilling the roles and responsibilities outlined in statute. OIT will work with CDHS and HCPF to reaffirm through interagency agreement that OIT will continue to work in alignment with statute, and its support of the CBMS program does not extend to roles and responsibilities that are outside of OIT's statute like program administration, including program audit and compliance.
Show full finding ▾Hide full finding ▴Finding 2023-063, 2023-064, and 2023-065 Internal Controls Over Colorado Benefits Management System The Department of Human Services uses the Colorado Benefits Management System (CBMS) for the TANF and SNAP programs. In addition, the Department of Health Care Policy and Financing (HCPF) uses CBMS for the federal Medicaid and the Children’s Basic Health Plan (CBHP) programs. For Fiscal Year 2023, the Governor’s Office of Information Technology (OIT) contracted with independent auditors (service auditors) to perform an evaluation of the Department, HCPF, and OIT’s internal controls for CBMS. For these types of evaluations, the service auditors follow the guidance issued by the American Institute of Certified Public Accountants (AICPA), Statement on Standards for Attestation Engagements (SSAE), within AT-C Section 320, and issue System and Organization Controls (SOC) reports at the conclusion of the evaluation. One type of SOC report—a SOC 1, Type II (SOC 1) report—provides the service auditor’s opinion on the service organization’s internal controls, specifically as to whether the internal controls are suitably designed, implemented, and operating effectively for a specified period. The Fiscal Year 2023 CBMS SOC 1 report covers the period of July 1, 2022 through June 30, 2023. The Department, HCPF, and OIT can use the CBMS SOC 1 report to obtain assurance that CBMS’s internal controls are in place and working effectively in relation to the related federal programs administered through CBMS. If the SOC 1 report has issues noted, then the departments and office can assess how to address the issues. In addition, when service auditors provide a SOC 1 report with a modified opinion—which indicates that the service auditor has identified internal controls that fail to meet the standard upon which they are being measured or the service auditor was unable to obtain sufficient and appropriate evidence—the Department and HCPF should determine if actions to mitigate the increased risk to their federal programs and related internal control and compliance considerations are necessary. In April 2023, the Department created a Business Innovation, Technology & Security (BITS) Division within the Department to help manage CBMS. The BITS Division is a new technology management division that works with OIT and vendors to ensure proper management of technology projects and assets. In 2023, the BITS Division took on much of the CBMS management through a joint-agency effort between the Department, HCPF, and OIT. This project was called the “CBMS Realignment” and it shifted centralized OIT staff to the Department and HCPF in an effort to bring CBMS management closer to the programs and the constituents they serve. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department and HCPF had effective internal controls in place related to their federal programs and CBMS for Fiscal Year 2023. Specifically, we requested a copy of the Fiscal Year 2023 CBMS SOC 1 report. We also inquired with the Department and HCPF on the timeline related to the receipt of the report. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulation [2 CFR 200.303] requires the non-federal entity, in this instance the Department and HCPF, to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to the OSC’s policy, Internal Control System, the OSC and state departments must use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as their framework for their systems of internal control. Green Book Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations. Furthermore, the Green Book specifies that management needs to understand the internal controls that each service organization has designed, implemented, and operates, as well as how each service organization’s internal control system impacts the Department’s internal control systems. Additionally, the Green Book states the following: • Principle 3.06 states that, to achieve the entity’s objectives, management should assign responsibility and delegate authority to key roles throughout the entity. • Principle 10.13 states that management should ensure duties are segregated in relation to authority and operation activities, to reduce the risk of overriding existing or established controls and preventing abuse, through potential collusion, in the internal control system. • Principle 14.3 states that management should communicate quality information down and across reporting lines to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. The CBMS SOC 1 report should be received by the Department, HCPF, and OIT no later than the end of October of each year—or within 4 months of the end of the fiscal year, as identified by industry best practices. This ensures that timely information is provided to the reviewed agency about the system being reviewed on the internal controls in place during the prior fiscal year. What problem did the audit work identify? The Department, HCPF, and OIT did not receive the CBMS SOC 1 report for the July 1, 2022 through June 30, 2023 period by October 2023. Rather, the Department received the report on January 26, 2024, 86 days after the end of October. Historically, OIT received this report between September and October each fiscal year and then provided the report to the Department and HCPF. Why did this problem occur? The Fiscal Year 2023 CBMS SOC 1 report was late due to the realignment of the CBMS OIT team, which was previously in charge of obtaining the CBMS SOC 1 report. According to the Department, when the CBMS OIT team was transitioned to the Department and HCPF during Fiscal Year 2023, there were coordination issues between the Department, HCPF, and the service auditor regarding the performance of the CBMS SOC 1 audit. In addition, the service auditor identified exceptions that the Department and HCPF were required to respond to prior to issuance of the CBMS SOC 1 report. With the recent changes, the Department, HCPF, and OIT do not have an interagency agreement in place to properly delineate responsibilities for CBMS, including SOC 1 audit oversight and the responsibilities associated with that audit. Why does this problem matter? The Department and HCPF are responsible for ensuring they have effective internal controls over their federal programs. By not establishing interagency agreements between the Department, HCPF, and OIT—not having clear roles and responsibilities outlined—the Department and HCPF could miss major CBMS management responsibilities, such as obtaining the CBMS SOC 1 reports in a timely manner. Further, the Department and HCPF have been unable to review the CBMS SOC 1 report for updates to compensating user entity controls and determine if there was a modified opinion in the report and, if so, take action to correct the identified issues. Recommendation 2023-065 The Governor’s Office of Information Technology (OIT) should improve its internal controls over the Colorado Benefits Management System (CBMS) by establishing the roles and responsibilities for OIT through interagency agreements with the Department of Health Care Policy and Financing and Department of Human Services. Response Governor’s Office of Information Technology Agree Implementation Date: June 2024 OIT's roles and responsibilities related to the Colorado Benefits Management System (CBMS) are outlined in statute, C.R.S. 24-37.5-105. The "CBMS realignment" demonstrated OIT's commitment to focus on fulfilling the roles and responsibilities outlined in statute. OIT will work with CDHS and HCPF to reaffirm through interagency agreement that OIT will continue to work in alignment with statute, and its support of the CBMS program does not extend to roles and responsibilities that are outside of OIT's statute like program administration, including program audit and compliance.
OIT's roles and responsibilities related to the Colorado Benefits Management System (CBMS) are outlined in statute, C.R.S. 24-37.5-105. The "CBMS realignment" demonstrated OIT's commitment to focus on fulfilling the roles and responsibilities outlined in statute. OIT will work with CDHS and HCPF to reaffirm through interagency agreement that OIT will continue to work in alignment with statute, and its support of the CBMS program does not extend to roles and responsibilities that are outside of OIT's statute like program administration, including program audit and compliance.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-080 Foster Care Controls Over Eligibility Determinations The Program was enacted under Title IV-E of the Social Security Act and is overseen at the federal level by HHS. The purpose of the Program is to help States provide proper care for eligible children who need placement outside of their homes. A child may be removed from a home either by a court order or a voluntary placement agreement and may be placed with a relative, a foster family home, a residential child care facility, or a group home. In Colorado, the county departments of human/social services administer the Program, such as determining a child’s eligibility, and the Department supervises and monitors the counties. When a child is removed from the home, the county caseworkers gather necessary information to open a Program case for that child. County caseworkers enter the information on a prescribed form for initial determination and redetermination for the Program, including date of birth, whether the removal was voluntary or court ordered, household demographics, family income, and how the child was deprived of parental support. This information is also entered into the Department’s case management system, Trails, to document the child’s eligibility for the Program. In Fiscal Year 2022, the Department’s expenditures for the Program were approximately $81.7 million. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the Program’s eligibility determination process, as well as to determine whether the Department complied with applicable eligibility determination requirements during Fiscal Year 2022. We reviewed a sample of 60 Program case files for children who were determined eligible for the Program, and resided with a provider who received payments for providing foster care for the child during Fiscal Year 2022. Our testing included reviewing supporting documentation included in the case files as well as data entered into Trails related to eligibility determinations/redeterminations. How were the results of the audit work measured? We applied the following criteria during our testing: • State regulation [12 CCR 2509-7 7.601.71.A.2] requires the county caseworkers to document eligibility information on the prescribed form. It also requires the county caseworker to ensure that a copy of the signed voluntary placement agreement or court order are in the case file. • State regulation [12 CCR 2509-7 7.601.71.I.1] requires county caseworkers to determine eligibility for children “entering out-of-home foster care within 45 calendar days of the placement unless good faith efforts have been made and recorded in the child’s record”. • State regulation [12 CCR 2509-7 7.601.71.I.2] requires the county caseworkers to “redetermine eligibility using the state prescribed form every 12 months from the date the child enters foster care”. • State regulation [12 CCR 2509-7 7.601.71.K.2] requires county caseworkers to finalize a permanence plan within 12 months of entering the Program, and every 12 months after that while the child is in the Program. What problems did the audit work identify? We identified at least one issue in 10 of the 60 case files tested (17 percent). Specifically, we identified the following: • In one case, the Department provided court orders, however, the court orders were not signed. • In five cases, the caseworker did not determine eligibility within 45 calendar days as required by state regulation. The caseworker determined eligibility one to 587 days after the 45-day requirement and the case file did not have documentation of good faith efforts to meet the requirement. • In four cases, the caseworker did not redetermine eligibility within 12 months as required. In these cases, the caseworker redetermined eligibility 4 to 11 months after the 12-month requirement. • In one case, the caseworker did not ensure reasonable efforts to finalize a permanency plan every 12 months, as required. Specifically, the caseworker obtained a court document that would provide reasonable efforts to finalize a permanency plan required for Fiscal Year 2022 13 months after the previous permanency plan, one month after the required time frame. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with eligibility requirements for the Program during Fiscal Year 2022. For example, the Department did not provide adequate or effective training to the counties over the requirements of the Program. Specifically, the training provided was only required for new caseworkers and not for all caseworkers that work on the Program, and the Department did not require at least one representative from each county to attend training. The Department communicated that the counties that administer the Program have experienced significant turnover in caseworker positions; having new, inexperienced county caseworkers determining eligibility for the Foster Care Program further heightens the need for frequent, detailed training and an effective quality review process. Why do these problems matter? It is essential for the Department to ensure that a child’s eligibility for the Program is properly determined, documented, and in accordance with state and federal regulations. Furthermore, providing continuous and effective training on eligibility determinations and redetermination, will aid in reducing errors and omissions of required documentation. Inaccurate processing of case file information to determine eligibility can result in counties improperly granting Program benefits to ineligible individuals, or denying benefits to eligible individuals. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2022-080 The Department of Human Services should strengthen its internal controls over, and ensure compliance with, the Foster Care Title IV-E program (Program) eligibility requirements by ensuring that county caseworkers are appropriately trained on Program requirements. This should include training all caseworkers that work on the Program at a frequency that ensures that new caseworkers receive comprehensive training within a reasonable timeframe after hire, and requiring that there is at least one representative from each county in attendance for Department-provided training. Response Department of Human Resources Agree Implementation Date: June 30, 2024 The Department currently provides quarterly training for both new workers and quarterly meetings. The department will require at least one representative from each county to attend a minimum of one training per fiscal year. New workers will still be required to attend a new worker training prior to gaining access to the IV-E module in Trails.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-080 Foster Care Controls Over Eligibility Determinations The Program was enacted under Title IV-E of the Social Security Act and is overseen at the federal level by HHS. The purpose of the Program is to help States provide proper care for eligible children who need placement outside of their homes. A child may be removed from a home either by a court order or a voluntary placement agreement and may be placed with a relative, a foster family home, a residential child care facility, or a group home. In Colorado, the county departments of human/social services administer the Program, such as determining a child’s eligibility, and the Department supervises and monitors the counties. When a child is removed from the home, the county caseworkers gather necessary information to open a Program case for that child. County caseworkers enter the information on a prescribed form for initial determination and redetermination for the Program, including date of birth, whether the removal was voluntary or court ordered, household demographics, family income, and how the child was deprived of parental support. This information is also entered into the Department’s case management system, Trails, to document the child’s eligibility for the Program. In Fiscal Year 2022, the Department’s expenditures for the Program were approximately $81.7 million. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department’s internal controls over the Program’s eligibility determination process, as well as to determine whether the Department complied with applicable eligibility determination requirements during Fiscal Year 2022. We reviewed a sample of 60 Program case files for children who were determined eligible for the Program, and resided with a provider who received payments for providing foster care for the child during Fiscal Year 2022. Our testing included reviewing supporting documentation included in the case files as well as data entered into Trails related to eligibility determinations/redeterminations. How were the results of the audit work measured? We applied the following criteria during our testing: • State regulation [12 CCR 2509-7 7.601.71.A.2] requires the county caseworkers to document eligibility information on the prescribed form. It also requires the county caseworker to ensure that a copy of the signed voluntary placement agreement or court order are in the case file. • State regulation [12 CCR 2509-7 7.601.71.I.1] requires county caseworkers to determine eligibility for children “entering out-of-home foster care within 45 calendar days of the placement unless good faith efforts have been made and recorded in the child’s record”. • State regulation [12 CCR 2509-7 7.601.71.I.2] requires the county caseworkers to “redetermine eligibility using the state prescribed form every 12 months from the date the child enters foster care”. • State regulation [12 CCR 2509-7 7.601.71.K.2] requires county caseworkers to finalize a permanence plan within 12 months of entering the Program, and every 12 months after that while the child is in the Program. What problems did the audit work identify? We identified at least one issue in 10 of the 60 case files tested (17 percent). Specifically, we identified the following: • In one case, the Department provided court orders, however, the court orders were not signed. • In five cases, the caseworker did not determine eligibility within 45 calendar days as required by state regulation. The caseworker determined eligibility one to 587 days after the 45-day requirement and the case file did not have documentation of good faith efforts to meet the requirement. • In four cases, the caseworker did not redetermine eligibility within 12 months as required. In these cases, the caseworker redetermined eligibility 4 to 11 months after the 12-month requirement. • In one case, the caseworker did not ensure reasonable efforts to finalize a permanency plan every 12 months, as required. Specifically, the caseworker obtained a court document that would provide reasonable efforts to finalize a permanency plan required for Fiscal Year 2022 13 months after the previous permanency plan, one month after the required time frame. Why did these problems occur? The Department lacked sufficient internal controls to ensure compliance with eligibility requirements for the Program during Fiscal Year 2022. For example, the Department did not provide adequate or effective training to the counties over the requirements of the Program. Specifically, the training provided was only required for new caseworkers and not for all caseworkers that work on the Program, and the Department did not require at least one representative from each county to attend training. The Department communicated that the counties that administer the Program have experienced significant turnover in caseworker positions; having new, inexperienced county caseworkers determining eligibility for the Foster Care Program further heightens the need for frequent, detailed training and an effective quality review process. Why do these problems matter? It is essential for the Department to ensure that a child’s eligibility for the Program is properly determined, documented, and in accordance with state and federal regulations. Furthermore, providing continuous and effective training on eligibility determinations and redetermination, will aid in reducing errors and omissions of required documentation. Inaccurate processing of case file information to determine eligibility can result in counties improperly granting Program benefits to ineligible individuals, or denying benefits to eligible individuals. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Recommendation 2022-080 The Department of Human Services should strengthen its internal controls over, and ensure compliance with, the Foster Care Title IV-E program (Program) eligibility requirements by ensuring that county caseworkers are appropriately trained on Program requirements. This should include training all caseworkers that work on the Program at a frequency that ensures that new caseworkers receive comprehensive training within a reasonable timeframe after hire, and requiring that there is at least one representative from each county in attendance for Department-provided training. Response Department of Human Resources Agree Implementation Date: June 30, 2024 The Department currently provides quarterly training for both new workers and quarterly meetings. The department will require at least one representative from each county to attend a minimum of one training per fiscal year. New workers will still be required to attend a new worker training prior to gaining access to the IV-E module in Trails.
The Department currently provides quarterly training for both new workers and quarterly meetings. The department will require at least one representative from each county to attend a minimum of one training per fiscal year. New workers will still be required to attend a new worker training prior to gaining access to the IV-E module in Trails.
2022-080
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-081 Federal Funding Accountability and Transparency Act The Department receives funding from HHS for the Program and then awards this federal funding to Colorado counties for administration of the Program. In other words, the counties receive the Program’s subawards from the Department, which is considered a pass-through-entity in this instance. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through-entity to another entity to carry out part of a federal grant received by the pass-through-entity. According to the Program’s ALN description at www.sam.gov, this federal funding helps states “provide safe and stable out-of-home care for children under the jurisdiction of the state…until the children are returned home safely, placed with adoptive families, or placed in other planned arrangements permanently. The program provides funds to assist with the costs of foster care maintenance for eligible children; administrative costs to manage the program; and training for public agency staff, foster parents, and eligible professional partner agency staff.” Because the Department receives federal funding from HHS and passes it through as subawards to 64 Colorado counties, the Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (FFATA). FFATA requires the federal government to make certain information on federal awards available to the public via a single, searchable website (www.usaspending.gov). To achieve this objective, FFATA federal regulations [2 CFR 170] require the Department to report information about the Program subawards it makes to subrecipients (i.e., the counties). Federal regulations [2 CFR 200.1] define a subrecipient as “an entity…that receives a subaward from a pass-through-entity to carry out part of a Federal award.” In Fiscal Year 2022, the Department spent $81.7 million in Program grant funds from HHS and $66.4 million of this was passed through to, and expended by, Colorado’s 64 counties. FFATA federal regulations [2 CFR 170, Appendix A] specifically require the Department to submit Foster Care Program subaward information through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subawardee’s name, subaward number, subaward obligation/action date, and subaward amount. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Program during Fiscal Year 2022. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and the FFATA reports it submitted for the Program for Fiscal Year 2022. How were the results of the audit work measured? In accordance with FFATA regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if it made an award or supplemental award equal to or greater than $30,000 in April 2022. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA regulations for the Program. Specifically, the Department did not report any foster care subawards in FSRS for Fiscal Year 2022. The following table summarizes the results of our testing. Why did this problem occur? The Department stated that it believed the FFATA regulations did not apply to the Program because it is primarily administered by the counties, and therefore, the counties should be considered part of the State for FFATA reporting purposes instead of subrecipients. However, the Department could not provide any information from the federal government to support this conclusion. Because the Program funds are awarded to 64 Colorado counties that are subrecipients, the FFATA regulations specify that the Department “must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a subrecipient.” Why does this problem matter? By failing to properly report the Program funding subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, by not reporting the relevant information, it is failing to meet the federal intent of transparency for federal program spending. Recommendation 2022-081 The Department of Human Services (Department) should ensure that it complies with the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for the Department of Health and Human Services’ (HHS) Foster Care Title IV-E program. The Department should work with HHS to obtain documented approval for its current approach. Otherwise, the Department must report its subawards in accordance with FFATA regulations. Response Department of Human Services Agree Implementation Date: December 2023 The Department agrees with the recommendation and will work with HHS to determine if the counties should be reported on the FFATA.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-081 Federal Funding Accountability and Transparency Act The Department receives funding from HHS for the Program and then awards this federal funding to Colorado counties for administration of the Program. In other words, the counties receive the Program’s subawards from the Department, which is considered a pass-through-entity in this instance. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through-entity to another entity to carry out part of a federal grant received by the pass-through-entity. According to the Program’s ALN description at www.sam.gov, this federal funding helps states “provide safe and stable out-of-home care for children under the jurisdiction of the state…until the children are returned home safely, placed with adoptive families, or placed in other planned arrangements permanently. The program provides funds to assist with the costs of foster care maintenance for eligible children; administrative costs to manage the program; and training for public agency staff, foster parents, and eligible professional partner agency staff.” Because the Department receives federal funding from HHS and passes it through as subawards to 64 Colorado counties, the Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (FFATA). FFATA requires the federal government to make certain information on federal awards available to the public via a single, searchable website (www.usaspending.gov). To achieve this objective, FFATA federal regulations [2 CFR 170] require the Department to report information about the Program subawards it makes to subrecipients (i.e., the counties). Federal regulations [2 CFR 200.1] define a subrecipient as “an entity…that receives a subaward from a pass-through-entity to carry out part of a Federal award.” In Fiscal Year 2022, the Department spent $81.7 million in Program grant funds from HHS and $66.4 million of this was passed through to, and expended by, Colorado’s 64 counties. FFATA federal regulations [2 CFR 170, Appendix A] specifically require the Department to submit Foster Care Program subaward information through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subawardee’s name, subaward number, subaward obligation/action date, and subaward amount. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Program during Fiscal Year 2022. As part of our audit work, we requested the Department’s policies and procedures over FFATA reporting and the FFATA reports it submitted for the Program for Fiscal Year 2022. How were the results of the audit work measured? In accordance with FFATA regulations [2 CFR 170, Appendix A], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if it made an award or supplemental award equal to or greater than $30,000 in April 2022. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA regulations for the Program. Specifically, the Department did not report any foster care subawards in FSRS for Fiscal Year 2022. The following table summarizes the results of our testing. Why did this problem occur? The Department stated that it believed the FFATA regulations did not apply to the Program because it is primarily administered by the counties, and therefore, the counties should be considered part of the State for FFATA reporting purposes instead of subrecipients. However, the Department could not provide any information from the federal government to support this conclusion. Because the Program funds are awarded to 64 Colorado counties that are subrecipients, the FFATA regulations specify that the Department “must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a subrecipient.” Why does this problem matter? By failing to properly report the Program funding subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, by not reporting the relevant information, it is failing to meet the federal intent of transparency for federal program spending. Recommendation 2022-081 The Department of Human Services (Department) should ensure that it complies with the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for the Department of Health and Human Services’ (HHS) Foster Care Title IV-E program. The Department should work with HHS to obtain documented approval for its current approach. Otherwise, the Department must report its subawards in accordance with FFATA regulations. Response Department of Human Services Agree Implementation Date: December 2023 The Department agrees with the recommendation and will work with HHS to determine if the counties should be reported on the FFATA.
The Department agrees with the recommendation and will work with HHS to determine if the counties should be reported on the FFATA.
2022-081
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-082 Quarterly Reporting of Foster Care Program Expenditures and Children Assisted According to the Program’s description at www.sam.gov, this federal funding helps states “provide safe and stable out-of-home care for children under the jurisdiction of the state…until the children are returned home safely, placed with adoptive families, or placed in other planned arrangements permanently. The program provides funds to assist with the costs of foster care maintenance for eligible children; administrative costs to manage the program; and training for public agency staff, foster parents, and eligible professional partner agency staff.” As part of the terms and conditions of federal funding from HHS’s Foster Care Program, the Department is required to submit quarterly reports called CB-496, Title IV-E Programs Quarterly Financial Report (OMB No. 970-0205) (Report). This Report must include accurate information about the Department’s quarterly foster care expenditures, prior quarter foster care expenditure adjustments, and the average monthly number of children assisted by the State’s foster care program. According to the Report instructions, it is used by HHS to “…award funds, determine allowability of reported expenditures and to provide reports to Congress.” What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with the Program’s Report requirements during State Fiscal Year 2022 (SFY 2022). As part of our audit work, we requested the Department’s procedures and internal controls for preparing the Report and copies of the four Reports it submitted for the Foster Care Program for SFY 2022. Then, we selected a sample of two quarterly reports for testing (the First Quarter of SFY 2022 and Third Quarter of SFY 2022). This testing included the following procedures: • We obtained the supporting records and recalculated the average monthly number of children assisted, by foster care assistance type, according to HHS’s Report instructions and the Department’s Report procedures. • We recreated the Reports for current quarter expenditures and prior quarter expenditure adjustments by independently pulling data from the Colorado Operations Resource Engine (CORE), the State’s accounting system, and then following the Department’s Report procedures and HHS’s Report instructions. How were the results of the audit work measured? HHS’s Report instructions require the Department to report the average monthly number of children assisted by the Program, by the type of foster care assistance received. The Report instructions also provide details for reporting current quarter expenditures and prior quarter expenditure adjustments by the type of foster care assistance received. For example, foster care assistance expenditures are required to be reported in different lines on the Report for case planning and management, eligibility determinations, legal representation, etc. In addition, these expenditures are also required to be broken out further into those for children who are currently receiving foster care services (i.e., in-placement) and those for children who are candidates to receive foster care services (i.e., pre-placement). What problems did the audit work identify? Based on the audit work performed on the First Quarter and Third Quarter Reports we selected for testing, we identified two overall problems in both reports. First, we determined that the Department overstated the average monthly number of children who received legal representation assistance from the Foster Care Program on both of the Reports we tested. This number was overstated on each Report by approximately 200 percent because the Department reported the actual number of children assisted for each quarter (6,188 for the First Quarter; 6,062 for the Third Quarter) instead of the average monthly number of children assisted during each quarter (2,063 for the First Quarter; 2,021 for the Third Quarter) as required by HHS Report instructions. After identifying this error on our selected reports, we also reviewed the Second Quarter and Fourth Quarter SFY 2022 Reports and noted the same error on the Fourth Quarter Report, while the Second Quarter Report failed to identify any number of children receiving legal representation. Additionally, the Department reported case planning and management expenditures for foster care candidates of $0 on the two reports we tested. However, we determined the Department should have reported $3.3 million on the First Quarter Report and $0.4 million on the Third Quarter Report. The Department incorrectly included foster care candidate case planning and management expenditures within case planning and management expenditures for children currently in the Program rather than as candidates for the Program. Why did these problems occur? The Department’s internal controls over the Report did not include a process for periodic review, update, and approval of the Department’s Report procedures to ensure they agreed with HHS’s Report instructions and changes in data being reported for the Program. Specifically, the Department’s Report procedures did not address the average monthly number of children who received legal representation assistance, and because of this, the Department did not take the average of the total number of children who received this assistance during the quarters we tested. Instead, the total number for 3 months was reported, which was not in compliance with HHS Report instructions. In addition, the Department’s Report procedures did not adequately reflect the details included in the HHS instructions related to the classification of case management and planning expenditures. Why do these problems matter? By failing to prepare accurate Reports for the Program, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, this may also negatively impact HHS’s awarding of Program funds to the State. HHS reported to the Department that they also identified errors in the Reports for the average monthly number of children assisted and have requested that the Department obtain permission from the federal Office of Grants Management to re-open the system that captures these Reports to revise all of the impacted numbers for average monthly number of children assisted. Recommendation 2022-082 The Department of Human Services (Department) should ensure that it provides accurate CB-496, Title IV-E Programs Quarterly Financial Reports (OMB No. 970-0205) (Report) to the federal Department of Health and Human Services for the Foster Care Title IV-E program. This should include periodically updating its Report procedures to ensure they agree to the federal program reporting requirements. Response Department of Human Services Agree Implementation Date: January 1, 2024 The Department will ensure that it provides accurate CB-496, Title IV-E Programs Quarterly Financial Reports (OMB No. 970-0205) by reviewing federal program reporting requirements annually to ensure report procedures align with the requirements.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-082 Quarterly Reporting of Foster Care Program Expenditures and Children Assisted According to the Program’s description at www.sam.gov, this federal funding helps states “provide safe and stable out-of-home care for children under the jurisdiction of the state…until the children are returned home safely, placed with adoptive families, or placed in other planned arrangements permanently. The program provides funds to assist with the costs of foster care maintenance for eligible children; administrative costs to manage the program; and training for public agency staff, foster parents, and eligible professional partner agency staff.” As part of the terms and conditions of federal funding from HHS’s Foster Care Program, the Department is required to submit quarterly reports called CB-496, Title IV-E Programs Quarterly Financial Report (OMB No. 970-0205) (Report). This Report must include accurate information about the Department’s quarterly foster care expenditures, prior quarter foster care expenditure adjustments, and the average monthly number of children assisted by the State’s foster care program. According to the Report instructions, it is used by HHS to “…award funds, determine allowability of reported expenditures and to provide reports to Congress.” What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with the Program’s Report requirements during State Fiscal Year 2022 (SFY 2022). As part of our audit work, we requested the Department’s procedures and internal controls for preparing the Report and copies of the four Reports it submitted for the Foster Care Program for SFY 2022. Then, we selected a sample of two quarterly reports for testing (the First Quarter of SFY 2022 and Third Quarter of SFY 2022). This testing included the following procedures: • We obtained the supporting records and recalculated the average monthly number of children assisted, by foster care assistance type, according to HHS’s Report instructions and the Department’s Report procedures. • We recreated the Reports for current quarter expenditures and prior quarter expenditure adjustments by independently pulling data from the Colorado Operations Resource Engine (CORE), the State’s accounting system, and then following the Department’s Report procedures and HHS’s Report instructions. How were the results of the audit work measured? HHS’s Report instructions require the Department to report the average monthly number of children assisted by the Program, by the type of foster care assistance received. The Report instructions also provide details for reporting current quarter expenditures and prior quarter expenditure adjustments by the type of foster care assistance received. For example, foster care assistance expenditures are required to be reported in different lines on the Report for case planning and management, eligibility determinations, legal representation, etc. In addition, these expenditures are also required to be broken out further into those for children who are currently receiving foster care services (i.e., in-placement) and those for children who are candidates to receive foster care services (i.e., pre-placement). What problems did the audit work identify? Based on the audit work performed on the First Quarter and Third Quarter Reports we selected for testing, we identified two overall problems in both reports. First, we determined that the Department overstated the average monthly number of children who received legal representation assistance from the Foster Care Program on both of the Reports we tested. This number was overstated on each Report by approximately 200 percent because the Department reported the actual number of children assisted for each quarter (6,188 for the First Quarter; 6,062 for the Third Quarter) instead of the average monthly number of children assisted during each quarter (2,063 for the First Quarter; 2,021 for the Third Quarter) as required by HHS Report instructions. After identifying this error on our selected reports, we also reviewed the Second Quarter and Fourth Quarter SFY 2022 Reports and noted the same error on the Fourth Quarter Report, while the Second Quarter Report failed to identify any number of children receiving legal representation. Additionally, the Department reported case planning and management expenditures for foster care candidates of $0 on the two reports we tested. However, we determined the Department should have reported $3.3 million on the First Quarter Report and $0.4 million on the Third Quarter Report. The Department incorrectly included foster care candidate case planning and management expenditures within case planning and management expenditures for children currently in the Program rather than as candidates for the Program. Why did these problems occur? The Department’s internal controls over the Report did not include a process for periodic review, update, and approval of the Department’s Report procedures to ensure they agreed with HHS’s Report instructions and changes in data being reported for the Program. Specifically, the Department’s Report procedures did not address the average monthly number of children who received legal representation assistance, and because of this, the Department did not take the average of the total number of children who received this assistance during the quarters we tested. Instead, the total number for 3 months was reported, which was not in compliance with HHS Report instructions. In addition, the Department’s Report procedures did not adequately reflect the details included in the HHS instructions related to the classification of case management and planning expenditures. Why do these problems matter? By failing to prepare accurate Reports for the Program, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, this may also negatively impact HHS’s awarding of Program funds to the State. HHS reported to the Department that they also identified errors in the Reports for the average monthly number of children assisted and have requested that the Department obtain permission from the federal Office of Grants Management to re-open the system that captures these Reports to revise all of the impacted numbers for average monthly number of children assisted. Recommendation 2022-082 The Department of Human Services (Department) should ensure that it provides accurate CB-496, Title IV-E Programs Quarterly Financial Reports (OMB No. 970-0205) (Report) to the federal Department of Health and Human Services for the Foster Care Title IV-E program. This should include periodically updating its Report procedures to ensure they agree to the federal program reporting requirements. Response Department of Human Services Agree Implementation Date: January 1, 2024 The Department will ensure that it provides accurate CB-496, Title IV-E Programs Quarterly Financial Reports (OMB No. 970-0205) by reviewing federal program reporting requirements annually to ensure report procedures align with the requirements.
The Department will ensure that it provides accurate CB-496, Title IV-E Programs Quarterly Financial Reports (OMB No. 970-0205) by reviewing federal program reporting requirements annually to ensure report procedures align with the requirements.
2022-082
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-083 and 2022-084 Trails—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the responses, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and responses have been provided to the Department and OIT in a separate, confidential memorandum. The Department utilizes Trails, its statewide automated child welfare information system, to aid in administering a number of federally-funded child welfare programs, including the Program. Trails went live in 2001 and, in Fiscal Year 2017, the Department and the Governor’s Office of Information Technology (OIT) began a multi-phase and multi-year modernization project that continued during Fiscal Year 2022. The Department is the business owner and is responsible for designing information security processes for the Trails application. To meet management’s IT expectations, the role of Trails Security Administrator was established to conduct Trails application access management procedures. OIT, as the IT service provider, works closely with the Department and is also responsible for conducting certain access management procedures. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department and OIT designed effective procedures for and configured Trails to address risks associated with information security. Our audit work was performed through interviews conducted of Department and OIT staff and reviewing supporting documentation. How were the results of the audit work measured? We measured the results of our audit work using the following criteria: • Colorado Information Security Policies (Security Policies), which are developed and published by OIT. • Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO). What problems did the audit work identify? Based on our Fiscal Year 2022 audit work, we identified problems with information security, access management, IT general controls for Trails at both the Department and OIT. Why did these problems occur? Department staff did not provide explanations for why the identified access management problems occurred. OIT staff provided an explanation for one of the identified access management problems, but not all of the problems. Why do these problems matter? When access management IT general controls are lacking, management cannot ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of Trails. Recommendation 2022-083 Department of Human Services The Department of Human Services should improve access management IT general controls over Trails, its statewide automated child welfare information system, by: A. Implementing the recommendation noted in Part A of the confidential finding. B. Implementing the recommendation noted in Part B of the confidential finding. Response Department of Human Services A. Partially Agree Implementation Date: December 2023 The Department will work on implementing recommendations for Part A that it agrees to implement. Auditor’s Addendum A confidential auditor’s addendum has been included in the confidential finding to address the Department’s “partially agree” response. B. Partially Agree Implementation Date: September 2023 The Department will work on implementing recommendations for Part B that it agrees to implement. Auditor’s Addendum A confidential auditor’s addendum has been included in the confidential finding to address the Department’s “partially agree” response.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-080 through 2022-084 Department of Human Services—Foster Care Program The Office of the State Auditor conducted the Fiscal Year 2022 audit work that resulted in findings and recommendations addressed to the Department related to the Foster Care Title IV-E program. These findings and recommendations, and the responses, are included in the Department of Human Services – Foster Care Program chapter at III-125 within this section of the report. See Recommendations 2022-080 through 2022-084. These recommendations are classified as Material Weaknesses and Significant Deficiencies. The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. Findings 2022-083 and 2022-084 Trails—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the responses, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and responses have been provided to the Department and OIT in a separate, confidential memorandum. The Department utilizes Trails, its statewide automated child welfare information system, to aid in administering a number of federally-funded child welfare programs, including the Program. Trails went live in 2001 and, in Fiscal Year 2017, the Department and the Governor’s Office of Information Technology (OIT) began a multi-phase and multi-year modernization project that continued during Fiscal Year 2022. The Department is the business owner and is responsible for designing information security processes for the Trails application. To meet management’s IT expectations, the role of Trails Security Administrator was established to conduct Trails application access management procedures. OIT, as the IT service provider, works closely with the Department and is also responsible for conducting certain access management procedures. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department and OIT designed effective procedures for and configured Trails to address risks associated with information security. Our audit work was performed through interviews conducted of Department and OIT staff and reviewing supporting documentation. How were the results of the audit work measured? We measured the results of our audit work using the following criteria: • Colorado Information Security Policies (Security Policies), which are developed and published by OIT. • Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO). What problems did the audit work identify? Based on our Fiscal Year 2022 audit work, we identified problems with information security, access management, IT general controls for Trails at both the Department and OIT. Why did these problems occur? Department staff did not provide explanations for why the identified access management problems occurred. OIT staff provided an explanation for one of the identified access management problems, but not all of the problems. Why do these problems matter? When access management IT general controls are lacking, management cannot ensure their expectations and the entity’s objectives are being met, that risks are responded to appropriately, and that a strong system of internal control is established, which increases the risk of unauthorized access and can impact the confidentiality, integrity, and availability of Trails. Recommendation 2022-083 Department of Human Services The Department of Human Services should improve access management IT general controls over Trails, its statewide automated child welfare information system, by: A. Implementing the recommendation noted in Part A of the confidential finding. B. Implementing the recommendation noted in Part B of the confidential finding. Response Department of Human Services A. Partially Agree Implementation Date: December 2023 The Department will work on implementing recommendations for Part A that it agrees to implement. Auditor’s Addendum A confidential auditor’s addendum has been included in the confidential finding to address the Department’s “partially agree” response. B. Partially Agree Implementation Date: September 2023 The Department will work on implementing recommendations for Part B that it agrees to implement. Auditor’s Addendum A confidential auditor’s addendum has been included in the confidential finding to address the Department’s “partially agree” response.
The Department will work on implementing recommendations for Part B that it agrees to implement.
2022-083
Finding 2023-070 Federal Funding Accountability and Transparency Act The Department is responsible for administering three programs as part of the Workforce Innovation and Opportunity Act (WIOA) Cluster—WIOA Adult Program [ALN 17.258], WIOA Youth Activities [ALN 17.259], and WIOA Dislocated Worker Formula Grants [ALN 17.278]. The overall purpose of these programs is to help job seekers access employment, education, training, and support services to success in the job market. The Department administers the programs and also passes WIOA Cluster funds through to Colorado counties so they can help provide these services to individuals. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for the WIOA Cluster. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department made 18 subawards totaling $26.6 million to 10 subrecipients for the WIOA Cluster, as follows: • $7.1 million in subawards to 9 subrecipients for WIOA Adult Program, • $9.4 million in subawards to 9 subrecipients for WIOA Youth Activities, • $7.3 million in subawards to 9 subrecipients for WIOA Dislocated Worker Formula Grants, and • $2.8 million in subawards to 9 subrecipients for WIOA Colorado Rural Workforce Consortium The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the WIOA Cluster programs during Fiscal Year 2023. As part of our audit work, we requested 4 months of FFATA reports for all 10 of the WIOA Cluster’s subrecipients. We compared the amounts reported by the Department for subawards in FSRS to the underlying support provided by the Department, as well as the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the State’s accounting system, and inquired about any differences. In addition, we tested to determine whether the Department submitted the FFATA reports within the month following the month the subaward was made, as required by federal regulations. We also requested and reviewed the Department’s policies and procedures over FFATA reporting, the FFATA reports submitted by the Department in Fiscal Year 2023, and a list of all subawards made by the Department during Fiscal Year 2023 for the WIOA Cluster. How were the results of the audit work measured? In accordance with federal regulation [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA reporting requirements for the WIOA Cluster during Fiscal Year 2023. Specifically, we determined that the Department incorrectly reported $8.7 million in subawards to 10 subrecipients, while $7.7 million was not reported timely. The following table summarizes our testing results and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did this problem occur? The Department did not have adequate internal controls in place to ensure it was in compliance with FFATA requirements. Specifically, the Department did not have sufficient documented policies and procedures that included how it tracked the money it passed to subrecipients. Additionally, the Department did not reconcile the spreadsheet it used to compile the reports in CORE, in order to ensure it accurately represented the WIOA Cluster funds the Department passed to subrecipients. Why does this problem matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-070 The Department of Labor and Employment (Department) should strengthen its internal controls over and ensure it complies with requirements under Federal Funding Accountability and Transparency Act (FFATA) reporting for the Workforce Innovation and Opportunity Act (WIOA) Cluster by: A. Updating its policies and procedures for FFATA reporting. These policies and procedures should include requirements for the method in which Department staff must track funds passed to subrecipients. B. Developing and implementing a reconciliation process between the Department’s spreadsheet it uses to compile the FFATA reports and the Colorado Operations Resource Engine (CORE), the State’s accounting system. Response Department of Labor and Employment A. Agree Implementation Date: June 2024 The Colorado Department of Labor and Employment Division of Employment and Training will refine our FFATA procedure to ensure the WIOA sub-award information is reported in the FSRS system within required deadlines. The procedure will include specific steps regarding the tracking of sub-awards and required timelines in which the data will be entered into the system. B. Agree Implementation Date: June 2024 The Colorado Department of Labor and Employment Division of Employment and Training will develop and implement a reconciliation process that ensures the information tracked in the Notice of Funding Allocation spreadsheet is reconciled with the information entered into CORE so that it will be accurately reported in FSRS.
Show full finding ▾Hide full finding ▴Finding 2023-070 Federal Funding Accountability and Transparency Act The Department is responsible for administering three programs as part of the Workforce Innovation and Opportunity Act (WIOA) Cluster—WIOA Adult Program [ALN 17.258], WIOA Youth Activities [ALN 17.259], and WIOA Dislocated Worker Formula Grants [ALN 17.278]. The overall purpose of these programs is to help job seekers access employment, education, training, and support services to success in the job market. The Department administers the programs and also passes WIOA Cluster funds through to Colorado counties so they can help provide these services to individuals. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for the WIOA Cluster. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department made 18 subawards totaling $26.6 million to 10 subrecipients for the WIOA Cluster, as follows: • $7.1 million in subawards to 9 subrecipients for WIOA Adult Program, • $9.4 million in subawards to 9 subrecipients for WIOA Youth Activities, • $7.3 million in subawards to 9 subrecipients for WIOA Dislocated Worker Formula Grants, and • $2.8 million in subawards to 9 subrecipients for WIOA Colorado Rural Workforce Consortium The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the WIOA Cluster programs during Fiscal Year 2023. As part of our audit work, we requested 4 months of FFATA reports for all 10 of the WIOA Cluster’s subrecipients. We compared the amounts reported by the Department for subawards in FSRS to the underlying support provided by the Department, as well as the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the State’s accounting system, and inquired about any differences. In addition, we tested to determine whether the Department submitted the FFATA reports within the month following the month the subaward was made, as required by federal regulations. We also requested and reviewed the Department’s policies and procedures over FFATA reporting, the FFATA reports submitted by the Department in Fiscal Year 2023, and a list of all subawards made by the Department during Fiscal Year 2023 for the WIOA Cluster. How were the results of the audit work measured? In accordance with federal regulation [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA reporting requirements for the WIOA Cluster during Fiscal Year 2023. Specifically, we determined that the Department incorrectly reported $8.7 million in subawards to 10 subrecipients, while $7.7 million was not reported timely. The following table summarizes our testing results and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did this problem occur? The Department did not have adequate internal controls in place to ensure it was in compliance with FFATA requirements. Specifically, the Department did not have sufficient documented policies and procedures that included how it tracked the money it passed to subrecipients. Additionally, the Department did not reconcile the spreadsheet it used to compile the reports in CORE, in order to ensure it accurately represented the WIOA Cluster funds the Department passed to subrecipients. Why does this problem matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. Recommendation 2023-070 The Department of Labor and Employment (Department) should strengthen its internal controls over and ensure it complies with requirements under Federal Funding Accountability and Transparency Act (FFATA) reporting for the Workforce Innovation and Opportunity Act (WIOA) Cluster by: A. Updating its policies and procedures for FFATA reporting. These policies and procedures should include requirements for the method in which Department staff must track funds passed to subrecipients. B. Developing and implementing a reconciliation process between the Department’s spreadsheet it uses to compile the FFATA reports and the Colorado Operations Resource Engine (CORE), the State’s accounting system. Response Department of Labor and Employment A. Agree Implementation Date: June 2024 The Colorado Department of Labor and Employment Division of Employment and Training will refine our FFATA procedure to ensure the WIOA sub-award information is reported in the FSRS system within required deadlines. The procedure will include specific steps regarding the tracking of sub-awards and required timelines in which the data will be entered into the system. B. Agree Implementation Date: June 2024 The Colorado Department of Labor and Employment Division of Employment and Training will develop and implement a reconciliation process that ensures the information tracked in the Notice of Funding Allocation spreadsheet is reconciled with the information entered into CORE so that it will be accurately reported in FSRS.
The Colorado Department of Labor and Employment Division of Employment and Training will develop and implement a reconciliation process that ensures the information tracked in the Notice of Funding Allocation spreadsheet is reconciled with the information entered into CORE so that it will be accurately reported in FSRS.
Finding 2023-071 Rehabilitation Services – Vocational Rehabilitation Grants to States—Federal Reporting The Department is responsible for administering the federal Rehabilitation Services -Vocational Rehabilitation Grants to States (VR) program [ALN 84.126]. The program’s overall purpose is to assist individuals whose disabilities result in barriers to employment with attaining and maintaining employment. At any of the 25 field and satellite offices located throughout the State, rehabilitation counselors work with individuals to assess their needs and identify appropriate vocational rehabilitation services. The Department’s Division of Vocational Rehabilitation (Division) is responsible for completing the RSA-17, Vocational Rehabilitation Financial Report, a quarterly, federally-required report for the VR program for all VR grants open during the fiscal year. It is also responsible for the data used to complete the reports and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Department’s Finance Office provides the Division with reports from CORE and creates a workbook with the applicable financial information that the Division uses to complete the reports. Division staff run reports from its electronic case management system, the Accessible Web-Based Activity and Reporting Environment (AWARE)— the system Division program staff use to track expenditures—and use some of this information to help complete the reports. The Department had three open grants during Fiscal Year 2023 and was, therefore, required to submit one quarterly report for each grant for as long as the grant was open during the year, resulting in a total of 8 reports submitted during the fiscal year. During Fiscal Year 2023, the Department expended approximately $51.4 million for the VR program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Division had adequate internal controls in place over and complied with federal reporting requirements for the VR program during Fiscal Year 2023. As part of our audit work, we gained an understanding of the Division’s procedures that were in place during Fiscal Year 2023 to prepare the federal reports. In addition, we reviewed four RSA-17 reports—two related to the quarter ended September 30, 2022 and two related to the quarter ended June 30, 2023—submitted to the federal government for Fiscal Year 2023 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Division’s policies and procedures related to RSA-17 report completion, as well as the supporting documentation for the reports we selected for testing. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the Office of the State Controller’s policy, Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity’s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The federal Rehabilitation Services Administration provides instructions for completing the RSA-17, as well as a template. The template provided in the instructions requires the Division to select the method of accounting used to prepare the reports, and requires the Division to maintain supporting documentation to substantiate the data reported in the report. The instructions also state that the Division is responsible for having internal controls necessary to ensure the reports are accurate and reliable. What problems did the audit work identify? We identified at least one issue with all four (100 percent) of the RSA-17 reports we tested. For example, the Division could not provide documentation to support information for a total of over $25 million in expenditures reported by the Division. Specifically, we found the following: • Reports for the quarter ended September 30, 2022: o For one report, the Division could not provide documentation to support information on the following two lines of the report: Administrative Expenditures—$21.5 million American Job Center Infrastructure Expenditures—$467,083 o In the other report, the Division could not provide documentation to support a $3.1 million amount noted for the American Job Center Infrastructure Expenditures line on the report. • Reports for the quarter ended June 30, 2023: o In one report, the Division could not provide documentation for $7,315 of the $8.6 million reported in the Administrative Expenditures line. Additionally, it did not include $913,166 in expenditures from the month of June and, therefore, underreported, the following lines: Administrative Expenditures - Reported—The Division reported $8.6 million instead of the correct amount of $9.5 million. Expenditures incurred for the Provision of Pre-Employment Transition Services by Agency Staff Only - Reported—The Division reported $96,903 instead of the correct amount of $115,511. o In the other report, the Division could not provide documentation for $22,707 of the $8.5 million reported in the Administrative Expenditures line. Why did these problems occur? The Division did not have sufficient internal controls in place to ensure that its federal RSA-17 reports were accurate and complete, and that the associated documentation was maintained during Fiscal Year 2023. Although the Division has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement to reconcile information that Division program staff obtains from AWARE to CORE to ensure the expenditures agree in both systems and that any differences are identified and corrected, as appropriate. Additionally, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to staff inputting the wrong information into the reports, which a review could have caught and corrected prior to submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including documented policies with adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause report users to rely on incorrect information. This could have a negative impact on the Department’s future federal program funding. Recommendation 2023-071 The Department of Labor and Employment’s (Department) Division of Vocational Rehabilitation (Division) should strengthen its internal controls over, and ensure compliance with, federal reporting for the Rehabilitation Services-Vocational Rehabilitation Grants to States program by developing, documenting, and implementing policies for completing its federal reports. These policies should require the Division to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE) it receives from the Department’s Finance Section, and to ensure that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: October 2024 DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
Show full finding ▾Hide full finding ▴Finding 2023-071 Rehabilitation Services – Vocational Rehabilitation Grants to States—Federal Reporting The Department is responsible for administering the federal Rehabilitation Services -Vocational Rehabilitation Grants to States (VR) program [ALN 84.126]. The program’s overall purpose is to assist individuals whose disabilities result in barriers to employment with attaining and maintaining employment. At any of the 25 field and satellite offices located throughout the State, rehabilitation counselors work with individuals to assess their needs and identify appropriate vocational rehabilitation services. The Department’s Division of Vocational Rehabilitation (Division) is responsible for completing the RSA-17, Vocational Rehabilitation Financial Report, a quarterly, federally-required report for the VR program for all VR grants open during the fiscal year. It is also responsible for the data used to complete the reports and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Department’s Finance Office provides the Division with reports from CORE and creates a workbook with the applicable financial information that the Division uses to complete the reports. Division staff run reports from its electronic case management system, the Accessible Web-Based Activity and Reporting Environment (AWARE)— the system Division program staff use to track expenditures—and use some of this information to help complete the reports. The Department had three open grants during Fiscal Year 2023 and was, therefore, required to submit one quarterly report for each grant for as long as the grant was open during the year, resulting in a total of 8 reports submitted during the fiscal year. During Fiscal Year 2023, the Department expended approximately $51.4 million for the VR program. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Division had adequate internal controls in place over and complied with federal reporting requirements for the VR program during Fiscal Year 2023. As part of our audit work, we gained an understanding of the Division’s procedures that were in place during Fiscal Year 2023 to prepare the federal reports. In addition, we reviewed four RSA-17 reports—two related to the quarter ended September 30, 2022 and two related to the quarter ended June 30, 2023—submitted to the federal government for Fiscal Year 2023 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Division’s policies and procedures related to RSA-17 report completion, as well as the supporting documentation for the reports we selected for testing. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the Office of the State Controller’s policy, Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity’s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The federal Rehabilitation Services Administration provides instructions for completing the RSA-17, as well as a template. The template provided in the instructions requires the Division to select the method of accounting used to prepare the reports, and requires the Division to maintain supporting documentation to substantiate the data reported in the report. The instructions also state that the Division is responsible for having internal controls necessary to ensure the reports are accurate and reliable. What problems did the audit work identify? We identified at least one issue with all four (100 percent) of the RSA-17 reports we tested. For example, the Division could not provide documentation to support information for a total of over $25 million in expenditures reported by the Division. Specifically, we found the following: • Reports for the quarter ended September 30, 2022: o For one report, the Division could not provide documentation to support information on the following two lines of the report: Administrative Expenditures—$21.5 million American Job Center Infrastructure Expenditures—$467,083 o In the other report, the Division could not provide documentation to support a $3.1 million amount noted for the American Job Center Infrastructure Expenditures line on the report. • Reports for the quarter ended June 30, 2023: o In one report, the Division could not provide documentation for $7,315 of the $8.6 million reported in the Administrative Expenditures line. Additionally, it did not include $913,166 in expenditures from the month of June and, therefore, underreported, the following lines: Administrative Expenditures - Reported—The Division reported $8.6 million instead of the correct amount of $9.5 million. Expenditures incurred for the Provision of Pre-Employment Transition Services by Agency Staff Only - Reported—The Division reported $96,903 instead of the correct amount of $115,511. o In the other report, the Division could not provide documentation for $22,707 of the $8.5 million reported in the Administrative Expenditures line. Why did these problems occur? The Division did not have sufficient internal controls in place to ensure that its federal RSA-17 reports were accurate and complete, and that the associated documentation was maintained during Fiscal Year 2023. Although the Division has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement to reconcile information that Division program staff obtains from AWARE to CORE to ensure the expenditures agree in both systems and that any differences are identified and corrected, as appropriate. Additionally, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to staff inputting the wrong information into the reports, which a review could have caught and corrected prior to submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including documented policies with adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause report users to rely on incorrect information. This could have a negative impact on the Department’s future federal program funding. Recommendation 2023-071 The Department of Labor and Employment’s (Department) Division of Vocational Rehabilitation (Division) should strengthen its internal controls over, and ensure compliance with, federal reporting for the Rehabilitation Services-Vocational Rehabilitation Grants to States program by developing, documenting, and implementing policies for completing its federal reports. These policies should require the Division to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE) it receives from the Department’s Finance Section, and to ensure that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: October 2024 DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
DVR is committed to collaborating with CDLE Finance to develop clear roles and responsibilities associated with the completion and submission of the RSA-17 report and further to develop the internal controls necessary to ensure the reports are compliant with all requirements, by developing, formally documenting, and implementing policies for completing its federal reports. These policies will require the Department to reconcile the expenditure information it uses from the Accessible Web-Based Activity and Reporting Environment (AWARE) system to the Colorado Operations Resource Engine (CORE), and will ensure that a supervisory review occurs prior to submitting the reports to the federal government.
The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and a Significant Deficiency were communicated to the Department of Labor and Employment (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-070 Unemployment Insurance Program Integrity Fraud Holds The Department’s UI Division is responsible for the administration and monitoring of Colorado’s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits to ensure they are properly paid. Employer-paid premiums are the primary source of funding for UI benefits. When an individual applies for UI benefits, they are called a claimant, and the application is called a claim. Each claimant creates an account in MyUI+, the Department’s unemployment benefit system, in order to apply for unemployment benefits. The Department reviews, or adjudicates, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to all employers that the claimant worked for within the last 18 months to determine the validity and reason for the claimant leaving the workplace. In addition, Department staff indicate that, on a weekly basis, they perform reviews to identify potential issues with a claimant’s ability and availability to work, and to determine whether the claimant is accurately reporting earned income. If information provided by an interested party, such as a former employer, relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. In Fiscal Year 2022, the Department paid $1.1 billion in UI benefits. The Department has processes and systems to detect and prevent identity theft related to UI benefits. For example, when the Department identifies a claim with characteristics that are indicators of fraud, it places a fraud hold (also known as a program integrity hold) on the claimant’s UI claim, which holds the claim for investigation and which prevents any future benefit payments to the claimant until the fraud hold is removed and eligibility is determined. For each fraud hold, the Department has to determine if the identity of the individual filing the claim matches the personally identifiable information used on the claim. Once that is verified, the Department then must verify that the individual did not make any false statements in order to establish program eligibility. The steps that the Department takes to resolve a fraud hold differ depending on the characteristics of the claim that caused the Department to question its legitimacy. If Department staff determine that the fraud hold was not legitimate, the Department clears the hold in MyUI+ and then proceeds with determining if the individual is eligible to receive UI benefits. The Department uses an automated system, called ID.me, as part of its identity verification process. ID.me is a federally-certified identity provider that assists the Department in verifying claimants’ identity. In some instances, MyUI+ will clear the fraud hold if the claimant passes ID.me and the claim does not need further investigation. In other cases, the Department performs an investigation to determine if the fraud hold is legitimate, or if the hold was placed in error. According to the information in MyUI+, the Department cleared 54,047 fraud holds during Fiscal Year 2022 – 44,936 were cleared through the ID.me process, and 9,111 were cleared by the Department. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over fraud holds during Fiscal Year 2022, including whether only appropriate, authorized individuals cleared the fraud hold from MyUI+, and if the Department had adequate segregation of duties between staff investigating a fraud hold, and staff releasing the hold in MyUI+. As part of our audit work, we requested the Department’s policies and procedures for their investigation process and documentation used to support the Department’s investigations that resulted in clearing a fraud hold, and inquired how the Department determined who is authorized to release fraud holds from MyUI+. The Department’s documentation included case reports for the investigations and log notes from Salesforce, the Department’s software that is primarily used as a workflow management tool and documentation repository for UI claims requiring an investigation. We selected a sample of 60 of the 9,111 fraud holds that were cleared by the Department during Fiscal Year 2022 to determine if the Department performed an investigation prior to releasing the fraud hold in MyUI+. In addition, as part of our testing of the sample, we determined that 20 different Department staff cleared the 60 fraud holds in MyUI+; we performed testing to determine if those staff were authorized to clear the holds in MyUI+. How were the results of the audit work measured? We measured the results of our audit against the following: Section 7511, Part V, of the Employment Security Manual (ESM) requires state UI laws to include provisions for such methods of administration as are, within reason, calculated (1) to detect benefits paid through error by the state UI agency or through willful misrepresentation or error by the claimant or others, (2) to deter claimants from obtaining benefits through willful misrepresentation, and (3) to recover benefits overpaid under certain circumstances. These required functions are accomplished through designated staff responsible for promoting and maintaining the integrity of the UI program through prevention, detection, investigations, establishment, and recovery of overpayments. Designated staff also prepare cases for prosecution. The Department’s UI Investigation Procedures state that if Department staff determine that a fraud hold that they are investigating can be released in MyUI+, Department staff should write an event log note in Salesforce. Information security is the practice of protecting information by mitigating information risk. ISO 27001 Standard for Information Security Management Systems is the international standard for information security, and its best practice approach helps organizations manage their information security by addressing people, processes, and technology. User-access management has the following objectives: • Ensure authorized user access • Prevent unauthorized access to information systems Expanding on the objectives from ISO 27001, a broad set of business-level objectives for user-access management can be defined as follows: • Allow only authorized users to have access to information and resources • Restrict access to the least privileges required by these authorized users to fulfill their business role The federal Social Security Act [Section 303(a)(1), SSA], contains a merit-based system requirement for the UI program. Specifically, this section requires that, as a condition of receiving federal UI administrative grants, states must have laws that include “provision for such methods of administration” that includes a merit system. A merit system is defined as the process of promoting and hiring government employees based on their ability to perform a job, rather than on their political connections. As part of this requirement, any position which involves the determination of whether or not a UI claimant will be paid, or which involves determining an employer's liability for contributions, must be “merit staffed.” According to federal regulations [5 CFR 900.603, Standards For a Merit System of Personnel Administration], “The quality of public service can be improved by the development of systems of personnel administration consistent with such merit principles as - (a) Recruiting, selecting, and advancing employees on the basis of their relative ability, knowledge, and skills, including open consideration of qualified applicants for initial appointment. (b) Providing equitable and adequate compensation. (c) Training employees, as needed, to assure high quality performance. (d) Retaining employees on the basis of the adequacy of their performance, correcting inadequate performance, and separating employees whose inadequate performance cannot be corrected…” The U. S. Department of Labor Unemployment Insurance Program Letter (UIPL) No. 12-01, states that only those employees considered as merit-staff can determine whether to pay or deny payment to a claim. Additionally, UIPL No. 12-01 Change 2 states that, “Determinations of overpayments or fraud must be made by merit-staffed employees.” The Department’s SPP 1053 Code of Conduct, Ethics and Values Policy, Attachment A: Unemployment Insurance Ethics Policy states that employees are not permitted to do the following: • Investigate or attempt to investigate suspected fraud unless it is within their assigned duties. • Backdate a claim, transfer claim status retroactively (UI to UCFE, UCX to TRA, etc.), alter information provided by a claimant or employer, or change or defer a UI document due date without valid documentation or approval of the appropriate branch chief or UI Director. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 10.01 of the Green Book, the Department should design control activities to achieve objectives and respond to risks. Segregation of duties contribute to the design, implementation, and operating effectiveness of control activities. Under Paragraph 10.03 of the Green Book, the Department should divide or segregate key duties and responsibilities among different people to reduce the risk of error, misuse, or fraud. This includes separating the responsibilities for authorizing transactions, processing and recording them, reviewing the transactions, and handling any related assets so that no one individual controls all key aspects of a transaction or event. What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to the clearing of fraud holds during Fiscal Year 2022. Specifically, we identified issues with 32 of the 60 (53 percent) fraud holds we tested, as follows: • The Department cleared 12 of the 60 fraud holds tested (20 percent) without performing an investigation or providing evidence of the reasoning used to clear the hold. Specifically, when we asked for investigation documentation for the 12 fraud holds, the Department indicated these were cleared without an investigation, and there were no related log notes in Salesforce, as required. • For 20 of the 48 cases in our sample (42 percent) for which the Department did conduct an investigation, it did not segregate the duty of investigating the fraud hold and clearing the fraud hold from MyUI+. Specifically, in these cases, only one person conducted the investigation, concluded on the investigation, and cleared the fraud hold in MyUI+. • One of the 20 Department staff who cleared a portion (5 percent) of the 60 fraud holds we sampled was not authorized to clear fraud holds from MyUI+ because the individual was not considered to be merit-staffed. Further, this unauthorized individual cleared 11 of 12 fraud holds we identified above that did not have an investigation, as required. We also found that this individual cleared an additional 55 fraud holds outside of our sample during Fiscal Year 2022. Why did these problems occur? The Department did not have sufficient internal controls in place, including appropriate policies and procedures, to ensure it enforced compliance with federal and Department-level requirements regarding the clearing of UI fraud holds during Fiscal Year 2022, as follows: • The Department did not ensure that all fraud hold claims cleared in MyUI+ had a related log note in Salesforce that explained the rationale for clearing the hold, or that there was an investigation performed over the fraud hold prior to it being cleared in MyUI+. Specifically, in 11 of the 12 instances, the Department’s controls failed to prevent non-merit staff from using their MyUI+ access inappropriately, and in the other instance, Department controls failed to ensure the UI claim was reviewed by the UI section that reviews fraud holds rather than the UI section that resolves non-fraud UI claims. The Department provided full, rather than read-only access to the non-merit, Executive Director’s Office’s staff member noted in our finding. UI management indicated that they gave the individual full access to MyUI+ during the height of the pandemic with the assumption that the individual would use such access in a read-only manner solely to review claim information for inquiries coming through the Executive Director's Office. According to UI Division leadership, after they identified that the individual had full access during Fiscal Year 2022, they changed the individual’s access to read-only in January 2022. • The Department lacked policies regarding management override of controls related to the clearing of fraud holds, in order to prevent or appropriately manage those responsibilities. UI staff indicated that in some cases, the non-merit, Executive Director’s Office’s staff member noted in our finding would reach out to other staff within the UI Division to help escalate the MyUI+ fraud hold clearing process. In some of these instances, because of the position of the individual within the Executive Director’s Office, UI staff circumvented the normal escalation process and aided the individual with clearing the fraud hold. • The Department’s current policies and procedures do not require segregation of duties between those staff who investigate a fraud hold, and those staff who remove the fraud hold in MyUI+. Why do these problems matter? Improper segregation of duties, including the separation of responsibilities for both investigating and clearing potential fraud holds, leaves the UI program vulnerable to fraudulent activity. Specifically, fraud risk increases if there is no segregation between the investigation and the actual clearing of the fraud hold from MyUI+ and, as a result, the same staff could inappropriately clear holds and initiate UI payments. Further, a lack of strong checks and balances within the UI program could erode the integrity of the program at large, ultimately negatively impacting public trust. Strong internal controls related to UI fraud are especially important given the large amount of funds that are paid by the Department for UI claims each year and the significant amount of fraudulent claims that are paid by the Department. For example, the Department recorded an estimated receivable for amounts due back to the Department of $45 million for fraudulently-obtained UI claims at June 30, 2022. Without strengthening its controls over UI claims and fraud holds, there is a risk that a significant amount of UI funds could continue to be paid out each year for fraudulently obtained UI claims. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-070 The Department of Labor and Employment (Department) should strengthen its internal controls over Unemployment Insurance (UI) program integrity holds by: A. Ensuring all fraud holds are properly investigated and documented with a log note in Salesforce that explains the rationale for releasing the claim, prior to releasing the claim in MyUI+. B. Adequately reviewing claims for a fraud indicator to ensure the hold is sent to the appropriate UI section for resolution. C. Ensuring Department staff are given the appropriate access in MyUI+ to prevent individuals from clearing fraud holds inappropriately and periodically monitoring access to ensure access levels remain appropriate. D. Instituting policies and procedures over management override of internal controls related to UI claims and providing staff training on those policies and procedures. This should include ensuring that UI staff are aware of the importance of following all procedures related to fraud holds and that any inappropriate requests or pressures are communicated through the appropriate channels. E. Updating its current policies and procedures to require segregation of duties between the investigation of a fraud hold and the release of a fraud hold in MyUI+ to ensure more than one person is involved in the fraud hold process from beginning to end. Response Department of Labor and Employment A. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department is moving all adjudication and investigation of program integrity holds into the MyUI+ system, so there will be one system of record. The Department will ensure that all program integrity holds have all documentation through adjudication and investigation, including log notes. The Department anticipates this to be fully implemented by July 2024. B. Agree Implementation Date: July 2024 The Department agrees with this finding. The department has modified processes to ensure all holds are only routed to the appropriate team to be adjudicated. In addition the Department is working to have all claims identified as fraud delivered in a workflow process in MyUI+ rather than the various processes in place now. Further the department is working with our MyUI+ system experts to implement new technology to strengthen and streamline the fraud indicator escalation process and systems within MyUI+. In working with our MyUI+ system experts, the Department anticipates this to be fully implemented by July 2024. C. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department will continue strengthening security in this area and internal procedures to periodically monitor the potential for internal fraud activities. Additionally, the Department will periodically monitor and review My UI+ access levels for appropriateness. In consultation with our MyUI+ systems experts, the Department anticipates this finding to be fully implemented by July 2024. D. Agree Implementation Date: July 2023 The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be completed by July 2023. E. Disagree When a PI hold is identified as being highly suspicious for criminally fraudulent activity, it is routed to a specialized unit for review, thereby leaving the standard adjudication process. This is handled by passing the review to the UI Investigations and/or Criminal Enforcement (ICE) unit. The investigator performs their investigation and if no actual fraudulent activity is found they will release the hold. The UI Division also performs several quality control reviews of claims and claim decisions via Benefits Payment Control (BPC), Benefits Accuracy Measurements (BAM), Benefits Timeliness and Quality (BTQ), and internal Quality Assurance (QA) reviews. Claims are reviewed for such criteria as adequate support documentation, benefit payment accuracy, timely processing, and correct claim decision determination on all program integrity holds. The Green Book states in Section 10.14, “ If segregation of duties is not practical within an operational process because of limited personnel or other factors, management designs alternative control activities to address the risk of fraud, waste, or abuse in the operational process.” CDLE believes the reviews represent adequate and sufficient compensating controls for the need for segregation of duties on fraud holds. Changing the current process would hinder our ability to deliver UI benefit services timely to our customers and would put us in jeopardy of fulfilling our federal and state payment timeliness requirements. Auditor’s Addendum Segregating the duties between investigating and releasing a fraud hold in MyUI+ reduces the risk of an employee inappropriately and potentially fraudulently clearing the hold without conducting a proper investigation. The issues identified in our audit indicate that the Department’s current compensating controls did not identify that a current employee released fraud holds without a proper investigation. The Department should consider updating its procedures and processes to segregate these duties to reduce the risk of this occurring in the future.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and a Significant Deficiency were communicated to the Department of Labor and Employment (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-070 Unemployment Insurance Program Integrity Fraud Holds The Department’s UI Division is responsible for the administration and monitoring of Colorado’s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits to ensure they are properly paid. Employer-paid premiums are the primary source of funding for UI benefits. When an individual applies for UI benefits, they are called a claimant, and the application is called a claim. Each claimant creates an account in MyUI+, the Department’s unemployment benefit system, in order to apply for unemployment benefits. The Department reviews, or adjudicates, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to all employers that the claimant worked for within the last 18 months to determine the validity and reason for the claimant leaving the workplace. In addition, Department staff indicate that, on a weekly basis, they perform reviews to identify potential issues with a claimant’s ability and availability to work, and to determine whether the claimant is accurately reporting earned income. If information provided by an interested party, such as a former employer, relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. In Fiscal Year 2022, the Department paid $1.1 billion in UI benefits. The Department has processes and systems to detect and prevent identity theft related to UI benefits. For example, when the Department identifies a claim with characteristics that are indicators of fraud, it places a fraud hold (also known as a program integrity hold) on the claimant’s UI claim, which holds the claim for investigation and which prevents any future benefit payments to the claimant until the fraud hold is removed and eligibility is determined. For each fraud hold, the Department has to determine if the identity of the individual filing the claim matches the personally identifiable information used on the claim. Once that is verified, the Department then must verify that the individual did not make any false statements in order to establish program eligibility. The steps that the Department takes to resolve a fraud hold differ depending on the characteristics of the claim that caused the Department to question its legitimacy. If Department staff determine that the fraud hold was not legitimate, the Department clears the hold in MyUI+ and then proceeds with determining if the individual is eligible to receive UI benefits. The Department uses an automated system, called ID.me, as part of its identity verification process. ID.me is a federally-certified identity provider that assists the Department in verifying claimants’ identity. In some instances, MyUI+ will clear the fraud hold if the claimant passes ID.me and the claim does not need further investigation. In other cases, the Department performs an investigation to determine if the fraud hold is legitimate, or if the hold was placed in error. According to the information in MyUI+, the Department cleared 54,047 fraud holds during Fiscal Year 2022 – 44,936 were cleared through the ID.me process, and 9,111 were cleared by the Department. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over fraud holds during Fiscal Year 2022, including whether only appropriate, authorized individuals cleared the fraud hold from MyUI+, and if the Department had adequate segregation of duties between staff investigating a fraud hold, and staff releasing the hold in MyUI+. As part of our audit work, we requested the Department’s policies and procedures for their investigation process and documentation used to support the Department’s investigations that resulted in clearing a fraud hold, and inquired how the Department determined who is authorized to release fraud holds from MyUI+. The Department’s documentation included case reports for the investigations and log notes from Salesforce, the Department’s software that is primarily used as a workflow management tool and documentation repository for UI claims requiring an investigation. We selected a sample of 60 of the 9,111 fraud holds that were cleared by the Department during Fiscal Year 2022 to determine if the Department performed an investigation prior to releasing the fraud hold in MyUI+. In addition, as part of our testing of the sample, we determined that 20 different Department staff cleared the 60 fraud holds in MyUI+; we performed testing to determine if those staff were authorized to clear the holds in MyUI+. How were the results of the audit work measured? We measured the results of our audit against the following: Section 7511, Part V, of the Employment Security Manual (ESM) requires state UI laws to include provisions for such methods of administration as are, within reason, calculated (1) to detect benefits paid through error by the state UI agency or through willful misrepresentation or error by the claimant or others, (2) to deter claimants from obtaining benefits through willful misrepresentation, and (3) to recover benefits overpaid under certain circumstances. These required functions are accomplished through designated staff responsible for promoting and maintaining the integrity of the UI program through prevention, detection, investigations, establishment, and recovery of overpayments. Designated staff also prepare cases for prosecution. The Department’s UI Investigation Procedures state that if Department staff determine that a fraud hold that they are investigating can be released in MyUI+, Department staff should write an event log note in Salesforce. Information security is the practice of protecting information by mitigating information risk. ISO 27001 Standard for Information Security Management Systems is the international standard for information security, and its best practice approach helps organizations manage their information security by addressing people, processes, and technology. User-access management has the following objectives: • Ensure authorized user access • Prevent unauthorized access to information systems Expanding on the objectives from ISO 27001, a broad set of business-level objectives for user-access management can be defined as follows: • Allow only authorized users to have access to information and resources • Restrict access to the least privileges required by these authorized users to fulfill their business role The federal Social Security Act [Section 303(a)(1), SSA], contains a merit-based system requirement for the UI program. Specifically, this section requires that, as a condition of receiving federal UI administrative grants, states must have laws that include “provision for such methods of administration” that includes a merit system. A merit system is defined as the process of promoting and hiring government employees based on their ability to perform a job, rather than on their political connections. As part of this requirement, any position which involves the determination of whether or not a UI claimant will be paid, or which involves determining an employer's liability for contributions, must be “merit staffed.” According to federal regulations [5 CFR 900.603, Standards For a Merit System of Personnel Administration], “The quality of public service can be improved by the development of systems of personnel administration consistent with such merit principles as - (a) Recruiting, selecting, and advancing employees on the basis of their relative ability, knowledge, and skills, including open consideration of qualified applicants for initial appointment. (b) Providing equitable and adequate compensation. (c) Training employees, as needed, to assure high quality performance. (d) Retaining employees on the basis of the adequacy of their performance, correcting inadequate performance, and separating employees whose inadequate performance cannot be corrected…” The U. S. Department of Labor Unemployment Insurance Program Letter (UIPL) No. 12-01, states that only those employees considered as merit-staff can determine whether to pay or deny payment to a claim. Additionally, UIPL No. 12-01 Change 2 states that, “Determinations of overpayments or fraud must be made by merit-staffed employees.” The Department’s SPP 1053 Code of Conduct, Ethics and Values Policy, Attachment A: Unemployment Insurance Ethics Policy states that employees are not permitted to do the following: • Investigate or attempt to investigate suspected fraud unless it is within their assigned duties. • Backdate a claim, transfer claim status retroactively (UI to UCFE, UCX to TRA, etc.), alter information provided by a claimant or employer, or change or defer a UI document due date without valid documentation or approval of the appropriate branch chief or UI Director. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 10.01 of the Green Book, the Department should design control activities to achieve objectives and respond to risks. Segregation of duties contribute to the design, implementation, and operating effectiveness of control activities. Under Paragraph 10.03 of the Green Book, the Department should divide or segregate key duties and responsibilities among different people to reduce the risk of error, misuse, or fraud. This includes separating the responsibilities for authorizing transactions, processing and recording them, reviewing the transactions, and handling any related assets so that no one individual controls all key aspects of a transaction or event. What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to the clearing of fraud holds during Fiscal Year 2022. Specifically, we identified issues with 32 of the 60 (53 percent) fraud holds we tested, as follows: • The Department cleared 12 of the 60 fraud holds tested (20 percent) without performing an investigation or providing evidence of the reasoning used to clear the hold. Specifically, when we asked for investigation documentation for the 12 fraud holds, the Department indicated these were cleared without an investigation, and there were no related log notes in Salesforce, as required. • For 20 of the 48 cases in our sample (42 percent) for which the Department did conduct an investigation, it did not segregate the duty of investigating the fraud hold and clearing the fraud hold from MyUI+. Specifically, in these cases, only one person conducted the investigation, concluded on the investigation, and cleared the fraud hold in MyUI+. • One of the 20 Department staff who cleared a portion (5 percent) of the 60 fraud holds we sampled was not authorized to clear fraud holds from MyUI+ because the individual was not considered to be merit-staffed. Further, this unauthorized individual cleared 11 of 12 fraud holds we identified above that did not have an investigation, as required. We also found that this individual cleared an additional 55 fraud holds outside of our sample during Fiscal Year 2022. Why did these problems occur? The Department did not have sufficient internal controls in place, including appropriate policies and procedures, to ensure it enforced compliance with federal and Department-level requirements regarding the clearing of UI fraud holds during Fiscal Year 2022, as follows: • The Department did not ensure that all fraud hold claims cleared in MyUI+ had a related log note in Salesforce that explained the rationale for clearing the hold, or that there was an investigation performed over the fraud hold prior to it being cleared in MyUI+. Specifically, in 11 of the 12 instances, the Department’s controls failed to prevent non-merit staff from using their MyUI+ access inappropriately, and in the other instance, Department controls failed to ensure the UI claim was reviewed by the UI section that reviews fraud holds rather than the UI section that resolves non-fraud UI claims. The Department provided full, rather than read-only access to the non-merit, Executive Director’s Office’s staff member noted in our finding. UI management indicated that they gave the individual full access to MyUI+ during the height of the pandemic with the assumption that the individual would use such access in a read-only manner solely to review claim information for inquiries coming through the Executive Director's Office. According to UI Division leadership, after they identified that the individual had full access during Fiscal Year 2022, they changed the individual’s access to read-only in January 2022. • The Department lacked policies regarding management override of controls related to the clearing of fraud holds, in order to prevent or appropriately manage those responsibilities. UI staff indicated that in some cases, the non-merit, Executive Director’s Office’s staff member noted in our finding would reach out to other staff within the UI Division to help escalate the MyUI+ fraud hold clearing process. In some of these instances, because of the position of the individual within the Executive Director’s Office, UI staff circumvented the normal escalation process and aided the individual with clearing the fraud hold. • The Department’s current policies and procedures do not require segregation of duties between those staff who investigate a fraud hold, and those staff who remove the fraud hold in MyUI+. Why do these problems matter? Improper segregation of duties, including the separation of responsibilities for both investigating and clearing potential fraud holds, leaves the UI program vulnerable to fraudulent activity. Specifically, fraud risk increases if there is no segregation between the investigation and the actual clearing of the fraud hold from MyUI+ and, as a result, the same staff could inappropriately clear holds and initiate UI payments. Further, a lack of strong checks and balances within the UI program could erode the integrity of the program at large, ultimately negatively impacting public trust. Strong internal controls related to UI fraud are especially important given the large amount of funds that are paid by the Department for UI claims each year and the significant amount of fraudulent claims that are paid by the Department. For example, the Department recorded an estimated receivable for amounts due back to the Department of $45 million for fraudulently-obtained UI claims at June 30, 2022. Without strengthening its controls over UI claims and fraud holds, there is a risk that a significant amount of UI funds could continue to be paid out each year for fraudulently obtained UI claims. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-070 The Department of Labor and Employment (Department) should strengthen its internal controls over Unemployment Insurance (UI) program integrity holds by: A. Ensuring all fraud holds are properly investigated and documented with a log note in Salesforce that explains the rationale for releasing the claim, prior to releasing the claim in MyUI+. B. Adequately reviewing claims for a fraud indicator to ensure the hold is sent to the appropriate UI section for resolution. C. Ensuring Department staff are given the appropriate access in MyUI+ to prevent individuals from clearing fraud holds inappropriately and periodically monitoring access to ensure access levels remain appropriate. D. Instituting policies and procedures over management override of internal controls related to UI claims and providing staff training on those policies and procedures. This should include ensuring that UI staff are aware of the importance of following all procedures related to fraud holds and that any inappropriate requests or pressures are communicated through the appropriate channels. E. Updating its current policies and procedures to require segregation of duties between the investigation of a fraud hold and the release of a fraud hold in MyUI+ to ensure more than one person is involved in the fraud hold process from beginning to end. Response Department of Labor and Employment A. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department is moving all adjudication and investigation of program integrity holds into the MyUI+ system, so there will be one system of record. The Department will ensure that all program integrity holds have all documentation through adjudication and investigation, including log notes. The Department anticipates this to be fully implemented by July 2024. B. Agree Implementation Date: July 2024 The Department agrees with this finding. The department has modified processes to ensure all holds are only routed to the appropriate team to be adjudicated. In addition the Department is working to have all claims identified as fraud delivered in a workflow process in MyUI+ rather than the various processes in place now. Further the department is working with our MyUI+ system experts to implement new technology to strengthen and streamline the fraud indicator escalation process and systems within MyUI+. In working with our MyUI+ system experts, the Department anticipates this to be fully implemented by July 2024. C. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department will continue strengthening security in this area and internal procedures to periodically monitor the potential for internal fraud activities. Additionally, the Department will periodically monitor and review My UI+ access levels for appropriateness. In consultation with our MyUI+ systems experts, the Department anticipates this finding to be fully implemented by July 2024. D. Agree Implementation Date: July 2023 The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be completed by July 2023. E. Disagree When a PI hold is identified as being highly suspicious for criminally fraudulent activity, it is routed to a specialized unit for review, thereby leaving the standard adjudication process. This is handled by passing the review to the UI Investigations and/or Criminal Enforcement (ICE) unit. The investigator performs their investigation and if no actual fraudulent activity is found they will release the hold. The UI Division also performs several quality control reviews of claims and claim decisions via Benefits Payment Control (BPC), Benefits Accuracy Measurements (BAM), Benefits Timeliness and Quality (BTQ), and internal Quality Assurance (QA) reviews. Claims are reviewed for such criteria as adequate support documentation, benefit payment accuracy, timely processing, and correct claim decision determination on all program integrity holds. The Green Book states in Section 10.14, “ If segregation of duties is not practical within an operational process because of limited personnel or other factors, management designs alternative control activities to address the risk of fraud, waste, or abuse in the operational process.” CDLE believes the reviews represent adequate and sufficient compensating controls for the need for segregation of duties on fraud holds. Changing the current process would hinder our ability to deliver UI benefit services timely to our customers and would put us in jeopardy of fulfilling our federal and state payment timeliness requirements. Auditor’s Addendum Segregating the duties between investigating and releasing a fraud hold in MyUI+ reduces the risk of an employee inappropriately and potentially fraudulently clearing the hold without conducting a proper investigation. The issues identified in our audit indicate that the Department’s current compensating controls did not identify that a current employee released fraud holds without a proper investigation. The Department should consider updating its procedures and processes to segregate these duties to reduce the risk of this occurring in the future.
The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be complete by July 2024
2022-070
The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and a Significant Deficiency were communicated to the Department of Labor and Employment (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-072 MyUI+ and Connecting Colorado—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance and Employment Service Cluster programs, and the Department relies on IT systems to aid with determining applicants’ eligibility for the programs and to provide information necessary to meet federal reporting requirements. For these two programs, the associated systems are MyUI+ and Connecting Colorado. The Department is the business owner and works with the Governor’s Office of Information Technology (OIT) and two different external IT service providers. High level descriptions of the two systems are as follows: • MyUI+ — The Department’s system for UI eligibility determinations and calculation of UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ will also provide data necessary for federal reporting to the U.S. Department of Labor for the UI program that was previously generated by the Colorado Labor and Employment Accounting Resource system. • Connecting Colorado — The Department’s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to staff responsible, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department, OIT, and the Department’s two external IT service providers for MyUI+ and Connecting Colorado had policies and procedures related to information security, designed and implemented for MyUI+ and Connecting Colorado. Our audit work was performed through interviews conducted of Department and OIT staff. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2022, we identified information security problems with the MyUI+ and Connecting Colorado systems. We have grouped these problems first by those common to the two systems and then those unique to each system. MyUI+ and Connecting Colorado Common Problems • Policies and procedures were lacking. Department management had not established its expectations through the development and implementation of formalized policies and procedures related to information security general controls for MyUI+ and Connecting Colorado. o Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO) states in Paragraph 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraph 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. o Colorado Information Security Policies (Security Policies or CISP) that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy and the General Responsibilities sections, specifically 8.3.1 and 8.3.2 for Business Owners or the Department, that all agencies, except for the institutions of higher education and the general assembly, as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for its systems, as the business owner, and is responsible for following and adhering to all identified business owner requirements, as stated within the Security Policies. • Vendor oversight was lacking. The Department had not ensured its IT service providers complied with Security Policies. o Security Policies state that IT service providers—defined as OIT and/or external service providers—must follow the Security Policy requirements, among certain other requirements, as communicated to the Department within the confidential finding. o Section C.iii. (Legal Authority – Contractor Signatory, Information Technology Specific) of the Department’s contract with the Connecting Colorado IT service provider states: “…the contractor warrants that it will at all times comply with all Security Policies.” o Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department’s contract with the MyUI+ IT service provider states: “…the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor’s Office of Information Technology.” o The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. MyUI+ and Connecting Colorado Unique Problems We also found other problems with access management, unique to each MyUI+ and Connecting Colorado, that lacked compliance with Security Policies, OIT Cyber Policies, and the IRS’s, Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, November 2021 Revision, and were communicated through the confidential finding. Why did these problems occur? Overall, the Department did not have sufficient IT governance and information security internal controls in place, including policies and procedures, to ensure that Department staff and its IT service providers complied with various data security compliance requirements set forth by OIT and the IRS, as well as those internal control principles established within the Green Book’s internal control framework. We discuss other specific causes for the problems we identified below: MyUI+ and Connecting Colorado • Policies and procedures were lacking (MyUI+). Department staff stated that they followed and complied with the October 2021 dated Security Policies for the entire fiscal year, as these were more stringent than the March 2022 dated Security Policies. However, the Department did not provide documentation of a formal adoption of the October 2021 dated Security Policies. Staff also stated it maintains informal procedures of how to perform certain access management processes, but no standard operating procedures were in place. • Policies and procedures were lacking (Connecting Colorado). Department staff had released a program guidance letter that addressed data security and access, but staff acknowledged that these program guidance letters are a guide and not official policy statements. In addition, the program guidance letter provided by Department staff was directed to the workforce centers that are located across the state that provide employment services to eligible beneficiaries and, therefore, did not provide any data security or access policies and procedures for state staff. • Vendor oversight was lacking. We determined the Department did not have a vendor management process in place to hold its IT service providers accountable for contract provisions that required the IT service providers to comply with Security Policies, as demonstrated by the noncompliance issues we identified. In addition, and based on the March 2022 Security Policies, the Department has not determined whether contract amendments may be necessary with its two external IT service providers. • Other Access Management Non-Compliance: o Department staff indicated that in one instance of non-compliance identified, a more efficient process was to not comply with the requirement. o Department staff stated that the certain access management non-compliance area was set up as it was during the COVID-19 pandemic to help prevent backlogs and issues for users during that time and was not subsequently changed. o Department staff did not update its rules for Connecting Colorado account management non-compliance area to reflect Security Policy changes. Specifically, we noted that OIT introduced the specific account management requirements in its Security Policies in February 2015, and those requirements remained constant through the March 2022 version; however, Department staff did not have a process in place to ensure periodic reviews of OIT’s Security Policies occurred and Department rules for the workforce centers appropriately aligned with any Security Policy changes. In addition, Department staff did not have a process in place to ensure its external IT service providers were complying with contract provisions to comply with Security Policy requirements. o Department staff stated they have not found cause to mandate IT service provider actions that are deemed privately owned business methodologies. However, and as noted above, the Department’s contract states that the external IT service provider must comply with OIT’s Security Policies that require specific security safeguards to be implemented by all IT service providers, including the Connecting Colorado external IT service provider. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security measures are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately impacts data reliability of the data stored and processed within MyUI+ and Connecting Colorado. Lastly, without having a strong internal control framework in place, management cannot ensure that state and federal funds are being used appropriately, which may impact the Department’s compliance with federal grant requirements and/or the accuracy of the Department’s federal and financial reporting. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-072 The Department of Labor and Employment (Department) should improve its overall Information Technology (IT) governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ and Connecting Colorado information systems by: A. Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the Business Owner requirements listed within the Governor’s Office of Information Technology’s (OIT) March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. B. Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Implementing recommendation Part E as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. B. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. C. Agree Implementation Date: December 2023 CDLE agrees with the recommendation and as part of A and B recommendations of this document, the Department will include a requirement from vendors to affirm they have reviewed and will comply with OIT security policies for all new contracts. Furthermore, as the Department becomes aware of changes to OIT Security Policies through its annual review process, these will be communicated to the vendors, and they will be required to reaffirm their compliance with any applicable changes. We will work with our current vendors for MyUI+ and Connecting Colorado to address the compliance issues noted in the audit and ensure they are compliant with OIT Security Policies and IT policies developed in part A and B of this recommendation. If non-compliance is determined to be unavoidable, the Department will file for a security exception with OIT. D. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part D as noted in the confidential finding. E. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and a Significant Deficiency were communicated to the Department of Labor and Employment (Department) in the previous year and have not been remediated as of June 30, 2023 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. Finding 2022-072 MyUI+ and Connecting Colorado—Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate “classified or limited use” report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance and Employment Service Cluster programs, and the Department relies on IT systems to aid with determining applicants’ eligibility for the programs and to provide information necessary to meet federal reporting requirements. For these two programs, the associated systems are MyUI+ and Connecting Colorado. The Department is the business owner and works with the Governor’s Office of Information Technology (OIT) and two different external IT service providers. High level descriptions of the two systems are as follows: • MyUI+ — The Department’s system for UI eligibility determinations and calculation of UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ will also provide data necessary for federal reporting to the U.S. Department of Labor for the UI program that was previously generated by the Colorado Labor and Employment Accounting Resource system. • Connecting Colorado — The Department’s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to staff responsible, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department, OIT, and the Department’s two external IT service providers for MyUI+ and Connecting Colorado had policies and procedures related to information security, designed and implemented for MyUI+ and Connecting Colorado. Our audit work was performed through interviews conducted of Department and OIT staff. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2022, we identified information security problems with the MyUI+ and Connecting Colorado systems. We have grouped these problems first by those common to the two systems and then those unique to each system. MyUI+ and Connecting Colorado Common Problems • Policies and procedures were lacking. Department management had not established its expectations through the development and implementation of formalized policies and procedures related to information security general controls for MyUI+ and Connecting Colorado. o Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO) states in Paragraph 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraph 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity’s information system, including information system general controls that facilitate the proper operation of the entity’s systems. o Colorado Information Security Policies (Security Policies or CISP) that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy and the General Responsibilities sections, specifically 8.3.1 and 8.3.2 for Business Owners or the Department, that all agencies, except for the institutions of higher education and the general assembly, as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for its systems, as the business owner, and is responsible for following and adhering to all identified business owner requirements, as stated within the Security Policies. • Vendor oversight was lacking. The Department had not ensured its IT service providers complied with Security Policies. o Security Policies state that IT service providers—defined as OIT and/or external service providers—must follow the Security Policy requirements, among certain other requirements, as communicated to the Department within the confidential finding. o Section C.iii. (Legal Authority – Contractor Signatory, Information Technology Specific) of the Department’s contract with the Connecting Colorado IT service provider states: “…the contractor warrants that it will at all times comply with all Security Policies.” o Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department’s contract with the MyUI+ IT service provider states: “…the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor’s Office of Information Technology.” o The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. MyUI+ and Connecting Colorado Unique Problems We also found other problems with access management, unique to each MyUI+ and Connecting Colorado, that lacked compliance with Security Policies, OIT Cyber Policies, and the IRS’s, Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, November 2021 Revision, and were communicated through the confidential finding. Why did these problems occur? Overall, the Department did not have sufficient IT governance and information security internal controls in place, including policies and procedures, to ensure that Department staff and its IT service providers complied with various data security compliance requirements set forth by OIT and the IRS, as well as those internal control principles established within the Green Book’s internal control framework. We discuss other specific causes for the problems we identified below: MyUI+ and Connecting Colorado • Policies and procedures were lacking (MyUI+). Department staff stated that they followed and complied with the October 2021 dated Security Policies for the entire fiscal year, as these were more stringent than the March 2022 dated Security Policies. However, the Department did not provide documentation of a formal adoption of the October 2021 dated Security Policies. Staff also stated it maintains informal procedures of how to perform certain access management processes, but no standard operating procedures were in place. • Policies and procedures were lacking (Connecting Colorado). Department staff had released a program guidance letter that addressed data security and access, but staff acknowledged that these program guidance letters are a guide and not official policy statements. In addition, the program guidance letter provided by Department staff was directed to the workforce centers that are located across the state that provide employment services to eligible beneficiaries and, therefore, did not provide any data security or access policies and procedures for state staff. • Vendor oversight was lacking. We determined the Department did not have a vendor management process in place to hold its IT service providers accountable for contract provisions that required the IT service providers to comply with Security Policies, as demonstrated by the noncompliance issues we identified. In addition, and based on the March 2022 Security Policies, the Department has not determined whether contract amendments may be necessary with its two external IT service providers. • Other Access Management Non-Compliance: o Department staff indicated that in one instance of non-compliance identified, a more efficient process was to not comply with the requirement. o Department staff stated that the certain access management non-compliance area was set up as it was during the COVID-19 pandemic to help prevent backlogs and issues for users during that time and was not subsequently changed. o Department staff did not update its rules for Connecting Colorado account management non-compliance area to reflect Security Policy changes. Specifically, we noted that OIT introduced the specific account management requirements in its Security Policies in February 2015, and those requirements remained constant through the March 2022 version; however, Department staff did not have a process in place to ensure periodic reviews of OIT’s Security Policies occurred and Department rules for the workforce centers appropriately aligned with any Security Policy changes. In addition, Department staff did not have a process in place to ensure its external IT service providers were complying with contract provisions to comply with Security Policy requirements. o Department staff stated they have not found cause to mandate IT service provider actions that are deemed privately owned business methodologies. However, and as noted above, the Department’s contract states that the external IT service provider must comply with OIT’s Security Policies that require specific security safeguards to be implemented by all IT service providers, including the Connecting Colorado external IT service provider. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management’s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security measures are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately impacts data reliability of the data stored and processed within MyUI+ and Connecting Colorado. Lastly, without having a strong internal control framework in place, management cannot ensure that state and federal funds are being used appropriately, which may impact the Department’s compliance with federal grant requirements and/or the accuracy of the Department’s federal and financial reporting. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-072 The Department of Labor and Employment (Department) should improve its overall Information Technology (IT) governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ and Connecting Colorado information systems by: A. Formalizing and communicating to Department staff and the Department’s IT service providers’ IT policies that comply with the Business Owner requirements listed within the Governor’s Office of Information Technology’s (OIT) March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. B. Formalizing and communicating IT procedures to provide guidance to Department staff and the Department’s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT’s Security Policies to ensure the Department’s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing a vendor management process that ensures the Department’s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department’s current external IT service providers’ contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Implementing recommendation Part E as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. B. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. C. Agree Implementation Date: December 2023 CDLE agrees with the recommendation and as part of A and B recommendations of this document, the Department will include a requirement from vendors to affirm they have reviewed and will comply with OIT security policies for all new contracts. Furthermore, as the Department becomes aware of changes to OIT Security Policies through its annual review process, these will be communicated to the vendors, and they will be required to reaffirm their compliance with any applicable changes. We will work with our current vendors for MyUI+ and Connecting Colorado to address the compliance issues noted in the audit and ensure they are compliant with OIT Security Policies and IT policies developed in part A and B of this recommendation. If non-compliance is determined to be unavoidable, the Department will file for a security exception with OIT. D. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part D as noted in the confidential finding. E. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
2022-072
Finding 2023-074 Compliance with Federal Procurement and Suspension and Debarment Requirements The Department receives federal grant funds from SLFRF and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is required to follow the State’s procurement policies and procedures, unless the procurement requirements are exempted through an Executive Order by the Governor (emergency procurement order). In addition, non-federal entities are prohibited from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. “Covered transactions” include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the Department can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. During Fiscal Year 2023, the Department expended $59.4 million in SLFRF funds. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the SLFRF program during Fiscal Year 2023. As part of our audit work, we reviewed the Department’s internal controls over the SLFRF program’s procurement and suspension and debarment requirements. In addition, we tested a sample of 9 of the 74 (12 percent) SLFRF procurement transactions subject to testing to determine if the Department was in compliance with federal procurement requirements. We also tested 23 of the 174 (13 percent) SLFRF subrecipients and contractors subject to testing for suspension and debarment to determine whether the Department’s subrecipients and contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website’s exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the Department, as a recipient of federal funds, must establish and maintain effective internal control over federal awards that provides reasonable assurance that the Department is managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions, which includes maintaining documentation of its compliance. • Federal regulation [2 CFR 200.318] states that the Department must document its procurement procedures. The Department utilized State Fiscal Rule 3-1, Commitment Vouchers, as its procurement policy, which requires that a state contract or a purchase order be utilized for services purchased for more than $10,000 but not more than $250,000. A commitment voucher is a “document that authorizes the purchase of goods or services, encumbers the funds, and provides for disbursement of funds.” Examples of a commitment voucher include a purchase order, contract, or grant agreement. The rule also requires that a commitment voucher be executed as soon as possible if any future performance obligations are necessary after disbursements for emergency procurements. An emergency procurement is a procurement authorized by the State when there is a “threat to public health, welfare, or safety under emergency conditions”. What problems did the audit work identify? We identified the following: • The Department could not provide documentation to support that suspension and debarment verification procedures were performed for 1 of the 23 (4 percent) transactions we reviewed. We confirmed through additional audit work that this vendor was not suspended or debarred; as a result, we determined that this error did not result in questioned costs. • The Department could not provide documentation of a purchase order or a state contract for 1 of the 9 (11 percent) procurement transactions tested. For this transaction, the original contract for $ 1,875,913 was signed in March 2020 and was covered by an emergency procurement order; the contract and emergency procurement order expired June 30, 2022. The Department paid the vendor $184,433 during the year ended June 30, 2023, which was not covered by a contract or the emergency procurement order. This error resulted in questioned costs of $184,433 for the year ended June 30, 2023. Why did these problems occur? The Department did not always follow its procurement policies and procedures, which include following the procurement guidelines in the State’s Fiscal Rules. Specifically, for the SLFRF program, as the Department transitioned away from emergency procurement orders, Department staff were not aware of the processes required to be followed for procurement, suspension, and debarment. Further, the Department had staff turnover during Fiscal Year 2023 in the Controller position, which contributed to the issues. Why do these problems matter? The Department is required to follow the State’s Fiscal Rules in relation to any procurements of its federal or state programs and be able to provide documentation to demonstrate compliance with these laws. In addition, the Department’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the Department paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-074 The Department of Public Health and Environment (Department) should strengthen its internal controls over, and ensure it complies with, COVID-19 – Coronavirus State and Local Fiscal Recovery Funds program requirements related to procurement and suspension and debarment by: A. Ensuring staff follow the State’s Fiscal Rules over procurement, suspension and debarment, including maintaining supporting documentation to demonstrate how the Department complied with one of the three suspension and debarment options for compliance. B. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Department of Public Health and Environment A. Agree Implementation Date: June 2024 The Department has already begun development of an improved contracting process for this work. The Department will review and update existing guidance on suspension and debarment review as necessary. The Department has already begun development of an improved contracting process for division staff working with the COVID-19 Coronavirus State and Local Response Funds, which includes the development of program focused guidance. The Department will retrain existing central contract staff that review supporting documentation, emphasizing the need for proper suspension and debarment compliance. B. Agree Implementation Date: June 2024 The Department has already begun development of an improved contracting process for this work. As part of the new process, new and existing division contract and program staff that work with contracts will be trained on proper documentation to support suspension and debarment compliance. The Department will ensure division staff working with the COVID-19 Coronavirus State and Local Response Funds take existing and any future training on statutory violations, with a focus on commitment vouchers.
Show full finding ▾Hide full finding ▴Finding 2023-074 Compliance with Federal Procurement and Suspension and Debarment Requirements The Department receives federal grant funds from SLFRF and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is required to follow the State’s procurement policies and procedures, unless the procurement requirements are exempted through an Executive Order by the Governor (emergency procurement order). In addition, non-federal entities are prohibited from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. “Covered transactions” include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the Department can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. During Fiscal Year 2023, the Department expended $59.4 million in SLFRF funds. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the SLFRF program during Fiscal Year 2023. As part of our audit work, we reviewed the Department’s internal controls over the SLFRF program’s procurement and suspension and debarment requirements. In addition, we tested a sample of 9 of the 74 (12 percent) SLFRF procurement transactions subject to testing to determine if the Department was in compliance with federal procurement requirements. We also tested 23 of the 174 (13 percent) SLFRF subrecipients and contractors subject to testing for suspension and debarment to determine whether the Department’s subrecipients and contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website’s exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the Department, as a recipient of federal funds, must establish and maintain effective internal control over federal awards that provides reasonable assurance that the Department is managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions, which includes maintaining documentation of its compliance. • Federal regulation [2 CFR 200.318] states that the Department must document its procurement procedures. The Department utilized State Fiscal Rule 3-1, Commitment Vouchers, as its procurement policy, which requires that a state contract or a purchase order be utilized for services purchased for more than $10,000 but not more than $250,000. A commitment voucher is a “document that authorizes the purchase of goods or services, encumbers the funds, and provides for disbursement of funds.” Examples of a commitment voucher include a purchase order, contract, or grant agreement. The rule also requires that a commitment voucher be executed as soon as possible if any future performance obligations are necessary after disbursements for emergency procurements. An emergency procurement is a procurement authorized by the State when there is a “threat to public health, welfare, or safety under emergency conditions”. What problems did the audit work identify? We identified the following: • The Department could not provide documentation to support that suspension and debarment verification procedures were performed for 1 of the 23 (4 percent) transactions we reviewed. We confirmed through additional audit work that this vendor was not suspended or debarred; as a result, we determined that this error did not result in questioned costs. • The Department could not provide documentation of a purchase order or a state contract for 1 of the 9 (11 percent) procurement transactions tested. For this transaction, the original contract for $ 1,875,913 was signed in March 2020 and was covered by an emergency procurement order; the contract and emergency procurement order expired June 30, 2022. The Department paid the vendor $184,433 during the year ended June 30, 2023, which was not covered by a contract or the emergency procurement order. This error resulted in questioned costs of $184,433 for the year ended June 30, 2023. Why did these problems occur? The Department did not always follow its procurement policies and procedures, which include following the procurement guidelines in the State’s Fiscal Rules. Specifically, for the SLFRF program, as the Department transitioned away from emergency procurement orders, Department staff were not aware of the processes required to be followed for procurement, suspension, and debarment. Further, the Department had staff turnover during Fiscal Year 2023 in the Controller position, which contributed to the issues. Why do these problems matter? The Department is required to follow the State’s Fiscal Rules in relation to any procurements of its federal or state programs and be able to provide documentation to demonstrate compliance with these laws. In addition, the Department’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the Department paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-074 The Department of Public Health and Environment (Department) should strengthen its internal controls over, and ensure it complies with, COVID-19 – Coronavirus State and Local Fiscal Recovery Funds program requirements related to procurement and suspension and debarment by: A. Ensuring staff follow the State’s Fiscal Rules over procurement, suspension and debarment, including maintaining supporting documentation to demonstrate how the Department complied with one of the three suspension and debarment options for compliance. B. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Department of Public Health and Environment A. Agree Implementation Date: June 2024 The Department has already begun development of an improved contracting process for this work. The Department will review and update existing guidance on suspension and debarment review as necessary. The Department has already begun development of an improved contracting process for division staff working with the COVID-19 Coronavirus State and Local Response Funds, which includes the development of program focused guidance. The Department will retrain existing central contract staff that review supporting documentation, emphasizing the need for proper suspension and debarment compliance. B. Agree Implementation Date: June 2024 The Department has already begun development of an improved contracting process for this work. As part of the new process, new and existing division contract and program staff that work with contracts will be trained on proper documentation to support suspension and debarment compliance. The Department will ensure division staff working with the COVID-19 Coronavirus State and Local Response Funds take existing and any future training on statutory violations, with a focus on commitment vouchers.
The Department has already begun development of an improved contracting process for this work. As part of the new process, new and existing division contract and program staff that work with contracts will be trained on proper documentation to support suspension and debarment compliance. The Department will ensure division staff working with the COVID-19 Coronavirus State and Local Response Funds take existing and any future training on statutory violations, with a focus on commitment vouchers.
Finding 2023-075 Disaster Grants (Presidentially Declared Disasters) Subrecipient Monitoring Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the U.S. Department of Homeland Security (DHS), awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2023, the Department received funding for the following Disaster Grants programs: • FEMA-4145-DR for the 2013 floods incident • FEMA-4429-DR-CO for the 2015 floods incident • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 wildfires incident • FEMA-4634-DR for the 2021 wildfires and straight-line winds incident The Disaster Grants program is based on a partnership with the recipient, which in these instances is the Department; the subrecipients (local governments or PNPs); and FEMA. FEMA is responsible for managing the program, approving grants, and providing technical assistance to the SLTT and subrecipients. The Department, as the recipient for the Disaster Grants program, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. The subrecipient requests assistance, identifies the damaged facilities, provides information to support the request, maintains accurate documentation, and performs necessary work (a recipient can also be a subrecipient). A subrecipient is defined in federal regulation [2 CFR 200.1] as, “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity (such as the Department) to an entity to carry out part of a federal grant award received by the pass-through entity. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its monitoring of its subrecipients. The risk assessment includes considerations of financial risk factors such as financial implications of operational and compliance failures, operational risk factors such as risks resulting from inadequate internal controls, and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed and management decisions issued, if applicable. During Fiscal Year 2023, the Department passed approximately $48.4 million to 80 subrecipients for responses to various disasters covered by the Department’s Disaster Grants. In addition, the Department reported that they approved 78 new subawards during Fiscal Year 2023. In total, the Department reported that they had approximately 300 total subrecipients; many of these subrecipients had open projects that had been completed but were awaiting final approval and close out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over and complied with subrecipient monitoring requirements over the federal Disaster Grants program for Fiscal Year 2023. As part of our audit work, we tested 17 of 80 (21 percent) of the Department’s subrecipients who received approximately $4.2 million of Disaster Grant funding during Fiscal Year 2023 to determine whether the Department performed the subrecipient risk assessments required by federal regulations. We also requested the Department’s annual Risk Assessment package to determine whether the subrecipients’ risk assessments were appropriate and in accordance with federal regulations, and to determine whether the Department completed its onsite monitoring for those subrecipients that met the risk criteria for onsite monitoring. In addition, we performed testwork to determine whether the Department obtained the subrecipients’ single audit reports, and issued a management decision, if applicable. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over the federal award that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332] requires the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for the purposes of determining the appropriate subrecipient monitoring. Additionally, it requires the non-federal entity to verify that every subrecipient is audited, as required by 2 CFR 200, Subpart F, and to consider whether the results of the subrecipient’s audits indicate conditions that necessitate adjustment to the pass-through entity’s—in this case, the Department’s own records. • The Division of Homeland Security and Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that “DHSEM will perform an annual evaluation of Subrecipients’ risks prior to the start of each fiscal year, incorporating active awards and Subrecipients for the upcoming year.” The policy further indicates that each subrecipient will receive an overall risk score based on the quantitative and qualitative dated used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” The policy further indicates that “The subrecipients included in a fiscal year are those who have a fiscal year end between 4/1 and 3/31 of the year prior. This is tracked by utilizing the 15-month period DHSEM has to issue a management decision letter (nine months for subrecipient to obtain the audit + six months to review and issue decision).” • Federal regulation [2 CFR 200.329] stipulates that the Department is responsible for oversight of the operations of the federal award supported activities. The non-federal entity must monitor its activities under federal awards to assure compliance with applicable federal requirements and performance expectations are being achieved. • Federal regulation [2 CFR 200.521] indicates that the Department must issue a management decision for audit findings that relate to federal awards it makes to subrecipients within 6 months of acceptance of the audit report by the Federal Audit Clearinghouse (FAC). What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to subrecipient monitoring during Fiscal Year 2023. Specifically, we identified issues with 16 of the 17 (94 percent) subrecipients we tested, as follows: • The Department did not document risk assessments for 16 of the subrecipients selected for testing. Specifically, the Department did not document risk assessments for subrecipients related to the Disaster Grants for the 2013 floods incident (FEMA-4145-DR), the 2015 floods incident (FEMA-4429-DR-CO), small projects, and projects that were written at 100 percent work completed where FEMA had already approved the project worksheet. The Department subsequently provided its reasons for why these subrecipients were deemed to have low to no subrecipient risk based on the nature of the specific FEMA subawards, such as the projects were complete but waiting on final FEMA approval or had undergone a detailed approval process by FEMA prior to funds being obligated; however, the specific risk assessment for these subrecipients was not documented. We quantified the exposure for the lack of risk assessments by reviewing the Department’s listing of amounts paid to subrecipients and cross-referencing the listing to the risk assessments that were performed, noting that 68 of the 80 subrecipients (85 percent) did not have a risk assessment performed. These subrecipients accounted for approximately $15.2 million of the total $48.4 million (31 percent) of the total payments made by the Department to subrecipients during the current year. • The Department did not monitor whether 12 of the subrecipients were required to have a single audit, and if applicable, review the subrecipient’s single audit report and issue a management decision on findings. • The Department did not issue a management decision for 1 subrecipient until 8 months after the subrecipient filed its audit with the FAC, or 2 months after the time frame required by federal regulations. In addition, there was no documented approval for a change in the subrecipient monitoring plan to require performance of a more lenient set of procedures. Specifically, the Department’s original subrecipient monitoring plan specified that site visits would be performed for five specific subrecipients in Fiscal Year 2023; however, the Department indicated that they subsequently amended the subrecipient monitoring plan to revise the specific subrecipients subject to site visits, as well as reduced the total number of subrecipients that would receive site visits to four. Why did these problems occur? The Department did not have adequate internal controls in place to ensure it complied with subrecipient requirements or that it followed its own policies during Fiscal Year 2023. Specifically: • The Department indicated that they excluded subawards related to the 2013 floods incident, 2015 floods incident, small awards, and awards written at 100 percent complete because they viewed those arrangements as having little risk of noncompliance based on reporting that occurred up until that point in time, and did not document a risk assessment for each of the individual subrecipients. • The Department did not comply with its subrecipient monitoring policy or federal regulations, both of which require the Department to perform reviews of single audits for all subrecipients. • The Department failed to comply with the required timeframes for issuing management decisions because its subrecipient monitoring policy does not align with federal regulations. Specifically, the Department’s subrecipient monitoring policy requires management decisions to be issued within 15 months after the end of each subrecipient’s fiscal year rather than within 6 months of acceptance of the subrecipient’s audit report by the FAC. Additionally, the Department did not have an appropriate mechanism in place to identify, in a timely manner, when a subrecipient submitted an audit to the FAC. • The Department does not have written policies to address requirements for approval when modifications to the initial subrecipient risk assessment are made. Why do these problems matter? The issues we found are important because of the following: • By failing to properly document assessed risk of subrecipients, the Department is out of compliance with federal requirements and with its policy to assess risk for each subrecipient. This could result in the Department not timely identifying risks for subrecipients and modifying the extent of its monitoring activities to ensure the subrecipient has proper accountability and resources to be able to meet the program requirements. • By failing to verify that all subrecipients are audited as required by 2 CFR 200, Subpart F, the Department is out of compliance with federal requirements and its internal policies. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions to the monitoring risk assessment for the subrecipient. • Failing to ensure that subrecipient monitoring policies are in compliance with federal regulations could result in the Department not timely issuing management responses to a subrecipient’s findings. This could also result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and including revisions to the subrecipient monitoring risk assessment. Recommendation 2023-075 The Department of Public Safety should strengthen its internal controls over, and ensure it complies with federal Disaster Grants – Public Assistance (Presidentially Declared Disasters) program requirements for subrecipient monitoring by: A. Updating its current policy to address considerations specific to subrecipients with open subawards that were waiting for final approval or had undergone a detailed approval by the Federal Emergency Management Agency prior to funds being obligated and modifications to the subrecipients risk assessments. B. Reviewing all subrecipients’ single audit reports. C. Updating its current subrecipient monitoring policy to be in compliance with federal regulations requiring management decisions to be issued within 6 months of acceptance of the subrecipient’s audit report by the Federal Audit Clearinghouse (FAC), and implementing a mechanism to track when subrecipients submit single audits to the FAC. Response Department of Public Safety A. Agree Implementation Date: June 2024 The Department will make sure that all subrecipients have a documented risk assessment, and if any changes to the risk assessment process are made, those will also be documented. B. Agree Implementation Date: March 2024 There is a requirement is to ensure that all single audit reports are completed by all sub-recipients, and we agree we need to implement this change with the annual Risk Assessment. C. Agree Implementation Date: June 2024 DHSEM Subrecipient Monitoring team will update their policy to reflect the following: single audits from the Subrecipients must be submitted to the Federal Audit Clearinghouse within the earlier of: 30 calendar days after receipt of the auditor's report(s); or nine months after the end of the audit period, unless a different period is specified in a program-specific audit guide. DHSEM Subrecipient Monitoring team will monitor the FAC for subrecipients recognized on the annual Risk Assessment, review the Single Audit and a management letter will go out within six months of the acceptance date from the FAC.
Show full finding ▾Hide full finding ▴Finding 2023-075 Disaster Grants (Presidentially Declared Disasters) Subrecipient Monitoring Following a presidential declaration of a major disaster or an emergency, the Federal Emergency Management Agency (FEMA) within the U.S. Department of Homeland Security (DHS), awards grants to assist state, local, tribal, and territorial governments (SLTT) and certain private nonprofit (PNP) entities to respond to and recover from disasters. The mission of FEMA’s Disaster Grants program is to provide assistance to SLTT governments and certain types of PNP organizations so that communities can quickly respond to and recover from major disasters or emergencies declared by the President. Through the Disaster Grants program, FEMA provides supplemental federal grant assistance for debris removal, emergency protective measures, and the restoration of disaster-damaged, publicly-owned facilities and specific facilities of certain PNP organizations. The Disaster Grants program also encourages protection of these damaged facilities from future incidents by providing assistance for hazard mitigation measures. FEMA provides this assistance based on authority in statutes, executive orders, regulations, and policies. The federal statute that authorizes FEMA to provide assistance via the Disaster Grants is the Robert T. Stafford Disaster Relief and Emergency Assistance Act, as Amended (Stafford Act), Title 42 of the United States Code (U.S.C.) § 5121 et seq. For Fiscal Year 2023, the Department received funding for the following Disaster Grants programs: • FEMA-4145-DR for the 2013 floods incident • FEMA-4429-DR-CO for the 2015 floods incident • FEMA-4498-DR for the COVID-19 incident • FEMA-4581-DR for the 2020 wildfires incident • FEMA-4634-DR for the 2021 wildfires and straight-line winds incident The Disaster Grants program is based on a partnership with the recipient, which in these instances is the Department; the subrecipients (local governments or PNPs); and FEMA. FEMA is responsible for managing the program, approving grants, and providing technical assistance to the SLTT and subrecipients. The Department, as the recipient for the Disaster Grants program, is responsible for providing technical advice and assistance to eligible subrecipients, providing support for damage survey activities, ensuring that all potential applicants are aware of funding assistance available, and submitting documents necessary for grant awards. The subrecipient requests assistance, identifies the damaged facilities, provides information to support the request, maintains accurate documentation, and performs necessary work (a recipient can also be a subrecipient). A subrecipient is defined in federal regulation [2 CFR 200.1] as, “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity (such as the Department) to an entity to carry out part of a federal grant award received by the pass-through entity. As part of its subrecipient monitoring process, the Department should complete an annual risk assessment to determine the extent of its monitoring of its subrecipients. The risk assessment includes considerations of financial risk factors such as financial implications of operational and compliance failures, operational risk factors such as risks resulting from inadequate internal controls, and compliance risks, such as violations with laws, regulations, and internal policies. In addition, the Department should be using monitoring tools to track the status of whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed and management decisions issued, if applicable. During Fiscal Year 2023, the Department passed approximately $48.4 million to 80 subrecipients for responses to various disasters covered by the Department’s Disaster Grants. In addition, the Department reported that they approved 78 new subawards during Fiscal Year 2023. In total, the Department reported that they had approximately 300 total subrecipients; many of these subrecipients had open projects that had been completed but were awaiting final approval and close out from FEMA. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over and complied with subrecipient monitoring requirements over the federal Disaster Grants program for Fiscal Year 2023. As part of our audit work, we tested 17 of 80 (21 percent) of the Department’s subrecipients who received approximately $4.2 million of Disaster Grant funding during Fiscal Year 2023 to determine whether the Department performed the subrecipient risk assessments required by federal regulations. We also requested the Department’s annual Risk Assessment package to determine whether the subrecipients’ risk assessments were appropriate and in accordance with federal regulations, and to determine whether the Department completed its onsite monitoring for those subrecipients that met the risk criteria for onsite monitoring. In addition, we performed testwork to determine whether the Department obtained the subrecipients’ single audit reports, and issued a management decision, if applicable. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over the federal award that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332] requires the Department to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for the purposes of determining the appropriate subrecipient monitoring. Additionally, it requires the non-federal entity to verify that every subrecipient is audited, as required by 2 CFR 200, Subpart F, and to consider whether the results of the subrecipient’s audits indicate conditions that necessitate adjustment to the pass-through entity’s—in this case, the Department’s own records. • The Division of Homeland Security and Emergency Management’s (DHSEM) Subrecipient Monitoring policy states that “DHSEM will perform an annual evaluation of Subrecipients’ risks prior to the start of each fiscal year, incorporating active awards and Subrecipients for the upcoming year.” The policy further indicates that each subrecipient will receive an overall risk score based on the quantitative and qualitative dated used for the assessment inputs. • The DHSEM Subrecipient Monitoring policy states that “DHSEM will perform reviews of single audit results for Subrecipients who have expended Federal grant funds in excess of $750,000 of which some portion is passed through DHSEM.” The policy further indicates that “The subrecipients included in a fiscal year are those who have a fiscal year end between 4/1 and 3/31 of the year prior. This is tracked by utilizing the 15-month period DHSEM has to issue a management decision letter (nine months for subrecipient to obtain the audit + six months to review and issue decision).” • Federal regulation [2 CFR 200.329] stipulates that the Department is responsible for oversight of the operations of the federal award supported activities. The non-federal entity must monitor its activities under federal awards to assure compliance with applicable federal requirements and performance expectations are being achieved. • Federal regulation [2 CFR 200.521] indicates that the Department must issue a management decision for audit findings that relate to federal awards it makes to subrecipients within 6 months of acceptance of the audit report by the Federal Audit Clearinghouse (FAC). What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to subrecipient monitoring during Fiscal Year 2023. Specifically, we identified issues with 16 of the 17 (94 percent) subrecipients we tested, as follows: • The Department did not document risk assessments for 16 of the subrecipients selected for testing. Specifically, the Department did not document risk assessments for subrecipients related to the Disaster Grants for the 2013 floods incident (FEMA-4145-DR), the 2015 floods incident (FEMA-4429-DR-CO), small projects, and projects that were written at 100 percent work completed where FEMA had already approved the project worksheet. The Department subsequently provided its reasons for why these subrecipients were deemed to have low to no subrecipient risk based on the nature of the specific FEMA subawards, such as the projects were complete but waiting on final FEMA approval or had undergone a detailed approval process by FEMA prior to funds being obligated; however, the specific risk assessment for these subrecipients was not documented. We quantified the exposure for the lack of risk assessments by reviewing the Department’s listing of amounts paid to subrecipients and cross-referencing the listing to the risk assessments that were performed, noting that 68 of the 80 subrecipients (85 percent) did not have a risk assessment performed. These subrecipients accounted for approximately $15.2 million of the total $48.4 million (31 percent) of the total payments made by the Department to subrecipients during the current year. • The Department did not monitor whether 12 of the subrecipients were required to have a single audit, and if applicable, review the subrecipient’s single audit report and issue a management decision on findings. • The Department did not issue a management decision for 1 subrecipient until 8 months after the subrecipient filed its audit with the FAC, or 2 months after the time frame required by federal regulations. In addition, there was no documented approval for a change in the subrecipient monitoring plan to require performance of a more lenient set of procedures. Specifically, the Department’s original subrecipient monitoring plan specified that site visits would be performed for five specific subrecipients in Fiscal Year 2023; however, the Department indicated that they subsequently amended the subrecipient monitoring plan to revise the specific subrecipients subject to site visits, as well as reduced the total number of subrecipients that would receive site visits to four. Why did these problems occur? The Department did not have adequate internal controls in place to ensure it complied with subrecipient requirements or that it followed its own policies during Fiscal Year 2023. Specifically: • The Department indicated that they excluded subawards related to the 2013 floods incident, 2015 floods incident, small awards, and awards written at 100 percent complete because they viewed those arrangements as having little risk of noncompliance based on reporting that occurred up until that point in time, and did not document a risk assessment for each of the individual subrecipients. • The Department did not comply with its subrecipient monitoring policy or federal regulations, both of which require the Department to perform reviews of single audits for all subrecipients. • The Department failed to comply with the required timeframes for issuing management decisions because its subrecipient monitoring policy does not align with federal regulations. Specifically, the Department’s subrecipient monitoring policy requires management decisions to be issued within 15 months after the end of each subrecipient’s fiscal year rather than within 6 months of acceptance of the subrecipient’s audit report by the FAC. Additionally, the Department did not have an appropriate mechanism in place to identify, in a timely manner, when a subrecipient submitted an audit to the FAC. • The Department does not have written policies to address requirements for approval when modifications to the initial subrecipient risk assessment are made. Why do these problems matter? The issues we found are important because of the following: • By failing to properly document assessed risk of subrecipients, the Department is out of compliance with federal requirements and with its policy to assess risk for each subrecipient. This could result in the Department not timely identifying risks for subrecipients and modifying the extent of its monitoring activities to ensure the subrecipient has proper accountability and resources to be able to meet the program requirements. • By failing to verify that all subrecipients are audited as required by 2 CFR 200, Subpart F, the Department is out of compliance with federal requirements and its internal policies. This could result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and then making revisions to the monitoring risk assessment for the subrecipient. • Failing to ensure that subrecipient monitoring policies are in compliance with federal regulations could result in the Department not timely issuing management responses to a subrecipient’s findings. This could also result in the Department not timely identifying enforcement actions that may be needed against noncompliant subrecipients and including revisions to the subrecipient monitoring risk assessment. Recommendation 2023-075 The Department of Public Safety should strengthen its internal controls over, and ensure it complies with federal Disaster Grants – Public Assistance (Presidentially Declared Disasters) program requirements for subrecipient monitoring by: A. Updating its current policy to address considerations specific to subrecipients with open subawards that were waiting for final approval or had undergone a detailed approval by the Federal Emergency Management Agency prior to funds being obligated and modifications to the subrecipients risk assessments. B. Reviewing all subrecipients’ single audit reports. C. Updating its current subrecipient monitoring policy to be in compliance with federal regulations requiring management decisions to be issued within 6 months of acceptance of the subrecipient’s audit report by the Federal Audit Clearinghouse (FAC), and implementing a mechanism to track when subrecipients submit single audits to the FAC. Response Department of Public Safety A. Agree Implementation Date: June 2024 The Department will make sure that all subrecipients have a documented risk assessment, and if any changes to the risk assessment process are made, those will also be documented. B. Agree Implementation Date: March 2024 There is a requirement is to ensure that all single audit reports are completed by all sub-recipients, and we agree we need to implement this change with the annual Risk Assessment. C. Agree Implementation Date: June 2024 DHSEM Subrecipient Monitoring team will update their policy to reflect the following: single audits from the Subrecipients must be submitted to the Federal Audit Clearinghouse within the earlier of: 30 calendar days after receipt of the auditor's report(s); or nine months after the end of the audit period, unless a different period is specified in a program-specific audit guide. DHSEM Subrecipient Monitoring team will monitor the FAC for subrecipients recognized on the annual Risk Assessment, review the Single Audit and a management letter will go out within six months of the acceptance date from the FAC.
DHSEM Subrecipient Monitoring team will update their policy to reflect the following: single audits from the Subrecipients must be submitted to the Federal Audit Clearinghouse within the earlier of: 30 calendar days after receipt of the auditor's report(s); or nine months after the end of the audit period, unless a different period is specified in a program-specific audit guide. DHSEM Subrecipient Monitoring team will monitor the FAC for subrecipients recognized on the annual Risk Assessment, review the Single Audit and a management letter will go out within six months of the acceptance date from the FAC.
Finding 2023-076 and 2023-077 Internal Controls Over Exhibit K1 FEMA Disaster Grants Program Reporting, Activities Allowed or Unallowed and Allowable Costs/Cost Principles The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards include funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in the current year were for expenditures initially incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE personnel have the option to either submit costs that are classified as “work to be completed” or “work completed” to FEMA directly, and then if FEMA agrees that the costs are allowable, they will obligate additional funding. Then CDPHE submits costs to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, prior to disbursing funds to CDPHE. At the end of each fiscal year, CDPHE provides the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that have not been submitted for reimbursement through an interdepartmental transaction, and the Department in turn, recognizes an interdepartmental payable to CDPHE, along with the corresponding federal expenditures, federal revenues, and a federal receivable for the current fiscal year’s activity. The Department also includes this additional CDPHE-provided expenditure amount in the federal FEMA Disaster Grants program amount it reports on the Exhibit K1 each year. The Department does not complete a detailed review of the allowability of CDPHE’s expenditures until CDPHE submits supporting documentation for allowable expenditures to the Department’s grants management information system—EM Grants. Once CDPHE provides all necessary supporting documentation in EM Grants, the Department reports that it will complete its review of expenditures. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. Ultimately, the Department is responsible for appropriate review and approval of all allowable expenditures within EM Grants and for the appropriate reporting of the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2023, the Department reported $286.9 million in total FEMA Disaster Grants program expenditures. Of this amount, the Department reported $166.2 million (58 percent) of CDPHE’s Program expenditures during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department was in compliance with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether proper internal controls were in place over the FEMA Disaster Grants program during Fiscal Year 2023. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting and financial reporting of the FEMA Disaster Grants program activities within the Department’s Exhibit K1, and to determine whether the Department complied with applicable accounting standards during Fiscal Year 2023. We obtained an understanding of the Department’s internal controls over account balances, financial processes, and fiscal year-end close processes. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department and CDPHE personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures, and the associated Fiscal Year to report allowable expenditures in the Department’s and CDPHE’s Exhibit K1. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented the FEMA Disaster Grants program’s pass-through expenditures at CDPHE during the fiscal year, totaling $166.2 million, and compared to CDPHE’s CORE transactional data for the FEMA Disaster Grants program’s pass-through expenditures from the Department for Fiscal Year 2023, totaling $137.0 million. In addition, we inquired how the Department reconciled the transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 125 FEMA Disaster Grants program expenditures—totaling approximately $172.7 million—reported as being incurred during Fiscal Year 2023 to test the Department’s internal controls and compliance. Of these expenditures, 64 expenditures were specific to CDPHE’s CORE transaction data of FEMA Disaster Grants program expenditures (related to 17 journal entries) and totaled approximately $92.6 million. We performed testing on the 125 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-2 (3.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system. This should include controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • The OSC required departments to submit their Exhibit K1 by September 29, 2023. • The OSC’s Exhibit Instructions indicated that “When one State department or IHE passes a federal award through to another State department or IHE, a duplication of expenditures will be reported if both entities report the federal award or subaward on their Exhibits. To prevent this duplication in reporting, federal subawards received by a State department or IHE from another State department or IHE must not be reported on the Exhibit. The federal award must only be reported on the Exhibit of the State department or IHE that received the award from an entity external to the state government of Colorado.” • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulation [2 CFR 200.403(g)] requires that costs be adequately documented. • The 2023 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? As a result of our audit work, we determined that the Department did not have adequate internal controls over financial reporting, and did not comply with applicable accounting standards during Fiscal Year 2023. Specifically, the Department could not provide sufficient supporting documentation for $29.2 million of the $166.2 million (18 percent) of FEMA Disaster Grants program expenditures reported on its Fiscal Year 2023 Exhibit K1 related to FEMA Disaster Grants program funds expended by another state department—CDPHE. The Department did not properly reconcile summary-level reports received with the interdepartmental transactions to the amounts contained within CDPHE’s supporting transactional detail. We identified that the Department did not obtain detailed supporting documentation from CDPHE of FEMA Disaster Grants program expenditures that supported the interdepartmental payable, which represented cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE had incurred but for which it had not been reimbursed. We determined through follow-up testing of CDPHE’s expenditures of FEMA Disaster Grants program funds passed through from the Department that CDPHE’s records reflected $137.0 million in Fiscal Year 2023 expenditures—$29.2 million less than the Department reported on its Exhibit K1. During our audit and as of the completion of audit procedures, we were unable to obtain underlying support for the $29.2 million difference noted. Additionally, we identified issues with 28 of the 64 (44 percent) CDPHE pass-through expenditures reported on the Department’s Exhibit K1 that we selected for testing: • We noted 26 invoices (41 percent) that were posted to CORE and the Department’s Exhibit K1 as Fiscal Year 2023 expenditures, but that had service dates prior to Fiscal Year 2023 totaling $19.9 million. As of the completion of our audit fieldwork, the Department was unable to substantiate whether these costs were included within the prior year’s Exhibit K1. We were also unable to determine whether this $19.9 million in expenditures related to the $29.2 million difference we identified between the Department’s amount reported on the Fiscal Year 2023 Exhibit K1 and CDPHE records. • One transaction reported on the Department’s Exhibit K1 was a $10,000 estimate that was not adequately supported as of the completion of audit work. • One invoice totaling $53 was incorrectly coded to the FEMA Disaster Grants program within CORE and the Department’s Exhibit K1. Further, CDPHE improperly reported $139.3 million on CDPHE’s Exhibit K1 relating to the FEMA Disaster Grants program. These amounts were passed through from the Department to CDPHE and should not be included on CDPHE’s Exhibit K1. After we brought the issue to CDPHE’s attention, they corrected this error by submitting a revised Exhibit K1 to the OSC on January 31, 2024. Why did these problems occur? The Department and CDPHE did not have adequate internal controls, including sufficient policies and procedures, in place for Fiscal Year 2023 to ensure accurate and timely accounting and reporting of allowable FEMA Disaster Grants program expenditures on the Exhibit K1. Overall, the Department did not have a process in place to perform a full reconciliation of amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year-end; accrual amounts reported by CDPHE from the Department for the FEMA Disaster Grants program during the year; or fiscal period recording of reimbursement payments made by the Department to CDPHE during the year. The Department stated that it reconciled CDPHE’s FEMA Disaster Grants program expenditures based on the summary-level information provided with CDPHE’s interdepartmental transactions of the FEMA Disaster Grants program expenditures. However, the Department did not have policies and procedures in place requiring that Department staff request, obtain, and review sufficiently-detailed FEMA Disaster Grants program expenditure data from CDPHE to ensure that the interdepartmental transactions were appropriate, and that the Department’s Exhibit K1 reporting was correct when it was submitted to the OSC in September 2023. Additionally, the Department did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. As a result of the lack of reconciliation of expenditures incurred, and due to the nature of some expenditures tested related to periods prior to Fiscal Year 2023, we were unable to determine the full extent to which the Department’s Exhibit K1 FEMA Disaster Grants program expenditures ultimately were overstated or understated. Further, we were unable to determine whether CDPHE provided complete supporting documentation to the Department for all underlying costs incurred during Fiscal Year 2023, since the summary-level data utilized by the Department to prepare the Department’s K1 and the transactional level data provided by CDPHE was not reconciled until the end of the audit in January 2024. As part of the Department’s current process, the Department does not complete a detailed review of CDPHE’s FEMA Disaster Grants program expenditures at the time interdepartmental transactions are submitted by CDPHE, and reported on the Department’s Exhibit K1. Rather, the Department completes a detailed review once CDPHE submits supporting documentation for allowable expenditures into EM Grants. Once CDPHE provides all necessary supporting documentation, the Department will complete its expenditures review. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. As a result, any FEMA Disaster Grants program-eligible expenditures that CDPHE identified and reported to the Department as an interdepartmental accrual—but had not yet been reviewed by the Department within EM Grants—did not have a detailed review of allowability completed by the Department at the time the expenditures were reported on the Department’s Exhibit K1. Additionally, CDPHE did not review and identify the errors we identified in the two transactions where there was an estimated cost that was not adequately supported and one invoice that was incorrectly coded to the FEMA Disaster Grants program. Further, CDPHE was unable to provide a detailed reconciliation to the Department that reconciled summary-level information identified in the interdepartmental accrual to detailed transactions that were incurred. For instance, CDPHE did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. At the end of our audit test work in January 2024—nearly 4 months after the Exhibit K1 was due to the OSC—Department staff reported to us that they determined that the CDPHE-run report that was provided to us during the audit as support for the Disaster Grants program expenditures contained budget fiscal-year expenditures rather than fiscal year expenditures. Department staff further reported that, after identifying the fiscal year reporting issue, the Department compared the Exhibit K1 differences that we identified, and determined that the Exhibit K1 was actually understated by $12.0 million, and that they should have reported $178.2 million on the Exhibit K1 for the Disaster Grants program. Because our audit test work was complete, we did not review or test the Department’s comparison or the recalculated documentation provided by the Department. The current process for accounting and reporting over the FEMA Disaster Grants program did not include adequate communication and coordination between the Department and CDPHE to ensure that amounts were not duplicated by both the Department and CDPHE on each of their Exhibit K1s. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements, including an appropriate reconciliation and review of allowable expenditures, the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the Department to the federal granting agency. Recommendation 2023-076 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants – Public Assistance (Presidentially Declared Disasters) program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Developing, documenting, and implementing policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department and perform reconciliations of the information to underlying transactional data. This should include requiring that Department staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year and resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Developing, documenting, and implementing policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. Response Department of Public Safety A. Agree Implementation Date: September 2024 Policies and procedures have been created requiring sufficient detailed documentation from other agencies for all expenses submitted for reimbursement, including applicable period and allowability of expenses as recorded in EMGrants. We will perform an annual reconciliation of expenditures reported for accruals and reconcile differences when compiling the Exhibit K1. B. Agree Implementation Date: September 2024 Policies and procedures will be updated to require an annual reconciliation of expenditures reported for interagency accruals. Detailed expenses will also be reconciled with EMGrants for verification of allowability and applicable period as part of compiling the Exhibit K1.
Show full finding ▾Hide full finding ▴Finding 2023-076 and 2023-077 Internal Controls Over Exhibit K1 FEMA Disaster Grants Program Reporting, Activities Allowed or Unallowed and Allowable Costs/Cost Principles The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards include funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in the current year were for expenditures initially incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE personnel have the option to either submit costs that are classified as “work to be completed” or “work completed” to FEMA directly, and then if FEMA agrees that the costs are allowable, they will obligate additional funding. Then CDPHE submits costs to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, prior to disbursing funds to CDPHE. At the end of each fiscal year, CDPHE provides the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that have not been submitted for reimbursement through an interdepartmental transaction, and the Department in turn, recognizes an interdepartmental payable to CDPHE, along with the corresponding federal expenditures, federal revenues, and a federal receivable for the current fiscal year’s activity. The Department also includes this additional CDPHE-provided expenditure amount in the federal FEMA Disaster Grants program amount it reports on the Exhibit K1 each year. The Department does not complete a detailed review of the allowability of CDPHE’s expenditures until CDPHE submits supporting documentation for allowable expenditures to the Department’s grants management information system—EM Grants. Once CDPHE provides all necessary supporting documentation in EM Grants, the Department reports that it will complete its review of expenditures. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. Ultimately, the Department is responsible for appropriate review and approval of all allowable expenditures within EM Grants and for the appropriate reporting of the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2023, the Department reported $286.9 million in total FEMA Disaster Grants program expenditures. Of this amount, the Department reported $166.2 million (58 percent) of CDPHE’s Program expenditures during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department was in compliance with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether proper internal controls were in place over the FEMA Disaster Grants program during Fiscal Year 2023. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting and financial reporting of the FEMA Disaster Grants program activities within the Department’s Exhibit K1, and to determine whether the Department complied with applicable accounting standards during Fiscal Year 2023. We obtained an understanding of the Department’s internal controls over account balances, financial processes, and fiscal year-end close processes. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department and CDPHE personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures, and the associated Fiscal Year to report allowable expenditures in the Department’s and CDPHE’s Exhibit K1. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented the FEMA Disaster Grants program’s pass-through expenditures at CDPHE during the fiscal year, totaling $166.2 million, and compared to CDPHE’s CORE transactional data for the FEMA Disaster Grants program’s pass-through expenditures from the Department for Fiscal Year 2023, totaling $137.0 million. In addition, we inquired how the Department reconciled the transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 125 FEMA Disaster Grants program expenditures—totaling approximately $172.7 million—reported as being incurred during Fiscal Year 2023 to test the Department’s internal controls and compliance. Of these expenditures, 64 expenditures were specific to CDPHE’s CORE transaction data of FEMA Disaster Grants program expenditures (related to 17 journal entries) and totaled approximately $92.6 million. We performed testing on the 125 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-2 (3.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system. This should include controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • The OSC required departments to submit their Exhibit K1 by September 29, 2023. • The OSC’s Exhibit Instructions indicated that “When one State department or IHE passes a federal award through to another State department or IHE, a duplication of expenditures will be reported if both entities report the federal award or subaward on their Exhibits. To prevent this duplication in reporting, federal subawards received by a State department or IHE from another State department or IHE must not be reported on the Exhibit. The federal award must only be reported on the Exhibit of the State department or IHE that received the award from an entity external to the state government of Colorado.” • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulation [2 CFR 200.403(g)] requires that costs be adequately documented. • The 2023 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? As a result of our audit work, we determined that the Department did not have adequate internal controls over financial reporting, and did not comply with applicable accounting standards during Fiscal Year 2023. Specifically, the Department could not provide sufficient supporting documentation for $29.2 million of the $166.2 million (18 percent) of FEMA Disaster Grants program expenditures reported on its Fiscal Year 2023 Exhibit K1 related to FEMA Disaster Grants program funds expended by another state department—CDPHE. The Department did not properly reconcile summary-level reports received with the interdepartmental transactions to the amounts contained within CDPHE’s supporting transactional detail. We identified that the Department did not obtain detailed supporting documentation from CDPHE of FEMA Disaster Grants program expenditures that supported the interdepartmental payable, which represented cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE had incurred but for which it had not been reimbursed. We determined through follow-up testing of CDPHE’s expenditures of FEMA Disaster Grants program funds passed through from the Department that CDPHE’s records reflected $137.0 million in Fiscal Year 2023 expenditures—$29.2 million less than the Department reported on its Exhibit K1. During our audit and as of the completion of audit procedures, we were unable to obtain underlying support for the $29.2 million difference noted. Additionally, we identified issues with 28 of the 64 (44 percent) CDPHE pass-through expenditures reported on the Department’s Exhibit K1 that we selected for testing: • We noted 26 invoices (41 percent) that were posted to CORE and the Department’s Exhibit K1 as Fiscal Year 2023 expenditures, but that had service dates prior to Fiscal Year 2023 totaling $19.9 million. As of the completion of our audit fieldwork, the Department was unable to substantiate whether these costs were included within the prior year’s Exhibit K1. We were also unable to determine whether this $19.9 million in expenditures related to the $29.2 million difference we identified between the Department’s amount reported on the Fiscal Year 2023 Exhibit K1 and CDPHE records. • One transaction reported on the Department’s Exhibit K1 was a $10,000 estimate that was not adequately supported as of the completion of audit work. • One invoice totaling $53 was incorrectly coded to the FEMA Disaster Grants program within CORE and the Department’s Exhibit K1. Further, CDPHE improperly reported $139.3 million on CDPHE’s Exhibit K1 relating to the FEMA Disaster Grants program. These amounts were passed through from the Department to CDPHE and should not be included on CDPHE’s Exhibit K1. After we brought the issue to CDPHE’s attention, they corrected this error by submitting a revised Exhibit K1 to the OSC on January 31, 2024. Why did these problems occur? The Department and CDPHE did not have adequate internal controls, including sufficient policies and procedures, in place for Fiscal Year 2023 to ensure accurate and timely accounting and reporting of allowable FEMA Disaster Grants program expenditures on the Exhibit K1. Overall, the Department did not have a process in place to perform a full reconciliation of amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year-end; accrual amounts reported by CDPHE from the Department for the FEMA Disaster Grants program during the year; or fiscal period recording of reimbursement payments made by the Department to CDPHE during the year. The Department stated that it reconciled CDPHE’s FEMA Disaster Grants program expenditures based on the summary-level information provided with CDPHE’s interdepartmental transactions of the FEMA Disaster Grants program expenditures. However, the Department did not have policies and procedures in place requiring that Department staff request, obtain, and review sufficiently-detailed FEMA Disaster Grants program expenditure data from CDPHE to ensure that the interdepartmental transactions were appropriate, and that the Department’s Exhibit K1 reporting was correct when it was submitted to the OSC in September 2023. Additionally, the Department did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. As a result of the lack of reconciliation of expenditures incurred, and due to the nature of some expenditures tested related to periods prior to Fiscal Year 2023, we were unable to determine the full extent to which the Department’s Exhibit K1 FEMA Disaster Grants program expenditures ultimately were overstated or understated. Further, we were unable to determine whether CDPHE provided complete supporting documentation to the Department for all underlying costs incurred during Fiscal Year 2023, since the summary-level data utilized by the Department to prepare the Department’s K1 and the transactional level data provided by CDPHE was not reconciled until the end of the audit in January 2024. As part of the Department’s current process, the Department does not complete a detailed review of CDPHE’s FEMA Disaster Grants program expenditures at the time interdepartmental transactions are submitted by CDPHE, and reported on the Department’s Exhibit K1. Rather, the Department completes a detailed review once CDPHE submits supporting documentation for allowable expenditures into EM Grants. Once CDPHE provides all necessary supporting documentation, the Department will complete its expenditures review. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. As a result, any FEMA Disaster Grants program-eligible expenditures that CDPHE identified and reported to the Department as an interdepartmental accrual—but had not yet been reviewed by the Department within EM Grants—did not have a detailed review of allowability completed by the Department at the time the expenditures were reported on the Department’s Exhibit K1. Additionally, CDPHE did not review and identify the errors we identified in the two transactions where there was an estimated cost that was not adequately supported and one invoice that was incorrectly coded to the FEMA Disaster Grants program. Further, CDPHE was unable to provide a detailed reconciliation to the Department that reconciled summary-level information identified in the interdepartmental accrual to detailed transactions that were incurred. For instance, CDPHE did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. At the end of our audit test work in January 2024—nearly 4 months after the Exhibit K1 was due to the OSC—Department staff reported to us that they determined that the CDPHE-run report that was provided to us during the audit as support for the Disaster Grants program expenditures contained budget fiscal-year expenditures rather than fiscal year expenditures. Department staff further reported that, after identifying the fiscal year reporting issue, the Department compared the Exhibit K1 differences that we identified, and determined that the Exhibit K1 was actually understated by $12.0 million, and that they should have reported $178.2 million on the Exhibit K1 for the Disaster Grants program. Because our audit test work was complete, we did not review or test the Department’s comparison or the recalculated documentation provided by the Department. The current process for accounting and reporting over the FEMA Disaster Grants program did not include adequate communication and coordination between the Department and CDPHE to ensure that amounts were not duplicated by both the Department and CDPHE on each of their Exhibit K1s. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements, including an appropriate reconciliation and review of allowable expenditures, the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the Department to the federal granting agency. Recommendation 2023-076 The Department of Public Safety (Department) should strengthen its internal controls over the Federal Emergency Management Agency (FEMA) Disaster Grants – Public Assistance (Presidentially Declared Disasters) program funds, including financial accounting and reporting on its annual Exhibit K1, Schedule of Federal Assistance, by: A. Developing, documenting, and implementing policies and procedures to require that Department staff obtain and maintain sufficiently-detailed supporting documentation from the Department of Public Health and Environment (CDPHE) for CDPHE’s expenditure accrual of FEMA’s Disaster Grants program funds recorded by the Department and perform reconciliations of the information to underlying transactional data. This should include requiring that Department staff complete a full reconciliation on at least an annual basis of detailed amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year end; reimbursement amounts requested by CDPHE from the Department for the FEMA Disaster Grants program during the year; and reimbursement payments made by the Department to CDPHE during the year and resolve any reconciling differences prior to submitting the Exhibit K1 to the Office of the State Controller. B. Developing, documenting, and implementing policies and procedures to require that Department staff have a monitoring and review process in place over CDPHE’s Disaster Grants program federal expenditures that are reported on the Exhibit K1 in order to verify that expenditures are reported in the proper period and incurred under an approved project, and that expenditures are allowable under the federal program. Response Department of Public Safety A. Agree Implementation Date: September 2024 Policies and procedures have been created requiring sufficient detailed documentation from other agencies for all expenses submitted for reimbursement, including applicable period and allowability of expenses as recorded in EMGrants. We will perform an annual reconciliation of expenditures reported for accruals and reconcile differences when compiling the Exhibit K1. B. Agree Implementation Date: September 2024 Policies and procedures will be updated to require an annual reconciliation of expenditures reported for interagency accruals. Detailed expenses will also be reconciled with EMGrants for verification of allowability and applicable period as part of compiling the Exhibit K1.
Policies and procedures will be updated to require an annual reconciliation of expenditures reported for interagency accruals. Detailed expenses will also be reconciled with EMGrants for verification of allowability and applicable period as part of compiling the Exhibit K1.
Finding 2023-076 and 2023-077 Internal Controls Over Exhibit K1 FEMA Disaster Grants Program Reporting, Activities Allowed or Unallowed and Allowable Costs/Cost Principles The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards include funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in the current year were for expenditures initially incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE personnel have the option to either submit costs that are classified as “work to be completed” or “work completed” to FEMA directly, and then if FEMA agrees that the costs are allowable, they will obligate additional funding. Then CDPHE submits costs to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, prior to disbursing funds to CDPHE. At the end of each fiscal year, CDPHE provides the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that have not been submitted for reimbursement through an interdepartmental transaction, and the Department in turn, recognizes an interdepartmental payable to CDPHE, along with the corresponding federal expenditures, federal revenues, and a federal receivable for the current fiscal year’s activity. The Department also includes this additional CDPHE-provided expenditure amount in the federal FEMA Disaster Grants program amount it reports on the Exhibit K1 each year. The Department does not complete a detailed review of the allowability of CDPHE’s expenditures until CDPHE submits supporting documentation for allowable expenditures to the Department’s grants management information system—EM Grants. Once CDPHE provides all necessary supporting documentation in EM Grants, the Department reports that it will complete its review of expenditures. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. Ultimately, the Department is responsible for appropriate review and approval of all allowable expenditures within EM Grants and for the appropriate reporting of the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2023, the Department reported $286.9 million in total FEMA Disaster Grants program expenditures. Of this amount, the Department reported $166.2 million (58 percent) of CDPHE’s Program expenditures during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department was in compliance with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether proper internal controls were in place over the FEMA Disaster Grants program during Fiscal Year 2023. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting and financial reporting of the FEMA Disaster Grants program activities within the Department’s Exhibit K1, and to determine whether the Department complied with applicable accounting standards during Fiscal Year 2023. We obtained an understanding of the Department’s internal controls over account balances, financial processes, and fiscal year-end close processes. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department and CDPHE personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures, and the associated Fiscal Year to report allowable expenditures in the Department’s and CDPHE’s Exhibit K1. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented the FEMA Disaster Grants program’s pass-through expenditures at CDPHE during the fiscal year, totaling $166.2 million, and compared to CDPHE’s CORE transactional data for the FEMA Disaster Grants program’s pass-through expenditures from the Department for Fiscal Year 2023, totaling $137.0 million. In addition, we inquired how the Department reconciled the transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 125 FEMA Disaster Grants program expenditures—totaling approximately $172.7 million—reported as being incurred during Fiscal Year 2023 to test the Department’s internal controls and compliance. Of these expenditures, 64 expenditures were specific to CDPHE’s CORE transaction data of FEMA Disaster Grants program expenditures (related to 17 journal entries) and totaled approximately $92.6 million. We performed testing on the 125 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-2 (3.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system. This should include controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • The OSC required departments to submit their Exhibit K1 by September 29, 2023. • The OSC’s Exhibit Instructions indicated that “When one State department or IHE passes a federal award through to another State department or IHE, a duplication of expenditures will be reported if both entities report the federal award or subaward on their Exhibits. To prevent this duplication in reporting, federal subawards received by a State department or IHE from another State department or IHE must not be reported on the Exhibit. The federal award must only be reported on the Exhibit of the State department or IHE that received the award from an entity external to the state government of Colorado.” • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulation [2 CFR 200.403(g)] requires that costs be adequately documented. • The 2023 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? As a result of our audit work, we determined that the Department did not have adequate internal controls over financial reporting, and did not comply with applicable accounting standards during Fiscal Year 2023. Specifically, the Department could not provide sufficient supporting documentation for $29.2 million of the $166.2 million (18 percent) of FEMA Disaster Grants program expenditures reported on its Fiscal Year 2023 Exhibit K1 related to FEMA Disaster Grants program funds expended by another state department—CDPHE. The Department did not properly reconcile summary-level reports received with the interdepartmental transactions to the amounts contained within CDPHE’s supporting transactional detail. We identified that the Department did not obtain detailed supporting documentation from CDPHE of FEMA Disaster Grants program expenditures that supported the interdepartmental payable, which represented cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE had incurred but for which it had not been reimbursed. We determined through follow-up testing of CDPHE’s expenditures of FEMA Disaster Grants program funds passed through from the Department that CDPHE’s records reflected $137.0 million in Fiscal Year 2023 expenditures—$29.2 million less than the Department reported on its Exhibit K1. During our audit and as of the completion of audit procedures, we were unable to obtain underlying support for the $29.2 million difference noted. Additionally, we identified issues with 28 of the 64 (44 percent) CDPHE pass-through expenditures reported on the Department’s Exhibit K1 that we selected for testing: • We noted 26 invoices (41 percent) that were posted to CORE and the Department’s Exhibit K1 as Fiscal Year 2023 expenditures, but that had service dates prior to Fiscal Year 2023 totaling $19.9 million. As of the completion of our audit fieldwork, the Department was unable to substantiate whether these costs were included within the prior year’s Exhibit K1. We were also unable to determine whether this $19.9 million in expenditures related to the $29.2 million difference we identified between the Department’s amount reported on the Fiscal Year 2023 Exhibit K1 and CDPHE records. • One transaction reported on the Department’s Exhibit K1 was a $10,000 estimate that was not adequately supported as of the completion of audit work. • One invoice totaling $53 was incorrectly coded to the FEMA Disaster Grants program within CORE and the Department’s Exhibit K1. Further, CDPHE improperly reported $139.3 million on CDPHE’s Exhibit K1 relating to the FEMA Disaster Grants program. These amounts were passed through from the Department to CDPHE and should not be included on CDPHE’s Exhibit K1. After we brought the issue to CDPHE’s attention, they corrected this error by submitting a revised Exhibit K1 to the OSC on January 31, 2024. Why did these problems occur? The Department and CDPHE did not have adequate internal controls, including sufficient policies and procedures, in place for Fiscal Year 2023 to ensure accurate and timely accounting and reporting of allowable FEMA Disaster Grants program expenditures on the Exhibit K1. Overall, the Department did not have a process in place to perform a full reconciliation of amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year-end; accrual amounts reported by CDPHE from the Department for the FEMA Disaster Grants program during the year; or fiscal period recording of reimbursement payments made by the Department to CDPHE during the year. The Department stated that it reconciled CDPHE’s FEMA Disaster Grants program expenditures based on the summary-level information provided with CDPHE’s interdepartmental transactions of the FEMA Disaster Grants program expenditures. However, the Department did not have policies and procedures in place requiring that Department staff request, obtain, and review sufficiently-detailed FEMA Disaster Grants program expenditure data from CDPHE to ensure that the interdepartmental transactions were appropriate, and that the Department’s Exhibit K1 reporting was correct when it was submitted to the OSC in September 2023. Additionally, the Department did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. As a result of the lack of reconciliation of expenditures incurred, and due to the nature of some expenditures tested related to periods prior to Fiscal Year 2023, we were unable to determine the full extent to which the Department’s Exhibit K1 FEMA Disaster Grants program expenditures ultimately were overstated or understated. Further, we were unable to determine whether CDPHE provided complete supporting documentation to the Department for all underlying costs incurred during Fiscal Year 2023, since the summary-level data utilized by the Department to prepare the Department’s K1 and the transactional level data provided by CDPHE was not reconciled until the end of the audit in January 2024. As part of the Department’s current process, the Department does not complete a detailed review of CDPHE’s FEMA Disaster Grants program expenditures at the time interdepartmental transactions are submitted by CDPHE, and reported on the Department’s Exhibit K1. Rather, the Department completes a detailed review once CDPHE submits supporting documentation for allowable expenditures into EM Grants. Once CDPHE provides all necessary supporting documentation, the Department will complete its expenditures review. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. As a result, any FEMA Disaster Grants program-eligible expenditures that CDPHE identified and reported to the Department as an interdepartmental accrual—but had not yet been reviewed by the Department within EM Grants—did not have a detailed review of allowability completed by the Department at the time the expenditures were reported on the Department’s Exhibit K1. Additionally, CDPHE did not review and identify the errors we identified in the two transactions where there was an estimated cost that was not adequately supported and one invoice that was incorrectly coded to the FEMA Disaster Grants program. Further, CDPHE was unable to provide a detailed reconciliation to the Department that reconciled summary-level information identified in the interdepartmental accrual to detailed transactions that were incurred. For instance, CDPHE did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. At the end of our audit test work in January 2024—nearly 4 months after the Exhibit K1 was due to the OSC—Department staff reported to us that they determined that the CDPHE-run report that was provided to us during the audit as support for the Disaster Grants program expenditures contained budget fiscal-year expenditures rather than fiscal year expenditures. Department staff further reported that, after identifying the fiscal year reporting issue, the Department compared the Exhibit K1 differences that we identified, and determined that the Exhibit K1 was actually understated by $12.0 million, and that they should have reported $178.2 million on the Exhibit K1 for the Disaster Grants program. Because our audit test work was complete, we did not review or test the Department’s comparison or the recalculated documentation provided by the Department. The current process for accounting and reporting over the FEMA Disaster Grants program did not include adequate communication and coordination between the Department and CDPHE to ensure that amounts were not duplicated by both the Department and CDPHE on each of their Exhibit K1s. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements, including an appropriate reconciliation and review of allowable expenditures, the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the Department to the federal granting agency. Recommendation 2023-077 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants – Public Assistance (Presidentially Declared Disasters) program expenditures that are submitted to the Department of Public Safety (Department) through interdepartmental transactions and requests for reimbursement by: A. Ensuring that all Disaster Grants program expenditures are properly supported with appropriate documentation and are reviewed to ensure the expenditures are allowable under the FEMA Disaster Grants program and recorded for the correct fiscal year. B. Expanding the Department’s existing policies and procedures that outline the process CDPHE staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department for the Exhibit K1, Schedule of Federal Assistance, reporting and for recording and reconciling interdepartmental reimbursements. The policies and procedures should also include required points of communication between staff of the Department and CDPHE to ensure that reported amounts are not duplicated. C. Providing applicable training to CDPHE staff responsible for Disaster Grants program reporting on the policies and procedures developed and implemented in part B of this finding. Response Department of Public Health and Environment A. Partially Agree Implementation Date: June 2024 CDPHE consistently saves every invoice related to requested reimbursement, and the CDPS Office of Grants Management/Preparedness reviews and approves them through the EMGrants system. CDPHE has not charged any expenditures to the CDPS through an interdepartmental charge that were not accompanied by an approved request for reimbursement (RFR). We do not charge or draw down any funds from CDPS until explicit approvals are received regarding FEMA eligibility, as reflected in EMGrants. Copies of the relevant EMGrants RFR approvals are included every time CDPHE draws down funds from CDPS. This process will be written into a procedure to ensure consistency. FEMA program expenditures will continue to be submitted, reviewed, and approved through the RFR process in EMGrants to determine allowability. Steps will be taken when requesting payment from CDPS to ensure the data is accurate. As a process improvement, these will be included in the procedure document, which will include identifying the Project Worksheet number for each transaction to match the FEMA listing and the applicable fiscal year on all documents. Individual transactions will continue to display this information, and additional backup will be included for adjusting entries. Auditor’s Addendum At the time CDPHE submits interdepartmental charges to the Department through the year end interdepartmental payable, CDPHE should ensure that all individual transactions are adequately supported through documentation that supports the allowability of eligible costs under the FEMA Disaster Grants Program, this is in addition to approvals within the RFR process in EMGrants. Oftentimes there is a lag between when expenditures are required to be recognized on the Department of Public Safety’s Exhibit K1 and when the RFR process is completed within EMGrants. B. Agree Implementation Date: June 2024 CDPHE currently has a written procedure in place to complete Exhibit K1. However, this wasn’t completely followed due to turnover in the CDPHE Controller position during the Fiscal Year transition, as that document was not known to the new Controller. For FY23, CDPHE primarily followed the standard Exhibit Instructions from OSC, which included several pages on the K1. The internal procedure has now been identified and will be updated to incorporate any new OSC instructions for subsequent reporting to ensure CDPHE is maintaining compliance with all requirements. Additionally, the procedure will include steps to verify the K1 with CDPS before it’s submission to ensure that the pass through Disaster Grant expenditures are not included with both agency’s K1’s. As part of the procedure to be developed in response to part A of this finding, Disaster Grants Program staff will complete a full reconciliation of detailed amounts reported as FEMA Disaster Grants Program expenditures for the fiscal year, including accruals for expenses incurred but not yet reimbursed by CDPHE. CDPHE and CDPS will meet on a regular basis to ensure proper communication between the agencies. C. Agree Implementation Date: June 2024 To follow up on parts a and b of these recommendations, CDPHE accounting will work with the staff responsible for Disaster Grants Program to document the procedure for requesting reimbursement from CDPS. This training will ensure that transactions are recorded to the proper fiscal year and should simplify the year-end reporting process and reduce the likelihood of repeat errors. In updating the specific K1 documented procedures, CDPHE accounting will make sure that the written K1 procedures have additional instructions to reflect amounts that are passed through from other state agencies. Those accounting staff responsible for generating the Exhibit K1 will be trained to ensure that interdepartmental charges are appropriate and that the department’s Exhibit K1 report is correct when submitted to the OSC.
Show full finding ▾Hide full finding ▴Finding 2023-076 and 2023-077 Internal Controls Over Exhibit K1 FEMA Disaster Grants Program Reporting, Activities Allowed or Unallowed and Allowable Costs/Cost Principles The Department’s accounting staff is responsible for all of the Department’s financial accounting and reporting, including the accurate and timely entry of financial transactions into the Colorado Operations Resource Engine (CORE), the State’s accounting system. The Department is also required to prepare its financial transactions in accordance with Generally Accepted Accounting Principles (GAAP). The Office of the State Controller (OSC) uses the financial transactions in CORE to prepare the State’s financial statements, which are also required to be prepared in accordance with GAAP. The Governmental Accounting Standards Board (GASB) establishes GAAP for state and local government entities through the issuance of GASB statements and authoritative accounting guidance such as GASB implementation guides, that the Department and OSC must comply with when preparing financial transactions and statements. The OSC has also established guidelines that require the Department to report its financial activities through forms, or exhibits, submitted to the OSC for inclusion in the State’s financial statements. The OSC collects the information from state departments through submitted exhibits to assist in its preparation of the State’s financial statements, required note disclosures, and the Schedule of Expenditures of Federal Awards (SEFA). The State is required to comply with the reporting requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for the State’s SEFA. The federal Office of Management and Budget’s (OMB) Compliance Supplement is part of Uniform Guidance and provides additional information required to be included on the SEFA. For SEFA reporting, the OSC requires that state departments prepare and submit an Exhibit K1, Schedule of Federal Assistance, after each fiscal year end to provide information on their federal expenditures for the OSC’s preparation of the State’s SEFA. The OSC specifies that expenditures of federal funds that are received by one state agency and passed on to another state agency for spending should be reported on the first department’s Exhibit K1. For example, the Department is required to report federal expenditures of FEMA Disaster Grants program funds that were passed by the Department to the Department of Public Health and Environment (CDPHE); this includes any expenditures that have been made by CDPHE but have not yet been reimbursed by the Department. The Department’s FEMA Disaster Grants program awards include funding for the purpose of responding to the COVID-19 pandemic. A portion of expenditures recognized by the Department under this award in the current year were for expenditures initially incurred by CDPHE for responding to the COVID-19 pandemic. CDPHE personnel have the option to either submit costs that are classified as “work to be completed” or “work completed” to FEMA directly, and then if FEMA agrees that the costs are allowable, they will obligate additional funding. Then CDPHE submits costs to the Department through a request for reimbursement, and the Department has policies and procedures to verify that CDPHE complied with all applicable rules and regulations and followed the scope of work, prior to disbursing funds to CDPHE. At the end of each fiscal year, CDPHE provides the Department summary-level detail of cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE incurred during prior fiscal years, as well as the current fiscal year, that have not been submitted for reimbursement through an interdepartmental transaction, and the Department in turn, recognizes an interdepartmental payable to CDPHE, along with the corresponding federal expenditures, federal revenues, and a federal receivable for the current fiscal year’s activity. The Department also includes this additional CDPHE-provided expenditure amount in the federal FEMA Disaster Grants program amount it reports on the Exhibit K1 each year. The Department does not complete a detailed review of the allowability of CDPHE’s expenditures until CDPHE submits supporting documentation for allowable expenditures to the Department’s grants management information system—EM Grants. Once CDPHE provides all necessary supporting documentation in EM Grants, the Department reports that it will complete its review of expenditures. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. Ultimately, the Department is responsible for appropriate review and approval of all allowable expenditures within EM Grants and for the appropriate reporting of the FEMA Disaster Grants program expenditures on the Exhibit K1. For Fiscal Year 2023, the Department reported $286.9 million in total FEMA Disaster Grants program expenditures. Of this amount, the Department reported $166.2 million (58 percent) of CDPHE’s Program expenditures during Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department was in compliance with the FEMA Disaster Grants program requirements for incurring and recognizing allowable activities and allowable costs, and whether proper internal controls were in place over the FEMA Disaster Grants program during Fiscal Year 2023. In addition, the purpose of our audit work was to review the Department’s internal controls over accounting and financial reporting of the FEMA Disaster Grants program activities within the Department’s Exhibit K1, and to determine whether the Department complied with applicable accounting standards during Fiscal Year 2023. We obtained an understanding of the Department’s internal controls over account balances, financial processes, and fiscal year-end close processes. Specifically, we performed the following: • Inquired of the Department to gain an understanding of its process for recognizing and reporting expenditures on its Exhibit K1, including the recognition of the FEMA Disaster Grants program expenditures incurred by CDPHE. • Inquired of the Department and CDPHE personnel regarding their processes for determining allowability of the FEMA Disaster Grants program expenditures, and the associated Fiscal Year to report allowable expenditures in the Department’s and CDPHE’s Exhibit K1. • Obtained and analyzed the Department’s summary-level expenditure transactions recorded in CORE that represented the FEMA Disaster Grants program’s pass-through expenditures at CDPHE during the fiscal year, totaling $166.2 million, and compared to CDPHE’s CORE transactional data for the FEMA Disaster Grants program’s pass-through expenditures from the Department for Fiscal Year 2023, totaling $137.0 million. In addition, we inquired how the Department reconciled the transactional data to CDPHE data to determine whether CDPHE FEMA Disaster Grants program expenditures were recognized for the proper amount and in the proper fiscal year on the Department’s Exhibit K1. • Selected a sample of 125 FEMA Disaster Grants program expenditures—totaling approximately $172.7 million—reported as being incurred during Fiscal Year 2023 to test the Department’s internal controls and compliance. Of these expenditures, 64 expenditures were specific to CDPHE’s CORE transaction data of FEMA Disaster Grants program expenditures (related to 17 journal entries) and totaled approximately $92.6 million. We performed testing on the 125 expenditures to determine whether the expenditures were made in accordance with FEMA’s Disaster Grants program requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • The OSC’s Fiscal Procedures Manual, Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives, states that one of the objectives of the State of Colorado reporting includes “maintaining accounting records in accordance with Generally Accepted Accounting Principles (GAAP) and in compliance with Governmental Accounting Standards Board (GASB) pronouncements.” • State Fiscal Rule 1-2 (3.5), Internal Controls, requires that state agencies “implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to the Fiscal Rules, and reflect the underlying realities of the accounting transaction (substance rather than form).” For example, internal accounting and administrative controls include periodic staff training on fiscal year-end accounting processes, development of procedures, and implementation of new governmental accounting standards. • The OSC has adopted the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as the State’s standard for internal controls, which all state agencies must follow. Green Book, Paragraph OV2.14, Roles in an Internal Control System, states that management is responsible for designing an internal control system. This should include controls over the preparation of financial reporting in accordance with professional standards and applicable laws and regulations. • The OSC required departments to submit their Exhibit K1 by September 29, 2023. • The OSC’s Exhibit Instructions indicated that “When one State department or IHE passes a federal award through to another State department or IHE, a duplication of expenditures will be reported if both entities report the federal award or subaward on their Exhibits. To prevent this duplication in reporting, federal subawards received by a State department or IHE from another State department or IHE must not be reported on the Exhibit. The federal award must only be reported on the Exhibit of the State department or IHE that received the award from an entity external to the state government of Colorado.” • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards that provide reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the date of submission of the final expenditures report. • Federal regulation [2 CFR 200.403(g)] requires that costs be adequately documented. • The 2023 OMB Compliance Supplement requires FEMA Disaster Grants program expenditures to be reported on the SEFA when (1) FEMA has approved the project and (2) eligible expenditures have been incurred. What problems did the audit work identify? As a result of our audit work, we determined that the Department did not have adequate internal controls over financial reporting, and did not comply with applicable accounting standards during Fiscal Year 2023. Specifically, the Department could not provide sufficient supporting documentation for $29.2 million of the $166.2 million (18 percent) of FEMA Disaster Grants program expenditures reported on its Fiscal Year 2023 Exhibit K1 related to FEMA Disaster Grants program funds expended by another state department—CDPHE. The Department did not properly reconcile summary-level reports received with the interdepartmental transactions to the amounts contained within CDPHE’s supporting transactional detail. We identified that the Department did not obtain detailed supporting documentation from CDPHE of FEMA Disaster Grants program expenditures that supported the interdepartmental payable, which represented cumulative-to-date FEMA Disaster Grants program allowable expenditures that CDPHE had incurred but for which it had not been reimbursed. We determined through follow-up testing of CDPHE’s expenditures of FEMA Disaster Grants program funds passed through from the Department that CDPHE’s records reflected $137.0 million in Fiscal Year 2023 expenditures—$29.2 million less than the Department reported on its Exhibit K1. During our audit and as of the completion of audit procedures, we were unable to obtain underlying support for the $29.2 million difference noted. Additionally, we identified issues with 28 of the 64 (44 percent) CDPHE pass-through expenditures reported on the Department’s Exhibit K1 that we selected for testing: • We noted 26 invoices (41 percent) that were posted to CORE and the Department’s Exhibit K1 as Fiscal Year 2023 expenditures, but that had service dates prior to Fiscal Year 2023 totaling $19.9 million. As of the completion of our audit fieldwork, the Department was unable to substantiate whether these costs were included within the prior year’s Exhibit K1. We were also unable to determine whether this $19.9 million in expenditures related to the $29.2 million difference we identified between the Department’s amount reported on the Fiscal Year 2023 Exhibit K1 and CDPHE records. • One transaction reported on the Department’s Exhibit K1 was a $10,000 estimate that was not adequately supported as of the completion of audit work. • One invoice totaling $53 was incorrectly coded to the FEMA Disaster Grants program within CORE and the Department’s Exhibit K1. Further, CDPHE improperly reported $139.3 million on CDPHE’s Exhibit K1 relating to the FEMA Disaster Grants program. These amounts were passed through from the Department to CDPHE and should not be included on CDPHE’s Exhibit K1. After we brought the issue to CDPHE’s attention, they corrected this error by submitting a revised Exhibit K1 to the OSC on January 31, 2024. Why did these problems occur? The Department and CDPHE did not have adequate internal controls, including sufficient policies and procedures, in place for Fiscal Year 2023 to ensure accurate and timely accounting and reporting of allowable FEMA Disaster Grants program expenditures on the Exhibit K1. Overall, the Department did not have a process in place to perform a full reconciliation of amounts reported as FEMA Disaster Grants program expenditures for the fiscal year, including expenditures incurred by CDPHE but not yet reimbursed by the Department as of fiscal year-end; accrual amounts reported by CDPHE from the Department for the FEMA Disaster Grants program during the year; or fiscal period recording of reimbursement payments made by the Department to CDPHE during the year. The Department stated that it reconciled CDPHE’s FEMA Disaster Grants program expenditures based on the summary-level information provided with CDPHE’s interdepartmental transactions of the FEMA Disaster Grants program expenditures. However, the Department did not have policies and procedures in place requiring that Department staff request, obtain, and review sufficiently-detailed FEMA Disaster Grants program expenditure data from CDPHE to ensure that the interdepartmental transactions were appropriate, and that the Department’s Exhibit K1 reporting was correct when it was submitted to the OSC in September 2023. Additionally, the Department did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. As a result of the lack of reconciliation of expenditures incurred, and due to the nature of some expenditures tested related to periods prior to Fiscal Year 2023, we were unable to determine the full extent to which the Department’s Exhibit K1 FEMA Disaster Grants program expenditures ultimately were overstated or understated. Further, we were unable to determine whether CDPHE provided complete supporting documentation to the Department for all underlying costs incurred during Fiscal Year 2023, since the summary-level data utilized by the Department to prepare the Department’s K1 and the transactional level data provided by CDPHE was not reconciled until the end of the audit in January 2024. As part of the Department’s current process, the Department does not complete a detailed review of CDPHE’s FEMA Disaster Grants program expenditures at the time interdepartmental transactions are submitted by CDPHE, and reported on the Department’s Exhibit K1. Rather, the Department completes a detailed review once CDPHE submits supporting documentation for allowable expenditures into EM Grants. Once CDPHE provides all necessary supporting documentation, the Department will complete its expenditures review. After the Department has completed its review, CDPHE submits a request for reimbursement for the approved allowable expenditures. As a result, any FEMA Disaster Grants program-eligible expenditures that CDPHE identified and reported to the Department as an interdepartmental accrual—but had not yet been reviewed by the Department within EM Grants—did not have a detailed review of allowability completed by the Department at the time the expenditures were reported on the Department’s Exhibit K1. Additionally, CDPHE did not review and identify the errors we identified in the two transactions where there was an estimated cost that was not adequately supported and one invoice that was incorrectly coded to the FEMA Disaster Grants program. Further, CDPHE was unable to provide a detailed reconciliation to the Department that reconciled summary-level information identified in the interdepartmental accrual to detailed transactions that were incurred. For instance, CDPHE did not reconcile Fiscal Year 2023 CDPHE requests for reimbursement of the FEMA Disaster Grants program’s expenditures against transactions that were included in Fiscal Year 2022’s expenditures to ensure they were reported in the appropriate fiscal year. At the end of our audit test work in January 2024—nearly 4 months after the Exhibit K1 was due to the OSC—Department staff reported to us that they determined that the CDPHE-run report that was provided to us during the audit as support for the Disaster Grants program expenditures contained budget fiscal-year expenditures rather than fiscal year expenditures. Department staff further reported that, after identifying the fiscal year reporting issue, the Department compared the Exhibit K1 differences that we identified, and determined that the Exhibit K1 was actually understated by $12.0 million, and that they should have reported $178.2 million on the Exhibit K1 for the Disaster Grants program. Because our audit test work was complete, we did not review or test the Department’s comparison or the recalculated documentation provided by the Department. The current process for accounting and reporting over the FEMA Disaster Grants program did not include adequate communication and coordination between the Department and CDPHE to ensure that amounts were not duplicated by both the Department and CDPHE on each of their Exhibit K1s. Why do these problems matter? Without adequate internal controls in place over compliance with the FEMA Disaster Grants program requirements, including an appropriate reconciliation and review of allowable expenditures, the Department and CDPHE could be out of compliance with federal allowable cost requirements, which may result in the federal oversight agency relying on incorrect data reported in the State’s SEFA. Further, failure to properly reconcile and report expenditures on the Department’s Exhibit K1, if uncorrected, could cause the State’s SEFA to be inaccurate and the Department to be out of compliance with federal reporting requirements. Lastly, federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the Department to the federal granting agency. Recommendation 2023-077 The Colorado Department of Public Health and Environment (CDPHE) should improve its internal controls over Federal Emergency Management Agency (FEMA) Disaster Grants – Public Assistance (Presidentially Declared Disasters) program expenditures that are submitted to the Department of Public Safety (Department) through interdepartmental transactions and requests for reimbursement by: A. Ensuring that all Disaster Grants program expenditures are properly supported with appropriate documentation and are reviewed to ensure the expenditures are allowable under the FEMA Disaster Grants program and recorded for the correct fiscal year. B. Expanding the Department’s existing policies and procedures that outline the process CDPHE staff must follow when reporting fiscal year Disaster Grants program expenditures to the Department for the Exhibit K1, Schedule of Federal Assistance, reporting and for recording and reconciling interdepartmental reimbursements. The policies and procedures should also include required points of communication between staff of the Department and CDPHE to ensure that reported amounts are not duplicated. C. Providing applicable training to CDPHE staff responsible for Disaster Grants program reporting on the policies and procedures developed and implemented in part B of this finding. Response Department of Public Health and Environment A. Partially Agree Implementation Date: June 2024 CDPHE consistently saves every invoice related to requested reimbursement, and the CDPS Office of Grants Management/Preparedness reviews and approves them through the EMGrants system. CDPHE has not charged any expenditures to the CDPS through an interdepartmental charge that were not accompanied by an approved request for reimbursement (RFR). We do not charge or draw down any funds from CDPS until explicit approvals are received regarding FEMA eligibility, as reflected in EMGrants. Copies of the relevant EMGrants RFR approvals are included every time CDPHE draws down funds from CDPS. This process will be written into a procedure to ensure consistency. FEMA program expenditures will continue to be submitted, reviewed, and approved through the RFR process in EMGrants to determine allowability. Steps will be taken when requesting payment from CDPS to ensure the data is accurate. As a process improvement, these will be included in the procedure document, which will include identifying the Project Worksheet number for each transaction to match the FEMA listing and the applicable fiscal year on all documents. Individual transactions will continue to display this information, and additional backup will be included for adjusting entries. Auditor’s Addendum At the time CDPHE submits interdepartmental charges to the Department through the year end interdepartmental payable, CDPHE should ensure that all individual transactions are adequately supported through documentation that supports the allowability of eligible costs under the FEMA Disaster Grants Program, this is in addition to approvals within the RFR process in EMGrants. Oftentimes there is a lag between when expenditures are required to be recognized on the Department of Public Safety’s Exhibit K1 and when the RFR process is completed within EMGrants. B. Agree Implementation Date: June 2024 CDPHE currently has a written procedure in place to complete Exhibit K1. However, this wasn’t completely followed due to turnover in the CDPHE Controller position during the Fiscal Year transition, as that document was not known to the new Controller. For FY23, CDPHE primarily followed the standard Exhibit Instructions from OSC, which included several pages on the K1. The internal procedure has now been identified and will be updated to incorporate any new OSC instructions for subsequent reporting to ensure CDPHE is maintaining compliance with all requirements. Additionally, the procedure will include steps to verify the K1 with CDPS before it’s submission to ensure that the pass through Disaster Grant expenditures are not included with both agency’s K1’s. As part of the procedure to be developed in response to part A of this finding, Disaster Grants Program staff will complete a full reconciliation of detailed amounts reported as FEMA Disaster Grants Program expenditures for the fiscal year, including accruals for expenses incurred but not yet reimbursed by CDPHE. CDPHE and CDPS will meet on a regular basis to ensure proper communication between the agencies. C. Agree Implementation Date: June 2024 To follow up on parts a and b of these recommendations, CDPHE accounting will work with the staff responsible for Disaster Grants Program to document the procedure for requesting reimbursement from CDPS. This training will ensure that transactions are recorded to the proper fiscal year and should simplify the year-end reporting process and reduce the likelihood of repeat errors. In updating the specific K1 documented procedures, CDPHE accounting will make sure that the written K1 procedures have additional instructions to reflect amounts that are passed through from other state agencies. Those accounting staff responsible for generating the Exhibit K1 will be trained to ensure that interdepartmental charges are appropriate and that the department’s Exhibit K1 report is correct when submitted to the OSC.
To follow up on parts a and b of these recommendations, CDPHE accounting will work with the staff responsible for Disaster Grants Program to document the procedure for requesting reimbursement from CDPS. This training will ensure that transactions are recorded to the proper fiscal year and should simplify the year-end reporting process and reduce the likelihood of repeat errors. In updating the specific K1 documented procedures, CDPHE accounting will make sure that the written K1 procedures have additional instructions to reflect amounts that are passed through from other state agencies. Those accounting staff responsible for generating the Exhibit K1 will be trained to ensure that interdepartmental charges are appropriate and that the department’s Exhibit K1 report is correct when submitted to the OSC.
Finding 2023-078 Disaster Grants – Public Assistance (Presidentially Declared Disasters) Federal Reporting The Department receives federal grant awards and is required to follow certain financial, performance, and other reporting requirements as specifically identified in the various grant award agreements. The Department allocates funds received from these federal awards to subrecipients and the Department is responsible for the reporting of the payments made to its subrecipients. Federal Financial Reporting The Department is required to submit Federal Financial Status Reports (FFR) quarterly to the FEMA Regional Office for each of its Disaster Grants. The FFRs are a way for the Department to show FEMA, as the granting agency, the status of its grant funds and demonstrate that it is meeting the grant’s cost-sharing requirements. The FFRs provide cumulative-to-date information from project inception through the end of each reporting period. Financial information within the FFRs includes information such as federal cash disbursements from grant inception to the date of the report, total federal funds authorized, federal share of expenditures from grant inception to the date of the report, and recipient share of expenditures from grant inception to the date of the report. During Fiscal Year 2023, the Department had five outstanding FEMA grant awards and was required to submit 20 quarterly FFRs. Performance Reporting The Department is required to submit Large Project Quarterly Progress Reports (QPR) to FEMA on a quarterly basis. The QPRs are a tool for FEMA and the Department to track the progress of Large Projects—defined by FEMA as an individual project with approved estimated, eligible costs of $1,000,000 or greater. The QPRs include information submitted from the Department’s FEMA subrecipients, such as: • Subrecipient’s total expenditures from grant inception to report date, • Status of the project(s) (e.g., the percent complete), • Whether the work is complete, and • Projected or actual completion date for the project(s). The Department must review, verify, and submit the subrecipient’s information on the QPR, and the Department must then, on a quarterly basis, submit the following for each open Large Project: • Total amount disbursed to the subrecipient from grant inception to report date. • Whether final payment was made to that specific subrecipient and the subrecipient’s project was ready for closeout. • Whether extensions to overall project closeout timing were submitted by the State and approved by FEMA. • Applicable project closeout deadline approved by FEMA. For Fiscal Year 2023, the Department had five outstanding FEMA grant awards with total federal funds obligated of approximately $2.4 billion, as of June 30, 2023, and was required to submit eight QPRs in accordance with FEMA’s Large Project requirements. Federal Funding Accountability and Transparency Act The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Disaster Grants. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department made 196 obligating actions totaling $71.3 million to 75 subrecipients for its Disaster Grants. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Accordingly, the Department was required to submit 196 FFATA reports for its Disaster Grants, with net obligating actions of approximately $71.3 million for Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with reporting requirements for its federal Disaster Grants for Fiscal Year 2023. In addition, the purpose of our audit work was to determine whether the information in these reports was accurate and complete, and submitted in accordance with federal regulations. As part of our audit work, we requested a listing of all ongoing Disaster Grants, the specific reporting requirements identified either in the grant award agreement or required by federal statute, and performed the following: • We tested a sample of 8 FFRs submitted to the FEMA Regional Office and selected three key line items within those reports identified as (1) Federal Cash Disbursements, (2) Federal Share of Expenditures, and (3) Recipient Share of Expenditures, and compared these line item amounts to underlying support to determine if the federal financial reports were accurate and complete. • We tested a sample of 4 QPRs submitted to the FEMA Regional Office to determine if the reports were appropriately completed in accordance with federal regulations. In addition, we selected a total of 60 large projects contained on six of the cumulative from grant inception to date QPR reports to determine whether the amounts reported for Federal Cash Disbursements to date for these large projects was accurate and complete. • From the listing of 196 FFATA obligating actions, we selected a sample of 26 Disaster Grants subawards and requested copies of the FFATA reports that should have been uploaded to the FSRS system by the Department for Fiscal Year 2023 to determine if the Department uploaded the FFATA reports as required and whether the reports contained accurate and complete information. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards, providing reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and a federal award’s terms and conditions. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the submission date of the final expenditures report. • In accordance with federal regulation [2 CFR 170.330.1(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. What problems did the audit work identify? Based on the testwork performed, we identified the following: • The Department did not accurately report the amount for the Recipient Share of Expenditures on any of the 8 (100 percent) FFRs tested. Specifically, Department staff overreported the amount of the cumulative-to-date recipient share of expenditures as of June 30, 2023 within the 8 FFRs by a total of approximately $26.2 million. • The Department understated the amount reported as Federal Funds Disbursed for 9 of 60 (15 percent) large projects tested on six QPRs by a total of approximately $8.8 million. • The Department did not report any Disaster Grant subawards in FSRS for Fiscal Year 2023 and, therefore, did not comply with FFATA reporting requirements. Specifically, the Department did not report approximately $55.1 million in subawards for Fiscal Year 2023. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did these problems occur? The Department did not have adequate internal controls over federal reporting requirements in place for its Disaster Grants during Fiscal Year 2023. Specifically: • The Department did not adequately review the FFRs and did not identify that the preparer populated the line item for cumulative-to-date recipient share of expenditures based on an incorrect formula, rather than reporting actual recipient share of expenditures as supported in program records. • The Department did not adequately review the QPRs. Additionally, Department staff did not fully investigate the differences they did identify through their review and reconciliation process and inaccurately identified differences as timing issues. • The Department failed to file FFATA reports for its Disaster Grants because it does not have documented policies and procedures in place to designate responsibilities over FSRS reporting between fiscal staff and program staff. Further, the Department did not adequately assign resources to ensure FFATA reporting requirements were identified and that reports were submitted. Why do these problems matter? By failing to properly report its recipient share of expenditures on the FFRs, and the federal disbursements on the QPRs, the Department is out of compliance with federal reporting requirements which may result in the federal oversight agency for the applicable grants relying on incorrect data. Also, by failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. Based on information provided by the Department, it had 196 FFATA obligating actions with a net total of approximately $71.3 million that should have been reported to FSRS during Fiscal Year 2023. Recommendation 2023-078 The Department of Public Safety (Department) should improve its internal controls over, and ensure it complies with, federal reporting requirements for its Disaster Grants – Public Assistance (Presidentially Declared Disasters) program. This should include: A. Performing an adequate review over its Federal Financial Status Reports and correcting any identified errors prior to submission. B. Performing an adequate review over its Large Project Quarterly Progress Reports, and adequately investigating differences identified during its reconciliation process to ensure the reports are supported by program records. C. Developing, documenting, and implementing policies and procedures to ensure that staff, as applicable, are aware of, and comply with, requirements under the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for its Disaster Grants. This should include improving the Department’s process for determining the timing of reporting within the FFATA Subaward Reporting System. This process should also include appropriately allocating staff resources for FFATA reporting responsibilities. Response Department of Public Safety A. Agree Implementation Date: June 2024 The Department has corrected the formula error for the cost share value and created controls to identify and prevent similar errors in the future. This error did not affect the accuracy of any other component of the reporting. The Department has also updated its procedures to include a secondary review process for the reporting. B. Agree Implementation Date: June 2024 The Department will modify its grant procedure to include reconciliation and investigation requirements. C. Agree Implementation Date: June 2024 The Department agrees and will update policies and procedures accordingly.
Show full finding ▾Hide full finding ▴Finding 2023-078 Disaster Grants – Public Assistance (Presidentially Declared Disasters) Federal Reporting The Department receives federal grant awards and is required to follow certain financial, performance, and other reporting requirements as specifically identified in the various grant award agreements. The Department allocates funds received from these federal awards to subrecipients and the Department is responsible for the reporting of the payments made to its subrecipients. Federal Financial Reporting The Department is required to submit Federal Financial Status Reports (FFR) quarterly to the FEMA Regional Office for each of its Disaster Grants. The FFRs are a way for the Department to show FEMA, as the granting agency, the status of its grant funds and demonstrate that it is meeting the grant’s cost-sharing requirements. The FFRs provide cumulative-to-date information from project inception through the end of each reporting period. Financial information within the FFRs includes information such as federal cash disbursements from grant inception to the date of the report, total federal funds authorized, federal share of expenditures from grant inception to the date of the report, and recipient share of expenditures from grant inception to the date of the report. During Fiscal Year 2023, the Department had five outstanding FEMA grant awards and was required to submit 20 quarterly FFRs. Performance Reporting The Department is required to submit Large Project Quarterly Progress Reports (QPR) to FEMA on a quarterly basis. The QPRs are a tool for FEMA and the Department to track the progress of Large Projects—defined by FEMA as an individual project with approved estimated, eligible costs of $1,000,000 or greater. The QPRs include information submitted from the Department’s FEMA subrecipients, such as: • Subrecipient’s total expenditures from grant inception to report date, • Status of the project(s) (e.g., the percent complete), • Whether the work is complete, and • Projected or actual completion date for the project(s). The Department must review, verify, and submit the subrecipient’s information on the QPR, and the Department must then, on a quarterly basis, submit the following for each open Large Project: • Total amount disbursed to the subrecipient from grant inception to report date. • Whether final payment was made to that specific subrecipient and the subrecipient’s project was ready for closeout. • Whether extensions to overall project closeout timing were submitted by the State and approved by FEMA. • Applicable project closeout deadline approved by FEMA. For Fiscal Year 2023, the Department had five outstanding FEMA grant awards with total federal funds obligated of approximately $2.4 billion, as of June 30, 2023, and was required to submit eight QPRs in accordance with FEMA’s Large Project requirements. Federal Funding Accountability and Transparency Act The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Disaster Grants. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as “an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.” In Fiscal Year 2023, the Department made 196 obligating actions totaling $71.3 million to 75 subrecipients for its Disaster Grants. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. Accordingly, the Department was required to submit 196 FFATA reports for its Disaster Grants, with net obligating actions of approximately $71.3 million for Fiscal Year 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with reporting requirements for its federal Disaster Grants for Fiscal Year 2023. In addition, the purpose of our audit work was to determine whether the information in these reports was accurate and complete, and submitted in accordance with federal regulations. As part of our audit work, we requested a listing of all ongoing Disaster Grants, the specific reporting requirements identified either in the grant award agreement or required by federal statute, and performed the following: • We tested a sample of 8 FFRs submitted to the FEMA Regional Office and selected three key line items within those reports identified as (1) Federal Cash Disbursements, (2) Federal Share of Expenditures, and (3) Recipient Share of Expenditures, and compared these line item amounts to underlying support to determine if the federal financial reports were accurate and complete. • We tested a sample of 4 QPRs submitted to the FEMA Regional Office to determine if the reports were appropriately completed in accordance with federal regulations. In addition, we selected a total of 60 large projects contained on six of the cumulative from grant inception to date QPR reports to determine whether the amounts reported for Federal Cash Disbursements to date for these large projects was accurate and complete. • From the listing of 196 FFATA obligating actions, we selected a sample of 26 Disaster Grants subawards and requested copies of the FFATA reports that should have been uploaded to the FSRS system by the Department for Fiscal Year 2023 to determine if the Department uploaded the FFATA reports as required and whether the reports contained accurate and complete information. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 200.303] requires the Department to establish and maintain effective internal controls over federal awards, providing reasonable assurance that the Department is managing its federal awards in compliance with federal statutes, regulations, and a federal award’s terms and conditions. • Federal regulation [2 CFR 200.334] requires the Department to keep all financial records and supporting documentation pertinent to a federal award for a minimum period of 3 years from the submission date of the final expenditures report. • In accordance with federal regulation [2 CFR 170.330.1(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2023 if an award or supplemental award equal to or greater than $30,000 was made in April 2023. What problems did the audit work identify? Based on the testwork performed, we identified the following: • The Department did not accurately report the amount for the Recipient Share of Expenditures on any of the 8 (100 percent) FFRs tested. Specifically, Department staff overreported the amount of the cumulative-to-date recipient share of expenditures as of June 30, 2023 within the 8 FFRs by a total of approximately $26.2 million. • The Department understated the amount reported as Federal Funds Disbursed for 9 of 60 (15 percent) large projects tested on six QPRs by a total of approximately $8.8 million. • The Department did not report any Disaster Grant subawards in FSRS for Fiscal Year 2023 and, therefore, did not comply with FFATA reporting requirements. Specifically, the Department did not report approximately $55.1 million in subawards for Fiscal Year 2023. The following table summarizes the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. Why did these problems occur? The Department did not have adequate internal controls over federal reporting requirements in place for its Disaster Grants during Fiscal Year 2023. Specifically: • The Department did not adequately review the FFRs and did not identify that the preparer populated the line item for cumulative-to-date recipient share of expenditures based on an incorrect formula, rather than reporting actual recipient share of expenditures as supported in program records. • The Department did not adequately review the QPRs. Additionally, Department staff did not fully investigate the differences they did identify through their review and reconciliation process and inaccurately identified differences as timing issues. • The Department failed to file FFATA reports for its Disaster Grants because it does not have documented policies and procedures in place to designate responsibilities over FSRS reporting between fiscal staff and program staff. Further, the Department did not adequately assign resources to ensure FFATA reporting requirements were identified and that reports were submitted. Why do these problems matter? By failing to properly report its recipient share of expenditures on the FFRs, and the federal disbursements on the QPRs, the Department is out of compliance with federal reporting requirements which may result in the federal oversight agency for the applicable grants relying on incorrect data. Also, by failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. Based on information provided by the Department, it had 196 FFATA obligating actions with a net total of approximately $71.3 million that should have been reported to FSRS during Fiscal Year 2023. Recommendation 2023-078 The Department of Public Safety (Department) should improve its internal controls over, and ensure it complies with, federal reporting requirements for its Disaster Grants – Public Assistance (Presidentially Declared Disasters) program. This should include: A. Performing an adequate review over its Federal Financial Status Reports and correcting any identified errors prior to submission. B. Performing an adequate review over its Large Project Quarterly Progress Reports, and adequately investigating differences identified during its reconciliation process to ensure the reports are supported by program records. C. Developing, documenting, and implementing policies and procedures to ensure that staff, as applicable, are aware of, and comply with, requirements under the Federal Funding Accountability and Transparency Act of 2006 (FFATA) for its Disaster Grants. This should include improving the Department’s process for determining the timing of reporting within the FFATA Subaward Reporting System. This process should also include appropriately allocating staff resources for FFATA reporting responsibilities. Response Department of Public Safety A. Agree Implementation Date: June 2024 The Department has corrected the formula error for the cost share value and created controls to identify and prevent similar errors in the future. This error did not affect the accuracy of any other component of the reporting. The Department has also updated its procedures to include a secondary review process for the reporting. B. Agree Implementation Date: June 2024 The Department will modify its grant procedure to include reconciliation and investigation requirements. C. Agree Implementation Date: June 2024 The Department agrees and will update policies and procedures accordingly.
The Department agrees and will update policies and procedures accordingly.
Finding 2023-079 Coronavirus State and Local Fiscal Recovery Funds (SLFRF) Procurement, Suspension and Debarment Compliance Enacted on March 11, 2021, the American Rescue Plan Act of 2021 (ARPA) authorized the Coronavirus State and Local Fiscal Recovery Funds (SLFRF). Through SLFRF, recipient governments are investing funds to address the unique needs of their local communities and create a stronger national economy by using these essential funds to: • Fight the pandemic and support families and businesses struggling with its public health and economic impacts. • Maintain vital public services, even amid declines in revenue resulting from the crisis. • Build a strong, resilient, and equitable recovery by making investments that support long-term growth and opportunity. The U.S. Department of the Treasury’s Final Rule describes how recipients may use SLFRF funds to: 1. Respond to the public health emergency with respect to COVID-19 or its negative economic impacts, including by providing assistance to households, small businesses, nonprofits, and impacted industries, such as tourism, travel, and hospitality; 2. Respond to workers performing essential work during the COVID-19 public health emergency by providing premium pay to eligible workers of the recipient that perform essential work or by providing grants to eligible employers that have eligible workers who are performing essential work; 3. Provide government services, to the extent of the reduction in revenue of the eligible entities due to the COVID-19 public health emergency relative to revenues collected in the most recent full fiscal year of the eligible entities prior to the emergency; and 4. Make necessary investments in water, sewer, or broadband infrastructure. During Fiscal Year 2023, the Department reported federal SLFRF expenditures in the amount of approximately $15.3 million. Of the total federal expenditures, $12.0 million were passed through to subrecipients and the remaining $3.3 million were direct Department expenditures subject to federal procurement, suspension, and debarment regulations. Federal procurement regulations prohibit non-federal entities, including the Department, from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. Covered transactions include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the Department can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. During Fiscal Year 2023, the Department paid $3.1 million to 37 vendors that were subject to the suspension and debarment criteria identified above. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal suspension and debarment requirements for the SLFRF grant during Fiscal Year 2023. As part of our audit work, we tested a sample of 6 of the Department’s SLFRF-related 37 vendors, who represented a total of $1.4 million of the Department’s SLFRF expenditures during Fiscal Year 2023, to determine whether the Department complied with requirements to ensure the vendors were not suspended or debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Further, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the Department, as the recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. • Federal regulation [2 CFR 200.318] states that the Department must document procurement procedures. The Department utilizes Section 24-101 through 112, C.R.S., as its procurement policy. Specifically, the Procurement Code [R-24-109-105-02c] states that “The Director shall maintain a current list of debarred and suspended persons and shall send lists and updates of it to heads of all purchasing agencies.” What problem did the audit work identify? We identified an issue with 1 of the 6 vendors tested (17 percent). The Department could not provide documentation to support that they performed suspension and debarment verification procedures for this vendor prior to paying them with federal funds. Specifically, the Department made payments to this vendor in December 2022, and did not perform a SAM check until after we notified them of the issue in November 2023. They confirmed at that time that the vendor was not suspended or debarred from receiving federal monies. Why did this problem occur? The Department did not have adequate internal controls in place to ensure they complied with SLFRF suspension and debarment requirements. Specifically, while the Department’s current process is to follow the State’s policy for federally funded projects, they do not have a process in place to ensure compliance with suspension and debarment requirements when funding changes from state to federal funding. Specifically, the Department initially funded the vendor’s contract with State funds, however, the funding source was subsequently changed to SLFRF monies in the 2022-23 Long Appropriations Bill (HB22-1329), effective July 1, 2022. The change in funding source to federal awards required additional procurement procedures that were missed by the Department and not completed until identified during the audit. The Department’s contract manager was not aware of SLFRF suspension and debarment requirements upon the State’s decision to use the federal funds towards capital construction projects. Why does this problem matter? It is important for the Department to ensure that it obtains and maintains appropriate documentation to support procurement decisions, especially when they are the basis for determining the Department’s compliance with specific SLFRF program requirements. In addition, the Department’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the Department paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-079 The Department of Public Safety (Department) should strengthen its internal controls to ensure it complies with suspension and debarment requirements for the federal Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program by developing a process to verify that a vendor is not suspended or debarred from receiving federal dollars when, for example, the funding source is moved to federal monies from another source. In addition, the Department should ensure staff is trained on the updated process. Response Department of Public Safety Agree Implementation Date: January 2024 This oversight occurred because the funding for some capital construction projects was changed to federal funds (State and Local Recovery Funds). Although this process is followed for federal grants at the Department, federal funding for capital projects is not common, so this requirement was inadvertently overlooked. The Department of Public Safety has implemented a department-wide process for suspension and debarment screening as of January 5, 2024 and training sessions were held in January as well.
Show full finding ▾Hide full finding ▴Finding 2023-079 Coronavirus State and Local Fiscal Recovery Funds (SLFRF) Procurement, Suspension and Debarment Compliance Enacted on March 11, 2021, the American Rescue Plan Act of 2021 (ARPA) authorized the Coronavirus State and Local Fiscal Recovery Funds (SLFRF). Through SLFRF, recipient governments are investing funds to address the unique needs of their local communities and create a stronger national economy by using these essential funds to: • Fight the pandemic and support families and businesses struggling with its public health and economic impacts. • Maintain vital public services, even amid declines in revenue resulting from the crisis. • Build a strong, resilient, and equitable recovery by making investments that support long-term growth and opportunity. The U.S. Department of the Treasury’s Final Rule describes how recipients may use SLFRF funds to: 1. Respond to the public health emergency with respect to COVID-19 or its negative economic impacts, including by providing assistance to households, small businesses, nonprofits, and impacted industries, such as tourism, travel, and hospitality; 2. Respond to workers performing essential work during the COVID-19 public health emergency by providing premium pay to eligible workers of the recipient that perform essential work or by providing grants to eligible employers that have eligible workers who are performing essential work; 3. Provide government services, to the extent of the reduction in revenue of the eligible entities due to the COVID-19 public health emergency relative to revenues collected in the most recent full fiscal year of the eligible entities prior to the emergency; and 4. Make necessary investments in water, sewer, or broadband infrastructure. During Fiscal Year 2023, the Department reported federal SLFRF expenditures in the amount of approximately $15.3 million. Of the total federal expenditures, $12.0 million were passed through to subrecipients and the remaining $3.3 million were direct Department expenditures subject to federal procurement, suspension, and debarment regulations. Federal procurement regulations prohibit non-federal entities, including the Department, from contracting with or making subawards under “covered transactions” to parties that are suspended or debarred from doing business with the federal government. Covered transactions include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the Department can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. During Fiscal Year 2023, the Department paid $3.1 million to 37 vendors that were subject to the suspension and debarment criteria identified above. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal suspension and debarment requirements for the SLFRF grant during Fiscal Year 2023. As part of our audit work, we tested a sample of 6 of the Department’s SLFRF-related 37 vendors, who represented a total of $1.4 million of the Department’s SLFRF expenditures during Fiscal Year 2023, to determine whether the Department complied with requirements to ensure the vendors were not suspended or debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: • Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Further, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. • Federal regulation [2 CFR 200.303] states that the Department, as the recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. • Federal regulation [2 CFR 200.318] states that the Department must document procurement procedures. The Department utilizes Section 24-101 through 112, C.R.S., as its procurement policy. Specifically, the Procurement Code [R-24-109-105-02c] states that “The Director shall maintain a current list of debarred and suspended persons and shall send lists and updates of it to heads of all purchasing agencies.” What problem did the audit work identify? We identified an issue with 1 of the 6 vendors tested (17 percent). The Department could not provide documentation to support that they performed suspension and debarment verification procedures for this vendor prior to paying them with federal funds. Specifically, the Department made payments to this vendor in December 2022, and did not perform a SAM check until after we notified them of the issue in November 2023. They confirmed at that time that the vendor was not suspended or debarred from receiving federal monies. Why did this problem occur? The Department did not have adequate internal controls in place to ensure they complied with SLFRF suspension and debarment requirements. Specifically, while the Department’s current process is to follow the State’s policy for federally funded projects, they do not have a process in place to ensure compliance with suspension and debarment requirements when funding changes from state to federal funding. Specifically, the Department initially funded the vendor’s contract with State funds, however, the funding source was subsequently changed to SLFRF monies in the 2022-23 Long Appropriations Bill (HB22-1329), effective July 1, 2022. The change in funding source to federal awards required additional procurement procedures that were missed by the Department and not completed until identified during the audit. The Department’s contract manager was not aware of SLFRF suspension and debarment requirements upon the State’s decision to use the federal funds towards capital construction projects. Why does this problem matter? It is important for the Department to ensure that it obtains and maintains appropriate documentation to support procurement decisions, especially when they are the basis for determining the Department’s compliance with specific SLFRF program requirements. In addition, the Department’s failure to perform procedures to ensure an entity is not suspended or debarred could result in the Department paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. Recommendation 2023-079 The Department of Public Safety (Department) should strengthen its internal controls to ensure it complies with suspension and debarment requirements for the federal Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program by developing a process to verify that a vendor is not suspended or debarred from receiving federal dollars when, for example, the funding source is moved to federal monies from another source. In addition, the Department should ensure staff is trained on the updated process. Response Department of Public Safety Agree Implementation Date: January 2024 This oversight occurred because the funding for some capital construction projects was changed to federal funds (State and Local Recovery Funds). Although this process is followed for federal grants at the Department, federal funding for capital projects is not common, so this requirement was inadvertently overlooked. The Department of Public Safety has implemented a department-wide process for suspension and debarment screening as of January 5, 2024 and training sessions were held in January as well.
This oversight occurred because the funding for some capital construction projects was changed to federal funds (State and Local Recovery Funds). Although this process is followed for federal grants at the Department, federal funding for capital projects is not common, so this requirement was inadvertently overlooked. The Department of Public Safety has implemented a department-wide process for suspension and debarment screening as of January 5, 2024 and training sessions were held in January as well.
Finding 2023-080 Compliance with Federal Subrecipient Monitoring Requirements The Department receives federal grant funds directly from the federal government for the Highway Program and the Formula Grants Program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The Department executes an Intergovernmental Agreement (IGA) between the Department and the subrecipient. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is responsible for evaluating each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward, and, ultimately, for ensuring the subrecipient is determined eligible. In some instances, in coordination with the Federal Highway Association, a Metropolitan Planning Organization—rather than the primary recipient, such as the Department—is responsible for performing eligibility determinations. In those instances, the Department does not perform risk-assessments on these contracts and only is responsible for ongoing monitoring. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over and complied with subrecipient monitoring requirements for the Highway Program and Formula Grants Program during Fiscal Year 2023, and to determine whether the Department had implemented our prior audit recommendations for both the Highway Program and the Formula Grants Program. In our Fiscal Year 2022 audit (for Highway Program) and Fiscal Years 2022, 2021, and 2020 (for Formula Grants Program), we recommended for both programs that the Department update its current subrecipient monitoring and risk assessment policy to clarify the risk assessment process and provide training to staff responsible for subrecipient monitoring activities. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring requirements for the Highway Program and the Formula Grants Program, including the Department’s policies and procedures. We tested a random sample of 15 of the Department’s 98 subrecipients (15 percent) for the Highway Program and a random sample of 8 of the Department’s 44 subrecipients (18 percent) for the Formula Grants Program—for which the Department had an IGA in place during Fiscal Year 2023—to determine whether subrecipient monitoring procedures performed by Department staff during the year were compliant with federal regulations. Our testing included evaluating whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the subrecipient’s unique entity identifier (UEI). • Federal regulation [2 CFR 200.332(b)] states that the Department must evaluate each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward, which may include various factors. • Federal regulations [2 CFR 200.332(d) through (f) and 2 CFR 200.521] require the Department to monitor the activities of its subrecipients, as necessary, to ensure that each subaward is used for authorized purposes, the subrecipient complies with the terms and conditions of the subaward, and the subrecipient achieves performance goals. The Department’s monitoring must include: o Reviewing financial and performance reports submitted by the subrecipient. o Following up on and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. o Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements for the Highway Program during Fiscal Year 2023 and did not fully implement our prior audit recommendation. Specifically: • The Department did not perform a risk assessment for 1 of the 15 subrecipients (6.7 percent) we tested. • The Department did not include the subrecipient’s unique entity identifier (UEI) number on the IGA, nor did they obtain the number from the subrecipient prior to signing of the IGA, for 1 of the 15 subrecipients (6.7 percent) we tested. We also determined that, while the Fiscal Year 2023 sample testing revealed no exceptions for the Formula Grants Program, the Department did not fully implement our prior audit recommendation for the Formula Grants Program related to subrecipient monitoring by its planned implementation date of July 2022. When we inquired of the Department about what steps it had taken to implement the recommendation, Department staff indicated that they did not make significant progress on implementing the recommendation to provide training and to update the subrecipient monitoring and risk assessment policy during Fiscal Year 2023. Why did these problems occur? While the Department has created a subrecipient monitoring and risk assessment manual, which applies to all federal programs administered by the Department, its manual effective for Fiscal Year 2023—then in the process of being updated—lacks clarity in certain areas, including the following: • For contracts which extend over multiple fiscal years, the policies do not specify the frequency with which subrecipient risk-assessments should be reviewed or updated. • The current manual does not include guidance related to the requirement of the UEI being included on the IGA. Further, while the Department was developing training during Fiscal Year 2023, the Department did not provide sufficiently detailed training to staff during the fiscal year to ensure they were aware of and conducted required subrecipient monitoring responsibilities. Why do these problems matter? Performing timely and appropriate subrecipient monitoring provides the Department with a method to ensure its subrecipients are complying with applicable federal grant requirements. By taking appropriate actions based on the results of its subrecipient monitoring activities, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with program requirements. Overall, the Department’s failure to comply with federal requirements could result in a loss of funding from the federal government. Recommendation 2023-080 The Department of Transportation should strengthen internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Highway Planning and Construction program and the Formula Grants for Rural Areas Program and Tribal Transit Program by: A. Completing the process of updating its current subrecipient monitoring and risk assessment policy to clarify the frequency in which a risk assessment is required to be completed or updated, and updating the policy to address the nature of the requirement to include the unique entity identifier number on the intergovernmental agreement. B. Providing training to staff responsible for subrecipient monitoring activities related to the policies updated in Part A of the finding. Response Department of Transportation A. Agree Implementation Date: November 2023 A cross functional work-group with representatives from accounting, project support, compliance, engineering contract services, and internal audit have updated the subrecipient monitoring and risk assessment manual. This update was completed on November 30th and it includes the following clarifications: • The frequency in which risk assessments are required to be completed for contracts that span multiple fiscal years on page 45 of the policy • Exceptions and when it is acceptable to forgo a risk assessments on page 11 of the policy • Requirements for the inclusion of a Unique Entity Identifier (UEI) on intergovernmental agreements on page 33 of the policy B. Agree Implementation Date: November 2023 The cross-functional work-group noted in the prior response provided training to staff responsible for the monitoring activities. Training was provided in November 2023 for all the updates related to the recommendation items in part A of the finding.
Show full finding ▾Hide full finding ▴Finding 2023-080 Compliance with Federal Subrecipient Monitoring Requirements The Department receives federal grant funds directly from the federal government for the Highway Program and the Formula Grants Program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The Department executes an Intergovernmental Agreement (IGA) between the Department and the subrecipient. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is responsible for evaluating each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward, and, ultimately, for ensuring the subrecipient is determined eligible. In some instances, in coordination with the Federal Highway Association, a Metropolitan Planning Organization—rather than the primary recipient, such as the Department—is responsible for performing eligibility determinations. In those instances, the Department does not perform risk-assessments on these contracts and only is responsible for ongoing monitoring. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over and complied with subrecipient monitoring requirements for the Highway Program and Formula Grants Program during Fiscal Year 2023, and to determine whether the Department had implemented our prior audit recommendations for both the Highway Program and the Formula Grants Program. In our Fiscal Year 2022 audit (for Highway Program) and Fiscal Years 2022, 2021, and 2020 (for Formula Grants Program), we recommended for both programs that the Department update its current subrecipient monitoring and risk assessment policy to clarify the risk assessment process and provide training to staff responsible for subrecipient monitoring activities. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring requirements for the Highway Program and the Formula Grants Program, including the Department’s policies and procedures. We tested a random sample of 15 of the Department’s 98 subrecipients (15 percent) for the Highway Program and a random sample of 8 of the Department’s 44 subrecipients (18 percent) for the Formula Grants Program—for which the Department had an IGA in place during Fiscal Year 2023—to determine whether subrecipient monitoring procedures performed by Department staff during the year were compliant with federal regulations. Our testing included evaluating whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the subrecipient’s unique entity identifier (UEI). • Federal regulation [2 CFR 200.332(b)] states that the Department must evaluate each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward, which may include various factors. • Federal regulations [2 CFR 200.332(d) through (f) and 2 CFR 200.521] require the Department to monitor the activities of its subrecipients, as necessary, to ensure that each subaward is used for authorized purposes, the subrecipient complies with the terms and conditions of the subaward, and the subrecipient achieves performance goals. The Department’s monitoring must include: o Reviewing financial and performance reports submitted by the subrecipient. o Following up on and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. o Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements for the Highway Program during Fiscal Year 2023 and did not fully implement our prior audit recommendation. Specifically: • The Department did not perform a risk assessment for 1 of the 15 subrecipients (6.7 percent) we tested. • The Department did not include the subrecipient’s unique entity identifier (UEI) number on the IGA, nor did they obtain the number from the subrecipient prior to signing of the IGA, for 1 of the 15 subrecipients (6.7 percent) we tested. We also determined that, while the Fiscal Year 2023 sample testing revealed no exceptions for the Formula Grants Program, the Department did not fully implement our prior audit recommendation for the Formula Grants Program related to subrecipient monitoring by its planned implementation date of July 2022. When we inquired of the Department about what steps it had taken to implement the recommendation, Department staff indicated that they did not make significant progress on implementing the recommendation to provide training and to update the subrecipient monitoring and risk assessment policy during Fiscal Year 2023. Why did these problems occur? While the Department has created a subrecipient monitoring and risk assessment manual, which applies to all federal programs administered by the Department, its manual effective for Fiscal Year 2023—then in the process of being updated—lacks clarity in certain areas, including the following: • For contracts which extend over multiple fiscal years, the policies do not specify the frequency with which subrecipient risk-assessments should be reviewed or updated. • The current manual does not include guidance related to the requirement of the UEI being included on the IGA. Further, while the Department was developing training during Fiscal Year 2023, the Department did not provide sufficiently detailed training to staff during the fiscal year to ensure they were aware of and conducted required subrecipient monitoring responsibilities. Why do these problems matter? Performing timely and appropriate subrecipient monitoring provides the Department with a method to ensure its subrecipients are complying with applicable federal grant requirements. By taking appropriate actions based on the results of its subrecipient monitoring activities, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with program requirements. Overall, the Department’s failure to comply with federal requirements could result in a loss of funding from the federal government. Recommendation 2023-080 The Department of Transportation should strengthen internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Highway Planning and Construction program and the Formula Grants for Rural Areas Program and Tribal Transit Program by: A. Completing the process of updating its current subrecipient monitoring and risk assessment policy to clarify the frequency in which a risk assessment is required to be completed or updated, and updating the policy to address the nature of the requirement to include the unique entity identifier number on the intergovernmental agreement. B. Providing training to staff responsible for subrecipient monitoring activities related to the policies updated in Part A of the finding. Response Department of Transportation A. Agree Implementation Date: November 2023 A cross functional work-group with representatives from accounting, project support, compliance, engineering contract services, and internal audit have updated the subrecipient monitoring and risk assessment manual. This update was completed on November 30th and it includes the following clarifications: • The frequency in which risk assessments are required to be completed for contracts that span multiple fiscal years on page 45 of the policy • Exceptions and when it is acceptable to forgo a risk assessments on page 11 of the policy • Requirements for the inclusion of a Unique Entity Identifier (UEI) on intergovernmental agreements on page 33 of the policy B. Agree Implementation Date: November 2023 The cross-functional work-group noted in the prior response provided training to staff responsible for the monitoring activities. Training was provided in November 2023 for all the updates related to the recommendation items in part A of the finding.
The cross-functional work-group noted in the prior response provided training to staff responsible for the monitoring activities. Training was provided in November 2023 for all the updates related to the recommendation items in part A of the finding.
2022-076, 2022-078
Finding 2023-081 Minerals Leasing Act—Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state’s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Minerals Leasing Act Program (Program) funds to Treasury, which passes through Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments may use Program funds for “…planning; construction and maintenance of public facilities; and provision of public services.” During Fiscal Year 2023, ONRR distributed approximately $173.0 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $68.9 million of the $72.3 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.4 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2023. As part of our testing, we reviewed Treasury’s progress in implementing our Fiscal Year 2022 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. As a result of our testwork, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, and dollar amount made available to subrecipients, and the related federal requirements. As part of our testing, we conducted interviews with Treasury staff regarding its process over the monitoring of Program funds during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. The Minerals Leasing Act of 1920, as amended in 1976, states that Program funds should be provided to those subdivisions socially or economically impacted by the development of minerals leased for planning, construction, and maintenance of public facilities. Federal regulations [2 CFR 200.331] require a pass-through entity to make case-by-case determinations regarding whether each agreement it makes for the disbursement of federal program funds casts the party receiving the funds in the role of a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The following paragraphs detail requirements for subrecipients. Federal regulations [2 CFR 200.332 (a)(1)(2) and (3)] require that Treasury, as the primary recipient of Program funds, ensure that every pass-through of federal funds it makes clearly identify all requirements that Treasury imposed on the subrecipient so that the federal award is used in accordance with federal statutes, regulations, and the terms and conditions of the award, as well as specify any additional requirements that Treasury imposes on the subrecipient in order for Treasury to meet its own responsibility for the federal award (e.g., financial, performance, and special reports). In addition, regulations require that Treasury, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury, or DOLA, provides specific information about the Program to the subrecipients, including, but not limited to, the following: • Assistance Listing Number • Name of the program, name of the federal awarding agency, and name of the department awarding the Program funds • Contact information for Treasury • Dollar amount made available to the subrecipient • Reporting requirements Federal regulation [2 CFR 200.332(b)] requires that Treasury, as the primary recipient of Program funds, ensure DOLA staff conducts risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the Treasury should ensure that DOLA staff use the risk assessments to determine the appropriate level of subrecipient monitoring that DOLA staff should perform on each subrecipient. Specifically, federal regulations [2 CFR 200.332(d)-(e)] require that Treasury, as the primary recipient of Program funds, ensure that DOLA staff monitor the subrecipient activities as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: • Reviewing financial performance reports. • Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. • Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity’s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulation [2 CFR 200.332(f)] require that Treasury, as the primary recipient of the Program funds, ensure or communicate to DOLA that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFA and, if applicable, undergo a Single Audit. The Exhibit K1, Schedule of Federal Assistance, is used by the State’s departments and institutions of higher education to report federal expenditure information to the Office of the State Controller (OSC) to aid the OSC in preparing the State’s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the various Exhibits in preparing the SEFA each year. What problems did the audit work identify? We found that Treasury did not implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2023. Specifically, we identified the following: • Treasury reported that DOLA did not perform a subrecipient versus contractor determination to ensure proper compliance with the subaward requirement and reporting of information to Treasury for its federal reporting. • Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury staff reported that they continue working with DOLA to ensure that required information is communicated to all subrecipients in compliance with state and federal regulations. In addition, Treasury reported that they are working with the Attorney General’s Office toward the implementation of an interagency agreement that will establish expectations for DOLA. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. • Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, Treasury did not ensure that DOLA used the risk assessments to determine the appropriate level of subrecipient monitoring on each subrecipient. • Treasury did not have a process in place to ensure that DOLA monitors the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. • Further, Treasury, as the primary recipient of Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2023 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. Why did these problems occur? Overall, Treasury did not have adequate internal controls in place during Fiscal Year 2023 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff indicated that DOLA determined during Fiscal Year 2023 that it does not have any Program subrecipients, but Treasury did not obtain and review any subrecipient versus contractor determinations from DOLA to verify the appropriateness of the determinations. Alternatively, Treasury did not perform its own assessment of subrecipient versus contractor status for the Program payments or obtain clarification from the Attorney General, as necessary, regarding the determination. Treasury also did not have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds—including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2023 were required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In addition, Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. Neither Treasury or DOLA monitored the activities of the subrecipients, as necessary, to ensure that the subawards are used for authorized purposes, comply with the terms and conditions of the subawards, and achieve performance goals. Why do these problems matter? The subrecipient versus contractor determinations help Treasury or DOLA to assess specific federal requirements that have to be followed, and ensure the proper reporting on Treasury’s Exhibit K1. Because the OSC uses the Exhibit K1 to prepare the State’s SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds that Treasury pays annually to its subrecipients. By continuing to fail to fulfill the Program’s subrecipient monitoring requirements, Treasury, and the State as a whole, are out of compliance with the provisions of Program awards. Ultimately, insufficient monitoring of Program subrecipients could result in future federal funding being reduced. If Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could result in local governments not undergoing Single Audits, as required. Further, without evaluating its subrecipients’ risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, Treasury does not have assurance that it appropriately monitors its subrecipients and identifies issues. Recommendation 2023-081 The Department of Treasury (Treasury) should strengthen its internal controls related to, and ensure it complies with, federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act Program (Program) by: A. Requiring other State agencies, including the Department of Local Affairs, to whom Treasury subgrants Program funds, to perform subrecipient versus contractor determinations to identify Program subrecipients and to perform appropriate subrecipient monitoring procedures. As needed, this should include obtaining clarification from the Attorney General as to whether parties to whom Treasury or its subgrantor state agencies send Program funds are subrecipients or vendors. B. Ensuring that it reports Program funds properly on its Exhibit K1, Schedule of Federal Assistance, including that expenditures are accurately presented as direct or pass-through subrecipient expenditures. C. Developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount, are made available to the subrecipient, the related federal requirements are communicated to Program subrecipients, and the subrecipients report the funds on their respective annual Schedule of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. This should include communicating all requirements imposed by the grantor agency on the subrecipient so Program funds are used in accordance with federal statutes, regulations, and the terms and conditions of the subaward, and that Treasury meets its own responsibility for the federal award. D. Developing an effective monitoring process to ensure risk assessments of subrecipients and monitoring of subrecipients are performed. Response Department of the Treasury A. Agree Implementation Date: December 2026 Treasury has been working with the Department of Local Affairs (DOLA) on a pilot program for monitoring and compliance of fund recipients and was in the process of instituting an Interagency Agreement with DOLA on this matter. Treasury will pursue further guidance from the Attorney General's office on federal rules interpretation regarding subrecipients. Treasury plans to continue to work with DOLA to aid in determining what financial resources and FTE may be necessary to ensure monitoring and compliance is successful. B. Agree Implementation Date: December 2026 The Department will seek guidance from the Attorney General's Office regarding federal rules interpretation to ensure distributions are properly identified. DOLA distributes the funds once received from Treasury, and therefore Treasury will work with DOLA as well to ensure there is agreement on subrecipient identification. C. and D. Agree Implementation Date: December 2026 As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
Show full finding ▾Hide full finding ▴Finding 2023-081 Minerals Leasing Act—Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state’s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Minerals Leasing Act Program (Program) funds to Treasury, which passes through Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments may use Program funds for “…planning; construction and maintenance of public facilities; and provision of public services.” During Fiscal Year 2023, ONRR distributed approximately $173.0 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $68.9 million of the $72.3 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.4 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2023. As part of our testing, we reviewed Treasury’s progress in implementing our Fiscal Year 2022 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. As a result of our testwork, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, and dollar amount made available to subrecipients, and the related federal requirements. As part of our testing, we conducted interviews with Treasury staff regarding its process over the monitoring of Program funds during Fiscal Year 2023. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. The Minerals Leasing Act of 1920, as amended in 1976, states that Program funds should be provided to those subdivisions socially or economically impacted by the development of minerals leased for planning, construction, and maintenance of public facilities. Federal regulations [2 CFR 200.331] require a pass-through entity to make case-by-case determinations regarding whether each agreement it makes for the disbursement of federal program funds casts the party receiving the funds in the role of a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization’s own use or for the use of beneficiaries of the federal program. The following paragraphs detail requirements for subrecipients. Federal regulations [2 CFR 200.332 (a)(1)(2) and (3)] require that Treasury, as the primary recipient of Program funds, ensure that every pass-through of federal funds it makes clearly identify all requirements that Treasury imposed on the subrecipient so that the federal award is used in accordance with federal statutes, regulations, and the terms and conditions of the award, as well as specify any additional requirements that Treasury imposes on the subrecipient in order for Treasury to meet its own responsibility for the federal award (e.g., financial, performance, and special reports). In addition, regulations require that Treasury, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury, or DOLA, provides specific information about the Program to the subrecipients, including, but not limited to, the following: • Assistance Listing Number • Name of the program, name of the federal awarding agency, and name of the department awarding the Program funds • Contact information for Treasury • Dollar amount made available to the subrecipient • Reporting requirements Federal regulation [2 CFR 200.332(b)] requires that Treasury, as the primary recipient of Program funds, ensure DOLA staff conducts risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the Treasury should ensure that DOLA staff use the risk assessments to determine the appropriate level of subrecipient monitoring that DOLA staff should perform on each subrecipient. Specifically, federal regulations [2 CFR 200.332(d)-(e)] require that Treasury, as the primary recipient of Program funds, ensure that DOLA staff monitor the subrecipient activities as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: • Reviewing financial performance reports. • Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. • Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity’s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulation [2 CFR 200.332(f)] require that Treasury, as the primary recipient of the Program funds, ensure or communicate to DOLA that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFA and, if applicable, undergo a Single Audit. The Exhibit K1, Schedule of Federal Assistance, is used by the State’s departments and institutions of higher education to report federal expenditure information to the Office of the State Controller (OSC) to aid the OSC in preparing the State’s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the various Exhibits in preparing the SEFA each year. What problems did the audit work identify? We found that Treasury did not implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2023. Specifically, we identified the following: • Treasury reported that DOLA did not perform a subrecipient versus contractor determination to ensure proper compliance with the subaward requirement and reporting of information to Treasury for its federal reporting. • Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury staff reported that they continue working with DOLA to ensure that required information is communicated to all subrecipients in compliance with state and federal regulations. In addition, Treasury reported that they are working with the Attorney General’s Office toward the implementation of an interagency agreement that will establish expectations for DOLA. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. • Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, Treasury did not ensure that DOLA used the risk assessments to determine the appropriate level of subrecipient monitoring on each subrecipient. • Treasury did not have a process in place to ensure that DOLA monitors the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. • Further, Treasury, as the primary recipient of Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2023 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. Why did these problems occur? Overall, Treasury did not have adequate internal controls in place during Fiscal Year 2023 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff indicated that DOLA determined during Fiscal Year 2023 that it does not have any Program subrecipients, but Treasury did not obtain and review any subrecipient versus contractor determinations from DOLA to verify the appropriateness of the determinations. Alternatively, Treasury did not perform its own assessment of subrecipient versus contractor status for the Program payments or obtain clarification from the Attorney General, as necessary, regarding the determination. Treasury also did not have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds—including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2023 were required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In addition, Treasury did not ensure that DOLA performed risk assessments for each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. Neither Treasury or DOLA monitored the activities of the subrecipients, as necessary, to ensure that the subawards are used for authorized purposes, comply with the terms and conditions of the subawards, and achieve performance goals. Why do these problems matter? The subrecipient versus contractor determinations help Treasury or DOLA to assess specific federal requirements that have to be followed, and ensure the proper reporting on Treasury’s Exhibit K1. Because the OSC uses the Exhibit K1 to prepare the State’s SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds that Treasury pays annually to its subrecipients. By continuing to fail to fulfill the Program’s subrecipient monitoring requirements, Treasury, and the State as a whole, are out of compliance with the provisions of Program awards. Ultimately, insufficient monitoring of Program subrecipients could result in future federal funding being reduced. If Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could result in local governments not undergoing Single Audits, as required. Further, without evaluating its subrecipients’ risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, Treasury does not have assurance that it appropriately monitors its subrecipients and identifies issues. Recommendation 2023-081 The Department of Treasury (Treasury) should strengthen its internal controls related to, and ensure it complies with, federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act Program (Program) by: A. Requiring other State agencies, including the Department of Local Affairs, to whom Treasury subgrants Program funds, to perform subrecipient versus contractor determinations to identify Program subrecipients and to perform appropriate subrecipient monitoring procedures. As needed, this should include obtaining clarification from the Attorney General as to whether parties to whom Treasury or its subgrantor state agencies send Program funds are subrecipients or vendors. B. Ensuring that it reports Program funds properly on its Exhibit K1, Schedule of Federal Assistance, including that expenditures are accurately presented as direct or pass-through subrecipient expenditures. C. Developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount, are made available to the subrecipient, the related federal requirements are communicated to Program subrecipients, and the subrecipients report the funds on their respective annual Schedule of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. This should include communicating all requirements imposed by the grantor agency on the subrecipient so Program funds are used in accordance with federal statutes, regulations, and the terms and conditions of the subaward, and that Treasury meets its own responsibility for the federal award. D. Developing an effective monitoring process to ensure risk assessments of subrecipients and monitoring of subrecipients are performed. Response Department of the Treasury A. Agree Implementation Date: December 2026 Treasury has been working with the Department of Local Affairs (DOLA) on a pilot program for monitoring and compliance of fund recipients and was in the process of instituting an Interagency Agreement with DOLA on this matter. Treasury will pursue further guidance from the Attorney General's office on federal rules interpretation regarding subrecipients. Treasury plans to continue to work with DOLA to aid in determining what financial resources and FTE may be necessary to ensure monitoring and compliance is successful. B. Agree Implementation Date: December 2026 The Department will seek guidance from the Attorney General's Office regarding federal rules interpretation to ensure distributions are properly identified. DOLA distributes the funds once received from Treasury, and therefore Treasury will work with DOLA as well to ensure there is agreement on subrecipient identification. C. and D. Agree Implementation Date: December 2026 As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
As discussed in the Department response to Item A above, Treasury has been in the process of creating an Interagency Agreement with DOLA regarding compliance and monitoring of fund recipients. The Department will rely on guidance on this matter from the Attorney General, which is already in process. Additionally, the Department hopes to work in partnership with DOLA to determine what financial resources are necessary - and to be supportive of such a request - to implement a monitoring and compliance system, as the Attorney General's office may recommend.
2022-079
FAC accepted this audit on March 12, 2023 — management decision was due September 12, 2023.
Finding 2022-042 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In order to obtain this information, the federal government requires grant recipients to provide information to it. For example, the federal Department of Education (DOE) requires the Department to report information about subgrants, or subawards, it gives to other governments or to nonprofit organizations (also referred to as subrecipients) from the DOE grants it receives. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is specifically required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department is required to file a FFATA report in the following circumstances: ? If the initial award is equal to or more than $30,000; ? If subsequent grant modifications result in a total award are equal to or more than $30,000; ? If the initial award is equal to or more than $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department?s required FFATA reports for Fiscal Year 2022 included information on Title I Grants to Local Education Agencies [ALN 84.010] and COVID-19 Education Stabilization Fund (ESF) [84.425], specifically Elementary and Secondary School Emergency Relief (ESSER) Fund [84.425D] and American Rescue Plan - Elementary and Secondary School Emergency Relief (ARP ESSER) [84.425U]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for both programs in excess of $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, during Fiscal Year 2022, it was required to submit and revise 180 and 450 FFATA reports for the Title I and ESF programs, respectively. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over FFATA reporting during Fiscal Year 2022 and whether the information in the Department?s submitted FFATA reports was accurate and submitted in a timely manner. We requested a list of all Title I and ESF subawards made by the Department during Fiscal Year 2022. We then selected a sample of 18 Title I and 29 ESF subawards and requested copies of the FFATA reports that were uploaded to the FSRS system by the Department. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. Once the Department provided copies of the uploaded reports, we then reviewed the FFATA reports within FSRS for each subaward selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if an award or supplemental award equal to or greater than $30,000 was made in April 2022. The FFATA reports are required to include the following key data elements: ? Subrecipient name ? Subrecipient DUNS number ? Amount of subaward ? Subaward obligation/action date ? Date of report submission ? Subaward number ? Subaward project description ? Subrecipient names and compensation of highly compensated officers Transparency Act reporting requirements outlined on the FSRS website prescribe certain information that must be reported for these subawards, including the name of the entity receiving the award, the award amount, funding agency, and unique identifier of the entity. Federal regulations [2 CFR 200.303] require the non-Federal entity, in this instance the Department, to establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. What problems did the audit work identify? Based on our audit testwork, for the sample we tested, we determined that the Department was late in reporting all 18 of 18 Title I subawards in FSRS, by an average of 3 to 4 months, and failed to report 1 of 29 ESF subawards by the time of our audit, which represented a delay of approximately 16 months; and was late in reporting 2 of 29 ESF subawards by approximately 7 and 10 months, respectively. Collectively, these subawards totaled about $30 million for Fiscal Year 2022. The following tables summarize the results of our testing and group each exception within the following categories: Subaward Not Reported and Report Not Timely. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did these problems occur? The Department reported that an influx in pandemic funding resulted in the Department experiencing a 233 percent volume increase in funding distributions and to more than 5,000 submissions and resubmissions in its required Fiscal Year 2022 FFATA reporting for all federal programs managed by the Department?s grant fiscal team. The Department indicated that its grant fiscal team also experienced staff turnover and vacancies during the year and the Department did not adequately reassign resources to ensure FFATA reporting requirements were identified and that reports were submitted on time. Initially, only one FTE was dedicated to FFATA reporting. During the year, the Department allocated a portion of the FFATA workload to another existing FTE and added an additional FTE in May 2022 to work on reconciling FFATA submissions; as a result, Department staff identified the two submissions previously missed, but the reallocations and reconciliations were not made in time to ensure the Department met all of its required FFATA report submission timelines. In addition, Department staff indicated that they made a conscious decision to not report the Title I subawards until May 2022?even though the initial subawards were finalized in January 2022?because the Department had historically received multiple funding allocations in addition to the initial allocation that required FFATA reporting for each allocation for up to 178 subawardees. However, the Department did not communicate with the federal awarding agency to determine whether waiting until it received all related allocations to submit its FFATA reports was appropriate. During the majority of Fiscal Year 2022, the Department also did not have a control, such as a reconciliation, to help identify subawards that went unreported during the fiscal year. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-042 The Department of Education (Department) should strengthen its internal controls over, and ensure it complies with requirements under, the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Improving the Department?s process for determining the timing of reporting within the FFATA Subaward Reporting System. This process should include appropriately allocating staff resources for reporting responsibilities, and considerations such as expected future award allocations and communications with the federal awarding agency when it is determined to not be feasible to report information in a timely manner. B. Continuing to develop and implement reconciliation procedures to identify subawards that went unreported during the fiscal year. Response Department of Education A. Agree Implementation Date: December 31, 2022 We agree with this recommendation. In recent years, the Federal Government had multiple continuing resolutions in their budget process, resulting in CDE?s Title I allocations coming in multiple iterations. For the last several years, CDE has received revised allocations from the US Department of Education for the fiscal year as late as early summer; in one example, we received six revisions. With staffing shortages and the administrative burden to continuously revise, research issues and update FFATA for each allocation change, CDE took the step to report only the final allocation to FFATA, which was reported as of the month the awardee was awarded. However, the report was submitted later in the fiscal year. CDE will take a two-fold approach to rectify the issue related to the required FFATA reporting for Title I. First, we will report to FSRS the initial awards within 30 days following the date the awardee was provided final approval on their award. This is consistent with CDE?s approach to all other federal awards. Second, we will monitor the continuing resolutions and changes in allocations, and report only the net changes to each awardee, in the month those changes occur from the US Department of Education. Thereby, FSRS will represent the total revised award. In addition to this approach, all Title I awards will continue to be a part of our regular FFATA reconciliation process. B. Agree Implementation Date: December 31, 2022 We agree with this recommendation. CDE identified its own failure to report two ESSER subawards to FFATA within 30 days as part of the successful development and implementation of a FFATA-specific reconciliation process in Summer 2022. CDE will continue to refine and improve its FFATA reconciliation process.
Show full finding ▾Hide full finding ▴Finding 2022-042 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In order to obtain this information, the federal government requires grant recipients to provide information to it. For example, the federal Department of Education (DOE) requires the Department to report information about subgrants, or subawards, it gives to other governments or to nonprofit organizations (also referred to as subrecipients) from the DOE grants it receives. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is specifically required to file FFATA reports through the FFATA Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department is required to file a FFATA report in the following circumstances: ? If the initial award is equal to or more than $30,000; ? If subsequent grant modifications result in a total award are equal to or more than $30,000; ? If the initial award is equal to or more than $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department?s required FFATA reports for Fiscal Year 2022 included information on Title I Grants to Local Education Agencies [ALN 84.010] and COVID-19 Education Stabilization Fund (ESF) [84.425], specifically Elementary and Secondary School Emergency Relief (ESSER) Fund [84.425D] and American Rescue Plan - Elementary and Secondary School Emergency Relief (ARP ESSER) [84.425U]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for both programs in excess of $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, during Fiscal Year 2022, it was required to submit and revise 180 and 450 FFATA reports for the Title I and ESF programs, respectively. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over FFATA reporting during Fiscal Year 2022 and whether the information in the Department?s submitted FFATA reports was accurate and submitted in a timely manner. We requested a list of all Title I and ESF subawards made by the Department during Fiscal Year 2022. We then selected a sample of 18 Title I and 29 ESF subawards and requested copies of the FFATA reports that were uploaded to the FSRS system by the Department. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. Once the Department provided copies of the uploaded reports, we then reviewed the FFATA reports within FSRS for each subaward selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of federal grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if an award or supplemental award equal to or greater than $30,000 was made in April 2022. The FFATA reports are required to include the following key data elements: ? Subrecipient name ? Subrecipient DUNS number ? Amount of subaward ? Subaward obligation/action date ? Date of report submission ? Subaward number ? Subaward project description ? Subrecipient names and compensation of highly compensated officers Transparency Act reporting requirements outlined on the FSRS website prescribe certain information that must be reported for these subawards, including the name of the entity receiving the award, the award amount, funding agency, and unique identifier of the entity. Federal regulations [2 CFR 200.303] require the non-Federal entity, in this instance the Department, to establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. What problems did the audit work identify? Based on our audit testwork, for the sample we tested, we determined that the Department was late in reporting all 18 of 18 Title I subawards in FSRS, by an average of 3 to 4 months, and failed to report 1 of 29 ESF subawards by the time of our audit, which represented a delay of approximately 16 months; and was late in reporting 2 of 29 ESF subawards by approximately 7 and 10 months, respectively. Collectively, these subawards totaled about $30 million for Fiscal Year 2022. The following tables summarize the results of our testing and group each exception within the following categories: Subaward Not Reported and Report Not Timely. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did these problems occur? The Department reported that an influx in pandemic funding resulted in the Department experiencing a 233 percent volume increase in funding distributions and to more than 5,000 submissions and resubmissions in its required Fiscal Year 2022 FFATA reporting for all federal programs managed by the Department?s grant fiscal team. The Department indicated that its grant fiscal team also experienced staff turnover and vacancies during the year and the Department did not adequately reassign resources to ensure FFATA reporting requirements were identified and that reports were submitted on time. Initially, only one FTE was dedicated to FFATA reporting. During the year, the Department allocated a portion of the FFATA workload to another existing FTE and added an additional FTE in May 2022 to work on reconciling FFATA submissions; as a result, Department staff identified the two submissions previously missed, but the reallocations and reconciliations were not made in time to ensure the Department met all of its required FFATA report submission timelines. In addition, Department staff indicated that they made a conscious decision to not report the Title I subawards until May 2022?even though the initial subawards were finalized in January 2022?because the Department had historically received multiple funding allocations in addition to the initial allocation that required FFATA reporting for each allocation for up to 178 subawardees. However, the Department did not communicate with the federal awarding agency to determine whether waiting until it received all related allocations to submit its FFATA reports was appropriate. During the majority of Fiscal Year 2022, the Department also did not have a control, such as a reconciliation, to help identify subawards that went unreported during the fiscal year. Why do these problems matter? By failing to properly report FFATA subawards through FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, the Department fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-042 The Department of Education (Department) should strengthen its internal controls over, and ensure it complies with requirements under, the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Improving the Department?s process for determining the timing of reporting within the FFATA Subaward Reporting System. This process should include appropriately allocating staff resources for reporting responsibilities, and considerations such as expected future award allocations and communications with the federal awarding agency when it is determined to not be feasible to report information in a timely manner. B. Continuing to develop and implement reconciliation procedures to identify subawards that went unreported during the fiscal year. Response Department of Education A. Agree Implementation Date: December 31, 2022 We agree with this recommendation. In recent years, the Federal Government had multiple continuing resolutions in their budget process, resulting in CDE?s Title I allocations coming in multiple iterations. For the last several years, CDE has received revised allocations from the US Department of Education for the fiscal year as late as early summer; in one example, we received six revisions. With staffing shortages and the administrative burden to continuously revise, research issues and update FFATA for each allocation change, CDE took the step to report only the final allocation to FFATA, which was reported as of the month the awardee was awarded. However, the report was submitted later in the fiscal year. CDE will take a two-fold approach to rectify the issue related to the required FFATA reporting for Title I. First, we will report to FSRS the initial awards within 30 days following the date the awardee was provided final approval on their award. This is consistent with CDE?s approach to all other federal awards. Second, we will monitor the continuing resolutions and changes in allocations, and report only the net changes to each awardee, in the month those changes occur from the US Department of Education. Thereby, FSRS will represent the total revised award. In addition to this approach, all Title I awards will continue to be a part of our regular FFATA reconciliation process. B. Agree Implementation Date: December 31, 2022 We agree with this recommendation. CDE identified its own failure to report two ESSER subawards to FFATA within 30 days as part of the successful development and implementation of a FFATA-specific reconciliation process in Summer 2022. CDE will continue to refine and improve its FFATA reconciliation process.
(A) We agree with this recommendation. In recent years, the Federal Government had multiple continuing resolutions in their budget process, resulting in CDE?s Title I allocations coming in multiple iterations. For the last several years, CDE has received revised allocations from the US Department of Education for the fiscal year as late as early summer; in one example, we received six revisions. With staffing shortages and the administrative burden to continuously revise, research issues and update FFATA for each allocation change, CDE took the step to report only the final allocation to FFATA, which was reported as of the month the awardee was awarded. However, the report was submitted later in the fiscal year. CDE will take a two-fold approach to rectify the issue related to the required FFATA reporting for Title I. First, we will report to FSRS the initial awards within 30 days following the date the awardee was provided final approval on their award. This is consistent with CDE?s approach to all other federal awards. Second, we will monitor the continuing resolutions and changes in allocations, and report only the net changes to each awardee, in the month those changes occur from the US Department of Education. Thereby, FSRS will represent the total revised award. In addition to this approach, all Title I awards will continue to be a part of our regular FFATA reconciliation process. (B) We agree with this recommendation. CDE identified its own failure to report two ESSER subawards to FFATA within 30 days as part of the successful development and implementation of a FFATA-specific reconciliation process in Summer 2022. CDE will continue to refine and improve its FFATA reconciliation process.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
Show full finding ▾Hide full finding ▴Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
(A) The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. (B) The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
2021-055
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-041 Medicaid Eligibility?Social Security Numbers associated with Multiple State IDs Each beneficiary?s Medicaid application must contain specific information, including the beneficiary?s Social Security Number (SSN), a copy of their birth certificate, and support for their income, necessary for determining their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD), which is managed by the Office of Information Technology (OIT), is designed to assign a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange, the Department?s Medicaid claims payment system, on a daily basis to update eligibility information, such as a beneficiary?s eligibility status or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including assessing the Department?s progress in implementing our Fiscal Year 2019 recommendation related to this issue. At that time, we recommended that the Department improve its internal controls in this area to ensure that it complies with federal regulations regarding Medicaid eligibility. The Department agreed with the Fiscal Year 2019 recommendation and, during our Fiscal Year 2021 audit, reported that it had implemented this recommendation as of December 2020. As part of our testing, we reviewed the internal controls the Department had in place during Fiscal Year 2021 to identify any beneficiaries whose SSN is linked to more than one State ID in Colorado interChange. During our audit, we requested a list of all Medicaid claims that were submitted by providers and paid by the Department from December 1, 2020, through June 30, 2021, including the beneficiaries? names, SSNs, and State IDs. The Department provided a list that included approximately 924,000 beneficiaries who received benefits during that period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries from December 2020 through June 2021. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within one year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to one year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation. During our testing, we identified 102 unique SSNs that appeared to be inappropriately associated with more than one State ID; in total, the 102 SSNs were tied to 209 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN and, as a result, made claims payments on behalf of ineligible beneficiaries or the SSNs could be valid, but with more than one State ID, a provider could submit and have a claim paid for the same services under both State IDs. Specifically, we found the following: ? For 62 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 129 different State IDs, where the State IDs appeared to be for different people based on the names and/or dates of birth. ? For 40 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 80 different State IDs, where the State IDs had the same name and date of birth. ? For 99 SSNs, each SSN was tied to two different State IDs in Colorado interChange. ? For three SSNs, each SSN was tied to more than two different State IDs in Colorado interChange. For example, in one of the three instances, there were five different State IDs associated with one invalid SSN. These issues affected a total of 209 Medicaid State IDs that had not been corrected as of June 2021, representing a total of $67,235 Medicaid claims paid through Colorado interChange from December 2020 through June 2021. We provided the list of SSNs and State IDs to the Department to research. The Department found that, as of the end of our audit in April 2022, 59 out of the 102 SSNs identified during the audit had been corrected by a caseworker, but 43 SSNs need to be corrected in CBMS. The Department reported that these 43 SSNs had been flagged through a system edit in CBMS implemented in December 2020; however, the SSNs had not yet been corrected because ?To merge or correct [the SSNs and State IDs] is a time intensive process and must be prioritized within the business process of the [local counties and] Medical Assistance sites.? Although the Department was able to determine which SSN and State ID discrepancies had been corrected in CBMS as of April 2022, the Department has not completed its research to determine which claims made in Colorado interChange were made on behalf of beneficiaries with a correct SSN, and whether the implemented system edit appropriately addresses the issues identified in both Fiscal Years 2019 and 2021. As of the end of the audit, the Department had not completed this research and we were unable to determine whether the payments were made on behalf of beneficiaries with a valid SSN at the time payments were made. Therefore, we consider all $67,235 of the payments to be known questioned costs; $37,786 of these costs were paid with federal grant funds. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements] (Uniform Guidance), is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place during Fiscal Year 2021 to prevent or detect all instances of multiple State IDs associated with the same SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. SIDMOD does not prevent several situations that can result in the same SSN with more than one State ID. For example, caseworkers could incorrectly input an SSN into CBMS or the SSN could be reported by the beneficiary incorrectly and, as a result, cause a new State ID to be created. There can also be instances when someone changes their name, such as when they get married, and apply for benefits prior to getting married and also after getting married, which could cause two State IDs to be created. If someone starts an application and does not finish the application and then restarts a new application at a later date, this can also cause two State IDs to be created. Further, when inputting multiple family members into the system, an input error of the SSN can occur with multiple family members with the same SSN, which would create multiple State IDs (one for each family member) with the same SSN. According to the Department, in order to implement the Fiscal Year 2019 recommendation, it implemented a system edit in CBMS in December 2020 that is designed to identify discrepancies in newly-entered or updated SSNs and State IDs in CBMS after that date and to then notify the caseworker so the caseworker can address the discrepancy; this edit was not designed to address SSN and State ID discrepancies that existed prior to December 2020. As a result, the system edit did not identify SSN and State ID discrepancies for claims made from December 2020 to June 2021 if those discrepancies existed prior to the implementation of the system edit in CBMS and the beneficiaries? information had not been updated in CBMS. For example, if a beneficiary had an incorrect SSN prior to the system edit and was, therefore, ineligible to receive Medicaid services, Colorado interChange would continue paying claims on behalf of the beneficiary until information was updated in CBMS and the beneficiary was determined to be ineligible for Medicaid. Because the system edit implemented in CBMS is only designed to detect and correct future SSN and State ID discrepancies, the Department has not fully addressed the issue of inappropriate claims payments that we identified in the prior audit recommendation. According to the Department, addressing SSN and State ID discrepancies that existed prior to December 2020 involves a manual process to identify, research, and resolve the discrepancies. The Department stated that a report to identify SSNs with multiple State IDs is being developed and is currently scheduled for deployment in June 2023. Furthermore, the Department has not established a monitoring process over caseworkers to ensure SSN and State ID discrepancies are addressed appropriately and in a timely manner. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to multiple State IDs associated with the same SSN. For example, without adequate controls in place to prevent multiple State IDs from being created, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2021-041 See Schedule of Findings and Questioned Costs for chart/table The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid eligibility by: A. Researching the claims payments that were identified during our audit to determine whether the local counties or Medical Assistance sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate?in accordance with federal regulation at the time the payments were made?and recovering any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify SSNs associated with multiple State IDs and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. C. Implementing a process to monitor that caseworkers are addressing the Colorado Benefits Management System alerts related to SSN and State ID discrepancies appropriately and in a timely manner. Response Department of Health Care Policy and Financing A. Disagree The research required to identify the appropriateness of payments for 102 SSNs compared to the 1.6 million Coloradans the Department serves is administratively impractical and not an efficient use of limited state resources. Instead the Department will continue our existing proactive approach. Based on previous research, 92% of errors noted in the 2019 sample actually supplied a SSN or met exceptions criteria; therefore, payments were appropriate. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs, which is working since 58% of the SSNs had already been corrected through the existing process during the audit work. The Department could not agree to the questioned costs as the testing failed to determine which member case was incorrect. The OSA should have documented the incorrect case or identified which State IDs had not been merged through the existing process. The OSA pulled claims data (not Colorado Benefits Management System, or CBMS, cases) and did not identify if those claims were from newly entered cases or cases entered prior to December 2020. The auditor?s sample should have only included the cases impacted by the Department?s system change related to the original recommendation. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department?s system, that provider is guaranteed payment if they render an authorized service. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or that we ?question? as appropriate. It is ultimately the Department?s responsibility to perform research over questioned costs to determine whether the payments were or were not appropriate and, working with CMS, whether the Department must refund the federal share of any overpayments to CMS, regardless of whether the Department recovers the payments from the providers. B. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. C. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-041 Medicaid Eligibility?Social Security Numbers associated with Multiple State IDs Each beneficiary?s Medicaid application must contain specific information, including the beneficiary?s Social Security Number (SSN), a copy of their birth certificate, and support for their income, necessary for determining their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD), which is managed by the Office of Information Technology (OIT), is designed to assign a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange, the Department?s Medicaid claims payment system, on a daily basis to update eligibility information, such as a beneficiary?s eligibility status or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including assessing the Department?s progress in implementing our Fiscal Year 2019 recommendation related to this issue. At that time, we recommended that the Department improve its internal controls in this area to ensure that it complies with federal regulations regarding Medicaid eligibility. The Department agreed with the Fiscal Year 2019 recommendation and, during our Fiscal Year 2021 audit, reported that it had implemented this recommendation as of December 2020. As part of our testing, we reviewed the internal controls the Department had in place during Fiscal Year 2021 to identify any beneficiaries whose SSN is linked to more than one State ID in Colorado interChange. During our audit, we requested a list of all Medicaid claims that were submitted by providers and paid by the Department from December 1, 2020, through June 30, 2021, including the beneficiaries? names, SSNs, and State IDs. The Department provided a list that included approximately 924,000 beneficiaries who received benefits during that period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries from December 2020 through June 2021. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within one year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to one year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation. During our testing, we identified 102 unique SSNs that appeared to be inappropriately associated with more than one State ID; in total, the 102 SSNs were tied to 209 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN and, as a result, made claims payments on behalf of ineligible beneficiaries or the SSNs could be valid, but with more than one State ID, a provider could submit and have a claim paid for the same services under both State IDs. Specifically, we found the following: ? For 62 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 129 different State IDs, where the State IDs appeared to be for different people based on the names and/or dates of birth. ? For 40 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 80 different State IDs, where the State IDs had the same name and date of birth. ? For 99 SSNs, each SSN was tied to two different State IDs in Colorado interChange. ? For three SSNs, each SSN was tied to more than two different State IDs in Colorado interChange. For example, in one of the three instances, there were five different State IDs associated with one invalid SSN. These issues affected a total of 209 Medicaid State IDs that had not been corrected as of June 2021, representing a total of $67,235 Medicaid claims paid through Colorado interChange from December 2020 through June 2021. We provided the list of SSNs and State IDs to the Department to research. The Department found that, as of the end of our audit in April 2022, 59 out of the 102 SSNs identified during the audit had been corrected by a caseworker, but 43 SSNs need to be corrected in CBMS. The Department reported that these 43 SSNs had been flagged through a system edit in CBMS implemented in December 2020; however, the SSNs had not yet been corrected because ?To merge or correct [the SSNs and State IDs] is a time intensive process and must be prioritized within the business process of the [local counties and] Medical Assistance sites.? Although the Department was able to determine which SSN and State ID discrepancies had been corrected in CBMS as of April 2022, the Department has not completed its research to determine which claims made in Colorado interChange were made on behalf of beneficiaries with a correct SSN, and whether the implemented system edit appropriately addresses the issues identified in both Fiscal Years 2019 and 2021. As of the end of the audit, the Department had not completed this research and we were unable to determine whether the payments were made on behalf of beneficiaries with a valid SSN at the time payments were made. Therefore, we consider all $67,235 of the payments to be known questioned costs; $37,786 of these costs were paid with federal grant funds. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements] (Uniform Guidance), is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place during Fiscal Year 2021 to prevent or detect all instances of multiple State IDs associated with the same SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. SIDMOD does not prevent several situations that can result in the same SSN with more than one State ID. For example, caseworkers could incorrectly input an SSN into CBMS or the SSN could be reported by the beneficiary incorrectly and, as a result, cause a new State ID to be created. There can also be instances when someone changes their name, such as when they get married, and apply for benefits prior to getting married and also after getting married, which could cause two State IDs to be created. If someone starts an application and does not finish the application and then restarts a new application at a later date, this can also cause two State IDs to be created. Further, when inputting multiple family members into the system, an input error of the SSN can occur with multiple family members with the same SSN, which would create multiple State IDs (one for each family member) with the same SSN. According to the Department, in order to implement the Fiscal Year 2019 recommendation, it implemented a system edit in CBMS in December 2020 that is designed to identify discrepancies in newly-entered or updated SSNs and State IDs in CBMS after that date and to then notify the caseworker so the caseworker can address the discrepancy; this edit was not designed to address SSN and State ID discrepancies that existed prior to December 2020. As a result, the system edit did not identify SSN and State ID discrepancies for claims made from December 2020 to June 2021 if those discrepancies existed prior to the implementation of the system edit in CBMS and the beneficiaries? information had not been updated in CBMS. For example, if a beneficiary had an incorrect SSN prior to the system edit and was, therefore, ineligible to receive Medicaid services, Colorado interChange would continue paying claims on behalf of the beneficiary until information was updated in CBMS and the beneficiary was determined to be ineligible for Medicaid. Because the system edit implemented in CBMS is only designed to detect and correct future SSN and State ID discrepancies, the Department has not fully addressed the issue of inappropriate claims payments that we identified in the prior audit recommendation. According to the Department, addressing SSN and State ID discrepancies that existed prior to December 2020 involves a manual process to identify, research, and resolve the discrepancies. The Department stated that a report to identify SSNs with multiple State IDs is being developed and is currently scheduled for deployment in June 2023. Furthermore, the Department has not established a monitoring process over caseworkers to ensure SSN and State ID discrepancies are addressed appropriately and in a timely manner. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to multiple State IDs associated with the same SSN. For example, without adequate controls in place to prevent multiple State IDs from being created, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Recommendation 2021-041 See Schedule of Findings and Questioned Costs for chart/table The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid eligibility by: A. Researching the claims payments that were identified during our audit to determine whether the local counties or Medical Assistance sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate?in accordance with federal regulation at the time the payments were made?and recovering any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify SSNs associated with multiple State IDs and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. C. Implementing a process to monitor that caseworkers are addressing the Colorado Benefits Management System alerts related to SSN and State ID discrepancies appropriately and in a timely manner. Response Department of Health Care Policy and Financing A. Disagree The research required to identify the appropriateness of payments for 102 SSNs compared to the 1.6 million Coloradans the Department serves is administratively impractical and not an efficient use of limited state resources. Instead the Department will continue our existing proactive approach. Based on previous research, 92% of errors noted in the 2019 sample actually supplied a SSN or met exceptions criteria; therefore, payments were appropriate. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs, which is working since 58% of the SSNs had already been corrected through the existing process during the audit work. The Department could not agree to the questioned costs as the testing failed to determine which member case was incorrect. The OSA should have documented the incorrect case or identified which State IDs had not been merged through the existing process. The OSA pulled claims data (not Colorado Benefits Management System, or CBMS, cases) and did not identify if those claims were from newly entered cases or cases entered prior to December 2020. The auditor?s sample should have only included the cases impacted by the Department?s system change related to the original recommendation. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department?s system, that provider is guaranteed payment if they render an authorized service. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or that we ?question? as appropriate. It is ultimately the Department?s responsibility to perform research over questioned costs to determine whether the payments were or were not appropriate and, working with CMS, whether the Department must refund the federal share of any overpayments to CMS, regardless of whether the Department recovers the payments from the providers. B. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. C. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
(B) The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. (C) The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
2021-041
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-042 Medical Loss Ratio Reporting for Managed Care Entities The Department contracts with Managed Care Entities (MCEs) to provide managed care health plans and deliver health care services to eligible Medicaid and CBHP beneficiaries and pays MCEs monthly fixed amounts, known as capitation payments, based on rates determined by actuaries for the provision of services covered under the contract. The Department pays the MCEs monthly capitation payments on behalf of each Medicaid and CBHP beneficiary enrolled in the MCE?s plan. MCEs then coordinate services for the eligible Medicaid and CBHP beneficiaries and providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid and CBHP beneficiaries. The MCEs are then responsible for paying the providers for the Medicaid and CBHP claims. The Department contracts with three different types of MCEs?Managed Care Organizations (MCO), Prepaid Inpatient Health Plans (PIHP), and Primary Care Case Management (PCCM) Entities. During Fiscal Year 2021, the Department had a total of 8 contracts with 10 MCEs, with two pairs of MCEs sharing a single contract with the Department. The Department is responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions, including requirements that the MCEs annually submit Medical Loss Ratio (MLR) reports to the Department. The MLR is the proportion of state and federal Medicaid and CBHP funds that the MCE used for medical services compared to the funds used for its administrative costs. MCEs are required by both federal regulations and their Department contract provisions to have an MLR above 85 percent (i.e., an MCE?s administrative costs cannot exceed 15 percent) except for specific exceptions defined in federal regulations. If the MLR is below 85 percent, the MCE must pay back the state and federal government for the amount that caused the MCE to fall below 85 percent. Every fiscal year, the Department provides an MLR reporting template for the MCEs to complete and return to the Department. The Department reported that when it receives the completed templates, staff review the information provided by the MCEs and compare it to supporting documentation to ensure it is accurate and complete. Once the Department has reviewed the MLR reports submitted by the MCEs, the Department submits the MLR reports to CMS, which are due by June 30 of the year following the end of the MLR reporting year. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation to CMS by June 30, 2021. During Fiscal Year 2021, the Department reported that it paid approximately $1.4 billion in Medicaid and CBHP capitation payments to MCEs for medical services, not including the capitation payments for other services, such as administrative costs. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department?s internal controls and compliance over ensuring that MLR reports submitted to CMS by the Department include all the required information in accordance with federal regulations during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over obtaining and reviewing MLR reports from each MCE. In addition, we requested and reviewed all MLR reports submitted to the Department by the 10 MCEs that were under contract with the Department in Fiscal Year 2021 to determine whether the MLR reports included all information required by federal regulations and were submitted within the required timeframes. How were the results of the audit work measured? Federal regulations [42 CFR 438.8(k)] require that the Department ensure each MCE under contract with the Department submits a report with the data elements specified in 42 CFR section 438.8(k)(1). The reports are specifically required to contain 13 required data elements, reflect the correct reporting years, and contain an attestation of accuracy regarding the calculation of the MLR. The 13 data elements include items such as total incurred claims, the methodology for allocating expenditures, the calculated MLR, and a comparison of the information reported in the MLR report to the MCE?s audited financial report. Federal regulations [42 CFR 438.8(g)] note that the method used to allocate expenses in the MLR calculation must be: ? Based on a generally accepted accounting method that is expected to yield the most accurate results; ? Any shared expenses must be apportioned pro rata to the contract incurring the expense; and ? Expenses that relate solely to the operation of a reporting entity must be borne solely by the reporting entity and are not to be apportioned to other entities. Federal regulations [42 CFR 438.8(k)(2)] require MCEs to submit the MLR report in a timeframe and manner determined by the Department, which must be within 12 months of the end of the MCE?s reporting year. The Department?s contract provisions for MCEs state that the MLR reporting year should align with the State?s fiscal year, beginning on July 1 and ending on June 30 of the subsequent calendar year. Contract provisions also state that each MCE shall submit to the Department the completed MLR calculation template and supporting documentation for each reporting year by the following January 15. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation template to the Department by January 15, 2021, and the Department would be required to submit the MLR calculation to CMS by June 30, 2021. What problems did the audit work identify? We reviewed all reports provided to the Department by the 10 MCEs during Fiscal Year 2021 (for the MLR reporting year ended June 30, 2020) and determined that none of the MLR reports submitted by the 10 MCEs to the Department contained all of the required data elements in Fiscal Year 2021. Specifically, the MLR reports were missing 2 of the 13 (15 percent) required data elements: the methodology for the MCEs? allocation of expenditures and a comparison of the information reported in the MLR report to the MCEs? audited financial reports. This omission is significant because the MCEs reported total medical expenditures ranging from $20.5 million to $208.4 million and earned revenue from $23.4 million to $219.1 million. In addition, we determined that 1 of the 10 MLR reports received in Fiscal Year 2021 (10 percent) had not been submitted to CMS as of April 2022. This report was due to CMS on June 30, 2021. Why did these problems occur? We found that the Department lacked adequate controls to ensure that MLR reports submitted by the MCEs fully complied with federal regulations. First, we noted that although the Department?s MCE contracts state the MCE?s MLR report should include all 13 federally required data elements, the MLR template the Department provided to the MCEs did not include specific sections addressing the two missing federally-required data elements. As a result, the MCEs did not submit this information. Furthermore, the Department did not have written policies and procedures for reviewing completed MLR reports to ensure the reports ultimately included those requirements. Second, the Department does not have an enforcement mechanism to ensure the MCEs provide corrected MLR report information in a timely manner. The Department reported that it had not submitted the one MLR report to CMS because it had open questions on the MLR report and was unable to verify that the information was correct, valid, and in compliance with federal regulations. Although the Department sent the MLR report back to the MCE for correction several times, the Department did not have sufficient controls in place to ensure the MCE ultimately provided the corrected report back to the Department within the required reporting timeline for CMS submission. Why do these problems matter? The Department is responsible for ensuring MLR reports are obtained and submitted to CMS in accordance with federal regulations and that MCEs have an MLR above 85 percent. While all 10 MCEs reported that their MLRs were above 85 percent for the reports submitted during Fiscal Year 2021, without providing all required data elements, neither the Department nor the federal government can validate that this percentage is accurate. By not including the methodology for the MCE?s allocation of expenditures, the Department, and ultimately CMS, are unable to confirm that each type of expense is being allocated correctly and that any shared expenses are being prorated appropriately. Additionally, by not including a comparison of the information reported in the MRL to the MCE?s audited financial report, the Department is unable to confirm that the information the MCE used to calculate their MLR is accurate. Overall, without effective internal controls in place, the Department risks providing MLR reports to CMS that contain inaccurate or incomplete information or that the MLR is below 85 percent and the Department does not catch the error. As a result, state and federal funds could be used disproportionately on administrative costs rather than medical services, which would negatively impact the quality of care Medicaid and CBHP beneficiaries receive. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Medical Loss Ratio (MLR) reporting by: A. Updating its MLR report template provided to Managed Care Entities (MCEs) to comply with federal regulations and developing and implementing written policies and procedures. These policies and procedures should include the requirement for MCEs to submit MLR reports that include the data elements required by federal regulations and specify the Department?s review process of those MLR reports to ensure they include accurate and complete information. B. Developing an enforcement mechanism to ensure it receives accurate and corrected information from the MCEs in a timely manner so the Department is able to complete its validation process of MLR reports and meet the June 30 deadline for report submission to the Centers for Medicare & Medicaid Services. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2022 The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. B. Agree Implementation Date: January 2023 The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-042 Medical Loss Ratio Reporting for Managed Care Entities The Department contracts with Managed Care Entities (MCEs) to provide managed care health plans and deliver health care services to eligible Medicaid and CBHP beneficiaries and pays MCEs monthly fixed amounts, known as capitation payments, based on rates determined by actuaries for the provision of services covered under the contract. The Department pays the MCEs monthly capitation payments on behalf of each Medicaid and CBHP beneficiary enrolled in the MCE?s plan. MCEs then coordinate services for the eligible Medicaid and CBHP beneficiaries and providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid and CBHP beneficiaries. The MCEs are then responsible for paying the providers for the Medicaid and CBHP claims. The Department contracts with three different types of MCEs?Managed Care Organizations (MCO), Prepaid Inpatient Health Plans (PIHP), and Primary Care Case Management (PCCM) Entities. During Fiscal Year 2021, the Department had a total of 8 contracts with 10 MCEs, with two pairs of MCEs sharing a single contract with the Department. The Department is responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions, including requirements that the MCEs annually submit Medical Loss Ratio (MLR) reports to the Department. The MLR is the proportion of state and federal Medicaid and CBHP funds that the MCE used for medical services compared to the funds used for its administrative costs. MCEs are required by both federal regulations and their Department contract provisions to have an MLR above 85 percent (i.e., an MCE?s administrative costs cannot exceed 15 percent) except for specific exceptions defined in federal regulations. If the MLR is below 85 percent, the MCE must pay back the state and federal government for the amount that caused the MCE to fall below 85 percent. Every fiscal year, the Department provides an MLR reporting template for the MCEs to complete and return to the Department. The Department reported that when it receives the completed templates, staff review the information provided by the MCEs and compare it to supporting documentation to ensure it is accurate and complete. Once the Department has reviewed the MLR reports submitted by the MCEs, the Department submits the MLR reports to CMS, which are due by June 30 of the year following the end of the MLR reporting year. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation to CMS by June 30, 2021. During Fiscal Year 2021, the Department reported that it paid approximately $1.4 billion in Medicaid and CBHP capitation payments to MCEs for medical services, not including the capitation payments for other services, such as administrative costs. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department?s internal controls and compliance over ensuring that MLR reports submitted to CMS by the Department include all the required information in accordance with federal regulations during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over obtaining and reviewing MLR reports from each MCE. In addition, we requested and reviewed all MLR reports submitted to the Department by the 10 MCEs that were under contract with the Department in Fiscal Year 2021 to determine whether the MLR reports included all information required by federal regulations and were submitted within the required timeframes. How were the results of the audit work measured? Federal regulations [42 CFR 438.8(k)] require that the Department ensure each MCE under contract with the Department submits a report with the data elements specified in 42 CFR section 438.8(k)(1). The reports are specifically required to contain 13 required data elements, reflect the correct reporting years, and contain an attestation of accuracy regarding the calculation of the MLR. The 13 data elements include items such as total incurred claims, the methodology for allocating expenditures, the calculated MLR, and a comparison of the information reported in the MLR report to the MCE?s audited financial report. Federal regulations [42 CFR 438.8(g)] note that the method used to allocate expenses in the MLR calculation must be: ? Based on a generally accepted accounting method that is expected to yield the most accurate results; ? Any shared expenses must be apportioned pro rata to the contract incurring the expense; and ? Expenses that relate solely to the operation of a reporting entity must be borne solely by the reporting entity and are not to be apportioned to other entities. Federal regulations [42 CFR 438.8(k)(2)] require MCEs to submit the MLR report in a timeframe and manner determined by the Department, which must be within 12 months of the end of the MCE?s reporting year. The Department?s contract provisions for MCEs state that the MLR reporting year should align with the State?s fiscal year, beginning on July 1 and ending on June 30 of the subsequent calendar year. Contract provisions also state that each MCE shall submit to the Department the completed MLR calculation template and supporting documentation for each reporting year by the following January 15. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation template to the Department by January 15, 2021, and the Department would be required to submit the MLR calculation to CMS by June 30, 2021. What problems did the audit work identify? We reviewed all reports provided to the Department by the 10 MCEs during Fiscal Year 2021 (for the MLR reporting year ended June 30, 2020) and determined that none of the MLR reports submitted by the 10 MCEs to the Department contained all of the required data elements in Fiscal Year 2021. Specifically, the MLR reports were missing 2 of the 13 (15 percent) required data elements: the methodology for the MCEs? allocation of expenditures and a comparison of the information reported in the MLR report to the MCEs? audited financial reports. This omission is significant because the MCEs reported total medical expenditures ranging from $20.5 million to $208.4 million and earned revenue from $23.4 million to $219.1 million. In addition, we determined that 1 of the 10 MLR reports received in Fiscal Year 2021 (10 percent) had not been submitted to CMS as of April 2022. This report was due to CMS on June 30, 2021. Why did these problems occur? We found that the Department lacked adequate controls to ensure that MLR reports submitted by the MCEs fully complied with federal regulations. First, we noted that although the Department?s MCE contracts state the MCE?s MLR report should include all 13 federally required data elements, the MLR template the Department provided to the MCEs did not include specific sections addressing the two missing federally-required data elements. As a result, the MCEs did not submit this information. Furthermore, the Department did not have written policies and procedures for reviewing completed MLR reports to ensure the reports ultimately included those requirements. Second, the Department does not have an enforcement mechanism to ensure the MCEs provide corrected MLR report information in a timely manner. The Department reported that it had not submitted the one MLR report to CMS because it had open questions on the MLR report and was unable to verify that the information was correct, valid, and in compliance with federal regulations. Although the Department sent the MLR report back to the MCE for correction several times, the Department did not have sufficient controls in place to ensure the MCE ultimately provided the corrected report back to the Department within the required reporting timeline for CMS submission. Why do these problems matter? The Department is responsible for ensuring MLR reports are obtained and submitted to CMS in accordance with federal regulations and that MCEs have an MLR above 85 percent. While all 10 MCEs reported that their MLRs were above 85 percent for the reports submitted during Fiscal Year 2021, without providing all required data elements, neither the Department nor the federal government can validate that this percentage is accurate. By not including the methodology for the MCE?s allocation of expenditures, the Department, and ultimately CMS, are unable to confirm that each type of expense is being allocated correctly and that any shared expenses are being prorated appropriately. Additionally, by not including a comparison of the information reported in the MRL to the MCE?s audited financial report, the Department is unable to confirm that the information the MCE used to calculate their MLR is accurate. Overall, without effective internal controls in place, the Department risks providing MLR reports to CMS that contain inaccurate or incomplete information or that the MLR is below 85 percent and the Department does not catch the error. As a result, state and federal funds could be used disproportionately on administrative costs rather than medical services, which would negatively impact the quality of care Medicaid and CBHP beneficiaries receive. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Medical Loss Ratio (MLR) reporting by: A. Updating its MLR report template provided to Managed Care Entities (MCEs) to comply with federal regulations and developing and implementing written policies and procedures. These policies and procedures should include the requirement for MCEs to submit MLR reports that include the data elements required by federal regulations and specify the Department?s review process of those MLR reports to ensure they include accurate and complete information. B. Developing an enforcement mechanism to ensure it receives accurate and corrected information from the MCEs in a timely manner so the Department is able to complete its validation process of MLR reports and meet the June 30 deadline for report submission to the Centers for Medicare & Medicaid Services. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2022 The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. B. Agree Implementation Date: January 2023 The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
(A) The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. (B) The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
2021-042
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https:hcpf.colorado.gov/quality-and-healthimprovement-reports.
2021-043
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
(B) The Department will review and revise, as necessary, its taxi claim billing requirements and rates to ensure that they are consistent. In addition, the Department will devise controls to ensure that taxi claims are paid in accordance with established requirements and rates and explore controls to ensure that only permitted providers bill as a taxi. The Department is working on reductions in the max fee and unit limits for taxi claim billing codes, which it will have completed by the end of October 2021. In addition, the Department is considering systematically pricing the code at each taxi provider?s specific Public Utilities Commission (PUC) rate. This change, if pursued, will require a system change request, which will take a year or more, which is why the Department has selected an implementation date of December 2022. If this proves infeasible, alternate controls will be implemented. HCPF has met with DORA PUC. The Department is trying to establish a process to decide if the PUC taxi rate still applies or an internal rate can be created. Because of these discussions and needed system changes the implementation date has been moved to December 2023. (D) The Department intends to define in rule the types of documentation that NEMT providers must keep on hand and make clear that they must furnish records to the Department upon request. The July 2022 date will allow for the completion of formal rulemaking. The Department further intends to develop and implement a process to perform regular risk-based provider file reviews with a focus on noncompliant providers. These reviews will ensure, at a minimum, that the providers? paid claims are supported with appropriate documentation and represent the least costly option appropriate to meet each recipient?s needs. The Department met with the RAC team on February 22, 2023 to come up with a process to perform small audits for claims from providers that are outside the Intelliride service area. New systems will be implemented which has pushed the anticipated completion date to December 2023. (E) The Department will amend its contract with its NEMT broker by adding a mandatory annual audit so that it can reconcile trip scheduling data with paid claims data. This will help ensure that the Department pays accurately, pays for NEMT services, and pays for the least costly transportation option appropriate for each recipient. The Department chose July 2022 to add the audit through its annual contract amendment and renewal processes. The contract amendment was completed and signed June 30, 2022 that included a clause for an annual audit of claims. (F) The Department will develop a data review process to reconcile interChange data on NEMT trip claims to interChange data on Medicaid medical claims. This process will entail periodic reviews of NEMT claims to see if members have corresponding medical claims on those dates. If they do not, the Department will follow up with the appropriate NEMT provider to investigate. The July 2022 implementation date reflects the potential need for system changes. This is implemented, the Department has been pulling claims data and where corresponding medical claims are not found HCPF is investigating on a case by case basis to find the cause. (G) Department staff will work with the Department?s Program Integrity (PI) staff on processes to investigate and recover, as appropriate, the overpayments and inappropriate payments that the audit identified as known or likely questioned costs, and repay the federal portion, as appropriate. The December 2022 implementation date reflects the time needed to investigate and when appropriate, recover any overpayments. This has been implemented and the federal portion has been returned to CMS. (H) The Department will develop a process to track staff time and productivity to ensure that it has sufficient staff assigned to oversee and administer NEMT. This process will include documenting time spent each week on various tasks to get a sense of where help is needed, and which tasks take up the most staff resources. Based on its findings, the Department will explore staffing options, as needed. The Department selected the July 2022 implementation date to allow for data collection through the end of State Fiscal Year 2021-22. This has been implemented. New NEMT staff was hired November 1, 2022 to act as the liaison to the counties and clients in the 55 counties outside of the Intelliride service area.
2021-045
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-047 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-034 MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Individuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations. Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020. We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE. Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. STATISTICAL SAMPLING METHODOLOGY We selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period. Our methodology included the following procedures: ? We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary. ? We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period. ? We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG). ? For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period. ? After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period. See Schedule of Findings and Questioned Costs for chart/table. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? For 32 of the 125 Medicaid beneficiaries? case files that we tested (26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs. PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million. PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projections. See Schedule of FIndings and Questioned Costs for chart/table. The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: ? PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102. Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments. According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? ? INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020. State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI. ? INCOME ISSUES. We identified the following income-related issues: ? INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281. ? INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280. ? INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. ? INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines. Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income. ? MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. ? BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs. State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits. ? INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs. State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-047 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-034 MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Individuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations. Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020. We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE. Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. STATISTICAL SAMPLING METHODOLOGY We selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period. Our methodology included the following procedures: ? We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary. ? We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period. ? We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG). ? For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period. ? After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period. See Schedule of Findings and Questioned Costs for chart/table. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? For 32 of the 125 Medicaid beneficiaries? case files that we tested (26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs. PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million. PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projections. See Schedule of FIndings and Questioned Costs for chart/table. The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: ? PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102. Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments. According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? ? INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020. State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI. ? INCOME ISSUES. We identified the following income-related issues: ? INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281. ? INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280. ? INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. ? INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines. Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income. ? MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. ? BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs. State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits. ? INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs. State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.
(A) Caseworker errors can be caused by an array of issues, including, training material retention; a lack of adequate funding to balance caseload inventory versus available work hours and staffing levels; a lack of quality review and performance reinforcement; and an assortment of local issues that lead to employee turnover. The Department will continue to work with eligibility sites regarding caseworker errors identified through this audit. The Department?s caseworker training resources, or Staff Development Center (SDC), is in the process of revamping all of their foundational training materials into a "Process-Based Training" model to be more effective and efficient based on training industry best practice. In addition, the SDC is converting all training materials into several different training modalities (instructor led courses, eLearning courses, desk aids, process manuals, infographics, workbooks, etc.) to be more engaging, effective, and accessible to adult learners with varying needs and preferences across large geographical areas. The revised training model is on track to be completed by July 31, 2021 and fully rolled out to all counties by Fiscal year end 2022. (C) The Department has thoroughly researched the issues identified in this audit and has made changes to CBMS to ensure that it is using the correct income information, income thresholds in determining eligibility, and buy-in premiums are assessed. These issues were fixed May 2019, February 2020, and March 2020, and in June 2021 the income information system issue will be corrected. The Department disagrees with the auditor?s questioned costs and projection of those questions costs. The Department disagrees with the auditor?s sampling, stratification, and costs used to generate the projected questioned costs. The costs incorrectly include members who remain eligible once the identified error had been resolved, payments that will be recovered by the Department through an existing process to recover capitation payments from deceased members, a Social Security Administration (SSA) interface error outside the control of the Department, and costs related to an already identified issue regarding reconciling eligibility between CBMS and Colorado interChange. Some of these costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department and should have been excluded from the questioned costs and the resulting projections. The Department will resume the reconciliation process between CBMS and Colorado interChange when authorized by CMS. Regarding the SSA interfaces, SSA posted results that are valid conditions for Medicaid eligibility, so those costs should have been excluded from the resulting projections. The Department agrees to bring interface issues to the attention of SSA. The Department has heard that other individuals have been notified on an SSA incarceration status which was incorrect. We have reached out to SSA concerning interface issues and will reach out again. In the meantime we will work with our eligibility workers to attempt to update these cases when they occur.
2021-047
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-048 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-035 MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIES As a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death. Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations. CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death. In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered. Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows: MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death. We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds. MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP. We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds. The following table summarizes the issues we identified. See Schedule of Findings and Questioned Costs for chart/table. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows: ? LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death. ? SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified: ? According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death. ? The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments. WHY DO THESE PROBLEMS MATTER? Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-035 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by: A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations. B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries. C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. B AGREE. IMPLEMENTATION DATE: JULY 2022. The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. AUDITOR?S ADDENDUM As noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines. AUDITOR?S ADDENDUM As noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-048 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-035 MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIES As a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death. Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations. CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death. In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered. Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows: MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death. We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds. MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP. We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds. The following table summarizes the issues we identified. See Schedule of Findings and Questioned Costs for chart/table. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows: ? LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death. ? SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified: ? According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death. ? The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments. WHY DO THESE PROBLEMS MATTER? Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-035 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by: A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations. B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries. C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. B AGREE. IMPLEMENTATION DATE: JULY 2022. The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. AUDITOR?S ADDENDUM As noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines. AUDITOR?S ADDENDUM As noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
(A) The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. (B) The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. (C) The review for FFS claims is complete and all Notices of Adverse Action have been sent to providers. At this time we are waiting on any requests for informal reconsiderations, appeals, and/or payments to process.
2021-048
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-049 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-036 CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. We performed the following testwork: REVIEW OF CBHP ELIGIBILITY CASE FILES ? We reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees. ? Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program. DATA ANALYSES OF CBHP BENEFICIARIES ? INELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits. ? CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits. CBHP ELIGIBILITY MONITORING AND REVIEW We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY CASE FILE ISSUES In 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP. The following table outlines the types of issues we found. See Schedule of Findings and Questioned Costs for chart/table. The specific issues we identified and the breakdown of identified questioned costs are as follows: ? CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically: ? In seven cases, the Department did not assess an enrollment fee. ? In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries. Benefits were inappropriately paid on behalf of these 10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260. State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program. ? LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546. State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. ? INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines. In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level. ? MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows: ? In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs. ? In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs. According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].? State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES We identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows. CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified 39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020. We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)]. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....? Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider. CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange. We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS. In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020. Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP. The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004]. The following table summarizes the eligibility issues we identified through our data analyses. See Schedule of FIndings and Questioned Costs for chart/table. ELIGIBILITY MONITORING ISSUES CBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations. CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income. MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations. SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals. Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-049 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-036 CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. We performed the following testwork: REVIEW OF CBHP ELIGIBILITY CASE FILES ? We reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees. ? Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program. DATA ANALYSES OF CBHP BENEFICIARIES ? INELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits. ? CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits. CBHP ELIGIBILITY MONITORING AND REVIEW We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY CASE FILE ISSUES In 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP. The following table outlines the types of issues we found. See Schedule of Findings and Questioned Costs for chart/table. The specific issues we identified and the breakdown of identified questioned costs are as follows: ? CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically: ? In seven cases, the Department did not assess an enrollment fee. ? In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries. Benefits were inappropriately paid on behalf of these 10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260. State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program. ? LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546. State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. ? INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines. In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level. ? MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows: ? In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs. ? In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs. According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].? State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES We identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows. CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified 39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020. We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)]. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....? Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider. CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange. We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS. In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020. Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP. The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004]. The following table summarizes the eligibility issues we identified through our data analyses. See Schedule of FIndings and Questioned Costs for chart/table. ELIGIBILITY MONITORING ISSUES CBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations. CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income. MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations. SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals. Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.
(B) The Department revised its training model which is on track and will be fully rolled out to all eligibility sites by July 2022. (D) The Department disagrees with the auditor?s findings and questioned costs related to capitation payments under the Eligibility Issues Identified through Data Analyses section. These costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department. The Department was actively working to resolve these cases with CMS prior to the Public Health Emergency (PHE). The Department developed and implemented a reconciliation report that is used to research and resolve CBMS and Colorado interChange interface mismatches. Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS.
2021-049
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-050 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-037 RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTS The Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified. The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS. The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system. The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate. The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020. During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations. Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS. The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following: ? UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest. According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider. According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment. ? INACCURATE FEDERAL REPORTING. For all 13 Medicaid (100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance. Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections. ? EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the 13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired. According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division. ? INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS. Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors: ? LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports. ? LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet. ? LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports. ? LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments. WHY DO THESE PROBLEMS MATTER? Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations. Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-037 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by: A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports. B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations. C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports. D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. D AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-050 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-037 RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTS The Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified. The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS. The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system. The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate. The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020. During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations. Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS. The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following: ? UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest. According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider. According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment. ? INACCURATE FEDERAL REPORTING. For all 13 Medicaid (100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance. Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections. ? EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the 13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired. According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division. ? INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS. Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors: ? LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports. ? LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet. ? LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports. ? LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments. WHY DO THESE PROBLEMS MATTER? Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations. Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-037 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by: A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports. B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations. C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports. D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. D AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
(A) The training materials have been created, and the training will take place on June 23, 2022. (B) The policies and procedures have been updated and were effective on July 1, 2022. (C) The Department implemented procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. (D) The Program Integrity Division has created a supervisory review process that is included in the updated policies and procedures. This process was effective July 1, 2022.
2021-050
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2020-051 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-038 PRESUMPTIVE ELIGIBILITY Colorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible. To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020. During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews. In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following: ? UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. ? LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020. State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site. ? LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following: ? For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020. ? 11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes. ? Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored. Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?. According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed. Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations. ? MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible. Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible. ? SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs. CBMS is designed to display case and applicant information consistently between various screens within the system. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: ? LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites. ? LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations. ? CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens. WHY DO THESE PROBLEMS MATTER? As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-038 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by: A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites. B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed. C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it. C AGREE. IMPLEMENTATION DATE: IMPLEMENTED. Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it. AUDITOR?S ADDENDUM for Parts A, B, and C As noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2020-051 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-038 PRESUMPTIVE ELIGIBILITY Colorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible. To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020. During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews. In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following: ? UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. ? LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020. State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site. ? LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following: ? For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020. ? 11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes. ? Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored. Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?. According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed. Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations. ? MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible. Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible. ? SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs. CBMS is designed to display case and applicant information consistently between various screens within the system. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: ? LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites. ? LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations. ? CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens. WHY DO THESE PROBLEMS MATTER? As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-038 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by: A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites. B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed. C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it. C AGREE. IMPLEMENTATION DATE: IMPLEMENTED. Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it. AUDITOR?S ADDENDUM for Parts A, B, and C As noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
(A) The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. (B) The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the recertifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it. (C) The Department fixed enrollment information for Fiscal Year 2020 and 2021 in CBMS for beneficiaries who were no longer eligible for presumptive eligibility and have either had their benefits terminated or were moved to the regular Medicaid and Children?s Basic Health Plan programs. The Department is currently performing regular reviews to appropriately terminate applicants? presumptive eligibility in CBMS when appropriate. However, the Department has not addressed the programming and system issues in CBMS. The Department plans to fully implement this recommendation by December 2022.
2021-051
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2020-052 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-039 PROVIDER ELIGIBILITY The providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP. Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020. Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers. We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year. We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment. In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: ? FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.? ? STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations. ? DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license. ? FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under 42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services. ? CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP. ? FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s). WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES INELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows: ? 13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers. ? One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract. ELIGIBILITY CASE FILE ISSUES MISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations. ? INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner. ? POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance. ? LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs. Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-039 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by: A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired. B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations. C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2020-052 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-039 PROVIDER ELIGIBILITY The providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP. Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020. Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers. We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year. We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment. In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: ? FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.? ? STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations. ? DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license. ? FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under 42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services. ? CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP. ? FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s). WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES INELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows: ? 13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers. ? One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract. ELIGIBILITY CASE FILE ISSUES MISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations. ? INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner. ? POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance. ? LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs. Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-039 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by: A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired. B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations. C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
(A) The Department completed the system enhancement, allowing on-going data feeds from DORA into the interChange. The enhancement included implementation of a front-end claim edit, to prevent claim payments to providers with an expired license. The edit will be functional once the impact to providers has been determined. The project was completed mid July 2022 with courtesy notices to our provider network, to update license information as applicable. Policies and procedures were updated to address this finding on May 17, 2022. The policy and procedure is effective July 1, 2022. (B) The Department has updated its policies and procedure for reviewing license actions, effective July 1, 2022. (C) Licensure continues to be a quality monitoring criterion for the Department and the Fiscal Agent. The Department completed the system enhancement, allowing on-going data feeds from DORA into the interChange. The enhancement included implementation of a front-end claim edit, to prevent claim payments to providers with an expired license. The edit will be functional once the impact to providers has been determined. The project was completed mid July 2022 with courtesy notices to our provider network, to update license information as applicable.
2021-052
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
(A) The state implemented the first phase of the monitoring dashboard in June 2020 with Project 13889 that identifies members that are active with no SSN without exemptions. The second phase of the monitoring dashboard implementation was pushed back to July 2023 due to competing legislative mandates.
2021-054
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
(A) The Department continues to work with the Fiscal Agent to ensure that the required database matches occur and the interChange properly displays the results of Social Security Number and Federal Employer Identification Number verifications for all providers. The project was completed mid July 2022.
2021-056
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
Show full finding ▾Hide full finding ▴Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
(A) Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. (B) Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Show full finding ▾Hide full finding ▴Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
(A) Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. (B) Otero College will ensure they maintain supporting documentation for procurements. (C) Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Show full finding ▾Hide full finding ▴Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
(A) Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. (B) The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. (C) Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Finding 2022-059 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF I) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund (Assistance Listing No. 84.425). The HEERF program contains two portions: the Student Aid portion (Assistance Listing No. 84.425E) and the Institutional portion, which is made up of the following: HEERF Institutional Aid Portion (Assistance Listing No. 84.425F), HEERF Minority Serving Institutions (Assistance Listing No. 84.425L), HEERF Strengthening Institutions Program (Assistance Listing No. 84.425M), Institutional Resilience and Expanded Postsecondary Opportunity (Assistance Listing No. 84.425P), and HEERF Supplemental Assistance to Institutions of Higher Education program (Assistance Listing No. 84.425S). Amounts provided to students through HEERF are considered to be ?Emergency Financial Aid Grants to Students? under the Program. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent approximately $97.8 million for the HEERF program Student Aid portion which is used to award Emergency Financial Aid Grants to students and $113.9 million for the HEERF Institutional Portion, which is used to support the colleges. $117.3 of this amount was expended by the System during Fiscal Year 2022. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the ED to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The annual report is to be submitted directly to the ED. The ED has specified certain criteria that must be included in each report. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over, and complied with, the HEERF Institutional and Student Aid grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 25 of the 117 HEERF reports submitted by the System?s campuses during Fiscal Year 2022 to determine whether the reports were posted on each campus? primary website (quarterly reports) or submitted to ED (annual reports) by the federal due dates. Furthermore, for the Student Aid Quarterly Report we requested from each Campus the underlying support for the reports, which consisted of student data detailing how much aid was awarded and the methods the campuses used to determine which students would receive Emergency Financial Aid Grants. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? On May 13, 2021, the ED published in the Federal Register a notice for student aid public reporting under CRRSAA and ARP, which requires that institutions publicly post certain information on their website. The following information must appear in a format and location that is easily accessible to the public: o An acknowledgement that the institution signed and returned to the ED the Certification and Agreement and the assurance that the institution has used the applicable amount of funds designated under the CRRSAA and ARP programs to provide Emergency Financial Aid Grants to Students. o The total amount of funds that the institution will receive or has received from the ED pursuant to the institution's Certification and Agreement for Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total amount of Emergency Financial Aid Grants distributed to students under the CRRSAA and ARP programs as of the date of submission (i.e., as of the initial report and every calendar quarter thereafter). o The estimated total number of students at the institution that are eligible to receive Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total number of students who have received an Emergency Financial Aid Grant to students under the CRRSAA and ARP programs. o The method(s) used by the institution to determine which students receive Emergency Financial Aid Grants and how much they would receive under the CRRSAA and ARP programs. o Any instructions, directions, or guidance provided by the institution to students concerning the Emergency Financial Aid Grants. ? Federal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that federal reports are accurate and report complete information. Appropriate supporting documentation is evidence of such internal controls. What problems did the audit work identify? We identified issues with 5 of the 25 Fiscal Year 2022 reports we tested (20 percent). Specifically, Front Range Community College (FRCC), Pueblo Community College (PCC), and Lamar Community College (LCC) could not provide appropriate supporting documentation for one or more of the following data elements in five of the Student Aid Quarterly Reports: student data detailing (a) the total amount of Emergency Financial Aid Grants distributed to students, (b) the total number of students eligible to receive Emergency Financial Aid Grants and/or (c) the total number of students at the institution who have received an Emergency Financial Aid Grant. The specific issues we found the following: ? FRCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended September 30, 2021 as 20,684; based on our review, we determined the supported number was 20,782. ? FRCC reported the total number of students at the institution who have received an Emergency Financial Aid Grant for the quarter ended June 30, 2022 as 20,385 (student portion) and 3,207 (institutional portion); based on our review, we determined the supported numbers were 20,401 and 3,222, respectively. ? LCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended June 30, 2022 as 1,007; based on our review, we determined the supported number was 1,034. In addition, the amount disbursed directly to student emergency financial aid grants to date was reported as 961 and total for all HEERF funds was 1,124; based on our review, we determined the supported numbers were 988 and 1,151, respectively. ? PCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarters ending September 30, 2021 and December 31, 2021 as 3,191; based on our review, we determined this amount could not be supported and PCC did not provide a revised count. Why did these problems occur? FRCC, PCC, and LCC campuses did not have procedures in place to ensure that supporting documentation was maintained for its Student Aid Quarterly Reporting. Employee turnover in the FRCC Controller position and FRCC, PCC, and LCC Student Financial Aid Director positions further contributed to FRCC, PCC, and LCC?s inability to locate or recreate the supporting documentation. Why do these problems matter? It is important for FRCC, PCC, and LCC to ensure that they obtain and maintain appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining FRCC, PCC, and LCC?s compliance with specific federal program requirements. This issue could lead to inaccurate federal reporting and potential noncompliance, which could result in the federal government requiring FRCC, PCC, and LCC to return funds or a negative impact to the System?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-059 Front Range Community College, Lamar Community College, and Pueblo Community College campuses should strengthen their internal controls over federal reporting and ensure they comply with the Higher Education Emergency Relief Fund reporting requirements by reviewing reports for accuracy and developing procedures for ensuring the required maintenance of all related supporting documentation. Response Front Range Community College Agree Implementation Date: September 2022 Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Response Lamar Community College Agree Implementation Date: July 2022 The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Response Pueblo Community College Agree Implementation Date: October 2022 Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.
Show full finding ▾Hide full finding ▴Finding 2022-059 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF I) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund (Assistance Listing No. 84.425). The HEERF program contains two portions: the Student Aid portion (Assistance Listing No. 84.425E) and the Institutional portion, which is made up of the following: HEERF Institutional Aid Portion (Assistance Listing No. 84.425F), HEERF Minority Serving Institutions (Assistance Listing No. 84.425L), HEERF Strengthening Institutions Program (Assistance Listing No. 84.425M), Institutional Resilience and Expanded Postsecondary Opportunity (Assistance Listing No. 84.425P), and HEERF Supplemental Assistance to Institutions of Higher Education program (Assistance Listing No. 84.425S). Amounts provided to students through HEERF are considered to be ?Emergency Financial Aid Grants to Students? under the Program. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent approximately $97.8 million for the HEERF program Student Aid portion which is used to award Emergency Financial Aid Grants to students and $113.9 million for the HEERF Institutional Portion, which is used to support the colleges. $117.3 of this amount was expended by the System during Fiscal Year 2022. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the ED to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The annual report is to be submitted directly to the ED. The ED has specified certain criteria that must be included in each report. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over, and complied with, the HEERF Institutional and Student Aid grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 25 of the 117 HEERF reports submitted by the System?s campuses during Fiscal Year 2022 to determine whether the reports were posted on each campus? primary website (quarterly reports) or submitted to ED (annual reports) by the federal due dates. Furthermore, for the Student Aid Quarterly Report we requested from each Campus the underlying support for the reports, which consisted of student data detailing how much aid was awarded and the methods the campuses used to determine which students would receive Emergency Financial Aid Grants. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? On May 13, 2021, the ED published in the Federal Register a notice for student aid public reporting under CRRSAA and ARP, which requires that institutions publicly post certain information on their website. The following information must appear in a format and location that is easily accessible to the public: o An acknowledgement that the institution signed and returned to the ED the Certification and Agreement and the assurance that the institution has used the applicable amount of funds designated under the CRRSAA and ARP programs to provide Emergency Financial Aid Grants to Students. o The total amount of funds that the institution will receive or has received from the ED pursuant to the institution's Certification and Agreement for Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total amount of Emergency Financial Aid Grants distributed to students under the CRRSAA and ARP programs as of the date of submission (i.e., as of the initial report and every calendar quarter thereafter). o The estimated total number of students at the institution that are eligible to receive Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total number of students who have received an Emergency Financial Aid Grant to students under the CRRSAA and ARP programs. o The method(s) used by the institution to determine which students receive Emergency Financial Aid Grants and how much they would receive under the CRRSAA and ARP programs. o Any instructions, directions, or guidance provided by the institution to students concerning the Emergency Financial Aid Grants. ? Federal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that federal reports are accurate and report complete information. Appropriate supporting documentation is evidence of such internal controls. What problems did the audit work identify? We identified issues with 5 of the 25 Fiscal Year 2022 reports we tested (20 percent). Specifically, Front Range Community College (FRCC), Pueblo Community College (PCC), and Lamar Community College (LCC) could not provide appropriate supporting documentation for one or more of the following data elements in five of the Student Aid Quarterly Reports: student data detailing (a) the total amount of Emergency Financial Aid Grants distributed to students, (b) the total number of students eligible to receive Emergency Financial Aid Grants and/or (c) the total number of students at the institution who have received an Emergency Financial Aid Grant. The specific issues we found the following: ? FRCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended September 30, 2021 as 20,684; based on our review, we determined the supported number was 20,782. ? FRCC reported the total number of students at the institution who have received an Emergency Financial Aid Grant for the quarter ended June 30, 2022 as 20,385 (student portion) and 3,207 (institutional portion); based on our review, we determined the supported numbers were 20,401 and 3,222, respectively. ? LCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended June 30, 2022 as 1,007; based on our review, we determined the supported number was 1,034. In addition, the amount disbursed directly to student emergency financial aid grants to date was reported as 961 and total for all HEERF funds was 1,124; based on our review, we determined the supported numbers were 988 and 1,151, respectively. ? PCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarters ending September 30, 2021 and December 31, 2021 as 3,191; based on our review, we determined this amount could not be supported and PCC did not provide a revised count. Why did these problems occur? FRCC, PCC, and LCC campuses did not have procedures in place to ensure that supporting documentation was maintained for its Student Aid Quarterly Reporting. Employee turnover in the FRCC Controller position and FRCC, PCC, and LCC Student Financial Aid Director positions further contributed to FRCC, PCC, and LCC?s inability to locate or recreate the supporting documentation. Why do these problems matter? It is important for FRCC, PCC, and LCC to ensure that they obtain and maintain appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining FRCC, PCC, and LCC?s compliance with specific federal program requirements. This issue could lead to inaccurate federal reporting and potential noncompliance, which could result in the federal government requiring FRCC, PCC, and LCC to return funds or a negative impact to the System?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-059 Front Range Community College, Lamar Community College, and Pueblo Community College campuses should strengthen their internal controls over federal reporting and ensure they comply with the Higher Education Emergency Relief Fund reporting requirements by reviewing reports for accuracy and developing procedures for ensuring the required maintenance of all related supporting documentation. Response Front Range Community College Agree Implementation Date: September 2022 Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Response Lamar Community College Agree Implementation Date: July 2022 The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Response Pueblo Community College Agree Implementation Date: October 2022 Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.
Front Range: Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Lamar: The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Pueblo: Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.
Finding 2022-060 Internal Controls and Compliance Over Student Financial Aid Cluster?Compliance Enrollment Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Title IV Student Financial Aid funds to report enrollment information within specified timeframes to the USDE through its central database for student aid, the National Student Loan Data System (NSLDS). Enrollment reporting, including submission of student roster files and enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Colorado School of Mines submits student roster files to NSLDS via a third-party servicer, the National Student Clearinghouse (Clearinghouse), which is then uploaded by the Clearinghouse directly to NSLDS. The School?s Registrars? Office compiles the roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Title IV aid at the School. The School performs an initial review of participating students? enrollment information during the census, which is typically during the second week of the semester, for reporting to NSLDS. After the census date each month, Registrar?s Office staff prepare student roster files of enrollment status through a manual comparison of applicable students? enrollment status at the census date to the current enrollment status per the School?s reporting system. During Fiscal Year 2022, the Colorado School of Mines issued approximately $38.5 million in federal Student Financial Aid to its enrolled students during the year, which included approximately $3.4 million and $35.1 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the School had adequate internal controls over and complied with enrollment reporting requirements regarding student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2022. Another purpose of our audit work was to determine the School?s progress in implementing our Fiscal Year 2021 audit recommendation related to Student Financial Aid enrollment reporting requirements. At that time, we recommended that the School implement a review process that ensures the date of the student enrollment change included in NSLDS student roster files agrees to the School?s records. As part of our Fiscal Year 2022 testwork, we reviewed a random sample of 40 students whose attendance information was required to be reported to NSLDS during Fiscal Year 2022. For each student in our sample, we compared information within the School?s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal from the institution or a change in enrolled credit hours, to determine if the information was reported accurately and within federal timeliness requirements. How were the results of the audit work measured? Under the federal Pell Grant and Direct Loan program requirements [34 CFR 690.83(b)(2) and 685.309], an institution must report any enrollment status changes, including the date of the change, per the institution?s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student?s enrollment status to NSLDS when there is a (a) reduction or increase in the student?s attendance levels, (b) graduation, (c) withdrawal, and/or (d) student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against a 60-day timeframe of submitted roster files. What problem did the audit work identify? We found that the School had not reported status changes to NSLDS for 2 the 40 (5 percent) students we tested. Specifically, the status changes should have been submitted on March 7, 2022 and April 12, 2022, respectively, but had not been submitted by June 30, 2022, the end of Fiscal Year 2022. As of the end of the audit testing in August 2022, the School had submitted these status changes. Why did this problem occur? The School did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Aid program. Specifically, we found that the School did not implement the prior year recommendation and that it did not have a review process that ensures all students with an enrollment status change noted in the School?s reporting system are submitted to NSLDS within the 60-day requirement. For one case, Student Financial Aid Office staff indicated that they missed the student in their review process due to turnover, and in the other case, there was a mix up with the student?s social security number that resulted in the status change not being reported. Why does this problem matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the School fails to meet the required reporting timelines, the borrower?s repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-060 The Colorado School of Mines should strengthen its internal controls over reporting Student Financial Aid Pell Grants and Direct Loan Program student enrollment to the National Student Loan Data System (NSLDS) by implementing a review process over all student enrollment changes in the School?s reporting system to ensure the changes are submitted to NSLDS within 60-days of the enrollment change, as required by federal regulations. Response Colorado School of Mines Agree Implementation Date: October 31, 2022 Mines was delayed in processing NSLDS files due to staffing changes and employee leave. Mines has constructed a process to ensure timely future reporting along with an agreed upon trained back-up for the primary person if they are out for an extended time. Additionally, we have changed how often we report enrollment files to the Clearinghouse (NSC). We are now reporting every two weeks. The error reports generated after the files are submitted are reviewed as soon as they?re posted, a copy downloaded from NSC and reviewed for corrections which are then completed as soon as possible. Mines is working on an updating the documentation for the full process, including all of the cleanup reports that are run in COGNOS and the Banner jobs before the enrollment file is even processed.
Show full finding ▾Hide full finding ▴Finding 2022-060 Internal Controls and Compliance Over Student Financial Aid Cluster?Compliance Enrollment Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Title IV Student Financial Aid funds to report enrollment information within specified timeframes to the USDE through its central database for student aid, the National Student Loan Data System (NSLDS). Enrollment reporting, including submission of student roster files and enrollment status changes, assists the federal government in managing the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Colorado School of Mines submits student roster files to NSLDS via a third-party servicer, the National Student Clearinghouse (Clearinghouse), which is then uploaded by the Clearinghouse directly to NSLDS. The School?s Registrars? Office compiles the roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Title IV aid at the School. The School performs an initial review of participating students? enrollment information during the census, which is typically during the second week of the semester, for reporting to NSLDS. After the census date each month, Registrar?s Office staff prepare student roster files of enrollment status through a manual comparison of applicable students? enrollment status at the census date to the current enrollment status per the School?s reporting system. During Fiscal Year 2022, the Colorado School of Mines issued approximately $38.5 million in federal Student Financial Aid to its enrolled students during the year, which included approximately $3.4 million and $35.1 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the School had adequate internal controls over and complied with enrollment reporting requirements regarding student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2022. Another purpose of our audit work was to determine the School?s progress in implementing our Fiscal Year 2021 audit recommendation related to Student Financial Aid enrollment reporting requirements. At that time, we recommended that the School implement a review process that ensures the date of the student enrollment change included in NSLDS student roster files agrees to the School?s records. As part of our Fiscal Year 2022 testwork, we reviewed a random sample of 40 students whose attendance information was required to be reported to NSLDS during Fiscal Year 2022. For each student in our sample, we compared information within the School?s Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal from the institution or a change in enrolled credit hours, to determine if the information was reported accurately and within federal timeliness requirements. How were the results of the audit work measured? Under the federal Pell Grant and Direct Loan program requirements [34 CFR 690.83(b)(2) and 685.309], an institution must report any enrollment status changes, including the date of the change, per the institution?s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student?s enrollment status to NSLDS when there is a (a) reduction or increase in the student?s attendance levels, (b) graduation, (c) withdrawal, and/or (d) student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against a 60-day timeframe of submitted roster files. What problem did the audit work identify? We found that the School had not reported status changes to NSLDS for 2 the 40 (5 percent) students we tested. Specifically, the status changes should have been submitted on March 7, 2022 and April 12, 2022, respectively, but had not been submitted by June 30, 2022, the end of Fiscal Year 2022. As of the end of the audit testing in August 2022, the School had submitted these status changes. Why did this problem occur? The School did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Aid program. Specifically, we found that the School did not implement the prior year recommendation and that it did not have a review process that ensures all students with an enrollment status change noted in the School?s reporting system are submitted to NSLDS within the 60-day requirement. For one case, Student Financial Aid Office staff indicated that they missed the student in their review process due to turnover, and in the other case, there was a mix up with the student?s social security number that resulted in the status change not being reported. Why does this problem matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the School fails to meet the required reporting timelines, the borrower?s repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-060 The Colorado School of Mines should strengthen its internal controls over reporting Student Financial Aid Pell Grants and Direct Loan Program student enrollment to the National Student Loan Data System (NSLDS) by implementing a review process over all student enrollment changes in the School?s reporting system to ensure the changes are submitted to NSLDS within 60-days of the enrollment change, as required by federal regulations. Response Colorado School of Mines Agree Implementation Date: October 31, 2022 Mines was delayed in processing NSLDS files due to staffing changes and employee leave. Mines has constructed a process to ensure timely future reporting along with an agreed upon trained back-up for the primary person if they are out for an extended time. Additionally, we have changed how often we report enrollment files to the Clearinghouse (NSC). We are now reporting every two weeks. The error reports generated after the files are submitted are reviewed as soon as they?re posted, a copy downloaded from NSC and reviewed for corrections which are then completed as soon as possible. Mines is working on an updating the documentation for the full process, including all of the cleanup reports that are run in COGNOS and the Banner jobs before the enrollment file is even processed.
Mines was delayed in processing NSLDS files due to staffing changes and employee leave. Mines has constructed a process to ensure timely future reporting along with an agreed upon trained back-up for the primary person if they are out for an extended time. Additionally, we have changed how often we report enrollment files to the Clearinghouse (NSC). We are now reporting every two weeks. The error reports generated after the files are submitted are reviewed as soon as they?re posted, a copy downloaded from NSC and reviewed for corrections which are then completed as soon as possible. Mines is working on an updating the documentation for the full process, including all of the cleanup reports that are run in COGNOS and the Banner jobs before the enrollment file is even processed.
2021-058
Finding 2022-061 Internal Controls and Compliance Over Research and Development Cluster Period of Performance and Procurement The federal government sponsors Research and Development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal grantee entity. The types of R&D conducted under these awards vary greatly. The objective of an individual project is explained in the federal award. R&D activities at the Colorado School of Mines are subject to federal period of performance and procurement requirements. Period of performance is the time in which the School may incur new obligations to carry out the work authorized by the federal award. Procurement is the process that the School follows to purchase goods and services. The School has established a process to review expenditures charged to federal awards during the federal award?s period of performance period to ensure that any costs incurred outside of the allowable timeframe are reversed out and not charged to the federal award. Per the Colorado School of Mines policies and procedures, the School pre-audits travel, equipment, personal disbursements, and participant support expenses prior to recording the transaction to ensure allowability of the expense. The School also post-audits salary, fringe benefits, tuition, and credit card expenses to ensure allowability. The School?s procurement process includes a policy that establishes levels of approval for purchase orders (PO) based on the dollar amount of the PO. Based on the dollar amount of the PO, the School will also attach the vendor contract to the PO. The School?s Controller?s Office sends the contracts with the attached PO to the assigned individual for signature and approval. During Fiscal Year 2022, the School expended approximately $65 million in federal R&D grant funds. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the School had adequate internal controls in place over, and complied with, the Procurement and Period of Performance requirements within the R&D Cluster during Fiscal Year 2022. Period of Performance. We reviewed a random sample of 40 costs that were incurred prior to or within the first month of the grant start date to determine whether the School only charged the allowable cost to a federal award during the period of performance. Procurement. We reviewed a random sample of 16 procurement transactions that were over the micro-purchase threshold of $10,000 to determine whether School staff complied with the School?s internal procurement policy. All transactions over the micro-purchase threshold are subject to the procurement policy approval thresholds. We also compared the original PO issued against the School?s procurement policy to determine if the appropriate approval was obtained. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [2 CFR 200.303(a)] states that a non-federal entity should establish and maintain effective internal control over Federal awards that provide reasonable assurance that non-federal entities are managing Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of Federal awards. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework,? issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). As a part of maintaining internal controls, the School should maintain evidence of such controls occurring to show that the School Mines has internal controls in place as required by the Uniform Guidance and that it is evaluating and monitoring its compliance with Federal statutes, regulations, and the terms and conditions of Federal awards. ? Federal regulations [2 CFR 200.77 and 2 CFR 200.458] state that a non-Federal entity may only charge allowable costs to a federal award during the period of performance. According to the grant agreement, pre-award costs may be charged up to 90 days prior to the start date. Therefore, the pre-award cost period for the School?s R&D grant for Federal Fiscal Year 2022 began on October 19, 2021. ? Federal regulation [2 CFR 200.318] states that the School must document procurement procedures. The Schools procurement policy provides approval limits for purchase orders. According to this policy, certain individuals can approve POs up to $500,000, and others can approve POs up to $5 million. What problems did the audit work identify? During our Fiscal Year 2022 audit, we identified exceptions with period of performance and procurement requirements for the R&D grant. Specifically, we identified the following issues: Period of Performance. We found that the School incurred expenses prior to the period of performance start date related to 2 of the 40 disbursements (5 percent) tested. Specifically, School spent $2,593 between October 1, 2021 and October 16, 2021, or 3 to 18 days before the allowable period. Procurement. We found that the School did not obtain the appropriate approval for 1 of the 16 (6 percent) transactions tested. Specifically, the individual who signed the PO for $706,660 only had authority to sign PO?s up to a threshold of $ $500,000, which was $206,660 less than the amount of the PO. Why did these problems occur? The School did not have adequate internal controls over period of performance and procurement requirements for its R&D grant during Fiscal Year 2022. Specifically: Period of Performance. The School?s reviewer misunderstood the period of performance requirements related to the transaction and related federal award. Specifically, according to the School, the reviewer confused the period of performance start date of October 19, 2021 with the payroll period of October 1, 2021 through October 15, 2021, which was prior to the period of performance start date and resulted in the expenditures erroneously being charged to the grant. Procurement. We found that there was inconsistency with the Schools internal process and its published procurement policy regarding the approval process for POs. Specifically, the verbally approved internal process allowed the individual we noted as an exception to approve POs up to $2.5 million; however, this had not been updated in the published procurement policy. Why do these problems matter? By charging expenditures to federal awards outside of the period of performance, the School is not complying with the requirements of the federal awards. In addition, by not obtaining documented evidence of approval from the appropriate individuals, the School is not complying with its internal procurement procedures. This could result in procuring a service or product for an unreasonable amount and there is an increased risk of fictitious or fraudulent POs if the charge does not align with the Schools mission. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-061 The Colorado School of Mines should strengthen its internal controls over and ensure it complies with period of performance and procurement requirements for its Research and Development (R&D) grants by: A. Instituting an appropriate review of expenditures to ensure they are within the period of performance for the federal award, and ensuring that staff have an appropriate understanding of the related period of performance requirements or obtain clarification from the federal grantor, as appropriate. B. Updating its published procurement policy to ensure it contains the current approval process and thresholds. Response Colorado School of Mines A. Agree Implementation Date: July 1, 2022 Colorado School of Mines will ensure appropriate reviews of expenditures occur to ensure they are within the period of performance for the federal award, and ensure that staff have an appropriate understanding of the related period of performance requirements or obtain clarification from the federal grantor, as appropriate. B. Agree Implementation Date: June 30, 2023 Mines did not update published Procurement Policies specific to approval limits by position to accurately reflect the delegated approval authority. Mines will update the published policies to accurately reflect delegated approval limits and review the procurement approval process.
Show full finding ▾Hide full finding ▴Finding 2022-061 Internal Controls and Compliance Over Research and Development Cluster Period of Performance and Procurement The federal government sponsors Research and Development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal grantee entity. The types of R&D conducted under these awards vary greatly. The objective of an individual project is explained in the federal award. R&D activities at the Colorado School of Mines are subject to federal period of performance and procurement requirements. Period of performance is the time in which the School may incur new obligations to carry out the work authorized by the federal award. Procurement is the process that the School follows to purchase goods and services. The School has established a process to review expenditures charged to federal awards during the federal award?s period of performance period to ensure that any costs incurred outside of the allowable timeframe are reversed out and not charged to the federal award. Per the Colorado School of Mines policies and procedures, the School pre-audits travel, equipment, personal disbursements, and participant support expenses prior to recording the transaction to ensure allowability of the expense. The School also post-audits salary, fringe benefits, tuition, and credit card expenses to ensure allowability. The School?s procurement process includes a policy that establishes levels of approval for purchase orders (PO) based on the dollar amount of the PO. Based on the dollar amount of the PO, the School will also attach the vendor contract to the PO. The School?s Controller?s Office sends the contracts with the attached PO to the assigned individual for signature and approval. During Fiscal Year 2022, the School expended approximately $65 million in federal R&D grant funds. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the School had adequate internal controls in place over, and complied with, the Procurement and Period of Performance requirements within the R&D Cluster during Fiscal Year 2022. Period of Performance. We reviewed a random sample of 40 costs that were incurred prior to or within the first month of the grant start date to determine whether the School only charged the allowable cost to a federal award during the period of performance. Procurement. We reviewed a random sample of 16 procurement transactions that were over the micro-purchase threshold of $10,000 to determine whether School staff complied with the School?s internal procurement policy. All transactions over the micro-purchase threshold are subject to the procurement policy approval thresholds. We also compared the original PO issued against the School?s procurement policy to determine if the appropriate approval was obtained. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [2 CFR 200.303(a)] states that a non-federal entity should establish and maintain effective internal control over Federal awards that provide reasonable assurance that non-federal entities are managing Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of Federal awards. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework,? issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). As a part of maintaining internal controls, the School should maintain evidence of such controls occurring to show that the School Mines has internal controls in place as required by the Uniform Guidance and that it is evaluating and monitoring its compliance with Federal statutes, regulations, and the terms and conditions of Federal awards. ? Federal regulations [2 CFR 200.77 and 2 CFR 200.458] state that a non-Federal entity may only charge allowable costs to a federal award during the period of performance. According to the grant agreement, pre-award costs may be charged up to 90 days prior to the start date. Therefore, the pre-award cost period for the School?s R&D grant for Federal Fiscal Year 2022 began on October 19, 2021. ? Federal regulation [2 CFR 200.318] states that the School must document procurement procedures. The Schools procurement policy provides approval limits for purchase orders. According to this policy, certain individuals can approve POs up to $500,000, and others can approve POs up to $5 million. What problems did the audit work identify? During our Fiscal Year 2022 audit, we identified exceptions with period of performance and procurement requirements for the R&D grant. Specifically, we identified the following issues: Period of Performance. We found that the School incurred expenses prior to the period of performance start date related to 2 of the 40 disbursements (5 percent) tested. Specifically, School spent $2,593 between October 1, 2021 and October 16, 2021, or 3 to 18 days before the allowable period. Procurement. We found that the School did not obtain the appropriate approval for 1 of the 16 (6 percent) transactions tested. Specifically, the individual who signed the PO for $706,660 only had authority to sign PO?s up to a threshold of $ $500,000, which was $206,660 less than the amount of the PO. Why did these problems occur? The School did not have adequate internal controls over period of performance and procurement requirements for its R&D grant during Fiscal Year 2022. Specifically: Period of Performance. The School?s reviewer misunderstood the period of performance requirements related to the transaction and related federal award. Specifically, according to the School, the reviewer confused the period of performance start date of October 19, 2021 with the payroll period of October 1, 2021 through October 15, 2021, which was prior to the period of performance start date and resulted in the expenditures erroneously being charged to the grant. Procurement. We found that there was inconsistency with the Schools internal process and its published procurement policy regarding the approval process for POs. Specifically, the verbally approved internal process allowed the individual we noted as an exception to approve POs up to $2.5 million; however, this had not been updated in the published procurement policy. Why do these problems matter? By charging expenditures to federal awards outside of the period of performance, the School is not complying with the requirements of the federal awards. In addition, by not obtaining documented evidence of approval from the appropriate individuals, the School is not complying with its internal procurement procedures. This could result in procuring a service or product for an unreasonable amount and there is an increased risk of fictitious or fraudulent POs if the charge does not align with the Schools mission. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-061 The Colorado School of Mines should strengthen its internal controls over and ensure it complies with period of performance and procurement requirements for its Research and Development (R&D) grants by: A. Instituting an appropriate review of expenditures to ensure they are within the period of performance for the federal award, and ensuring that staff have an appropriate understanding of the related period of performance requirements or obtain clarification from the federal grantor, as appropriate. B. Updating its published procurement policy to ensure it contains the current approval process and thresholds. Response Colorado School of Mines A. Agree Implementation Date: July 1, 2022 Colorado School of Mines will ensure appropriate reviews of expenditures occur to ensure they are within the period of performance for the federal award, and ensure that staff have an appropriate understanding of the related period of performance requirements or obtain clarification from the federal grantor, as appropriate. B. Agree Implementation Date: June 30, 2023 Mines did not update published Procurement Policies specific to approval limits by position to accurately reflect the delegated approval authority. Mines will update the published policies to accurately reflect delegated approval limits and review the procurement approval process.
(A) Colorado School of Mines will ensure appropriate reviews of expenditures occur to ensure they are within the period of performance for the federal award, and ensure that staff have an appropriate understanding of the related period of performance requirements or obtain clarification from the federal grantor, as appropriate. (B) Mines did not update published Procurement Policies specific to approval limits by position to accurately reflect the delegated approval authority. Mines will update the published policies to accurately reflect delegated approval limits and review the procurement approval process.
Finding 2022-062 Higher Education Emergency Relief Fund Student Aid Finding The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to higher education institutions, including the University, under the HEERF program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA) was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. Since March 11, 2021, the University has been awarded $45.6 million in HEERF grant funds through the American Rescue Plan (ARP), otherwise known as HEERF III. Of this award, the University was provided both 1) Student Aid monies, along with 2) Institutional Aid monies. Student Aid monies must be used to provide financial aid grants to students (including students exclusively enrolled in distance education), which may be used for ?any component of the student?s cost of attendance or for emergency costs that arise due to coronavirus, such as tuition, food, housing, healthcare (including mental health care), or childcare. Institutional Aid monies may be used to defray expenses associated with coronavirus (including lost revenue, reimbursement for expenses already incurred, technology costs associated with a transition to distance education, faculty and staff trainings, and payroll) and to make additional financial grants to students. During Fiscal Year 2022, the University spent $21.0 million for the Student Aid portion and $20.2 million for the Institutional portion of HEERF III funds. For the Student Aid portion of the HEERF III funding, the University divided the funding into different groups. The University developed a written plan (that applied during Fiscal Year 2022) for each group and a control process for awarding the monies to students. One of the groups of funding was to be awarded to students with unpaid balances in their tuition or auxiliary accounts with past due balances incurred during the 2020-2021 or 2021-2022 academic years. A team of University employees (CARES Team) was tasked with identifying those students, then contacting those students and asking if they would like the University to apply the student?s HEERF award to pay down the student?s account balance or pay it to the student directly. Once the student informed the University of their election, then the University awarded and disbursed the funds. What was the purpose of our audit work and what was performed? The purpose of the audit work was to determine whether the University was in compliance with the HEERF program regulations for awarding and paying the Student Aid portion of the HEERF funding, and whether proper controls were in place over the program during Fiscal Year 2022. Our testing included conducting interviews with management and selecting a sample of 60 disbursements made to students during Fiscal Year 2022 to test controls and compliance. We performed testing on the 60 disbursements to determine whether awards and disbursements were made in accordance with the University?s documented plan. How were the results of the audit work measured? In accordance with HEERF III requirements, the University must prioritize student aid distributions to students with exceptional needs. In addition, the University must have a documented plan to distribute funds to students. Federal regulations [2 CFR 200.303] require any non-federal grant award recipient to establish and maintain effective internal control over the federal award that provides reasonable assurance that the grant award recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. Lastly, student aid application best practices discourage employees from awarding aid to family members. What problem did the audit work identify? Based on interviews with University management, the University identified that a University employee inappropriately provided $700 in HEERF Student Aid funding to the employee?s family member who was a student at the University but was not eligible to receive the funds. Specifically, the CARES Team selected students to receive these funds that met the following criteria: 1) Student was enrolled in the Fall of 2021 or Spring 2022, 2) student had past due balances incurred during the 2020-2021 or 2021-2022 academic years, 3) the student was in good academic standing, and 4) they were participating in a payment plan or in the College Completion Advising program. The student was not selected by the CARES Team as eligible to receive these funds. During our testing of additional 60 student disbursement transactions we found no other exceptions. Why did this problem occur? The University has not established proper segregation of duties to prevent University employees from awarding federal funding to a member of their family. Specifically, the employee had access rights within the University?s financial aid system that granted the employee the ability to both award and disburse federal funds without another employee reviewing or approving. In addition, the University did not have a written policy, as recommended by industry best practices, that prohibits employees from applying aid to family members? accounts. Why does this problem matter? Federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the University to the federal granting agency. Without ensuring adequate segregation of duties within the University?s financial aid system for awarding and disbursing federal funds, the University increases the risk that fraud could occur. In the instance identified, the University recovered the funding from the student. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-062 Metropolitan State University of Denver (University) should improve its internal controls over federal Higher Education Emergency Relief Funds by instituting appropriate segregation of duties over the awarding of federal funds to students. This should include requiring that no one employee can both award then disburse aid to students and developing and implementing a formal written policy that prohibits University employees from awarding financial aid to their family members. Response Metropolitan State University Agree Implementation Date: June 2023 In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
Show full finding ▾Hide full finding ▴Finding 2022-062 Higher Education Emergency Relief Fund Student Aid Finding The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to higher education institutions, including the University, under the HEERF program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA) was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. Since March 11, 2021, the University has been awarded $45.6 million in HEERF grant funds through the American Rescue Plan (ARP), otherwise known as HEERF III. Of this award, the University was provided both 1) Student Aid monies, along with 2) Institutional Aid monies. Student Aid monies must be used to provide financial aid grants to students (including students exclusively enrolled in distance education), which may be used for ?any component of the student?s cost of attendance or for emergency costs that arise due to coronavirus, such as tuition, food, housing, healthcare (including mental health care), or childcare. Institutional Aid monies may be used to defray expenses associated with coronavirus (including lost revenue, reimbursement for expenses already incurred, technology costs associated with a transition to distance education, faculty and staff trainings, and payroll) and to make additional financial grants to students. During Fiscal Year 2022, the University spent $21.0 million for the Student Aid portion and $20.2 million for the Institutional portion of HEERF III funds. For the Student Aid portion of the HEERF III funding, the University divided the funding into different groups. The University developed a written plan (that applied during Fiscal Year 2022) for each group and a control process for awarding the monies to students. One of the groups of funding was to be awarded to students with unpaid balances in their tuition or auxiliary accounts with past due balances incurred during the 2020-2021 or 2021-2022 academic years. A team of University employees (CARES Team) was tasked with identifying those students, then contacting those students and asking if they would like the University to apply the student?s HEERF award to pay down the student?s account balance or pay it to the student directly. Once the student informed the University of their election, then the University awarded and disbursed the funds. What was the purpose of our audit work and what was performed? The purpose of the audit work was to determine whether the University was in compliance with the HEERF program regulations for awarding and paying the Student Aid portion of the HEERF funding, and whether proper controls were in place over the program during Fiscal Year 2022. Our testing included conducting interviews with management and selecting a sample of 60 disbursements made to students during Fiscal Year 2022 to test controls and compliance. We performed testing on the 60 disbursements to determine whether awards and disbursements were made in accordance with the University?s documented plan. How were the results of the audit work measured? In accordance with HEERF III requirements, the University must prioritize student aid distributions to students with exceptional needs. In addition, the University must have a documented plan to distribute funds to students. Federal regulations [2 CFR 200.303] require any non-federal grant award recipient to establish and maintain effective internal control over the federal award that provides reasonable assurance that the grant award recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. Lastly, student aid application best practices discourage employees from awarding aid to family members. What problem did the audit work identify? Based on interviews with University management, the University identified that a University employee inappropriately provided $700 in HEERF Student Aid funding to the employee?s family member who was a student at the University but was not eligible to receive the funds. Specifically, the CARES Team selected students to receive these funds that met the following criteria: 1) Student was enrolled in the Fall of 2021 or Spring 2022, 2) student had past due balances incurred during the 2020-2021 or 2021-2022 academic years, 3) the student was in good academic standing, and 4) they were participating in a payment plan or in the College Completion Advising program. The student was not selected by the CARES Team as eligible to receive these funds. During our testing of additional 60 student disbursement transactions we found no other exceptions. Why did this problem occur? The University has not established proper segregation of duties to prevent University employees from awarding federal funding to a member of their family. Specifically, the employee had access rights within the University?s financial aid system that granted the employee the ability to both award and disburse federal funds without another employee reviewing or approving. In addition, the University did not have a written policy, as recommended by industry best practices, that prohibits employees from applying aid to family members? accounts. Why does this problem matter? Federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the University to the federal granting agency. Without ensuring adequate segregation of duties within the University?s financial aid system for awarding and disbursing federal funds, the University increases the risk that fraud could occur. In the instance identified, the University recovered the funding from the student. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-062 Metropolitan State University of Denver (University) should improve its internal controls over federal Higher Education Emergency Relief Funds by instituting appropriate segregation of duties over the awarding of federal funds to students. This should include requiring that no one employee can both award then disburse aid to students and developing and implementing a formal written policy that prohibits University employees from awarding financial aid to their family members. Response Metropolitan State University Agree Implementation Date: June 2023 In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
Finding 2022-063 Higher Education Emergency Relief Fund Reporting Compliance Finding The CARES Act was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the (HEERF Program. CRRSAA was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the University has been awarded a total of $86.3 million in HEERF funding. From inception through June 30, 2022, the University spent $35.4 million for the HEERF program Student Aid Portion and $48.9 million for the HEERF program Institutional Portion. The University reports that it will spend the remaining amount of funding during Fiscal Year 2023. The University signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate the University?s acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the federal ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the University?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 5 of the 8 HEERF reports submitted by the University during Fiscal Year 2022 to determine whether the reports were posted on the University?s primary website or submitted directly to the ED by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after the award date, and to update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA require an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the University, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The University signed a HEERF Certification and Agreement to accept the funding and acknowledge its responsibilities under the grant; therefore, the University was responsible under the Agreement to ensure that it complied with HEERF reporting and other requirements. What problems did the audit work identify? We determined that 2 out of 5 reports tested (40 percent) did not meet the HEERF grant report posting requirements. Specifically: ? The University did not post the HEERF CRRSAA Student quarterly report for the quarter ending September 30, 2021 on the University?s primary website, as required. ? The University published the HEERF ARP Student quarterly report for the quarter ending March 31, 2022 on May 26, 2022?46 days past the due date of April 10, 2022. No issues were noted on the accuracy of the financial information on this report. Why did these problems occur? The University did not implement adequate internal controls to ensure it complied with the HEERF grant reporting requirements. Specifically, the University did not have appropriate policies and procedures in place to ensure that staff submit the required reports within federally required timeframes. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-063 Metropolitan State University of Denver (University) should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing and documenting policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the University?s website the required reports within federally required timeframes. In addition, the University should ensure that all the HEERF reports that are currently required to be posted are on the website. Response Metropolitan State University Agree Implementation Date: December 2022 In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
Show full finding ▾Hide full finding ▴Finding 2022-063 Higher Education Emergency Relief Fund Reporting Compliance Finding The CARES Act was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the (HEERF Program. CRRSAA was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the University has been awarded a total of $86.3 million in HEERF funding. From inception through June 30, 2022, the University spent $35.4 million for the HEERF program Student Aid Portion and $48.9 million for the HEERF program Institutional Portion. The University reports that it will spend the remaining amount of funding during Fiscal Year 2023. The University signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate the University?s acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the federal ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the University?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 5 of the 8 HEERF reports submitted by the University during Fiscal Year 2022 to determine whether the reports were posted on the University?s primary website or submitted directly to the ED by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after the award date, and to update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA require an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the University, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The University signed a HEERF Certification and Agreement to accept the funding and acknowledge its responsibilities under the grant; therefore, the University was responsible under the Agreement to ensure that it complied with HEERF reporting and other requirements. What problems did the audit work identify? We determined that 2 out of 5 reports tested (40 percent) did not meet the HEERF grant report posting requirements. Specifically: ? The University did not post the HEERF CRRSAA Student quarterly report for the quarter ending September 30, 2021 on the University?s primary website, as required. ? The University published the HEERF ARP Student quarterly report for the quarter ending March 31, 2022 on May 26, 2022?46 days past the due date of April 10, 2022. No issues were noted on the accuracy of the financial information on this report. Why did these problems occur? The University did not implement adequate internal controls to ensure it complied with the HEERF grant reporting requirements. Specifically, the University did not have appropriate policies and procedures in place to ensure that staff submit the required reports within federally required timeframes. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-063 Metropolitan State University of Denver (University) should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing and documenting policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the University?s website the required reports within federally required timeframes. In addition, the University should ensure that all the HEERF reports that are currently required to be posted are on the website. Response Metropolitan State University Agree Implementation Date: December 2022 In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
Finding 2022-064 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide emergency financial assistance to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF I) Program. The federal Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the federal American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Each of the University?s campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (DOE) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements of the HEERF program there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The DOE specified that the Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The University?s campuses are required to submit the annual report directly to the DOE. During Fiscal Year 2022, each University campus was required to complete and post 8 reports (four Student Aid and four Institutional) to their website. During Fiscal Year 2022, the University?s three campuses in total expended approximately $60 million in HEERF grant funds: $27 million was expended by the Boulder campus, $10.5 million was expended by the Colorado Springs campus, and $22.5 million was expended by the Denver campus. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over and complied with the HEERF grant reporting requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls over the HEERF grant reporting requirements. In addition, we tested 11 of the 12 student reports and 3 of the 12 institutional reports posted by the University during Fiscal Year 2022 to determine whether the University campuses posted the required information on each campus? website accurately, and by the federal due dates. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? The DOE issued a notice on May 13, 2021, requiring institutions to publicly post their required HEERF reports on the institution?s website as soon as possible, but no later than 30 days after the publication of the notice, or 30 days after the date the DOE first obligated funds under HEERF I, II, or III to the institution for emergency financial assistance to students; whichever comes later. The institution is required to post the report no later than 10 days after the end of each calendar quarter, after the initial posting. ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problem did the audit work identify? We identified 2 out of the 14 reports tested (14.3 percent) that did not meet the HEERF grant report posting requirements. Specifically, the University of Colorado, Colorado Springs Campus, did not post the required information for the HEERF Student Aid Portion on its website for two of four quarters of Fiscal Year 2022 timely. First, the University posted the quarter-ending September 30, 2021 report to its website on December 23, 2021, or 74 days after the deadline of October 10. Second, the University did not post the quarter-ending March 31, 2022 report, which was due April 10, 2022, until October 2022, after we notified them of the error; this was approximately 6 months late. We did not identify any issues with the accuracy of the reports, and we found that the other two campuses in the University of Colorado System posted the required information on their respective websites as required by federal regulations. Why did this problem occur? The University?s Colorado Springs campus did not have adequate internal controls in place to ensure it complied with the HEERF grant reporting requirements. Specifically, the Colorado Springs Campus did not have appropriate policies and procedures in place for identifying and researching changes in HEERF reporting requirements. The federal government updated and provided a new form for HEERF reporting in September 2021 that included a section for institutional information but inadvertently excluded student information from the form. Because the form no longer required the student information, the Colorado Springs campus staff inaccurately assumed that the student information was no longer required to be reported. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in the DOE Certification and Agreement that is signed and agreed to by the University. By failing to report required information in accordance with federal regulations, the University failed to comply with the requirements of the HEERF program and potentially risks repercussions from the DOE as specified in the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-064 The University of Colorado?s Colorado Springs campus should strengthen its internal controls over and ensure that it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by establishing policies and procedures for identifying and researching changes in HEERF reporting requirements and posting reports to the campus website as required by federal regulations. Response University of Colorado Agree Implementation Date: Implemented Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting. This process has been duplicated with the annual reporting process. Before the annual report is submitted a review will be done to verify the report figures match the CU financials for the calendar year.
Show full finding ▾Hide full finding ▴Finding 2022-064 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide emergency financial assistance to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF I) Program. The federal Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the federal American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Each of the University?s campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (DOE) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements of the HEERF program there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The DOE specified that the Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The University?s campuses are required to submit the annual report directly to the DOE. During Fiscal Year 2022, each University campus was required to complete and post 8 reports (four Student Aid and four Institutional) to their website. During Fiscal Year 2022, the University?s three campuses in total expended approximately $60 million in HEERF grant funds: $27 million was expended by the Boulder campus, $10.5 million was expended by the Colorado Springs campus, and $22.5 million was expended by the Denver campus. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over and complied with the HEERF grant reporting requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls over the HEERF grant reporting requirements. In addition, we tested 11 of the 12 student reports and 3 of the 12 institutional reports posted by the University during Fiscal Year 2022 to determine whether the University campuses posted the required information on each campus? website accurately, and by the federal due dates. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? The DOE issued a notice on May 13, 2021, requiring institutions to publicly post their required HEERF reports on the institution?s website as soon as possible, but no later than 30 days after the publication of the notice, or 30 days after the date the DOE first obligated funds under HEERF I, II, or III to the institution for emergency financial assistance to students; whichever comes later. The institution is required to post the report no later than 10 days after the end of each calendar quarter, after the initial posting. ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problem did the audit work identify? We identified 2 out of the 14 reports tested (14.3 percent) that did not meet the HEERF grant report posting requirements. Specifically, the University of Colorado, Colorado Springs Campus, did not post the required information for the HEERF Student Aid Portion on its website for two of four quarters of Fiscal Year 2022 timely. First, the University posted the quarter-ending September 30, 2021 report to its website on December 23, 2021, or 74 days after the deadline of October 10. Second, the University did not post the quarter-ending March 31, 2022 report, which was due April 10, 2022, until October 2022, after we notified them of the error; this was approximately 6 months late. We did not identify any issues with the accuracy of the reports, and we found that the other two campuses in the University of Colorado System posted the required information on their respective websites as required by federal regulations. Why did this problem occur? The University?s Colorado Springs campus did not have adequate internal controls in place to ensure it complied with the HEERF grant reporting requirements. Specifically, the Colorado Springs Campus did not have appropriate policies and procedures in place for identifying and researching changes in HEERF reporting requirements. The federal government updated and provided a new form for HEERF reporting in September 2021 that included a section for institutional information but inadvertently excluded student information from the form. Because the form no longer required the student information, the Colorado Springs campus staff inaccurately assumed that the student information was no longer required to be reported. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in the DOE Certification and Agreement that is signed and agreed to by the University. By failing to report required information in accordance with federal regulations, the University failed to comply with the requirements of the HEERF program and potentially risks repercussions from the DOE as specified in the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-064 The University of Colorado?s Colorado Springs campus should strengthen its internal controls over and ensure that it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by establishing policies and procedures for identifying and researching changes in HEERF reporting requirements and posting reports to the campus website as required by federal regulations. Response University of Colorado Agree Implementation Date: Implemented Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting. This process has been duplicated with the annual reporting process. Before the annual report is submitted a review will be done to verify the report figures match the CU financials for the calendar year.
Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting.
Finding 2022-065 Research and Development Cluster Equipment Management Compliance The federal government sponsors Research and Development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal entity. The types of R&D activities conducted under these awards vary greatly. The objective of an individual project is explained in the federal award document. R&D activities at the University are subject to federal equipment management requirements. In accordance with Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), Section 201.1 Definitions, equipment is defined as tangible personal property (including information technology systems) having a useful life of more than one year and a per-unit acquisition cost which equals or exceeds the lesser of the capitalization level established by the non-Federal entity for financial statement purposes, or $5,000. The University uses equipment to meet the objective of its various research projects and this equipment may be common items such as a microscope or very complex scientific equipment, Under federal regulations, the University is required, for any equipment purchased under a federal contract, to maintain and track the equipment as to its location. The University must have an internal control structure in place in order to protect and safeguard the equipment and the University should be able to provide evidence that the equipment is safeguarded and maintained and show the location of all equipment. The Campus Controller?s Property Accounting Office (PAO) within the Boulder campus is responsible for equipment and property management. The PAO sends its full equipment listing quarterly to a portion of its individual departments with equipment, in a frequency to cover all departments within a two-year period. The individual departments are required to review the equipment listing, add any new equipment to the listing, and remove any equipment from the listing that has been disposed of or is no longer in service. Once the departments return the listings to the PAO, the PAO selects a sample to verify the information provided by the departments. The PAO selects the sample and the PAO Property Accountant then verifies the equipment?s existence by performing a site visit to the department and observing the equipment. The PAO selects a new sample each quarter. During Fiscal Year 2022, the University?s three campuses in total expended approximately $916 million in R&D grant funds: $504 million, $406 million and $6 million from the Boulder, Denver and UCCS campuses, respectively. Of that amount, the University?s three campuses expended a total of approximately $191 million for equipment purchases, with $116 million, $69.6 million, and $5.4 million being spent by the Boulder, Denver, and UCCS campuses, respectively. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over, and complied with, the R&D Cluster?s equipment management requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls related to the R&D equipment management requirements. We tested 60 items of equipment with a total value of $1.2 million to determine whether the University appropriately safeguarded and maintained equipment, as required by federal regulations. In addition, we tested 40 of the 60 items of equipment with a total value of $840,000 to determine whether the University?s campuses appropriately placed property tags on the equipment as required by University policy. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation 2 CFR 200.313(b) states that a State must use, manage and dispose of equipment acquired under a federal award to the State in accordance with the state laws and procedures. The University?s Property Control Manual section 1.3 states that the University is responsible and accountable for all property acquired with federal funding in accordance with federal regulations and the provision of a sponsored award. While under the heading of ?non-federal entities other than States,? federal regulation 2 CFR 200.313(c) through (e) also requires that equipment records be maintained, a physical inventory of equipment be taken at least once every two years and reconciled to the equipment record, an appropriate control system be used to safeguard equipment and all equipment shall be adequately maintained. ? The University?s Property Control Manual Section 3.3.1 states that ?only items having an acquisition cost of $5,000 or more are logged and tracked in the university property record.? Furthermore, the University?s Property Control Manual Section 3.3.3, states that equipment records should be updated for any changes discovered during the performance of an inventory over equipment. This would include equipment that should be removed from the listing because it was disposed of or is no longer in service. ? The University?s Property Control Manual section 3.2 states that ?All Government property at $5,000 or above in the custody of the Boulder campus must be tagged.? What problems did the audit work identify? We found that 2 of the 60 equipment items that we tested (3 percent,) with a total value of $39,400, were inappropriately included on the equipment listing even though they had either been disposed of in a prior period or were not in service. Specifically, one equipment item with an approximate value of $28,000 was no longer in service by the University, but still remained on the University?s inventory listing. The second equipment item with an approximate value of $8,400 was disposed of by the University on October 3, 2017, but was still on the list. In addition, we determined that 2 of the 40 equipment items we tested for tagging (5 percent) did not contain the tag as required by the University?s Property Control Manual. One of these items was valued at approximately $28,000. The second item was valued at approximately $31,000. Why did these problems occur? The University?s Boulder campus did not have adequate internal controls in place to ensure it complied with the R&D equipment management requirements. Specifically, although the University does have policies over equipment, Boulder campus staff were not adequately performing the procedures intrinsic in the policy. Specifically, neither the PAO nor the individual University departments adequately reconciled the equipment listing to the physical equipment on hand, which resulted in the list including equipment that had been disposed of or was no longer in use. Additionally, the Boulder Campus did not follow its own policies and procedures requiring that equipment with a value of $5,000 was appropriately tagged. One item?s tag was missing and a replacement tag had been ordered and not received at the time of our procedures. We could not determine whether the University identified that the tag was missing before we requested the information for review. The second item was below ground and the University did not maintain evidence of the original tag. Why do these problems matter? The University is obligated to adhere to specified requirements as outlined by federal regulations and the respective award agreement. By failing to adhere to the requirements for maintenance of equipment, the University potentially risks repercussions from the awarding agency. Furthermore, failing to properly maintain the equipment in accordance with federal and University requirements could increase the risk of theft or loss and decrease the ability of the University to adequately identify theft or loss. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-065 The University of Colorado?s Boulder campus should strengthen its internal controls over equipment management and ensure that it complies with the Research and Development equipment management federal compliance requirements by: A. Ensuring the Campus Controller?s Property Accounting Office and the individual departments adequately reconcile the equipment listing to the physical equipment on hand to ensure that the list is accurate, and remove equipment from the listing that has been disposed of or is no longer in use. B. Enforcing its current policies and procedures for ensuring all equipment is appropriately tagged and maintained. Response University of Colorado A. Agree Implementation Date: March 2023 Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: ? Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. ? The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment. B. Agree Implementation Date: March 2023 Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: ? Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. ? The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment.
Show full finding ▾Hide full finding ▴Finding 2022-065 Research and Development Cluster Equipment Management Compliance The federal government sponsors Research and Development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal entity. The types of R&D activities conducted under these awards vary greatly. The objective of an individual project is explained in the federal award document. R&D activities at the University are subject to federal equipment management requirements. In accordance with Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), Section 201.1 Definitions, equipment is defined as tangible personal property (including information technology systems) having a useful life of more than one year and a per-unit acquisition cost which equals or exceeds the lesser of the capitalization level established by the non-Federal entity for financial statement purposes, or $5,000. The University uses equipment to meet the objective of its various research projects and this equipment may be common items such as a microscope or very complex scientific equipment, Under federal regulations, the University is required, for any equipment purchased under a federal contract, to maintain and track the equipment as to its location. The University must have an internal control structure in place in order to protect and safeguard the equipment and the University should be able to provide evidence that the equipment is safeguarded and maintained and show the location of all equipment. The Campus Controller?s Property Accounting Office (PAO) within the Boulder campus is responsible for equipment and property management. The PAO sends its full equipment listing quarterly to a portion of its individual departments with equipment, in a frequency to cover all departments within a two-year period. The individual departments are required to review the equipment listing, add any new equipment to the listing, and remove any equipment from the listing that has been disposed of or is no longer in service. Once the departments return the listings to the PAO, the PAO selects a sample to verify the information provided by the departments. The PAO selects the sample and the PAO Property Accountant then verifies the equipment?s existence by performing a site visit to the department and observing the equipment. The PAO selects a new sample each quarter. During Fiscal Year 2022, the University?s three campuses in total expended approximately $916 million in R&D grant funds: $504 million, $406 million and $6 million from the Boulder, Denver and UCCS campuses, respectively. Of that amount, the University?s three campuses expended a total of approximately $191 million for equipment purchases, with $116 million, $69.6 million, and $5.4 million being spent by the Boulder, Denver, and UCCS campuses, respectively. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over, and complied with, the R&D Cluster?s equipment management requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls related to the R&D equipment management requirements. We tested 60 items of equipment with a total value of $1.2 million to determine whether the University appropriately safeguarded and maintained equipment, as required by federal regulations. In addition, we tested 40 of the 60 items of equipment with a total value of $840,000 to determine whether the University?s campuses appropriately placed property tags on the equipment as required by University policy. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation 2 CFR 200.313(b) states that a State must use, manage and dispose of equipment acquired under a federal award to the State in accordance with the state laws and procedures. The University?s Property Control Manual section 1.3 states that the University is responsible and accountable for all property acquired with federal funding in accordance with federal regulations and the provision of a sponsored award. While under the heading of ?non-federal entities other than States,? federal regulation 2 CFR 200.313(c) through (e) also requires that equipment records be maintained, a physical inventory of equipment be taken at least once every two years and reconciled to the equipment record, an appropriate control system be used to safeguard equipment and all equipment shall be adequately maintained. ? The University?s Property Control Manual Section 3.3.1 states that ?only items having an acquisition cost of $5,000 or more are logged and tracked in the university property record.? Furthermore, the University?s Property Control Manual Section 3.3.3, states that equipment records should be updated for any changes discovered during the performance of an inventory over equipment. This would include equipment that should be removed from the listing because it was disposed of or is no longer in service. ? The University?s Property Control Manual section 3.2 states that ?All Government property at $5,000 or above in the custody of the Boulder campus must be tagged.? What problems did the audit work identify? We found that 2 of the 60 equipment items that we tested (3 percent,) with a total value of $39,400, were inappropriately included on the equipment listing even though they had either been disposed of in a prior period or were not in service. Specifically, one equipment item with an approximate value of $28,000 was no longer in service by the University, but still remained on the University?s inventory listing. The second equipment item with an approximate value of $8,400 was disposed of by the University on October 3, 2017, but was still on the list. In addition, we determined that 2 of the 40 equipment items we tested for tagging (5 percent) did not contain the tag as required by the University?s Property Control Manual. One of these items was valued at approximately $28,000. The second item was valued at approximately $31,000. Why did these problems occur? The University?s Boulder campus did not have adequate internal controls in place to ensure it complied with the R&D equipment management requirements. Specifically, although the University does have policies over equipment, Boulder campus staff were not adequately performing the procedures intrinsic in the policy. Specifically, neither the PAO nor the individual University departments adequately reconciled the equipment listing to the physical equipment on hand, which resulted in the list including equipment that had been disposed of or was no longer in use. Additionally, the Boulder Campus did not follow its own policies and procedures requiring that equipment with a value of $5,000 was appropriately tagged. One item?s tag was missing and a replacement tag had been ordered and not received at the time of our procedures. We could not determine whether the University identified that the tag was missing before we requested the information for review. The second item was below ground and the University did not maintain evidence of the original tag. Why do these problems matter? The University is obligated to adhere to specified requirements as outlined by federal regulations and the respective award agreement. By failing to adhere to the requirements for maintenance of equipment, the University potentially risks repercussions from the awarding agency. Furthermore, failing to properly maintain the equipment in accordance with federal and University requirements could increase the risk of theft or loss and decrease the ability of the University to adequately identify theft or loss. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-065 The University of Colorado?s Boulder campus should strengthen its internal controls over equipment management and ensure that it complies with the Research and Development equipment management federal compliance requirements by: A. Ensuring the Campus Controller?s Property Accounting Office and the individual departments adequately reconcile the equipment listing to the physical equipment on hand to ensure that the list is accurate, and remove equipment from the listing that has been disposed of or is no longer in use. B. Enforcing its current policies and procedures for ensuring all equipment is appropriately tagged and maintained. Response University of Colorado A. Agree Implementation Date: March 2023 Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: ? Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. ? The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment. B. Agree Implementation Date: March 2023 Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: ? Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. ? The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment.
(A) Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: - Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. - The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment. (B) Management agrees with the recommendation. Procedures have been initiated with cross campus partners and will be fully implemented by March 2023. The proposed corrective action plan is as follows: - Escalation procedures will be implemented in collaboration with campus partners so that action items identified in inventory reviews are addressed timely. - The Campus Controller?s Office will work with campus partners to increase physical monitoring procedures to ensure tags are affixed and maintained on equipment.
Finding 2022-066 Research and Development Cluster Subrecipient Monitoring Compliance Requirement The federal government sponsors research and development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal entity. The types of R&D conducted under these awards vary greatly. The objective of an individual project is explained in the federal award letter. R&D activities at the University are subject to federal subrecipient monitoring requirements. Under these requirements, the University is required to monitor its subrecipients to ensure they use funds in accordance with applicable laws, regulations and terms of the award. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the University, to an entity to carry out part of a Federal grant award received by the pass-through entity. As part of its subrecipient monitoring process, the University uses a subrecipient monitoring checklist that includes a variety of checkpoints, including whether an approved budget is in place and reviewed: whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed; and whether a risk assessment related to a subrecipient?s potential noncompliance has been performed. During Fiscal Year 2022, the University?s three campuses in total expended approximately $916 million in R&D grant funds: $504 million, $406 million, and $6 million from the Boulder, Denver, and UCCS campuses, respectively. The University passed approximately $120 million to 1,325 subrecipients including other universities and non-profit organizations, to assist in the performance of a wide-range of projects such as research into learning disabilities or the advancement of scientific discovery, or other research related projects. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over, and complied with, the R&D?s subrecipient monitoring requirements for Fiscal Year 2022. As part of our audit work, we tested 40 subrecipients to determine whether the University campuses? performed the subrecipient risk assessments related to a subrecipient?s potential noncompliance as required by federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation 2 CFR 200.331(b) requires that the University?s campuses, as federal grant recipients, must ?evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring.? ? The Boulder campus? policy states that monitoring the subaward is a ?collaborative effort? made in both Central Administration as well as in the departments through the Principal Investigator and their supporting Department Administrator.? Completion of a risk analysis and the subrecipient monitoring checklist is listed among the responsibilities of the Central Office. What problem did the audit work identify? The Boulder campus did not perform a risk assessment for six out of the 40 subrecipients we tested (15 percent). However, the campus did perform other monitoring procedures over these subrecipients as the risk assessment process is one procedure in the overall subrecipient monitoring process. Why did this problem occur? The University did not have adequate internal controls in place for monitoring its subrecipients. Specifically, the University?s Boulder campus did not ensure that staff reviewed the subrecipient monitoring checklist in all instances to ensure all appropriate steps were completed, including risk assessments. University personnel indicated that proper staffing was not in place and specific monitoring of risk assessments was not being performed. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in federal regulations and the respective award agreement. By failing to adhere to the requirements for subrecipient monitoring, the University risks performing inadequate or inappropriate monitoring procedures and thereby increases the risk of subawards being used for unauthorized purposes. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-066 The University of Colorado?s Boulder campus should strengthen its internal controls over, and ensure compliance with, federal subrecipient monitoring requirements for the Research and Development Cluster grant programs by enforcing required reviews of the subrecipient checklist for completeness to ensure all of the appropriate steps are completed, including risk assessments, and by ensuring that appropriate levels of staff are assigned responsibility for the reviews. Response University of Colorado Agree Implementation Date: November 2022 Management agrees with the recommendation. Due to hiring of new staff and an internal audit with similar findings, these actions were in process and implemented as of November 2022. These actions are part of the Sub Team?s standard operating processes and will continue. The proposed corrective action plan is as follows: ? The hiring of new team members in 2022; all team members trained on subcontracting processes and documentation requirements with an emphasis on following standard baseline procedures. ? New Subcontract Administrator (SCA) position tasked with compiling final packets for each sub, which includes a quality check to ensure all documents and signatures required are included. ? Use of subcontract checklist and risk assessments required and consistently done by the team.
Show full finding ▾Hide full finding ▴Finding 2022-066 Research and Development Cluster Subrecipient Monitoring Compliance Requirement The federal government sponsors research and development (R&D) activities under a variety of types of awards, most commonly grants, cooperative agreements, and contracts, to achieve objectives agreed upon between the federal awarding agency and the non-federal entity. The types of R&D conducted under these awards vary greatly. The objective of an individual project is explained in the federal award letter. R&D activities at the University are subject to federal subrecipient monitoring requirements. Under these requirements, the University is required to monitor its subrecipients to ensure they use funds in accordance with applicable laws, regulations and terms of the award. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the University, to an entity to carry out part of a Federal grant award received by the pass-through entity. As part of its subrecipient monitoring process, the University uses a subrecipient monitoring checklist that includes a variety of checkpoints, including whether an approved budget is in place and reviewed: whether the subrecipient had an audit, if applicable, and whether that audit has been reviewed; and whether a risk assessment related to a subrecipient?s potential noncompliance has been performed. During Fiscal Year 2022, the University?s three campuses in total expended approximately $916 million in R&D grant funds: $504 million, $406 million, and $6 million from the Boulder, Denver, and UCCS campuses, respectively. The University passed approximately $120 million to 1,325 subrecipients including other universities and non-profit organizations, to assist in the performance of a wide-range of projects such as research into learning disabilities or the advancement of scientific discovery, or other research related projects. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over, and complied with, the R&D?s subrecipient monitoring requirements for Fiscal Year 2022. As part of our audit work, we tested 40 subrecipients to determine whether the University campuses? performed the subrecipient risk assessments related to a subrecipient?s potential noncompliance as required by federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation 2 CFR 200.331(b) requires that the University?s campuses, as federal grant recipients, must ?evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring.? ? The Boulder campus? policy states that monitoring the subaward is a ?collaborative effort? made in both Central Administration as well as in the departments through the Principal Investigator and their supporting Department Administrator.? Completion of a risk analysis and the subrecipient monitoring checklist is listed among the responsibilities of the Central Office. What problem did the audit work identify? The Boulder campus did not perform a risk assessment for six out of the 40 subrecipients we tested (15 percent). However, the campus did perform other monitoring procedures over these subrecipients as the risk assessment process is one procedure in the overall subrecipient monitoring process. Why did this problem occur? The University did not have adequate internal controls in place for monitoring its subrecipients. Specifically, the University?s Boulder campus did not ensure that staff reviewed the subrecipient monitoring checklist in all instances to ensure all appropriate steps were completed, including risk assessments. University personnel indicated that proper staffing was not in place and specific monitoring of risk assessments was not being performed. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in federal regulations and the respective award agreement. By failing to adhere to the requirements for subrecipient monitoring, the University risks performing inadequate or inappropriate monitoring procedures and thereby increases the risk of subawards being used for unauthorized purposes. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-066 The University of Colorado?s Boulder campus should strengthen its internal controls over, and ensure compliance with, federal subrecipient monitoring requirements for the Research and Development Cluster grant programs by enforcing required reviews of the subrecipient checklist for completeness to ensure all of the appropriate steps are completed, including risk assessments, and by ensuring that appropriate levels of staff are assigned responsibility for the reviews. Response University of Colorado Agree Implementation Date: November 2022 Management agrees with the recommendation. Due to hiring of new staff and an internal audit with similar findings, these actions were in process and implemented as of November 2022. These actions are part of the Sub Team?s standard operating processes and will continue. The proposed corrective action plan is as follows: ? The hiring of new team members in 2022; all team members trained on subcontracting processes and documentation requirements with an emphasis on following standard baseline procedures. ? New Subcontract Administrator (SCA) position tasked with compiling final packets for each sub, which includes a quality check to ensure all documents and signatures required are included. ? Use of subcontract checklist and risk assessments required and consistently done by the team.
Management agrees with the recommendation. Due to hiring of new staff and an internal audit with similar findings, these actions were in process and implemented as of November 2022. These actions are part of the Sub Team?s standard operating processes and will continue. The proposed corrective action plan is as follows: - The hiring of new team members in 2022; all team members trained on subcontracting processes and documentation requirements with an emphasis on following standard baseline procedures. - New Subcontract Administrator (SCA) position tasked with compiling final packets for each sub, which includes a quality check to ensure all documents and signatures required are included. - Use of subcontract checklist and risk assessments required and consistently done by the team.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-059 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s required FFATA reports for Fiscal Year 2021 included information on the Low-Income Home Energy Assistance (LIHEAP), COVID-19 ? Low-Income Home Energy Assistance [ALN 93.568]; the Child Care and Development Fund (CCDF) Cluster, consisting of the Child Care and Development Block Grant [ALN 93.575], and Child Care Mandatory and Matching Funds of the Child Care and Development Fund [ALN 93.596]; and the Block Grant for Prevention and Treatment of Substance Abuse (Substance Abuse), COVID-19 ? Block Grant for Prevention and Treatment of Substance Abuse [ALN 93.959]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: LIHEAP funds to one subrecipient, CCDF funds to nine subrecipients, and Substance Abuse funds to seven subrecipients for Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the FFATA reporting and to determine whether the Department correctly reported its subawards to the FSRS during Fiscal Year 2021. Based on our audit testwork, we reviewed the Department?s subawards and related federal expenditures in Fiscal Year 2021 to determine if there was FFATA reporting that was completed within the month following the month the subaward was made, as required. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the state?s accounting system, for the LIHEAP, CCDF, and Substance Abuse programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: LIHEAP had one sample, CCDF had five samples, and Substance Abuse had five samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department?s program staff are responsible for understanding FFATA reporting requirements related to their programs, and providing key data elements for subrecipients at the point that funds are obligated. When program staff determine that the Department is making a subaward that requires FFATA reporting, program staff are required to report these key data elements in eClearance, an approval workflow and document depository system utilized by the Department in their purchasing process. Guidance for the FFATA reporting is included within the Department?s FFATA Quick Reference Guide that is made available to the program staff. Program staff enter the subaward information into eClearance via an online form called a Requisition eForm (eForm), which goes through an approval process and is then routed to the Department?s Purchasing and Contracts unit to process the purchase request that translates into an obligation of an award for subrecipients. Once the eForm is completed processing in eClearance, it is archived in the system and an automated query is run by the Department?s Business Technology Unit to export this data and it is automatically emailed to the Compliance Accounting team on a daily basis. Each day, the Department?s compliance accountant compiles the subaward data emailed to them that originated from eClearance into a daily report. At the end of the month, the compliance accountant combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report?s accuracy. The compliance accountant uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did not report its subawards in FSRS for any of the three federal grant programs we tested for Fiscal Year 2021: the LIHEAP, CCDF, and Substance Abuse programs. In total, for the three programs, the Department failed to report subawards totaling $5.77 million (approximately $3.04 million for LIHEAP, approximately $861 thousand for CCDF, and approximately $1.87 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did these problems occur? The Department does not have adequate internal controls over the FFATA reporting. Specifically, the Department has not validated the automated process to compile the data needed for the FFATA reports. In addition, the Department has not implemented a supervisory review process of the final FFATA report data that is used to submit the FFATA report via FSRS. We determined that automated reports generated did not include the full population of data needed to compile the FFATA reports. Based on test work, we found that program staff entered key data elements needed for FFATA reporting correctly into the eForm during the purchasing process, and that accounting staff used the data provided in the reports received to complete the FFATA reporting in FSRS. However, the data exported from eClearance and sent to accounting to compile the FFATA reports did not contain all of the population needed for reporting. Thus, accounting was using data that was not complete in the FFATA reporting to FSRS, but was unaware that the data was not complete. Further, when there was incomplete information in the data received, the compliance accountant failed to follow up with the various program staff to obtain the necessary information and input it into and submit it through FSRS. Why do these problems matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search; excluding the information could be misleading to the public and fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-059 The Department of Human Service (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Correcting the automated reporting process from eClearance to ensure that data compiled for Transparency Act reporting contains all relevant data. B. Developing and implementing procedures to validate that data derived from eClearance reports and ultimately used to compile Transparency Act reporting is complete and accurate by reviewing the population from an alternate source, such as the Colorado Operations Resource Engine. C. Improving the Department?s supervisory review process to provide for a complete and thorough review of the final FFATA report data that the Department will report within the Federal Funding Accountability and Transparency Act Subaward Reporting System. This process should include taking steps to ensure the compliance accountant follows up with the program staff if the necessary information is not input into eClearance, so that it can be obtained and reported accurately and timely. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unkown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. B. Agree Implementation Date: July 2022 The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. C. Agree Implementation Date: July 2022 CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-059 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s required FFATA reports for Fiscal Year 2021 included information on the Low-Income Home Energy Assistance (LIHEAP), COVID-19 ? Low-Income Home Energy Assistance [ALN 93.568]; the Child Care and Development Fund (CCDF) Cluster, consisting of the Child Care and Development Block Grant [ALN 93.575], and Child Care Mandatory and Matching Funds of the Child Care and Development Fund [ALN 93.596]; and the Block Grant for Prevention and Treatment of Substance Abuse (Substance Abuse), COVID-19 ? Block Grant for Prevention and Treatment of Substance Abuse [ALN 93.959]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: LIHEAP funds to one subrecipient, CCDF funds to nine subrecipients, and Substance Abuse funds to seven subrecipients for Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the FFATA reporting and to determine whether the Department correctly reported its subawards to the FSRS during Fiscal Year 2021. Based on our audit testwork, we reviewed the Department?s subawards and related federal expenditures in Fiscal Year 2021 to determine if there was FFATA reporting that was completed within the month following the month the subaward was made, as required. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the state?s accounting system, for the LIHEAP, CCDF, and Substance Abuse programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: LIHEAP had one sample, CCDF had five samples, and Substance Abuse had five samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department?s program staff are responsible for understanding FFATA reporting requirements related to their programs, and providing key data elements for subrecipients at the point that funds are obligated. When program staff determine that the Department is making a subaward that requires FFATA reporting, program staff are required to report these key data elements in eClearance, an approval workflow and document depository system utilized by the Department in their purchasing process. Guidance for the FFATA reporting is included within the Department?s FFATA Quick Reference Guide that is made available to the program staff. Program staff enter the subaward information into eClearance via an online form called a Requisition eForm (eForm), which goes through an approval process and is then routed to the Department?s Purchasing and Contracts unit to process the purchase request that translates into an obligation of an award for subrecipients. Once the eForm is completed processing in eClearance, it is archived in the system and an automated query is run by the Department?s Business Technology Unit to export this data and it is automatically emailed to the Compliance Accounting team on a daily basis. Each day, the Department?s compliance accountant compiles the subaward data emailed to them that originated from eClearance into a daily report. At the end of the month, the compliance accountant combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report?s accuracy. The compliance accountant uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did not report its subawards in FSRS for any of the three federal grant programs we tested for Fiscal Year 2021: the LIHEAP, CCDF, and Substance Abuse programs. In total, for the three programs, the Department failed to report subawards totaling $5.77 million (approximately $3.04 million for LIHEAP, approximately $861 thousand for CCDF, and approximately $1.87 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did these problems occur? The Department does not have adequate internal controls over the FFATA reporting. Specifically, the Department has not validated the automated process to compile the data needed for the FFATA reports. In addition, the Department has not implemented a supervisory review process of the final FFATA report data that is used to submit the FFATA report via FSRS. We determined that automated reports generated did not include the full population of data needed to compile the FFATA reports. Based on test work, we found that program staff entered key data elements needed for FFATA reporting correctly into the eForm during the purchasing process, and that accounting staff used the data provided in the reports received to complete the FFATA reporting in FSRS. However, the data exported from eClearance and sent to accounting to compile the FFATA reports did not contain all of the population needed for reporting. Thus, accounting was using data that was not complete in the FFATA reporting to FSRS, but was unaware that the data was not complete. Further, when there was incomplete information in the data received, the compliance accountant failed to follow up with the various program staff to obtain the necessary information and input it into and submit it through FSRS. Why do these problems matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search; excluding the information could be misleading to the public and fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-059 The Department of Human Service (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Correcting the automated reporting process from eClearance to ensure that data compiled for Transparency Act reporting contains all relevant data. B. Developing and implementing procedures to validate that data derived from eClearance reports and ultimately used to compile Transparency Act reporting is complete and accurate by reviewing the population from an alternate source, such as the Colorado Operations Resource Engine. C. Improving the Department?s supervisory review process to provide for a complete and thorough review of the final FFATA report data that the Department will report within the Federal Funding Accountability and Transparency Act Subaward Reporting System. This process should include taking steps to ensure the compliance accountant follows up with the program staff if the necessary information is not input into eClearance, so that it can be obtained and reported accurately and timely. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unkown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. B. Agree Implementation Date: July 2022 The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. C. Agree Implementation Date: July 2022 CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
(A) CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unknown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. (B) The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. (C) CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
2021-059
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-060 Misreporting of Federal Expenditures for the COVID-19 ?Pandemic EBT Food Benefits and Child Care and Development Block Grant on the Exhibit K1 Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State?s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Number (ALN)?s related to the programs they support. The program accountants complete this review using a CORE report that the Department created, pulling transaction detail level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department?s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department?s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. The Department is also separately required within its approved State Plan for the COVID-19 ? Pandemic EBT Food Benefits program [ALN 10.542] (P-EBT) to report its P-EBT federal expenditures to the U.S. Department of Agriculture (USDA) via the Report of Disaster Food Stamp Benefit Issuance (FNS-292-B). The Department is also required to support the financial expenditures reported on the FNS-292-B report with source data and files, which includes a P-EBT Summary report that is exported from the Colorado Benefits Management System (CBMS) and includes the number of eligible children, number of eligible households, and total amount paid in P-EBT benefits. The P-EBT summary report is then reconciled by the Department to the County Financial Management System (CFMS), where the counties? issuance of P-EBT program benefits is accumulated and reported. For Fiscal Year 2021, the Department administered more than 70 federal programs and expended approximately $2.4 billion in federal funds. The P-EBT program and Child Care and Development Block Grant (Grant) [ALN 93.575] were two of these federal programs administered by the Department during Fiscal Year 2021. The Department reported more than $292 million in federal expenditures for the P-EBT program and approximately $74 million in federal expenditures for the Grant in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2021 and to determine whether the Department correctly reported its Fiscal Year 2021 federal grant expenditures to the OSC on its Exhibit K1. The purpose of our audit work was also to evaluate the Department?s internal controls over the financial reporting to the USDA regarding the P-EBT program. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2021 Exhibit K1 to the underlying financial records in CORE for the Grant and P-EBT federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. We also reviewed 4 out of 12 Fiscal Year 2021 monthly submissions to the USDA for the FNS-292-B reports and compared federal expenditure amounts reported by the Department to the underlying financial records in CORE. How were the results of the audit work measured? The OSC is required to present the State?s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State?s expenditures of federal awards during the fiscal year. Federal regulations [2 CFR 200.38(b)] define a federal award as, ?The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance?? Federal regulations [2 CFR 200.510(b)(3) and (4)] require that the SEFA must show both total federal awards expended for each individual federal program, the Assistance Listing Number, and the total amount passed through to subrecipients for each federal program. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC?s exhibit instructions include guidelines for completing the Exhibit K1, including defining ?direct and indirect expenditures? as ?all monetary and non-monetary direct and indirect Federal award expenditures,? and ?pass-through expenditures? as ?the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.? For the Department?s Grant federal program, subrecipients consist of counties, school districts, and health centers. State Fiscal Rule 1-2, Internal Controls, requires that state departments ?implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).? Federal regulations [7 CFR 274.4] require the Department to submit an FNS-292-B report in the format prescribed by the USDA with information detailing the P-EBT federal benefit payments. The Department is required to support the information in the report with its underlying records. The FNS-292-B report is identified as a required report within the Department?s State Plan that is approved by the USDA. What problems did the audit work identify? The Department overstated $63.5 million in P-EBT expenditures on its June 2021 FNS-292-B report to USDA that was submitted on August 30, 2021, as well as on the Department?s Exhibit K1 for Fiscal Year 2021. The Department subsequently identified that the FNS-292-B report was misstated and updated and resubmitted the report on September 28, 2021, approximately one month later. The Department, however, did not update its Exhibit K1 for Fiscal Year 2021 to correct the error, because the program staff did not notify the accounting team of the misstatement and need for Exhibit K1 correction. Based on our audit testwork, we also determined that the Department misreported $8.7 million in the Grant?s expenditures as subrecipient, rather than direct, expenditures on its Exhibit K1. Why did these problems occur? The P-EBT program staff did not notify the Department?s accounting team, who prepares the Exhibit K1, of a revision to the FNS-292-B report. The P-EBT program staff prepared the reconciliation of the CBMS summary report to the CFMS P-EBT benefits issued report and identified a variance. The variance was eventually resolved and the P-EBT program staff resubmitted the FNS-292-B report to the USDA; however P-EBT program staff did not communicate this error to the Department?s accounting team. As a result, the accounting team was unaware of the revision and, therefore, did not update the Exhibit K1 to reflect the reduction in federal expenditures. Overall, the Department did not have adequate internal controls, such as an appropriate supervisory review process or adequate communication plan, in place for Fiscal Year 2021 to ensure that the FNS-292-B report was prepared accurately, that the Exhibit K1 was completed in accordance with the instructions provided by the OSC, and that the FNS-292-B and Exhibit K1 were reviewed for accuracy and compared to the underlying data. For the Grant program error, Department staff indicated that these funds were incorrectly identified and coded as subrecipient expenditures in CORE, which caused them to be incorrectly reported as such on the Exhibit K1. When the expenditures were initially posted in CORE, they were not adequately reviewed to determine if they were subrecipient or direct expenditures. Why do these problems matter? By failing to properly report grant expenditures to the federal government and the OSC, who ultimately then fails to properly report expenditures to the federal government on the State?s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, because the error resulted in the Department misstating its federal expenditure results for the fiscal year, federal staff and taxpayers have an incorrect or unreliable picture of the P-EBT grant?s overall status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-060 The Department of Human Services (Department) should strengthen its internal controls over the preparation of federal reports and the Exhibit K1, Schedule of Federal Assistance, by: A. Strengthening its internal controls over its monthly Pandemic Electronic Benefit Transfer Food Benefits (P-EBT) reporting to ensure its reporting is accurate and goes through supervisory review. B. Improving communication between program and accounting staff to ensure the Exhibit K1 is accurately updated when errors in federal reporting are identified and resolved. C. Improving the supervisory review process over the Exhibit K1 and the federal expenditures entered in the Colorado Operations Resource Engine (CORE), the state?s accounting system, to ensure expenditures are coded correctly as direct or subrecipient expenditures and that, ultimately, the Exhibit K1 is accurate and complete. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. B. Agree Implementation Date: July 2022 CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. C. Agree Implementation Date: July 2022 CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-060 Misreporting of Federal Expenditures for the COVID-19 ?Pandemic EBT Food Benefits and Child Care and Development Block Grant on the Exhibit K1 Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State?s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Number (ALN)?s related to the programs they support. The program accountants complete this review using a CORE report that the Department created, pulling transaction detail level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department?s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department?s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. The Department is also separately required within its approved State Plan for the COVID-19 ? Pandemic EBT Food Benefits program [ALN 10.542] (P-EBT) to report its P-EBT federal expenditures to the U.S. Department of Agriculture (USDA) via the Report of Disaster Food Stamp Benefit Issuance (FNS-292-B). The Department is also required to support the financial expenditures reported on the FNS-292-B report with source data and files, which includes a P-EBT Summary report that is exported from the Colorado Benefits Management System (CBMS) and includes the number of eligible children, number of eligible households, and total amount paid in P-EBT benefits. The P-EBT summary report is then reconciled by the Department to the County Financial Management System (CFMS), where the counties? issuance of P-EBT program benefits is accumulated and reported. For Fiscal Year 2021, the Department administered more than 70 federal programs and expended approximately $2.4 billion in federal funds. The P-EBT program and Child Care and Development Block Grant (Grant) [ALN 93.575] were two of these federal programs administered by the Department during Fiscal Year 2021. The Department reported more than $292 million in federal expenditures for the P-EBT program and approximately $74 million in federal expenditures for the Grant in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2021 and to determine whether the Department correctly reported its Fiscal Year 2021 federal grant expenditures to the OSC on its Exhibit K1. The purpose of our audit work was also to evaluate the Department?s internal controls over the financial reporting to the USDA regarding the P-EBT program. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2021 Exhibit K1 to the underlying financial records in CORE for the Grant and P-EBT federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. We also reviewed 4 out of 12 Fiscal Year 2021 monthly submissions to the USDA for the FNS-292-B reports and compared federal expenditure amounts reported by the Department to the underlying financial records in CORE. How were the results of the audit work measured? The OSC is required to present the State?s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State?s expenditures of federal awards during the fiscal year. Federal regulations [2 CFR 200.38(b)] define a federal award as, ?The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance?? Federal regulations [2 CFR 200.510(b)(3) and (4)] require that the SEFA must show both total federal awards expended for each individual federal program, the Assistance Listing Number, and the total amount passed through to subrecipients for each federal program. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC?s exhibit instructions include guidelines for completing the Exhibit K1, including defining ?direct and indirect expenditures? as ?all monetary and non-monetary direct and indirect Federal award expenditures,? and ?pass-through expenditures? as ?the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.? For the Department?s Grant federal program, subrecipients consist of counties, school districts, and health centers. State Fiscal Rule 1-2, Internal Controls, requires that state departments ?implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).? Federal regulations [7 CFR 274.4] require the Department to submit an FNS-292-B report in the format prescribed by the USDA with information detailing the P-EBT federal benefit payments. The Department is required to support the information in the report with its underlying records. The FNS-292-B report is identified as a required report within the Department?s State Plan that is approved by the USDA. What problems did the audit work identify? The Department overstated $63.5 million in P-EBT expenditures on its June 2021 FNS-292-B report to USDA that was submitted on August 30, 2021, as well as on the Department?s Exhibit K1 for Fiscal Year 2021. The Department subsequently identified that the FNS-292-B report was misstated and updated and resubmitted the report on September 28, 2021, approximately one month later. The Department, however, did not update its Exhibit K1 for Fiscal Year 2021 to correct the error, because the program staff did not notify the accounting team of the misstatement and need for Exhibit K1 correction. Based on our audit testwork, we also determined that the Department misreported $8.7 million in the Grant?s expenditures as subrecipient, rather than direct, expenditures on its Exhibit K1. Why did these problems occur? The P-EBT program staff did not notify the Department?s accounting team, who prepares the Exhibit K1, of a revision to the FNS-292-B report. The P-EBT program staff prepared the reconciliation of the CBMS summary report to the CFMS P-EBT benefits issued report and identified a variance. The variance was eventually resolved and the P-EBT program staff resubmitted the FNS-292-B report to the USDA; however P-EBT program staff did not communicate this error to the Department?s accounting team. As a result, the accounting team was unaware of the revision and, therefore, did not update the Exhibit K1 to reflect the reduction in federal expenditures. Overall, the Department did not have adequate internal controls, such as an appropriate supervisory review process or adequate communication plan, in place for Fiscal Year 2021 to ensure that the FNS-292-B report was prepared accurately, that the Exhibit K1 was completed in accordance with the instructions provided by the OSC, and that the FNS-292-B and Exhibit K1 were reviewed for accuracy and compared to the underlying data. For the Grant program error, Department staff indicated that these funds were incorrectly identified and coded as subrecipient expenditures in CORE, which caused them to be incorrectly reported as such on the Exhibit K1. When the expenditures were initially posted in CORE, they were not adequately reviewed to determine if they were subrecipient or direct expenditures. Why do these problems matter? By failing to properly report grant expenditures to the federal government and the OSC, who ultimately then fails to properly report expenditures to the federal government on the State?s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, because the error resulted in the Department misstating its federal expenditure results for the fiscal year, federal staff and taxpayers have an incorrect or unreliable picture of the P-EBT grant?s overall status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-060 The Department of Human Services (Department) should strengthen its internal controls over the preparation of federal reports and the Exhibit K1, Schedule of Federal Assistance, by: A. Strengthening its internal controls over its monthly Pandemic Electronic Benefit Transfer Food Benefits (P-EBT) reporting to ensure its reporting is accurate and goes through supervisory review. B. Improving communication between program and accounting staff to ensure the Exhibit K1 is accurately updated when errors in federal reporting are identified and resolved. C. Improving the supervisory review process over the Exhibit K1 and the federal expenditures entered in the Colorado Operations Resource Engine (CORE), the state?s accounting system, to ensure expenditures are coded correctly as direct or subrecipient expenditures and that, ultimately, the Exhibit K1 is accurate and complete. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. B. Agree Implementation Date: July 2022 CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. C. Agree Implementation Date: July 2022 CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
(A) CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. (B) CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. (C) CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
2021-060
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-061 The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-054 INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORY The Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food). Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens. The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods. Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs. During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program: ? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report. ? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)]. The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions. The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed. Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically: EMERGENCY FOOD PROGRAM ? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory. ? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered. ? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million. ? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report. SUPPLEMENTAL FOOD PROGRAM ? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000. WHY DID THESE PROBLEMS OCCUR? The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation. WHY DO THESE PROBLEMS MATTER? Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-054 The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by: A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate. B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate. C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories. B AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. C AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses were communicated to the Department in the previous year and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-061 The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-054 INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORY The Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food). Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens. The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods. Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs. During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program: ? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report. ? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)]. The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions. The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed. Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically: EMERGENCY FOOD PROGRAM ? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory. ? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered. ? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million. ? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report. SUPPLEMENTAL FOOD PROGRAM ? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000. WHY DID THESE PROBLEMS OCCUR? The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation. WHY DO THESE PROBLEMS MATTER? Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-054 The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by: A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate. B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate. C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories. B AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. C AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
(B) The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. (C) The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
2021-061
Finding 2022-070 Unemployment Insurance Program Integrity Fraud Holds The Department?s UI Division is responsible for the administration and monitoring of Colorado?s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits to ensure they are properly paid. Employer-paid premiums are the primary source of funding for UI benefits. When an individual applies for UI benefits, they are called a claimant, and the application is called a claim. Each claimant creates an account in MyUI+, the Department?s unemployment benefit system, in order to apply for unemployment benefits. The Department reviews, or adjudicates, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to all employers that the claimant worked for within the last 18 months to determine the validity and reason for the claimant leaving the workplace. In addition, Department staff indicate that, on a weekly basis, they perform reviews to identify potential issues with a claimant?s ability and availability to work, and to determine whether the claimant is accurately reporting earned income. If information provided by an interested party, such as a former employer, relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. In Fiscal Year 2022, the Department paid $1.1 billion in UI benefits. The Department has processes and systems to detect and prevent identity theft related to UI benefits. For example, when the Department identifies a claim with characteristics that are indicators of fraud, it places a fraud hold (also known as a program integrity hold) on the claimant?s UI claim, which holds the claim for investigation and which prevents any future benefit payments to the claimant until the fraud hold is removed and eligibility is determined. For each fraud hold, the Department has to determine if the identity of the individual filing the claim matches the personally identifiable information used on the claim. Once that is verified, the Department then must verify that the individual did not make any false statements in order to establish program eligibility. The steps that the Department takes to resolve a fraud hold differ depending on the characteristics of the claim that caused the Department to question its legitimacy. If Department staff determine that the fraud hold was not legitimate, the Department clears the hold in MyUI+ and then proceeds with determining if the individual is eligible to receive UI benefits. The Department uses an automated system, called ID.me, as part of its identity verification process. ID.me is a federally-certified identity provider that assists the Department in verifying claimants? identity. In some instances, MyUI+ will clear the fraud hold if the claimant passes ID.me and the claim does not need further investigation. In other cases, the Department performs an investigation to determine if the fraud hold is legitimate, or if the hold was placed in error. According to the information in MyUI+, the Department cleared 54,047 fraud holds during Fiscal Year 2022 ? 44,936 were cleared through the ID.me process, and 9,111 were cleared by the Department. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over fraud holds during Fiscal Year 2022, including whether only appropriate, authorized individuals cleared the fraud hold from MyUI+, and if the Department had adequate segregation of duties between staff investigating a fraud hold, and staff releasing the hold in MyUI+. As part of our audit work, we requested the Department?s policies and procedures for their investigation process and documentation used to support the Department?s investigations that resulted in clearing a fraud hold, and inquired how the Department determined who is authorized to release fraud holds from MyUI+. The Department?s documentation included case reports for the investigations and log notes from Salesforce, the Department?s software that is primarily used as a workflow management tool and documentation repository for UI claims requiring an investigation. We selected a sample of 60 of the 9,111 fraud holds that were cleared by the Department during Fiscal Year 2022 to determine if the Department performed an investigation prior to releasing the fraud hold in MyUI+. In addition, as part of our testing of the sample, we determined that 20 different Department staff cleared the 60 fraud holds in MyUI+; we performed testing to determine if those staff were authorized to clear the holds in MyUI+. How were the results of the audit work measured? We measured the results of our audit against the following: Section 7511, Part V, of the Employment Security Manual (ESM) requires state UI laws to include provisions for such methods of administration as are, within reason, calculated (1) to detect benefits paid through error by the state UI agency or through willful misrepresentation or error by the claimant or others, (2) to deter claimants from obtaining benefits through willful misrepresentation, and (3) to recover benefits overpaid under certain circumstances. These required functions are accomplished through designated staff responsible for promoting and maintaining the integrity of the UI program through prevention, detection, investigations, establishment, and recovery of overpayments. Designated staff also prepare cases for prosecution. The Department?s UI Investigation Procedures state that if Department staff determine that a fraud hold that they are investigating can be released in MyUI+, Department staff should write an event log note in Salesforce. Information security is the practice of protecting information by mitigating information risk. ISO 27001 Standard for Information Security Management Systems is the international standard for information security, and its best practice approach helps organizations manage their information security by addressing people, processes, and technology. User-access management has the following objectives: ? Ensure authorized user access ? Prevent unauthorized access to information systems Expanding on the objectives from ISO 27001, a broad set of business-level objectives for user-access management can be defined as follows: ? Allow only authorized users to have access to information and resources ? Restrict access to the least privileges required by these authorized users to fulfill their business role The federal Social Security Act [Section 303(a)(1), SSA], contains a merit-based system requirement for the UI program. Specifically, this section requires that, as a condition of receiving federal UI administrative grants, states must have laws that include ?provision for such methods of administration? that includes a merit system. A merit system is defined as the process of promoting and hiring government employees based on their ability to perform a job, rather than on their political connections. As part of this requirement, any position which involves the determination of whether or not a UI claimant will be paid, or which involves determining an employer's liability for contributions, must be ?merit staffed.? According to federal regulations [5 CFR 900.603, Standards For a Merit System of Personnel Administration], ?The quality of public service can be improved by the development of systems of personnel administration consistent with such merit principles as - (a) Recruiting, selecting, and advancing employees on the basis of their relative ability, knowledge, and skills, including open consideration of qualified applicants for initial appointment. (b) Providing equitable and adequate compensation. (c) Training employees, as needed, to assure high quality performance. (d) Retaining employees on the basis of the adequacy of their performance, correcting inadequate performance, and separating employees whose inadequate performance cannot be corrected?? The U. S. Department of Labor Unemployment Insurance Program Letter (UIPL) No. 12-01, states that only those employees considered as merit-staff can determine whether to pay or deny payment to a claim. Additionally, UIPL No. 12-01 Change 2 states that, ?Determinations of overpayments or fraud must be made by merit-staffed employees.? The Department?s SPP 1053 Code of Conduct, Ethics and Values Policy, Attachment A: Unemployment Insurance Ethics Policy states that employees are not permitted to do the following: ? Investigate or attempt to investigate suspected fraud unless it is within their assigned duties. ? Backdate a claim, transfer claim status retroactively (UI to UCFE, UCX to TRA, etc.), alter information provided by a claimant or employer, or change or defer a UI document due date without valid documentation or approval of the appropriate branch chief or UI Director. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 10.01 of the Green Book, the Department should design control activities to achieve objectives and respond to risks. Segregation of duties contribute to the design, implementation, and operating effectiveness of control activities. Under Paragraph 10.03 of the Green Book, the Department should divide or segregate key duties and responsibilities among different people to reduce the risk of error, misuse, or fraud. This includes separating the responsibilities for authorizing transactions, processing and recording them, reviewing the transactions, and handling any related assets so that no one individual controls all key aspects of a transaction or event. What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to the clearing of fraud holds during Fiscal Year 2022. Specifically, we identified issues with 32 of the 60 (53 percent) fraud holds we tested, as follows: ? The Department cleared 12 of the 60 fraud holds tested (20 percent) without performing an investigation or providing evidence of the reasoning used to clear the hold. Specifically, when we asked for investigation documentation for the 12 fraud holds, the Department indicated these were cleared without an investigation, and there were no related log notes in Salesforce, as required. ? For 20 of the 48 cases in our sample (42 percent) for which the Department did conduct an investigation, it did not segregate the duty of investigating the fraud hold and clearing the fraud hold from MyUI+. Specifically, in these cases, only one person conducted the investigation, concluded on the investigation, and cleared the fraud hold in MyUI+. ? One of the 20 Department staff who cleared a portion (5 percent) of the 60 fraud holds we sampled was not authorized to clear fraud holds from MyUI+ because the individual was not considered to be merit-staffed. Further, this unauthorized individual cleared 11 of 12 fraud holds we identified above that did not have an investigation, as required. We also found that this individual cleared an additional 55 fraud holds outside of our sample during Fiscal Year 2022. Why did these problems occur? The Department did not have sufficient internal controls in place, including appropriate policies and procedures, to ensure it enforced compliance with federal and Department-level requirements regarding the clearing of UI fraud holds during Fiscal Year 2022, as follows: ? The Department did not ensure that all fraud hold claims cleared in MyUI+ had a related log note in Salesforce that explained the rationale for clearing the hold, or that there was an investigation performed over the fraud hold prior to it being cleared in MyUI+. Specifically, in 11 of the 12 instances, the Department?s controls failed to prevent non-merit staff from using their MyUI+ access inappropriately, and in the other instance, Department controls failed to ensure the UI claim was reviewed by the UI section that reviews fraud holds rather than the UI section that resolves non-fraud UI claims. The Department provided full, rather than read-only access to the non-merit, Executive Director?s Office?s staff member noted in our finding. UI management indicated that they gave the individual full access to MyUI+ during the height of the pandemic with the assumption that the individual would use such access in a read-only manner solely to review claim information for inquiries coming through the Executive Director's Office. According to UI Division leadership, after they identified that the individual had full access during Fiscal Year 2022, they changed the individual?s access to read-only in January 2022. ? The Department lacked policies regarding management override of controls related to the clearing of fraud holds, in order to prevent or appropriately manage those responsibilities. UI staff indicated that in some cases, the non-merit, Executive Director?s Office?s staff member noted in our finding would reach out to other staff within the UI Division to help escalate the MyUI+ fraud hold clearing process. In some of these instances, because of the position of the individual within the Executive Director?s Office, UI staff circumvented the normal escalation process and aided the individual with clearing the fraud hold. ? The Department?s current policies and procedures do not require segregation of duties between those staff who investigate a fraud hold, and those staff who remove the fraud hold in MyUI+. Why do these problems matter? Improper segregation of duties, including the separation of responsibilities for both investigating and clearing potential fraud holds, leaves the UI program vulnerable to fraudulent activity. Specifically, fraud risk increases if there is no segregation between the investigation and the actual clearing of the fraud hold from MyUI+ and, as a result, the same staff could inappropriately clear holds and initiate UI payments. Further, a lack of strong checks and balances within the UI program could erode the integrity of the program at large, ultimately negatively impacting public trust. Strong internal controls related to UI fraud are especially important given the large amount of funds that are paid by the Department for UI claims each year and the significant amount of fraudulent claims that are paid by the Department. For example, the Department recorded an estimated receivable for amounts due back to the Department of $45 million for fraudulently-obtained UI claims at June 30, 2022. Without strengthening its controls over UI claims and fraud holds, there is a risk that a significant amount of UI funds could continue to be paid out each year for fraudulently obtained UI claims. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-070 The Department of Labor and Employment (Department) should strengthen its internal controls over Unemployment Insurance (UI) program integrity holds by: A. Ensuring all fraud holds are properly investigated and documented with a log note in Salesforce that explains the rationale for releasing the claim, prior to releasing the claim in MyUI+. B. Adequately reviewing claims for a fraud indicator to ensure the hold is sent to the appropriate UI section for resolution. C. Ensuring Department staff are given the appropriate access in MyUI+ to prevent individuals from clearing fraud holds inappropriately and periodically monitoring access to ensure access levels remain appropriate. D. Instituting policies and procedures over management override of internal controls related to UI claims and providing staff training on those policies and procedures. This should include ensuring that UI staff are aware of the importance of following all procedures related to fraud holds and that any inappropriate requests or pressures are communicated through the appropriate channels. E. Updating its current policies and procedures to require segregation of duties between the investigation of a fraud hold and the release of a fraud hold in MyUI+ to ensure more than one person is involved in the fraud hold process from beginning to end. Response Department of Labor and Employment A. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department is moving all adjudication and investigation of program integrity holds into the MyUI+ system, so there will be one system of record. The Department will ensure that all program integrity holds have all documentation through adjudication and investigation, including log notes. The Department anticipates this to be fully implemented by July 2024. B. Agree Implementation Date: July 2024 The Department agrees with this finding. The department has modified processes to ensure all holds are only routed to the appropriate team to be adjudicated. In addition the Department is working to have all claims identified as fraud delivered in a workflow process in MyUI+ rather than the various processes in place now. Further the department is working with our MyUI+ system experts to implement new technology to strengthen and streamline the fraud indicator escalation process and systems within MyUI+. In working with our MyUI+ system experts, the Department anticipates this to be fully implemented by July 2024. C. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department will continue strengthening security in this area and internal procedures to periodically monitor the potential for internal fraud activities. Additionally, the Department will periodically monitor and review My UI+ access levels for appropriateness. In consultation with our MyUI+ systems experts, the Department anticipates this finding to be fully implemented by July 2024. D. Agree Implementation Date: July 2023 The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be completed by July 2023. E. Disagree When a PI hold is identified as being highly suspicious for criminally fraudulent activity, it is routed to a specialized unit for review, thereby leaving the standard adjudication process. This is handled by passing the review to the UI Investigations and/or Criminal Enforcement (ICE) unit. The investigator performs their investigation and if no actual fraudulent activity is found they will release the hold. The UI Division also performs several quality control reviews of claims and claim decisions via Benefits Payment Control (BPC), Benefits Accuracy Measurements (BAM), Benefits Timeliness and Quality (BTQ), and internal Quality Assurance (QA) reviews. Claims are reviewed for such criteria as adequate support documentation, benefit payment accuracy, timely processing, and correct claim decision determination on all program integrity holds. The Green Book states in Section 10.14, ? If segregation of duties is not practical within an operational process because of limited personnel or other factors, management designs alternative control activities to address the risk of fraud, waste, or abuse in the operational process.? CDLE believes the reviews represent adequate and sufficient compensating controls for the need for segregation of duties on fraud holds. Changing the current process would hinder our ability to deliver UI benefit services timely to our customers and would put us in jeopardy of fulfilling our federal and state payment timeliness requirements. Auditor?s Addendum Segregating the duties between investigating and releasing a fraud hold in MyUI+ reduces the risk of an employee inappropriately and potentially fraudulently clearing the hold without conducting a proper investigation. The issues identified in our audit indicate that the Department?s current compensating controls did not identify that a current employee released fraud holds without a proper investigation. The Department should consider updating its procedures and processes to segregate these duties to reduce the risk of this occurring in the future.
Show full finding ▾Hide full finding ▴Finding 2022-070 Unemployment Insurance Program Integrity Fraud Holds The Department?s UI Division is responsible for the administration and monitoring of Colorado?s UI programs, including the collection of unemployment premiums from employers, the payment of UI benefits to claimants, and the performance of audits and investigations of premiums and benefits to ensure they are properly paid. Employer-paid premiums are the primary source of funding for UI benefits. When an individual applies for UI benefits, they are called a claimant, and the application is called a claim. Each claimant creates an account in MyUI+, the Department?s unemployment benefit system, in order to apply for unemployment benefits. The Department reviews, or adjudicates, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to all employers that the claimant worked for within the last 18 months to determine the validity and reason for the claimant leaving the workplace. In addition, Department staff indicate that, on a weekly basis, they perform reviews to identify potential issues with a claimant?s ability and availability to work, and to determine whether the claimant is accurately reporting earned income. If information provided by an interested party, such as a former employer, relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. In Fiscal Year 2022, the Department paid $1.1 billion in UI benefits. The Department has processes and systems to detect and prevent identity theft related to UI benefits. For example, when the Department identifies a claim with characteristics that are indicators of fraud, it places a fraud hold (also known as a program integrity hold) on the claimant?s UI claim, which holds the claim for investigation and which prevents any future benefit payments to the claimant until the fraud hold is removed and eligibility is determined. For each fraud hold, the Department has to determine if the identity of the individual filing the claim matches the personally identifiable information used on the claim. Once that is verified, the Department then must verify that the individual did not make any false statements in order to establish program eligibility. The steps that the Department takes to resolve a fraud hold differ depending on the characteristics of the claim that caused the Department to question its legitimacy. If Department staff determine that the fraud hold was not legitimate, the Department clears the hold in MyUI+ and then proceeds with determining if the individual is eligible to receive UI benefits. The Department uses an automated system, called ID.me, as part of its identity verification process. ID.me is a federally-certified identity provider that assists the Department in verifying claimants? identity. In some instances, MyUI+ will clear the fraud hold if the claimant passes ID.me and the claim does not need further investigation. In other cases, the Department performs an investigation to determine if the fraud hold is legitimate, or if the hold was placed in error. According to the information in MyUI+, the Department cleared 54,047 fraud holds during Fiscal Year 2022 ? 44,936 were cleared through the ID.me process, and 9,111 were cleared by the Department. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over fraud holds during Fiscal Year 2022, including whether only appropriate, authorized individuals cleared the fraud hold from MyUI+, and if the Department had adequate segregation of duties between staff investigating a fraud hold, and staff releasing the hold in MyUI+. As part of our audit work, we requested the Department?s policies and procedures for their investigation process and documentation used to support the Department?s investigations that resulted in clearing a fraud hold, and inquired how the Department determined who is authorized to release fraud holds from MyUI+. The Department?s documentation included case reports for the investigations and log notes from Salesforce, the Department?s software that is primarily used as a workflow management tool and documentation repository for UI claims requiring an investigation. We selected a sample of 60 of the 9,111 fraud holds that were cleared by the Department during Fiscal Year 2022 to determine if the Department performed an investigation prior to releasing the fraud hold in MyUI+. In addition, as part of our testing of the sample, we determined that 20 different Department staff cleared the 60 fraud holds in MyUI+; we performed testing to determine if those staff were authorized to clear the holds in MyUI+. How were the results of the audit work measured? We measured the results of our audit against the following: Section 7511, Part V, of the Employment Security Manual (ESM) requires state UI laws to include provisions for such methods of administration as are, within reason, calculated (1) to detect benefits paid through error by the state UI agency or through willful misrepresentation or error by the claimant or others, (2) to deter claimants from obtaining benefits through willful misrepresentation, and (3) to recover benefits overpaid under certain circumstances. These required functions are accomplished through designated staff responsible for promoting and maintaining the integrity of the UI program through prevention, detection, investigations, establishment, and recovery of overpayments. Designated staff also prepare cases for prosecution. The Department?s UI Investigation Procedures state that if Department staff determine that a fraud hold that they are investigating can be released in MyUI+, Department staff should write an event log note in Salesforce. Information security is the practice of protecting information by mitigating information risk. ISO 27001 Standard for Information Security Management Systems is the international standard for information security, and its best practice approach helps organizations manage their information security by addressing people, processes, and technology. User-access management has the following objectives: ? Ensure authorized user access ? Prevent unauthorized access to information systems Expanding on the objectives from ISO 27001, a broad set of business-level objectives for user-access management can be defined as follows: ? Allow only authorized users to have access to information and resources ? Restrict access to the least privileges required by these authorized users to fulfill their business role The federal Social Security Act [Section 303(a)(1), SSA], contains a merit-based system requirement for the UI program. Specifically, this section requires that, as a condition of receiving federal UI administrative grants, states must have laws that include ?provision for such methods of administration? that includes a merit system. A merit system is defined as the process of promoting and hiring government employees based on their ability to perform a job, rather than on their political connections. As part of this requirement, any position which involves the determination of whether or not a UI claimant will be paid, or which involves determining an employer's liability for contributions, must be ?merit staffed.? According to federal regulations [5 CFR 900.603, Standards For a Merit System of Personnel Administration], ?The quality of public service can be improved by the development of systems of personnel administration consistent with such merit principles as - (a) Recruiting, selecting, and advancing employees on the basis of their relative ability, knowledge, and skills, including open consideration of qualified applicants for initial appointment. (b) Providing equitable and adequate compensation. (c) Training employees, as needed, to assure high quality performance. (d) Retaining employees on the basis of the adequacy of their performance, correcting inadequate performance, and separating employees whose inadequate performance cannot be corrected?? The U. S. Department of Labor Unemployment Insurance Program Letter (UIPL) No. 12-01, states that only those employees considered as merit-staff can determine whether to pay or deny payment to a claim. Additionally, UIPL No. 12-01 Change 2 states that, ?Determinations of overpayments or fraud must be made by merit-staffed employees.? The Department?s SPP 1053 Code of Conduct, Ethics and Values Policy, Attachment A: Unemployment Insurance Ethics Policy states that employees are not permitted to do the following: ? Investigate or attempt to investigate suspected fraud unless it is within their assigned duties. ? Backdate a claim, transfer claim status retroactively (UI to UCFE, UCX to TRA, etc.), alter information provided by a claimant or employer, or change or defer a UI document due date without valid documentation or approval of the appropriate branch chief or UI Director. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 10.01 of the Green Book, the Department should design control activities to achieve objectives and respond to risks. Segregation of duties contribute to the design, implementation, and operating effectiveness of control activities. Under Paragraph 10.03 of the Green Book, the Department should divide or segregate key duties and responsibilities among different people to reduce the risk of error, misuse, or fraud. This includes separating the responsibilities for authorizing transactions, processing and recording them, reviewing the transactions, and handling any related assets so that no one individual controls all key aspects of a transaction or event. What problems did the audit work identify? The Department did not comply with federal regulations or its own policies and procedures related to the clearing of fraud holds during Fiscal Year 2022. Specifically, we identified issues with 32 of the 60 (53 percent) fraud holds we tested, as follows: ? The Department cleared 12 of the 60 fraud holds tested (20 percent) without performing an investigation or providing evidence of the reasoning used to clear the hold. Specifically, when we asked for investigation documentation for the 12 fraud holds, the Department indicated these were cleared without an investigation, and there were no related log notes in Salesforce, as required. ? For 20 of the 48 cases in our sample (42 percent) for which the Department did conduct an investigation, it did not segregate the duty of investigating the fraud hold and clearing the fraud hold from MyUI+. Specifically, in these cases, only one person conducted the investigation, concluded on the investigation, and cleared the fraud hold in MyUI+. ? One of the 20 Department staff who cleared a portion (5 percent) of the 60 fraud holds we sampled was not authorized to clear fraud holds from MyUI+ because the individual was not considered to be merit-staffed. Further, this unauthorized individual cleared 11 of 12 fraud holds we identified above that did not have an investigation, as required. We also found that this individual cleared an additional 55 fraud holds outside of our sample during Fiscal Year 2022. Why did these problems occur? The Department did not have sufficient internal controls in place, including appropriate policies and procedures, to ensure it enforced compliance with federal and Department-level requirements regarding the clearing of UI fraud holds during Fiscal Year 2022, as follows: ? The Department did not ensure that all fraud hold claims cleared in MyUI+ had a related log note in Salesforce that explained the rationale for clearing the hold, or that there was an investigation performed over the fraud hold prior to it being cleared in MyUI+. Specifically, in 11 of the 12 instances, the Department?s controls failed to prevent non-merit staff from using their MyUI+ access inappropriately, and in the other instance, Department controls failed to ensure the UI claim was reviewed by the UI section that reviews fraud holds rather than the UI section that resolves non-fraud UI claims. The Department provided full, rather than read-only access to the non-merit, Executive Director?s Office?s staff member noted in our finding. UI management indicated that they gave the individual full access to MyUI+ during the height of the pandemic with the assumption that the individual would use such access in a read-only manner solely to review claim information for inquiries coming through the Executive Director's Office. According to UI Division leadership, after they identified that the individual had full access during Fiscal Year 2022, they changed the individual?s access to read-only in January 2022. ? The Department lacked policies regarding management override of controls related to the clearing of fraud holds, in order to prevent or appropriately manage those responsibilities. UI staff indicated that in some cases, the non-merit, Executive Director?s Office?s staff member noted in our finding would reach out to other staff within the UI Division to help escalate the MyUI+ fraud hold clearing process. In some of these instances, because of the position of the individual within the Executive Director?s Office, UI staff circumvented the normal escalation process and aided the individual with clearing the fraud hold. ? The Department?s current policies and procedures do not require segregation of duties between those staff who investigate a fraud hold, and those staff who remove the fraud hold in MyUI+. Why do these problems matter? Improper segregation of duties, including the separation of responsibilities for both investigating and clearing potential fraud holds, leaves the UI program vulnerable to fraudulent activity. Specifically, fraud risk increases if there is no segregation between the investigation and the actual clearing of the fraud hold from MyUI+ and, as a result, the same staff could inappropriately clear holds and initiate UI payments. Further, a lack of strong checks and balances within the UI program could erode the integrity of the program at large, ultimately negatively impacting public trust. Strong internal controls related to UI fraud are especially important given the large amount of funds that are paid by the Department for UI claims each year and the significant amount of fraudulent claims that are paid by the Department. For example, the Department recorded an estimated receivable for amounts due back to the Department of $45 million for fraudulently-obtained UI claims at June 30, 2022. Without strengthening its controls over UI claims and fraud holds, there is a risk that a significant amount of UI funds could continue to be paid out each year for fraudulently obtained UI claims. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-070 The Department of Labor and Employment (Department) should strengthen its internal controls over Unemployment Insurance (UI) program integrity holds by: A. Ensuring all fraud holds are properly investigated and documented with a log note in Salesforce that explains the rationale for releasing the claim, prior to releasing the claim in MyUI+. B. Adequately reviewing claims for a fraud indicator to ensure the hold is sent to the appropriate UI section for resolution. C. Ensuring Department staff are given the appropriate access in MyUI+ to prevent individuals from clearing fraud holds inappropriately and periodically monitoring access to ensure access levels remain appropriate. D. Instituting policies and procedures over management override of internal controls related to UI claims and providing staff training on those policies and procedures. This should include ensuring that UI staff are aware of the importance of following all procedures related to fraud holds and that any inappropriate requests or pressures are communicated through the appropriate channels. E. Updating its current policies and procedures to require segregation of duties between the investigation of a fraud hold and the release of a fraud hold in MyUI+ to ensure more than one person is involved in the fraud hold process from beginning to end. Response Department of Labor and Employment A. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department is moving all adjudication and investigation of program integrity holds into the MyUI+ system, so there will be one system of record. The Department will ensure that all program integrity holds have all documentation through adjudication and investigation, including log notes. The Department anticipates this to be fully implemented by July 2024. B. Agree Implementation Date: July 2024 The Department agrees with this finding. The department has modified processes to ensure all holds are only routed to the appropriate team to be adjudicated. In addition the Department is working to have all claims identified as fraud delivered in a workflow process in MyUI+ rather than the various processes in place now. Further the department is working with our MyUI+ system experts to implement new technology to strengthen and streamline the fraud indicator escalation process and systems within MyUI+. In working with our MyUI+ system experts, the Department anticipates this to be fully implemented by July 2024. C. Agree Implementation Date: July 2024 The Department agrees with this finding. The Department will continue strengthening security in this area and internal procedures to periodically monitor the potential for internal fraud activities. Additionally, the Department will periodically monitor and review My UI+ access levels for appropriateness. In consultation with our MyUI+ systems experts, the Department anticipates this finding to be fully implemented by July 2024. D. Agree Implementation Date: July 2023 The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be completed by July 2023. E. Disagree When a PI hold is identified as being highly suspicious for criminally fraudulent activity, it is routed to a specialized unit for review, thereby leaving the standard adjudication process. This is handled by passing the review to the UI Investigations and/or Criminal Enforcement (ICE) unit. The investigator performs their investigation and if no actual fraudulent activity is found they will release the hold. The UI Division also performs several quality control reviews of claims and claim decisions via Benefits Payment Control (BPC), Benefits Accuracy Measurements (BAM), Benefits Timeliness and Quality (BTQ), and internal Quality Assurance (QA) reviews. Claims are reviewed for such criteria as adequate support documentation, benefit payment accuracy, timely processing, and correct claim decision determination on all program integrity holds. The Green Book states in Section 10.14, ? If segregation of duties is not practical within an operational process because of limited personnel or other factors, management designs alternative control activities to address the risk of fraud, waste, or abuse in the operational process.? CDLE believes the reviews represent adequate and sufficient compensating controls for the need for segregation of duties on fraud holds. Changing the current process would hinder our ability to deliver UI benefit services timely to our customers and would put us in jeopardy of fulfilling our federal and state payment timeliness requirements. Auditor?s Addendum Segregating the duties between investigating and releasing a fraud hold in MyUI+ reduces the risk of an employee inappropriately and potentially fraudulently clearing the hold without conducting a proper investigation. The issues identified in our audit indicate that the Department?s current compensating controls did not identify that a current employee released fraud holds without a proper investigation. The Department should consider updating its procedures and processes to segregate these duties to reduce the risk of this occurring in the future.
(A) The Department agrees with this finding. The Department is moving all adjudication and investigation of program integrity holds into the MyUI+ system, so there will be one system of record. The Department will ensure that all program integrity holds have all documentation through adjudication and investigation, including log notes. The Department anticipates this to be fully implemented by July 2024. (B) The Department agrees with this finding. The department has modified processes to ensure all holds are only routed to the appropriate team to be adjudicated. In addition the Department is working to have all claims identified as fraud delivered in a workflow process in MyUI+ rather than the various processes in place now. Further the department is working with our MyUI+ system experts to implement new technology to strengthen and streamline the fraud indicator escalation process and systems within MyUI+. In working with our MyUI+ system experts, the Department anticipates this to be fully implemented by July 2024. (C) The Department agrees with this finding. The Department will continue strengthening security in this area and internal procedures to periodically monitor the potential for internal fraud activities. Additionally, the Department will periodically monitor and review My UI+ access levels for appropriateness. In consultation with our MyUI+ systems experts, the Department anticipates this finding to be fully implemented by July 2024. (D) The Department agrees with this finding. The Department will reinforce and strengthen the ethics policies in yearly communication to staff and tighten escalation policies to ensure pressures and inappropriate requests are handled in accordance with guidelines. The Department anticipates this will be completed by July 2023. (E) When a PI hold is identified as being highly suspicious for criminally fraudulent activity, it is routed to a specialized unit for review, thereby leaving the standard adjudication process. This is handled by passing the review to the UI Investigations and/or Criminal Enforcement (ICE) unit. The investigator performs their investigation and if no actual fraudulent activity is found they will release the hold. The UI Division also performs several quality control reviews of claims and claim decisions via Benefits Payment Control (BPC), Benefits Accuracy Measurements (BAM), Benefits Timeliness and Quality (BTQ), and internal Quality Assurance (QA) reviews. Claims are reviewed for such criteria as adequate support documentation, benefit payment accuracy, timely processing, and correct claim decision determination on all program integrity holds. The Green Book states in Section 10.14, ? If segregation of duties is not practical within an operational process because of limited personnel or other factors, management designs alternative control activities to address the risk of fraud, waste, or abuse in the operational process.? CDLE believes the reviews represent adequate and sufficient compensating controls for the need for segregation of duties on fraud holds. Changing the current process would hinder our ability to deliver UI benefit services timely to our customers and would put us in jeopardy of fulfilling our federal and state payment timeliness requirements.
Finding 2022-071 Federal Funding Accountability and Transparency Act The Department is responsible for administering two programs as part of the Employment Service Cluster: Employment Service/Wagner Peyser Funded Activities (Wagner) [ALN 17.207], and Jobs for Veterans State Grant (JSVG) [ALN 17.801]. The main overall purpose of these programs is to improve the functioning of the nation's labor markets by bringing together individuals who are seeking employment and employers who are seeking workers. The Wagner program provides a variety of services to job seekers, including career services and job search assistances; in addition, employers can access the program to post job orders and obtain qualified applicants. The JSVG provides federal funding through a formula grant to State Workforce Agencies (SWAs), including the Department, to hire dedicated staff to provide individualized career and training-related service to veterans and eligible individuals with significant barriers to employment, and to assist employers in filling their workforce needs with job-seeking veterans. The Department administers the programs and also passes Employment Service Cluster funds through to Colorado counties so they can help provide these services to individuals. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for both programs within the Employment Service Cluster. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? In Fiscal Year 2022, the Department made 11 subawards to 10 Colorado counties (subrecipients) for the Employment Service Cluster, $11.2 million in subawards to 10 counties for Wagner, and $45,116 in subawards to one county for JVSG, totaling $11.3 million. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Employment Service Cluster programs during Fiscal Year 2022. As part of our audit work, we requested the Department?s policies and procedures over FFATA reporting, the FFATA reports submitted by the Department in Fiscal Year 2022, and a list of all subawards made by the Department during Fiscal Year 2022. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if an award or supplemental award equal to or greater than $30,000 was made in April 2022. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA reporting requirements for the Employment Cluster and did not report any subawards in FSRS for Fiscal Year 2022. Specifically, we determined that the Department did not report $11.21 million in subawards to 10 subrecipients (the counties) for Wagner, and $45,116 in subawards to one county for JVSG. The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did this problem occur? The Department was not aware of the FFATA reporting requirement because it did not review the federal grant agreements to determine that the requirement was applicable for the program. Why does this problem matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-071 The Department of Labor and Employment should implement appropriate internal controls and related processes, such as detailed reviews of federal grant agreements, over the Employment Service Cluster to ensure that it is aware of, and in compliance with all federal reporting requirements, including requirements under the Federal Funding Accountability and Transparency Act of 2006. Response Department of Labor and Employment Agree Implementation Date: February 2023 By the implementation date, the Department of Labor and Employment (CDLE) will complete a review of grant agreements for reporting requirements, including the Federal Funding Accountability and Transparency Act of 2006. By the implementation date, the CDLE will develop and implement appropriate controls and processes to come into compliance with the reporting requirements and submit FFATA reports for the 10 entities identified in the audit.
Show full finding ▾Hide full finding ▴Finding 2022-071 Federal Funding Accountability and Transparency Act The Department is responsible for administering two programs as part of the Employment Service Cluster: Employment Service/Wagner Peyser Funded Activities (Wagner) [ALN 17.207], and Jobs for Veterans State Grant (JSVG) [ALN 17.801]. The main overall purpose of these programs is to improve the functioning of the nation's labor markets by bringing together individuals who are seeking employment and employers who are seeking workers. The Wagner program provides a variety of services to job seekers, including career services and job search assistances; in addition, employers can access the program to post job orders and obtain qualified applicants. The JSVG provides federal funding through a formula grant to State Workforce Agencies (SWAs), including the Department, to hire dedicated staff to provide individualized career and training-related service to veterans and eligible individuals with significant barriers to employment, and to assist employers in filling their workforce needs with job-seeking veterans. The Department administers the programs and also passes Employment Service Cluster funds through to Colorado counties so they can help provide these services to individuals. The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for both programs within the Employment Service Cluster. The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. In accordance with the Transparency Act, the Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? In Fiscal Year 2022, the Department made 11 subawards to 10 Colorado counties (subrecipients) for the Employment Service Cluster, $11.2 million in subawards to 10 counties for Wagner, and $45,116 in subawards to one county for JVSG, totaling $11.3 million. The Department is required to submit FFATA information through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Employment Service Cluster programs during Fiscal Year 2022. As part of our audit work, we requested the Department?s policies and procedures over FFATA reporting, the FFATA reports submitted by the Department in Fiscal Year 2022, and a list of all subawards made by the Department during Fiscal Year 2022. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170.330.l(a)], the Department is required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2022 if an award or supplemental award equal to or greater than $30,000 was made in April 2022. What problem did the audit work identify? Based on our audit work, we determined that the Department did not comply with FFATA reporting requirements for the Employment Cluster and did not report any subawards in FSRS for Fiscal Year 2022. Specifically, we determined that the Department did not report $11.21 million in subawards to 10 subrecipients (the counties) for Wagner, and $45,116 in subawards to one county for JVSG. The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Why did this problem occur? The Department was not aware of the FFATA reporting requirement because it did not review the federal grant agreements to determine that the requirement was applicable for the program. Why does this problem matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, it fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-071 The Department of Labor and Employment should implement appropriate internal controls and related processes, such as detailed reviews of federal grant agreements, over the Employment Service Cluster to ensure that it is aware of, and in compliance with all federal reporting requirements, including requirements under the Federal Funding Accountability and Transparency Act of 2006. Response Department of Labor and Employment Agree Implementation Date: February 2023 By the implementation date, the Department of Labor and Employment (CDLE) will complete a review of grant agreements for reporting requirements, including the Federal Funding Accountability and Transparency Act of 2006. By the implementation date, the CDLE will develop and implement appropriate controls and processes to come into compliance with the reporting requirements and submit FFATA reports for the 10 entities identified in the audit.
By the implementation date, the Department of Labor and Employment (CDLE) will complete a review of grant agreements for reporting requirements, including the Federal Funding Accountability and Transparency Act of 2006. By the implementation date, the CDLE will develop and implement appropriate controls and processes to come into compliance with the reporting requirements and submit FFATA reports for the 10 entities identified in the audit.
Finding 2022-072 MyUI+ and Connecting Colorado?Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance and Employment Service Cluster programs, and the Department relies on IT systems to aid with determining applicants? eligibility for the programs and to provide information necessary to meet federal reporting requirements. For these two programs, the associated systems are MyUI+ and Connecting Colorado. The Department is the business owner and works with the Governor?s Office of Information Technology (OIT) and two different external IT service providers. High level descriptions of the two systems are as follows: ? MyUI+ ? The Department?s system for UI eligibility determinations and calculation of UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ will also provide data necessary for federal reporting to the U.S. Department of Labor for the UI program that was previously generated by the Colorado Labor and Employment Accounting Resource system. ? Connecting Colorado ? The Department?s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to staff responsible, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department, OIT, and the Department?s two external IT service providers for MyUI+ and Connecting Colorado had policies and procedures related to information security, designed and implemented for MyUI+ and Connecting Colorado. Our audit work was performed through interviews conducted of Department and OIT staff. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2022, we identified information security problems with the MyUI+ and Connecting Colorado systems. We have grouped these problems first by those common to the two systems and then those unique to each system. MyUI+ and Connecting Colorado Common Problems ? Policies and procedures were lacking. Department management had not established its expectations through the development and implementation of formalized policies and procedures related to information security general controls for MyUI+ and Connecting Colorado. o Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO) states in Paragraph 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraph 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity?s information system, including information system general controls that facilitate the proper operation of the entity?s systems. o Colorado Information Security Policies (Security Policies or CISP) that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy and the General Responsibilities sections, specifically 8.3.1 and 8.3.2 for Business Owners or the Department, that all agencies, except for the institutions of higher education and the general assembly, as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for its systems, as the business owner, and is responsible for following and adhering to all identified business owner requirements, as stated within the Security Policies. ? Vendor oversight was lacking. The Department had not ensured its IT service providers complied with Security Policies. o Security Policies state that IT service providers?defined as OIT and/or external service providers?must follow the Security Policy requirements, among certain other requirements, as communicated to the Department within the confidential finding. o Section C.iii. (Legal Authority ? Contractor Signatory, Information Technology Specific) of the Department?s contract with the Connecting Colorado IT service provider states: ??the contractor warrants that it will at all times comply with all Security Policies.? o Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department?s contract with the MyUI+ IT service provider states: ??the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor?s Office of Information Technology.? o The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. MyUI+ and Connecting Colorado Unique Problems We also found other problems with access management, unique to each MyUI+ and Connecting Colorado, that lacked compliance with Security Policies, OIT Cyber Policies, and the IRS?s, Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, November 2021 Revision, and were communicated through the confidential finding. Why did these problems occur? Overall, the Department did not have sufficient IT governance and information security internal controls in place, including policies and procedures, to ensure that Department staff and its IT service providers complied with various data security compliance requirements set forth by OIT and the IRS, as well as those internal control principles established within the Green Book?s internal control framework. We discuss other specific causes for the problems we identified below: MyUI+ and Connecting Colorado ? Policies and procedures were lacking (MyUI+). Department staff stated that they followed and complied with the October 2021 dated Security Policies for the entire fiscal year, as these were more stringent than the March 2022 dated Security Policies. However, the Department did not provide documentation of a formal adoption of the October 2021 dated Security Policies. Staff also stated it maintains informal procedures of how to perform certain access management processes, but no standard operating procedures were in place. ? Policies and procedures were lacking (Connecting Colorado). Department staff had released a program guidance letter that addressed data security and access, but staff acknowledged that these program guidance letters are a guide and not official policy statements. In addition, the program guidance letter provided by Department staff was directed to the workforce centers that are located across the state that provide employment services to eligible beneficiaries and, therefore, did not provide any data security or access policies and procedures for state staff. ? Vendor oversight was lacking. We determined the Department did not have a vendor management process in place to hold its IT service providers accountable for contract provisions that required the IT service providers to comply with Security Policies, as demonstrated by the noncompliance issues we identified. In addition, and based on the March 2022 Security Policies, the Department has not determined whether contract amendments may be necessary with its two external IT service providers. ? Other Access Management Non-Compliance: o Department staff indicated that in one instance of non-compliance identified, a more efficient process was to not comply with the requirement. o Department staff stated that the certain access management non-compliance area was set up as it was during the COVID-19 pandemic to help prevent backlogs and issues for users during that time and was not subsequently changed. o Department staff did not update its rules for Connecting Colorado account management non-compliance area to reflect Security Policy changes. Specifically, we noted that OIT introduced the specific account management requirements in its Security Policies in February 2015, and those requirements remained constant through the March 2022 version; however, Department staff did not have a process in place to ensure periodic reviews of OIT?s Security Policies occurred and Department rules for the workforce centers appropriately aligned with any Security Policy changes. In addition, Department staff did not have a process in place to ensure its external IT service providers were complying with contract provisions to comply with Security Policy requirements. o Department staff stated they have not found cause to mandate IT service provider actions that are deemed privately owned business methodologies. However, and as noted above, the Department?s contract states that the external IT service provider must comply with OIT?s Security Policies that require specific security safeguards to be implemented by all IT service providers, including the Connecting Colorado external IT service provider. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management?s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security measures are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately impacts data reliability of the data stored and processed within MyUI+ and Connecting Colorado. Lastly, without having a strong internal control framework in place, management cannot ensure that state and federal funds are being used appropriately, which may impact the Department?s compliance with federal grant requirements and/or the accuracy of the Department?s federal and financial reporting. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-072 The Department of Labor and Employment (Department) should improve its overall Information Technology (IT) governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ and Connecting Colorado information systems by: A. Formalizing and communicating to Department staff and the Department?s IT service providers? IT policies that comply with the Business Owner requirements listed within the Governor?s Office of Information Technology?s (OIT) March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. B. Formalizing and communicating IT procedures to provide guidance to Department staff and the Department?s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT?s Security Policies to ensure the Department?s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing a vendor management process that ensures the Department?s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department?s current external IT service providers? contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Implementing recommendation Part E as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. B. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. C. Agree Implementation Date: December 2023 CDLE agrees with the recommendation and as part of A and B recommendations of this document, the Department will include a requirement from vendors to affirm they have reviewed and will comply with OIT security policies for all new contracts. Furthermore, as the Department becomes aware of changes to OIT Security Policies through its annual review process, these will be communicated to the vendors, and they will be required to reaffirm their compliance with any applicable changes. We will work with our current vendors for MyUI+ and Connecting Colorado to address the compliance issues noted in the audit and ensure they are compliant with OIT Security Policies and IT policies developed in part A and B of this recommendation. If non-compliance is determined to be unavoidable, the Department will file for a security exception with OIT. D. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part D as noted in the confidential finding. E. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
Show full finding ▾Hide full finding ▴Finding 2022-072 MyUI+ and Connecting Colorado?Information Security Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department administers the federal Unemployment Insurance and Employment Service Cluster programs, and the Department relies on IT systems to aid with determining applicants? eligibility for the programs and to provide information necessary to meet federal reporting requirements. For these two programs, the associated systems are MyUI+ and Connecting Colorado. The Department is the business owner and works with the Governor?s Office of Information Technology (OIT) and two different external IT service providers. High level descriptions of the two systems are as follows: ? MyUI+ ? The Department?s system for UI eligibility determinations and calculation of UI payments to eligible recipients. According to Department staff, starting in Fiscal Year 2023, MyUI+ will also provide data necessary for federal reporting to the U.S. Department of Labor for the UI program that was previously generated by the Colorado Labor and Employment Accounting Resource system. ? Connecting Colorado ? The Department?s workforce case management, labor exchange, and federal reporting system that supports the Employment Service Cluster program. The system provides services for job seekers and businesses, as well as provides all required federal reporting to the U.S. Department of Labor, for the Employment Service Cluster programs. In order for the Department to achieve its objectives and respond to risks, including those related to the federal programs it administers, management should establish a strong framework of internal controls that also address information system controls. Specifically, information system controls typically start with management documenting IT policies that address IT general control responsibilities and procedures that document the more granular details on how to implement Department policies. These IT general control policies and procedures should include those policies and procedures that are specific to information security. Once policies and procedures have been formalized and communicated to staff responsible, specific internal control activities can be implemented and operationalized. What was the purpose of our audit work and what work was performed? The purpose of our Fiscal Year 2022 audit work was to determine whether the Department, OIT, and the Department?s two external IT service providers for MyUI+ and Connecting Colorado had policies and procedures related to information security, designed and implemented for MyUI+ and Connecting Colorado. Our audit work was performed through interviews conducted of Department and OIT staff. What problems did the audit work identify and how were the results of the audit work measured? During Fiscal Year 2022, we identified information security problems with the MyUI+ and Connecting Colorado systems. We have grouped these problems first by those common to the two systems and then those unique to each system. MyUI+ and Connecting Colorado Common Problems ? Policies and procedures were lacking. Department management had not established its expectations through the development and implementation of formalized policies and procedures related to information security general controls for MyUI+ and Connecting Colorado. o Standards for Internal Control in the Federal Government (Green Book) published by the U.S. Government Accountability Office (GAO) states in Paragraph 3.09, Documentation of Internal Control System, and 12.02, Documentation of Responsibilities through Policies, that management should develop and maintain documentation of its internal control system and document in policies the internal control responsibilities of the organization. Paragraph 11.06 and 11.07, Design Appropriate Types of Control Activities, states that management should design appropriate types of control activities in the entity?s information system, including information system general controls that facilitate the proper operation of the entity?s systems. o Colorado Information Security Policies (Security Policies or CISP) that are developed, published, and required to be followed by the Department and its external IT service providers state within the Policy and the General Responsibilities sections, specifically 8.3.1 and 8.3.2 for Business Owners or the Department, that all agencies, except for the institutions of higher education and the general assembly, as the business owner, must implement governance principles, which would include IT policies and procedures, for promoting data quality and integrity for its systems, as the business owner, and is responsible for following and adhering to all identified business owner requirements, as stated within the Security Policies. ? Vendor oversight was lacking. The Department had not ensured its IT service providers complied with Security Policies. o Security Policies state that IT service providers?defined as OIT and/or external service providers?must follow the Security Policy requirements, among certain other requirements, as communicated to the Department within the confidential finding. o Section C.iii. (Legal Authority ? Contractor Signatory, Information Technology Specific) of the Department?s contract with the Connecting Colorado IT service provider states: ??the contractor warrants that it will at all times comply with all Security Policies.? o Exhibit C, Section 1.C.vi. (Information Technology Provisions, Protection of System Data) of the Department?s contract with the MyUI+ IT service provider states: ??the contractor shall comply with all rules, policies, procedures, and standards issued by the Governor?s Office of Information Technology.? o The Green Book states in Paragraph OV4.01, Service Organizations, that management retains responsibility for the performance of processes assigned to service organizations. MyUI+ and Connecting Colorado Unique Problems We also found other problems with access management, unique to each MyUI+ and Connecting Colorado, that lacked compliance with Security Policies, OIT Cyber Policies, and the IRS?s, Publication 1075, Tax Information Security Guidelines for Federal, State, and Local Agencies, November 2021 Revision, and were communicated through the confidential finding. Why did these problems occur? Overall, the Department did not have sufficient IT governance and information security internal controls in place, including policies and procedures, to ensure that Department staff and its IT service providers complied with various data security compliance requirements set forth by OIT and the IRS, as well as those internal control principles established within the Green Book?s internal control framework. We discuss other specific causes for the problems we identified below: MyUI+ and Connecting Colorado ? Policies and procedures were lacking (MyUI+). Department staff stated that they followed and complied with the October 2021 dated Security Policies for the entire fiscal year, as these were more stringent than the March 2022 dated Security Policies. However, the Department did not provide documentation of a formal adoption of the October 2021 dated Security Policies. Staff also stated it maintains informal procedures of how to perform certain access management processes, but no standard operating procedures were in place. ? Policies and procedures were lacking (Connecting Colorado). Department staff had released a program guidance letter that addressed data security and access, but staff acknowledged that these program guidance letters are a guide and not official policy statements. In addition, the program guidance letter provided by Department staff was directed to the workforce centers that are located across the state that provide employment services to eligible beneficiaries and, therefore, did not provide any data security or access policies and procedures for state staff. ? Vendor oversight was lacking. We determined the Department did not have a vendor management process in place to hold its IT service providers accountable for contract provisions that required the IT service providers to comply with Security Policies, as demonstrated by the noncompliance issues we identified. In addition, and based on the March 2022 Security Policies, the Department has not determined whether contract amendments may be necessary with its two external IT service providers. ? Other Access Management Non-Compliance: o Department staff indicated that in one instance of non-compliance identified, a more efficient process was to not comply with the requirement. o Department staff stated that the certain access management non-compliance area was set up as it was during the COVID-19 pandemic to help prevent backlogs and issues for users during that time and was not subsequently changed. o Department staff did not update its rules for Connecting Colorado account management non-compliance area to reflect Security Policy changes. Specifically, we noted that OIT introduced the specific account management requirements in its Security Policies in February 2015, and those requirements remained constant through the March 2022 version; however, Department staff did not have a process in place to ensure periodic reviews of OIT?s Security Policies occurred and Department rules for the workforce centers appropriately aligned with any Security Policy changes. In addition, Department staff did not have a process in place to ensure its external IT service providers were complying with contract provisions to comply with Security Policy requirements. o Department staff stated they have not found cause to mandate IT service provider actions that are deemed privately owned business methodologies. However, and as noted above, the Department?s contract states that the external IT service provider must comply with OIT?s Security Policies that require specific security safeguards to be implemented by all IT service providers, including the Connecting Colorado external IT service provider. Why do these problems matter? The lack of established IT policies and procedures make it difficult for Department management to measure and hold staff accountable to management?s expectations, as well as ensuring risks are addressed and overall objectives and missions are fulfilled. In turn, without policies and procedures, staff may not perform processes and controls in a consistent manner. In addition, without holding vendors accountable and ensuring that strong security measures are designed, implemented, and operating effectively, the risk of unauthorized access increases and ultimately impacts data reliability of the data stored and processed within MyUI+ and Connecting Colorado. Lastly, without having a strong internal control framework in place, management cannot ensure that state and federal funds are being used appropriately, which may impact the Department?s compliance with federal grant requirements and/or the accuracy of the Department?s federal and financial reporting. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-072 The Department of Labor and Employment (Department) should improve its overall Information Technology (IT) governance and information security IT general controls, and work with its IT service providers, as applicable, for the MyUI+ and Connecting Colorado information systems by: A. Formalizing and communicating to Department staff and the Department?s IT service providers? IT policies that comply with the Business Owner requirements listed within the Governor?s Office of Information Technology?s (OIT) March 2022 Colorado Information Security Policies (Security Policies). As an option, the Department could formally adopt the October 2021 Security Policies, identify any gaps between the October 2021 and March 2022 versions, and then formalize and communicate policies that address the identified gaps. B. Formalizing and communicating IT procedures to provide guidance to Department staff and the Department?s IT service providers performing IT general control activities that further address the IT policies formalized in recommendation Part A. The formalization and communication should include an organizationally defined, periodic review process of OIT?s Security Policies to ensure the Department?s IT policies, procedures, and rules are updated accordingly to align with the most current version of the Security Policies. C. Formalizing a vendor management process that ensures the Department?s IT service providers are held accountable to contract provisions requiring compliance with Colorado Information Security Policies and IT policies and procedures formalized in recommendation Parts A and B. This should include a review of the Department?s current external IT service providers? contracts and a determination of whether amendments to those contracts are necessary, based on the formalization of recommendation Parts A and B. D. Implementing recommendation Part D as noted in the confidential finding. E. Implementing recommendation Part E as noted in the confidential finding. Response Department of Labor and Employment A. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. B. Agree Implementation Date: July 2023 The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. C. Agree Implementation Date: December 2023 CDLE agrees with the recommendation and as part of A and B recommendations of this document, the Department will include a requirement from vendors to affirm they have reviewed and will comply with OIT security policies for all new contracts. Furthermore, as the Department becomes aware of changes to OIT Security Policies through its annual review process, these will be communicated to the vendors, and they will be required to reaffirm their compliance with any applicable changes. We will work with our current vendors for MyUI+ and Connecting Colorado to address the compliance issues noted in the audit and ensure they are compliant with OIT Security Policies and IT policies developed in part A and B of this recommendation. If non-compliance is determined to be unavoidable, the Department will file for a security exception with OIT. D. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part D as noted in the confidential finding. E. Agree Implementation Date: June 2023 CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
(A) The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. (B) The Department will formalize IT security policies and procedures to comply with the Business Owner requirements contained within the Governor's Office of Information Technology's (OIT) March 2022, Colorado Information Security Policies. The Department will further formalize a procedure for product owners to annually review the OIT Colorado Information Security Policies and ensure alignment with the formalized Department IT policies and update any affected formalized IT procedures. The Department will communicate the formalized policies and procedures to Department staff and IT Service Providers, and then any future changes, as deemed necessary. (C) CDLE agrees with the recommendation and as part of A and B recommendations of this document, the Department will include a requirement from vendors to affirm they have reviewed and will comply with OIT security policies for all new contracts. Furthermore, as the Department becomes aware of changes to OIT Security Policies through its annual review process, these will be communicated to the vendors, and they will be required to reaffirm their compliance with any applicable changes. We will work with our current vendors for MyUI+ and Connecting Colorado to address the compliance issues noted in the audit and ensure they are compliant with OIT Security Policies and IT policies developed in part A and B of this recommendation. If non-compliance is determined to be unavoidable, the Department will file for a security exception with OIT. (D) CDLE agrees with the recommendation and will implement recommendation Part D as noted in the confidential finding. (E) CDLE agrees with the recommendation and will implement recommendation Part E as noted in the confidential finding.
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-063 Unemployment Insurance?Federal Reporting The Department?s Accounting Section is responsible for completing the following two federal financial reports for the UI program and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Accounting Section uses bank statements and reports from the Colorado Operations Resource Engine (CORE), the State?s accounting system, to create a workbook with the information and uses that workbook to complete the reports. ? ETA 9130, Financial Status Report, UI Programs. This is a quarterly report used to report the Department?s UI program and administrative expenditures. Financial data is required to be reported cumulatively from grant inception through the end of the reporting period. ? ETA 2112, UI Financial Transaction Summary. This is a monthly report that is a summary of the UI program?s transactions, which account for all funds received in, passed through, or paid out of the state employment fund during the applicable month. The UI division is responsible for completing the following federal report for the UI program and ensuring the report is accurate, complete, and submitted to the federal government by the required timeline. The UI division uses data pulled from MyUI+, the UI claims and benefits system, to generate two reports to fill out the ETA 191 report, described as follows. ? ETA 191, Financial Status of UCFE/UCX. This is a quarterly report on the State?s unemployment compensation expenditures paid by the Department to former federal employees (UCFE) and ex-service members (UCX) who have filed with the Department for unemployment benefits, and total amount of benefits paid to claimants of specific federal agencies. The federal government uses this report to request reimbursement of UCFE and UCX benefit payments from federal and military agencies. The federal government reimburses the Department for these benefit payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over and complied with federal reporting requirements for the UI program during Fiscal Year 2021. As part of our audit work, we gained an understanding of the Department?s procedures that were in place to prepare the federal reports. In addition, we reviewed four ETA 2112 reports and two ETA 191 reports submitted to the federal government for Fiscal Year 2021 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Department?s policies and procedures for completing the reports, as well as the Department?s supporting documentation for the reports. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the OSC?s policy Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The U.S. Department of Labor Unemployment Insurance Handbook 401 (Handbook) states that the ETA 2112 is due the first day of the second month following the month that the data in the report represents. In addition, the Handbook states that the ETA 191 is due by the 25th of the month following the close of the quarter. What problems did the audit work identify? We identified issues with 2 of the 4 (50 percent) ETA 2112 reports we tested, and 1 of the 2 (50 percent) ETA 191 reports we tested. Specifically, we identified the following: ETA 2112. We identified four issues with the September 2020 report, as follows: ? The Department could not provide support for $50.6 million reported as federal tax withholding on the report. ? The Department could not provide documentation related to the FPUC deposits and disbursements reported on the report. Specifically, the Department reported FPUC deposits as $27.0 million and FPUC Disbursements as $28.4 million. Because the Department could not provide documentation, we could not determine the correct amounts that should have been reported. ? The Department overstated the deposit amount for the intra-account transfer line by $240.2 million. Specifically, the Department reported that the amount deposited during the month for the intra-account transfers was $378.1 million, but the supporting documentation we reviewed showed the deposits totaled $137.9 million. ? The Department submitted the report on November 5, 2020, or 3 days after the deadline of November 2, 2020. In the February 2021 report, we identified that the Department understated reimbursement benefits from nonprofits by $540,000, reimbursements from local governments by $1.1 million; and reimbursements from state government by $204,700. Finally, based on discussion with the Department, it does not protect the formulas in its ETA 2112 workbooks it uses to prepare the reports in order to prevent intentional or inadvertent changes to calculations. ETA 191. We identified two issues with the ETA 191 report for the quarter ended March 2021 report. First, the Department failed to appropriately correct a federal Department of Labor-identified error from the previous quarter for expenditures for military agencies. Specifically, the Department incorrectly adjusted the $1,089,761, by $2,100, which was an under correction of the error of $2,120. Second, the Department submitted the report on May 14, 2021, nearly a month after the April 16, 2021, deadline. Why did these problems occur? The Department did not have sufficient internal controls in place to ensure that the federal reports and associated documentation were accurate and complete during Fiscal Year 2021. Specifically, the Department does not have formal, documented policies for completing the reports or a requirement that the workbooks are protected. Although the Department has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to the wrong information being input into the reports, which a review could have caught and corrected prior to the Department submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including formal, documented policies, protection of formulas in the workbooks used to prepare the reports to prevent intentional or inadvertent changes to calculations, and adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause the users of these reports to rely on incorrect information. This could have a negative impact on the Department?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-063 The Department of Labor and Employment should strengthen its internal controls over federal reporting by developing, formally documenting, and implementing policies for completing its federal reports for the Unemployment Insurance program. These policies should require the workbooks used to prepare the reports to be protected and that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: March 2023 CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-063 Unemployment Insurance?Federal Reporting The Department?s Accounting Section is responsible for completing the following two federal financial reports for the UI program and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Accounting Section uses bank statements and reports from the Colorado Operations Resource Engine (CORE), the State?s accounting system, to create a workbook with the information and uses that workbook to complete the reports. ? ETA 9130, Financial Status Report, UI Programs. This is a quarterly report used to report the Department?s UI program and administrative expenditures. Financial data is required to be reported cumulatively from grant inception through the end of the reporting period. ? ETA 2112, UI Financial Transaction Summary. This is a monthly report that is a summary of the UI program?s transactions, which account for all funds received in, passed through, or paid out of the state employment fund during the applicable month. The UI division is responsible for completing the following federal report for the UI program and ensuring the report is accurate, complete, and submitted to the federal government by the required timeline. The UI division uses data pulled from MyUI+, the UI claims and benefits system, to generate two reports to fill out the ETA 191 report, described as follows. ? ETA 191, Financial Status of UCFE/UCX. This is a quarterly report on the State?s unemployment compensation expenditures paid by the Department to former federal employees (UCFE) and ex-service members (UCX) who have filed with the Department for unemployment benefits, and total amount of benefits paid to claimants of specific federal agencies. The federal government uses this report to request reimbursement of UCFE and UCX benefit payments from federal and military agencies. The federal government reimburses the Department for these benefit payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over and complied with federal reporting requirements for the UI program during Fiscal Year 2021. As part of our audit work, we gained an understanding of the Department?s procedures that were in place to prepare the federal reports. In addition, we reviewed four ETA 2112 reports and two ETA 191 reports submitted to the federal government for Fiscal Year 2021 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Department?s policies and procedures for completing the reports, as well as the Department?s supporting documentation for the reports. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the OSC?s policy Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The U.S. Department of Labor Unemployment Insurance Handbook 401 (Handbook) states that the ETA 2112 is due the first day of the second month following the month that the data in the report represents. In addition, the Handbook states that the ETA 191 is due by the 25th of the month following the close of the quarter. What problems did the audit work identify? We identified issues with 2 of the 4 (50 percent) ETA 2112 reports we tested, and 1 of the 2 (50 percent) ETA 191 reports we tested. Specifically, we identified the following: ETA 2112. We identified four issues with the September 2020 report, as follows: ? The Department could not provide support for $50.6 million reported as federal tax withholding on the report. ? The Department could not provide documentation related to the FPUC deposits and disbursements reported on the report. Specifically, the Department reported FPUC deposits as $27.0 million and FPUC Disbursements as $28.4 million. Because the Department could not provide documentation, we could not determine the correct amounts that should have been reported. ? The Department overstated the deposit amount for the intra-account transfer line by $240.2 million. Specifically, the Department reported that the amount deposited during the month for the intra-account transfers was $378.1 million, but the supporting documentation we reviewed showed the deposits totaled $137.9 million. ? The Department submitted the report on November 5, 2020, or 3 days after the deadline of November 2, 2020. In the February 2021 report, we identified that the Department understated reimbursement benefits from nonprofits by $540,000, reimbursements from local governments by $1.1 million; and reimbursements from state government by $204,700. Finally, based on discussion with the Department, it does not protect the formulas in its ETA 2112 workbooks it uses to prepare the reports in order to prevent intentional or inadvertent changes to calculations. ETA 191. We identified two issues with the ETA 191 report for the quarter ended March 2021 report. First, the Department failed to appropriately correct a federal Department of Labor-identified error from the previous quarter for expenditures for military agencies. Specifically, the Department incorrectly adjusted the $1,089,761, by $2,100, which was an under correction of the error of $2,120. Second, the Department submitted the report on May 14, 2021, nearly a month after the April 16, 2021, deadline. Why did these problems occur? The Department did not have sufficient internal controls in place to ensure that the federal reports and associated documentation were accurate and complete during Fiscal Year 2021. Specifically, the Department does not have formal, documented policies for completing the reports or a requirement that the workbooks are protected. Although the Department has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to the wrong information being input into the reports, which a review could have caught and corrected prior to the Department submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including formal, documented policies, protection of formulas in the workbooks used to prepare the reports to prevent intentional or inadvertent changes to calculations, and adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause the users of these reports to rely on incorrect information. This could have a negative impact on the Department?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-063 The Department of Labor and Employment should strengthen its internal controls over federal reporting by developing, formally documenting, and implementing policies for completing its federal reports for the Unemployment Insurance program. These policies should require the workbooks used to prepare the reports to be protected and that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: March 2023 CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
2021-063
Finding 2022-074 Coronavirus Relief Funds?Property Owner Preservation Program The President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020 and Congress subsequently passed the Coronavirus Aid, Relief, and Economic Security (CARES) Act. The CARES Act provided emergency assistance in response to the COVID-19 pandemic and established the Coronavirus Relief Fund (CRF) program, which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of CRF funds in April 2020, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the CRF funds to numerous state departments and agencies. In June 2020, the State passed House Bill 20-1410, concerning assistance for individuals facing a housing-related hardship due to the COVID-19 pandemic, and transferred approximately $19.7 million of CRF funds to the Housing Development Grant Fund to provide such assistance. This bill includes a provision for the Property Owners Preservation Program (Program), which was managed by the Department, to allow landlords and property owners to seek rental assistance on behalf of their tenants who experienced a financial need on or after March 1, 2020, due to the effects of the COVID-19 pandemic. In Fiscal Year 2021, the Department expended the $19.7 million of the CRF funds it received in April 2020, for the Property Owners Preservation Program (POPP). What was the purpose of our audit work and what work was performed? The purpose of the audit work was to follow up on our prior year audit recommendation, which recommended that the Department implement internal controls to ensure it complies with federal regulations for any new federal funds it receives, such as the CRF. The Department planned to implement this recommendation by June 2022. During the Fiscal Year 2022 audit, we inquired with the Department on the implementation status of this recommendation. We also obtained and reviewed the Department?s Exhibit K3, Schedule of Prior Year Audit Recommendation Status, which it was required to submit to the State Controller. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Under House Bill 20-1410, the Housing Development Grant Fund was appropriated $19,650,000 of funds from the CRF for the purpose of providing individuals and households who, on or after March 1, 2020, experienced financial need due to the COVID-19 pandemic or effects of the COVID-19 pandemic, with rental assistance. The House Bill also provided guidance on how to access additional housing services. The Department developed and issued a new application for the POPP to address the criteria for experiencing direct or indirect impacts of the COVID-19 pandemic. ? Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, the Department must determine that amounts paid with federal grant funds were necessary and reasonable for the performance of the federal award and are adequately documented. Therefore, the Department must maintain appropriate supporting documentation to verify costs were properly charged to the federal grants. ? The Office of the State Controller (OSC) requires each department that had a prior audit recommendation that was reported in the prior fiscal year?s Office of the State Auditor Statewide audit to complete an Exhibit K3 to report the Department?s determination of the status of their recommendation as of June 30. Possible status descriptions include ?Implemented,? ?Partially Implemented,? ?Not Implemented,? and ?No Longer Valid.? The Department must provide an explanation for each recommendation status. What problem did the audit work identify? We determined that the Department did not implement the prior year?s recommendation by its planned implementation date of June 2022. Specifically, during prior year audit work, we found that the Department could not provide appropriate underlying support for 4 of the 60 transactions (7 percent) we tested that were charged as CRF expenditures for the Program; as a result, we recommended that the Department strengthen its internal controls over federal grant spending, including that it develop and implement policies and procedures with a requirement that Department staff review and maintain records supporting its expenditures charged to federal programs. When we inquired of the Department about what steps it had taken to implement the recommendation, Department staff indicated that they did not implement the recommendation during Fiscal Year 2022. Why did this problem occur? The Department reported on its Exhibit K3 that it determined that the original implementation date of June 2022 that the Department provided as its planned implementation date for our Fiscal Year 2021 recommendation was unrealistic, given the Department?s staffing challenges. Specifically, the Department indicated that it was not able to allocate sufficient time to develop and implement the recommended policy and procedure guidance by the end of Fiscal Year 2022. Why does this problem matter? The Department?s lack of sufficient internal controls over the maintenance of complete and accurate records for the federal CRF monies could result in inadequate documentation to support its payments and ultimately, disallowed federal costs and potential sanctions. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-074 The Department of Local Affairs (Department) should implement internal controls to ensure it complies with federal regulations, specifically for activities allowed or unallowed and allowable costs/cost principles, for any new federal funds it receives, such as the Coronavirus Relief Fund. This should include developing and implementing policies and procedures that include a requirement that Department staff review and maintain records supporting the expenditures charged to the federal program. Response Department of Local Affairs Agree Implementation Date: September 2022 The Division of Housing within the Department of Local Affairs has implemented internal controls to ensure compliance with federal regulations for new federal funds, including the development of a standard procedure and the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
Show full finding ▾Hide full finding ▴Finding 2022-074 Coronavirus Relief Funds?Property Owner Preservation Program The President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020 and Congress subsequently passed the Coronavirus Aid, Relief, and Economic Security (CARES) Act. The CARES Act provided emergency assistance in response to the COVID-19 pandemic and established the Coronavirus Relief Fund (CRF) program, which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of CRF funds in April 2020, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the CRF funds to numerous state departments and agencies. In June 2020, the State passed House Bill 20-1410, concerning assistance for individuals facing a housing-related hardship due to the COVID-19 pandemic, and transferred approximately $19.7 million of CRF funds to the Housing Development Grant Fund to provide such assistance. This bill includes a provision for the Property Owners Preservation Program (Program), which was managed by the Department, to allow landlords and property owners to seek rental assistance on behalf of their tenants who experienced a financial need on or after March 1, 2020, due to the effects of the COVID-19 pandemic. In Fiscal Year 2021, the Department expended the $19.7 million of the CRF funds it received in April 2020, for the Property Owners Preservation Program (POPP). What was the purpose of our audit work and what work was performed? The purpose of the audit work was to follow up on our prior year audit recommendation, which recommended that the Department implement internal controls to ensure it complies with federal regulations for any new federal funds it receives, such as the CRF. The Department planned to implement this recommendation by June 2022. During the Fiscal Year 2022 audit, we inquired with the Department on the implementation status of this recommendation. We also obtained and reviewed the Department?s Exhibit K3, Schedule of Prior Year Audit Recommendation Status, which it was required to submit to the State Controller. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Under House Bill 20-1410, the Housing Development Grant Fund was appropriated $19,650,000 of funds from the CRF for the purpose of providing individuals and households who, on or after March 1, 2020, experienced financial need due to the COVID-19 pandemic or effects of the COVID-19 pandemic, with rental assistance. The House Bill also provided guidance on how to access additional housing services. The Department developed and issued a new application for the POPP to address the criteria for experiencing direct or indirect impacts of the COVID-19 pandemic. ? Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, the Department must determine that amounts paid with federal grant funds were necessary and reasonable for the performance of the federal award and are adequately documented. Therefore, the Department must maintain appropriate supporting documentation to verify costs were properly charged to the federal grants. ? The Office of the State Controller (OSC) requires each department that had a prior audit recommendation that was reported in the prior fiscal year?s Office of the State Auditor Statewide audit to complete an Exhibit K3 to report the Department?s determination of the status of their recommendation as of June 30. Possible status descriptions include ?Implemented,? ?Partially Implemented,? ?Not Implemented,? and ?No Longer Valid.? The Department must provide an explanation for each recommendation status. What problem did the audit work identify? We determined that the Department did not implement the prior year?s recommendation by its planned implementation date of June 2022. Specifically, during prior year audit work, we found that the Department could not provide appropriate underlying support for 4 of the 60 transactions (7 percent) we tested that were charged as CRF expenditures for the Program; as a result, we recommended that the Department strengthen its internal controls over federal grant spending, including that it develop and implement policies and procedures with a requirement that Department staff review and maintain records supporting its expenditures charged to federal programs. When we inquired of the Department about what steps it had taken to implement the recommendation, Department staff indicated that they did not implement the recommendation during Fiscal Year 2022. Why did this problem occur? The Department reported on its Exhibit K3 that it determined that the original implementation date of June 2022 that the Department provided as its planned implementation date for our Fiscal Year 2021 recommendation was unrealistic, given the Department?s staffing challenges. Specifically, the Department indicated that it was not able to allocate sufficient time to develop and implement the recommended policy and procedure guidance by the end of Fiscal Year 2022. Why does this problem matter? The Department?s lack of sufficient internal controls over the maintenance of complete and accurate records for the federal CRF monies could result in inadequate documentation to support its payments and ultimately, disallowed federal costs and potential sanctions. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-074 The Department of Local Affairs (Department) should implement internal controls to ensure it complies with federal regulations, specifically for activities allowed or unallowed and allowable costs/cost principles, for any new federal funds it receives, such as the Coronavirus Relief Fund. This should include developing and implementing policies and procedures that include a requirement that Department staff review and maintain records supporting the expenditures charged to the federal program. Response Department of Local Affairs Agree Implementation Date: September 2022 The Division of Housing within the Department of Local Affairs has implemented internal controls to ensure compliance with federal regulations for new federal funds, including the development of a standard procedure and the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
The Division of Housing within the Department of Local Affairs has implemented internal controls to ensure compliance with federal regulations for new federal funds, including the development of a standard procedure and the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
2021-065
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Local Affairs (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-066 Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs?Internal Controls over the Waiting List The Department annually receives advance payments from the federal government for the Housing Voucher Programs (Program) to provide tenant-based subsidies for rent paid by low-income households. A housing subsidy is paid to the landlord directly by the Department on behalf of the Program?s participants. During Fiscal Year 2021, the Department incurred approximately $62.9 million in federal costs for the Housing Voucher Programs. Federal regulation [24 CFR 982.54] requires the Department to have an administrative plan to establish policies for carrying out the Program in a manner consistent with the U.S. Department of Housing and Urban Development (HUD) requirements and local goals and objectives. HUD requires the Division of Housing (DOH), a section within the Department, to place all families that apply for assistance on a waiting list. DOH must select families from the waiting list and maintain clear records of all information required to verify that the family is selected from the waiting list according to HUD requirements and Department policies as stated in the Department?s administrative plan [24 CFR 982.204(b) and 982.207(e)]. The DOH maintains the waiting list in an electronic database within its Public Housing Agencies (PHA) Software, called Emphasys Elite. DOH has established preferences for order of selection off of the waiting list, and gives priority or first preference (point system) to serving families that meet various criteria, including someone experiencing homelessness, a person with a disability, households that include victims of domestic violence, etc. The second preference for selecting from the waiting list is based on when DOH placed the individual on the waiting list, by date and time. HUD may also award the Department funding for a specified category of families on the waiting list (targeted funding [24 CFR 982.204(e)]). DOH must use this funding only to assist families within the specified category allowed by the targeted funding. DOH administers the following types of targeted funding: Veterans Affairs Supporting Housing (VASH), Non-Elderly Disabled, Family Unification Program, and Family Self-Sufficiency. DOH delegates some of its voucher administration responsibilities, such as application reviews and interviews with applicants, to agencies that provide housing services to applicants and participants of the Program. These agencies, or contractors, include public housing authorities, community mental health centers, community centered boards or their contract service agencies, independent living centers, the Veterans Affairs Medical Center (VAMC), homeless service providers, and others. DOH will enter into a contract with these agencies that outline each party?s responsibilities. Contractors employ housing coordinators who assist applicants and participants to complete the necessary Program documentation and understand regulations to help them acquire and maintain units that conform to Program regulations. DOH provides each contractor with vouchers to give eligible applicants. When a contractor has available vouchers, it will ask the DOH to select and issue the next name(s) from its waiting list. DOH then uses its electronic database to select individuals from the waiting list. In order for an applicant to receive the voucher, the applicant must first attend an interview with the contractor. At the interview, the contractor will determine whether the applicant is eligible based on requiring the applicant to complete a full application and provide proof of income sources, social security number, citizenship status, release of information forms, federal or state-issued picture ID, and birth certificate, as well as the contractor?s verification of those items. If it is determined at the interview that the applicant is not eligible, the voucher will be terminated in the Emphasys Elite system and the voucher can be used for the next applicant in line on the waiting list. HUD regulations require that all families have an equal opportunity to apply for and receive housing assistance [24 CFR 982.53]. DOH must also have policies regarding various aspects of organizing and managing the waiting list of applicant families. This includes opening the list to new applicants, closing the list to new applicants, notifying the public of waiting list openings and closings, updating waiting list information, and removing families that are no longer interested in or eligible for assistance from the list. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements related to the Program?s waiting list during Fiscal Year 2021. We requested and obtained a report from the Department that showed all individuals that were added to the Program during Fiscal Year 2021. We selected and tested 40 of these individuals admitted to the Program during Fiscal Year 2021 to determine if they were selected from the waiting list in accordance with the Department?s applicant selection policies. We also requested and obtained another report from the Department that showed any individuals selected from the waiting list due to reaching the top position on the waiting list during Fiscal Year 2021, regardless of whether the individuals were added or not added to the Program. From this report, we selected and tested 40 different individuals to ascertain if they were admitted to the Program or provided the opportunity to be admitted to the Program in accordance with the Department?s applicant selection policies. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [24 CFR 5.410, 982.54(d), and 982.201 through 982.207] require the Department to have written policies in its administrative plan for selecting applicants from the waiting list and documentation must show that the Department follows these policies when selecting applicants for admission from the waiting list. Selection from the waiting list generally occurs when the Department notifies a family whose name reaches the top of the waiting list to come in to verify eligibility for admission to the Program. ? The Department?s administrative plan states that when a family wishes to receive assistance under the Program, the family must submit an application that provides DOH with the information needed to determine the family?s eligibility [HCV GB, pp. 4-11 ? 4-16, Notice PIH 2009-36]. ? Federal regulation [24 CFR 982.207] requires that DOH select applicant families from the waiting list first by preference and secondly by date and time of application. ? Federal regulations [24 CFR 982.554(a)] specify that when a family has been selected from the waiting list for an application interview, DOH and/or its contractor will notify the family and the family will be required to participate in the interview. The notice must inform the family of the date, time, and location of the scheduled application interview, who is required to attend the interview, and all documents that must be provided by the family at the interview. ? Federal regulations [24 CFR 982.201(f) and 982.204(c)] establish the rules for removing Program participants from the waiting list. If at any time an applicant family is on the waiting list and DOH determines that the family is not eligible for assistance, the family will be removed from the waiting list. Federal regulations further state the family may also remove itself from the waiting list at any time by requesting removal in writing. If a family is removed from the waiting list because DOH has determined the family is not eligible for assistance, a notice must be sent to the family?s address of record as well as to any alternate address provided on the initial application. The notice must state the reasons the family was removed from the waiting list and inform the family how to request an informal review regarding DOH?s decision. ? Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. What problems did the audit work identify? During our testing of 40 individuals admitted to the Program during Fiscal Year 2021, we found that the Department could not provide appropriate support for 5 of the 40 (12.5 percent) tenant files reviewed. Specifically: ? For five individuals, the Department could not provide documentation of the eligibility interview. ? For one of those five individuals, the Department also could not locate the individual?s application. During our testing of 40 individuals that the Department selected from the waiting list due to the individuals reaching the top of the waiting list during Fiscal Year 2021, we found certain issues with 8 of the 40 (20 percent) tenant files reviewed. Specifically: ? In five instances, individuals were selected from the waiting list out of turn; therefore, they were not at the top of the waiting list when selected, as required. ? In three instances, the Department could not provide the applications for the individuals. Why did these problems occur? The Department lacked internal controls over the Program?s waiting list. Specifically, the Department is not ensuring its contractors are maintaining supporting documentation within tenant files, including interview documentation and applications. Both the Department and its contractors experienced employee turnover in Fiscal Year 2021. Although the Department conducted monthly webinars for various training manuals, including the administrative plan, and made training materials available for future reference, new employees did not receive sufficient training to ensure the Department complied with Program requirements over the waiting list. In addition, the Department did not properly train the DOH employees on the policies and procedures for maintaining and selecting applicants from the waiting list, which ultimately led to applicants being incorrectly selected from the waiting list. Specifically, DOH did not properly update the waiting list for new applicants and addressing unused vouchers from prior selections, which caused individuals to be incorrectly selected from the waiting list. Why do these problems matter? By not maintaining the waiting list supporting documentation, including interview documentation and applications, the Department cannot ensure that all tenants are eligible or qualified to participate in the Program. The Department must ensure it maintains accurate and complete tenant files to demonstrate compliance with federal requirements. Additionally, by not training employees properly on the Department?s policies and procedures surrounding the waiting list, applicants are at risk of being improperly removed from the waiting list and not given the opportunity to receive funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-066 The Department of Local Affairs (Department) should strengthen its internal controls to ensure it complies with waiting list requirements for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include the Department developing and providing a training plan for its contractors that covers all of the programs? requirements on an ongoing basis. In addition, the Department should ensure its new employees are trained and able to properly run the waiting list in accordance with the Department?s policies and procedures, which includes ensuring the waiting list is properly updated for new applicants and addressing unused vouchers prior to making waiting list selections. Response Department of Local Affairs Agree Implementation Date: February 2023 The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Local Affairs (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-066 Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs?Internal Controls over the Waiting List The Department annually receives advance payments from the federal government for the Housing Voucher Programs (Program) to provide tenant-based subsidies for rent paid by low-income households. A housing subsidy is paid to the landlord directly by the Department on behalf of the Program?s participants. During Fiscal Year 2021, the Department incurred approximately $62.9 million in federal costs for the Housing Voucher Programs. Federal regulation [24 CFR 982.54] requires the Department to have an administrative plan to establish policies for carrying out the Program in a manner consistent with the U.S. Department of Housing and Urban Development (HUD) requirements and local goals and objectives. HUD requires the Division of Housing (DOH), a section within the Department, to place all families that apply for assistance on a waiting list. DOH must select families from the waiting list and maintain clear records of all information required to verify that the family is selected from the waiting list according to HUD requirements and Department policies as stated in the Department?s administrative plan [24 CFR 982.204(b) and 982.207(e)]. The DOH maintains the waiting list in an electronic database within its Public Housing Agencies (PHA) Software, called Emphasys Elite. DOH has established preferences for order of selection off of the waiting list, and gives priority or first preference (point system) to serving families that meet various criteria, including someone experiencing homelessness, a person with a disability, households that include victims of domestic violence, etc. The second preference for selecting from the waiting list is based on when DOH placed the individual on the waiting list, by date and time. HUD may also award the Department funding for a specified category of families on the waiting list (targeted funding [24 CFR 982.204(e)]). DOH must use this funding only to assist families within the specified category allowed by the targeted funding. DOH administers the following types of targeted funding: Veterans Affairs Supporting Housing (VASH), Non-Elderly Disabled, Family Unification Program, and Family Self-Sufficiency. DOH delegates some of its voucher administration responsibilities, such as application reviews and interviews with applicants, to agencies that provide housing services to applicants and participants of the Program. These agencies, or contractors, include public housing authorities, community mental health centers, community centered boards or their contract service agencies, independent living centers, the Veterans Affairs Medical Center (VAMC), homeless service providers, and others. DOH will enter into a contract with these agencies that outline each party?s responsibilities. Contractors employ housing coordinators who assist applicants and participants to complete the necessary Program documentation and understand regulations to help them acquire and maintain units that conform to Program regulations. DOH provides each contractor with vouchers to give eligible applicants. When a contractor has available vouchers, it will ask the DOH to select and issue the next name(s) from its waiting list. DOH then uses its electronic database to select individuals from the waiting list. In order for an applicant to receive the voucher, the applicant must first attend an interview with the contractor. At the interview, the contractor will determine whether the applicant is eligible based on requiring the applicant to complete a full application and provide proof of income sources, social security number, citizenship status, release of information forms, federal or state-issued picture ID, and birth certificate, as well as the contractor?s verification of those items. If it is determined at the interview that the applicant is not eligible, the voucher will be terminated in the Emphasys Elite system and the voucher can be used for the next applicant in line on the waiting list. HUD regulations require that all families have an equal opportunity to apply for and receive housing assistance [24 CFR 982.53]. DOH must also have policies regarding various aspects of organizing and managing the waiting list of applicant families. This includes opening the list to new applicants, closing the list to new applicants, notifying the public of waiting list openings and closings, updating waiting list information, and removing families that are no longer interested in or eligible for assistance from the list. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements related to the Program?s waiting list during Fiscal Year 2021. We requested and obtained a report from the Department that showed all individuals that were added to the Program during Fiscal Year 2021. We selected and tested 40 of these individuals admitted to the Program during Fiscal Year 2021 to determine if they were selected from the waiting list in accordance with the Department?s applicant selection policies. We also requested and obtained another report from the Department that showed any individuals selected from the waiting list due to reaching the top position on the waiting list during Fiscal Year 2021, regardless of whether the individuals were added or not added to the Program. From this report, we selected and tested 40 different individuals to ascertain if they were admitted to the Program or provided the opportunity to be admitted to the Program in accordance with the Department?s applicant selection policies. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [24 CFR 5.410, 982.54(d), and 982.201 through 982.207] require the Department to have written policies in its administrative plan for selecting applicants from the waiting list and documentation must show that the Department follows these policies when selecting applicants for admission from the waiting list. Selection from the waiting list generally occurs when the Department notifies a family whose name reaches the top of the waiting list to come in to verify eligibility for admission to the Program. ? The Department?s administrative plan states that when a family wishes to receive assistance under the Program, the family must submit an application that provides DOH with the information needed to determine the family?s eligibility [HCV GB, pp. 4-11 ? 4-16, Notice PIH 2009-36]. ? Federal regulation [24 CFR 982.207] requires that DOH select applicant families from the waiting list first by preference and secondly by date and time of application. ? Federal regulations [24 CFR 982.554(a)] specify that when a family has been selected from the waiting list for an application interview, DOH and/or its contractor will notify the family and the family will be required to participate in the interview. The notice must inform the family of the date, time, and location of the scheduled application interview, who is required to attend the interview, and all documents that must be provided by the family at the interview. ? Federal regulations [24 CFR 982.201(f) and 982.204(c)] establish the rules for removing Program participants from the waiting list. If at any time an applicant family is on the waiting list and DOH determines that the family is not eligible for assistance, the family will be removed from the waiting list. Federal regulations further state the family may also remove itself from the waiting list at any time by requesting removal in writing. If a family is removed from the waiting list because DOH has determined the family is not eligible for assistance, a notice must be sent to the family?s address of record as well as to any alternate address provided on the initial application. The notice must state the reasons the family was removed from the waiting list and inform the family how to request an informal review regarding DOH?s decision. ? Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. What problems did the audit work identify? During our testing of 40 individuals admitted to the Program during Fiscal Year 2021, we found that the Department could not provide appropriate support for 5 of the 40 (12.5 percent) tenant files reviewed. Specifically: ? For five individuals, the Department could not provide documentation of the eligibility interview. ? For one of those five individuals, the Department also could not locate the individual?s application. During our testing of 40 individuals that the Department selected from the waiting list due to the individuals reaching the top of the waiting list during Fiscal Year 2021, we found certain issues with 8 of the 40 (20 percent) tenant files reviewed. Specifically: ? In five instances, individuals were selected from the waiting list out of turn; therefore, they were not at the top of the waiting list when selected, as required. ? In three instances, the Department could not provide the applications for the individuals. Why did these problems occur? The Department lacked internal controls over the Program?s waiting list. Specifically, the Department is not ensuring its contractors are maintaining supporting documentation within tenant files, including interview documentation and applications. Both the Department and its contractors experienced employee turnover in Fiscal Year 2021. Although the Department conducted monthly webinars for various training manuals, including the administrative plan, and made training materials available for future reference, new employees did not receive sufficient training to ensure the Department complied with Program requirements over the waiting list. In addition, the Department did not properly train the DOH employees on the policies and procedures for maintaining and selecting applicants from the waiting list, which ultimately led to applicants being incorrectly selected from the waiting list. Specifically, DOH did not properly update the waiting list for new applicants and addressing unused vouchers from prior selections, which caused individuals to be incorrectly selected from the waiting list. Why do these problems matter? By not maintaining the waiting list supporting documentation, including interview documentation and applications, the Department cannot ensure that all tenants are eligible or qualified to participate in the Program. The Department must ensure it maintains accurate and complete tenant files to demonstrate compliance with federal requirements. Additionally, by not training employees properly on the Department?s policies and procedures surrounding the waiting list, applicants are at risk of being improperly removed from the waiting list and not given the opportunity to receive funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-066 The Department of Local Affairs (Department) should strengthen its internal controls to ensure it complies with waiting list requirements for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include the Department developing and providing a training plan for its contractors that covers all of the programs? requirements on an ongoing basis. In addition, the Department should ensure its new employees are trained and able to properly run the waiting list in accordance with the Department?s policies and procedures, which includes ensuring the waiting list is properly updated for new applicants and addressing unused vouchers prior to making waiting list selections. Response Department of Local Affairs Agree Implementation Date: February 2023 The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
2021-066
Finding 2022-076 Compliance with Federal Subrecipient Monitoring Requirements The Department receives federal grant funds directly from the federal government for the Highway Planning and Construction Program (Program) and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program. The Department executes an Intergovemental Agreement (IGA) between the Department and the subrecipient. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is responsible for evaluating each subrecipient's risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward and for ultimately ensuring the subrecipient is determined eligible. In some instances, in coordination with the Federal Highway Association (FHWA), a Metropolitan Planning Organization (MPO)? rather than the primary recipient, such as the Department?is responsible for performing eligibility determinations. As such, in those instances, the Department does not perform risk-assessments on these contracts and only is responsible for on-going monitoring. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place and complied with subrecipient monitoring activities for the Program during Fiscal Year 2022. As part of our audit work, we reviewed the Department?s internal controls over compliance for subrecipient monitoring requirements for the Program, including the Department?s policies and procedures. We tested a random sample of 25 of the Department?s 92 subrecipients (27 percent) for the Program?for which the Department had an IGA in place during Fiscal Year 2022?to determine whether subrecipient monitoring procedures performed by Department staff during the year were compliant with federal regulations. Our testing included evaluating whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. How were the results of the audit work measured? Our audit work was designed to measure the Department?s compliance with the following criteria: ? Federal regulations [2 CFR 200.303] state that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? ? Federal regulations [2 CFR 200.332(b)] also state that the Department must evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. ? Federal regulations [2 CFR 200.332(d) through (f)] and [2 CFR 200.521] further require the Department to monitor the activities of its subrecipients, as necessary, to ensure that each subaward is used for authorized purposes, the subrecipient complies with the terms and conditions of the subaward, and that the subrecipient achieves performance goals. The Department?s monitoring must include: o Reviewing financial and programmatic reports submitted by the subrecipient o Following-up on and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award o Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity What problems did the audit work identify? We determined that the Department did not comply with subrecipient monitoring requirements for the Highway Planning and Construction Program during Fiscal Year 2022, as noted below: ? The Department did not perform a risk assessment for 6 of the 25 subrecipients (24 percent) we tested, including subrecipients where eligibility was determined by a MPO. ? The Department improperly included one vendor in our population of subrecipients. The nature of services provided by the vendor was personal services, therefore, did not require the execution of an IGA. ? The Department did not provide supporting documentation for reviews of any Fiscal Year 2022 financial and programmatic reports. As a result, we were unable to determine if any reviews were conducted during the fiscal year, as required. Why did these problems occur? While the Department has created a subrecipient monitoring and risk assessment manual, the manual lacks clarity in a variety of areas, including the following: ? For contracts which extend over multiple fiscal years, the policies do not specify the frequency in which subrecipient risk-assessment should be reviewed or updated. ? There are multiple types of subrecipient contracts for which the full risk-assessment process may not be applicable, however, the current policies do not address acceptable exceptions to the policy. ? The Department?s current policies do not include guidance related to the review of financial and programmatic reports, including the extent to which required programmatic and financial reports should be obtained and reviewed. ? The Department?s policies and procedures do not clearly indicate that the Department is not required to complete a risk assessment when an MPO determines eligibility and therefore the nature of monitoring procedures to be performed is not defined. ? Requested audit documentation was not provided timely. Further, the Department did not provide sufficiently-detailed training to staff to ensure they were aware of and conducted required subrecipient monitoring responsibilities. Why do these problems matter? Performing timely and appropriate monitoring of subrecipients provides the Department with a method to ensure its subrecipients are complying with applicable federal grant requirements. By taking appropriate actions based on the results of its subrecipient monitoring activities, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with program requirements. Overall, the Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-076 The Department of Transportation should strengthen internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Highway Planning and Construction program by: A. Updating its current subrecipient monitoring and risk assessment policy to clarify the frequency in which a risk assessment is required to be completed or updated, as applicable for contracts that span multiple fiscal years, as well as direction regarding when it is acceptable to forgo performing a risk assessment and updating the policy to address the nature in which subrecipient programmatic and financial reports are reviewed B. Providing training to staff responsible for subrecipient monitoring activities related to the policies updated in Part A of the finding. Response Department of Transportation A. Agree Implementation Date: November 2023 The Department will update the policy to clarify the frequency in which the risk assessment is required to be completed or updated as applicable for contracts that span multiple fiscal years, as well as identifying exceptions, outlining when it is acceptable to forgo risk assessments. The Department will also update the policy to address the nature in which the subrecipient programmatic and financial reports are reviewed. The updates will be completed by November 2023. B. Agree Implementation Date: November 2023 The Department will provide training on the subrecipient monitoring policy manual to outline roles, responsibilities and the frequency of risk assessments that span over multiple fiscal years. The training will also provide guidance on the programmatic and financial information review process.
Show full finding ▾Hide full finding ▴Finding 2022-076 Compliance with Federal Subrecipient Monitoring Requirements The Department receives federal grant funds directly from the federal government for the Highway Planning and Construction Program (Program) and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required to conduct a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program. The Department executes an Intergovemental Agreement (IGA) between the Department and the subrecipient. Under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), the Department is responsible for evaluating each subrecipient's risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward and for ultimately ensuring the subrecipient is determined eligible. In some instances, in coordination with the Federal Highway Association (FHWA), a Metropolitan Planning Organization (MPO)? rather than the primary recipient, such as the Department?is responsible for performing eligibility determinations. As such, in those instances, the Department does not perform risk-assessments on these contracts and only is responsible for on-going monitoring. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place and complied with subrecipient monitoring activities for the Program during Fiscal Year 2022. As part of our audit work, we reviewed the Department?s internal controls over compliance for subrecipient monitoring requirements for the Program, including the Department?s policies and procedures. We tested a random sample of 25 of the Department?s 92 subrecipients (27 percent) for the Program?for which the Department had an IGA in place during Fiscal Year 2022?to determine whether subrecipient monitoring procedures performed by Department staff during the year were compliant with federal regulations. Our testing included evaluating whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. How were the results of the audit work measured? Our audit work was designed to measure the Department?s compliance with the following criteria: ? Federal regulations [2 CFR 200.303] state that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? ? Federal regulations [2 CFR 200.332(b)] also state that the Department must evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. ? Federal regulations [2 CFR 200.332(d) through (f)] and [2 CFR 200.521] further require the Department to monitor the activities of its subrecipients, as necessary, to ensure that each subaward is used for authorized purposes, the subrecipient complies with the terms and conditions of the subaward, and that the subrecipient achieves performance goals. The Department?s monitoring must include: o Reviewing financial and programmatic reports submitted by the subrecipient o Following-up on and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award o Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity What problems did the audit work identify? We determined that the Department did not comply with subrecipient monitoring requirements for the Highway Planning and Construction Program during Fiscal Year 2022, as noted below: ? The Department did not perform a risk assessment for 6 of the 25 subrecipients (24 percent) we tested, including subrecipients where eligibility was determined by a MPO. ? The Department improperly included one vendor in our population of subrecipients. The nature of services provided by the vendor was personal services, therefore, did not require the execution of an IGA. ? The Department did not provide supporting documentation for reviews of any Fiscal Year 2022 financial and programmatic reports. As a result, we were unable to determine if any reviews were conducted during the fiscal year, as required. Why did these problems occur? While the Department has created a subrecipient monitoring and risk assessment manual, the manual lacks clarity in a variety of areas, including the following: ? For contracts which extend over multiple fiscal years, the policies do not specify the frequency in which subrecipient risk-assessment should be reviewed or updated. ? There are multiple types of subrecipient contracts for which the full risk-assessment process may not be applicable, however, the current policies do not address acceptable exceptions to the policy. ? The Department?s current policies do not include guidance related to the review of financial and programmatic reports, including the extent to which required programmatic and financial reports should be obtained and reviewed. ? The Department?s policies and procedures do not clearly indicate that the Department is not required to complete a risk assessment when an MPO determines eligibility and therefore the nature of monitoring procedures to be performed is not defined. ? Requested audit documentation was not provided timely. Further, the Department did not provide sufficiently-detailed training to staff to ensure they were aware of and conducted required subrecipient monitoring responsibilities. Why do these problems matter? Performing timely and appropriate monitoring of subrecipients provides the Department with a method to ensure its subrecipients are complying with applicable federal grant requirements. By taking appropriate actions based on the results of its subrecipient monitoring activities, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with program requirements. Overall, the Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-076 The Department of Transportation should strengthen internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Highway Planning and Construction program by: A. Updating its current subrecipient monitoring and risk assessment policy to clarify the frequency in which a risk assessment is required to be completed or updated, as applicable for contracts that span multiple fiscal years, as well as direction regarding when it is acceptable to forgo performing a risk assessment and updating the policy to address the nature in which subrecipient programmatic and financial reports are reviewed B. Providing training to staff responsible for subrecipient monitoring activities related to the policies updated in Part A of the finding. Response Department of Transportation A. Agree Implementation Date: November 2023 The Department will update the policy to clarify the frequency in which the risk assessment is required to be completed or updated as applicable for contracts that span multiple fiscal years, as well as identifying exceptions, outlining when it is acceptable to forgo risk assessments. The Department will also update the policy to address the nature in which the subrecipient programmatic and financial reports are reviewed. The updates will be completed by November 2023. B. Agree Implementation Date: November 2023 The Department will provide training on the subrecipient monitoring policy manual to outline roles, responsibilities and the frequency of risk assessments that span over multiple fiscal years. The training will also provide guidance on the programmatic and financial information review process.
(A) The Department will update the policy to clarify the frequency in which the risk assessment is required to be completed or updated as applicable for contracts that span multiple fiscal years, as well as identifying exceptions, outlining when it is acceptable to forgo risk assessments. The Department will also update the policy to address the nature in which the subrecipient programmatic and financial reports are reviewed. The updates will be completed by November 2023. (B) The Department will provide training on the subrecipient monitoring policy manual to outline roles, responsibilities and the frequency of risk assessments that span over multiple fiscal years. The training will also provide guidance on the programmatic and financial information review process.
Finding 2022-077 Cash Management The Department operates on a reimbursement basis with the federal government for a portion of its federal grant programs, expending state dollars for the federal programs prior to requesting reimbursement for the appropriate federal share. The reimbursement process is governed by the Cash Management Improvement Act of 1990 (CMIA) and 31 CFR Part 205 Part B, Rules and Procedures for Efficient Federal-State Funds Transfers (Transfer Rules), which prescribe specific methods and timeframes for drawing down federal funds. The purpose of CMIA and the Transfer Rules is to minimize the time period from when the State makes an expenditure for a federal program and when the federal reimbursement is received, so that neither the State nor the federal government incurs a loss of interest on the funds. This timeframe for requesting reimbursement is referred to as the ?draw pattern.? Under CMIA, the State must enter into a formal agreement, referred to as the ?Treasury-State Agreement,? (Agreement) with the U.S. Department of the Treasury to establish reimbursement schedules for selected federal programs that have been awarded to the State. In Colorado, the Department of Treasury (Treasury), on behalf of all departments in the State, enters into the Agreement with the U.S. Department of the Treasury. For Fiscal Year 2022, Colorado?s CMIA Agreement included 10 programs administered by various state agencies. The Department has one federal program that is included in the Agreement. Specifically, the Department?s Highway Planning and Construction [ALN 20.205] is included in this Agreement. During Fiscal Year 2022, the Department expended $510.0 million in Highway Planning and Construction funds. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over its cash draw process and to determine whether the Department was in compliance with CMIA for the Highway Planning and Construction program during Fiscal Year 2022. As part of our audit, we tested the Department?s internal controls and compliance over its cash management process for the Highway Planning and Construction program. We tested a sample of 25 expenditures and the related draws the Department made for the program during Fiscal Year 2022 and calculated the number of days between each sampled expenditure and related federal draw and compared our results to the CMIA requirements in place at the time the draw occurred. Within our sample, draws for nine of the expenditures were performed prior to October 13, when the 4-day draw pattern was in place; draws for 16 expenditures were performed after October 13 on the 5-day pattern. How were the results of the audit work measured? Under CMIA rules, draw patterns should be interest-neutral between the State?s expenditure and receipt of federal funds. We compared the results of our testwork against the regulations within the CMIA for payments clearing the State?s bank that should result in the receipt of the federal reimbursements within specific timeframe as noted below: The Agreement in place at the beginning of Fiscal Year 2022 specified a 4-day draw pattern for Highway Planning and Construction. Therefore, the time between when the Department?s expenditure was made and when federal funds were received should have been 4 days. In October 2021, however, the Department requested the draw pattern be changed from 4 days to 5 days. This request was approved by the U.S. Department of the Treasury on October 13, 2021. What problem did the audit work identify? We determined that the Department did not comply with the approved cash management draw patterns contained in the Agreements for the Highway Planning and Construction program for Fiscal Year 2022. Overall, 8 of the 25 draws (32 percent) were not made in accordance with the applicable Agreement, as follows: ? We noted that 6 of the 16 draws (38 percent) were not performed on the 5-day approved draw pattern in place after October 13, 2021 and instead, were performed on a 4-day draw pattern. ? We also noted that 2 of the 9 draws (22 percent) sampled from the first Agreement were not completed in accordance with the 4-day approved draw pattern in place prior to October 13, 2021 and, instead, were performed on a 5-day draw pattern. Why did this problem occur? The Department did not have appropriate internal controls over its federal grant cash management process during Fiscal Year 2022. Specifically, the Department conducted an analysis on the draw pattern for Highway Planning and Construction in early Fiscal Year 2022 and determined that its draws were occurring within 5 rather than 4 days, so the Department requested and received approval from the U.S. Department of the Treasury to change from a 4 day draw pattern to a 5-day draw pattern; however, the Department did not properly communicate the change in the Agreement for the Highway Planning and Construction?s draw pattern to the primary individuals responsible for preparing and approving the draws. As a result, the billing procedure was not updated to reflect the change in draw pattern, which led to the draws being out of compliance with the approved CMIA draw pattern. Why does this problem matter? The timing of draws for requesting federal funds impacts the interest neutral requirements under the CMIA. By drawing funds early, the Department creates a risk that the State my ultimately owe interest charges to the federal government. Further, the Department?s lack of strong cash management internal controls may result in delays in the identification of expenditures for which reimbursement has not been requested and therefore, funds upon which the State has lost interest. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-077 The Department Transportation (Department) should strengthen its internal controls and processes over and ensure that it complies with federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by: A. Ensuring that Department personnel responsible for preparing and reviewing the cash draw requests are adequately informed of the draw pattern applicable for the current fiscal year, including any federally-approved changes that occur during the year. B. Establishing procedures that specify draw request dates in relation to Program expenditures that ensure required draw patterns are met. Response Colorado Department of Transportation A. Agree Implementation Date: March 2023 The Department will enhance its internal controls and processes to ensure it complies with the federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by ensuring personnel responsible for preparing and reviewing the cash draw requests are adequately informed of the draw pattern for the applicable fiscal year in which the draws occur including federally-approved changes during the year. Personnel responsible for the draw will review the approved draw letter from the State Treasury with a secondary verification on the Federal Site, www.fiscal.treasury.gov/cmia/resources-treasury-state-agreements.hmtl for the specified timeframe before conducting the draw. B. Agree Implementation Date: March 2023 The Department will enhance its internal controls and processes to ensure it complies with federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by establishing and maintaining formal procedures that specify the draw request dates in relation to the program expenditures to ensure required draw patterns are met. The process to implement changes to the cash draw pattern will be added to the draw procedure by March 2023.
Show full finding ▾Hide full finding ▴Finding 2022-077 Cash Management The Department operates on a reimbursement basis with the federal government for a portion of its federal grant programs, expending state dollars for the federal programs prior to requesting reimbursement for the appropriate federal share. The reimbursement process is governed by the Cash Management Improvement Act of 1990 (CMIA) and 31 CFR Part 205 Part B, Rules and Procedures for Efficient Federal-State Funds Transfers (Transfer Rules), which prescribe specific methods and timeframes for drawing down federal funds. The purpose of CMIA and the Transfer Rules is to minimize the time period from when the State makes an expenditure for a federal program and when the federal reimbursement is received, so that neither the State nor the federal government incurs a loss of interest on the funds. This timeframe for requesting reimbursement is referred to as the ?draw pattern.? Under CMIA, the State must enter into a formal agreement, referred to as the ?Treasury-State Agreement,? (Agreement) with the U.S. Department of the Treasury to establish reimbursement schedules for selected federal programs that have been awarded to the State. In Colorado, the Department of Treasury (Treasury), on behalf of all departments in the State, enters into the Agreement with the U.S. Department of the Treasury. For Fiscal Year 2022, Colorado?s CMIA Agreement included 10 programs administered by various state agencies. The Department has one federal program that is included in the Agreement. Specifically, the Department?s Highway Planning and Construction [ALN 20.205] is included in this Agreement. During Fiscal Year 2022, the Department expended $510.0 million in Highway Planning and Construction funds. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over its cash draw process and to determine whether the Department was in compliance with CMIA for the Highway Planning and Construction program during Fiscal Year 2022. As part of our audit, we tested the Department?s internal controls and compliance over its cash management process for the Highway Planning and Construction program. We tested a sample of 25 expenditures and the related draws the Department made for the program during Fiscal Year 2022 and calculated the number of days between each sampled expenditure and related federal draw and compared our results to the CMIA requirements in place at the time the draw occurred. Within our sample, draws for nine of the expenditures were performed prior to October 13, when the 4-day draw pattern was in place; draws for 16 expenditures were performed after October 13 on the 5-day pattern. How were the results of the audit work measured? Under CMIA rules, draw patterns should be interest-neutral between the State?s expenditure and receipt of federal funds. We compared the results of our testwork against the regulations within the CMIA for payments clearing the State?s bank that should result in the receipt of the federal reimbursements within specific timeframe as noted below: The Agreement in place at the beginning of Fiscal Year 2022 specified a 4-day draw pattern for Highway Planning and Construction. Therefore, the time between when the Department?s expenditure was made and when federal funds were received should have been 4 days. In October 2021, however, the Department requested the draw pattern be changed from 4 days to 5 days. This request was approved by the U.S. Department of the Treasury on October 13, 2021. What problem did the audit work identify? We determined that the Department did not comply with the approved cash management draw patterns contained in the Agreements for the Highway Planning and Construction program for Fiscal Year 2022. Overall, 8 of the 25 draws (32 percent) were not made in accordance with the applicable Agreement, as follows: ? We noted that 6 of the 16 draws (38 percent) were not performed on the 5-day approved draw pattern in place after October 13, 2021 and instead, were performed on a 4-day draw pattern. ? We also noted that 2 of the 9 draws (22 percent) sampled from the first Agreement were not completed in accordance with the 4-day approved draw pattern in place prior to October 13, 2021 and, instead, were performed on a 5-day draw pattern. Why did this problem occur? The Department did not have appropriate internal controls over its federal grant cash management process during Fiscal Year 2022. Specifically, the Department conducted an analysis on the draw pattern for Highway Planning and Construction in early Fiscal Year 2022 and determined that its draws were occurring within 5 rather than 4 days, so the Department requested and received approval from the U.S. Department of the Treasury to change from a 4 day draw pattern to a 5-day draw pattern; however, the Department did not properly communicate the change in the Agreement for the Highway Planning and Construction?s draw pattern to the primary individuals responsible for preparing and approving the draws. As a result, the billing procedure was not updated to reflect the change in draw pattern, which led to the draws being out of compliance with the approved CMIA draw pattern. Why does this problem matter? The timing of draws for requesting federal funds impacts the interest neutral requirements under the CMIA. By drawing funds early, the Department creates a risk that the State my ultimately owe interest charges to the federal government. Further, the Department?s lack of strong cash management internal controls may result in delays in the identification of expenditures for which reimbursement has not been requested and therefore, funds upon which the State has lost interest. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-077 The Department Transportation (Department) should strengthen its internal controls and processes over and ensure that it complies with federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by: A. Ensuring that Department personnel responsible for preparing and reviewing the cash draw requests are adequately informed of the draw pattern applicable for the current fiscal year, including any federally-approved changes that occur during the year. B. Establishing procedures that specify draw request dates in relation to Program expenditures that ensure required draw patterns are met. Response Colorado Department of Transportation A. Agree Implementation Date: March 2023 The Department will enhance its internal controls and processes to ensure it complies with the federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by ensuring personnel responsible for preparing and reviewing the cash draw requests are adequately informed of the draw pattern for the applicable fiscal year in which the draws occur including federally-approved changes during the year. Personnel responsible for the draw will review the approved draw letter from the State Treasury with a secondary verification on the Federal Site, www.fiscal.treasury.gov/cmia/resources-treasury-state-agreements.hmtl for the specified timeframe before conducting the draw. B. Agree Implementation Date: March 2023 The Department will enhance its internal controls and processes to ensure it complies with federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by establishing and maintaining formal procedures that specify the draw request dates in relation to the program expenditures to ensure required draw patterns are met. The process to implement changes to the cash draw pattern will be added to the draw procedure by March 2023.
(A) The Department will enhance its internal controls and processes to ensure it complies with the federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by ensuring personnel responsible for preparing and reviewing the cash draw requests are adequately informed of the draw pattern for the applicable fiscal year in which the draws occur including federally-approved changes during the year. Personnel responsible for the draw will review the approved draw letter from the State Treasury with a secondary verification on the Federal Site, www.fiscal.treasury.gov/cmia/resources-treasury-state-agreements.hmtl for the specified timeframe before conducting the draw. (B) The Department will enhance its internal controls and processes to ensure it complies with federal Cash Management Improvement Act requirements for the federal Highway Planning and Construction Program (Program) by establishing and maintaining formal procedures that specify the draw request dates in relation to the program expenditures to ensure required draw patterns are met. The process to implement changes to the cash draw pattern will be added to the draw procedure by March 2023.
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-068 The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-075 FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORING The Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research. Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities. As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Our audit work was designed to measure the results of compliance with the following criteria: ? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations [2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: ? Reviewing financial and programmatic reports. ? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. ? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. ? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings. ? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows: ? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient. ? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC. WHY DID THESE PROBLEMS OCCUR? The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts. WHY DO THESE PROBLEMS MATTER? Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-075 The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by: A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures. B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment. RESPONSE DEPARTMENT OF TRANSPORTATION A AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. B AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2022 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table Finding 2021-068 The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-075 FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORING The Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research. Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities. As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Our audit work was designed to measure the results of compliance with the following criteria: ? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations [2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: ? Reviewing financial and programmatic reports. ? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. ? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. ? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings. ? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows: ? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient. ? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC. WHY DID THESE PROBLEMS OCCUR? The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts. WHY DO THESE PROBLEMS MATTER? Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-075 The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by: A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures. B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment. RESPONSE DEPARTMENT OF TRANSPORTATION A AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. B AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
(A) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. (B) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
2021-068
Finding 2022-079 Minerals Leasing Act?Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.? During Fiscal Year 2022, ONRR distributed approximately $124.9 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $49.2 million of the $52.2 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.0 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2022. As part of our testing, we reviewed Treasury?s progress in implementing our Fiscal Year 2020 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount. In addition, we recommended that Treasury implement procedures to accurately prepare and submit the Exhibit K1, Schedule of Federal Assistance, to the Office of the State Controller (OSC) for reporting federal assistance information each year and to ensure the Exhibit K1 accurately reflects Program expenditures. During our Fiscal Year 2022 audit, we inquired about Treasury?s monitoring procedures over its Program subrecipients, including its required communications. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal reporting requirements and the OSC?s instructions. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provides specific information about the Program to the subrecipients, including, but not limited to, the following: ? Assistance Listing Number ? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies ? Contact information for Treasury ? Dollar amount made available to the subrecipient ? Reporting requirements The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332(f)] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. The Exhibit K1 is used to report federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA, which reports the total federal awards expended by the State during the fiscal year. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the Exhibit in preparing the SEFA. What problem did the audit work identify? We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2022. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury reported that they met with DOLA staff in June 2022 to discuss an interagency agreement that would establish expectations for DOLA to communicate required federal award information and applicable federal compliance requirements for this Program to subrecipients. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. Further, Treasury, as the primary recipient of the Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2022 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. We determined that Treasury implemented part of our prior audit recommendation related to the preparation of its Exhibit K1 in accordance with federal requirements. Specifically, Treasury received information from pass-through departments in order to properly determine whether Program funds ultimately flowed through to subrecipients and reported these funds as ?Expenditures -Passed Through to Subrecipient? on Treasury?s Exhibit K1. Why did this problem occur? Treasury did not have adequate internal controls in place during Fiscal Year 2022 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff did not effectively communicate with DOLA staff about their responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds, including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2022 are required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. Why does this problem matter? By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not undergoing Single Audits, as required. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-079 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program). This should include developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount made available to the subrecipient, and the related federal requirements are communicated to Program subrecipients, and that the subrecipients report the funds on their respective annual Schedules of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. Response Department of The Treasury Agree Implementation Date: June 30, 2023 The Department of the Treasury (Treasury) strengthened its internal controls with DOLA?s agreement to disseminate the necessary information to the subrecipients in compliance with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) at the earliest possible opportunity following receipt of the recommendation in the previous FYE?s report as the monitoring and reporting for the Program could only be performed following the annual distribution of such funds which took place subsequent to FYE 2022. The Department will formalize an Interagency Agreement with DOLA and any other relevant parties, incorporating additional corrective action before the stated date above (June 30, 2023).
Show full finding ▾Hide full finding ▴Finding 2022-079 Minerals Leasing Act?Subrecipient Monitoring In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.? During Fiscal Year 2022, ONRR distributed approximately $124.9 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $49.2 million of the $52.2 million in Program funds it received to local government subrecipients. DOLA retained the remaining $3.0 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2022. As part of our testing, we reviewed Treasury?s progress in implementing our Fiscal Year 2020 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Assistance Listing Number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount. In addition, we recommended that Treasury implement procedures to accurately prepare and submit the Exhibit K1, Schedule of Federal Assistance, to the Office of the State Controller (OSC) for reporting federal assistance information each year and to ensure the Exhibit K1 accurately reflects Program expenditures. During our Fiscal Year 2022 audit, we inquired about Treasury?s monitoring procedures over its Program subrecipients, including its required communications. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal reporting requirements and the OSC?s instructions. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provides specific information about the Program to the subrecipients, including, but not limited to, the following: ? Assistance Listing Number ? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies ? Contact information for Treasury ? Dollar amount made available to the subrecipient ? Reporting requirements The State and any local governments receiving federal funds are required to present a Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.501(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332(f)] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. The Exhibit K1 is used to report federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA, which reports the total federal awards expended by the State during the fiscal year. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the Exhibit in preparing the SEFA. What problem did the audit work identify? We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring for the Program during Fiscal Year 2022. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, the required award information and applicable federal compliance requirements to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury reported that they met with DOLA staff in June 2022 to discuss an interagency agreement that would establish expectations for DOLA to communicate required federal award information and applicable federal compliance requirements for this Program to subrecipients. However, as of the end of the fiscal year, this interagency agreement was not signed or in place. Further, Treasury, as the primary recipient of the Program funds, did not ensure that it or DOLA communicated and followed up with any non-state subrecipients receiving federal funds from the State during Fiscal Year 2022 to ensure the subrecipients reported the funds on their respective SEFAs and, if applicable, underwent a Single Audit. We determined that Treasury implemented part of our prior audit recommendation related to the preparation of its Exhibit K1 in accordance with federal requirements. Specifically, Treasury received information from pass-through departments in order to properly determine whether Program funds ultimately flowed through to subrecipients and reported these funds as ?Expenditures -Passed Through to Subrecipient? on Treasury?s Exhibit K1. Why did this problem occur? Treasury did not have adequate internal controls in place during Fiscal Year 2022 to ensure that it complied with federal subrecipient monitoring requirements for the Program. Specifically, Treasury staff did not effectively communicate with DOLA staff about their responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information and related federal reporting requirements to all subrecipients of Program funds, including a communication that any subrecipients receiving Program funds from the State during Fiscal Year 2022 are required to report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. Why does this problem matter? By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not undergoing Single Audits, as required. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-079 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program). This should include developing effective processes to ensure that required federal award information, including the Assistance Listing Number, federal program name, and dollar amount made available to the subrecipient, and the related federal requirements are communicated to Program subrecipients, and that the subrecipients report the funds on their respective annual Schedules of Expenditures of Federal Awards and, if applicable, undergo a Single Audit. Response Department of The Treasury Agree Implementation Date: June 30, 2023 The Department of the Treasury (Treasury) strengthened its internal controls with DOLA?s agreement to disseminate the necessary information to the subrecipients in compliance with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) at the earliest possible opportunity following receipt of the recommendation in the previous FYE?s report as the monitoring and reporting for the Program could only be performed following the annual distribution of such funds which took place subsequent to FYE 2022. The Department will formalize an Interagency Agreement with DOLA and any other relevant parties, incorporating additional corrective action before the stated date above (June 30, 2023).
The Department of the Treasury (Treasury) strengthened its internal controls with DOLA?s agreement to disseminate the necessary information to the subrecipients in compliance with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) at the earliest possible opportunity following receipt of the recommendation in the previous FYE?s report as the monitoring and reporting for the Program could only be performed following the annual distribution of such funds which took place subsequent to FYE 2022. The Department will formalize an Interagency Agreement with DOLA and any other relevant parties, incorporating additional corrective action before the stated date above (June 30, 2023).
2021-069
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on July 11, 2022 — management decision was due January 11, 2023.
The following findings and recommendations are related to both financial reporting and federal program internal control weaknesses. They were included within Volume I ? The Statewide Financial Report and, therefore, are not repeated in this Volume II. These findings and recommendations can be found within Section II: Financial Statement Findings of the Volume I Report. See See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-009 Colorado interChange and Business Intelligence and Data Management System Complementary User Entity Controls Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department has three systems with unique functions and uses these systems to administer and manage federal programs, such as the Medicaid program and CBHP: (1) Pharmacy Benefit Management System, which processes pharmacy and drug rebates; (2) Colorado interChange (interChange), which processes provider enrollment and payments; and (3) the Business Intelligence and Data Management System (BIDM), which provides data analytics and reporting functions. The Department contracts with several third-party service organizations for the processing of Medicaid data, claims, and the overall maintenance and operations of the systems, and requires each to have an examination performed by an independent service auditor. Examinations of this type are governed by the American Institute of Certified Public Accountants (AICPA) and result in one of various types of System and Organization Controls (SOC) reports. For example, a SOC 1, Type II (SOC 1) report provides the service auditors? opinion as to whether management has fairly presented its description of the service organization?s system of internal controls over financial reporting and whether the internal controls have been suitably designed and are operating effectively to achieve the related control objectives, over a specified period. Service organizations will also state that there are certain internal controls, referred to as Complementary User Entity Controls (User Controls), that must be designed, in place, and operating effectively at the user entity, in this case at the Department, for the controls listed in the report that are supported by the service organization to be fully relied upon by the user entity. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to gain an understanding of and determine whether the User Controls identified by the service organizations for interChange and BIDM were in place and operating effectively over the period of review. We obtained and reviewed the most recent SOC 1 reports that were provided to the Department from the interChange and BIDM service organizations, which included three SOC 1 reports, in order to identify the necessary IT User Controls that the Department needed to have in place. We also made inquiries of Department staff in performing our audit work. What problems did the audit work identify and how were the results of the audit work measured? Our Fiscal Year 2021 audit work identified problems with the Department?s IT procedures and information security compliance, as they relate to certain interChange and BIDM SOC 1 IT User Controls. We measured the results of our audit work against the Office of the State Controller?s (OSC) policy, Internal Control System, which requires state agencies to use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office (GAO), as its framework for its system of internal controls; and Colorado Information Security Policies that are developed and issued by the Governor?s Office of Information Technology. Why did these problems occur? In discussing these problems with Department management and staff, they stated the following: ? They are in the process of modernizing business processes related to their internal procedures. ? They did not establish and communicate their expectations for performing procedures related to the IT general controls in which we found problems. ? They accepted the risk associated with not implementing certain IT general controls but did not formally document the risk assessment. ? They have not yet formalized and implemented a process to address one of the problems we identified. Why do these problems matter? Failure to demonstrate implementation of required IT general controls over financial reporting with interChange and BIDM does not provide for adequate assurances over the maintenance, operations, integrity, and security of the systems and their data. Ultimately, this poses a risk to the integrity of the financial information being generated and maintained by the systems See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-009 The Department of Health Care Policy and Financing should improve IT controls over the Colorado interChange and the Business Intelligence and Data Management systems by: A. Implementing the recommendation as noted in Part A of the confidential finding. B. Implementing the recommendation as noted in Part B of the confidential finding. C. Implementing the recommendation as noted in Part C of the confidential finding. D. Implementing the recommendation as noted in Part D of the confidential finding. E. Implementing the recommendation as noted in Part E of the confidential finding. F. Implementing the recommendation as noted in Part F of the confidential finding. Response Department of Health Care Policy and Financing A. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part A of the confidential finding. B. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part B of the confidential finding. C. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part C of the confidential finding. D. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part D of the confidential finding. E. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part E of the confidential finding. F. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part F of the confidential finding.
Show full finding ▾Hide full finding ▴The following findings and recommendations are related to both financial reporting and federal program internal control weaknesses. They were included within Volume I ? The Statewide Financial Report and, therefore, are not repeated in this Volume II. These findings and recommendations can be found within Section II: Financial Statement Findings of the Volume I Report. See See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-009 Colorado interChange and Business Intelligence and Data Management System Complementary User Entity Controls Government Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to information technology system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department in a separate, confidential memorandum. The Department has three systems with unique functions and uses these systems to administer and manage federal programs, such as the Medicaid program and CBHP: (1) Pharmacy Benefit Management System, which processes pharmacy and drug rebates; (2) Colorado interChange (interChange), which processes provider enrollment and payments; and (3) the Business Intelligence and Data Management System (BIDM), which provides data analytics and reporting functions. The Department contracts with several third-party service organizations for the processing of Medicaid data, claims, and the overall maintenance and operations of the systems, and requires each to have an examination performed by an independent service auditor. Examinations of this type are governed by the American Institute of Certified Public Accountants (AICPA) and result in one of various types of System and Organization Controls (SOC) reports. For example, a SOC 1, Type II (SOC 1) report provides the service auditors? opinion as to whether management has fairly presented its description of the service organization?s system of internal controls over financial reporting and whether the internal controls have been suitably designed and are operating effectively to achieve the related control objectives, over a specified period. Service organizations will also state that there are certain internal controls, referred to as Complementary User Entity Controls (User Controls), that must be designed, in place, and operating effectively at the user entity, in this case at the Department, for the controls listed in the report that are supported by the service organization to be fully relied upon by the user entity. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to gain an understanding of and determine whether the User Controls identified by the service organizations for interChange and BIDM were in place and operating effectively over the period of review. We obtained and reviewed the most recent SOC 1 reports that were provided to the Department from the interChange and BIDM service organizations, which included three SOC 1 reports, in order to identify the necessary IT User Controls that the Department needed to have in place. We also made inquiries of Department staff in performing our audit work. What problems did the audit work identify and how were the results of the audit work measured? Our Fiscal Year 2021 audit work identified problems with the Department?s IT procedures and information security compliance, as they relate to certain interChange and BIDM SOC 1 IT User Controls. We measured the results of our audit work against the Office of the State Controller?s (OSC) policy, Internal Control System, which requires state agencies to use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office (GAO), as its framework for its system of internal controls; and Colorado Information Security Policies that are developed and issued by the Governor?s Office of Information Technology. Why did these problems occur? In discussing these problems with Department management and staff, they stated the following: ? They are in the process of modernizing business processes related to their internal procedures. ? They did not establish and communicate their expectations for performing procedures related to the IT general controls in which we found problems. ? They accepted the risk associated with not implementing certain IT general controls but did not formally document the risk assessment. ? They have not yet formalized and implemented a process to address one of the problems we identified. Why do these problems matter? Failure to demonstrate implementation of required IT general controls over financial reporting with interChange and BIDM does not provide for adequate assurances over the maintenance, operations, integrity, and security of the systems and their data. Ultimately, this poses a risk to the integrity of the financial information being generated and maintained by the systems See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-009 The Department of Health Care Policy and Financing should improve IT controls over the Colorado interChange and the Business Intelligence and Data Management systems by: A. Implementing the recommendation as noted in Part A of the confidential finding. B. Implementing the recommendation as noted in Part B of the confidential finding. C. Implementing the recommendation as noted in Part C of the confidential finding. D. Implementing the recommendation as noted in Part D of the confidential finding. E. Implementing the recommendation as noted in Part E of the confidential finding. F. Implementing the recommendation as noted in Part F of the confidential finding. Response Department of Health Care Policy and Financing A. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part A of the confidential finding. B. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part B of the confidential finding. C. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part C of the confidential finding. D. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part D of the confidential finding. E. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part E of the confidential finding. F. Agree Implementation Date: June 2022 The Department will implement the recommendation as described in the Department?s response in Part F of the confidential finding.
(A) The Department will implement the recommendation as described in the Department?s response in Part A of the confidential finding. (B) The Department will implement the recommendation as described in the Department?s response in Part B of the confidential finding. (C) The Department will implement the recommendation as described in the Department?s response in Part C of the confidential finding. (D) The Department will implement the recommendation as described in the Department?s response in Part D of the confidential finding. (E) The Department will implement the recommendation as described in the Department?s response in Part E of the confidential finding. (F) The Department will implement the recommendation as described in the Department?s response in Part F of the confidential finding.
The following findings and recommendations are related to both financial reporting and federal program internal control weaknesses. They were included within Volume I ? The Statewide Financial Report and, therefore, are not repeated in this Volume II. These findings and recommendations can be found within Section II: Financial Statement Findings of the Volume I Report. See See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-010 Colorado interChange SOC Report In 2017, the Department implemented the interChange system to replace the legacy Medicaid Management Information System. The Medicaid program is the State?s program, partially funded through the federal Medicaid grant, which provides public health insurance to eligible low-income citizens. The Department is responsible for both the Medicaid program and the interChange system. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is Gainwell Technologies LLC (Gainwell), formerly DXC Technology Services, LLC. Gainwell hosts the interChange system for the Department and manages IT services related to the maintenance and support of the system infrastructure and software. The Department?s contractual agreement with Gainwell requires it, as a service organization for the Department, to have an annual SOC examination performed by an independent service auditor. Examinations of this type are governed by the AICPA and result in one of various types of SOC reports. For the Department, Gainwell provides a SOC 1 report, which provides an independent auditor?s opinion on whether the service organization?s internal controls over financial reporting, including those over the system, have been suitably designed and operate effectively over a specified period. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2020 interChange SOC 1 reporting process recommendation, in which we recommended that the Department improve controls over its financial reporting by developing, documenting, implementing, and communicating a process for conducting annual reviews of the interChange SOC 1 reports to determine if any issues have been noted and whether actions are necessary to remediate these issues. As part of our Fiscal Year 2021 audit work, we also sought to determine the Department?s compliance with SOC 1 report requirements established and published within the Fiscal Procedures Manual, by the OSC. We performed our audit work through inquiry of Department staff, as well as inspection of supporting documentation. How were the results of the audit work measured? The OSC?s policy, Internal Control System, requires state agencies to use the Green Book, published by the GAO, as its framework for its system of internal control. Specifically, Green Book Paragraph OV4.08, Documentation Requirements, states that documentation is a necessary part of an effective internal control system and is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 14.03, Communication throughout the Entity, states that management should communicate quality information to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management should assign the internal control responsibilities for key roles. Fiscal Procedures Manual Section 3.41, Statewide System and Organizational Controls Reviews, includes agency responsibilities related to the receipt and review of SOC 1 reports. Specifically, the Department must: ? Provide the OSC a copy of its SOC 1 reports within 10 business days of receipt by the Department. ? Annually review the SOC 1 reports and determine whether any actions are necessary to remediate any issues noted. ? Provide a summarized remediation plan to the OSC, including the steps for remediation and when such steps will be taken. What problems did the audit work identify? During our Fiscal Year 2021 audit work, we found that the Department partially implemented our Fiscal Year 2020 recommendation related to the interchange SOC 1 reporting process. Specifically, we found the following: ? The Department developed and documented a desk manual, Contracts and Compliance Management Desk Manual (Manual), that addresses SOC 1 reports, including the roles and responsibilities to perform a review of the SOC 1 report and to document the review in a report summary; however, the Manual was not communicated to staff responsible for following the processes nor was the process implemented by the end of Fiscal Year 2021. ? In the process of reviewing the Manual to determine the disposition of the prior year audit recommendation, we noted that the Department did not document in the Manual a process related to the receipt and review of SOC 1 reports, as required by the OSC?s Fiscal Procedures Manual. Why did these problems occur? Based on our inquiries with the Department, we noted the following: ? The Department stated that it planned to fully implement the process by July 2021; however, the Department did not provide a reason for why the process detailed in the Manual was not communicated to and implemented by staff as of the end of Fiscal Year 2021. ? Although Department staff confirmed that they must comply with the Fiscal Procedures Manual?s SOC 1 report requirements, the Department?s Controller and Health Information Office had not developed a formalized process to include the missing reference to the Fiscal Procedures Manual requirement. Why do these problems matter? Without a formalized SOC 1 review process in place, the Department may not become aware of issues identified in the report relating to the controls its service organizations have designed, implemented, and operate over contracted services, as they relate to financial reporting and compliance with federal regulations. As a result, the Department may fail to address serious issues that impact the data reliability of the interChange system. See See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2021-010 The Department of Health Care Policy and Financing should improve processes over the Colorado interChange?s System and Organization Controls (SOC) reporting by: A. Communicating the processes documented within its newly developed Contract and Compliance Management Desk Manual (Manual) to the appropriate staff responsible for following the processes. B. Implementing the procedures contained within the Manual by conducting the annual review processes on the SOC 1, Type II reports received from its service organizations to determine if any issues have been noted and whether actions are necessary to remediate these issues. C. Formalizing a process to comply with the Office of the State Controller?s Fiscal Procedures Manual, Statewide System and Organizational Controls Reviews requirements. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2021 The Department communicated the process to staff on July 7, 2021 in compliance with the July 2021 implementation date provided in August 2020. B. Agree Implementation Date: June 2021 The Department formally documented the process for the review of SOC 1 reports in June 2021. However, the Department had already been following a process to review the SOC 1 reports prior to formally documenting it. Auditor?s Addendum As discussed in the finding, we did not find evidence that the Department communicated or implemented the Contract and Compliance Management Desk Manual during the fiscal year that would outline reviews of the SOC reports received by the Department. C. Agree Implementation Date: June 2022 The Department will develop, implement, and document the process to comply with the OSC Fiscal Procedure Manual, Statewide System and Organizational Controls Reviews requirements.
Show full finding ▾Hide full finding ▴The following findings and recommendations are related to both financial reporting and federal program internal control weaknesses. They were included within Volume I ? The Statewide Financial Report and, therefore, are not repeated in this Volume II. These findings and recommendations can be found within Section II: Financial Statement Findings of the Volume I Report. See See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-010 Colorado interChange SOC Report In 2017, the Department implemented the interChange system to replace the legacy Medicaid Management Information System. The Medicaid program is the State?s program, partially funded through the federal Medicaid grant, which provides public health insurance to eligible low-income citizens. The Department is responsible for both the Medicaid program and the interChange system. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is Gainwell Technologies LLC (Gainwell), formerly DXC Technology Services, LLC. Gainwell hosts the interChange system for the Department and manages IT services related to the maintenance and support of the system infrastructure and software. The Department?s contractual agreement with Gainwell requires it, as a service organization for the Department, to have an annual SOC examination performed by an independent service auditor. Examinations of this type are governed by the AICPA and result in one of various types of SOC reports. For the Department, Gainwell provides a SOC 1 report, which provides an independent auditor?s opinion on whether the service organization?s internal controls over financial reporting, including those over the system, have been suitably designed and operate effectively over a specified period. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2020 interChange SOC 1 reporting process recommendation, in which we recommended that the Department improve controls over its financial reporting by developing, documenting, implementing, and communicating a process for conducting annual reviews of the interChange SOC 1 reports to determine if any issues have been noted and whether actions are necessary to remediate these issues. As part of our Fiscal Year 2021 audit work, we also sought to determine the Department?s compliance with SOC 1 report requirements established and published within the Fiscal Procedures Manual, by the OSC. We performed our audit work through inquiry of Department staff, as well as inspection of supporting documentation. How were the results of the audit work measured? The OSC?s policy, Internal Control System, requires state agencies to use the Green Book, published by the GAO, as its framework for its system of internal control. Specifically, Green Book Paragraph OV4.08, Documentation Requirements, states that documentation is a necessary part of an effective internal control system and is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 14.03, Communication throughout the Entity, states that management should communicate quality information to enable personnel to perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management should assign the internal control responsibilities for key roles. Fiscal Procedures Manual Section 3.41, Statewide System and Organizational Controls Reviews, includes agency responsibilities related to the receipt and review of SOC 1 reports. Specifically, the Department must: ? Provide the OSC a copy of its SOC 1 reports within 10 business days of receipt by the Department. ? Annually review the SOC 1 reports and determine whether any actions are necessary to remediate any issues noted. ? Provide a summarized remediation plan to the OSC, including the steps for remediation and when such steps will be taken. What problems did the audit work identify? During our Fiscal Year 2021 audit work, we found that the Department partially implemented our Fiscal Year 2020 recommendation related to the interchange SOC 1 reporting process. Specifically, we found the following: ? The Department developed and documented a desk manual, Contracts and Compliance Management Desk Manual (Manual), that addresses SOC 1 reports, including the roles and responsibilities to perform a review of the SOC 1 report and to document the review in a report summary; however, the Manual was not communicated to staff responsible for following the processes nor was the process implemented by the end of Fiscal Year 2021. ? In the process of reviewing the Manual to determine the disposition of the prior year audit recommendation, we noted that the Department did not document in the Manual a process related to the receipt and review of SOC 1 reports, as required by the OSC?s Fiscal Procedures Manual. Why did these problems occur? Based on our inquiries with the Department, we noted the following: ? The Department stated that it planned to fully implement the process by July 2021; however, the Department did not provide a reason for why the process detailed in the Manual was not communicated to and implemented by staff as of the end of Fiscal Year 2021. ? Although Department staff confirmed that they must comply with the Fiscal Procedures Manual?s SOC 1 report requirements, the Department?s Controller and Health Information Office had not developed a formalized process to include the missing reference to the Fiscal Procedures Manual requirement. Why do these problems matter? Without a formalized SOC 1 review process in place, the Department may not become aware of issues identified in the report relating to the controls its service organizations have designed, implemented, and operate over contracted services, as they relate to financial reporting and compliance with federal regulations. As a result, the Department may fail to address serious issues that impact the data reliability of the interChange system. See See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2021-010 The Department of Health Care Policy and Financing should improve processes over the Colorado interChange?s System and Organization Controls (SOC) reporting by: A. Communicating the processes documented within its newly developed Contract and Compliance Management Desk Manual (Manual) to the appropriate staff responsible for following the processes. B. Implementing the procedures contained within the Manual by conducting the annual review processes on the SOC 1, Type II reports received from its service organizations to determine if any issues have been noted and whether actions are necessary to remediate these issues. C. Formalizing a process to comply with the Office of the State Controller?s Fiscal Procedures Manual, Statewide System and Organizational Controls Reviews requirements. Response Department of Health Care Policy and Financing A. Agree Implementation Date: July 2021 The Department communicated the process to staff on July 7, 2021 in compliance with the July 2021 implementation date provided in August 2020. B. Agree Implementation Date: June 2021 The Department formally documented the process for the review of SOC 1 reports in June 2021. However, the Department had already been following a process to review the SOC 1 reports prior to formally documenting it. Auditor?s Addendum As discussed in the finding, we did not find evidence that the Department communicated or implemented the Contract and Compliance Management Desk Manual during the fiscal year that would outline reviews of the SOC reports received by the Department. C. Agree Implementation Date: June 2022 The Department will develop, implement, and document the process to comply with the OSC Fiscal Procedure Manual, Statewide System and Organizational Controls Reviews requirements.
(A) The Department communicated the process to staff on July 7, 2021 in compliance with the July 2021 implementation date provided in August 2020. (B) The Department formally documented the process for the review of SOC 1 reports in June 2021. However, the Department had already been following a process to review the SOC 1 reports prior to formally documenting it. (C) The Department will develop, implement, and document the process to comply with the OSC Fiscal Procedure Manual, Statewide System and Organizational Controls Reviews requirements.
2020-014
The following finding and recommendation is related to both financial reporting and federal program compliance internal control weaknesses. The finding was included in Volume I ? The Statewide Financial Report and, therefore, is not repeated in this Volume II. This complete finding and recommendation can be found in Section II: Financial Statement Findings of the Volume I Report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-011 Internal Controls over Preparation of Exhibits Departments must prepare financial information in accordance with generally accepted accounting principles (GAAP), as required in statute [Section 24-30-204(1), C.R.S.]. The Department?s accounting staff are responsible for all financial reporting, including the reporting of fiscal year-end accounting information through exhibits submitted to the Office of the State Controller (OSC). The OSC requires that state departments and institutions of higher education prepare and submit exhibits to the OSC after each fiscal year end to assist in its preparation of the State?s financial statements and required note disclosures. The Department reports its fiscal year federal expenditures to the OSC on the Exhibit K1, Schedule of Federal Assistance, for inclusion in the State?s Schedule of Expenditures of Federal Awards (SEFA). In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to assess the adequacy and effectiveness of the Department?s Fiscal Year 2021 internal controls over the preparation of OSC exhibits and to determine whether the Department implemented our Fiscal Year 2020 audit recommendation. We reviewed the Department?s exhibits submitted to the OSC for Fiscal Year 2021 and the related supporting documentation to verify the accuracy of the information reported. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2020 audit recommendation related to the Exhibit K1 preparation. During that audit, we recommended that the Department strengthen its internal controls by reviewing the information on the Exhibit K1 to ensure it is accurate and complete, and coordinate with the OSC when it receives new federal funding to determine how Department staff should report the information on the Exhibit K1. How were the results of the audit work measured? We measured the results of our audit against the following: ? The OSC?s Fiscal Procedures Manual (Manual), Chapter 1, Sections 3.3 and 3.7a, requires State departments to ?establish internal controls for their departments? in order to ?maintain an internal control environment that enhances sound business practices, clearly defines roles, responsibilities, and accountability and provides for the prevention and detection of fraudulent activity.? This includes controls over the preparation of the applicable exhibits for submission to the OSC per the requirements of the Manual. The Manual also contains specific instructions for the completion of various exhibits, including the following: o Exhibit F2, Schedule of Operating Leases, is used to report future minimum payments for operating leases, which are contracts that permit the use of an asset without transferring ownership of the asset. o Exhibit K1, Schedule of Federal Assistance, is used to report the Department?s federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the Exhibit. What problems did the audit work identify? We identified errors and omissions related to 2 of 5 (40 percent) of the Department?s exhibits submitted to the OSC for Fiscal Year 2021. Specifically, we found the following issues: ? Exhibit F2. The Department?s Exhibit F2 contained errors that resulted in an overstatement of lease payments totaling approximately $1.0 million. Specifically, the Department overstated its required lease payments by approximately $1.4 million. The Exhibit F2 also reported amounts that did not agree to the lease agreement, which led to an understatement of about $486,000. Further, the Exhibit F2 incorrectly included an amount for minimum sublease rentals which led to an overstatement of about $131,000. After we brought these issues to the Department?s attention, the Department worked with the OSC and submitted a revised Exhibit F2 to correct the errors. ? Exhibit K1. We found that the Department did not implement our prior audit recommendation related to the preparation of the Exhibit K1. Specifically, we found that the Exhibit K1 did not accurately report the amount for Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) [Assistance Listing Number (ALN) 21.027]. These funds were omitted from the Department?s original Exhibit K1 submission, which led to an understatement of federal expenditures of about $1.6 million. After we brought this issue to the Department?s attention, they submitted a revised Exhibit K1 to the OSC to correct the error. Why did these problems occur? The Department lacked adequate internal controls over preparation and submission of exhibits to the OSC for Fiscal Year 2021. Specifically, the Department did not follow instructions in the Manual for preparing OSC-required exhibits and their review process did not catch the errors identified. For example, on the Exhibit F2 spreadsheet where operating leases are calculated, the Department?s review did not identify amounts from hidden rows that were erroneously included in the calculation. Furthermore, the Department did not implement our prior audit recommendation to coordinate with the OSC regarding how to report new federal funding on the Exhibit K1. Specifically, the Department did not coordinate with the OSC on the CSLFRF funds, which were new in Fiscal Year 2021, leading to the omission of the CSLFRF expenditures on the Exhibit K1. Why do these problems matter? Strong financial accounting internal controls, including effective review processes and procedures over exhibits, are necessary for the Department to ensure that its financial information is recorded and reported appropriately. Without sufficient internal controls, the Department cannot ensure that it is providing complete and accurate financial information to the OSC and, ultimately, that the State?s financial statements are complete and accurate. See See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2021-011 The Department of Higher Education (Department) should strengthen internal controls over the preparation and review of fiscal year-end exhibits submitted to the Office of the State Controller (OSC) by reviewing the information on exhibits to ensure they are accurate and complete prior to submission and coordinating with the OSC when the Department receives new federal funding to determine how it should report the information on the Exhibit K1, Schedule of Federal Assistance. Response Department of Higher Education Agree Implementation Date: September 2022 DHE will be implementing a documented review of all exhibits to be submitted to the Office of State Controller (OSC) by a person who is not the preparer of the exhibit. The preparer will present and review all exhibits with the Chief Financial Officer or other Executive Staff prior to the submission deadline. A reviewed and signed copy by the Chief Financial Officer or other Executive Staff will be kept on file with our year-end close files. DHE will ensure that all staff involved in the preparation and review processes of this recommendation receive adequate training to ensure the exhibits are accurate and comply with the OSC submission requirements. DHE will provide sufficient cross-training of accounting personnel in regard to the key preparation and review controls related to the exhibits, so that in the event of turnover or unexpected leaves of absence, the controls will continue to operate as designed. DHE will request addition training from the OSC on the submission requirements. DHE?s active participation in additional training will ensure that there is an understanding of any newly implemented requirements and will also give an opportunity to clarify any areas of uncertainty in producing the department?s exhibits.
Show full finding ▾Hide full finding ▴The following finding and recommendation is related to both financial reporting and federal program compliance internal control weaknesses. The finding was included in Volume I ? The Statewide Financial Report and, therefore, is not repeated in this Volume II. This complete finding and recommendation can be found in Section II: Financial Statement Findings of the Volume I Report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2021-011 Internal Controls over Preparation of Exhibits Departments must prepare financial information in accordance with generally accepted accounting principles (GAAP), as required in statute [Section 24-30-204(1), C.R.S.]. The Department?s accounting staff are responsible for all financial reporting, including the reporting of fiscal year-end accounting information through exhibits submitted to the Office of the State Controller (OSC). The OSC requires that state departments and institutions of higher education prepare and submit exhibits to the OSC after each fiscal year end to assist in its preparation of the State?s financial statements and required note disclosures. The Department reports its fiscal year federal expenditures to the OSC on the Exhibit K1, Schedule of Federal Assistance, for inclusion in the State?s Schedule of Expenditures of Federal Awards (SEFA). In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to assess the adequacy and effectiveness of the Department?s Fiscal Year 2021 internal controls over the preparation of OSC exhibits and to determine whether the Department implemented our Fiscal Year 2020 audit recommendation. We reviewed the Department?s exhibits submitted to the OSC for Fiscal Year 2021 and the related supporting documentation to verify the accuracy of the information reported. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2020 audit recommendation related to the Exhibit K1 preparation. During that audit, we recommended that the Department strengthen its internal controls by reviewing the information on the Exhibit K1 to ensure it is accurate and complete, and coordinate with the OSC when it receives new federal funding to determine how Department staff should report the information on the Exhibit K1. How were the results of the audit work measured? We measured the results of our audit against the following: ? The OSC?s Fiscal Procedures Manual (Manual), Chapter 1, Sections 3.3 and 3.7a, requires State departments to ?establish internal controls for their departments? in order to ?maintain an internal control environment that enhances sound business practices, clearly defines roles, responsibilities, and accountability and provides for the prevention and detection of fraudulent activity.? This includes controls over the preparation of the applicable exhibits for submission to the OSC per the requirements of the Manual. The Manual also contains specific instructions for the completion of various exhibits, including the following: o Exhibit F2, Schedule of Operating Leases, is used to report future minimum payments for operating leases, which are contracts that permit the use of an asset without transferring ownership of the asset. o Exhibit K1, Schedule of Federal Assistance, is used to report the Department?s federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA. The instructions state that the OSC relies on the accuracy of amounts and other information reported on the Exhibit. What problems did the audit work identify? We identified errors and omissions related to 2 of 5 (40 percent) of the Department?s exhibits submitted to the OSC for Fiscal Year 2021. Specifically, we found the following issues: ? Exhibit F2. The Department?s Exhibit F2 contained errors that resulted in an overstatement of lease payments totaling approximately $1.0 million. Specifically, the Department overstated its required lease payments by approximately $1.4 million. The Exhibit F2 also reported amounts that did not agree to the lease agreement, which led to an understatement of about $486,000. Further, the Exhibit F2 incorrectly included an amount for minimum sublease rentals which led to an overstatement of about $131,000. After we brought these issues to the Department?s attention, the Department worked with the OSC and submitted a revised Exhibit F2 to correct the errors. ? Exhibit K1. We found that the Department did not implement our prior audit recommendation related to the preparation of the Exhibit K1. Specifically, we found that the Exhibit K1 did not accurately report the amount for Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) [Assistance Listing Number (ALN) 21.027]. These funds were omitted from the Department?s original Exhibit K1 submission, which led to an understatement of federal expenditures of about $1.6 million. After we brought this issue to the Department?s attention, they submitted a revised Exhibit K1 to the OSC to correct the error. Why did these problems occur? The Department lacked adequate internal controls over preparation and submission of exhibits to the OSC for Fiscal Year 2021. Specifically, the Department did not follow instructions in the Manual for preparing OSC-required exhibits and their review process did not catch the errors identified. For example, on the Exhibit F2 spreadsheet where operating leases are calculated, the Department?s review did not identify amounts from hidden rows that were erroneously included in the calculation. Furthermore, the Department did not implement our prior audit recommendation to coordinate with the OSC regarding how to report new federal funding on the Exhibit K1. Specifically, the Department did not coordinate with the OSC on the CSLFRF funds, which were new in Fiscal Year 2021, leading to the omission of the CSLFRF expenditures on the Exhibit K1. Why do these problems matter? Strong financial accounting internal controls, including effective review processes and procedures over exhibits, are necessary for the Department to ensure that its financial information is recorded and reported appropriately. Without sufficient internal controls, the Department cannot ensure that it is providing complete and accurate financial information to the OSC and, ultimately, that the State?s financial statements are complete and accurate. See See Schedule of Findings and Questioned Costs for chart/table. Recommendation 2021-011 The Department of Higher Education (Department) should strengthen internal controls over the preparation and review of fiscal year-end exhibits submitted to the Office of the State Controller (OSC) by reviewing the information on exhibits to ensure they are accurate and complete prior to submission and coordinating with the OSC when the Department receives new federal funding to determine how it should report the information on the Exhibit K1, Schedule of Federal Assistance. Response Department of Higher Education Agree Implementation Date: September 2022 DHE will be implementing a documented review of all exhibits to be submitted to the Office of State Controller (OSC) by a person who is not the preparer of the exhibit. The preparer will present and review all exhibits with the Chief Financial Officer or other Executive Staff prior to the submission deadline. A reviewed and signed copy by the Chief Financial Officer or other Executive Staff will be kept on file with our year-end close files. DHE will ensure that all staff involved in the preparation and review processes of this recommendation receive adequate training to ensure the exhibits are accurate and comply with the OSC submission requirements. DHE will provide sufficient cross-training of accounting personnel in regard to the key preparation and review controls related to the exhibits, so that in the event of turnover or unexpected leaves of absence, the controls will continue to operate as designed. DHE will request addition training from the OSC on the submission requirements. DHE?s active participation in additional training will ensure that there is an understanding of any newly implemented requirements and will also give an opportunity to clarify any areas of uncertainty in producing the department?s exhibits.
DHE will be implementing a documented review of all exhibits to be submitted to the Office of State Controller (OSC) by a person who is not the preparer of the exhibit. The preparer will present and review all exhibits with the Chief Financial Officer or other Executive Staff prior to the submission deadline. A reviewed and signed copy by the Chief Financial Officer or other Executive Staff will be kept on file with our year-end close files. DHE will ensure that all staff involved in the preparation and review processes of this recommendation receive adequate training to ensure the exhibits are accurate and comply with the OSC submission requirements. DHE will provide sufficient cross-training of accounting personnel in regard to the key preparation and review controls related to the exhibits, so that in the event of turnover or unexpected leaves of absence, the controls will continue to operate as designed. DHE will request addition training from the OSC on the submission requirements. DHE?s active participation in additional training will ensure that there is an understanding of any newly implemented requirements and will also give an opportunity to clarify any areas of uncertainty in producing the department?s exhibits.
2020-073
Finding 2021-041 Medicaid Eligibility?Social Security Numbers associated with Multiple State IDs Each beneficiary?s Medicaid application must contain specific information, including the beneficiary?s Social Security Number (SSN), a copy of their birth certificate, and support for their income, necessary for determining their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD), which is managed by the Office of Information Technology (OIT), is designed to assign a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange, the Department?s Medicaid claims payment system, on a daily basis to update eligibility information, such as a beneficiary?s eligibility status or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including assessing the Department?s progress in implementing our Fiscal Year 2019 recommendation related to this issue. At that time, we recommended that the Department improve its internal controls in this area to ensure that it complies with federal regulations regarding Medicaid eligibility. The Department agreed with the Fiscal Year 2019 recommendation and, during our Fiscal Year 2021 audit, reported that it had implemented this recommendation as of December 2020. As part of our testing, we reviewed the internal controls the Department had in place during Fiscal Year 2021 to identify any beneficiaries whose SSN is linked to more than one State ID in Colorado interChange. During our audit, we requested a list of all Medicaid claims that were submitted by providers and paid by the Department from December 1, 2020, through June 30, 2021, including the beneficiaries? names, SSNs, and State IDs. The Department provided a list that included approximately 924,000 beneficiaries who received benefits during that period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries from December 2020 through June 2021. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within one year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to one year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation. During our testing, we identified 102 unique SSNs that appeared to be inappropriately associated with more than one State ID; in total, the 102 SSNs were tied to 209 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN and, as a result, made claims payments on behalf of ineligible beneficiaries or the SSNs could be valid, but with more than one State ID, a provider could submit and have a claim paid for the same services under both State IDs. Specifically, we found the following: ? For 62 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 129 different State IDs, where the State IDs appeared to be for different people based on the names and/or dates of birth. ? For 40 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 80 different State IDs, where the State IDs had the same name and date of birth. ? For 99 SSNs, each SSN was tied to two different State IDs in Colorado interChange. ? For three SSNs, each SSN was tied to more than two different State IDs in Colorado interChange. For example, in one of the three instances, there were five different State IDs associated with one invalid SSN. These issues affected a total of 209 Medicaid State IDs that had not been corrected as of June 2021, representing a total of $67,235 Medicaid claims paid through Colorado interChange from December 2020 through June 2021. We provided the list of SSNs and State IDs to the Department to research. The Department found that, as of the end of our audit in April 2022, 59 out of the 102 SSNs identified during the audit had been corrected by a caseworker, but 43 SSNs need to be corrected in CBMS. The Department reported that these 43 SSNs had been flagged through a system edit in CBMS implemented in December 2020; however, the SSNs had not yet been corrected because ?To merge or correct [the SSNs and State IDs] is a time intensive process and must be prioritized within the business process of the [local counties and] Medical Assistance sites.? Although the Department was able to determine which SSN and State ID discrepancies had been corrected in CBMS as of April 2022, the Department has not completed its research to determine which claims made in Colorado interChange were made on behalf of beneficiaries with a correct SSN, and whether the implemented system edit appropriately addresses the issues identified in both Fiscal Years 2019 and 2021. As of the end of the audit, the Department had not completed this research and we were unable to determine whether the payments were made on behalf of beneficiaries with a valid SSN at the time payments were made. Therefore, we consider all $67,235 of the payments to be known questioned costs; $37,786 of these costs were paid with federal grant funds. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements] (Uniform Guidance), is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place during Fiscal Year 2021 to prevent or detect all instances of multiple State IDs associated with the same SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. SIDMOD does not prevent several situations that can result in the same SSN with more than one State ID. For example, caseworkers could incorrectly input an SSN into CBMS or the SSN could be reported by the beneficiary incorrectly and, as a result, cause a new State ID to be created. There can also be instances when someone changes their name, such as when they get married, and apply for benefits prior to getting married and also after getting married, which could cause two State IDs to be created. If someone starts an application and does not finish the application and then restarts a new application at a later date, this can also cause two State IDs to be created. Further, when inputting multiple family members into the system, an input error of the SSN can occur with multiple family members with the same SSN, which would create multiple State IDs (one for each family member) with the same SSN. According to the Department, in order to implement the Fiscal Year 2019 recommendation, it implemented a system edit in CBMS in December 2020 that is designed to identify discrepancies in newly-entered or updated SSNs and State IDs in CBMS after that date and to then notify the caseworker so the caseworker can address the discrepancy; this edit was not designed to address SSN and State ID discrepancies that existed prior to December 2020. As a result, the system edit did not identify SSN and State ID discrepancies for claims made from December 2020 to June 2021 if those discrepancies existed prior to the implementation of the system edit in CBMS and the beneficiaries? information had not been updated in CBMS. For example, if a beneficiary had an incorrect SSN prior to the system edit and was, therefore, ineligible to receive Medicaid services, Colorado interChange would continue paying claims on behalf of the beneficiary until information was updated in CBMS and the beneficiary was determined to be ineligible for Medicaid. Because the system edit implemented in CBMS is only designed to detect and correct future SSN and State ID discrepancies, the Department has not fully addressed the issue of inappropriate claims payments that we identified in the prior audit recommendation. According to the Department, addressing SSN and State ID discrepancies that existed prior to December 2020 involves a manual process to identify, research, and resolve the discrepancies. The Department stated that a report to identify SSNs with multiple State IDs is being developed and is currently scheduled for deployment in June 2023. Furthermore, the Department has not established a monitoring process over caseworkers to ensure SSN and State ID discrepancies are addressed appropriately and in a timely manner. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to multiple State IDs associated with the same SSN. For example, without adequate controls in place to prevent multiple State IDs from being created, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-041 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid eligibility by: A. Researching the claims payments that were identified during our audit to determine whether the local counties or Medical Assistance sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate?in accordance with federal regulation at the time the payments were made?and recovering any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify SSNs associated with multiple State IDs and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. C. Implementing a process to monitor that caseworkers are addressing the Colorado Benefits Management System alerts related to SSN and State ID discrepancies appropriately and in a timely manner. Response Department of Health Care Policy and Financing A. Disagree The research required to identify the appropriateness of payments for 102 SSNs compared to the 1.6 million Coloradans the Department serves is administratively impractical and not an efficient use of limited state resources. Instead the Department will continue our existing proactive approach. Based on previous research, 92% of errors noted in the 2019 sample actually supplied a SSN or met exceptions criteria; therefore, payments were appropriate. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs, which is working since 58% of the SSNs had already been corrected through the existing process during the audit work. The Department could not agree to the questioned costs as the testing failed to determine which member case was incorrect. The OSA should have documented the incorrect case or identified which State IDs had not been merged through the existing process. The OSA pulled claims data (not Colorado Benefits Management System, or CBMS, cases) and did not identify if those claims were from newly entered cases or cases entered prior to December 2020. The auditor?s sample should have only included the cases impacted by the Department?s system change related to the original recommendation. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department?s system, that provider is guaranteed payment if they render an authorized service. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or that we ?question? as appropriate. It is ultimately the Department?s responsibility to perform research over questioned costs to determine whether the payments were or were not appropriate and, working with CMS, whether the Department must refund the federal share of any overpayments to CMS, regardless of whether the Department recovers the payments from the providers. B. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. C. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
Show full finding ▾Hide full finding ▴Finding 2021-041 Medicaid Eligibility?Social Security Numbers associated with Multiple State IDs Each beneficiary?s Medicaid application must contain specific information, including the beneficiary?s Social Security Number (SSN), a copy of their birth certificate, and support for their income, necessary for determining their Medicaid eligibility. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, the State Identification Module (SIDMOD), which is managed by the Office of Information Technology (OIT), is designed to assign a unique State ID for each beneficiary. CBMS interfaces with Colorado interChange, the Department?s Medicaid claims payment system, on a daily basis to update eligibility information, such as a beneficiary?s eligibility status or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a medical provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth, but not the SSN, submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. The Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department made claims payments on behalf of beneficiaries with the same SSN but different State IDs, including assessing the Department?s progress in implementing our Fiscal Year 2019 recommendation related to this issue. At that time, we recommended that the Department improve its internal controls in this area to ensure that it complies with federal regulations regarding Medicaid eligibility. The Department agreed with the Fiscal Year 2019 recommendation and, during our Fiscal Year 2021 audit, reported that it had implemented this recommendation as of December 2020. As part of our testing, we reviewed the internal controls the Department had in place during Fiscal Year 2021 to identify any beneficiaries whose SSN is linked to more than one State ID in Colorado interChange. During our audit, we requested a list of all Medicaid claims that were submitted by providers and paid by the Department from December 1, 2020, through June 30, 2021, including the beneficiaries? names, SSNs, and State IDs. The Department provided a list that included approximately 924,000 beneficiaries who received benefits during that period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID, and to determine if any claims payments were made on behalf of those beneficiaries from December 2020 through June 2021. How were the results of the audit work measured? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish a SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. Further, the Department is required by federal regulations to repay the federal government the federal share of any overpayments within one year. Specifically, pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to one year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS regardless of whether recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problem did the audit work identify? We determined that the Department has not fully implemented the prior audit recommendation. During our testing, we identified 102 unique SSNs that appeared to be inappropriately associated with more than one State ID; in total, the 102 SSNs were tied to 209 State IDs. This could indicate that the Department determined eligibility without a beneficiary furnishing the correct SSN and, as a result, made claims payments on behalf of ineligible beneficiaries or the SSNs could be valid, but with more than one State ID, a provider could submit and have a claim paid for the same services under both State IDs. Specifically, we found the following: ? For 62 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 129 different State IDs, where the State IDs appeared to be for different people based on the names and/or dates of birth. ? For 40 SSNs, the SSNs were tied to beneficiaries with more than one State ID, totaling 80 different State IDs, where the State IDs had the same name and date of birth. ? For 99 SSNs, each SSN was tied to two different State IDs in Colorado interChange. ? For three SSNs, each SSN was tied to more than two different State IDs in Colorado interChange. For example, in one of the three instances, there were five different State IDs associated with one invalid SSN. These issues affected a total of 209 Medicaid State IDs that had not been corrected as of June 2021, representing a total of $67,235 Medicaid claims paid through Colorado interChange from December 2020 through June 2021. We provided the list of SSNs and State IDs to the Department to research. The Department found that, as of the end of our audit in April 2022, 59 out of the 102 SSNs identified during the audit had been corrected by a caseworker, but 43 SSNs need to be corrected in CBMS. The Department reported that these 43 SSNs had been flagged through a system edit in CBMS implemented in December 2020; however, the SSNs had not yet been corrected because ?To merge or correct [the SSNs and State IDs] is a time intensive process and must be prioritized within the business process of the [local counties and] Medical Assistance sites.? Although the Department was able to determine which SSN and State ID discrepancies had been corrected in CBMS as of April 2022, the Department has not completed its research to determine which claims made in Colorado interChange were made on behalf of beneficiaries with a correct SSN, and whether the implemented system edit appropriately addresses the issues identified in both Fiscal Years 2019 and 2021. As of the end of the audit, the Department had not completed this research and we were unable to determine whether the payments were made on behalf of beneficiaries with a valid SSN at the time payments were made. Therefore, we consider all $67,235 of the payments to be known questioned costs; $37,786 of these costs were paid with federal grant funds. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements] (Uniform Guidance), is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [45 CFR 75.516] as questioned costs that are specifically identified by the auditor. Why did this problem occur? The Department did not have adequate internal controls in place during Fiscal Year 2021 to prevent or detect all instances of multiple State IDs associated with the same SSN in Colorado interChange and, as a result, could not ensure only eligible beneficiaries received Medicaid services. SIDMOD does not prevent several situations that can result in the same SSN with more than one State ID. For example, caseworkers could incorrectly input an SSN into CBMS or the SSN could be reported by the beneficiary incorrectly and, as a result, cause a new State ID to be created. There can also be instances when someone changes their name, such as when they get married, and apply for benefits prior to getting married and also after getting married, which could cause two State IDs to be created. If someone starts an application and does not finish the application and then restarts a new application at a later date, this can also cause two State IDs to be created. Further, when inputting multiple family members into the system, an input error of the SSN can occur with multiple family members with the same SSN, which would create multiple State IDs (one for each family member) with the same SSN. According to the Department, in order to implement the Fiscal Year 2019 recommendation, it implemented a system edit in CBMS in December 2020 that is designed to identify discrepancies in newly-entered or updated SSNs and State IDs in CBMS after that date and to then notify the caseworker so the caseworker can address the discrepancy; this edit was not designed to address SSN and State ID discrepancies that existed prior to December 2020. As a result, the system edit did not identify SSN and State ID discrepancies for claims made from December 2020 to June 2021 if those discrepancies existed prior to the implementation of the system edit in CBMS and the beneficiaries? information had not been updated in CBMS. For example, if a beneficiary had an incorrect SSN prior to the system edit and was, therefore, ineligible to receive Medicaid services, Colorado interChange would continue paying claims on behalf of the beneficiary until information was updated in CBMS and the beneficiary was determined to be ineligible for Medicaid. Because the system edit implemented in CBMS is only designed to detect and correct future SSN and State ID discrepancies, the Department has not fully addressed the issue of inappropriate claims payments that we identified in the prior audit recommendation. According to the Department, addressing SSN and State ID discrepancies that existed prior to December 2020 involves a manual process to identify, research, and resolve the discrepancies. The Department stated that a report to identify SSNs with multiple State IDs is being developed and is currently scheduled for deployment in June 2023. Furthermore, the Department has not established a monitoring process over caseworkers to ensure SSN and State ID discrepancies are addressed appropriately and in a timely manner. Why does this problem matter? Failing to institute appropriate controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. This includes ensuring that the Department has sufficient internal controls to address risks related to multiple State IDs associated with the same SSN. For example, without adequate controls in place to prevent multiple State IDs from being created, providers could erroneously or fraudulently submit duplicate claims under these State IDs for the same services, resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-041 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid eligibility by: A. Researching the claims payments that were identified during our audit to determine whether the local counties or Medical Assistance sites had a valid Social Security Number (SSN) when determining eligibility, if payments were appropriate?in accordance with federal regulation at the time the payments were made?and recovering any payments made to providers on behalf of ineligible beneficiaries in accordance with federal regulations. B. Continuing to develop a report to identify SSNs associated with multiple State IDs and establishing and implementing written policies and procedures outlining how the Department will use the report to effectively monitor and correct SSN and State ID discrepancies. C. Implementing a process to monitor that caseworkers are addressing the Colorado Benefits Management System alerts related to SSN and State ID discrepancies appropriately and in a timely manner. Response Department of Health Care Policy and Financing A. Disagree The research required to identify the appropriateness of payments for 102 SSNs compared to the 1.6 million Coloradans the Department serves is administratively impractical and not an efficient use of limited state resources. Instead the Department will continue our existing proactive approach. Based on previous research, 92% of errors noted in the 2019 sample actually supplied a SSN or met exceptions criteria; therefore, payments were appropriate. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs, which is working since 58% of the SSNs had already been corrected through the existing process during the audit work. The Department could not agree to the questioned costs as the testing failed to determine which member case was incorrect. The OSA should have documented the incorrect case or identified which State IDs had not been merged through the existing process. The OSA pulled claims data (not Colorado Benefits Management System, or CBMS, cases) and did not identify if those claims were from newly entered cases or cases entered prior to December 2020. The auditor?s sample should have only included the cases impacted by the Department?s system change related to the original recommendation. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department?s system, that provider is guaranteed payment if they render an authorized service. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or that we ?question? as appropriate. It is ultimately the Department?s responsibility to perform research over questioned costs to determine whether the payments were or were not appropriate and, working with CMS, whether the Department must refund the federal share of any overpayments to CMS, regardless of whether the Department recovers the payments from the providers. B. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. C. Agree Implementation Date: June 2023 The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
(A) The research required to identify the appropriateness of payments for 102 SSNs compared to the 1.6 million Coloradans the Department serves is administratively impractical and not an efficient use of limited state resources. Instead the Department will continue our existing proactive approach. Based on previous research, 92% of errors noted in the 2019 sample actually supplied a SSN or met exceptions criteria; therefore, payments were appropriate. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs, which is working since 58% of the SSNs had already been corrected through the existing process during the audit work. The Department could not agree to the questioned costs as the testing failed to determine which member case was incorrect. The OSA should have documented the incorrect case or identified which State IDs had not been merged through the existing process. The OSA pulled claims data (not Colorado Benefits Management System, or CBMS, cases) and did not identify if those claims were from newly entered cases or cases entered prior to December 2020. The auditor?s sample should have only included the cases impacted by the Department?s system change related to the original recommendation. Further, the Department cannot recover any payments from providers since this issue is not related to services provided. When a provider checks a member's eligibility on the day of service and finds the member eligible through the Department?s system, that provider is guaranteed payment if they render an authorized service. (B) The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. The Department will develop and implement policies and procedures outlining how the report will be used to effectively monitor and correct SSN and State ID discrepancies. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs. (C ) The Department will continue our existing proactive approach to minimize this issue. The resolution of a SSN discrepancy is addressed through manual intervention by county eligibility technicians when identified through the system edit implemented in December 2020. The Department will continue the existing process to address duplicate SSNs. The Department has already made significant progress to monitor CBMS through the use of CBMS monitoring dashboards. These dashboards allow the Department to monitor and perform daily analysis. The Department meets bi-weekly to discuss findings and next steps to resolve any issues identified through the dashboard. These dashboards are being implemented over time as areas of improvements are identified. As part of the Department's continual improvement strategy, SSN discrepancy reports are included in the next implementation phase of the monitoring dashboards scheduled for June 2023. Once that work is complete, the Department will send updated written guidance to our county and medical assistance sites on how to use system edits, reports, and dashboards to resolve duplicate SSNs appropriately and in a timely manner.
2020-043
Finding 2021-042 Medical Loss Ratio Reporting for Managed Care Entities The Department contracts with Managed Care Entities (MCEs) to provide managed care health plans and deliver health care services to eligible Medicaid and CBHP beneficiaries and pays MCEs monthly fixed amounts, known as capitation payments, based on rates determined by actuaries for the provision of services covered under the contract. The Department pays the MCEs monthly capitation payments on behalf of each Medicaid and CBHP beneficiary enrolled in the MCE?s plan. MCEs then coordinate services for the eligible Medicaid and CBHP beneficiaries and providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid and CBHP beneficiaries. The MCEs are then responsible for paying the providers for the Medicaid and CBHP claims. The Department contracts with three different types of MCEs?Managed Care Organizations (MCO), Prepaid Inpatient Health Plans (PIHP), and Primary Care Case Management (PCCM) Entities. During Fiscal Year 2021, the Department had a total of 8 contracts with 10 MCEs, with two pairs of MCEs sharing a single contract with the Department. The Department is responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions, including requirements that the MCEs annually submit Medical Loss Ratio (MLR) reports to the Department. The MLR is the proportion of state and federal Medicaid and CBHP funds that the MCE used for medical services compared to the funds used for its administrative costs. MCEs are required by both federal regulations and their Department contract provisions to have an MLR above 85 percent (i.e., an MCE?s administrative costs cannot exceed 15 percent) except for specific exceptions defined in federal regulations. If the MLR is below 85 percent, the MCE must pay back the state and federal government for the amount that caused the MCE to fall below 85 percent. Every fiscal year, the Department provides an MLR reporting template for the MCEs to complete and return to the Department. The Department reported that when it receives the completed templates, staff review the information provided by the MCEs and compare it to supporting documentation to ensure it is accurate and complete. Once the Department has reviewed the MLR reports submitted by the MCEs, the Department submits the MLR reports to CMS, which are due by June 30 of the year following the end of the MLR reporting year. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation to CMS by June 30, 2021. During Fiscal Year 2021, the Department reported that it paid approximately $1.4 billion in Medicaid and CBHP capitation payments to MCEs for medical services, not including the capitation payments for other services, such as administrative costs. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department?s internal controls and compliance over ensuring that MLR reports submitted to CMS by the Department include all the required information in accordance with federal regulations during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over obtaining and reviewing MLR reports from each MCE. In addition, we requested and reviewed all MLR reports submitted to the Department by the 10 MCEs that were under contract with the Department in Fiscal Year 2021 to determine whether the MLR reports included all information required by federal regulations and were submitted within the required timeframes. How were the results of the audit work measured? Federal regulations [42 CFR 438.8(k)] require that the Department ensure each MCE under contract with the Department submits a report with the data elements specified in 42 CFR section 438.8(k)(1). The reports are specifically required to contain 13 required data elements, reflect the correct reporting years, and contain an attestation of accuracy regarding the calculation of the MLR. The 13 data elements include items such as total incurred claims, the methodology for allocating expenditures, the calculated MLR, and a comparison of the information reported in the MLR report to the MCE?s audited financial report. Federal regulations [42 CFR 438.8(g)] note that the method used to allocate expenses in the MLR calculation must be: ? Based on a generally accepted accounting method that is expected to yield the most accurate results; ? Any shared expenses must be apportioned pro rata to the contract incurring the expense; and ? Expenses that relate solely to the operation of a reporting entity must be borne solely by the reporting entity and are not to be apportioned to other entities. Federal regulations [42 CFR 438.8(k)(2)] require MCEs to submit the MLR report in a timeframe and manner determined by the Department, which must be within 12 months of the end of the MCE?s reporting year. The Department?s contract provisions for MCEs state that the MLR reporting year should align with the State?s fiscal year, beginning on July 1 and ending on June 30 of the subsequent calendar year. Contract provisions also state that each MCE shall submit to the Department the completed MLR calculation template and supporting documentation for each reporting year by the following January 15. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation template to the Department by January 15, 2021, and the Department would be required to submit the MLR calculation to CMS by June 30, 2021. What problems did the audit work identify? We reviewed all reports provided to the Department by the 10 MCEs during Fiscal Year 2021 (for the MLR reporting year ended June 30, 2020) and determined that none of the MLR reports submitted by the 10 MCEs to the Department contained all of the required data elements in Fiscal Year 2021. Specifically, the MLR reports were missing 2 of the 13 (15 percent) required data elements: the methodology for the MCEs? allocation of expenditures and a comparison of the information reported in the MLR report to the MCEs? audited financial reports. This omission is significant because the MCEs reported total medical expenditures ranging from $20.5 million to $208.4 million and earned revenue from $23.4 million to $219.1 million. In addition, we determined that 1 of the 10 MLR reports received in Fiscal Year 2021 (10 percent) had not been submitted to CMS as of April 2022. This report was due to CMS on June 30, 2021. Why did these problems occur? We found that the Department lacked adequate controls to ensure that MLR reports submitted by the MCEs fully complied with federal regulations. First, we noted that although the Department?s MCE contracts state the MCE?s MLR report should include all 13 federally required data elements, the MLR template the Department provided to the MCEs did not include specific sections addressing the two missing federally-required data elements. As a result, the MCEs did not submit this information. Furthermore, the Department did not have written policies and procedures for reviewing completed MLR reports to ensure the reports ultimately included those requirements. Second, the Department does not have an enforcement mechanism to ensure the MCEs provide corrected MLR report information in a timely manner. The Department reported that it had not submitted the one MLR report to CMS because it had open questions on the MLR report and was unable to verify that the information was correct, valid, and in compliance with federal regulations. Although the Department sent the MLR report back to the MCE for correction several times, the Department did not have sufficient controls in place to ensure the MCE ultimately provided the corrected report back to the Department within the required reporting timeline for CMS submission. Why do these problems matter? The Department is responsible for ensuring MLR reports are obtained and submitted to CMS in accordance with federal regulations and that MCEs have an MLR above 85 percent. While all 10 MCEs reported that their MLRs were above 85 percent for the reports submitted during Fiscal Year 2021, without providing all required data elements, neither the Department nor the federal government can validate that this percentage is accurate. By not including the methodology for the MCE?s allocation of expenditures, the Department, and ultimately CMS, are unable to confirm that each type of expense is being allocated correctly and that any shared expenses are being prorated appropriately. Additionally, by not including a comparison of the information reported in the MRL to the MCE?s audited financial report, the Department is unable to confirm that the information the MCE used to calculate their MLR is accurate. Overall, without effective internal controls in place, the Department risks providing MLR reports to CMS that contain inaccurate or incomplete information or that the MLR is below 85 percent and the Department does not catch the error. As a result, state and federal funds could be used disproportionately on administrative costs rather than medical services, which would negatively impact the quality of care Medicaid and CBHP beneficiaries receive. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Medical Loss Ratio (MLR) reporting by: A. Updating its MLR report template provided to Managed Care Entities (MCEs) to comply with federal regulations and developing and implementing written policies and procedures. These policies and procedures should include the requirement for MCEs to submit MLR reports that include the data elements required by federal regulations and specify the Department?s review process of those MLR reports to ensure they include accurate and complete information. B. Developing an enforcement mechanism to ensure it receives accurate and corrected information from the MCEs in a timely manner so the Department is able to complete its validation process of MLR reports and meet the June 30 deadline for report submission to the Centers for Medicare & Medicaid Services. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2022 The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. B. Agree Implementation Date: January 2023 The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
Show full finding ▾Hide full finding ▴Finding 2021-042 Medical Loss Ratio Reporting for Managed Care Entities The Department contracts with Managed Care Entities (MCEs) to provide managed care health plans and deliver health care services to eligible Medicaid and CBHP beneficiaries and pays MCEs monthly fixed amounts, known as capitation payments, based on rates determined by actuaries for the provision of services covered under the contract. The Department pays the MCEs monthly capitation payments on behalf of each Medicaid and CBHP beneficiary enrolled in the MCE?s plan. MCEs then coordinate services for the eligible Medicaid and CBHP beneficiaries and providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid and CBHP beneficiaries. The MCEs are then responsible for paying the providers for the Medicaid and CBHP claims. The Department contracts with three different types of MCEs?Managed Care Organizations (MCO), Prepaid Inpatient Health Plans (PIHP), and Primary Care Case Management (PCCM) Entities. During Fiscal Year 2021, the Department had a total of 8 contracts with 10 MCEs, with two pairs of MCEs sharing a single contract with the Department. The Department is responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions, including requirements that the MCEs annually submit Medical Loss Ratio (MLR) reports to the Department. The MLR is the proportion of state and federal Medicaid and CBHP funds that the MCE used for medical services compared to the funds used for its administrative costs. MCEs are required by both federal regulations and their Department contract provisions to have an MLR above 85 percent (i.e., an MCE?s administrative costs cannot exceed 15 percent) except for specific exceptions defined in federal regulations. If the MLR is below 85 percent, the MCE must pay back the state and federal government for the amount that caused the MCE to fall below 85 percent. Every fiscal year, the Department provides an MLR reporting template for the MCEs to complete and return to the Department. The Department reported that when it receives the completed templates, staff review the information provided by the MCEs and compare it to supporting documentation to ensure it is accurate and complete. Once the Department has reviewed the MLR reports submitted by the MCEs, the Department submits the MLR reports to CMS, which are due by June 30 of the year following the end of the MLR reporting year. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation to CMS by June 30, 2021. During Fiscal Year 2021, the Department reported that it paid approximately $1.4 billion in Medicaid and CBHP capitation payments to MCEs for medical services, not including the capitation payments for other services, such as administrative costs. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to review the Department?s internal controls and compliance over ensuring that MLR reports submitted to CMS by the Department include all the required information in accordance with federal regulations during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over obtaining and reviewing MLR reports from each MCE. In addition, we requested and reviewed all MLR reports submitted to the Department by the 10 MCEs that were under contract with the Department in Fiscal Year 2021 to determine whether the MLR reports included all information required by federal regulations and were submitted within the required timeframes. How were the results of the audit work measured? Federal regulations [42 CFR 438.8(k)] require that the Department ensure each MCE under contract with the Department submits a report with the data elements specified in 42 CFR section 438.8(k)(1). The reports are specifically required to contain 13 required data elements, reflect the correct reporting years, and contain an attestation of accuracy regarding the calculation of the MLR. The 13 data elements include items such as total incurred claims, the methodology for allocating expenditures, the calculated MLR, and a comparison of the information reported in the MLR report to the MCE?s audited financial report. Federal regulations [42 CFR 438.8(g)] note that the method used to allocate expenses in the MLR calculation must be: ? Based on a generally accepted accounting method that is expected to yield the most accurate results; ? Any shared expenses must be apportioned pro rata to the contract incurring the expense; and ? Expenses that relate solely to the operation of a reporting entity must be borne solely by the reporting entity and are not to be apportioned to other entities. Federal regulations [42 CFR 438.8(k)(2)] require MCEs to submit the MLR report in a timeframe and manner determined by the Department, which must be within 12 months of the end of the MCE?s reporting year. The Department?s contract provisions for MCEs state that the MLR reporting year should align with the State?s fiscal year, beginning on July 1 and ending on June 30 of the subsequent calendar year. Contract provisions also state that each MCE shall submit to the Department the completed MLR calculation template and supporting documentation for each reporting year by the following January 15. For example, an MCE with a reporting year ending June 30, 2020, would be required to submit the MLR calculation template to the Department by January 15, 2021, and the Department would be required to submit the MLR calculation to CMS by June 30, 2021. What problems did the audit work identify? We reviewed all reports provided to the Department by the 10 MCEs during Fiscal Year 2021 (for the MLR reporting year ended June 30, 2020) and determined that none of the MLR reports submitted by the 10 MCEs to the Department contained all of the required data elements in Fiscal Year 2021. Specifically, the MLR reports were missing 2 of the 13 (15 percent) required data elements: the methodology for the MCEs? allocation of expenditures and a comparison of the information reported in the MLR report to the MCEs? audited financial reports. This omission is significant because the MCEs reported total medical expenditures ranging from $20.5 million to $208.4 million and earned revenue from $23.4 million to $219.1 million. In addition, we determined that 1 of the 10 MLR reports received in Fiscal Year 2021 (10 percent) had not been submitted to CMS as of April 2022. This report was due to CMS on June 30, 2021. Why did these problems occur? We found that the Department lacked adequate controls to ensure that MLR reports submitted by the MCEs fully complied with federal regulations. First, we noted that although the Department?s MCE contracts state the MCE?s MLR report should include all 13 federally required data elements, the MLR template the Department provided to the MCEs did not include specific sections addressing the two missing federally-required data elements. As a result, the MCEs did not submit this information. Furthermore, the Department did not have written policies and procedures for reviewing completed MLR reports to ensure the reports ultimately included those requirements. Second, the Department does not have an enforcement mechanism to ensure the MCEs provide corrected MLR report information in a timely manner. The Department reported that it had not submitted the one MLR report to CMS because it had open questions on the MLR report and was unable to verify that the information was correct, valid, and in compliance with federal regulations. Although the Department sent the MLR report back to the MCE for correction several times, the Department did not have sufficient controls in place to ensure the MCE ultimately provided the corrected report back to the Department within the required reporting timeline for CMS submission. Why do these problems matter? The Department is responsible for ensuring MLR reports are obtained and submitted to CMS in accordance with federal regulations and that MCEs have an MLR above 85 percent. While all 10 MCEs reported that their MLRs were above 85 percent for the reports submitted during Fiscal Year 2021, without providing all required data elements, neither the Department nor the federal government can validate that this percentage is accurate. By not including the methodology for the MCE?s allocation of expenditures, the Department, and ultimately CMS, are unable to confirm that each type of expense is being allocated correctly and that any shared expenses are being prorated appropriately. Additionally, by not including a comparison of the information reported in the MRL to the MCE?s audited financial report, the Department is unable to confirm that the information the MCE used to calculate their MLR is accurate. Overall, without effective internal controls in place, the Department risks providing MLR reports to CMS that contain inaccurate or incomplete information or that the MLR is below 85 percent and the Department does not catch the error. As a result, state and federal funds could be used disproportionately on administrative costs rather than medical services, which would negatively impact the quality of care Medicaid and CBHP beneficiaries receive. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over Medical Loss Ratio (MLR) reporting by: A. Updating its MLR report template provided to Managed Care Entities (MCEs) to comply with federal regulations and developing and implementing written policies and procedures. These policies and procedures should include the requirement for MCEs to submit MLR reports that include the data elements required by federal regulations and specify the Department?s review process of those MLR reports to ensure they include accurate and complete information. B. Developing an enforcement mechanism to ensure it receives accurate and corrected information from the MCEs in a timely manner so the Department is able to complete its validation process of MLR reports and meet the June 30 deadline for report submission to the Centers for Medicare & Medicaid Services. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2022 The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. B. Agree Implementation Date: January 2023 The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
(A) The MLR report template has been updated and will now be reviewed at least yearly by the Department. In addition, new written policies and procedures are being developed and will be implemented before the submission of the next MLR for review. (B) The Department will add contract language and enforcement mechanisms in order to receive accurate information in a timely manner. This includes specific timelines for correcting incomplete or inaccurate information in order to submit the MLR report timely to the Centers for Medicare & Medicaid Services.
Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
Show full finding ▾Hide full finding ▴Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https:hcpf.colorado.gov/quality-and-healthimprovement-reports.
Finding 2021-044 Federal Funding Accountability and Transparency Reporting for the Medicaid and Children?s Basic Health Plan Programs The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s FFATA reports include information on Medicaid and CBHP subawards. The Department is required to file a FFATA report in the following circumstances: ? If the initial award is equal to or more than $30,000; ? If subsequent grant modifications result in a total award are equal to or more than $30,000; ? If the initial award is equal to or more than $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, it submitted FFATA reports for 94 subawards in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with the Transparency Act reporting requirements for the Medicaid and CBHP programs during Fiscal Year 2021 and whether the information in the Department?s submitted FFATA reports were accurate. To assess the Department?s internal controls and compliance with federal requirements, we inquired of the Department related to its policies and procedures over FFATA reporting. In addition, we requested a list of all Medicaid and CBHP subawards made by the Department during Fiscal Year 2021. We then selected a sample of 5 subawards and requested copies of the FFATA reports that were uploaded to the FSRS system by the Department in June 2021. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2021 if an award or supplemental award equal to or greater than $30,000 was made in April 2021. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. Transparency Act reporting requirements outlined on the FSRS website prescribe certain information that must be reported for these subawards, including the name of the entity receiving the award, the award amount, funding agency, and unique identifier of the entity. What problem did the audit work identify? The Department was unable to provide copies of the FFATA reports for any of the five subawards (100 percent) that we requested. While the Department was able to provide support that the FFATA reports were submitted to FSRS, the Department could not provide the full FFATA reports from FSRS and, therefore, we were unable to verify that the information in the reports matched the subawards. Specifically, we could not verify the subaward number and amount, the unique identifier of the entity, and the date the reports were submitted. While some of this information is viewable on the FSRS public website, we were unable to agree the information on the Department?s subaward documents to the FSRS website information and the Department could not provide us this information. Why did this problem occur? The Department did not have policies and procedures in place to ensure that all FFATA reports submitted through FSRS during Fiscal Year 2021 were accessible to Department staff. According to the FSRS Awardee User Guide, FSRS only allows the individual user who entered the FFATA reports into the system to access the full report for that month, and the Department reported that the employee that entered the reports for the subawards we tested is no longer employed with the Department. In addition, the Department did not have a process to ensure copies of the FFATA reports were downloaded and maintained by the Department in case of employee turnover. As a result, the Department could not provide the FFATA reports from FSRS. After we brought the reporting issue to Department staff, they reported that they reached out to the FSRS Help Desk for support to access the FFATA reports for Fiscal Years 2021 and 2022, but had not received a response as of April 2022. Why does this problem matter? It is important for the Department to ensure it has access to previously submitted FFATA reports, especially when they are needed to support compliance with federal regulations. This issue could lead to inaccurate reporting and potential noncompliance. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-044 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting process by: A. Developing and implementing policies and procedures to ensure the Transparency Act reporting is accessible to Department staff, including requirements to download and maintain copies of the reports in order to ensure reports can be accessed, especially in the event of employee turnover or changes in job responsibilities. B. Continue working with the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) Help Desk to obtain access to any FFATA reports that are not currently accessible to Department staff for Fiscal Years 2021 and 2022. Response Department of Health Care Policy and Financing A. Agree Implementation Date: June 2022 The Department will amend its existing procedures to include downloading the FSRS reporting after each successful monthly upload. B. Agree Implementation Date: June 2022 The Department will continue to attempt to contact the help desk at fsd.gov to obtain the reports for which it currently does not have access.
Show full finding ▾Hide full finding ▴Finding 2021-044 Federal Funding Accountability and Transparency Reporting for the Medicaid and Children?s Basic Health Plan Programs The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s FFATA reports include information on Medicaid and CBHP subawards. The Department is required to file a FFATA report in the following circumstances: ? If the initial award is equal to or more than $30,000; ? If subsequent grant modifications result in a total award are equal to or more than $30,000; ? If the initial award is equal to or more than $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000. The Department is required to report the subaward information in FSRS no later than the end of the month following the month in which the award was made. According to the Department, it submitted FFATA reports for 94 subawards in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had adequate internal controls over and complied with the Transparency Act reporting requirements for the Medicaid and CBHP programs during Fiscal Year 2021 and whether the information in the Department?s submitted FFATA reports were accurate. To assess the Department?s internal controls and compliance with federal requirements, we inquired of the Department related to its policies and procedures over FFATA reporting. In addition, we requested a list of all Medicaid and CBHP subawards made by the Department during Fiscal Year 2021. We then selected a sample of 5 subawards and requested copies of the FFATA reports that were uploaded to the FSRS system by the Department in June 2021. The full FFATA reports are only accessible by the Department and are not fully viewable on FSRS. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to FSRS in May 2021 if an award or supplemental award equal to or greater than $30,000 was made in April 2021. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. Transparency Act reporting requirements outlined on the FSRS website prescribe certain information that must be reported for these subawards, including the name of the entity receiving the award, the award amount, funding agency, and unique identifier of the entity. What problem did the audit work identify? The Department was unable to provide copies of the FFATA reports for any of the five subawards (100 percent) that we requested. While the Department was able to provide support that the FFATA reports were submitted to FSRS, the Department could not provide the full FFATA reports from FSRS and, therefore, we were unable to verify that the information in the reports matched the subawards. Specifically, we could not verify the subaward number and amount, the unique identifier of the entity, and the date the reports were submitted. While some of this information is viewable on the FSRS public website, we were unable to agree the information on the Department?s subaward documents to the FSRS website information and the Department could not provide us this information. Why did this problem occur? The Department did not have policies and procedures in place to ensure that all FFATA reports submitted through FSRS during Fiscal Year 2021 were accessible to Department staff. According to the FSRS Awardee User Guide, FSRS only allows the individual user who entered the FFATA reports into the system to access the full report for that month, and the Department reported that the employee that entered the reports for the subawards we tested is no longer employed with the Department. In addition, the Department did not have a process to ensure copies of the FFATA reports were downloaded and maintained by the Department in case of employee turnover. As a result, the Department could not provide the FFATA reports from FSRS. After we brought the reporting issue to Department staff, they reported that they reached out to the FSRS Help Desk for support to access the FFATA reports for Fiscal Years 2021 and 2022, but had not received a response as of April 2022. Why does this problem matter? It is important for the Department to ensure it has access to previously submitted FFATA reports, especially when they are needed to support compliance with federal regulations. This issue could lead to inaccurate reporting and potential noncompliance. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-044 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting process by: A. Developing and implementing policies and procedures to ensure the Transparency Act reporting is accessible to Department staff, including requirements to download and maintain copies of the reports in order to ensure reports can be accessed, especially in the event of employee turnover or changes in job responsibilities. B. Continue working with the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) Help Desk to obtain access to any FFATA reports that are not currently accessible to Department staff for Fiscal Years 2021 and 2022. Response Department of Health Care Policy and Financing A. Agree Implementation Date: June 2022 The Department will amend its existing procedures to include downloading the FSRS reporting after each successful monthly upload. B. Agree Implementation Date: June 2022 The Department will continue to attempt to contact the help desk at fsd.gov to obtain the reports for which it currently does not have access.
(A) The Department has amended its existing procedures to include downloading the FSRS reporting after each successful monthly upload. (B) The Department will continue to attempt to contact the help desk at fsd.gov to obtain the reports for which it currently does not have access.
Finding 2021-045 Payments for Non-Emergent Medical Transportation Claims Prior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned costs for chart/table The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned for chart/table When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds.
Show full finding ▾Hide full finding ▴Finding 2021-045 Payments for Non-Emergent Medical Transportation Claims Prior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned costs for chart/table The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned for chart/table When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds.
(A) Implemented. Completion Date: December 14, 2021 The Department updated those providers identified in Intelliride?s service area to Performer Only on December 14, 2021. As of this date these providers cannot bill the Department directly for services; they must go through Intelliride. A provider communication was sent to these providers informing them of this change. The Department verified Providers outside of Intelliride?s service area are appropriately set as Biller and Performer. These providers may bill the Department directly. (B) The Department will review and revise, as necessary, its taxi claim billing requirements and rates to ensure that they are consistent. In addition, the Department will devise controls to ensure that taxi claims are paid in accordance with established requirements and rates and explore controls to ensure that only permitted providers bill as a taxi. The Department is working on reductions in the max fee and unit limits for taxi claim billing codes, which it will have completed by the end of October 2021. In addition, the Department is considering systematically pricing the code at each taxi provider?s specific Public Utilities Commission (PUC) rate. This change, if pursued, will require a system change request, which will take a year or more, which is why the Department has selected an implementation date of December 2022. If this proves infeasible, alternate controls will be implemented. (C) The Department implemented a manual review process with the Fiscal Agent for NEMT claims to ensure proper documentation showing authorization is in place before claims will be paid. (D) The Department intends to define in rule the types of documentation that NEMT providers must keep on hand and make clear that they must furnish records to the Department upon request. The July 2022 date will allow for the completion of formal rulemaking. The Department further intends to develop and implement a process to perform regular risk-based provider file reviews with a focus on noncompliant providers. These reviews will ensure, at a minimum, that the providers? paid claims are supported with appropriate documentation and represent the least costly option appropriate to meet each recipient?s needs. (E) The Department will amend its contract with its NEMT broker by adding a mandatory annual audit so that it can reconcile trip scheduling data with paid claims data. This will help ensure that the Department pays accurately, pays for NEMT services, and pays for the least costly transportation option appropriate for each recipient. The Department chose July 2022 to add the audit through its annual contract amendment and renewal processes. (F) The Department will develop a data review process to reconcile interChange data on NEMT trip claims to interChange data on Medicaid medical claims. This process will entail periodic reviews of NEMT claims to see if members have corresponding medical claims on those dates. If they do not, the Department will follow up with the appropriate NEMT provider to investigate. The July 2022 implementation date reflects the potential need for system changes. (G) Department staff will work with the Department?s Program Integrity (PI) staff on processes to investigate and recover, as appropriate, the overpayments and inappropriate payments that the audit identified as known or likely questioned costs, and repay the federal portion, as appropriate. The December 2022 implementation date reflects the time needed to investigate and when appropriate, recover any overpayments. (H) The Department will develop a process to track staff time and productivity to ensure that it has sufficient staff assigned to oversee and administer NEMT. This process will include documenting time spent each week on various tasks to get a sense of where help is needed, and which tasks take up the most staff resources. Based on its findings, the Department will explore staffing options, as needed. The Department selected the July 2022 implementation date to allow for data collection through the end of State Fiscal Year 2021-22.
Finding 2021-046 Payments to Non-Emergent Medical Transportation Providers As the statewide broker in Fiscal Year 2021, IntelliRide served as the fiscal agent responsible for submitting claims to the Department for each NEMT ride it brokered and paid those ride providers for their services. Specifically, after an NEMT provider completed a trip that IntelliRide brokered, the provider sent IntelliRide an invoice requesting reimbursement, and IntelliRide confirmed the invoice matched EcoLane data on completed trips, paid the provider the invoice amount, sent the Department a claim through interChange to request reimbursement, and kept accounting records of the date and amount it paid each provider. From July 1, 2020, through February 28, 2021, IntelliRide brokered NEMT trips for 119 providers and received reimbursement from the Department for provider payments it made for trip claims totaling about $19.8 million. How were the results of the audit work measured? The purpose of the audit work was to determine whether the Department has ensured that IntelliRide paid providers accurately. The Department?s statewide broker contract with IntelliRide?effective during the audit period July 1, 2020, through February 28, 2021?required IntelliRide to, ?pay the transportation provider the full amount of the Colorado interChange payment? for each trip [Contract Section 15.1.6]. What audit work was performed, what problems were identified, and why do they matter? Overall, we found that IntelliRide failed to pay some providers the full amounts that the providers were owed for NEMT services, even though the Department had paid the full amount as reimbursement to IntelliRide. We compared the Department?s interChange data on claims payments sent to IntelliRide for NEMT provider services with IntelliRide?s accounting records of its payments to providers during the audit period. We found that IntelliRide may not have paid a total of $126,840 to 28 NEMT providers for services rendered. As shown in the following table, IntelliRide did not fully pay 28 of the 119 providers (24 percent) after the Department sent IntelliRide payments for the providers? services. When we brought this problem to IntelliRide?s attention, its management indicated that it believed it had paid providers the amounts owed, but could not provide any evidence to support that the payments were made and did not plan to investigate the problem further, citing that it would be too resource intensive. See Schedule of Findings and Questioned Costs for chart/table According to IntelliRide, it did not actually underpay Provider 1, rather the discrepancy was due to an accounting reporting error. However, during the audit, Provider 1 told us that it believed it was underpaid by IntelliRide, but not by the amount we calculated, and this provider did not have another estimate of the amount. IntelliRide was not able to provide evidence confirming that it had paid Provider 1 accurately. When the Department?s contractor, IntelliRide, does not pay NEMT providers for each service provided, it can affect the providers? business operations, such as their ability to pay their employees. We surveyed NEMT providers and 20 of the 45 (44 percent) providers that responded to payment questions told us they were dissatisfied with the accuracy of IntelliRide?s payments for the trips they provided recipients; 10 of the 45 (22 percent) providers indicated that they were neutral. None of the providers in the western part of the state that responded to our survey indicated that they were satisfied with the accuracy of IntelliRide?s payments. A majority of these providers (14 of 20) reported confusion or frustration with IntelliRide?s accounting records and payment documents, including that it is difficult for providers to know what rides they have been paid for and if it was for the full amount. Additionally, there is a risk of fraud, waste, and abuse of Medicaid funds when the Department?s contractor does not pay providers accurately based on the payments it has received from the Department or keep accurate accounting records of its payments to providers for each Medicaid claim paid by the Department. When we provided the Department and IntelliRide information on the underpayments to providers that we identified, neither could determine how IntelliRide spent the Department?s Medicaid funds received to reimburse providers for NEMT trips. Why did these problems occur? The Department has not ensured that its contractor has effective methods for paying providers accurately. Specifically, the Department has not held IntelliRide accountable for having accounting processes to accurately reimburse providers for their trips or maintaining accurate records of payments to providers. For example, neither the Department nor IntelliRide has a process in place to compare data on the claims payments the Department sends IntelliRide to the payments IntelliRide makes to providers, such as quarterly reconciliations. Additionally, the Department does not require IntelliRide to provide any reporting to demonstrate that it pays providers accurately, such as evidence that IntelliRide?s payments to providers reconcile with the provider invoices, so IntelliRide does not track the extent to which it pays each invoice. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-046 The Department of Health Care Policy and Financing (Department) should ensure non-emergent medical transportation (NEMT) providers are paid accurately for the services they provide to recipients by: A. Requiring its NEMT contractor to develop and implement effective processes and methods to pay providers accurately for their services, based on claims paid by the Department, and maintain accurate accounting records of payments to providers. B. Investigating each instance identified by the audit where the Department?s NEMT contractor did not pay a provider accurately or did not have accurate accounting records, and requiring the contractor to pay each provider the accurate amounts they are owed and correct accounting records, as appropriate. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2021 The Department will require its NEMT contractor will pay providers in fully and accurately by billing the Department first and then passing the full reimbursement amount on to providers. The Department will further require the contractor to maintain accurate accounting records of payments to providers. The Department will ensure full and accurate payment by performing a semi-annual comparison of IntelliRide?s accounting data with the Department?s paid claims data, and by requiring corrective action (e.g., additional reimbursements for underpayments) as appropriate. The Department?s NEMT contractor will provide additional training to providers on how to use the provider portal, which contains complete records of trips and paid amounts for each trip. B. Agree Implementation Date: April 2022 The Department will use instances of underpayment or inaccurate payment identified by OSA as a basis for its investigation. We will compare the Department?s payments to IntelliRide with payments issued by IntelliRide and those received by an NEMT provider. The Department will then work with IntelliRide to ensure correct payment amounts to each provider, when appropriate, and update its accounting records.
Show full finding ▾Hide full finding ▴Finding 2021-046 Payments to Non-Emergent Medical Transportation Providers As the statewide broker in Fiscal Year 2021, IntelliRide served as the fiscal agent responsible for submitting claims to the Department for each NEMT ride it brokered and paid those ride providers for their services. Specifically, after an NEMT provider completed a trip that IntelliRide brokered, the provider sent IntelliRide an invoice requesting reimbursement, and IntelliRide confirmed the invoice matched EcoLane data on completed trips, paid the provider the invoice amount, sent the Department a claim through interChange to request reimbursement, and kept accounting records of the date and amount it paid each provider. From July 1, 2020, through February 28, 2021, IntelliRide brokered NEMT trips for 119 providers and received reimbursement from the Department for provider payments it made for trip claims totaling about $19.8 million. How were the results of the audit work measured? The purpose of the audit work was to determine whether the Department has ensured that IntelliRide paid providers accurately. The Department?s statewide broker contract with IntelliRide?effective during the audit period July 1, 2020, through February 28, 2021?required IntelliRide to, ?pay the transportation provider the full amount of the Colorado interChange payment? for each trip [Contract Section 15.1.6]. What audit work was performed, what problems were identified, and why do they matter? Overall, we found that IntelliRide failed to pay some providers the full amounts that the providers were owed for NEMT services, even though the Department had paid the full amount as reimbursement to IntelliRide. We compared the Department?s interChange data on claims payments sent to IntelliRide for NEMT provider services with IntelliRide?s accounting records of its payments to providers during the audit period. We found that IntelliRide may not have paid a total of $126,840 to 28 NEMT providers for services rendered. As shown in the following table, IntelliRide did not fully pay 28 of the 119 providers (24 percent) after the Department sent IntelliRide payments for the providers? services. When we brought this problem to IntelliRide?s attention, its management indicated that it believed it had paid providers the amounts owed, but could not provide any evidence to support that the payments were made and did not plan to investigate the problem further, citing that it would be too resource intensive. See Schedule of Findings and Questioned Costs for chart/table According to IntelliRide, it did not actually underpay Provider 1, rather the discrepancy was due to an accounting reporting error. However, during the audit, Provider 1 told us that it believed it was underpaid by IntelliRide, but not by the amount we calculated, and this provider did not have another estimate of the amount. IntelliRide was not able to provide evidence confirming that it had paid Provider 1 accurately. When the Department?s contractor, IntelliRide, does not pay NEMT providers for each service provided, it can affect the providers? business operations, such as their ability to pay their employees. We surveyed NEMT providers and 20 of the 45 (44 percent) providers that responded to payment questions told us they were dissatisfied with the accuracy of IntelliRide?s payments for the trips they provided recipients; 10 of the 45 (22 percent) providers indicated that they were neutral. None of the providers in the western part of the state that responded to our survey indicated that they were satisfied with the accuracy of IntelliRide?s payments. A majority of these providers (14 of 20) reported confusion or frustration with IntelliRide?s accounting records and payment documents, including that it is difficult for providers to know what rides they have been paid for and if it was for the full amount. Additionally, there is a risk of fraud, waste, and abuse of Medicaid funds when the Department?s contractor does not pay providers accurately based on the payments it has received from the Department or keep accurate accounting records of its payments to providers for each Medicaid claim paid by the Department. When we provided the Department and IntelliRide information on the underpayments to providers that we identified, neither could determine how IntelliRide spent the Department?s Medicaid funds received to reimburse providers for NEMT trips. Why did these problems occur? The Department has not ensured that its contractor has effective methods for paying providers accurately. Specifically, the Department has not held IntelliRide accountable for having accounting processes to accurately reimburse providers for their trips or maintaining accurate records of payments to providers. For example, neither the Department nor IntelliRide has a process in place to compare data on the claims payments the Department sends IntelliRide to the payments IntelliRide makes to providers, such as quarterly reconciliations. Additionally, the Department does not require IntelliRide to provide any reporting to demonstrate that it pays providers accurately, such as evidence that IntelliRide?s payments to providers reconcile with the provider invoices, so IntelliRide does not track the extent to which it pays each invoice. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-046 The Department of Health Care Policy and Financing (Department) should ensure non-emergent medical transportation (NEMT) providers are paid accurately for the services they provide to recipients by: A. Requiring its NEMT contractor to develop and implement effective processes and methods to pay providers accurately for their services, based on claims paid by the Department, and maintain accurate accounting records of payments to providers. B. Investigating each instance identified by the audit where the Department?s NEMT contractor did not pay a provider accurately or did not have accurate accounting records, and requiring the contractor to pay each provider the accurate amounts they are owed and correct accounting records, as appropriate. Response Department of Health Care Policy and Financing A. Agree Implementation Date: December 2021 The Department will require its NEMT contractor will pay providers in fully and accurately by billing the Department first and then passing the full reimbursement amount on to providers. The Department will further require the contractor to maintain accurate accounting records of payments to providers. The Department will ensure full and accurate payment by performing a semi-annual comparison of IntelliRide?s accounting data with the Department?s paid claims data, and by requiring corrective action (e.g., additional reimbursements for underpayments) as appropriate. The Department?s NEMT contractor will provide additional training to providers on how to use the provider portal, which contains complete records of trips and paid amounts for each trip. B. Agree Implementation Date: April 2022 The Department will use instances of underpayment or inaccurate payment identified by OSA as a basis for its investigation. We will compare the Department?s payments to IntelliRide with payments issued by IntelliRide and those received by an NEMT provider. The Department will then work with IntelliRide to ensure correct payment amounts to each provider, when appropriate, and update its accounting records.
(A) IntelliRide now bills the Department for trips and passes the full payment amount on to the providers (in contrast with the old practice of paying providers and then billing the Department). IntelliRide keeps accurate accounting data on disbursements to providers. The Department investigates and helps reconcile differences when providers report underpayments. Finally, IntelliRide continues to offer trainings on how to use their provider portal. (B) This has been implemented. The department is in regular contact with the broker and payments have been correct.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Individuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations. Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020. We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE. Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. STATISTICAL SAMPLING METHODOLOGY We selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period. Our methodology included the following procedures: ? We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary. ? We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period. ? We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG). ? For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period. ? After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period. See Schedule of Findings and Questioned Costs for chart/table. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? For 32 of the 125 Medicaid beneficiaries? case files that we tested (26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs. PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million. PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projections. See Schedule of FIndings and Questioned Costs for chart/table. The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: ? PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102. Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments. According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? ? INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020. State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI. ? INCOME ISSUES. We identified the following income-related issues: ? INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281. ? INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280. ? INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. ? INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines. Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income. ? MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. ? BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs. State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits. ? INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs. State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Individuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations. Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid. Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020. We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE. Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. STATISTICAL SAMPLING METHODOLOGY We selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period. Our methodology included the following procedures: ? We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary. ? We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period. ? We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG). ? For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period. ? After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period. See Schedule of Findings and Questioned Costs for chart/table. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? For 32 of the 125 Medicaid beneficiaries? case files that we tested (26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. A questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs. PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million. PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projections. See Schedule of FIndings and Questioned Costs for chart/table. The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: ? PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102. Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments. According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? ? INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020. State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI. ? INCOME ISSUES. We identified the following income-related issues: ? INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281. ? INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280. ? INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs. ? INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines. Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income. ? MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. ? BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs. State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits. ? INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs. State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.
(A) Caseworker errors can be caused by an array of issues, including, training material retention; a lack of adequate funding to balance caseload inventory versus available work hours and staffing levels; a lack of quality review and performance reinforcement; and an assortment of local issues that lead to employee turnover. The Department will continue to work with eligibility sites regarding caseworker errors identified through this audit. The Department?s caseworker training resources, or Staff Development Center (SDC), is in the process of revamping all of their foundational training materials into a "Process-Based Training" model to be more effective and efficient based on training industry best practice. In addition, the SDC is converting all training materials into several different training modalities (instructor led courses, eLearning courses, desk aids, process manuals, infographics, workbooks, etc.) to be more engaging, effective, and accessible to adult learners with varying needs and preferences across large geographical areas. The revised training model is on track to be completed by July 31, 2021 and fully rolled out to all counties by the beginning of calendar year 2022. (B) The Department implemented the Eligibility Site Oversight and Accountability Program in February 2021. The Monitoring Dashboard Phase 1 was implemented in June 2020, and Phase 2 of the Dashboard is delayed until July 2023 due to competing priorities. (C) The Department has thoroughly researched the issues identified in this audit and has made changes to CBMS to ensure that it is using the correct income information, income thresholds in determining eligibility, and buy-in premiums are assessed. These issues were fixed May 2019, February 2020, and March 2020, and in June 2021 the income information system issue will be corrected. The Department disagrees with the auditor?s questioned costs and projection of those questions costs. The Department disagrees with the auditor?s sampling, stratification, and costs used to generate the projected questioned costs. The costs incorrectly include members who remain eligible once the identified error had been resolved, payments that will be recovered by the Department through an existing process to recover capitation payments from deceased members, a Social Security Administration (SSA) interface error outside the control of the Department, and costs related to an already identified issue regarding reconciling eligibility between CBMS and Colorado interChange. Some of these costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department and should have been excluded from the questioned costs and the resulting projections. The Department will resume the reconciliation process between CBMS and Colorado interChange when authorized by CMS. Regarding the SSA interfaces, SSA posted results that are valid conditions for Medicaid eligibility, so those costs should have been excluded from the resulting projections. The Department agrees to bring interface issues to the attention of SSA.
2020-034
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIES As a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death. Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations. CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death. In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered. Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows: MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death. We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds. MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP. We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds. The following table summarizes the issues we identified. See Schedule of Findings and Questioned Costs for chart/table. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows: ? LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death. ? SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified: ? According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death. ? The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments. WHY DO THESE PROBLEMS MATTER? Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-035 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by: A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations. B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries. C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. B AGREE. IMPLEMENTATION DATE: JULY 2022. The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. AUDITOR?S ADDENDUM As noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines. AUDITOR?S ADDENDUM As noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIES As a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death. Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations. CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death. In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered. Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows: MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death. We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds. MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP. We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds. The following table summarizes the issues we identified. See Schedule of Findings and Questioned Costs for chart/table. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows: ? LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death. ? SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified: ? According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death. ? The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments. WHY DO THESE PROBLEMS MATTER? Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-035 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by: A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations. B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries. C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. B AGREE. IMPLEMENTATION DATE: JULY 2022. The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. AUDITOR?S ADDENDUM As noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines. AUDITOR?S ADDENDUM As noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
(A) The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. (B) The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death. (C) The review for FFS claims is complete and all Notices of Adverse Action have been sent to providers. At this time we are waiting on any requests for informal reconsiderations, appeals, and/or payments to process.
2020-035
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. We performed the following testwork: REVIEW OF CBHP ELIGIBILITY CASE FILES ? We reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees. ? Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program. DATA ANALYSES OF CBHP BENEFICIARIES ? INELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits. ? CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits. CBHP ELIGIBILITY MONITORING AND REVIEW We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY CASE FILE ISSUES In 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP. The following table outlines the types of issues we found. See Schedule of Findings and Questioned Costs for chart/table. The specific issues we identified and the breakdown of identified questioned costs are as follows: ? CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically: ? In seven cases, the Department did not assess an enrollment fee. ? In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries. Benefits were inappropriately paid on behalf of these 10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260. State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program. ? LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546. State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. ? INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines. In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level. ? MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows: ? In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs. ? In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs. According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].? State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES We identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows. CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified 39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020. We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)]. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....? Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider. CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange. We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS. In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020. Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP. The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004]. The following table summarizes the eligibility issues we identified through our data analyses. See Schedule of FIndings and Questioned Costs for chart/table. ELIGIBILITY MONITORING ISSUES CBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations. CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income. MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations. SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals. Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. We performed the following testwork: REVIEW OF CBHP ELIGIBILITY CASE FILES ? We reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees. ? Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program. DATA ANALYSES OF CBHP BENEFICIARIES ? INELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits. ? CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits. CBHP ELIGIBILITY MONITORING AND REVIEW We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY CASE FILE ISSUES In 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP. The following table outlines the types of issues we found. See Schedule of Findings and Questioned Costs for chart/table. The specific issues we identified and the breakdown of identified questioned costs are as follows: ? CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically: ? In seven cases, the Department did not assess an enrollment fee. ? In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries. Benefits were inappropriately paid on behalf of these 10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260. State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program. ? LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546. State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. ? INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines. In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level. ? MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows: ? In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs. ? In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs. According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].? State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES We identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows. CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified 39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020. We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds. According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)]. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....? Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider. CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange. We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS. In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020. Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP. The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004]. The following table summarizes the eligibility issues we identified through our data analyses. See Schedule of FIndings and Questioned Costs for chart/table. ELIGIBILITY MONITORING ISSUES CBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHY DID THESE PROBLEMS OCCUR? Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations. CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income. MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations. SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals. Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.
(A) The Child Health Plan Plus (CHP+) program enrollment fee at intake is being eliminated. In an effort to remove barriers for families seeking health coverage, the Department of Health Care Policy and Financing (HCPF) and the Colorado General Assembly championed a health care bill that also included an amendment to eliminate the CHP+ enrollment fee at intake and renewal. Effective 07/01/2022, the enrollment fee will no longer be required at intake for the CHP+ program. The CBMS project build date for this system change is 6/11/22. Please be advised, the requirement to collect an annual enrollment fee for CHP+ at renewal is currently suspended due to the Public Health Emergency (PHE) and will be permanently discontinued at the end of the PHE. (B) The Department revised its training model which is on track and will be fully rolled out to all eligibility sites by July 2022. (C) The Department began the implementation of a new monitoring process called the Eligibility Site Oversight and Accountability Program in February 2021 (Operational Memo OM21-004). Reference files named 778-034-10-2 & 778-041-10-0MAP Measure Owner Training.pdf, 778-034-10-2 & 778-041-10-0 OM 21-004, and 778-034-10-2 & 778-041-10-0 OM 21-079, 778-034-10-2 & 778-041-10-0 OM 21-005, and 778-034-10-2 & 778-041-10-0 ColoradoRegister. This documentation clearly shows that the new oversight monitoring process was implemented and that CBHP eligibility is processed in accordance with federal regulations and federal grant requirements. (D) The Department disagrees with the auditor?s findings and questioned costs related to capitation payments under the Eligibility Issues Identified through Data Analyses section. These costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department. The Department was actively working to resolve these cases with CMS prior to the Public Health Emergency (PHE). The Department developed and implemented a reconciliation report that is used to research and resolve CBMS and Colorado interChange interface mismatches. Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS. (E) The three remaining errors had to do with the CHP+ Enrollment fee. The Child Health Plan Plus (CHP+) program enrollment fee at intake is being eliminated. In an effort to remove barriers for families seeking health coverage, the Department of Health Care Policy and Financing (HCPF) and the Colorado General Assembly championed a health care bill that also included an amendment to eliminate the CHP+ enrollment fee at intake and renewal. Effective 07/01/2022, the enrollment fee will no longer be required at intake for the CHP+ program due to Colorado House Bill (HB) 22-1289. The CBMS project build date for this system change is 6/11/22. Please be advised, the requirement to collect an annual enrollment fee for CHP+ at renewal is currently suspended due to the Public Health Emergency (PHE) and will be permanently discontinued at the end of the PHE.
2020-036
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTS The Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified. The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS. The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system. The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate. The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020. During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations. Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS. The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following: ? UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest. According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider. According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment. ? INACCURATE FEDERAL REPORTING. For all 13 Medicaid (100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance. Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections. ? EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the 13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired. According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division. ? INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS. Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors: ? LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports. ? LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet. ? LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports. ? LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments. WHY DO THESE PROBLEMS MATTER? Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations. Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-037 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by: A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports. B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations. C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports. D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. D AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTS The Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified. The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS. The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system. The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate. The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020. During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations. Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS. The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following: ? UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest. According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider. According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment. ? INACCURATE FEDERAL REPORTING. For all 13 Medicaid (100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance. Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections. ? EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the 13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired. According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division. ? INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS. Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors: ? LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports. ? LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet. ? LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports. ? LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments. WHY DO THESE PROBLEMS MATTER? Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations. Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-037 The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by: A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports. B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations. C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports. D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. D AGREE. IMPLEMENTATION DATE: JULY 2022. The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
(A) The training materials have been created, and the training will take place on June 23, 2022. (B) The policies and procedures have been updated and will be effective on July 1, 2022. (C) The Department implemented procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports. (D) The Program Integrity Division has created a supervisory review process that is included in the updated policies and procedures. This process is effective July 1, 2022.
2020-037
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PRESUMPTIVE ELIGIBILITY Colorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible. To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020. During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews. In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following: ? UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. ? LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020. State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site. ? LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following: ? For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020. ? 11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes. ? Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored. Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?. According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed. Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations. ? MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible. Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible. ? SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs. CBMS is designed to display case and applicant information consistently between various screens within the system. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: ? LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites. ? LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations. ? CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens. WHY DO THESE PROBLEMS MATTER? As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-038 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by: A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites. B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed. C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it. C AGREE. IMPLEMENTATION DATE: IMPLEMENTED. Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it. AUDITOR?S ADDENDUM for Parts A, B, and C As noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PRESUMPTIVE ELIGIBILITY Colorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible. To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases. The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020. During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews. In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange. The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following: ? UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits. Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made. ? LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020. State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site. ? LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following: ? For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020. ? 11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes. ? Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored. Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?. According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed. Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations. ? MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible. Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible. ? SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs. CBMS is designed to display case and applicant information consistently between various screens within the system. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified: ? LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites. ? LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations. ? CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens. WHY DO THESE PROBLEMS MATTER? As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-038 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by: A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites. B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed. C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it. C AGREE. IMPLEMENTATION DATE: IMPLEMENTED. Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it. AUDITOR?S ADDENDUM for Parts A, B, and C As noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
(A) The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it. (B) The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the recertifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it.
2020-038
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PROVIDER ELIGIBILITY The providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP. Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020. Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers. We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year. We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment. In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: ? FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.? ? STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations. ? DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license. ? FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under 42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services. ? CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP. ? FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s). WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES INELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows: ? 13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers. ? One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract. ELIGIBILITY CASE FILE ISSUES MISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations. ? INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner. ? POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance. ? LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs. Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-039 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by: A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired. B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations. C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PROVIDER ELIGIBILITY The providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP. Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020. Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers. We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year. We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment. In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020. The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: ? FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.? ? STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations. ? DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license. ? FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under 42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services. ? CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP. ? FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s). WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section. ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSES INELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows: ? 13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers. ? One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract. ELIGIBILITY CASE FILE ISSUES MISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations. ? INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner. ? POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance. ? LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs. Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-039 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by: A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired. B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations. C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented. C AGREE. IMPLEMENTATION DATE: JULY 2022. The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
(A) The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying. (B) The Department has updated its policies and procedure for reviewing license actions, effective July 1, 2022. (C) The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
2020-039
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID NATIONAL CORRECT CODING INITIATIVE CMS launched the National Correct Coding Initiative (NCCI) in 2010 to promote national coding methodologies and to reduce improper coding, which may result in inappropriate payments of Medicaid claims. Through this initiative, CMS periodically creates edit files, which the states are required to incorporate into their claims processing systems, including Colorado interChange. These edit files contain sensitive information designed to identify and prevent improper payments, based on the types and amounts of services that are included in the claims. CMS has also issued a Medicaid NCCI Technical Guidance Manual (technical guidance) that provides information for state Medicaid agencies with specific instructions to implement these edit files. The Department contracts with a fiscal agent to execute the NCCI methodologies and incorporate the edit files into Colorado interChange. Given the sensitive nature of the information in the edit files, the Department is ultimately responsible for ensuring confidentiality and compliance with the NCCI technical guidance and program requirements. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid NCCI process and to determine whether the Department complied with applicable federal requirements and technical guidance during Fiscal Year 2020. In addition, we reviewed the contract in place between the Department and the fiscal agent during Fiscal Year 2020 to determine whether the contract included a confidentiality agreement that has all of the provisions that CMS requires, as specified in technical guidance. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations [Affordable Care Act (2010), Section 6507(2)(A)(iii)(I) and (II)] require that CMS informs states as to how they must incorporate the NCCI methodologies for claims filed under Medicaid. This regulation requires the Department to incorporate NCCI methodologies into claims processing for the Medicaid program. The technical guidance [Section 7.1.2] specifies seven minimum elements that must be included in each State?s confidentiality agreements, including those incorporated into contracts with any outside party, such as fiscal agents using the Medicaid NCCI edit files. These seven elements specify requirements, such as who may be granted access to the edit files, when the files may be implemented in the claims processing system, and penalties imposed for violations of any confidentiality agreement relating to the use of edit files. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department did not include five of the seven required provisions in the confidentiality agreement section of its contract in place during Fiscal Year 2020 with its fiscal agent as required by the technical guidance. Specifically, the contract did not include the following required elements for the fiscal agent: ? Limiting the disclosures to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter. ? After the start of the new calendar quarter, the fiscal agent may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. ? The fiscal agent shall not implement new, revised, or deleted Medicaid NCCI edits prior to the first day of the calendar quarter. ? Only the Department has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the Medicaid Integrity Institute (MII). ? The Department must impose penalties on the fiscal agent, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files. WHY DID THIS PROBLEM OCCUR? The Department lacked an adequate contract review process to ensure that the confidentiality-agreement section of the contract with the fiscal agent included all of the elements that are required to be in compliance with federal regulations and technical guidance. WHY DOES THIS PROBLEM MATTER? Because the Medicaid NCCI edit files contain sensitive information and are designed to identify and prevent improper payments, the Department risks the disclosure of confidential information without having a confidentiality agreement with all the requirements in place with its fiscal agent. Furthermore, by not including the confidentiality-agreement requirements that are specified in the technical guidance within the contract with the fiscal agent, the Department risks failing to comply with federal regulations and technical guidance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-040 The Department of Health Care Policy and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID NATIONAL CORRECT CODING INITIATIVE CMS launched the National Correct Coding Initiative (NCCI) in 2010 to promote national coding methodologies and to reduce improper coding, which may result in inappropriate payments of Medicaid claims. Through this initiative, CMS periodically creates edit files, which the states are required to incorporate into their claims processing systems, including Colorado interChange. These edit files contain sensitive information designed to identify and prevent improper payments, based on the types and amounts of services that are included in the claims. CMS has also issued a Medicaid NCCI Technical Guidance Manual (technical guidance) that provides information for state Medicaid agencies with specific instructions to implement these edit files. The Department contracts with a fiscal agent to execute the NCCI methodologies and incorporate the edit files into Colorado interChange. Given the sensitive nature of the information in the edit files, the Department is ultimately responsible for ensuring confidentiality and compliance with the NCCI technical guidance and program requirements. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid NCCI process and to determine whether the Department complied with applicable federal requirements and technical guidance during Fiscal Year 2020. In addition, we reviewed the contract in place between the Department and the fiscal agent during Fiscal Year 2020 to determine whether the contract included a confidentiality agreement that has all of the provisions that CMS requires, as specified in technical guidance. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations [Affordable Care Act (2010), Section 6507(2)(A)(iii)(I) and (II)] require that CMS informs states as to how they must incorporate the NCCI methodologies for claims filed under Medicaid. This regulation requires the Department to incorporate NCCI methodologies into claims processing for the Medicaid program. The technical guidance [Section 7.1.2] specifies seven minimum elements that must be included in each State?s confidentiality agreements, including those incorporated into contracts with any outside party, such as fiscal agents using the Medicaid NCCI edit files. These seven elements specify requirements, such as who may be granted access to the edit files, when the files may be implemented in the claims processing system, and penalties imposed for violations of any confidentiality agreement relating to the use of edit files. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department did not include five of the seven required provisions in the confidentiality agreement section of its contract in place during Fiscal Year 2020 with its fiscal agent as required by the technical guidance. Specifically, the contract did not include the following required elements for the fiscal agent: ? Limiting the disclosures to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter. ? After the start of the new calendar quarter, the fiscal agent may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. ? The fiscal agent shall not implement new, revised, or deleted Medicaid NCCI edits prior to the first day of the calendar quarter. ? Only the Department has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the Medicaid Integrity Institute (MII). ? The Department must impose penalties on the fiscal agent, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files. WHY DID THIS PROBLEM OCCUR? The Department lacked an adequate contract review process to ensure that the confidentiality-agreement section of the contract with the fiscal agent included all of the elements that are required to be in compliance with federal regulations and technical guidance. WHY DOES THIS PROBLEM MATTER? Because the Medicaid NCCI edit files contain sensitive information and are designed to identify and prevent improper payments, the Department risks the disclosure of confidential information without having a confidentiality agreement with all the requirements in place with its fiscal agent. Furthermore, by not including the confidentiality-agreement requirements that are specified in the technical guidance within the contract with the fiscal agent, the Department risks failing to comply with federal regulations and technical guidance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-040 The Department of Health Care Policy and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
2020-040
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
(A) The state implemented the first phase of the monitoring dashboard in June 2020 with Project 13889 that identifies members that are active with no SSN without exemptions. The second phase of the monitoring dashboard implementation was pushed back to July 2023 due to competing legislative mandates. (C) The Monitoring Dashboard Phase 1 was implemented in June 2020, and Phase 2 of the Dashboard was delayed until July 2023 due to competing priorities.
2020-041
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: ? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. ? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: ? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. ? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for chart/table. The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments. WHY DID THESE PROBLEMS OCCUR? Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries. After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute. WHY DO THESE PROBLEMS MATTER? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-044 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by: A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B Identifying and correcting any additional cases affected by the system issues noted in our audit. C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: ? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. ? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: ? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. ? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for chart/table. The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments. WHY DID THESE PROBLEMS OCCUR? Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries. After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute. WHY DO THESE PROBLEMS MATTER? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-044 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by: A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B Identifying and correcting any additional cases affected by the system issues noted in our audit. C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
(A) Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS. (B) Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS.
2020-042
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
(A) The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23.
2020-044
Finding 2021-057 Higher Education Emergency Relief Fund Reporting Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ?Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the System was awarded a total of $254.9 million in HEERF funding. From inception through June 30, 2021, the System spent approximately $34.4 million for the HEERF program Student Aid Portion and $58.3 million for the HEERF program Institutional Portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2022 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2021. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a random sample of 16 of the 143 HEERF reports submitted by the System?s campuses during Fiscal Year 2021 to determine whether the reports were posted on each campus? primary website by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after award, and update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA requires an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problems did the audit work identify? We identified 5 out of 16 reports tested (31.2 percent) that did not meet the HEERF grant report posting requirements; however, no issues were noted on the accuracy of financial information on these reports. We found the following issues related to HEERF report posting specifically: ? Lamar Community College (LCC) did not comply with the record retention requirement requiring all public quarterly reports to remain online for a period of three years after the submission of the last HEERF report. LCC initially posted the Student Aid report for quarter- ended September 30, 2020, on October 23, 2020, which was before the October 30, 2020, due date. However, due to a website crash in November 2020, LCC failed to repost the September 30, 2020, report and this report was not posted to the website as of the year ended June 30, 2021. ? Northeastern Junior College (NJC) did not post an Institutional quarterly report and Otero Junior College (OJC) did not post a Student Aid quarterly report for the period of October 1, 2020, through December 31, 2020, as neither campus spent any funds during this period. However, since the reports are cumulative in nature, although no funds were spent, a report was required to be posted per the HEERF grant requirements. ? Pikes Peak Community College (PPCC) did not comply with the Student Aid reporting requirement to post ?every quarter;? rather, PPCC continued to post the Student Aid report every 45 days, even after the ED revised the reporting requirement on August 31, 2020, to decrease the frequency from every 45 days to every quarter. As such, although PPCC posted a report more frequently than ?every quarter? during the fiscal year, the reports for the quarters ended September 30, 2020, and March 31, 2021, were not completed for the appropriate period as the report dates did not correspond with the calendar quarters. Why did these problems occur? Each of the System?s 13 campuses individually signed a HEERF Certification and Agreement to accept the funding and acknowledge their responsibilities under the grant; therefore, they were individually responsible under the Agreement to ensure that they complied with HEERF reporting and other requirements. ED revised the HEERF reporting requirements three times during the fiscal year. Although CCCS held weekly cross-functional team meetings where various HEERF compliance requirements were addressed with the System?s 13 campuses the LCC, NJC, OJC, and PPCC Campuses did not implement adequate internal controls in place to ensure they complied with the HEERF grant reporting requirements. Specifically, the campuses did not have appropriate policies and procedures in place for identifying and researching changes in federal reporting compliance, ensuring that staff submit the required reports within federally required timeframes, and ensuring that all public quarterly reports remain online for a period of at least three years after the submission of the last quarterly or annual performance report. PPCC believed it was erring on the side of being more conservative with the 45-day reporting period, instead of switching to the quarterly reporting requirements. In addition, LCC did not have an adequate process in place to ensure that all reports were properly re-posted after their website crash. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the LCC, NJC, OJC, and PPCC Campuses failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-057 Lamar Community College, Northeastern Junior College, Otero Junior College, and Pikes Peak Community College campuses should strengthen their internal controls over reporting and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the websites the required reports within federally required timeframes. In addition, Lamar Community College should ensure that all the HEERF reports that are required to be posted are currently on the website. Response Lamar Community College Agree Implementation Date: November 2021 Lamar Community College will implement a procedure moving forward for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date. In the event of another website crash, both the Financial Aid Director and Controller will work together to ensure all reports are loaded back to the website. The October 2020 Student report was loaded to the website in November 2021. Response Northeastern Junior College Agree Implementation Date: November 2021 The Vice President of Administrative Services will ensure that reporting is timely and accurate and retroactively correct deficiencies as guidance changes. Either the September 30, 2020 report should have been marked final or a December 31, 2020 report should have been posted. Due to the issuance of HEERF II and HEERF III, the September 30, 2020 can no longer be considered final, therefore a December 31, 2020 report will be posted in November 2021 after resolution of a technical issue. Response Otero Junior College Agree Implementation Date: August 2021 Otero Junior College has implemented a procedure for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date, copying one another on the requests to update the website so both are aware the posting request was submitted timely. The webmaster then emails a screen print of the posting with the posting date for our records, the controller then verifies the posting is on the website. The missing student report was posted in August 2021. Response Pikes Peak Community College Agree Implementation Date: December 2021 Beginning December 2021, PPCC will comply with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by ensuring that staff post requisite information on the College?s website within federally mandated timeframes. The Director of Budgets is responsible for preparing and posting; Controller and Vice President of Administrative Services will complete a final review.
Show full finding ▾Hide full finding ▴Finding 2021-057 Higher Education Emergency Relief Fund Reporting Compliance The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ?Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the System was awarded a total of $254.9 million in HEERF funding. From inception through June 30, 2021, the System spent approximately $34.4 million for the HEERF program Student Aid Portion and $58.3 million for the HEERF program Institutional Portion. The System reports that it will spend the remaining amount of funding during Fiscal Year 2022 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2021. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a random sample of 16 of the 143 HEERF reports submitted by the System?s campuses during Fiscal Year 2021 to determine whether the reports were posted on each campus? primary website by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after award, and update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA requires an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problems did the audit work identify? We identified 5 out of 16 reports tested (31.2 percent) that did not meet the HEERF grant report posting requirements; however, no issues were noted on the accuracy of financial information on these reports. We found the following issues related to HEERF report posting specifically: ? Lamar Community College (LCC) did not comply with the record retention requirement requiring all public quarterly reports to remain online for a period of three years after the submission of the last HEERF report. LCC initially posted the Student Aid report for quarter- ended September 30, 2020, on October 23, 2020, which was before the October 30, 2020, due date. However, due to a website crash in November 2020, LCC failed to repost the September 30, 2020, report and this report was not posted to the website as of the year ended June 30, 2021. ? Northeastern Junior College (NJC) did not post an Institutional quarterly report and Otero Junior College (OJC) did not post a Student Aid quarterly report for the period of October 1, 2020, through December 31, 2020, as neither campus spent any funds during this period. However, since the reports are cumulative in nature, although no funds were spent, a report was required to be posted per the HEERF grant requirements. ? Pikes Peak Community College (PPCC) did not comply with the Student Aid reporting requirement to post ?every quarter;? rather, PPCC continued to post the Student Aid report every 45 days, even after the ED revised the reporting requirement on August 31, 2020, to decrease the frequency from every 45 days to every quarter. As such, although PPCC posted a report more frequently than ?every quarter? during the fiscal year, the reports for the quarters ended September 30, 2020, and March 31, 2021, were not completed for the appropriate period as the report dates did not correspond with the calendar quarters. Why did these problems occur? Each of the System?s 13 campuses individually signed a HEERF Certification and Agreement to accept the funding and acknowledge their responsibilities under the grant; therefore, they were individually responsible under the Agreement to ensure that they complied with HEERF reporting and other requirements. ED revised the HEERF reporting requirements three times during the fiscal year. Although CCCS held weekly cross-functional team meetings where various HEERF compliance requirements were addressed with the System?s 13 campuses the LCC, NJC, OJC, and PPCC Campuses did not implement adequate internal controls in place to ensure they complied with the HEERF grant reporting requirements. Specifically, the campuses did not have appropriate policies and procedures in place for identifying and researching changes in federal reporting compliance, ensuring that staff submit the required reports within federally required timeframes, and ensuring that all public quarterly reports remain online for a period of at least three years after the submission of the last quarterly or annual performance report. PPCC believed it was erring on the side of being more conservative with the 45-day reporting period, instead of switching to the quarterly reporting requirements. In addition, LCC did not have an adequate process in place to ensure that all reports were properly re-posted after their website crash. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the LCC, NJC, OJC, and PPCC Campuses failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-057 Lamar Community College, Northeastern Junior College, Otero Junior College, and Pikes Peak Community College campuses should strengthen their internal controls over reporting and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the websites the required reports within federally required timeframes. In addition, Lamar Community College should ensure that all the HEERF reports that are required to be posted are currently on the website. Response Lamar Community College Agree Implementation Date: November 2021 Lamar Community College will implement a procedure moving forward for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date. In the event of another website crash, both the Financial Aid Director and Controller will work together to ensure all reports are loaded back to the website. The October 2020 Student report was loaded to the website in November 2021. Response Northeastern Junior College Agree Implementation Date: November 2021 The Vice President of Administrative Services will ensure that reporting is timely and accurate and retroactively correct deficiencies as guidance changes. Either the September 30, 2020 report should have been marked final or a December 31, 2020 report should have been posted. Due to the issuance of HEERF II and HEERF III, the September 30, 2020 can no longer be considered final, therefore a December 31, 2020 report will be posted in November 2021 after resolution of a technical issue. Response Otero Junior College Agree Implementation Date: August 2021 Otero Junior College has implemented a procedure for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date, copying one another on the requests to update the website so both are aware the posting request was submitted timely. The webmaster then emails a screen print of the posting with the posting date for our records, the controller then verifies the posting is on the website. The missing student report was posted in August 2021. Response Pikes Peak Community College Agree Implementation Date: December 2021 Beginning December 2021, PPCC will comply with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by ensuring that staff post requisite information on the College?s website within federally mandated timeframes. The Director of Budgets is responsible for preparing and posting; Controller and Vice President of Administrative Services will complete a final review.
Lamar Community College will implement a procedure moving forward for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date. In the event of another website crash, both the Financial Aid Director and Controller will work together to ensure all reports are loaded back to the website. The October 2020 Student report was loaded to the website in November 2021. The Vice President of Administrative Services will ensure that reporting is timely and accurate and retroactively correct deficiencies as guidance changes. Either the September 30, 2020 report should have been marked final or a December 31, 2020 report should have been posted. Due to the issuance of HEERF II and HEERF III, the September 30, 2020 can no longer be considered final, therefore a December 31, 2020 report will be posted in November 2021 after resolution of a technical issue. Otero Junior College has implemented a procedure for both the Financial Aid Director and Controller to verify that both the Student and Institutional reports are posted by the due date, copying one another on the requests to update the website so both are aware the posting request was submitted timely. The webmaster then emails a screen print of the posting with the posting date for our records, the controller then verifies the posting is on the website. The missing student report was posted in August 2021. Beginning December 2021, PPCC will comply with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by ensuring that staff post requisite information on the College?s website within federally mandated timeframes. The Director of Budgets is responsible for preparing and posting; Controller and Vice President of Administrative Services will complete a final review.
Finding 2021-058 Internal Controls Over Student Financial Aid Cluster Compliance Enrollment Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Student Financial Aid funds to report enrollment information within specified timeframes to the USDE through its central database for student aid, the National Student Loan Data System (NSLDS). Enrollment reporting, including submission of student roster files and enrollment status changes, assists the federal government in management of the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Colorado School of Mines submits student roster files to NSLDS via a third-party servicer, the National Student Clearinghouse (Clearinghouse) or directly to NSLDS. The Colorado School of Mines Registrars? Office compiles the roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Title IV aid at the institution. The Colorado School of Mines performs an initial review of participating students? enrollment information during the census, typically during the second week of the semester, for reporting to NSLDS. After the census date, student roster files of enrollment status are prepared monthly by the Registrar?s Office through a manual comparison of applicable students? enrollment status at the census date to the current enrollment status per the institution?s reporting system. During Fiscal Year 2021, the Colorado School of Mines issued approximately $36.7 million in federal Student Financial Aid during the year, which included approximately $3.4 million and $32.6 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Colorado School of Mines complied with enrollment reporting requirements regarding student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2021. We reviewed a random sample of 40 students whose attendance information was required to be reported to NSLDS during Fiscal Year 2021 per federal reporting requirements. For each student in our sample, we compared information within the Colorado School of Mines Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal from the institution or a change in enrolled credit hours, to determine if the information was reported accurately and within federal timeliness requirements. How were the results of the audit work measured? Under the federal Pell Grant and Direct Loan program requirements [34 CFR 690.83(b)(2) and 685.309], an institution must report any enrollment status changes, including the date of the change per the institution?s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student?s enrollment status to NSLDS when there is a (a) reduction or increase in the student?s attendance levels, (b) graduation, (c) withdrawal, and/or (d) student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against a 60-day timeframe of submitted roster files. What problems did the audit work identify? We found that the Colorado School of Mines did not report the correct date of the enrollment status change for 9 of the 40 (23 percent) students tested. Additionally, the Colorado School of Mines did not report status changes timely to NSLDS for 6 of the 40 (15 percent) students tested, ranging from 2 to 10 days past the 60-day requirement. There was an overlap of the previously mentioned exceptions?3 of the 9 students whose dates were improperly reported were also not reported timely. Why did these problems occur? The Colorado School of Mines did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements. Specifically, we found that the institution does not have a review that ensures the date of the enrollment status change per the institution?s reporting system agrees to the date included in the institution?s student roster file submitted to NSLDS after the census date. Additionally, we found that the Colorado School of Mines changed the frequency of its submission of student roster files to NSLDS after the census date from bi-weekly to monthly, resulting in certain enrollment status changes not being posted to NSLDS within the required timeframe. Why do these problems matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the Colorado School of Mines fails to meet the required reporting timelines or submits inaccurate information to NSLDS, the borrowers? repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-058 The Colorado School of Mines should strengthen its internal controls over reporting Student Financial Aid Pell Grants and Direct Loan Program enrollment to the National Student Loan Data System (NSLDS) by: A. Implementing a review process that ensures the date of the student enrollment change included in NSLDS student roster files agrees to the institution?s records. B. Ensuring that information is uploaded and posted to NSLDS within 60 days of the enrollment status change, as required by federal regulations. Response Colorado School of Mines A. Agree Implementation Date: August 2021 The issue occurred due to staff utilizing the date of the clean up in the space for the effective date, not the status change date. Now we utilize two additional forms in our information system to ensure the correct date is recorded. We also have a report that will be run and reviewed prior to submission to ensure the dates match the status date change. B. Agree Implementation Date: August 2021 We have changed the frequency of reporting from monthly to bi-weekly (every 2 weeks). Increasing the frequency of reporting will help us ensure that we are reporting status changes in a timely manner.
Show full finding ▾Hide full finding ▴Finding 2021-058 Internal Controls Over Student Financial Aid Cluster Compliance Enrollment Reporting The federal Department of Education (USDE) requires institutions of higher education who receive Student Financial Aid funds to report enrollment information within specified timeframes to the USDE through its central database for student aid, the National Student Loan Data System (NSLDS). Enrollment reporting, including submission of student roster files and enrollment status changes, assists the federal government in management of the Pell Grant and Direct Loan programs, which are both parts of Student Financial Aid. In accordance with federal requirements, the Colorado School of Mines submits student roster files to NSLDS via a third-party servicer, the National Student Clearinghouse (Clearinghouse) or directly to NSLDS. The Colorado School of Mines Registrars? Office compiles the roster file to report details about students, such as the campus-level enrollment and program attendance for the students who have received Title IV aid at the institution. The Colorado School of Mines performs an initial review of participating students? enrollment information during the census, typically during the second week of the semester, for reporting to NSLDS. After the census date, student roster files of enrollment status are prepared monthly by the Registrar?s Office through a manual comparison of applicable students? enrollment status at the census date to the current enrollment status per the institution?s reporting system. During Fiscal Year 2021, the Colorado School of Mines issued approximately $36.7 million in federal Student Financial Aid during the year, which included approximately $3.4 million and $32.6 million of Pell Grants and Direct Loan funding, respectively. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Colorado School of Mines complied with enrollment reporting requirements regarding student attendance status changes for Pell Grants and Direct Loan programs during Fiscal Year 2021. We reviewed a random sample of 40 students whose attendance information was required to be reported to NSLDS during Fiscal Year 2021 per federal reporting requirements. For each student in our sample, we compared information within the Colorado School of Mines Financial Aid system to information contained on the NSLDS website for the specific enrollment status change selected, such as a withdrawal from the institution or a change in enrolled credit hours, to determine if the information was reported accurately and within federal timeliness requirements. How were the results of the audit work measured? Under the federal Pell Grant and Direct Loan program requirements [34 CFR 690.83(b)(2) and 685.309], an institution must report any enrollment status changes, including the date of the change per the institution?s reporting system, to NSLDS for participating students within 60 days of the change. An institution must report a change in a student?s enrollment status to NSLDS when there is a (a) reduction or increase in the student?s attendance levels, (b) graduation, (c) withdrawal, and/or (d) student who has been accepted for enrollment but never attended. Institutions are responsible for timely reporting whether they report directly or via a third-party servicer. We measured the results of our testing against a 60-day timeframe of submitted roster files. What problems did the audit work identify? We found that the Colorado School of Mines did not report the correct date of the enrollment status change for 9 of the 40 (23 percent) students tested. Additionally, the Colorado School of Mines did not report status changes timely to NSLDS for 6 of the 40 (15 percent) students tested, ranging from 2 to 10 days past the 60-day requirement. There was an overlap of the previously mentioned exceptions?3 of the 9 students whose dates were improperly reported were also not reported timely. Why did these problems occur? The Colorado School of Mines did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements. Specifically, we found that the institution does not have a review that ensures the date of the enrollment status change per the institution?s reporting system agrees to the date included in the institution?s student roster file submitted to NSLDS after the census date. Additionally, we found that the Colorado School of Mines changed the frequency of its submission of student roster files to NSLDS after the census date from bi-weekly to monthly, resulting in certain enrollment status changes not being posted to NSLDS within the required timeframe. Why do these problems matter? Enrollment reporting assists lenders in the determination of whether a borrower should be moved into loan repayment status or if they are eligible for an in-school deferment. Thus, if the Colorado School of Mines fails to meet the required reporting timelines or submits inaccurate information to NSLDS, the borrowers? repayment responsibilities may be reported incorrectly and result in either a lack of timely repayments by the borrower or the student being inappropriately moved into loan repayment status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-058 The Colorado School of Mines should strengthen its internal controls over reporting Student Financial Aid Pell Grants and Direct Loan Program enrollment to the National Student Loan Data System (NSLDS) by: A. Implementing a review process that ensures the date of the student enrollment change included in NSLDS student roster files agrees to the institution?s records. B. Ensuring that information is uploaded and posted to NSLDS within 60 days of the enrollment status change, as required by federal regulations. Response Colorado School of Mines A. Agree Implementation Date: August 2021 The issue occurred due to staff utilizing the date of the clean up in the space for the effective date, not the status change date. Now we utilize two additional forms in our information system to ensure the correct date is recorded. We also have a report that will be run and reviewed prior to submission to ensure the dates match the status date change. B. Agree Implementation Date: August 2021 We have changed the frequency of reporting from monthly to bi-weekly (every 2 weeks). Increasing the frequency of reporting will help us ensure that we are reporting status changes in a timely manner.
(A) The issue occurred due to staff utilizing the date of the clean up in the space for the effective date, not the status change date. Now we utilize two additional forms in our information system to ensure the correct date is recorded. We also have a report that will be run and reviewed prior to submission to ensure the dates match the status date change. (B) We have changed the frequency of reporting from monthly to bi-weekly (every 2 weeks). Increasing the frequency of reporting will help us ensure that we are reporting status changes in a timely manner.
Finding 2021-059 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s required FFATA reports for Fiscal Year 2021 included information on the Low-Income Home Energy Assistance (LIHEAP), COVID-19 ? Low-Income Home Energy Assistance [ALN 93.568]; the Child Care and Development Fund (CCDF) Cluster, consisting of the Child Care and Development Block Grant [ALN 93.575], and Child Care Mandatory and Matching Funds of the Child Care and Development Fund [ALN 93.596]; and the Block Grant for Prevention and Treatment of Substance Abuse (Substance Abuse), COVID-19 ? Block Grant for Prevention and Treatment of Substance Abuse [ALN 93.959]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: LIHEAP funds to one subrecipient, CCDF funds to nine subrecipients, and Substance Abuse funds to seven subrecipients for Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the FFATA reporting and to determine whether the Department correctly reported its subawards to the FSRS during Fiscal Year 2021. Based on our audit testwork, we reviewed the Department?s subawards and related federal expenditures in Fiscal Year 2021 to determine if there was FFATA reporting that was completed within the month following the month the subaward was made, as required. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the state?s accounting system, for the LIHEAP, CCDF, and Substance Abuse programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: LIHEAP had one sample, CCDF had five samples, and Substance Abuse had five samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department?s program staff are responsible for understanding FFATA reporting requirements related to their programs, and providing key data elements for subrecipients at the point that funds are obligated. When program staff determine that the Department is making a subaward that requires FFATA reporting, program staff are required to report these key data elements in eClearance, an approval workflow and document depository system utilized by the Department in their purchasing process. Guidance for the FFATA reporting is included within the Department?s FFATA Quick Reference Guide that is made available to the program staff. Program staff enter the subaward information into eClearance via an online form called a Requisition eForm (eForm), which goes through an approval process and is then routed to the Department?s Purchasing and Contracts unit to process the purchase request that translates into an obligation of an award for subrecipients. Once the eForm is completed processing in eClearance, it is archived in the system and an automated query is run by the Department?s Business Technology Unit to export this data and it is automatically emailed to the Compliance Accounting team on a daily basis. Each day, the Department?s compliance accountant compiles the subaward data emailed to them that originated from eClearance into a daily report. At the end of the month, the compliance accountant combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report?s accuracy. The compliance accountant uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did not report its subawards in FSRS for any of the three federal grant programs we tested for Fiscal Year 2021: the LIHEAP, CCDF, and Substance Abuse programs. In total, for the three programs, the Department failed to report subawards totaling $5.77 million (approximately $3.04 million for LIHEAP, approximately $861 thousand for CCDF, and approximately $1.87 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table. Why did these problems occur? The Department does not have adequate internal controls over the FFATA reporting. Specifically, the Department has not validated the automated process to compile the data needed for the FFATA reports. In addition, the Department has not implemented a supervisory review process of the final FFATA report data that is used to submit the FFATA report via FSRS. We determined that automated reports generated did not include the full population of data needed to compile the FFATA reports. Based on test work, we found that program staff entered key data elements needed for FFATA reporting correctly into the eForm during the purchasing process, and that accounting staff used the data provided in the reports received to complete the FFATA reporting in FSRS. However, the data exported from eClearance and sent to accounting to compile the FFATA reports did not contain all of the population needed for reporting. Thus, accounting was using data that was not complete in the FFATA reporting to FSRS, but was unaware that the data was not complete. Further, when there was incomplete information in the data received, the compliance accountant failed to follow up with the various program staff to obtain the necessary information and input it into and submit it through FSRS. Why do these problems matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search; excluding the information could be misleading to the public and fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-059 The Department of Human Service (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Correcting the automated reporting process from eClearance to ensure that data compiled for Transparency Act reporting contains all relevant data. B. Developing and implementing procedures to validate that data derived from eClearance reports and ultimately used to compile Transparency Act reporting is complete and accurate by reviewing the population from an alternate source, such as the Colorado Operations Resource Engine. C. Improving the Department?s supervisory review process to provide for a complete and thorough review of the final FFATA report data that the Department will report within the Federal Funding Accountability and Transparency Act Subaward Reporting System. This process should include taking steps to ensure the compliance accountant follows up with the program staff if the necessary information is not input into eClearance, so that it can be obtained and reported accurately and timely. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unkown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. B. Agree Implementation Date: July 2022 The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. C. Agree Implementation Date: July 2022 CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
Show full finding ▾Hide full finding ▴Finding 2021-059 Federal Funding Accountability and Transparency Act The Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations, also referred to as subrecipients. Federal regulations [2 CFR 200.1] define a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a Federal grant award received by the pass-through entity. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? The Department is required to file FFATA reports through the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Once the Department submits a report to FSRS, the public can view certain information from the report, including the subrecipient?s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department?s name, and the Department?s grant award identification number. The Department?s required FFATA reports for Fiscal Year 2021 included information on the Low-Income Home Energy Assistance (LIHEAP), COVID-19 ? Low-Income Home Energy Assistance [ALN 93.568]; the Child Care and Development Fund (CCDF) Cluster, consisting of the Child Care and Development Block Grant [ALN 93.575], and Child Care Mandatory and Matching Funds of the Child Care and Development Fund [ALN 93.596]; and the Block Grant for Prevention and Treatment of Substance Abuse (Substance Abuse), COVID-19 ? Block Grant for Prevention and Treatment of Substance Abuse [ALN 93.959]. FFATA reporting was required for the Department because the Department passed through funds to one or more subrecipients for each of the three programs in excess of $30,000, as follows: LIHEAP funds to one subrecipient, CCDF funds to nine subrecipients, and Substance Abuse funds to seven subrecipients for Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the FFATA reporting and to determine whether the Department correctly reported its subawards to the FSRS during Fiscal Year 2021. Based on our audit testwork, we reviewed the Department?s subawards and related federal expenditures in Fiscal Year 2021 to determine if there was FFATA reporting that was completed within the month following the month the subaward was made, as required. We compared amounts reported by the Department for subawards in FSRS to the underlying financial records reported in the Colorado Operations Resource Engine (CORE), the state?s accounting system, for the LIHEAP, CCDF, and Substance Abuse programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the FFATA reporting, including supervisory reviews. We reviewed the following number of subrecipient samples within each program for their internal control over compliance and compliance with FFATA reporting standards: LIHEAP had one sample, CCDF had five samples, and Substance Abuse had five samples. We reviewed the FFATA reports within FSRS for each subrecipient selected for testing to determine if the FFATA report was made in a timely manner in accordance with federal regulations and contained all of the required key data elements. How were the results of the audit work measured? In accordance with federal regulations [2 CFR 170], direct recipients of grants are required to report subawards of $30,000 or more to FSRS by the end of the month following the month in which the award was made. If the Department makes additional subawards greater than or equal to $30,000 under that same subaward at a later date or makes a supplemental award that increases an existing award to greater than or equal to $30,000, it must file additional FFATA reports to reflect the new or amended subaward. If the subaward does not change, no additional reporting is required. The FFATA reports are required to include the following key data elements: subrecipient name, subrecipient DUNS number, amount of subaward, subaward obligation/action date, date of report submission, subaward number, subaward project description, and subrecipient names and compensation of highly compensated officers. The Department?s program staff are responsible for understanding FFATA reporting requirements related to their programs, and providing key data elements for subrecipients at the point that funds are obligated. When program staff determine that the Department is making a subaward that requires FFATA reporting, program staff are required to report these key data elements in eClearance, an approval workflow and document depository system utilized by the Department in their purchasing process. Guidance for the FFATA reporting is included within the Department?s FFATA Quick Reference Guide that is made available to the program staff. Program staff enter the subaward information into eClearance via an online form called a Requisition eForm (eForm), which goes through an approval process and is then routed to the Department?s Purchasing and Contracts unit to process the purchase request that translates into an obligation of an award for subrecipients. Once the eForm is completed processing in eClearance, it is archived in the system and an automated query is run by the Department?s Business Technology Unit to export this data and it is automatically emailed to the Compliance Accounting team on a daily basis. Each day, the Department?s compliance accountant compiles the subaward data emailed to them that originated from eClearance into a daily report. At the end of the month, the compliance accountant combines the daily reports into a monthly summary and compares the monthly summary report to the daily reports to verify the summary report?s accuracy. The compliance accountant uses the information summarized within the monthly report to input the required FFATA information into FSRS, which ultimately is submitted as the required monthly FFATA report. What problems did the audit work identify? Based on our audit testwork, we determined that the Department did not report its subawards in FSRS for any of the three federal grant programs we tested for Fiscal Year 2021: the LIHEAP, CCDF, and Substance Abuse programs. In total, for the three programs, the Department failed to report subawards totaling $5.77 million (approximately $3.04 million for LIHEAP, approximately $861 thousand for CCDF, and approximately $1.87 million for Substance Abuse). The following tables summarize the results of our testing and groups each exception within the following categories: subaward not reported, report not timely, subaward amount incorrect, and subaward missing key elements. See Schedule of Findings and Questioned Costs for chart/table. Why did these problems occur? The Department does not have adequate internal controls over the FFATA reporting. Specifically, the Department has not validated the automated process to compile the data needed for the FFATA reports. In addition, the Department has not implemented a supervisory review process of the final FFATA report data that is used to submit the FFATA report via FSRS. We determined that automated reports generated did not include the full population of data needed to compile the FFATA reports. Based on test work, we found that program staff entered key data elements needed for FFATA reporting correctly into the eForm during the purchasing process, and that accounting staff used the data provided in the reports received to complete the FFATA reporting in FSRS. However, the data exported from eClearance and sent to accounting to compile the FFATA reports did not contain all of the population needed for reporting. Thus, accounting was using data that was not complete in the FFATA reporting to FSRS, but was unaware that the data was not complete. Further, when there was incomplete information in the data received, the compliance accountant failed to follow up with the various program staff to obtain the necessary information and input it into and submit it through FSRS. Why do these problems matter? By failing to properly report subawards to FSRS, the Department is out of compliance with federal reporting requirements and risks federal sanctions. In addition, information submitted via the FSRS is made publicly available at https://www.usaspending.gov/search; excluding the information could be misleading to the public and fails to meet the federal intent of transparency for federal program spending. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-059 The Department of Human Service (Department) should strengthen its internal controls over the Federal Funding Accountability and Transparency Act (Transparency Act or FFATA) reporting by: A. Correcting the automated reporting process from eClearance to ensure that data compiled for Transparency Act reporting contains all relevant data. B. Developing and implementing procedures to validate that data derived from eClearance reports and ultimately used to compile Transparency Act reporting is complete and accurate by reviewing the population from an alternate source, such as the Colorado Operations Resource Engine. C. Improving the Department?s supervisory review process to provide for a complete and thorough review of the final FFATA report data that the Department will report within the Federal Funding Accountability and Transparency Act Subaward Reporting System. This process should include taking steps to ensure the compliance accountant follows up with the program staff if the necessary information is not input into eClearance, so that it can be obtained and reported accurately and timely. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unkown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. B. Agree Implementation Date: July 2022 The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. C. Agree Implementation Date: July 2022 CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
(A) CDHS agrees that it needs to it needs to correct the automated reporting process from the eClearance system used to gather data needed for our FFATA reporting. The department thought that the reports obtained from eClearance were complete and relied on them as the basis of our reporting. Upon investigation we found that an internal process change enacted during the implementation of another system at the start of the pandemic was the cause of the data discrepancy. This occurred because the new system made the routing in eClearance after a certain point unnecessary for internal processing so this stopped. It was unknown that this further routing to archive files in eClearance was the trigger for eClearance to push out FFATA report data. Since the department has been able to identify the cause we are able to immediately remedy the problem and ensure that all processes are in sync to ensure accurate and complete FFATA data is contained in automated reporting processes. The department will catch up on FFATA reporting that was missed during this time frame. (B) The department agrees that it needs to implement procedures to validate that data derived from automated processes used as a basis for FFATA reporting should be periodically validated against another data source. To do this the department will create and implement procedures to use CORE reports of encumbrance data referencing subrecipient object codes and tie this to information received from the automated eClearance report. Doing this will validate that the data provided from eClearance is a complete listing of all FFATA reportable subrecipient awards, and thus is a valid source to base FFATA reporting on. This will also help us monitor the process in case any future inadvertent changes are made to processes that could cause data validity issues. (C) CDHS agrees that a supervisory review is needed over the FFATA reporting process in order to ensure more consistency, accuracy and timeliness in reporting processes and standards. The department is currently developing procedures that will allow for more oversight of the FFATA reporting through supervisory reviews and cross training staff on FFATA reporting duties. Supervisory reviews will help ensure that reporting is completed in line with reporting procedures and timeframes and can be a second set of eyes to ensure that information appears accurate and adds analytical judgement value (example - a supervisor might see that July typically has high volume, but this July volume is low, why). In addition, the department is taking this opportunity to cross train other staff on the process so that more individuals can be involved which leads to more transparency over processes allowing various individuals to notice if something isn't working as designed. These new procedures are being developed and implemented as the department catches up on reporting subrecipient awards that were missed since the automated process stopped working.
Finding 2021-060 Misreporting of Federal Expenditures for the COVID-19 ?Pandemic EBT Food Benefits and Child Care and Development Block Grant on the Exhibit K1 Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State?s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Number (ALN)?s related to the programs they support. The program accountants complete this review using a CORE report that the Department created, pulling transaction detail level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department?s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department?s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. The Department is also separately required within its approved State Plan for the COVID-19 ? Pandemic EBT Food Benefits program [ALN 10.542] (P-EBT) to report its P-EBT federal expenditures to the U.S. Department of Agriculture (USDA) via the Report of Disaster Food Stamp Benefit Issuance (FNS-292-B). The Department is also required to support the financial expenditures reported on the FNS-292-B report with source data and files, which includes a P-EBT Summary report that is exported from the Colorado Benefits Management System (CBMS) and includes the number of eligible children, number of eligible households, and total amount paid in P-EBT benefits. The P-EBT summary report is then reconciled by the Department to the County Financial Management System (CFMS), where the counties? issuance of P-EBT program benefits is accumulated and reported. For Fiscal Year 2021, the Department administered more than 70 federal programs and expended approximately $2.4 billion in federal funds. The P-EBT program and Child Care and Development Block Grant (Grant) [ALN 93.575] were two of these federal programs administered by the Department during Fiscal Year 2021. The Department reported more than $292 million in federal expenditures for the P-EBT program and approximately $74 million in federal expenditures for the Grant in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2021 and to determine whether the Department correctly reported its Fiscal Year 2021 federal grant expenditures to the OSC on its Exhibit K1. The purpose of our audit work was also to evaluate the Department?s internal controls over the financial reporting to the USDA regarding the P-EBT program. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2021 Exhibit K1 to the underlying financial records in CORE for the Grant and P-EBT federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. We also reviewed 4 out of 12 Fiscal Year 2021 monthly submissions to the USDA for the FNS-292-B reports and compared federal expenditure amounts reported by the Department to the underlying financial records in CORE. How were the results of the audit work measured? The OSC is required to present the State?s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State?s expenditures of federal awards during the fiscal year. Federal regulations [2 CFR 200.38(b)] define a federal award as, ?The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance?? Federal regulations [2 CFR 200.510(b)(3) and (4)] require that the SEFA must show both total federal awards expended for each individual federal program, the Assistance Listing Number, and the total amount passed through to subrecipients for each federal program. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC?s exhibit instructions include guidelines for completing the Exhibit K1, including defining ?direct and indirect expenditures? as ?all monetary and non-monetary direct and indirect Federal award expenditures,? and ?pass-through expenditures? as ?the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.? For the Department?s Grant federal program, subrecipients consist of counties, school districts, and health centers. State Fiscal Rule 1-2, Internal Controls, requires that state departments ?implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).? Federal regulations [7 CFR 274.4] require the Department to submit an FNS-292-B report in the format prescribed by the USDA with information detailing the P-EBT federal benefit payments. The Department is required to support the information in the report with its underlying records. The FNS-292-B report is identified as a required report within the Department?s State Plan that is approved by the USDA. What problems did the audit work identify? The Department overstated $63.5 million in P-EBT expenditures on its June 2021 FNS-292-B report to USDA that was submitted on August 30, 2021, as well as on the Department?s Exhibit K1 for Fiscal Year 2021. The Department subsequently identified that the FNS-292-B report was misstated and updated and resubmitted the report on September 28, 2021, approximately one month later. The Department, however, did not update its Exhibit K1 for Fiscal Year 2021 to correct the error, because the program staff did not notify the accounting team of the misstatement and need for Exhibit K1 correction. Based on our audit testwork, we also determined that the Department misreported $8.7 million in the Grant?s expenditures as subrecipient, rather than direct, expenditures on its Exhibit K1. Why did these problems occur? The P-EBT program staff did not notify the Department?s accounting team, who prepares the Exhibit K1, of a revision to the FNS-292-B report. The P-EBT program staff prepared the reconciliation of the CBMS summary report to the CFMS P-EBT benefits issued report and identified a variance. The variance was eventually resolved and the P-EBT program staff resubmitted the FNS-292-B report to the USDA; however P-EBT program staff did not communicate this error to the Department?s accounting team. As a result, the accounting team was unaware of the revision and, therefore, did not update the Exhibit K1 to reflect the reduction in federal expenditures. Overall, the Department did not have adequate internal controls, such as an appropriate supervisory review process or adequate communication plan, in place for Fiscal Year 2021 to ensure that the FNS-292-B report was prepared accurately, that the Exhibit K1 was completed in accordance with the instructions provided by the OSC, and that the FNS-292-B and Exhibit K1 were reviewed for accuracy and compared to the underlying data. For the Grant program error, Department staff indicated that these funds were incorrectly identified and coded as subrecipient expenditures in CORE, which caused them to be incorrectly reported as such on the Exhibit K1. When the expenditures were initially posted in CORE, they were not adequately reviewed to determine if they were subrecipient or direct expenditures. Why do these problems matter? By failing to properly report grant expenditures to the federal government and the OSC, who ultimately then fails to properly report expenditures to the federal government on the State?s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, because the error resulted in the Department misstating its federal expenditure results for the fiscal year, federal staff and taxpayers have an incorrect or unreliable picture of the P-EBT grant?s overall status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-060 The Department of Human Services (Department) should strengthen its internal controls over the preparation of federal reports and the Exhibit K1, Schedule of Federal Assistance, by: A. Strengthening its internal controls over its monthly Pandemic Electronic Benefit Transfer Food Benefits (P-EBT) reporting to ensure its reporting is accurate and goes through supervisory review. B. Improving communication between program and accounting staff to ensure the Exhibit K1 is accurately updated when errors in federal reporting are identified and resolved. C. Improving the supervisory review process over the Exhibit K1 and the federal expenditures entered in the Colorado Operations Resource Engine (CORE), the state?s accounting system, to ensure expenditures are coded correctly as direct or subrecipient expenditures and that, ultimately, the Exhibit K1 is accurate and complete. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. B. Agree Implementation Date: July 2022 CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. C. Agree Implementation Date: July 2022 CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
Show full finding ▾Hide full finding ▴Finding 2021-060 Misreporting of Federal Expenditures for the COVID-19 ?Pandemic EBT Food Benefits and Child Care and Development Block Grant on the Exhibit K1 Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA); this exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants passed through by the Department to other State and/or non-State agencies (subrecipient expenditures). The SEFA is to be presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) to show the State?s expenditures of federal awards during the fiscal year. A subrecipient is defined in federal regulations [2 CFR 200.1] as ?an entity, usually but not limited to non-Federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other Federal awards directly from a federal awarding agency.? Annually, the Department prepares its Exhibit K1 by following a process documented in its program accounting manual. First, program accountants review and analyze information from CORE for the federal Assistance Listing Number (ALN)?s related to the programs they support. The program accountants complete this review using a CORE report that the Department created, pulling transaction detail level data by ALN. Once the reviews and analysis are complete, the program accountants enter the information on the Department?s Exhibit K1 template for the correlating ALN. After the exhibit is prepared, the Department?s program accounting manual requires that it goes through two levels of review for accuracy. Once these reviews are completed, the Department submits the final Exhibit K1 to the OSC. The Department is also separately required within its approved State Plan for the COVID-19 ? Pandemic EBT Food Benefits program [ALN 10.542] (P-EBT) to report its P-EBT federal expenditures to the U.S. Department of Agriculture (USDA) via the Report of Disaster Food Stamp Benefit Issuance (FNS-292-B). The Department is also required to support the financial expenditures reported on the FNS-292-B report with source data and files, which includes a P-EBT Summary report that is exported from the Colorado Benefits Management System (CBMS) and includes the number of eligible children, number of eligible households, and total amount paid in P-EBT benefits. The P-EBT summary report is then reconciled by the Department to the County Financial Management System (CFMS), where the counties? issuance of P-EBT program benefits is accumulated and reported. For Fiscal Year 2021, the Department administered more than 70 federal programs and expended approximately $2.4 billion in federal funds. The P-EBT program and Child Care and Development Block Grant (Grant) [ALN 93.575] were two of these federal programs administered by the Department during Fiscal Year 2021. The Department reported more than $292 million in federal expenditures for the P-EBT program and approximately $74 million in federal expenditures for the Grant in Fiscal Year 2021. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to evaluate the Department?s internal controls over the preparation of its Exhibit K1 during Fiscal Year 2021 and to determine whether the Department correctly reported its Fiscal Year 2021 federal grant expenditures to the OSC on its Exhibit K1. The purpose of our audit work was also to evaluate the Department?s internal controls over the financial reporting to the USDA regarding the P-EBT program. As part of our audit testwork, we compared amounts reported by the Department for direct and subrecipient federal expenditures on its Fiscal Year 2021 Exhibit K1 to the underlying financial records in CORE for the Grant and P-EBT federal programs and inquired about any differences. In addition, we made inquiries of Department staff regarding its internal control processes over the Exhibit K1 preparation, including supervisory reviews. We also reviewed 4 out of 12 Fiscal Year 2021 monthly submissions to the USDA for the FNS-292-B reports and compared federal expenditure amounts reported by the Department to the underlying financial records in CORE. How were the results of the audit work measured? The OSC is required to present the State?s SEFA in accordance with the federal requirements of the Uniform Guidance to show the State?s expenditures of federal awards during the fiscal year. Federal regulations [2 CFR 200.38(b)] define a federal award as, ?The instrument setting forth the terms and conditions. The instrument is the grant agreement, cooperative agreement, other agreement for assistance?? Federal regulations [2 CFR 200.510(b)(3) and (4)] require that the SEFA must show both total federal awards expended for each individual federal program, the Assistance Listing Number, and the total amount passed through to subrecipients for each federal program. In order to prepare the SEFA, the OSC requires state departments to submit an Exhibit K1 to report expenditures, receipts, and receivables for each federal grant program administered by the Department during the fiscal year. The OSC?s exhibit instructions include guidelines for completing the Exhibit K1, including defining ?direct and indirect expenditures? as ?all monetary and non-monetary direct and indirect Federal award expenditures,? and ?pass-through expenditures? as ?the amount of all monetary and non-monetary Federal award amounts passed through to a subrecipient.? For the Department?s Grant federal program, subrecipients consist of counties, school districts, and health centers. State Fiscal Rule 1-2, Internal Controls, requires that state departments ?implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, conform to state fiscal rules, and reflect the underlying realities of the accounting transaction (substance rather than form).? Federal regulations [7 CFR 274.4] require the Department to submit an FNS-292-B report in the format prescribed by the USDA with information detailing the P-EBT federal benefit payments. The Department is required to support the information in the report with its underlying records. The FNS-292-B report is identified as a required report within the Department?s State Plan that is approved by the USDA. What problems did the audit work identify? The Department overstated $63.5 million in P-EBT expenditures on its June 2021 FNS-292-B report to USDA that was submitted on August 30, 2021, as well as on the Department?s Exhibit K1 for Fiscal Year 2021. The Department subsequently identified that the FNS-292-B report was misstated and updated and resubmitted the report on September 28, 2021, approximately one month later. The Department, however, did not update its Exhibit K1 for Fiscal Year 2021 to correct the error, because the program staff did not notify the accounting team of the misstatement and need for Exhibit K1 correction. Based on our audit testwork, we also determined that the Department misreported $8.7 million in the Grant?s expenditures as subrecipient, rather than direct, expenditures on its Exhibit K1. Why did these problems occur? The P-EBT program staff did not notify the Department?s accounting team, who prepares the Exhibit K1, of a revision to the FNS-292-B report. The P-EBT program staff prepared the reconciliation of the CBMS summary report to the CFMS P-EBT benefits issued report and identified a variance. The variance was eventually resolved and the P-EBT program staff resubmitted the FNS-292-B report to the USDA; however P-EBT program staff did not communicate this error to the Department?s accounting team. As a result, the accounting team was unaware of the revision and, therefore, did not update the Exhibit K1 to reflect the reduction in federal expenditures. Overall, the Department did not have adequate internal controls, such as an appropriate supervisory review process or adequate communication plan, in place for Fiscal Year 2021 to ensure that the FNS-292-B report was prepared accurately, that the Exhibit K1 was completed in accordance with the instructions provided by the OSC, and that the FNS-292-B and Exhibit K1 were reviewed for accuracy and compared to the underlying data. For the Grant program error, Department staff indicated that these funds were incorrectly identified and coded as subrecipient expenditures in CORE, which caused them to be incorrectly reported as such on the Exhibit K1. When the expenditures were initially posted in CORE, they were not adequately reviewed to determine if they were subrecipient or direct expenditures. Why do these problems matter? By failing to properly report grant expenditures to the federal government and the OSC, who ultimately then fails to properly report expenditures to the federal government on the State?s SEFA, the Department is out of compliance with federal and state reporting requirements and risks federal sanctions. In addition, because the error resulted in the Department misstating its federal expenditure results for the fiscal year, federal staff and taxpayers have an incorrect or unreliable picture of the P-EBT grant?s overall status. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-060 The Department of Human Services (Department) should strengthen its internal controls over the preparation of federal reports and the Exhibit K1, Schedule of Federal Assistance, by: A. Strengthening its internal controls over its monthly Pandemic Electronic Benefit Transfer Food Benefits (P-EBT) reporting to ensure its reporting is accurate and goes through supervisory review. B. Improving communication between program and accounting staff to ensure the Exhibit K1 is accurately updated when errors in federal reporting are identified and resolved. C. Improving the supervisory review process over the Exhibit K1 and the federal expenditures entered in the Colorado Operations Resource Engine (CORE), the state?s accounting system, to ensure expenditures are coded correctly as direct or subrecipient expenditures and that, ultimately, the Exhibit K1 is accurate and complete. Response Department of Human Services A. Agree Implementation Date: July 2022 CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. B. Agree Implementation Date: July 2022 CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. C. Agree Implementation Date: July 2022 CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
(A) CDHS agrees to enhance internal controls over monthly P-EBT reporting to better ensure accuracy. P-EBT is a new program derived from pandemic funding. Being a new program with a lack of federal guidance at implementation, and urgency to get the funds disbursed program staff had to learn about the nuances of the program and the reporting requirements as it was being implemented. During implementation we recognized that there are some inherent differences with P-EBT from other benefit programs which caused processes to have to be adjusted slightly. Additionally, timing of federal report filing for the P-EBT program is not in synch with our other processes and associated federal reporting requirements and deadlines. This makes it impossible to ensure reconciliation procedures are performed before filing occurs, which is one of our typical internal controls. As a compensating internal control CDHS will ensure that supervisory review processes are performed over P-EBT reporting, and that P-EBT reporting is reconciled to other sources (CBMS and CFMS) as soon as possible after reporting is available. If changes are discovered CDHS will make adjustments to filed P-EBT reports as needed based on reconciliation findings, and communicate changes to necessary parties. (B) CDHS will work to ensure better coordination between program activities and the accounting section relating to federal reporting changes. Accounting will iterate the importance of timely informing the accounting staff when changes are made to program filed federal reports. This message will be delivered in periodic fiscal meetings and identified on the closing calendar. The P-EBT program will ensure that corrections are communicated to accounting on any updates completed on the FNS-292-B report upon discovery, and no later than 30 days after the reporting period. (C) CDHS will ensure that review and approval processes are occurring as designed at various points in the process leading up to entry into CORE. As part of the Requisition (RQS) approval process program and accounting staff independently approve that the correct direct or subrecipient object code is used. These approved RQS transactions are then transitioned into encumbrance documents that drive which object code future expenditures will be booked to. For CCDF transactions related to this finding, both the OEC and Accounting teams inadvertently approved an incorrect object code in 4 RQS's. Staffing shortages coupled with a large increase in workload related to pandemic funding contributed to this oversight. To correct OEC and Accounting will train new staff, periodically familiarize themselves with the appropriate object codes, and perform quality assurance review over object codes before applying approval in CORE. The K1 is compiled from balances derived from expenditure data recorded in CORE. The compilation of the K1 relies on the fact that expenditure balances are accurate, and that prior reviews and approvals of individual transactions have occurred as designed. The K1 currently goes through various levels of review focusing on balance level validation coupled with analytical procedures. To enhance the review process, CDHS will ensure analytical procedures include line level expenditure comparison at the direct and subrecipient levels.
The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORY The Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food). Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens. The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods. Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs. During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program: ? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report. ? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)]. The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions. The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed. Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically: EMERGENCY FOOD PROGRAM ? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory. ? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered. ? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million. ? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report. SUPPLEMENTAL FOOD PROGRAM ? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000. WHY DID THESE PROBLEMS OCCUR? The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation. WHY DO THESE PROBLEMS MATTER? Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-054 The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by: A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate. B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate. C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories. B AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. C AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORY The Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food). Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens. The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods. Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs. During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program: ? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report. ? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)]. The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions. The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed. Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically: EMERGENCY FOOD PROGRAM ? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory. ? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered. ? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million. ? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report. SUPPLEMENTAL FOOD PROGRAM ? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000. WHY DID THESE PROBLEMS OCCUR? The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation. WHY DO THESE PROBLEMS MATTER? Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-054 The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by: A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate. B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate. C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories. B AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. C AGREE. IMPLEMENTATION DATE: DECEMBER 2022. The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
(A) The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories. (B) The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate. Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022. (C) The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents. The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management. Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
2020-054
The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. NATIONAL SCHOOL LUNCH PROGRAM FOOD INVENTORY RECONCILIATION The Department is in-charge of managing the procurement, storage, and distribution of donated agricultural commodities provided through and administered by the USDA?s National School Lunch Program (Lunch Program) [CFDA No. 10.555]. This program is part of the USDA?s Child Nutrition Cluster programs. The federal Child Nutrition Cluster programs are intended to (1) assist states in administering food services that provide healthy, nutritious meals to eligible children in public and nonprofit private schools, residential child care institutions, and summer recreation programs; and (2) encourage the domestic consumption of nutritious agricultural commodities. USDA enters into agreements with states for the distribution of USDA- donated foods. The states, in turn, enter into agreements with local Lunch Program operators, which are defined collectively as recipient agencies. The Department?s responsibility under the Lunch Program includes hiring a food logistics vendor to purchase food products and deliver them to schools and child care centers (recipient agencies) throughout Colorado; and tracking, maintaining, and reconciling inventory records for the food products. The Department contracts with a warehouse in Colorado Springs to store its food inventory. Once a donated food shipment arrives at the Department-contracted warehouse, the warehouse staff count the food to compare it to the provided Bill of Lading (BOL), review it for good condition, and check the temperature of all cases. The food logistics vendor then picks up the donated food from the warehouse and delivers it to the schools. The schools are responsible for inspecting the load, counting the items received, and signing off on the BOL to certify that it is accurate. The food logistics vendor keeps a copy of the BOL. The Colorado Department of Education (CDE) is responsible for all non-inventory related federal requirements for the Lunch Program. For example, CDE is responsible for collecting and tracking total school lunches served, which dictates the volume of donated foods the State receives. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had adequate internal controls over and complied with inventory-related requirements for the Lunch Program during Fiscal Year 2020, which included determining whether the Department maintained accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods through the Lunch Program and performed inventory reconciliations throughout the fiscal year. We obtained the Department?s procedures for preparing its fiscal year-end and monthly reconciliations of its Lunch Program inventory and documentation related to the receipt and shipment of the Lunch Program?s donated foods. We also requested that the Department provide its fiscal year-end inventory reconciliation. We obtained and tested two monthly inventory reconciliations prepared by the Department for Fiscal Year 2020. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against these requirements: Federal regulations [7 CFR 250.12(b)] for the Lunch Program require that the Department take a physical inventory of its Lunch Program donated foods at its warehouse and reconcile the results of the physical inventory annually with the warehouse?s inventory records. The Department must maintain the results of the inventory and the reconciliation itself or ensure the warehouse maintains the documentation. The regulations also require that the Department, as the distributing agency, report any donated food losses, and ensure that restitution is made for such losses. Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16 (a)]. Records relating to requirements for donated foods must be retained for a period of three years from the close of the fiscal or school year to which they pertain [7 CFR 250.19(b)]. The Department?s Inventory Tracking and Reconciliation policy for the Lunch Program requires the Department to perform a reconciliation between incoming inventory from the USDA and shipping reports provided by the food logistics vendor. The procedure states that ?any variances between the Reconciliation Spreadsheet and Physical Inventory are given to the food logistics vendor to check and agree on. If there is a significant variance the program completes a food loss investigation which may result in financial reimbursement.? WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully reconcile its Lunch Program donated food inventory at fiscal year end to the underlying records. Specifically, the Department conducted a fiscal year end physical inventory at the warehouse and compared the physical inventory counts to the inventory provided by the USDA throughout the fiscal year and what was delivered to schools and child care centers by the food logistics vendor, but did not follow-up and resolve variances noted through the comparison. Specifically, we noted that 25 of the 30 (83 percent) food items the Department compared between the USDA-provided and food logistics vendor-provided documentation contained differences. The overall gross value of the variances totaled $4,507, with a net variance of $259. We also noted that the Department did not obtain from the warehouse or retain records of the receipt and distribution of the Lunch Program?s donated inventory during the fiscal year. Rather, at fiscal year end, Department staff obtained records from the USDA database and reports provided by the food logistics vendor, and compared the reports with the warehouse?s inventory for the Lunch Program?s inventory reconciliation. WHY DID THESE PROBLEMS OCCUR? The Department did not have sufficient internal controls in place over its Lunch Program inventory during Fiscal Year 2020. First, the Department failed to follow its Lunch Program procedures related to completing an annual reconciliation of Lunch Program-donated foods and to investigate any inventory variances. The Department stated that the reason for the variance was that the food logistics vendor did not provide final shipping reports; however, the Department did not follow up and obtain the final shipping reports from its food logistics vendor to determine if the variances were resolved. Second, the Department does not have policies and procedures requiring that Department staff obtain from the warehouse and retain Lunch Program receipts and distributions, such as BOLs for the USDA shipments received by the warehouse and the BOLs for the distributions made by the food logistics vendor to the schools, and therefore, did not have adequate information to complete the fiscal year-end reconciliation. WHY DO THESE PROBLEM MATTER? If the Department does not obtain and maintain the Lunch Program?s inventory records, it will be out of compliance with federal guidance. In addition, if the Department does not reconcile its food inventory and investigate variances, food loss or waste could occur and the Department would be required to pay the federal government for this loss. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide the schools for children. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-057 The Department of Human Services (Department) should ensure that it complies with U.S. Department of Agriculture?s (USDA) federal requirements for the National School Lunch program by: A Completing fiscal year-end reconciliations of its donated foods inventory, including investigating and resolving all identified variances. B Developing and implementing policies and procedures for the Department to obtain and maintain complete inventory records, including Bills of Lading for the USDA shipments received by the warehouse and for the distributions made by the food logistics vendor to the schools. This should include maintaining its own records for verifying USDA and vendor information. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory. B PARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021. The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level. AUDITOR?S ADDENDUM Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Although the Department contracts with a warehouse to maintain the donated foods inventory and to obtain and maintain complete inventory records, the requirement for proper maintenance of inventory records is ultimately the Department?s responsibility.
Show full finding ▾Hide full finding ▴The following findings and recommendations relating to internal control deficiencies classified as a Material Weakness and Significant Deficiency were communicated to the Department of Human Services (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. NATIONAL SCHOOL LUNCH PROGRAM FOOD INVENTORY RECONCILIATION The Department is in-charge of managing the procurement, storage, and distribution of donated agricultural commodities provided through and administered by the USDA?s National School Lunch Program (Lunch Program) [CFDA No. 10.555]. This program is part of the USDA?s Child Nutrition Cluster programs. The federal Child Nutrition Cluster programs are intended to (1) assist states in administering food services that provide healthy, nutritious meals to eligible children in public and nonprofit private schools, residential child care institutions, and summer recreation programs; and (2) encourage the domestic consumption of nutritious agricultural commodities. USDA enters into agreements with states for the distribution of USDA- donated foods. The states, in turn, enter into agreements with local Lunch Program operators, which are defined collectively as recipient agencies. The Department?s responsibility under the Lunch Program includes hiring a food logistics vendor to purchase food products and deliver them to schools and child care centers (recipient agencies) throughout Colorado; and tracking, maintaining, and reconciling inventory records for the food products. The Department contracts with a warehouse in Colorado Springs to store its food inventory. Once a donated food shipment arrives at the Department-contracted warehouse, the warehouse staff count the food to compare it to the provided Bill of Lading (BOL), review it for good condition, and check the temperature of all cases. The food logistics vendor then picks up the donated food from the warehouse and delivers it to the schools. The schools are responsible for inspecting the load, counting the items received, and signing off on the BOL to certify that it is accurate. The food logistics vendor keeps a copy of the BOL. The Colorado Department of Education (CDE) is responsible for all non-inventory related federal requirements for the Lunch Program. For example, CDE is responsible for collecting and tracking total school lunches served, which dictates the volume of donated foods the State receives. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine if the Department had adequate internal controls over and complied with inventory-related requirements for the Lunch Program during Fiscal Year 2020, which included determining whether the Department maintained accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods through the Lunch Program and performed inventory reconciliations throughout the fiscal year. We obtained the Department?s procedures for preparing its fiscal year-end and monthly reconciliations of its Lunch Program inventory and documentation related to the receipt and shipment of the Lunch Program?s donated foods. We also requested that the Department provide its fiscal year-end inventory reconciliation. We obtained and tested two monthly inventory reconciliations prepared by the Department for Fiscal Year 2020. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against these requirements: Federal regulations [7 CFR 250.12(b)] for the Lunch Program require that the Department take a physical inventory of its Lunch Program donated foods at its warehouse and reconcile the results of the physical inventory annually with the warehouse?s inventory records. The Department must maintain the results of the inventory and the reconciliation itself or ensure the warehouse maintains the documentation. The regulations also require that the Department, as the distributing agency, report any donated food losses, and ensure that restitution is made for such losses. Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16 (a)]. Records relating to requirements for donated foods must be retained for a period of three years from the close of the fiscal or school year to which they pertain [7 CFR 250.19(b)]. The Department?s Inventory Tracking and Reconciliation policy for the Lunch Program requires the Department to perform a reconciliation between incoming inventory from the USDA and shipping reports provided by the food logistics vendor. The procedure states that ?any variances between the Reconciliation Spreadsheet and Physical Inventory are given to the food logistics vendor to check and agree on. If there is a significant variance the program completes a food loss investigation which may result in financial reimbursement.? WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully reconcile its Lunch Program donated food inventory at fiscal year end to the underlying records. Specifically, the Department conducted a fiscal year end physical inventory at the warehouse and compared the physical inventory counts to the inventory provided by the USDA throughout the fiscal year and what was delivered to schools and child care centers by the food logistics vendor, but did not follow-up and resolve variances noted through the comparison. Specifically, we noted that 25 of the 30 (83 percent) food items the Department compared between the USDA-provided and food logistics vendor-provided documentation contained differences. The overall gross value of the variances totaled $4,507, with a net variance of $259. We also noted that the Department did not obtain from the warehouse or retain records of the receipt and distribution of the Lunch Program?s donated inventory during the fiscal year. Rather, at fiscal year end, Department staff obtained records from the USDA database and reports provided by the food logistics vendor, and compared the reports with the warehouse?s inventory for the Lunch Program?s inventory reconciliation. WHY DID THESE PROBLEMS OCCUR? The Department did not have sufficient internal controls in place over its Lunch Program inventory during Fiscal Year 2020. First, the Department failed to follow its Lunch Program procedures related to completing an annual reconciliation of Lunch Program-donated foods and to investigate any inventory variances. The Department stated that the reason for the variance was that the food logistics vendor did not provide final shipping reports; however, the Department did not follow up and obtain the final shipping reports from its food logistics vendor to determine if the variances were resolved. Second, the Department does not have policies and procedures requiring that Department staff obtain from the warehouse and retain Lunch Program receipts and distributions, such as BOLs for the USDA shipments received by the warehouse and the BOLs for the distributions made by the food logistics vendor to the schools, and therefore, did not have adequate information to complete the fiscal year-end reconciliation. WHY DO THESE PROBLEM MATTER? If the Department does not obtain and maintain the Lunch Program?s inventory records, it will be out of compliance with federal guidance. In addition, if the Department does not reconcile its food inventory and investigate variances, food loss or waste could occur and the Department would be required to pay the federal government for this loss. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide the schools for children. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-057 The Department of Human Services (Department) should ensure that it complies with U.S. Department of Agriculture?s (USDA) federal requirements for the National School Lunch program by: A Completing fiscal year-end reconciliations of its donated foods inventory, including investigating and resolving all identified variances. B Developing and implementing policies and procedures for the Department to obtain and maintain complete inventory records, including Bills of Lading for the USDA shipments received by the warehouse and for the distributions made by the food logistics vendor to the schools. This should include maintaining its own records for verifying USDA and vendor information. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory. B PARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021. The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level. AUDITOR?S ADDENDUM Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Although the Department contracts with a warehouse to maintain the donated foods inventory and to obtain and maintain complete inventory records, the requirement for proper maintenance of inventory records is ultimately the Department?s responsibility.
(A) The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory. (B) The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level.
2020-057
Finding 2021-063 Unemployment Insurance?Federal Reporting The Department?s Accounting Section is responsible for completing the following two federal financial reports for the UI program and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Accounting Section uses bank statements and reports from the Colorado Operations Resource Engine (CORE), the State?s accounting system, to create a workbook with the information and uses that workbook to complete the reports. ? ETA 9130, Financial Status Report, UI Programs. This is a quarterly report used to report the Department?s UI program and administrative expenditures. Financial data is required to be reported cumulatively from grant inception through the end of the reporting period. ? ETA 2112, UI Financial Transaction Summary. This is a monthly report that is a summary of the UI program?s transactions, which account for all funds received in, passed through, or paid out of the state employment fund during the applicable month. The UI division is responsible for completing the following federal report for the UI program and ensuring the report is accurate, complete, and submitted to the federal government by the required timeline. The UI division uses data pulled from MyUI+, the UI claims and benefits system, to generate two reports to fill out the ETA 191 report, described as follows. ? ETA 191, Financial Status of UCFE/UCX. This is a quarterly report on the State?s unemployment compensation expenditures paid by the Department to former federal employees (UCFE) and ex-service members (UCX) who have filed with the Department for unemployment benefits, and total amount of benefits paid to claimants of specific federal agencies. The federal government uses this report to request reimbursement of UCFE and UCX benefit payments from federal and military agencies. The federal government reimburses the Department for these benefit payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over and complied with federal reporting requirements for the UI program during Fiscal Year 2021. As part of our audit work, we gained an understanding of the Department?s procedures that were in place to prepare the federal reports. In addition, we reviewed four ETA 2112 reports and two ETA 191 reports submitted to the federal government for Fiscal Year 2021 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Department?s policies and procedures for completing the reports, as well as the Department?s supporting documentation for the reports. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the OSC?s policy Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The U.S. Department of Labor Unemployment Insurance Handbook 401 (Handbook) states that the ETA 2112 is due the first day of the second month following the month that the data in the report represents. In addition, the Handbook states that the ETA 191 is due by the 25th of the month following the close of the quarter. What problems did the audit work identify? We identified issues with 2 of the 4 (50 percent) ETA 2112 reports we tested, and 1 of the 2 (50 percent) ETA 191 reports we tested. Specifically, we identified the following: ETA 2112. We identified four issues with the September 2020 report, as follows: ? The Department could not provide support for $50.6 million reported as federal tax withholding on the report. ? The Department could not provide documentation related to the FPUC deposits and disbursements reported on the report. Specifically, the Department reported FPUC deposits as $27.0 million and FPUC Disbursements as $28.4 million. Because the Department could not provide documentation, we could not determine the correct amounts that should have been reported. ? The Department overstated the deposit amount for the intra-account transfer line by $240.2 million. Specifically, the Department reported that the amount deposited during the month for the intra-account transfers was $378.1 million, but the supporting documentation we reviewed showed the deposits totaled $137.9 million. ? The Department submitted the report on November 5, 2020, or 3 days after the deadline of November 2, 2020. In the February 2021 report, we identified that the Department understated reimbursement benefits from nonprofits by $540,000, reimbursements from local governments by $1.1 million; and reimbursements from state government by $204,700. Finally, based on discussion with the Department, it does not protect the formulas in its ETA 2112 workbooks it uses to prepare the reports in order to prevent intentional or inadvertent changes to calculations. ETA 191. We identified two issues with the ETA 191 report for the quarter ended March 2021 report. First, the Department failed to appropriately correct a federal Department of Labor-identified error from the previous quarter for expenditures for military agencies. Specifically, the Department incorrectly adjusted the $1,089,761, by $2,100, which was an under correction of the error of $2,120. Second, the Department submitted the report on May 14, 2021, nearly a month after the April 16, 2021, deadline. Why did these problems occur? The Department did not have sufficient internal controls in place to ensure that the federal reports and associated documentation were accurate and complete during Fiscal Year 2021. Specifically, the Department does not have formal, documented policies for completing the reports or a requirement that the workbooks are protected. Although the Department has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to the wrong information being input into the reports, which a review could have caught and corrected prior to the Department submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including formal, documented policies, protection of formulas in the workbooks used to prepare the reports to prevent intentional or inadvertent changes to calculations, and adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause the users of these reports to rely on incorrect information. This could have a negative impact on the Department?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-063 The Department of Labor and Employment should strengthen its internal controls over federal reporting by developing, formally documenting, and implementing policies for completing its federal reports for the Unemployment Insurance program. These policies should require the workbooks used to prepare the reports to be protected and that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: March 2023 CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
Show full finding ▾Hide full finding ▴Finding 2021-063 Unemployment Insurance?Federal Reporting The Department?s Accounting Section is responsible for completing the following two federal financial reports for the UI program and ensuring the reports are accurate, complete, and submitted to the federal government by the required deadline. The Accounting Section uses bank statements and reports from the Colorado Operations Resource Engine (CORE), the State?s accounting system, to create a workbook with the information and uses that workbook to complete the reports. ? ETA 9130, Financial Status Report, UI Programs. This is a quarterly report used to report the Department?s UI program and administrative expenditures. Financial data is required to be reported cumulatively from grant inception through the end of the reporting period. ? ETA 2112, UI Financial Transaction Summary. This is a monthly report that is a summary of the UI program?s transactions, which account for all funds received in, passed through, or paid out of the state employment fund during the applicable month. The UI division is responsible for completing the following federal report for the UI program and ensuring the report is accurate, complete, and submitted to the federal government by the required timeline. The UI division uses data pulled from MyUI+, the UI claims and benefits system, to generate two reports to fill out the ETA 191 report, described as follows. ? ETA 191, Financial Status of UCFE/UCX. This is a quarterly report on the State?s unemployment compensation expenditures paid by the Department to former federal employees (UCFE) and ex-service members (UCX) who have filed with the Department for unemployment benefits, and total amount of benefits paid to claimants of specific federal agencies. The federal government uses this report to request reimbursement of UCFE and UCX benefit payments from federal and military agencies. The federal government reimburses the Department for these benefit payments. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over and complied with federal reporting requirements for the UI program during Fiscal Year 2021. As part of our audit work, we gained an understanding of the Department?s procedures that were in place to prepare the federal reports. In addition, we reviewed four ETA 2112 reports and two ETA 191 reports submitted to the federal government for Fiscal Year 2021 to ensure they were accurate, complete, and submitted by the required deadline. We also requested the Department?s policies and procedures for completing the reports, as well as the Department?s supporting documentation for the reports. How were the results of the audit work measured? We measured the results of our audit against the following: In accordance with Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and terms and conditions of the federal award. In accordance with the OSC?s policy Internal Control System, state agencies shall use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Green Book, Paragraph OV4.08, Documentation Requirements, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. Green Book Paragraph 12.02, Documentation of Responsibilities through Policies, specifically indicates that management should document in their policies the internal control responsibilities of the organization. The U.S. Department of Labor Unemployment Insurance Handbook 401 (Handbook) states that the ETA 2112 is due the first day of the second month following the month that the data in the report represents. In addition, the Handbook states that the ETA 191 is due by the 25th of the month following the close of the quarter. What problems did the audit work identify? We identified issues with 2 of the 4 (50 percent) ETA 2112 reports we tested, and 1 of the 2 (50 percent) ETA 191 reports we tested. Specifically, we identified the following: ETA 2112. We identified four issues with the September 2020 report, as follows: ? The Department could not provide support for $50.6 million reported as federal tax withholding on the report. ? The Department could not provide documentation related to the FPUC deposits and disbursements reported on the report. Specifically, the Department reported FPUC deposits as $27.0 million and FPUC Disbursements as $28.4 million. Because the Department could not provide documentation, we could not determine the correct amounts that should have been reported. ? The Department overstated the deposit amount for the intra-account transfer line by $240.2 million. Specifically, the Department reported that the amount deposited during the month for the intra-account transfers was $378.1 million, but the supporting documentation we reviewed showed the deposits totaled $137.9 million. ? The Department submitted the report on November 5, 2020, or 3 days after the deadline of November 2, 2020. In the February 2021 report, we identified that the Department understated reimbursement benefits from nonprofits by $540,000, reimbursements from local governments by $1.1 million; and reimbursements from state government by $204,700. Finally, based on discussion with the Department, it does not protect the formulas in its ETA 2112 workbooks it uses to prepare the reports in order to prevent intentional or inadvertent changes to calculations. ETA 191. We identified two issues with the ETA 191 report for the quarter ended March 2021 report. First, the Department failed to appropriately correct a federal Department of Labor-identified error from the previous quarter for expenditures for military agencies. Specifically, the Department incorrectly adjusted the $1,089,761, by $2,100, which was an under correction of the error of $2,120. Second, the Department submitted the report on May 14, 2021, nearly a month after the April 16, 2021, deadline. Why did these problems occur? The Department did not have sufficient internal controls in place to ensure that the federal reports and associated documentation were accurate and complete during Fiscal Year 2021. Specifically, the Department does not have formal, documented policies for completing the reports or a requirement that the workbooks are protected. Although the Department has a procedure document that provides instructions on how to complete the federal reports, the procedures do not include a requirement for a supervisory review of these reports prior to submitting them to the federal government. Some of the errors we identified were due to the wrong information being input into the reports, which a review could have caught and corrected prior to the Department submitting the report to the federal government. Why do these problems matter? Strong internal controls over federal reporting, including formal, documented policies, protection of formulas in the workbooks used to prepare the reports to prevent intentional or inadvertent changes to calculations, and adequate supervisory review, are necessary to ensure that the Department is in compliance with federal reporting requirements. Errors in the federal reports could cause the users of these reports to rely on incorrect information. This could have a negative impact on the Department?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-063 The Department of Labor and Employment should strengthen its internal controls over federal reporting by developing, formally documenting, and implementing policies for completing its federal reports for the Unemployment Insurance program. These policies should require the workbooks used to prepare the reports to be protected and that a supervisory review occurs prior to submitting the reports to the federal government. Response Department of Labor and Employment Agree Implementation Date: March 2023 CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
CDLE will continue to develop, formally document, and implement policies for completing its federal reports for the Unemployment Insurance program. These policies will require the workbooks used to prepare the reports to be protected, for the data to be substantiated, and will require supervisory review on a monthly basis prior to submitting the reports to the federal government.
The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. UNEMPLOYMENT INSURANCE The Unemployment Insurance (UI) program, created by the Social Security Act, provides benefits to unemployed workers for periods of involuntary unemployment and helps stabilize the economy by maintaining the spending power of workers while they are between jobs. The U.S. Department of Labor provides grant funding for each state to design and administer its own UI program within federal requirements. The Department?s Division of Unemployment Insurance is responsible for the administration and monitoring of Colorado's UI programs, including the establishment of policies and operating procedures which comply with federal requirements; determining claimant eligibility and making payment of UI benefits to claimants; and administering the programs in accordance with established policies and procedures. The regular UI program provides coverage to most salary and wage workers and is funded primarily by state UI taxes assessed on covered employers. These taxes are required to be deposited into the State?s Unemployment Trust Fund for the purpose of making UI payments under the federally approved state unemployment law. As part of the administration of this program, the Department uses the Colorado Unemployment Benefits System (CUBS) to aid in determining eligibility for UI benefits. On March 13, 2020, the President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, and Congress subsequently passed the Emergency Unemployment Insurance Stabilization and Access Act of 2020 (EUISAA) and the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). Both EUISAA and the CARES Act included additional federal funding for, and eased restrictions on, all states? UI programs. The CARES Act created three temporary unemployment compensation entitlement programs that are federally funded: ? The Pandemic Unemployment Assistance (PUA) program provided assistance for individuals not eligible for regular UI, which includes self-employed individuals; gig workers, who are independent contractors who work temporary jobs, typically in the service sector; and other independent contractors. These benefit payments were available specifically for individuals who lost employment due to the COVID-19 pandemic. ? The Pandemic Emergency Unemployment Compensation Program (PEUC) provided an additional 13 weeks of UI benefits for unemployed workers who have exhausted regular UI benefits. ? Federal Pandemic Unemployment Compensation provided an additional $600 weekly to all unemployed workers receiving regular UI, PUA, or PEUC benefits. Also in March 2020, the Governor declared a state of emergency relating to COVID-19 and issued Executive Order 2020-12 (Executive Order) to expedite UI benefits claim processing and payment distributions. To accomplish the directive, the Executive Order suspended various statutory provisions, including the requirement for the Department to wait a specified number of days before paying a claim, which was part of the adjudication process. The Department is responsible for reviewing, or adjudicating, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wages reported by the claimant, other than the new PUA claims, are compared to employer reported wages submitted to the Department on a quarterly basis, and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In order to adjudicate PUA claims, the Department is required to review the self-employment income reported by the claimant. In addition, the Department performs additional procedures, such as requesting information from the claimant and claimant?s last employer, to identify potential issues with a claimant?s ability and availability to work, and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. Prior to the Executive Order going into effect, the Department adjudicated claims prior to payment, which the Department indicated was generally a 4- to 6-week process. The Department is responsible for identifying overpayments to allow the Department to take appropriate follow-up action. The Department has established procedures to assist with the identification of overpayments, including cross-matching of earnings and incarceration information. The Department is required to use the federal Treasury Offset Program (TOP) to recover debts that remain uncollected after one year of the establishment of the overpayment. These debts include benefit overpayments due to fraud and overpayments due to a claimant?s failure to report earnings. Because of the COVID-19 pandemic, during Fiscal Year 2020, the Department paid more than 15 times the annual benefits for unemployed individuals as in a typical year. During the fiscal year ended June 30, 2020, the Department expended approximately $2.9 billion of federal funds for this program and an additional $1.5 billion was paid from the regular UI program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements for the UI program during Fiscal Year 2020. These federal requirements consisted of eligibility and allowable costs for the UI program and special provision requirements for overpayments of UI benefits. As part of our testing procedures, we interviewed Department staff to gain an understanding of the Department?s internal controls over the processing of UI payments, and the impacts on UI as a result of the pandemic. We requested the listings of UI claims that had not been adjudicated as of June 30, 2020, and PUA overpayments that were identified in October 2020 but related to UI claims paid between March and June 2020, and the related support. In addition, we requested the detail of UI benefit payments that were processed by the Department from March to June 2020, the period during Fiscal Year 2020 in which additional UI payments were issued as a result of the COVID-19 pandemic. We received the detail of benefit payments for this time period in three different populations: standard UI payments, payments that could not be processed through CUBS?referred to as manual payments, and PUA payments. We also interviewed Department staff to gain an understanding of the Department?s internal controls over the establishment of overpayments and to determine whether they were using the TOP as required by federal regulations. In addition, we selected a sample of 60 overpayments that were identified by the Department during the fiscal year ended June 30, 2020, to ensure that the Department was properly identifying and handling overpayments in accordance with its procedures. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? The Department was not able to provide documentation for several areas of the UI program and we were unable to perform testing to determine the Department?s compliance for eligibility, allowable costs, and special provision requirements for overpayments of UI benefits. Specifically: ? BACKLOG OF UI ADJUDICATION ISSUES. The Department could not provide a listing of the claims, either regular UI or PUA, that had not been adjudicated as of June 30, 2020. Therefore, we could not perform testing to determine if the individuals were eligible to receive benefits, received the appropriate amount of benefits, or needed to repay a portion of their benefits to the Department. In February 2021, the Department stated that it had not adjudicated, and still needed to review, approximately 206,000 standard UI issues, representing about 82,000 unique claimants, for payments that were processed prior to June 30, 2020, in order to determine whether the related claim was valid. However, the Department could not provide this listing of standard UI issues or a listing of the claimants that had gone through adjudication between July 2020 and February 2021. Furthermore, the Department could not provide the number of claims that still needed to be adjudicated for the PUA program. The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 23-20 in May 2020, to provide states with guidance regarding required program integrity functions for the UI programs under the CARES Act. The letter specifies that ?states must continue to operate their programs, both new and existing, in conformity and compliance with federal laws and guidance.? This issue was addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021. ? PUA OVERPAYMENTS. The Department did not provide support for PUA overpayments that were identified by the Department in October 2020; therefore, we could not identify which claimants were associated with the overpayments or whether the overpayments were correctly calculated. According to the Department, it made an estimated $52.1 million in PUA overpayments to 11,445 claimants, or 13 percent of PUA claimants, during Fiscal Year 2020. Subsequent to fiscal year end, in October 2020, the Department determined it would not require the claimants to repay the funds due to confusion in the form requesting wage information from PUA claimants and therefore, removed this amount of overpayments from the PUA system. Because the payments resulted in an estimated $52.1 million in overpayments, we considered this amount to be questioned costs. We also identified the following problem during our testing: ? PUA FRAUDULENT PAYMENTS. We identified approximately $243,000 in PUA fraudulent payments that the Department determined were the result of identity theft. Through our review of the benefit payment population, we identified an invalid social security number that appeared 151times. When we discussed these with Department staff, they stated that once they identified the fraudulent payment due to identity theft, they assigned an invalid social security number to identify these payments for tracking purposes. Because these payments of $243,000 were identified as fraudulent, we considered this amount to be questioned costs. The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 16-20 Change 1 in April 2020 to address questions and provide further guidance about the PUA program. An overpayment must be established for any benefits that were overpaid. Both of these issues were addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021. Furthermore, the Department inappropriately suspended certain procedures during the COVID-19 pandemic. Specifically: ? SUSPENSION OF WAGE CROSSMATCH. The Department suspended the crossmatch process after March 31, 2020, for regular UI claims. Our testing of 60 overpayments noted that the Department identified 23 overpayments (38 percent) by performing the wage crossmatch prior to the suspension of the process. Section 20 CFR 603.23 specifies that the Department, as a state unemployment compensation agency, ?must crossmatch quarterly wage information with [Unemployment Compensation] payment information to the extent that such information is likely, as determined by the Secretary of Labor, to be productive in identifying ineligibility for benefits and preventing or discovering incorrect payments.? As part of the Department?s adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In addition, the Department reviews to identify potential issues with a claimant?s ability and availability to work and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. ? SUSPENSION OF TREASURY OFFSET PROGRAM. The Department did not use the TOP in June 2020. The Bipartisan Budget Act of 2013 requires states to use the TOP to recover covered unemployment compensation debts that remain uncollected one year after the debt was determined to be due. ? LACK OF PRISON MATCH PROCEDURES OVER PUA CLAIMS. The Department did not use the Appriss system to crossmatch PUA claims to prison records prior to June 30, 2020. Per discussion with Department staff, this crossmatch began in January 2021 and, at the time of our audit, the Department had not performed this match procedure for payments issued prior to January 2021. The Division of Unemployment Insurance?s Regulations Concerning Unemployment Security [7 CCR 1101-2, Section 2.8.3.6] states that a ?claimant who is incarcerated and unable to accept employment under a work-release program is not available for work.? As the claimant would not be available for work, the claimant would not be entitled to benefits. The Department has documented incarceration procedures to identify and handle issues when a claimant is identified as being incarcerated while receiving UI benefits. Appriss is a system that is used by the Department to perform this cross-check with prison records. In addition, the U.S. Department of Labor strongly recommends an incarceration crossmatch as one of the activities a state should use as part of its integrity functions. WHY DID THESE PROBLEMS OCCUR? The Department lacked a business plan and internal controls to handle the significant increase in UI claims as a result of the COVID-19 pandemic, which contributed to the issues we identified, as follows: ? LACK OF DISASTER PLAN. The Department did not have a plan in place to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. The Executive Order enacted in March 2020 directed the Department to expedite UI benefits claim processing and distribution of payments. Since the Department did not have a plan in place for addressing the significant increase in demand for benefits, it did not adjudicate all claims during the last 3 months of Fiscal Year 2020 during the start of the COVID-19 pandemic. This led to the backlog we noted. ? LACK OF REPORTING. The Department did not have reports available regarding key areas of the UI programs, including listings of unadjudicated claims and overpayments, including PUA, by claimant as of any point in time. We also found inconsistencies in the data provided for the claimants and benefits paid during the fiscal year. For example, the detail of overpayments established during Fiscal Year 2020 did not provide information to identify the claimant associated with the overpayment; therefore, we could not compare these overpayments to the claimants that received payments during March to June 2020. In addition, as previously noted, we received the benefits paid data for the period March to June 2020 in three different populations. The information provided from these different populations did not contain the same elements; therefore, we could not perform procedures across all three populations. ? FRAUDULENT PAYMENTS. Prior to June 2020, the Department did not have analytical procedures that used fraud indicators to assist with analyzing claims for the identification of potential fraudulent payments. The Department reported it began to experience an increase in suspected fraudulent payments in June 2020; at that point, the Department stated that it began developing data analytical tools to identify claims not yet paid for the presence of unique fraud indicators. Using these data analytical tools, around June 17, 2020, the Program Integrity Division established a process to place holds on claims relating to fraud (Program Integrity Hold). If a payment had fraud indicators identified, a Program Integrity Hold was established on the claim until the claimant information could be reviewed. As of June 30, 2020, there were eight fraud indicators in effect on COVID-19 pandemic claims. Per discussions with Department staff, the number of fraud indicators had increased to about 50 fraud indicators by February 2021. ? DISCONTINUED WAGE CROSSMATCHES AND USE OF TOP. The Department reported that it stopped performing crossmatches due to the delayed implementation of the new unemployment system that replaced CUBS. In addition, the Department reported that TOP was not used due to the Department not using another state agency that had been collecting those payments on behalf of the Department. ? ISSUES WITH NEW PUA SYSTEM. A fourth UI system, the PUA system, was implemented during April 2020 to handle these claims. This system was not integrated with Appriss to perform the crossmatch with prison records. WHY DO THESE PROBLEMS MATTER? Without the appropriate controls in place, the Department cannot ensure that only eligible claimants are receiving benefits in a timely manner. The significant backlog of adjudication issues did not permit us, nor was it practical to extend or apply other auditing procedures, to obtain sufficient, appropriate audit evidence to conclude whether the Department was in compliance with federal requirements for eligibility, allowable costs, and special provisions relating to overpayments. In addition, delayed adjudication can cause difficulties in obtaining evidence to make eligibility decisions and can result in potential improper payments. A significant backlog can also affect a claimant?s past, present, or future eligibility for benefits. Furthermore, suspending the quarterly wage crossmatch and not using TOP resulted in the Department not being in compliance with federal requirements relating to special tests and provisions for overpayments. The Department?s failure to ensure compliance with federal requirements for the UI program could result in disallowed costs and federal sanctions. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-066 The Department of Labor and Employment should improve its internal controls over the Unemployment Insurance (UI) program and ensure it complies with the related federal and state requirements by: A Developing a disaster plan to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. B Identifying the necessary reporting for the UI program and ensuring consistent reporting. C Continuing to use the data analytical tools to identify possible fraud that requires a Program Integrity Hold and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. D Resuming the quarterly wage crossmatch for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. E Resuming the Treasury Offset Program to recover allowable UI debt for all state and federal programs. F Performing crossmatch against prison records for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. RESPONSE DEPARTMENT OF LABOR AND EMPLOYMENT A AGREE. IMPLEMENTATION DATE: JUNE 2023. The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable. Implementation Date: June 2023 B AGREE. IMPLEMENTATION DATE: JUNE 2023. The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments. Implementation Date: June 2023 C AGREE. IMPLEMENTATION DATE: JANUARY 2021. The Unemployment Insurance Division agrees. The creation of Pandemic Unemployment Assistance (PUA) for individuals traditionally not eligible for the receipt of regular state unemployment benefits created an opportunity for fraudulent claims filed as the result of identity theft. The Division recognized PUA claim filing data inconsistent with general economic conditions in June, 2020 related to claims being filed with stolen identities. The Division created automated fraud holds for claims filed within the PUA system exhibiting suspicious characteristics but did not have that same capability in the legacy system for regular unemployment claims. Data analytics were used to improve the fraud holds in the PUA system and were used to review claims activity in the legacy system where minimal identity theft activity was discovered and claims were manually shut down. In December 2020 increased suspicious activity began occurring in the state legacy system, resulting in a decision to implement MyUI+ on January 10, 2021 for all UI programs in order to apply the same fraud holds to all claims filed. Over 150,000 holds were placed on suspicious state UI claims that came from the legacy system immediately after the new system went live. As of this date, data analysis occurs multiple times per week and will continue in the future as this more sophisticated type of fraud is not expected to stop once the pandemic ends. Implementation Date: January 2021 D AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs. Implementation Date: December 2021 E AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The Unemployment Insurance Division agrees and is currently on a corrective action plan with USDOL related to its failure to continue use of the federal Treasury Offset Program (TOP) program and has until December 2021 to resolve this failure. The Division ceased using TOP in 2018 when it severed a relationship with another state agency, which had been collecting those intercepts on behalf of the Division. That relationship ended due to ongoing concerns about record keeping by that state agency and whether such intercepts were properly collected in cases where claimants were making payments towards debt owed. The intent had been for the Division to implement TOP with the original implementation date for MyUI+ that was ultimately delayed. The Division is working towards implementation of this required program before the 2021 tax season begins and anticipates its integration into MyUI+ at that time. Implementation Date: December 2021 F AGREE. IMPLEMENTATION DATE: JANUARY 2021. The Unemployment Insurance Division understands and agrees that prison record crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The prison record crossmatch was continually run in the legacy system and all federal requirements were followed in for standard UI claims. This crossmatch did not initially occur in the PUA system due to the urgency to stand up the federal PUA program quickly at the beginning of the pandemic, a separate system was stood up outside the current legacy system and programming time was reduced by not including many interfaces and cross matches, including the prison cross match. However, once all UI programs were integrated with the implementation of MyUI+ into production on January 10, 2021, this crossmatch ran against all claims filed within that system, including claims initially filed in the original stand alone PUA system. As such, this crossmatch began in January, 2021 including all PUA claims that had been previously filed. All federal requirements associated with prison record crossmatch are currently being followed for all UI programs. Implementation Date: January 2021.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to the Department of Labor and Employment (Department) in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. UNEMPLOYMENT INSURANCE The Unemployment Insurance (UI) program, created by the Social Security Act, provides benefits to unemployed workers for periods of involuntary unemployment and helps stabilize the economy by maintaining the spending power of workers while they are between jobs. The U.S. Department of Labor provides grant funding for each state to design and administer its own UI program within federal requirements. The Department?s Division of Unemployment Insurance is responsible for the administration and monitoring of Colorado's UI programs, including the establishment of policies and operating procedures which comply with federal requirements; determining claimant eligibility and making payment of UI benefits to claimants; and administering the programs in accordance with established policies and procedures. The regular UI program provides coverage to most salary and wage workers and is funded primarily by state UI taxes assessed on covered employers. These taxes are required to be deposited into the State?s Unemployment Trust Fund for the purpose of making UI payments under the federally approved state unemployment law. As part of the administration of this program, the Department uses the Colorado Unemployment Benefits System (CUBS) to aid in determining eligibility for UI benefits. On March 13, 2020, the President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, and Congress subsequently passed the Emergency Unemployment Insurance Stabilization and Access Act of 2020 (EUISAA) and the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). Both EUISAA and the CARES Act included additional federal funding for, and eased restrictions on, all states? UI programs. The CARES Act created three temporary unemployment compensation entitlement programs that are federally funded: ? The Pandemic Unemployment Assistance (PUA) program provided assistance for individuals not eligible for regular UI, which includes self-employed individuals; gig workers, who are independent contractors who work temporary jobs, typically in the service sector; and other independent contractors. These benefit payments were available specifically for individuals who lost employment due to the COVID-19 pandemic. ? The Pandemic Emergency Unemployment Compensation Program (PEUC) provided an additional 13 weeks of UI benefits for unemployed workers who have exhausted regular UI benefits. ? Federal Pandemic Unemployment Compensation provided an additional $600 weekly to all unemployed workers receiving regular UI, PUA, or PEUC benefits. Also in March 2020, the Governor declared a state of emergency relating to COVID-19 and issued Executive Order 2020-12 (Executive Order) to expedite UI benefits claim processing and payment distributions. To accomplish the directive, the Executive Order suspended various statutory provisions, including the requirement for the Department to wait a specified number of days before paying a claim, which was part of the adjudication process. The Department is responsible for reviewing, or adjudicating, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wages reported by the claimant, other than the new PUA claims, are compared to employer reported wages submitted to the Department on a quarterly basis, and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In order to adjudicate PUA claims, the Department is required to review the self-employment income reported by the claimant. In addition, the Department performs additional procedures, such as requesting information from the claimant and claimant?s last employer, to identify potential issues with a claimant?s ability and availability to work, and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. Prior to the Executive Order going into effect, the Department adjudicated claims prior to payment, which the Department indicated was generally a 4- to 6-week process. The Department is responsible for identifying overpayments to allow the Department to take appropriate follow-up action. The Department has established procedures to assist with the identification of overpayments, including cross-matching of earnings and incarceration information. The Department is required to use the federal Treasury Offset Program (TOP) to recover debts that remain uncollected after one year of the establishment of the overpayment. These debts include benefit overpayments due to fraud and overpayments due to a claimant?s failure to report earnings. Because of the COVID-19 pandemic, during Fiscal Year 2020, the Department paid more than 15 times the annual benefits for unemployed individuals as in a typical year. During the fiscal year ended June 30, 2020, the Department expended approximately $2.9 billion of federal funds for this program and an additional $1.5 billion was paid from the regular UI program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements for the UI program during Fiscal Year 2020. These federal requirements consisted of eligibility and allowable costs for the UI program and special provision requirements for overpayments of UI benefits. As part of our testing procedures, we interviewed Department staff to gain an understanding of the Department?s internal controls over the processing of UI payments, and the impacts on UI as a result of the pandemic. We requested the listings of UI claims that had not been adjudicated as of June 30, 2020, and PUA overpayments that were identified in October 2020 but related to UI claims paid between March and June 2020, and the related support. In addition, we requested the detail of UI benefit payments that were processed by the Department from March to June 2020, the period during Fiscal Year 2020 in which additional UI payments were issued as a result of the COVID-19 pandemic. We received the detail of benefit payments for this time period in three different populations: standard UI payments, payments that could not be processed through CUBS?referred to as manual payments, and PUA payments. We also interviewed Department staff to gain an understanding of the Department?s internal controls over the establishment of overpayments and to determine whether they were using the TOP as required by federal regulations. In addition, we selected a sample of 60 overpayments that were identified by the Department during the fiscal year ended June 30, 2020, to ensure that the Department was properly identifying and handling overpayments in accordance with its procedures. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? The Department was not able to provide documentation for several areas of the UI program and we were unable to perform testing to determine the Department?s compliance for eligibility, allowable costs, and special provision requirements for overpayments of UI benefits. Specifically: ? BACKLOG OF UI ADJUDICATION ISSUES. The Department could not provide a listing of the claims, either regular UI or PUA, that had not been adjudicated as of June 30, 2020. Therefore, we could not perform testing to determine if the individuals were eligible to receive benefits, received the appropriate amount of benefits, or needed to repay a portion of their benefits to the Department. In February 2021, the Department stated that it had not adjudicated, and still needed to review, approximately 206,000 standard UI issues, representing about 82,000 unique claimants, for payments that were processed prior to June 30, 2020, in order to determine whether the related claim was valid. However, the Department could not provide this listing of standard UI issues or a listing of the claimants that had gone through adjudication between July 2020 and February 2021. Furthermore, the Department could not provide the number of claims that still needed to be adjudicated for the PUA program. The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 23-20 in May 2020, to provide states with guidance regarding required program integrity functions for the UI programs under the CARES Act. The letter specifies that ?states must continue to operate their programs, both new and existing, in conformity and compliance with federal laws and guidance.? This issue was addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021. ? PUA OVERPAYMENTS. The Department did not provide support for PUA overpayments that were identified by the Department in October 2020; therefore, we could not identify which claimants were associated with the overpayments or whether the overpayments were correctly calculated. According to the Department, it made an estimated $52.1 million in PUA overpayments to 11,445 claimants, or 13 percent of PUA claimants, during Fiscal Year 2020. Subsequent to fiscal year end, in October 2020, the Department determined it would not require the claimants to repay the funds due to confusion in the form requesting wage information from PUA claimants and therefore, removed this amount of overpayments from the PUA system. Because the payments resulted in an estimated $52.1 million in overpayments, we considered this amount to be questioned costs. We also identified the following problem during our testing: ? PUA FRAUDULENT PAYMENTS. We identified approximately $243,000 in PUA fraudulent payments that the Department determined were the result of identity theft. Through our review of the benefit payment population, we identified an invalid social security number that appeared 151times. When we discussed these with Department staff, they stated that once they identified the fraudulent payment due to identity theft, they assigned an invalid social security number to identify these payments for tracking purposes. Because these payments of $243,000 were identified as fraudulent, we considered this amount to be questioned costs. The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 16-20 Change 1 in April 2020 to address questions and provide further guidance about the PUA program. An overpayment must be established for any benefits that were overpaid. Both of these issues were addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021. Furthermore, the Department inappropriately suspended certain procedures during the COVID-19 pandemic. Specifically: ? SUSPENSION OF WAGE CROSSMATCH. The Department suspended the crossmatch process after March 31, 2020, for regular UI claims. Our testing of 60 overpayments noted that the Department identified 23 overpayments (38 percent) by performing the wage crossmatch prior to the suspension of the process. Section 20 CFR 603.23 specifies that the Department, as a state unemployment compensation agency, ?must crossmatch quarterly wage information with [Unemployment Compensation] payment information to the extent that such information is likely, as determined by the Secretary of Labor, to be productive in identifying ineligibility for benefits and preventing or discovering incorrect payments.? As part of the Department?s adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In addition, the Department reviews to identify potential issues with a claimant?s ability and availability to work and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. ? SUSPENSION OF TREASURY OFFSET PROGRAM. The Department did not use the TOP in June 2020. The Bipartisan Budget Act of 2013 requires states to use the TOP to recover covered unemployment compensation debts that remain uncollected one year after the debt was determined to be due. ? LACK OF PRISON MATCH PROCEDURES OVER PUA CLAIMS. The Department did not use the Appriss system to crossmatch PUA claims to prison records prior to June 30, 2020. Per discussion with Department staff, this crossmatch began in January 2021 and, at the time of our audit, the Department had not performed this match procedure for payments issued prior to January 2021. The Division of Unemployment Insurance?s Regulations Concerning Unemployment Security [7 CCR 1101-2, Section 2.8.3.6] states that a ?claimant who is incarcerated and unable to accept employment under a work-release program is not available for work.? As the claimant would not be available for work, the claimant would not be entitled to benefits. The Department has documented incarceration procedures to identify and handle issues when a claimant is identified as being incarcerated while receiving UI benefits. Appriss is a system that is used by the Department to perform this cross-check with prison records. In addition, the U.S. Department of Labor strongly recommends an incarceration crossmatch as one of the activities a state should use as part of its integrity functions. WHY DID THESE PROBLEMS OCCUR? The Department lacked a business plan and internal controls to handle the significant increase in UI claims as a result of the COVID-19 pandemic, which contributed to the issues we identified, as follows: ? LACK OF DISASTER PLAN. The Department did not have a plan in place to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. The Executive Order enacted in March 2020 directed the Department to expedite UI benefits claim processing and distribution of payments. Since the Department did not have a plan in place for addressing the significant increase in demand for benefits, it did not adjudicate all claims during the last 3 months of Fiscal Year 2020 during the start of the COVID-19 pandemic. This led to the backlog we noted. ? LACK OF REPORTING. The Department did not have reports available regarding key areas of the UI programs, including listings of unadjudicated claims and overpayments, including PUA, by claimant as of any point in time. We also found inconsistencies in the data provided for the claimants and benefits paid during the fiscal year. For example, the detail of overpayments established during Fiscal Year 2020 did not provide information to identify the claimant associated with the overpayment; therefore, we could not compare these overpayments to the claimants that received payments during March to June 2020. In addition, as previously noted, we received the benefits paid data for the period March to June 2020 in three different populations. The information provided from these different populations did not contain the same elements; therefore, we could not perform procedures across all three populations. ? FRAUDULENT PAYMENTS. Prior to June 2020, the Department did not have analytical procedures that used fraud indicators to assist with analyzing claims for the identification of potential fraudulent payments. The Department reported it began to experience an increase in suspected fraudulent payments in June 2020; at that point, the Department stated that it began developing data analytical tools to identify claims not yet paid for the presence of unique fraud indicators. Using these data analytical tools, around June 17, 2020, the Program Integrity Division established a process to place holds on claims relating to fraud (Program Integrity Hold). If a payment had fraud indicators identified, a Program Integrity Hold was established on the claim until the claimant information could be reviewed. As of June 30, 2020, there were eight fraud indicators in effect on COVID-19 pandemic claims. Per discussions with Department staff, the number of fraud indicators had increased to about 50 fraud indicators by February 2021. ? DISCONTINUED WAGE CROSSMATCHES AND USE OF TOP. The Department reported that it stopped performing crossmatches due to the delayed implementation of the new unemployment system that replaced CUBS. In addition, the Department reported that TOP was not used due to the Department not using another state agency that had been collecting those payments on behalf of the Department. ? ISSUES WITH NEW PUA SYSTEM. A fourth UI system, the PUA system, was implemented during April 2020 to handle these claims. This system was not integrated with Appriss to perform the crossmatch with prison records. WHY DO THESE PROBLEMS MATTER? Without the appropriate controls in place, the Department cannot ensure that only eligible claimants are receiving benefits in a timely manner. The significant backlog of adjudication issues did not permit us, nor was it practical to extend or apply other auditing procedures, to obtain sufficient, appropriate audit evidence to conclude whether the Department was in compliance with federal requirements for eligibility, allowable costs, and special provisions relating to overpayments. In addition, delayed adjudication can cause difficulties in obtaining evidence to make eligibility decisions and can result in potential improper payments. A significant backlog can also affect a claimant?s past, present, or future eligibility for benefits. Furthermore, suspending the quarterly wage crossmatch and not using TOP resulted in the Department not being in compliance with federal requirements relating to special tests and provisions for overpayments. The Department?s failure to ensure compliance with federal requirements for the UI program could result in disallowed costs and federal sanctions. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-066 The Department of Labor and Employment should improve its internal controls over the Unemployment Insurance (UI) program and ensure it complies with the related federal and state requirements by: A Developing a disaster plan to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. B Identifying the necessary reporting for the UI program and ensuring consistent reporting. C Continuing to use the data analytical tools to identify possible fraud that requires a Program Integrity Hold and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. D Resuming the quarterly wage crossmatch for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. E Resuming the Treasury Offset Program to recover allowable UI debt for all state and federal programs. F Performing crossmatch against prison records for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants. RESPONSE DEPARTMENT OF LABOR AND EMPLOYMENT A AGREE. IMPLEMENTATION DATE: JUNE 2023. The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable. Implementation Date: June 2023 B AGREE. IMPLEMENTATION DATE: JUNE 2023. The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments. Implementation Date: June 2023 C AGREE. IMPLEMENTATION DATE: JANUARY 2021. The Unemployment Insurance Division agrees. The creation of Pandemic Unemployment Assistance (PUA) for individuals traditionally not eligible for the receipt of regular state unemployment benefits created an opportunity for fraudulent claims filed as the result of identity theft. The Division recognized PUA claim filing data inconsistent with general economic conditions in June, 2020 related to claims being filed with stolen identities. The Division created automated fraud holds for claims filed within the PUA system exhibiting suspicious characteristics but did not have that same capability in the legacy system for regular unemployment claims. Data analytics were used to improve the fraud holds in the PUA system and were used to review claims activity in the legacy system where minimal identity theft activity was discovered and claims were manually shut down. In December 2020 increased suspicious activity began occurring in the state legacy system, resulting in a decision to implement MyUI+ on January 10, 2021 for all UI programs in order to apply the same fraud holds to all claims filed. Over 150,000 holds were placed on suspicious state UI claims that came from the legacy system immediately after the new system went live. As of this date, data analysis occurs multiple times per week and will continue in the future as this more sophisticated type of fraud is not expected to stop once the pandemic ends. Implementation Date: January 2021 D AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs. Implementation Date: December 2021 E AGREE. IMPLEMENTATION DATE: DECEMBER 2021. The Unemployment Insurance Division agrees and is currently on a corrective action plan with USDOL related to its failure to continue use of the federal Treasury Offset Program (TOP) program and has until December 2021 to resolve this failure. The Division ceased using TOP in 2018 when it severed a relationship with another state agency, which had been collecting those intercepts on behalf of the Division. That relationship ended due to ongoing concerns about record keeping by that state agency and whether such intercepts were properly collected in cases where claimants were making payments towards debt owed. The intent had been for the Division to implement TOP with the original implementation date for MyUI+ that was ultimately delayed. The Division is working towards implementation of this required program before the 2021 tax season begins and anticipates its integration into MyUI+ at that time. Implementation Date: December 2021 F AGREE. IMPLEMENTATION DATE: JANUARY 2021. The Unemployment Insurance Division understands and agrees that prison record crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The prison record crossmatch was continually run in the legacy system and all federal requirements were followed in for standard UI claims. This crossmatch did not initially occur in the PUA system due to the urgency to stand up the federal PUA program quickly at the beginning of the pandemic, a separate system was stood up outside the current legacy system and programming time was reduced by not including many interfaces and cross matches, including the prison cross match. However, once all UI programs were integrated with the implementation of MyUI+ into production on January 10, 2021, this crossmatch ran against all claims filed within that system, including claims initially filed in the original stand alone PUA system. As such, this crossmatch began in January, 2021 including all PUA claims that had been previously filed. All federal requirements associated with prison record crossmatch are currently being followed for all UI programs. Implementation Date: January 2021.
(A) The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable. (B) The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments. (D) The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs. (E) The Unemployment Insurance Division continues to work with both IRS and USDOL to reestablish TOP. The primary obstacle is IRS Publication 1075 does not allow for the recording and connection of FTI to any other information. TOP requires the notification of any intercepted funds and the amount intercepted connecting FTI and personal information to notify the claimant. Therefore, TOP cannot be implemented and comply with FTI safeguards per IRS Publication 1075. Both IRS and USDOL have not provided any guidance or solution to this obstacle. The Unemployment Insurance Division has reached out to other state workforce agencies in Louisiana and New Mexico to discuss possible solutions they are pursuing. At this time at the earliest we anticipate is December 2024.
2020-066
Finding 2021-065 Coronavirus Relief Funds?Property Owner Preservation Program The President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020, and Congress subsequently passed the CARES Act. The CARES Act provided emergency assistance in response to the COVID-19 pandemic and established the COVID-19 ? Coronavirus Relief Fund program (CRF), which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of CRF funds, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the CRF funds to numerous state departments and agencies. In June 2020, the State passed House Bill 20-1410, concerning assistance for individuals facing a housing-related hardship due to the COVID-19 pandemic, and transferred $19,650,000 of CRF funds to the Housing Development Grant Fund to provide such assistance. This bill includes a provision for the Property Owners Preservation Program (Program), which was managed by the Department, to allow landlords and property owners to seek rental assistance on behalf of their tenants who experienced a financial need on or after March 1, 2020, due to the first- or second-order effects of the COVID-19 pandemic. In Fiscal Year 2021, the Department expended all $19,650,000. State departments are responsible for reporting to the Office of the State Controller (OSC) the amount of CRF expenditures they passed through to subrecipients on their Exhibit K1, Schedule of Federal Assistance. The OSC uses the Exhibit K1s to aid them in preparing the State?s Schedule of Expenditures of Federal Awards (SEFA). The State reports expenditures for all federal programs on its SEFA, which is used to report all federal expenditures to the federal government. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal activities allowed and allowable cost requirements for CRF, specifically expended from the Housing Development Grant Fund for the Program, during Fiscal Year 2021. We tested a sample of 60 payments made by the Department to Program participants totaling $128,261 that were expended during Fiscal Year 2021 to determine whether the related payments were allowable under the CRF grant requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Under House Bill 20-1410, the Housing Development Grant Fund was appropriated for the purpose of providing individuals and households who, on or after March 1, 2020, experienced financial need due to the COVID-19 pandemic or second-order effects of the COVID-19 pandemic, with rental assistance. The House Bill also provided guidance on how to access additional housing services. The Department developed and issued a new application for the Program to address the criteria for experiencing direct or indirect impacts of the COVID-19 pandemic. ? Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, the Department must determine that costs were necessary and reasonable for the performance of the federal award and are adequately documented. Therefore, the Department must maintain appropriate supporting documentation to verify costs were properly charged to the federal grants. What problems did the audit work identify? We found that the Department could not provide appropriate underlying support for 4 of the 60 transactions (6.7 percent) we tested that were charged to CRF for the Program. Specifically, we found: ? 1 instance where the amount charged to the grant differed by $17 from the supporting documentation provided. The questioned cost for this issue totals $17. ? 2 instances where the tenant application did not include specific criteria noting the need was related to COVID-19. The questioned costs for this issue total $2,245. ? 1 instance where the Department could not provide any support for a portion of the selected transaction. Specifically, the selected expenditure was made up of six individual housing assistance payments to differing individuals, and the Department could not provide the underlying support for one of the six tenant applications comprising the expenditure selected for testing. The questioned cost for this issue totals $3,145. Why did these problems occur? During Fiscal Year 2021, the Department lacked sufficient internal controls over costs charged to newly-received federal funds, including funds through the Program. Specifically, the Department did not have policies or procedures in place or establish new policies and procedures for the maintenance and review of expenditures under the Program in accordance with federal regulations and the Program. Although the Department expended all of the CRF and Program monies in Fiscal Year 2021, this issue applies to all new federal funds the Department may receive. Why do these problems matter? The Department?s lack of sufficient internal controls over the maintenance of complete and accurate records for the federal CRF monies could result in inadequate documentation to support its payments and ultimately, disallowed federal costs and potential sanctions. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-065 The Department of Local Affairs (Department) should implement internal controls to ensure it complies with federal regulations for any new federal funds it receives, such as the Coronavirus Relief Fund. This should include developing and implementing policies and procedures that include a requirement that Department staff review and maintain records supporting the expenditures charged to the federal program. Response Department of Local Affairs Agree Implementation Date: June 2022 The Division of Housing within the Department of Local Affairs will implement internal controls to ensure compliance with federal regulations for new federal funds. This includes development of a standard procedure that will be implemented in June 2022 and includes the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
Show full finding ▾Hide full finding ▴Finding 2021-065 Coronavirus Relief Funds?Property Owner Preservation Program The President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020, and Congress subsequently passed the CARES Act. The CARES Act provided emergency assistance in response to the COVID-19 pandemic and established the COVID-19 ? Coronavirus Relief Fund program (CRF), which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of CRF funds, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the CRF funds to numerous state departments and agencies. In June 2020, the State passed House Bill 20-1410, concerning assistance for individuals facing a housing-related hardship due to the COVID-19 pandemic, and transferred $19,650,000 of CRF funds to the Housing Development Grant Fund to provide such assistance. This bill includes a provision for the Property Owners Preservation Program (Program), which was managed by the Department, to allow landlords and property owners to seek rental assistance on behalf of their tenants who experienced a financial need on or after March 1, 2020, due to the first- or second-order effects of the COVID-19 pandemic. In Fiscal Year 2021, the Department expended all $19,650,000. State departments are responsible for reporting to the Office of the State Controller (OSC) the amount of CRF expenditures they passed through to subrecipients on their Exhibit K1, Schedule of Federal Assistance. The OSC uses the Exhibit K1s to aid them in preparing the State?s Schedule of Expenditures of Federal Awards (SEFA). The State reports expenditures for all federal programs on its SEFA, which is used to report all federal expenditures to the federal government. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal activities allowed and allowable cost requirements for CRF, specifically expended from the Housing Development Grant Fund for the Program, during Fiscal Year 2021. We tested a sample of 60 payments made by the Department to Program participants totaling $128,261 that were expended during Fiscal Year 2021 to determine whether the related payments were allowable under the CRF grant requirements. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Under House Bill 20-1410, the Housing Development Grant Fund was appropriated for the purpose of providing individuals and households who, on or after March 1, 2020, experienced financial need due to the COVID-19 pandemic or second-order effects of the COVID-19 pandemic, with rental assistance. The House Bill also provided guidance on how to access additional housing services. The Department developed and issued a new application for the Program to address the criteria for experiencing direct or indirect impacts of the COVID-19 pandemic. ? Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, the Department must determine that costs were necessary and reasonable for the performance of the federal award and are adequately documented. Therefore, the Department must maintain appropriate supporting documentation to verify costs were properly charged to the federal grants. What problems did the audit work identify? We found that the Department could not provide appropriate underlying support for 4 of the 60 transactions (6.7 percent) we tested that were charged to CRF for the Program. Specifically, we found: ? 1 instance where the amount charged to the grant differed by $17 from the supporting documentation provided. The questioned cost for this issue totals $17. ? 2 instances where the tenant application did not include specific criteria noting the need was related to COVID-19. The questioned costs for this issue total $2,245. ? 1 instance where the Department could not provide any support for a portion of the selected transaction. Specifically, the selected expenditure was made up of six individual housing assistance payments to differing individuals, and the Department could not provide the underlying support for one of the six tenant applications comprising the expenditure selected for testing. The questioned cost for this issue totals $3,145. Why did these problems occur? During Fiscal Year 2021, the Department lacked sufficient internal controls over costs charged to newly-received federal funds, including funds through the Program. Specifically, the Department did not have policies or procedures in place or establish new policies and procedures for the maintenance and review of expenditures under the Program in accordance with federal regulations and the Program. Although the Department expended all of the CRF and Program monies in Fiscal Year 2021, this issue applies to all new federal funds the Department may receive. Why do these problems matter? The Department?s lack of sufficient internal controls over the maintenance of complete and accurate records for the federal CRF monies could result in inadequate documentation to support its payments and ultimately, disallowed federal costs and potential sanctions. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-065 The Department of Local Affairs (Department) should implement internal controls to ensure it complies with federal regulations for any new federal funds it receives, such as the Coronavirus Relief Fund. This should include developing and implementing policies and procedures that include a requirement that Department staff review and maintain records supporting the expenditures charged to the federal program. Response Department of Local Affairs Agree Implementation Date: June 2022 The Division of Housing within the Department of Local Affairs will implement internal controls to ensure compliance with federal regulations for new federal funds. This includes development of a standard procedure that will be implemented in June 2022 and includes the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
The Division of Housing within the Department of Local Affairs will implement internal controls to ensure compliance with federal regulations for new federal funds. This includes development of a standard procedure that will be implemented in June 2022 and includes the requirement that Department staff review and maintain records supporting the expenditures charged to new federal programs.
Finding 2021-066 Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs?Internal Controls over the Waiting List The Department annually receives advance payments from the federal government for the Housing Voucher Programs (Program) to provide tenant-based subsidies for rent paid by low-income households. A housing subsidy is paid to the landlord directly by the Department on behalf of the Program?s participants. During Fiscal Year 2021, the Department incurred approximately $62.9 million in federal costs for the Housing Voucher Programs. Federal regulation [24 CFR 982.54] requires the Department to have an administrative plan to establish policies for carrying out the Program in a manner consistent with the U.S. Department of Housing and Urban Development (HUD) requirements and local goals and objectives. HUD requires the Division of Housing (DOH), a section within the Department, to place all families that apply for assistance on a waiting list. DOH must select families from the waiting list and maintain clear records of all information required to verify that the family is selected from the waiting list according to HUD requirements and Department policies as stated in the Department?s administrative plan [24 CFR 982.204(b) and 982.207(e)]. The DOH maintains the waiting list in an electronic database within its Public Housing Agencies (PHA) Software, called Emphasys Elite. DOH has established preferences for order of selection off of the waiting list, and gives priority or first preference (point system) to serving families that meet various criteria, including someone experiencing homelessness, a person with a disability, households that include victims of domestic violence, etc. The second preference for selecting from the waiting list is based on when DOH placed the individual on the waiting list, by date and time. HUD may also award the Department funding for a specified category of families on the waiting list (targeted funding [24 CFR 982.204(e)]). DOH must use this funding only to assist families within the specified category allowed by the targeted funding. DOH administers the following types of targeted funding: Veterans Affairs Supporting Housing (VASH), Non-Elderly Disabled, Family Unification Program, and Family Self-Sufficiency. DOH delegates some of its voucher administration responsibilities, such as application reviews and interviews with applicants, to agencies that provide housing services to applicants and participants of the Program. These agencies, or contractors, include public housing authorities, community mental health centers, community centered boards or their contract service agencies, independent living centers, the Veterans Affairs Medical Center (VAMC), homeless service providers, and others. DOH will enter into a contract with these agencies that outline each party?s responsibilities. Contractors employ housing coordinators who assist applicants and participants to complete the necessary Program documentation and understand regulations to help them acquire and maintain units that conform to Program regulations. DOH provides each contractor with vouchers to give eligible applicants. When a contractor has available vouchers, it will ask the DOH to select and issue the next name(s) from its waiting list. DOH then uses its electronic database to select individuals from the waiting list. In order for an applicant to receive the voucher, the applicant must first attend an interview with the contractor. At the interview, the contractor will determine whether the applicant is eligible based on requiring the applicant to complete a full application and provide proof of income sources, social security number, citizenship status, release of information forms, federal or state-issued picture ID, and birth certificate, as well as the contractor?s verification of those items. If it is determined at the interview that the applicant is not eligible, the voucher will be terminated in the Emphasys Elite system and the voucher can be used for the next applicant in line on the waiting list. HUD regulations require that all families have an equal opportunity to apply for and receive housing assistance [24 CFR 982.53]. DOH must also have policies regarding various aspects of organizing and managing the waiting list of applicant families. This includes opening the list to new applicants, closing the list to new applicants, notifying the public of waiting list openings and closings, updating waiting list information, and removing families that are no longer interested in or eligible for assistance from the list. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements related to the Program?s waiting list during Fiscal Year 2021. We requested and obtained a report from the Department that showed all individuals that were added to the Program during Fiscal Year 2021. We selected and tested 40 of these individuals admitted to the Program during Fiscal Year 2021 to determine if they were selected from the waiting list in accordance with the Department?s applicant selection policies. We also requested and obtained another report from the Department that showed any individuals selected from the waiting list due to reaching the top position on the waiting list during Fiscal Year 2021, regardless of whether the individuals were added or not added to the Program. From this report, we selected and tested 40 different individuals to ascertain if they were admitted to the Program or provided the opportunity to be admitted to the Program in accordance with the Department?s applicant selection policies. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [24 CFR 5.410, 982.54(d), and 982.201 through 982.207] require the Department to have written policies in its administrative plan for selecting applicants from the waiting list and documentation must show that the Department follows these policies when selecting applicants for admission from the waiting list. Selection from the waiting list generally occurs when the Department notifies a family whose name reaches the top of the waiting list to come in to verify eligibility for admission to the Program. ? The Department?s administrative plan states that when a family wishes to receive assistance under the Program, the family must submit an application that provides DOH with the information needed to determine the family?s eligibility [HCV GB, pp. 4-11 ? 4-16, Notice PIH 2009-36]. ? Federal regulation [24 CFR 982.207] requires that DOH select applicant families from the waiting list first by preference and secondly by date and time of application. ? Federal regulations [24 CFR 982.554(a)] specify that when a family has been selected from the waiting list for an application interview, DOH and/or its contractor will notify the family and the family will be required to participate in the interview. The notice must inform the family of the date, time, and location of the scheduled application interview, who is required to attend the interview, and all documents that must be provided by the family at the interview. ? Federal regulations [24 CFR 982.201(f) and 982.204(c)] establish the rules for removing Program participants from the waiting list. If at any time an applicant family is on the waiting list and DOH determines that the family is not eligible for assistance, the family will be removed from the waiting list. Federal regulations further state the family may also remove itself from the waiting list at any time by requesting removal in writing. If a family is removed from the waiting list because DOH has determined the family is not eligible for assistance, a notice must be sent to the family?s address of record as well as to any alternate address provided on the initial application. The notice must state the reasons the family was removed from the waiting list and inform the family how to request an informal review regarding DOH?s decision. ? Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. What problems did the audit work identify? During our testing of 40 individuals admitted to the Program during Fiscal Year 2021, we found that the Department could not provide appropriate support for 5 of the 40 (12.5 percent) tenant files reviewed. Specifically: ? For five individuals, the Department could not provide documentation of the eligibility interview. ? For one of those five individuals, the Department also could not locate the individual?s application. During our testing of 40 individuals that the Department selected from the waiting list due to the individuals reaching the top of the waiting list during Fiscal Year 2021, we found certain issues with 8 of the 40 (20 percent) tenant files reviewed. Specifically: ? In five instances, individuals were selected from the waiting list out of turn; therefore, they were not at the top of the waiting list when selected, as required. ? In three instances, the Department could not provide the applications for the individuals. Why did these problems occur? The Department lacked internal controls over the Program?s waiting list. Specifically, the Department is not ensuring its contractors are maintaining supporting documentation within tenant files, including interview documentation and applications. Both the Department and its contractors experienced employee turnover in Fiscal Year 2021. Although the Department conducted monthly webinars for various training manuals, including the administrative plan, and made training materials available for future reference, new employees did not receive sufficient training to ensure the Department complied with Program requirements over the waiting list. In addition, the Department did not properly train the DOH employees on the policies and procedures for maintaining and selecting applicants from the waiting list, which ultimately led to applicants being incorrectly selected from the waiting list. Specifically, DOH did not properly update the waiting list for new applicants and addressing unused vouchers from prior selections, which caused individuals to be incorrectly selected from the waiting list. Why do these problems matter? By not maintaining the waiting list supporting documentation, including interview documentation and applications, the Department cannot ensure that all tenants are eligible or qualified to participate in the Program. The Department must ensure it maintains accurate and complete tenant files to demonstrate compliance with federal requirements. Additionally, by not training employees properly on the Department?s policies and procedures surrounding the waiting list, applicants are at risk of being improperly removed from the waiting list and not given the opportunity to receive funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-066 The Department of Local Affairs (Department) should strengthen its internal controls to ensure it complies with waiting list requirements for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include the Department developing and providing a training plan for its contractors that covers all of the programs? requirements on an ongoing basis. In addition, the Department should ensure its new employees are trained and able to properly run the waiting list in accordance with the Department?s policies and procedures, which includes ensuring the waiting list is properly updated for new applicants and addressing unused vouchers prior to making waiting list selections. Response Department of Local Affairs Agree Implementation Date: February 2023 The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
Show full finding ▾Hide full finding ▴Finding 2021-066 Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs?Internal Controls over the Waiting List The Department annually receives advance payments from the federal government for the Housing Voucher Programs (Program) to provide tenant-based subsidies for rent paid by low-income households. A housing subsidy is paid to the landlord directly by the Department on behalf of the Program?s participants. During Fiscal Year 2021, the Department incurred approximately $62.9 million in federal costs for the Housing Voucher Programs. Federal regulation [24 CFR 982.54] requires the Department to have an administrative plan to establish policies for carrying out the Program in a manner consistent with the U.S. Department of Housing and Urban Development (HUD) requirements and local goals and objectives. HUD requires the Division of Housing (DOH), a section within the Department, to place all families that apply for assistance on a waiting list. DOH must select families from the waiting list and maintain clear records of all information required to verify that the family is selected from the waiting list according to HUD requirements and Department policies as stated in the Department?s administrative plan [24 CFR 982.204(b) and 982.207(e)]. The DOH maintains the waiting list in an electronic database within its Public Housing Agencies (PHA) Software, called Emphasys Elite. DOH has established preferences for order of selection off of the waiting list, and gives priority or first preference (point system) to serving families that meet various criteria, including someone experiencing homelessness, a person with a disability, households that include victims of domestic violence, etc. The second preference for selecting from the waiting list is based on when DOH placed the individual on the waiting list, by date and time. HUD may also award the Department funding for a specified category of families on the waiting list (targeted funding [24 CFR 982.204(e)]). DOH must use this funding only to assist families within the specified category allowed by the targeted funding. DOH administers the following types of targeted funding: Veterans Affairs Supporting Housing (VASH), Non-Elderly Disabled, Family Unification Program, and Family Self-Sufficiency. DOH delegates some of its voucher administration responsibilities, such as application reviews and interviews with applicants, to agencies that provide housing services to applicants and participants of the Program. These agencies, or contractors, include public housing authorities, community mental health centers, community centered boards or their contract service agencies, independent living centers, the Veterans Affairs Medical Center (VAMC), homeless service providers, and others. DOH will enter into a contract with these agencies that outline each party?s responsibilities. Contractors employ housing coordinators who assist applicants and participants to complete the necessary Program documentation and understand regulations to help them acquire and maintain units that conform to Program regulations. DOH provides each contractor with vouchers to give eligible applicants. When a contractor has available vouchers, it will ask the DOH to select and issue the next name(s) from its waiting list. DOH then uses its electronic database to select individuals from the waiting list. In order for an applicant to receive the voucher, the applicant must first attend an interview with the contractor. At the interview, the contractor will determine whether the applicant is eligible based on requiring the applicant to complete a full application and provide proof of income sources, social security number, citizenship status, release of information forms, federal or state-issued picture ID, and birth certificate, as well as the contractor?s verification of those items. If it is determined at the interview that the applicant is not eligible, the voucher will be terminated in the Emphasys Elite system and the voucher can be used for the next applicant in line on the waiting list. HUD regulations require that all families have an equal opportunity to apply for and receive housing assistance [24 CFR 982.53]. DOH must also have policies regarding various aspects of organizing and managing the waiting list of applicant families. This includes opening the list to new applicants, closing the list to new applicants, notifying the public of waiting list openings and closings, updating waiting list information, and removing families that are no longer interested in or eligible for assistance from the list. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements related to the Program?s waiting list during Fiscal Year 2021. We requested and obtained a report from the Department that showed all individuals that were added to the Program during Fiscal Year 2021. We selected and tested 40 of these individuals admitted to the Program during Fiscal Year 2021 to determine if they were selected from the waiting list in accordance with the Department?s applicant selection policies. We also requested and obtained another report from the Department that showed any individuals selected from the waiting list due to reaching the top position on the waiting list during Fiscal Year 2021, regardless of whether the individuals were added or not added to the Program. From this report, we selected and tested 40 different individuals to ascertain if they were admitted to the Program or provided the opportunity to be admitted to the Program in accordance with the Department?s applicant selection policies. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulations [24 CFR 5.410, 982.54(d), and 982.201 through 982.207] require the Department to have written policies in its administrative plan for selecting applicants from the waiting list and documentation must show that the Department follows these policies when selecting applicants for admission from the waiting list. Selection from the waiting list generally occurs when the Department notifies a family whose name reaches the top of the waiting list to come in to verify eligibility for admission to the Program. ? The Department?s administrative plan states that when a family wishes to receive assistance under the Program, the family must submit an application that provides DOH with the information needed to determine the family?s eligibility [HCV GB, pp. 4-11 ? 4-16, Notice PIH 2009-36]. ? Federal regulation [24 CFR 982.207] requires that DOH select applicant families from the waiting list first by preference and secondly by date and time of application. ? Federal regulations [24 CFR 982.554(a)] specify that when a family has been selected from the waiting list for an application interview, DOH and/or its contractor will notify the family and the family will be required to participate in the interview. The notice must inform the family of the date, time, and location of the scheduled application interview, who is required to attend the interview, and all documents that must be provided by the family at the interview. ? Federal regulations [24 CFR 982.201(f) and 982.204(c)] establish the rules for removing Program participants from the waiting list. If at any time an applicant family is on the waiting list and DOH determines that the family is not eligible for assistance, the family will be removed from the waiting list. Federal regulations further state the family may also remove itself from the waiting list at any time by requesting removal in writing. If a family is removed from the waiting list because DOH has determined the family is not eligible for assistance, a notice must be sent to the family?s address of record as well as to any alternate address provided on the initial application. The notice must state the reasons the family was removed from the waiting list and inform the family how to request an informal review regarding DOH?s decision. ? Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office. Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system. What problems did the audit work identify? During our testing of 40 individuals admitted to the Program during Fiscal Year 2021, we found that the Department could not provide appropriate support for 5 of the 40 (12.5 percent) tenant files reviewed. Specifically: ? For five individuals, the Department could not provide documentation of the eligibility interview. ? For one of those five individuals, the Department also could not locate the individual?s application. During our testing of 40 individuals that the Department selected from the waiting list due to the individuals reaching the top of the waiting list during Fiscal Year 2021, we found certain issues with 8 of the 40 (20 percent) tenant files reviewed. Specifically: ? In five instances, individuals were selected from the waiting list out of turn; therefore, they were not at the top of the waiting list when selected, as required. ? In three instances, the Department could not provide the applications for the individuals. Why did these problems occur? The Department lacked internal controls over the Program?s waiting list. Specifically, the Department is not ensuring its contractors are maintaining supporting documentation within tenant files, including interview documentation and applications. Both the Department and its contractors experienced employee turnover in Fiscal Year 2021. Although the Department conducted monthly webinars for various training manuals, including the administrative plan, and made training materials available for future reference, new employees did not receive sufficient training to ensure the Department complied with Program requirements over the waiting list. In addition, the Department did not properly train the DOH employees on the policies and procedures for maintaining and selecting applicants from the waiting list, which ultimately led to applicants being incorrectly selected from the waiting list. Specifically, DOH did not properly update the waiting list for new applicants and addressing unused vouchers from prior selections, which caused individuals to be incorrectly selected from the waiting list. Why do these problems matter? By not maintaining the waiting list supporting documentation, including interview documentation and applications, the Department cannot ensure that all tenants are eligible or qualified to participate in the Program. The Department must ensure it maintains accurate and complete tenant files to demonstrate compliance with federal requirements. Additionally, by not training employees properly on the Department?s policies and procedures surrounding the waiting list, applicants are at risk of being improperly removed from the waiting list and not given the opportunity to receive funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-066 The Department of Local Affairs (Department) should strengthen its internal controls to ensure it complies with waiting list requirements for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include the Department developing and providing a training plan for its contractors that covers all of the programs? requirements on an ongoing basis. In addition, the Department should ensure its new employees are trained and able to properly run the waiting list in accordance with the Department?s policies and procedures, which includes ensuring the waiting list is properly updated for new applicants and addressing unused vouchers prior to making waiting list selections. Response Department of Local Affairs Agree Implementation Date: February 2023 The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
The Department of Local Affairs (Department) agrees with the recommendation. The Department will strengthen its internal controls through the development of an onboarding program that will include different modules that new employees and/or contractors must work through to receive certification. These modules will include all relevant steps associated with the waiting list process.
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Local Affairs (Department) in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS The Housing Voucher Programs provide tenant-based subsidies for rents paid by low-income households based upon their income. A housing subsidy, or housing assistance payment, is paid to the landlord directly by the Department on behalf of the participating family. The family pays the difference between the actual rent charged by the landlord and the amount subsidized by the program. The Department, as the designated Public Housing Agency for the State, contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the Uniform Guidance for federal reporting purposes, to run the Housing Voucher Programs. To ensure housing assistance payments are allowable under the federal Housing Voucher Programs? requirements, the Department is required to inspect or oversee inspection of units leased to a family at initial occupancy and at least annually thereafter to determine if the unit meets Housing Quality Standards (HQS). HQS are HUD?s minimum quality standards for tenant-based programs to ensure the units are safe and sanitary. Department staff who act as contract managers generate lists of upcoming inspections that are required to be completed, and provide this listing to subrecipients to identify units to be inspected. The Department?s subrecipients must complete the inspection and a unit inspection report prior to the deadline for each inspection. For any failed inspections, the Department must mail a notice of failure along with an abatement letter to the landlord and participant to inform them of the violations identified. This letter will indicate the items in fail status and specify the time frame in which items must be resolved. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, HQS requirements for the Housing Voucher Programs during Fiscal Year 2020. We performed testing related to 68 HQS inspections conducted by the Department?s 53 subrecipients during Fiscal Year 2020 to determine whether the Department complied with the related Housing Voucher Programs? requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our testwork against the following requirements: Federal regulations [24 CFR 982.158(d) and 982.404] state that for units that fail to meet HQS, the subrecipients must require the owner to correct any life-threatening HQS deficiencies within 24 hours after the inspections and all other HQS deficiencies within 30 calendar days or within a specified subrecipient-approved extension. Additionally, if the owner does not correct the cited HQS deficiencies within the specified correction period, the Department must stop, or abate, the housing assistance payments beginning no later than the first of the month following the specified correction period. If failed items are not resolved and the housing assistance payment is abated, the Department must send a notice of a Housing Assistance Payment Contract Termination Letter to the landlord and participant. If failed items are not resolved during the abatement period, the Department must terminate the housing assistance payment contract on the first of the following month. Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department did not take appropriate action related to three of the 68 (4 percent) HQS inspections we tested. Failed inspections resulted from items such as ceilings, walls, or window conditions not meeting safety standards, as well as electrical hazards requiring corrections. In two of these instances, the Department failed to enter the property into abatement by placing a temporary hold on the property?s housing assistance payments after issues identified through a failed inspection were not corrected. In the third instance, the Department did not properly terminate the housing assistance contract after 30 days, as required, so the property remained in abatement beyond that time period. WHY DID THIS PROBLEM OCCUR? The Department lacked sufficient controls over HQS enforcement to ensure requirements under the Housing Voucher Programs were met during Fiscal Year 2020. Specifically, the Department lacked policies and procedures for the HQS process and did not provide sufficient training on HQS processes to ensure its subrecipients were aware of and met Housing Voucher Programs? requirements. The Department reported that it had staff turnover during the fiscal year which resulted in a loss of institutional knowledge and further contributed to the problems identified. WHY DOES THIS PROBLEM MATTER? By failing to meet federal HQS requirements, the Department could be subject to disallowed costs and federal sanctions for the Housing Voucher Programs. Furthermore, the Department cannot ensure that property owners participating in the Housing Voucher Programs address inspection issues. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-070 The Department of Local Affairs (Department) should strengthen its internal controls over the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs to ensure it complies with Housing Quality Standards (HQS)-related requirements. This should include: A Having documented policies and procedures in place and implemented for both Department staff and subrecipients. B Developing and providing training to staff and subrecipients on the HQS enforcement process. RESPONSE DEPARTMENT OF LOCAL AFFAIRS A AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021. The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series. B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021. As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Local Affairs (Department) in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS The Housing Voucher Programs provide tenant-based subsidies for rents paid by low-income households based upon their income. A housing subsidy, or housing assistance payment, is paid to the landlord directly by the Department on behalf of the participating family. The family pays the difference between the actual rent charged by the landlord and the amount subsidized by the program. The Department, as the designated Public Housing Agency for the State, contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the Uniform Guidance for federal reporting purposes, to run the Housing Voucher Programs. To ensure housing assistance payments are allowable under the federal Housing Voucher Programs? requirements, the Department is required to inspect or oversee inspection of units leased to a family at initial occupancy and at least annually thereafter to determine if the unit meets Housing Quality Standards (HQS). HQS are HUD?s minimum quality standards for tenant-based programs to ensure the units are safe and sanitary. Department staff who act as contract managers generate lists of upcoming inspections that are required to be completed, and provide this listing to subrecipients to identify units to be inspected. The Department?s subrecipients must complete the inspection and a unit inspection report prior to the deadline for each inspection. For any failed inspections, the Department must mail a notice of failure along with an abatement letter to the landlord and participant to inform them of the violations identified. This letter will indicate the items in fail status and specify the time frame in which items must be resolved. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, HQS requirements for the Housing Voucher Programs during Fiscal Year 2020. We performed testing related to 68 HQS inspections conducted by the Department?s 53 subrecipients during Fiscal Year 2020 to determine whether the Department complied with the related Housing Voucher Programs? requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our testwork against the following requirements: Federal regulations [24 CFR 982.158(d) and 982.404] state that for units that fail to meet HQS, the subrecipients must require the owner to correct any life-threatening HQS deficiencies within 24 hours after the inspections and all other HQS deficiencies within 30 calendar days or within a specified subrecipient-approved extension. Additionally, if the owner does not correct the cited HQS deficiencies within the specified correction period, the Department must stop, or abate, the housing assistance payments beginning no later than the first of the month following the specified correction period. If failed items are not resolved and the housing assistance payment is abated, the Department must send a notice of a Housing Assistance Payment Contract Termination Letter to the landlord and participant. If failed items are not resolved during the abatement period, the Department must terminate the housing assistance payment contract on the first of the following month. Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department did not take appropriate action related to three of the 68 (4 percent) HQS inspections we tested. Failed inspections resulted from items such as ceilings, walls, or window conditions not meeting safety standards, as well as electrical hazards requiring corrections. In two of these instances, the Department failed to enter the property into abatement by placing a temporary hold on the property?s housing assistance payments after issues identified through a failed inspection were not corrected. In the third instance, the Department did not properly terminate the housing assistance contract after 30 days, as required, so the property remained in abatement beyond that time period. WHY DID THIS PROBLEM OCCUR? The Department lacked sufficient controls over HQS enforcement to ensure requirements under the Housing Voucher Programs were met during Fiscal Year 2020. Specifically, the Department lacked policies and procedures for the HQS process and did not provide sufficient training on HQS processes to ensure its subrecipients were aware of and met Housing Voucher Programs? requirements. The Department reported that it had staff turnover during the fiscal year which resulted in a loss of institutional knowledge and further contributed to the problems identified. WHY DOES THIS PROBLEM MATTER? By failing to meet federal HQS requirements, the Department could be subject to disallowed costs and federal sanctions for the Housing Voucher Programs. Furthermore, the Department cannot ensure that property owners participating in the Housing Voucher Programs address inspection issues. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-070 The Department of Local Affairs (Department) should strengthen its internal controls over the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs to ensure it complies with Housing Quality Standards (HQS)-related requirements. This should include: A Having documented policies and procedures in place and implemented for both Department staff and subrecipients. B Developing and providing training to staff and subrecipients on the HQS enforcement process. RESPONSE DEPARTMENT OF LOCAL AFFAIRS A AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021. The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series. B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021. As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
(A) The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series. (B) As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
2020-070
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORING The Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research. Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities. As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Our audit work was designed to measure the results of compliance with the following criteria: ? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations [2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: ? Reviewing financial and programmatic reports. ? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. ? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. ? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings. ? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows: ? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient. ? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC. WHY DID THESE PROBLEMS OCCUR? The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts. WHY DO THESE PROBLEMS MATTER? Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-075 The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by: A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures. B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment. RESPONSE DEPARTMENT OF TRANSPORTATION A AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. B AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by the Department is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORING The Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research. Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities. As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Our audit work was designed to measure the results of compliance with the following criteria: ? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations [2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include: ? Reviewing financial and programmatic reports. ? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award. ? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521. ? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings. ? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows: ? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient. ? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC. WHY DID THESE PROBLEMS OCCUR? The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts. WHY DO THESE PROBLEMS MATTER? Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-075 The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by: A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures. B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment. RESPONSE DEPARTMENT OF TRANSPORTATION A AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. B AGREE. IMPLEMENTATION DATE: JULY 2022. CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
(A) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance. (B) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
2020-075
The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to Treasury in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by Treasury is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MINERALS LEASING ACT?SUBRECIPIENT MONITORING AND REPORTING In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.? During Fiscal Year 2020, ONRR distributed approximately $62.6 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $21.8 million of the $24.6 million in Program funds it received through to local government subrecipients. DOLA retained the remaining $2.8 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program. We also evaluated whether Treasury?s Exhibit K1, Schedule of Federal Assistance, submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2020 was accurate. As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal requirements and the OSC?s instructions. Additionally, we reviewed Treasury?s progress in implementing our Fiscal Year 2018 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by communicating required federal award information and reporting requirements for the grant when passing funds through to other state agencies or non-state subrecipients, and by developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds communicate the required federal award information to their subrecipients. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provide specific information about the Program to the subrecipients, including, but not limited to, the following: ? Catalog of Federal Domestic Assistance (CFDA) number ? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies ? Contact information for Treasury ? Dollar amount made available ? Reporting requirements The State and any local governments receiving federal funds are required to present their Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. Per the OSC?s Fiscal Procedures Manual (Manual), all federal award amounts passed through to a subrecipient should be reported in the Expenditures-Passed Through to Subrecipient column of the Exhibit K1. This should include any funds passed through to another state agency, which that state agency then ultimately passed on to subrecipients outside of the State (e.g., at the local government level.) Federal awards that are only passed through from one state agency to another are to be reported in the Expenditures-Direct and Indirect column, rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be subrecipient expenditures. Because Treasury maintains the reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2020. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, required award information to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury provided some Program information to county subrecipients with its annual Payments In Lieu of Taxes (PILT) confirmation letters; however, the counties that received the PILT confirmation letters only represented about 62 of 338 (18 percent) of the Program subrecipients and the letters did not communicate all required federal award information. In addition, DOLA did not communicate any of the required award information with its Fiscal Year 2020 Program distributions to the remaining local government subrecipients. We also found that Treasury misclassified approximately $21.8 million in federal Program funds that it passed to DOLA, which DOLA subsequently passed to local governments as direct expenditures rather than subrecipient expenditures for the Program on its Fiscal Year 2020 Exhibit K1. As a result, the direct expenditures for the Program were overstated on the exhibit by approximately $21.8 million and the Program?s subrecipient expenditures were understated by $21.8 million. If not corrected, this misclassification would have caused the State?s direct expenditures and subrecipient expenditures for the Program to be misstated on the State?s SEFA. WHY DID THESE PROBLEMS OCCUR? Treasury did not have adequate internal controls in place during Fiscal Year 2020 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, Treasury staff did not effectively communicate with DOLA staff about responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information to all subrecipients of Program funds. Additionally, Treasury did not have adequate procedures in place to ensure its Exhibit K1 was prepared in accordance with federal requirements and the Manual. Treasury did not communicate with the pass-through agencies in order to properly determine whether Program funds ultimately flowed through to subrecipients, and should have been reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1. WHY DO THESE PROBLEMS MATTER? By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not receiving Single Audits, as required. By failing to properly report federal funds that were passed to subrecipients on its Exhibit K1, Treasury was out of compliance with the Manual. Furthermore, this type of error, if uncorrected, would cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-076 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by: A Developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Catalog of Federal Domestic Assistance number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount; as well as reporting requirements for the funds, including the requirement to report Program expenditures on the subrecipients? Schedule of Expenditures of Federal Awards. B Implementing procedures to ensure the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures. This should include developing and implementing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine whether those funds ultimately flow through to subrecipients and should therefore be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1. RESPONSE DEPARMENT OF THE TREASURY A AGREE. IMPLEMENTATION DATE: JUNE 2022. Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards. B AGREE. IMPLEMENTATION DATE: JUNE 2022. Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
Show full finding ▾Hide full finding ▴The following finding and recommendation relating to an internal control deficiency classified as a Material Weakness was communicated to Treasury in the previous year and has not been remediated as of June 30, 2021, because the original implementation date provided by Treasury is in a subsequent fiscal year. This complete finding and recommendation can be found in the original report and Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. MINERALS LEASING ACT?SUBRECIPIENT MONITORING AND REPORTING In 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals. For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.? During Fiscal Year 2020, ONRR distributed approximately $62.6 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $21.8 million of the $24.6 million in Program funds it received through to local government subrecipients. DOLA retained the remaining $2.8 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program. We also evaluated whether Treasury?s Exhibit K1, Schedule of Federal Assistance, submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2020 was accurate. As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal requirements and the OSC?s instructions. Additionally, we reviewed Treasury?s progress in implementing our Fiscal Year 2018 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by communicating required federal award information and reporting requirements for the grant when passing funds through to other state agencies or non-state subrecipients, and by developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds communicate the required federal award information to their subrecipients. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provide specific information about the Program to the subrecipients, including, but not limited to, the following: ? Catalog of Federal Domestic Assistance (CFDA) number ? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies ? Contact information for Treasury ? Dollar amount made available ? Reporting requirements The State and any local governments receiving federal funds are required to present their Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit. In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. Per the OSC?s Fiscal Procedures Manual (Manual), all federal award amounts passed through to a subrecipient should be reported in the Expenditures-Passed Through to Subrecipient column of the Exhibit K1. This should include any funds passed through to another state agency, which that state agency then ultimately passed on to subrecipients outside of the State (e.g., at the local government level.) Federal awards that are only passed through from one state agency to another are to be reported in the Expenditures-Direct and Indirect column, rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be subrecipient expenditures. Because Treasury maintains the reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2020. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, required award information to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury provided some Program information to county subrecipients with its annual Payments In Lieu of Taxes (PILT) confirmation letters; however, the counties that received the PILT confirmation letters only represented about 62 of 338 (18 percent) of the Program subrecipients and the letters did not communicate all required federal award information. In addition, DOLA did not communicate any of the required award information with its Fiscal Year 2020 Program distributions to the remaining local government subrecipients. We also found that Treasury misclassified approximately $21.8 million in federal Program funds that it passed to DOLA, which DOLA subsequently passed to local governments as direct expenditures rather than subrecipient expenditures for the Program on its Fiscal Year 2020 Exhibit K1. As a result, the direct expenditures for the Program were overstated on the exhibit by approximately $21.8 million and the Program?s subrecipient expenditures were understated by $21.8 million. If not corrected, this misclassification would have caused the State?s direct expenditures and subrecipient expenditures for the Program to be misstated on the State?s SEFA. WHY DID THESE PROBLEMS OCCUR? Treasury did not have adequate internal controls in place during Fiscal Year 2020 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, Treasury staff did not effectively communicate with DOLA staff about responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information to all subrecipients of Program funds. Additionally, Treasury did not have adequate procedures in place to ensure its Exhibit K1 was prepared in accordance with federal requirements and the Manual. Treasury did not communicate with the pass-through agencies in order to properly determine whether Program funds ultimately flowed through to subrecipients, and should have been reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1. WHY DO THESE PROBLEMS MATTER? By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not receiving Single Audits, as required. By failing to properly report federal funds that were passed to subrecipients on its Exhibit K1, Treasury was out of compliance with the Manual. Furthermore, this type of error, if uncorrected, would cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2020-076 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by: A Developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Catalog of Federal Domestic Assistance number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount; as well as reporting requirements for the funds, including the requirement to report Program expenditures on the subrecipients? Schedule of Expenditures of Federal Awards. B Implementing procedures to ensure the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures. This should include developing and implementing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine whether those funds ultimately flow through to subrecipients and should therefore be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1. RESPONSE DEPARMENT OF THE TREASURY A AGREE. IMPLEMENTATION DATE: JUNE 2022. Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards. B AGREE. IMPLEMENTATION DATE: JUNE 2022. Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
(A) Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards. (B) Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
2020-076
FAC accepted this audit on July 13, 2021 — management decision was due January 13, 2022.
SOC REPORTSThe Department has three systems referred to as the COMMIT Project, comprised of: (1) Pharmacy Benefit Management System (PBMS), which provides processing of pharmacy and drug rebates; (2) Colorado interChange, which processes provider enrollment and payments; and (3) the Business Intelligence and Data Management System (BIDM), which provides data analytics and reporting functions. These systems all have unique functions, and the Department uses them to administer and manage federal programs, such as Medicaid and CBHP.The Department contracts with several third-party service organizations for the processing of Medicaid data, claims, and the overall maintenance and operations of the systems. The following table outlines each service organization and the corresponding system it services:See table in Schedule of Findings and Questioned costsThe Department?s contractual agreements with these three service organizations require each to have an examination performed by an independent service auditor. Examinations of this type are governed by the American Institute of Certified Public Accountants (AICPA) and result in one of various types of System and Organization Controls (SOC) reports. For example, a SOC 1, Type II report provides the service auditors? opinion as to whether management has fairly presented its description of the service organization?s system and that internal controls over financial reporting have been suitably designed, and are operating effectively to achieve the related control objectives over a specified period of time. Service organizations will also state that there are certain internal controls that must be designed, in place, and operating effectively at the user entity, in this case at the Department, for the controls listed in the report that are supported by the service organization to be fully relied upon by the Department.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Complementary User Entity Controls (User Controls) identified by IBM Watson Health for BIDM were in place and operating effectively over the period of review. We obtained the most recent reports provided to the Department by IBM Watson Health, including three SOC 1 reports that covered the components that comprise BIDM. We reviewed the SOC reports and inquired of Department staff in order to understand their key IT user controls.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? BIDM Contract Amendment No. 7 Exhibit C requirements, sections 37.2-37.2.1, effective February 2019, states that the Contractor shall pay and arrange for a SOC 1, Type II audit annually, to be conducted by an independent auditor, covering work performed by the Contractor at the Contractor's facility and data center sites and provide the report to the Department.? BIDM Contract Exhibit A, Transmittals, Section 6.5 states that transmittals may not be used in place of an amendment, and may not, under any circumstances, be used to modify the terms of the contract.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified the following problems related to the Department?s oversight of its SOC reporting requirements:? The Department received and accepted a SOC 1, Type I report and did not ensure that a SOC 1, Type II audit was conducted over work performed by IBM Watson Health, its service organization for BIDM, at its facility and data center sites, as required by its contract with IBM Watson Health. A SOC 1, Type I report only provides the service auditors? opinion that internal controls over financial reporting have been suitably designed to achieve the related control objectives as of the specified date, not over a period of time, which is part of a SOC 1, Type II report.? The Department executed a contract change to the IBM Watson Health contract through a transmittal to accept the results of aSOC 1, Type I audit, instead of the required SOC 1, Type II.WHY DID THESE PROBLEMS OCCUR?These problems occurred because of the following:? The Department has not ensured that staff are trained related to contractually-specified SOC reporting requirements and the controls its service organizations have designed, implemented, and operate over relevant operational processes, as identified in the SOC 1, Type II reports. This will better inform the need for the SOC 1, Type II reports and how the Department?s service organizations? internal control systems impact the Department?s internal control system.? The Department continues to have problems with SOC 1, Type II reports. Specifically, between Fiscal Years 2017 and 2019, we identified problems with:? The legacy MMIS?In Fiscal Year 2017, the Department did not obtain an annual SOC 1, Type II report over MMIS, for the period of July 1, 2016, through February 28, 2017, as required by the contract. This recommendation was implemented in Fiscal Year 2019.? The Colorado interChange system?In Fiscal Year 2017, the Colorado interChange SOC 1, Type II report lacked coverage of database controls. In Fiscal Year 2019, the Department did not ensure that relevant IT general controls over financial reporting were identified and included for testing in the scope of its service organization?s SOC 1, Type II reports. These have yet to be fully implemented.? IBM Watson Health and the service auditor informed the Department that the service auditor would not be able to conduct a SOC 1, Type II audit. Therefore, the Department documented contract changes to accept a SOC 1, Type I audit, however, this was through a transmittal versus a contract amendment.WHY DO THESE PROBLEMS MATTER?By not holding service organizations accountable to contract requirements for performing respective SOC 1, Type II annual examinations, there is a risk that the respective service organizations? internal controls over financial reporting may not be implemented and operating effectively during the audit period, or over a specified period of time. Additionally, when contract requirements are not followed or amended as required, this may put the State in a position that is not legally enforceable with the contractor. Furthermore, if the Department does not ensure that responsible staff are properly trained, knowledgeable, and understand the purpose and scope of its service organizations? contracts and SOC reports, there is a risk that the Department may not be able to identify problems that could impact its internal controls over financial reporting and reporting to the federal government for the Medicaid and CBHP programs.CLASSIFICATION OF FINDING MATERIAL WEAKNESSTHIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-013The Department of Health Care Policy and Financing (Department) should strengthen internal controls over financial reporting by:A Ensuring that the service organization for the Business Intelligence and Data Management System (BIDM) complies with contract requirements to perform and provide an annual System and Organization Control (SOC) 1, Type II audit.B Developing, documenting, and implementing Department policies and procedures that outline the acceptable methods for making contract changes and when to use contract amendments or the transmittal process.C Ensuring that staff are properly trained on their responsibilities related to the SOC audit reporting requirements, and ensuring that they understand the controls their service organizations have designed, implemented, and operate over relevant operational processes and how they impact the Department?s own internal control system.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA PARTIALLY AGREE. IMPLEMENTATION DATE: SEPTEMBER 2020.The Department made a one-time decision to allow a SOC 1, Type I audit to be conducted for the Department's Data Warehouse for FY18-19 after numerous discussions with the contractor about extenuating circumstances. Under contract law, any party to a contract has the right to waive the failure of the other party to meet a requirement. This concept is enshrined in the contract in section 19.N, which specifies that a waiver of any failure to perform doesn't imply a waiver of any other failure.In this case, the contractor informed the Department that it would not be able to comply with the requirement to complete a Type II audit for one year. The Department had three options: 1) hold the contractor in breach and seek damages - based on the circumstances, termination of the contract was determined to be infeasible; 2) provide an unconditional waiver authorizing the failure to perform; or 3) provide a conditional waiver authorizing the failure if the contractor does something to mitigate it. Based on the circumstances, the Department chose to provide a conditional waiver of the contractor's failure to complete the Type II audit so long as the contractor instead completed a Type I audit to mitigate the failure within the recommended audit report delivery timeline provided by the OSA.The Department agrees a SOC 1, Type II audit is required by service organizations under their contract unless prevented by circumstances beyond the control of the Department and service organization.AUDITOR?S ADDENDUMThe Department?s contract requires that the service organization conduct and provide a SOC 1, Type II audit and report, on an annual basis. The Department did not ensure that this provision was executed.B DISAGREE. IMPLEMENTATION DATE: NOT APPLICABLE.The Department does not agree that this one-time decision to issue a transmittal rather than a contract change justifies this recommendation.Specifically related to BIDM and as of September 2018, IBM Watson Health completed the business transfer of Truven Health Analytics ? the Department?s original BIDM service organization - after acquiring it in 2016. In this transfer, IBM Watson inherited the contract requirements to pay and arrange for a SOC 1, Type II audit on an annual basis. Around this same time period of September 2018, Truven Health Analytic?s service auditor determined there was a conflict of interest with IBM Watson Health and would not be able to conduct the SOC 1, Type II audit for Fiscal Year 2019. IBM Watson contracted with another service auditor and planning for the audit began in the fourth quarter of Calendar Year 2018.The Department issued a transmittal to waive the contract requirement on a one-time basis, and this was the appropriate action to take in this instance. The Department agrees that it is a best practice to document guidelines for staff to use to determine whether contract changes should be communicated via a transmittal or a contract amendment, and will develop, implement, and communicate such guidelines.AUDITOR?S ADDENDUMExhibit A, Transmittals, Section 6.5 of the Department?s BIDM Contract, states that transmittals may not be used in place of an amendment, and may not, under any circumstances be used to modify the terms of the Contract.C PARTIALLY AGREE. IMPLEMENTATION DATE: IMPLEMENTED.The Department does not agree that the finding in this report justifies this recommendation.The Department does agree that properly trained staff is important and to strengthen its internal controls, the Department hired a Contract Manager to fill a vacancy. In addition to currently trained staff, a Security and Compliance Program Manager was also hired to ensure the Department has a qualified and experienced resource available to assist in data security and service organization audit needs across the Department. Both of these roles were hired prior to this recommendation being issued.However, the Department does not agree that the problems and recommendations identified by the OSA in this current audit occurred as a result of training insufficiency.AUDITOR?S ADDENDUMThe problems identified in this and prior year findings, as mentioned in this finding, point to a lack of trained Department staff in the area of contractually specified SOC reporting requirements.
Show full finding ▾Hide full finding ▴SOC REPORTSThe Department has three systems referred to as the COMMIT Project, comprised of: (1) Pharmacy Benefit Management System (PBMS), which provides processing of pharmacy and drug rebates; (2) Colorado interChange, which processes provider enrollment and payments; and (3) the Business Intelligence and Data Management System (BIDM), which provides data analytics and reporting functions. These systems all have unique functions, and the Department uses them to administer and manage federal programs, such as Medicaid and CBHP.The Department contracts with several third-party service organizations for the processing of Medicaid data, claims, and the overall maintenance and operations of the systems. The following table outlines each service organization and the corresponding system it services:See table in Schedule of Findings and Questioned costsThe Department?s contractual agreements with these three service organizations require each to have an examination performed by an independent service auditor. Examinations of this type are governed by the American Institute of Certified Public Accountants (AICPA) and result in one of various types of System and Organization Controls (SOC) reports. For example, a SOC 1, Type II report provides the service auditors? opinion as to whether management has fairly presented its description of the service organization?s system and that internal controls over financial reporting have been suitably designed, and are operating effectively to achieve the related control objectives over a specified period of time. Service organizations will also state that there are certain internal controls that must be designed, in place, and operating effectively at the user entity, in this case at the Department, for the controls listed in the report that are supported by the service organization to be fully relied upon by the Department.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Complementary User Entity Controls (User Controls) identified by IBM Watson Health for BIDM were in place and operating effectively over the period of review. We obtained the most recent reports provided to the Department by IBM Watson Health, including three SOC 1 reports that covered the components that comprise BIDM. We reviewed the SOC reports and inquired of Department staff in order to understand their key IT user controls.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? BIDM Contract Amendment No. 7 Exhibit C requirements, sections 37.2-37.2.1, effective February 2019, states that the Contractor shall pay and arrange for a SOC 1, Type II audit annually, to be conducted by an independent auditor, covering work performed by the Contractor at the Contractor's facility and data center sites and provide the report to the Department.? BIDM Contract Exhibit A, Transmittals, Section 6.5 states that transmittals may not be used in place of an amendment, and may not, under any circumstances, be used to modify the terms of the contract.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified the following problems related to the Department?s oversight of its SOC reporting requirements:? The Department received and accepted a SOC 1, Type I report and did not ensure that a SOC 1, Type II audit was conducted over work performed by IBM Watson Health, its service organization for BIDM, at its facility and data center sites, as required by its contract with IBM Watson Health. A SOC 1, Type I report only provides the service auditors? opinion that internal controls over financial reporting have been suitably designed to achieve the related control objectives as of the specified date, not over a period of time, which is part of a SOC 1, Type II report.? The Department executed a contract change to the IBM Watson Health contract through a transmittal to accept the results of aSOC 1, Type I audit, instead of the required SOC 1, Type II.WHY DID THESE PROBLEMS OCCUR?These problems occurred because of the following:? The Department has not ensured that staff are trained related to contractually-specified SOC reporting requirements and the controls its service organizations have designed, implemented, and operate over relevant operational processes, as identified in the SOC 1, Type II reports. This will better inform the need for the SOC 1, Type II reports and how the Department?s service organizations? internal control systems impact the Department?s internal control system.? The Department continues to have problems with SOC 1, Type II reports. Specifically, between Fiscal Years 2017 and 2019, we identified problems with:? The legacy MMIS?In Fiscal Year 2017, the Department did not obtain an annual SOC 1, Type II report over MMIS, for the period of July 1, 2016, through February 28, 2017, as required by the contract. This recommendation was implemented in Fiscal Year 2019.? The Colorado interChange system?In Fiscal Year 2017, the Colorado interChange SOC 1, Type II report lacked coverage of database controls. In Fiscal Year 2019, the Department did not ensure that relevant IT general controls over financial reporting were identified and included for testing in the scope of its service organization?s SOC 1, Type II reports. These have yet to be fully implemented.? IBM Watson Health and the service auditor informed the Department that the service auditor would not be able to conduct a SOC 1, Type II audit. Therefore, the Department documented contract changes to accept a SOC 1, Type I audit, however, this was through a transmittal versus a contract amendment.WHY DO THESE PROBLEMS MATTER?By not holding service organizations accountable to contract requirements for performing respective SOC 1, Type II annual examinations, there is a risk that the respective service organizations? internal controls over financial reporting may not be implemented and operating effectively during the audit period, or over a specified period of time. Additionally, when contract requirements are not followed or amended as required, this may put the State in a position that is not legally enforceable with the contractor. Furthermore, if the Department does not ensure that responsible staff are properly trained, knowledgeable, and understand the purpose and scope of its service organizations? contracts and SOC reports, there is a risk that the Department may not be able to identify problems that could impact its internal controls over financial reporting and reporting to the federal government for the Medicaid and CBHP programs.CLASSIFICATION OF FINDING MATERIAL WEAKNESSTHIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-013The Department of Health Care Policy and Financing (Department) should strengthen internal controls over financial reporting by:A Ensuring that the service organization for the Business Intelligence and Data Management System (BIDM) complies with contract requirements to perform and provide an annual System and Organization Control (SOC) 1, Type II audit.B Developing, documenting, and implementing Department policies and procedures that outline the acceptable methods for making contract changes and when to use contract amendments or the transmittal process.C Ensuring that staff are properly trained on their responsibilities related to the SOC audit reporting requirements, and ensuring that they understand the controls their service organizations have designed, implemented, and operate over relevant operational processes and how they impact the Department?s own internal control system.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA PARTIALLY AGREE. IMPLEMENTATION DATE: SEPTEMBER 2020.The Department made a one-time decision to allow a SOC 1, Type I audit to be conducted for the Department's Data Warehouse for FY18-19 after numerous discussions with the contractor about extenuating circumstances. Under contract law, any party to a contract has the right to waive the failure of the other party to meet a requirement. This concept is enshrined in the contract in section 19.N, which specifies that a waiver of any failure to perform doesn't imply a waiver of any other failure.In this case, the contractor informed the Department that it would not be able to comply with the requirement to complete a Type II audit for one year. The Department had three options: 1) hold the contractor in breach and seek damages - based on the circumstances, termination of the contract was determined to be infeasible; 2) provide an unconditional waiver authorizing the failure to perform; or 3) provide a conditional waiver authorizing the failure if the contractor does something to mitigate it. Based on the circumstances, the Department chose to provide a conditional waiver of the contractor's failure to complete the Type II audit so long as the contractor instead completed a Type I audit to mitigate the failure within the recommended audit report delivery timeline provided by the OSA.The Department agrees a SOC 1, Type II audit is required by service organizations under their contract unless prevented by circumstances beyond the control of the Department and service organization.AUDITOR?S ADDENDUMThe Department?s contract requires that the service organization conduct and provide a SOC 1, Type II audit and report, on an annual basis. The Department did not ensure that this provision was executed.B DISAGREE. IMPLEMENTATION DATE: NOT APPLICABLE.The Department does not agree that this one-time decision to issue a transmittal rather than a contract change justifies this recommendation.Specifically related to BIDM and as of September 2018, IBM Watson Health completed the business transfer of Truven Health Analytics ? the Department?s original BIDM service organization - after acquiring it in 2016. In this transfer, IBM Watson inherited the contract requirements to pay and arrange for a SOC 1, Type II audit on an annual basis. Around this same time period of September 2018, Truven Health Analytic?s service auditor determined there was a conflict of interest with IBM Watson Health and would not be able to conduct the SOC 1, Type II audit for Fiscal Year 2019. IBM Watson contracted with another service auditor and planning for the audit began in the fourth quarter of Calendar Year 2018.The Department issued a transmittal to waive the contract requirement on a one-time basis, and this was the appropriate action to take in this instance. The Department agrees that it is a best practice to document guidelines for staff to use to determine whether contract changes should be communicated via a transmittal or a contract amendment, and will develop, implement, and communicate such guidelines.AUDITOR?S ADDENDUMExhibit A, Transmittals, Section 6.5 of the Department?s BIDM Contract, states that transmittals may not be used in place of an amendment, and may not, under any circumstances be used to modify the terms of the Contract.C PARTIALLY AGREE. IMPLEMENTATION DATE: IMPLEMENTED.The Department does not agree that the finding in this report justifies this recommendation.The Department does agree that properly trained staff is important and to strengthen its internal controls, the Department hired a Contract Manager to fill a vacancy. In addition to currently trained staff, a Security and Compliance Program Manager was also hired to ensure the Department has a qualified and experienced resource available to assist in data security and service organization audit needs across the Department. Both of these roles were hired prior to this recommendation being issued.However, the Department does not agree that the problems and recommendations identified by the OSA in this current audit occurred as a result of training insufficiency.AUDITOR?S ADDENDUMThe problems identified in this and prior year findings, as mentioned in this finding, point to a lack of trained Department staff in the area of contractually specified SOC reporting requirements.
(A) This was completed in September 2020 when SOC 1 Type II report for FY20 was provided to OSA.(B) The Department does not agree that this one-time decision to issue a transmittal rather than a contract change justifies this recommendation.Specifically related to BIDM and as of September 2018, IBM Watson Health completed the business transfer of Truven Health Analytics ? the Department?s original BIDM service organization - after acquiring it in 2016. In this transfer, IBM Watson inherited the contract requirements to pay and arrange for a SOC 1, Type II audit on an annual basis. Around this same time period of September 2018, Truven Health Analytics service auditor determined there was a conflict of interest with IBM Watson Health and would not be able to conduct the SOC 1, Type II audit for Fiscal Year 2019. IBM Watson contracted with another service auditor and planning for the audit began in the fourth quarter of Calendar Year 2018.(C) The Department does not agree that the finding in this report justifies this recommendation.The Department does agree that properly trained staff is important and to strengthen its internal controls, the Department hired a Contract Manager to fill a vacancy. In addition to currently trained staff, a Security and Compliance Program Manager was also hired to ensure the Department has a qualified and experienced resource available to assist in data security and service organization audit needs across the Department. Both of these roles were hired prior to this recommendation being issued.However, the Department does not agree that the problems and recommendations identified by the OSA in this current audit occurred as a result of training insufficiency.The Department issued a transmittal to waive the contract requirement on a one-time basis, and this was the appropriate action to take in this instance. The Department agrees that it is a best practice to document guidelines for staff to use to determine whether contract changes should be communicated via a transmittal or a contract amendment, and will develop, implement, and communicate such guidelines.
INTERCHANGE SERVICE ORGANIZATION CONTROL REPORTSIn 2017, the Health First Colorado program implemented Colorado interChange to replace the legacy MMIS. The Health First Colorado program, which is partially funded through the federal Medicaid grant, provides public health insurance to eligible low-income citizens. The Health First Colorado program and the Colorado interChange system are the responsibility of the Department. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is DXC Technology Services, LLC (DXC).DXC hosts the Colorado interChange system for the Department and manages IT services related to the maintenance and support of the system infrastructure and software. The Department?s contractual agreement with DXC requires that it, as a service organization for the Department, have an annual SOC examination performed by an independent service auditor. Examinations of this type are governed by the AICPA and result in one of various types of SOC reports. For the Department, DXC provides a SOC 1, Type II report, which provides an independent auditors? opinion on whether the service organization?s internal controls over financial reporting, including those over the system, have been suitably designed and operated effectively over a specified period of time.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2019 Colorado interChange SOC Report recommendation, in which the original recommendations were made in Fiscal Year 2017. Specifically, we recommended that the Department should improve controls over its financial reporting by (a) working with its service organization to ensure the Colorado interChange SOC 1, Type II reports clearly state the system components and controls that are in scope, such as database change management and database backup and recovery controls; and (b) developing, documenting, implementing, and communicating a process for conducting reviews of the SOC 1, Type II reports to ensure that all appropriate database internal controls impacting financial reporting are identified by the service organization, tested for effectiveness, and opined upon by the service auditor in its SOC 1, Type II report.We performed our audit work through inquiry of Department staff, as well as inspection of supporting documentation.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?The OSC?s Manual Section 3.41, Statewide System and Organizational Controls Reviews, includes agency responsibilities related to the receipt of SOC reports. Specifically, agencies are required to annually review such reports and determine whether any actions are necessary to remediate issues noted.The OSC?s policy, Internal Control System, requires state agencies to use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Specifically, Green Book Paragraph OV4.08, Documentation Requirements, states that documentation is a necessary part of an effective internal control system and is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?During our Fiscal Year 2020 audit work, we found that the Department worked with DXC to ensure that the appropriate system components and controls, such as database change management and database backup and recovery controls, were clearly identified in the SOC 1, Type II report. However, the Department did not develop, document, implement, or communicate a process to review the SOC 1, Type II reports annually.WHY DID THIS PROBLEM OCCUR?Department staff stated that SOC reports are reviewed when the Department receives them, but an annual review process has not yet been formally documented or implemented. The Department stated that it plans to document and implement the process by July 2021.WHY DOES THIS PROBLEM MATTER?Without a formalized SOC 1, Type II review process in place, the Department may not be aware of issues identified in the report relating to the controls its service organizations have designed, implemented, and operate over contracted services as they relate to financial reporting and compliance with federal regulations.CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTHIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2019-052BRECOMMENDATION2020-014The Department of Health Care Policy and Financing should improve internal controls over financial reporting by developing, documenting, implementing, and communicating a process for conducting annual reviews of the Colorado interChange?s System and Organization Controls (SOC) 1, Type II reports to determine if any issues have been noted and whether actions are necessary to remediate these issues.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: JULY 2021.The Department is currently documenting all processes and reports. Implementation of a process for conducting reviews of the SOC 1,Type II reports will be completed by the July 2021 due date.
Show full finding ▾Hide full finding ▴INTERCHANGE SERVICE ORGANIZATION CONTROL REPORTSIn 2017, the Health First Colorado program implemented Colorado interChange to replace the legacy MMIS. The Health First Colorado program, which is partially funded through the federal Medicaid grant, provides public health insurance to eligible low-income citizens. The Health First Colorado program and the Colorado interChange system are the responsibility of the Department. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is DXC Technology Services, LLC (DXC).DXC hosts the Colorado interChange system for the Department and manages IT services related to the maintenance and support of the system infrastructure and software. The Department?s contractual agreement with DXC requires that it, as a service organization for the Department, have an annual SOC examination performed by an independent service auditor. Examinations of this type are governed by the AICPA and result in one of various types of SOC reports. For the Department, DXC provides a SOC 1, Type II report, which provides an independent auditors? opinion on whether the service organization?s internal controls over financial reporting, including those over the system, have been suitably designed and operated effectively over a specified period of time.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2019 Colorado interChange SOC Report recommendation, in which the original recommendations were made in Fiscal Year 2017. Specifically, we recommended that the Department should improve controls over its financial reporting by (a) working with its service organization to ensure the Colorado interChange SOC 1, Type II reports clearly state the system components and controls that are in scope, such as database change management and database backup and recovery controls; and (b) developing, documenting, implementing, and communicating a process for conducting reviews of the SOC 1, Type II reports to ensure that all appropriate database internal controls impacting financial reporting are identified by the service organization, tested for effectiveness, and opined upon by the service auditor in its SOC 1, Type II report.We performed our audit work through inquiry of Department staff, as well as inspection of supporting documentation.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?The OSC?s Manual Section 3.41, Statewide System and Organizational Controls Reviews, includes agency responsibilities related to the receipt of SOC reports. Specifically, agencies are required to annually review such reports and determine whether any actions are necessary to remediate issues noted.The OSC?s policy, Internal Control System, requires state agencies to use the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, as its framework for its system of internal control. Specifically, Green Book Paragraph OV4.08, Documentation Requirements, states that documentation is a necessary part of an effective internal control system and is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?During our Fiscal Year 2020 audit work, we found that the Department worked with DXC to ensure that the appropriate system components and controls, such as database change management and database backup and recovery controls, were clearly identified in the SOC 1, Type II report. However, the Department did not develop, document, implement, or communicate a process to review the SOC 1, Type II reports annually.WHY DID THIS PROBLEM OCCUR?Department staff stated that SOC reports are reviewed when the Department receives them, but an annual review process has not yet been formally documented or implemented. The Department stated that it plans to document and implement the process by July 2021.WHY DOES THIS PROBLEM MATTER?Without a formalized SOC 1, Type II review process in place, the Department may not be aware of issues identified in the report relating to the controls its service organizations have designed, implemented, and operate over contracted services as they relate to financial reporting and compliance with federal regulations.CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTHIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2019-052BRECOMMENDATION2020-014The Department of Health Care Policy and Financing should improve internal controls over financial reporting by developing, documenting, implementing, and communicating a process for conducting annual reviews of the Colorado interChange?s System and Organization Controls (SOC) 1, Type II reports to determine if any issues have been noted and whether actions are necessary to remediate these issues.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: JULY 2021.The Department is currently documenting all processes and reports. Implementation of a process for conducting reviews of the SOC 1,Type II reports will be completed by the July 2021 due date.
The Department is currently documenting all processes and reports. Implementation of a process for conducting reviews of the SOC 1, Type II reports will be completed by the July 2021 due date.
2019-052
MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONSIndividuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations.Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid.Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020.We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE.Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit.STATISTICAL SAMPLING METHODOLOGYWe selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period.Our methodology included the following procedures:We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary.We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period.We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG).For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period.After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period.See Schedule of Findings and Questioned Costs for chart/tableWHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASUREDFor 32 of the 125 Medicaid beneficiaries? case files that we tested(26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table.See Schedule of Findings and Questioned Costs for chart/tableA questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs.PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries.The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million.PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projectionsSee Schedule of Findings and Questioned Costs for chart/table.The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020.See Schedule of Findings and Questioned Costs for chart/tableDETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following:PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102.Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments.According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.?INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020.State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI.INCOME ISSUES. We identified the following income-related issues:INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281.INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280.INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs.INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines.Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income.MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150.Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months.BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs.State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits.INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs.State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.RESOURCES NOT VERIFIED. In one case, the caseworker did not verify resources for the beneficiary at the time of the eligibility determination as required by state regulations. Specifically, the beneficiary was approved for the Home and Community Based Services (HCBS) program, which requires resources to be verified as part of the annual eligibility determination. After we brought this issue to the Department?s attention, they provided bank statements which showed that the beneficiary?s resources were less than the resource limit for Fiscal Year 2020. Therefore, there are no questioned costs as a result of this error.State regulation [10 CCR 2505-10, 8.100.3.L.1] requires resources to be counted for the HCBS program. Furthermore, state regulation [10 CCR 2505-10, 8.100.5.B.1.e] requires all resources be verified for the month for which eligibility is being determined.RESOURCES MISCALCULATED. In three cases, resources used to determine eligibility were miscalculated for beneficiaries, as follows:In two cases, the caseworker incorrectly calculated bank account balances for determining the beneficiaries? resources. As a result, the incorrect resource amount was used for the beneficiaries? eligibility determinations. These errors did not impact eligibility because the correct resource amounts were less than the resource threshold and, therefore, these errors did not result in questioned costs.In the remaining case, the caseworker failed to count the cash surrender value of the beneficiary?s life insurance policy towards the beneficiary?s resources for the eligibility determination, in accordance with state regulations. The beneficiary?s correct amount of total resources was less than the resource limit and, therefore, this error did not result in questioned costs.State regulation [10 CCR 2505-10, 8.100.5.M.1] defines resources as cash or other assets or any real or personal property that an individual or spouse owns. State regulation [10 CCR 2505-10, 8.100.5.E.3] states that resources are available when the individual or individual?s spouse has any ownership interest in resources.State regulation [10 CCR 2505-10, 8.100.5.M.2(f)] requires the cash surrender value of all life insurance policies to be counted towards a beneficiary?s resources when the face value of those policies exceeds $1,500 on one person.INCORRECT RESOURCE THRESHOLD. In one case, the caseworker applied the incorrect Community Spouse Resource Allowance (CSRA) limit to determine eligibility at the beneficiary?s annual renewal. CSRA is the amount of resources allowed in accordance with state regulation that a community spouse can retain to allow the beneficiary to qualify for Medicaid eligibility. Resources for the beneficiary were less than the appropriate resource limit and, therefore, this error did not result in any questioned costs.State regulation [10 CCR 2505-10, 8.100.7.M] requires the caseworker to apply the CSRA for an institutionalized individual who is over the resource limit set by state regulation [10 CCR 2505-10, 8.100.5.M.1]. The transfer of the CSRA shall be completed as soon as possible but no later than the individual?s annual renewal.MISSING CASE DOCUMENTATION. Twelve case files were missing documentation necessary to support the Medicaid eligibility determination, including documentation to support income and resources, such as wage stubs and bank statements; and documentation to support citizenship, such as birth certificates or other allowable records; as required by federal and state regulations. No questioned costs were identified in these cases because there was other corroborating documentation in the case files that indicated the beneficiaries were eligible.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided.State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.State regulation [10 CCR 2505-10, 8.100.5.M.1] sets the resource limit for an individual at $2,000. Resources are defined as cash or other assets or any real or personal property that an individual or spouse owns.DATA ENTRY ERRORS. In 11 cases, the information in CBMS did not match the supporting documentation in the case file due to caseworker error. Specifically, the caseworker entered the incorrect income and/or resource amount in CBMS. No questioned costs were identified in these instances because they did not negatively affect the beneficiaries? eligibility.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.ELIGIBILITY MONITORING ISSUESDepartment procedures require local counties and MA sites to compile and submit the results of their own quality reviews of Medicaid eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action.See additional text of this finding in Schedule of Findings and Questioned Costs
Show full finding ▾Hide full finding ▴MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONSIndividuals and families seeking medical benefits through Medicaid must apply and provide certain information to caseworkers at their local county or an MA site, which collects required documentation for determining the applicants? eligibility. Such documentation includes the applicants? birth certificates, support for income, and the value of resources, such as wage stubs and bank account balances. Caseworkers enter the applicant-provided data into CBMS, which contains system checks for determining the applicants? eligibility to receive Medicaid benefits. These system checks include calculating and verifying income and resources for the applicants, as well as assessing and collecting fees for benefits, such as buy-in premiums. For example, CBMS will mark an applicant?s eligibility as fail if the reported income or resources exceed specific limits that are set by federal and state regulations. The Department is responsible for monitoring the local counties? and MA sites? administration of Medicaid to ensure eligibility is determined in accordance with federal and state regulations.Medicaid applicants may be eligible for retroactive eligibility, which allows new Medicaid applicants to receive coverage for up to 3 months prior to the date of one?s application. As long as the individual meets Medicaid?s eligibility requirements in the 3 months preceding their application, the Department will retroactively pay Medicaid covered expenses that individuals incurred during that timeframe. Without retroactive eligibility, benefits for Medicaid eligible individuals begin on the date the application was received by the local county or MA site. As an example, if an individual has medical expenses in March, applies for Medicaid in June, and the individual has met the eligibility requirements for 3 months preceding their application, then any unpaid Medicaid covered expenses for March, April, and May are paid by Medicaid.Eligibility data from CBMS feeds into the Colorado interChange system (Colorado interChange), which issues payments to Medicaid providers for the services they render to Medicaid beneficiaries. The Department pays Medicaid providers through two methods: (1) directly through fee-for-service (FFS) payments for specific services rendered or (2) indirectly through monthly fixed amounts known as capitation payments that are paid to managed care entities, who contract with providers for services. The monthly capitation payments are paid every month on behalf of beneficiaries regardless of whether the beneficiaries receive medical services during the month. Colorado interChange is programmed to pay the FFS and monthly capitation payments only on behalf of beneficiaries deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state rules and regulations.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process, as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2020.We performed testing on a statistical sample of 125 case files related to beneficiaries who (1) were deemed eligible for Medicaid during Fiscal Year 2020 and (2) had a payment made on their behalf to a Medicaid provider between July 1, 2019, and February 29, 2020. The purpose of our testing was to determine whether the beneficiaries were appropriately determined to be eligible for Medicaid during the time they received services within this period. This audit period was selected to accommodate changes that were made to federal Medicaid eligibility requirements in March 2020 due to the COVID-19 PHE.Our testing involved reviewing Medicaid case files, CBMS data fields, and supporting documentation related to eligibility determinations and redeterminations, as well as Medicaid payment information in Colorado interChange. For each beneficiary, we determined whether the Department ensured that local county and MA site caseworkers obtained and maintained required documents supporting eligibility determinations and redeterminations, and correctly entered eligibility data into CBMS. Additionally, for each sampled beneficiary, we determined whether CBMS showed the correct income and resources, the beneficiary was enrolled in the appropriate Medicaid program, buy-in premiums were assessed, and payments were not made after eligibility had ended during Fiscal Year 2020. We also inquired about the Department?s monitoring procedures over local counties and MA sites to ensure eligibility is determined in accordance with federal and state regulations.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to Medicaid eligibility. Based on the results of that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring the local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit.STATISTICAL SAMPLING METHODOLOGYWe selected a statistical sample of Medicaid beneficiaries for our review of their case files in a manner that?if we found errors?would allow us to estimate the total number of beneficiaries who were improperly deemed eligible, as well as the resulting dollar amount of Medicaid benefit payments that were improperly paid during the audit period of July 1, 2019, through February 29, 2020. We designed our sampling methodology and sample size to support statistical projections of our testing results to the population of all beneficiaries for whom payments were made during the audit period.Our methodology included the following procedures:We requested and received from the Department a listing of all Medicaid FFS and capitation payments with a date of service during the audit period. The data set included State identification numbers (ID), which are unique to each beneficiary.We summarized all Medicaid payments made during the audit period by ID and removed any IDs for which total payments and adjustments netted to $0, which can happen when the Department catches and fixes payments made in error. This resulted in a population of 1,386,220 unique IDs that had a total of $5,408,339,948 in payments made on their behalf during the audit period.We used a stratified random sample, as shown in the following table, consisting of six strata defined by the total amount of payments for each unique ID. We selected random samples from each strata for a total of 125 IDs that had benefit payments totaling $3,127,704. The strata and sample sizes were defined based on our risk assessment and consultations with audit sampling methodologists from the U.S. Department of Health and Human Services, Office of Inspector General (HHS OIG).For each sampled ID, we tested eligibility covering the dates of service for every payment made on the individual?s behalf within the audit period.After we concluded our testing, we used HHS OIG?s Office of Audit Services statistical software in consultation with HHS OIG to project our results to the full population of IDs for which benefits were paid during the audit period.See Schedule of Findings and Questioned Costs for chart/tableWHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASUREDFor 32 of the 125 Medicaid beneficiaries? case files that we tested(26 percent), we identified at least one error within each case file. In total, we identified 43 errors within the 32 case files. These errors resulted in a total of $25,120 in known questioned costs for July 1, 2019, through February 29, 2020, and $6,843 in likely questioned costs for March 1, 2020, through June 30, 2020, as shown in the following table.See Schedule of Findings and Questioned Costs for chart/tableA questioned cost, as defined in federal regulations [45 CFR 75.2 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for HHS Awards (Uniform Guidance)], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Furthermore, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as an auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE but were receiving benefits during this period. CMS guidance indicated that the Department should keep these beneficiaries enrolled during the COVID-19 PHE. Therefore, we are reporting any identified questioned costs from March 1, 2020, through June 30, 2020, the period during the COVID-19 PHE, as likely questioned costs.PROJECTED LIKELY QUESTIONED COSTS FOR JULY 2019 THROUGH FEBRUARY 2020. Based on our sample, we estimate the projected Medicaid questioned costs resulting from payments made on behalf of ineligible beneficiaries in the population between July 1, 2019, and February 29, 2020, to be about $165.6 million and, with 90 percent confidence, to be at least $41.1 million but not more than $290.0 million. This projection is based on the $25,120 in known questioned costs, or misstatements, we identified in our sample during the audit period. The American Institute of Certified Public Accountants Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and that the original sample was not representative.? In accordance with this guidance, we projected the known questioned costs to the population of payments for services that occurred from July 1, 2019, through February 29, 2020, regardless of the nature of the errors or the programs involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries.The projected questioned costs amount of $165.6 million is based on a statistical calculation that does not correlate to specific payments to providers or to over-expenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $41.1 million and $290.0 million and the amount would most likely be close to $165.6 million in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $41.1 million, and a 5 percent chance the true amount is over $290.0 million.PROJECTED LIKELY NUMBER OF INELIGIBLE BENEFICIARIES FOR JULY 2019 THROUGH FEBRUARY 2020. We also estimate that 169,026 beneficiaries, or with 90 percent confidence that at least 59,622 (4.30 percent) but not more than 278,429 (20.09 percent) beneficiaries, in our total population of 1,386,220 were likely ineligible at the time they received services from July 1, 2019, through February 29, 2020. The following table summarizes the results of our projectionsSee Schedule of Findings and Questioned Costs for chart/table.The following table summarizes the total known and likely questioned costs based on our case file testing and statistical sampling results for Fiscal Year 2020.See Schedule of Findings and Questioned Costs for chart/tableDETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following:PAYMENTS AFTER ELIGIBILITY HAS ENDED. In three cases, the Department paid for services after the beneficiary?s eligibility had ended. Specifically, in two cases, the beneficiaries continued to receive benefits after their death. In the remaining case, the Department determined the beneficiary was ineligible and ended the beneficiary?s benefits; however, payments continued to be made on behalf of the beneficiary after their eligibility had ended. These issues resulted in known questioned costs of $11,102.Federal regulation [42 CFR 433.304] states that an overpayment is the amount paid by a state agency to a provider in excess of the allowable amount for furnished services. Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death. Accordingly, payments for medical services claimed to have been provided after a Medicaid beneficiary?s death are overpayments.According to federal regulation [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.?INELIGIBLE FOR PROGRAM. In one case, the beneficiary was ineligible for the benefits received under Medicaid?s Social Security Income (SSI) mandatory program, which is a medical assistance program provided to persons eligible for financial assistance under SSI from the Social Security Administration (SSA). As a result of an eligibility redetermination, the caseworker determined that the beneficiary had not been eligible for the program since January 2019; however, the beneficiary received benefits under this program for the entire fiscal year. This issue resulted in known questioned costs of $8,326 and likely questioned costs of $4,132 for Fiscal Year 2020.State regulations [10 CCR 2505-10, 8.100.6.C.1a. and b.] state that Medicaid benefits must be provided to persons receiving financial assistance under SSI or persons who are eligible for financial assistance under SSI, but are not receiving SSI.INCOME ISSUES. We identified the following income-related issues:INCOME EXCEEDING THRESHOLD. In two cases, CBMS incorrectly calculated the beneficiaries? income. CBMS used income information reported by the beneficiary when it should have used electronic income information received through an interface with another system. If CBMS had correctly used the electronic income information, beneficiaries? income would have been over the limit set by federal regulation and the beneficiaries, therefore, should have been denied benefits at their redetermination. Instead, the beneficiaries were approved at their redeterminations and Colorado interChange paid claims on their behalf. These errors resulted in known questioned costs of $4,613 and likely questioned costs of $2,281.INCOME NOT VERIFIED. In one case, the caseworker did not verify income for the beneficiary. Specifically, the beneficiary reported income on the application, but the caseworker was unable to verify the income and deleted the income record from CBMS. This error resulted in known questioned costs of $779 and likely questioned costs of $280.INCORRECT INCOME THRESHOLD. In one case, CBMS used the incorrect income threshold for the beneficiary?s eligibility determination. The beneficiary?s income was less than the correct income threshold and, therefore, this error did not result in questioned costs.INCORRECT INCOME. In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker excluded income when it should have been included for determining eligibility. In the remaining case, the caseworker did not include expenses to calculate self-employment income and, as a result, the caseworker overstated income for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within federal and state income guidelines.Federal regulation [42 CFR 435.119] requires household income to be at or below 133 percent threshold of the federal poverty level and the State regulation [10 CCR 2505-10, 8.100.6.L.2.c] requires qualified beneficiary?s income to be at or below the federal property level.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.State regulation [10 CCR 2505-10, 8.100.5.B.1.c] requires the caseworker to verify earned income in determining whether an individual qualifies for medical assistance and requires the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.State regulation [10 CCR 2505-10, 8.100.3.K.8.a] requires business expenses to be deducted from countable self-employment income when calculating Medicaid applicants? self-employment income.MISSING REDETERMINATION. In one case, the Department did not complete the annual redetermination for the beneficiary as required by the federal regulation. Specifically, the beneficiary had Medicaid payments paid on their behalf during the entire Fiscal Year 2020; however, the beneficiary had not been redetermined since April 2018 due to the beneficiary showing as ineligible in CBMS. This issue resulted in known questioned costs of $300 and likely questioned costs of $150.Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months.BUY-IN PREMIUMS NOT ASSESSED. In one case, the Department did not assess buy-in monthly premiums for the beneficiary. Beneficiaries are required to pay buy-in premiums to receive benefits under the Buy-in Working Adults with Disabilities program. Therefore, the beneficiary was not eligible for the Program during November 2019 through February 2020. The beneficiary did not have any claims submitted by providers during this time and therefore, this issue did not result in questioned costs.State regulations [10 CCR 2505-10, 8.100.6.P.1.f] require individuals to pay monthly premiums on a sliding scale based on income for the Buy-in Working Adults with Disabilities program to be eligible to receive benefits.INAPPROPRIATE CHANGE TO ELIGIBILITY. In two cases, the Department did not determine eligibility in accordance with state regulation. Specifically, the beneficiaries provided information to the Department that changed their eligibility and the caseworkers applied the change retroactively; these beneficiaries were current Medicaid beneficiaries rather than new applicants and state regulations do not allow eligibility to be changed retroactively for current beneficiaries. These issues did not result in questioned costs.State regulation [10 CCR 2505-10, 8.100.3.E] requires that retroactive eligibility only be provided to new applicants for the prior 3 months preceding the date of application. State regulations do not allow for retroactive redeterminations to existing beneficiaries.RESOURCES NOT VERIFIED. In one case, the caseworker did not verify resources for the beneficiary at the time of the eligibility determination as required by state regulations. Specifically, the beneficiary was approved for the Home and Community Based Services (HCBS) program, which requires resources to be verified as part of the annual eligibility determination. After we brought this issue to the Department?s attention, they provided bank statements which showed that the beneficiary?s resources were less than the resource limit for Fiscal Year 2020. Therefore, there are no questioned costs as a result of this error.State regulation [10 CCR 2505-10, 8.100.3.L.1] requires resources to be counted for the HCBS program. Furthermore, state regulation [10 CCR 2505-10, 8.100.5.B.1.e] requires all resources be verified for the month for which eligibility is being determined.RESOURCES MISCALCULATED. In three cases, resources used to determine eligibility were miscalculated for beneficiaries, as follows:In two cases, the caseworker incorrectly calculated bank account balances for determining the beneficiaries? resources. As a result, the incorrect resource amount was used for the beneficiaries? eligibility determinations. These errors did not impact eligibility because the correct resource amounts were less than the resource threshold and, therefore, these errors did not result in questioned costs.In the remaining case, the caseworker failed to count the cash surrender value of the beneficiary?s life insurance policy towards the beneficiary?s resources for the eligibility determination, in accordance with state regulations. The beneficiary?s correct amount of total resources was less than the resource limit and, therefore, this error did not result in questioned costs.State regulation [10 CCR 2505-10, 8.100.5.M.1] defines resources as cash or other assets or any real or personal property that an individual or spouse owns. State regulation [10 CCR 2505-10, 8.100.5.E.3] states that resources are available when the individual or individual?s spouse has any ownership interest in resources.State regulation [10 CCR 2505-10, 8.100.5.M.2(f)] requires the cash surrender value of all life insurance policies to be counted towards a beneficiary?s resources when the face value of those policies exceeds $1,500 on one person.INCORRECT RESOURCE THRESHOLD. In one case, the caseworker applied the incorrect Community Spouse Resource Allowance (CSRA) limit to determine eligibility at the beneficiary?s annual renewal. CSRA is the amount of resources allowed in accordance with state regulation that a community spouse can retain to allow the beneficiary to qualify for Medicaid eligibility. Resources for the beneficiary were less than the appropriate resource limit and, therefore, this error did not result in any questioned costs.State regulation [10 CCR 2505-10, 8.100.7.M] requires the caseworker to apply the CSRA for an institutionalized individual who is over the resource limit set by state regulation [10 CCR 2505-10, 8.100.5.M.1]. The transfer of the CSRA shall be completed as soon as possible but no later than the individual?s annual renewal.MISSING CASE DOCUMENTATION. Twelve case files were missing documentation necessary to support the Medicaid eligibility determination, including documentation to support income and resources, such as wage stubs and bank statements; and documentation to support citizenship, such as birth certificates or other allowable records; as required by federal and state regulations. No questioned costs were identified in these cases because there was other corroborating documentation in the case files that indicated the beneficiaries were eligible.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.State regulation [10 CCR 2505-10, 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided.State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.State regulation [10 CCR 2505-10, 8.100.5.M.1] sets the resource limit for an individual at $2,000. Resources are defined as cash or other assets or any real or personal property that an individual or spouse owns.DATA ENTRY ERRORS. In 11 cases, the information in CBMS did not match the supporting documentation in the case file due to caseworker error. Specifically, the caseworker entered the incorrect income and/or resource amount in CBMS. No questioned costs were identified in these instances because they did not negatively affect the beneficiaries? eligibility.Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.ELIGIBILITY MONITORING ISSUESDepartment procedures require local counties and MA sites to compile and submit the results of their own quality reviews of Medicaid eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action.See additional text of this finding in Schedule of Findings and Questioned Costs
(A) Caseworker errors can be caused by an array of issues, including, training material retention; a lack of adequate funding to balance caseload inventory versus available work hours and staffing levels; a lack of quality review and performance reinforcement; and an assortment of local issues that lead to employee turnover. The Department will continue to work with eligibility sites regarding caseworker errors identified through this audit. The Department?s caseworker training resources, or Staff Development Center (SDC), is in the process of revamping all of their foundational training materials into a "Process-Based Training" model to be more effective and efficient based on training industry best practice. In addition, the SDC is converting all training materials into several different training modalities (instructor led courses, eLearning courses, desk aids, process manuals, infographics, workbooks, etc.) to be more engaging, effective, and accessible to adult learners with varying needs and preferences across large geographical areas. The revised training model is on track to be completed by July 31, 2021 and fully rolled out to all counties by the beginning of calendar year 2022.(B) The Department began the implementation of a new monitoring process called the Eligibility Site Oversight and Accountability Program in February 2021. This program includes strengthening performance measures, developing mechanisms for collecting performance data, developing eligibility site specific performance dashboards, and developing corrective action plans. The first iteration of performance measures and dashboards began in March of 2021 and will continue through August 2021. Mechanisms used for oversight and accountability data gathering include administrative and eligibility process reviews called Management Evaluations and Eligibility State-level Quality Assurance reviews. Management Evaluations began in January 2021 and Eligibility State-level Quality Assurance reviews began in February 2021. All processes under the Eligibility Site Oversight and Accountability Program will be implemented through administrative rules, which will include implementation of Improvement and Corrective Action Plans to eligibility sites that are out of compliance with performance measures or have identified gaps in compliance. All mechanisms for data collection have been implemented and internal root cause analysis processes will be implemented in August 2021.In addition, the Department has taken steps to ensure that we have ongoing systemic and dashboard monitoring for Medicaid and CHP+ programs that captures eligibility errors, eligibility system performance, and eligibility results. The state implemented the first phase of the monitoring dashboard in June 2020 with the second phase to be implemented by July 2022.(C) The Department has thoroughly researched the issues identified in this audit and has made changes to CBMS to ensure that it is using the correct income information, income thresholds in determining eligibility, and buy-in premiums are assessed. These issues were fixed May 2019, February 2020, and March 2020, and in June 2021 the income information system issue will be corrected.The Department disagrees with the auditor?s questioned costs and projection of those questions costs. The Department disagrees with the auditor?s sampling, stratification, and costs used to generate the projected questioned costs. The costs incorrectly include members who remain eligible once the identified error had been resolved, payments that will be recovered by the Department through an existing process to recover capitation payments from deceased members, a Social Security Administration (SSA) interface error outside the control of the Department, and costs related to an already identified issue regarding reconciling eligibility between CBMS and Colorado interChange. Some of these costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department and should have been excluded from the questioned costs and the resulting projections. The Department will resume the reconciliation process between CBMS and Colorado interChange when authorized by CMS. Regarding the SSA interfaces, SSA posted results that are valid conditions for Medicaid eligibility, so those costs should have been excluded from the resulting projections. The Department agrees to bring interface issues to the attention of SSA.
2019-042, 2019-043, 2019-053
MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIESAs a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death.Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations.CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death.In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020.During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered.Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider.According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows:MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death.We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds.MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP.We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds.The following table summarizes the issues we identified.See table in Schedule of Findings and Questioned Costs1 Total number of Medicaid FFS beneficiaries does not include the four beneficiaries who were cleared through our Medicaid FFS payments testing.2 Total number of beneficiaries within each type of payment does not match the total number of beneficiaries because some beneficiaries had FFS payments as well as capitation payments.WHY DID THESE PROBLEMS OCCUR?Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows:LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death.SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified:According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death.The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments.WHY DO THESE PROBLEMS MATTER?Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018*XIX-MAP2019*XIX-MAP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.778*, MEDICAL ASSISTANCE PROGRAM; 93.767*, CHILDREN?S HEALTH INSURANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $185,265KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-035The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by:A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations.B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries.C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.B AGREE. IMPLEMENTATION DATE: JULY 2022.The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.AUDITOR?S ADDENDUMAs noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines.AUDITOR?S ADDENDUMAs noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
Show full finding ▾Hide full finding ▴MEDICAL ASSISTANCE PAYMENTS FOR DECEASED BENEFICIARIESAs a safeguard against potential errors and fraud, state and local agencies need to be vigilant in preventing payments for medical services on behalf of ineligible individuals, such as those who are deceased. In general, the Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under Medicaid and CBHP. Local counties and MA sites caseworkers enter the required data for eligibility determination into CBMS, which either approves or denies eligibility for MA benefits. In addition, CBMS has various system interfaces to confirm and update the eligibility information in CBMS, including the date of death.Eligibility data in CBMS feeds daily into Colorado interChange and the Department pays providers through two methods: (1) FFS payments to medical service providers for specific services, including pharmacy prescriptions, and (2) capitation payments. The monthly capitation payments are paid at the beginning of each month regardless of whether the providers serve beneficiaries during the month or not. FFS payments are only made for Medicaid beneficiaries while capitation payments are made for both Medicaid and CBHP beneficiaries. Colorado interChange is programmed to pay FFS and monthly capitation payments only on behalf of beneficiaries that are deemed eligible based on eligibility information received from CBMS and requirements specified in federal and state regulations.CBMS receives beneficiary death information through various sources, including updates from beneficiaries? family members, daily interfaces with the SSA, and a monthly interface with the Colorado Electronic Death Registration System maintained by the Colorado Department of Public Health and Environment (CDPHE). If death information received in CBMS has not been verified, the Department will confirm the death information by sending notification letters to the deceased beneficiary. Once the death information is verified, CBMS is programmed to terminate the beneficiary?s eligibility as of the date of death. On a daily basis, CBMS then sends updated beneficiary eligibility and date of death information to Colorado interChange, which is programmed to run a daily automated process to stop payments, check for payments, and recover all FFS and capitation payments made after the beneficiary?s verified date of death.In the majority of cases, there is a delay between when the beneficiary dies and when the Department receives death information, verifies the date of death, and terminates benefits; which means that claims may be paid on behalf of deceased beneficiaries for a period of time. Per federal regulations, the Department is required to recover any payments made on behalf of these beneficiaries after their date of death. Once the Department receives verified death information, overpayments are recovered through an automated process in Colorado interChange.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP payments related to beneficiaries who die while receiving benefits, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020.During our audit, we received a listing of all Coloradans who died during Fiscal Year 2020, including dates of death, from CDPHE staff. We also obtained a listing from the Department of all Medicaid and CBHP payments made to providers during Fiscal Year 2020. We compared the two listings using Social Security Numbers (SSN) and identified 1,059 Medicaid and CBHP IDs that had Medicaid payments totaling $429,951 made on their behalf and $194 in CBHP payments made on their behalf. In addition, we reviewed the Department?s processes, policies, and procedures for identifying, stopping, and recovering payments for deceased beneficiaries.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 431 Subpart Q, Requirements for Estimating Improper Payments in Medicaid and CHIP] states that any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount. Also, Section 25.5-4-301(2), C.R.S., requirements for Medicaid and CBHP, states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?? Additionally, Section 25.5-4-301(2)(a)(II), C.R.S., states, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?.? Because medically necessary services cannot be provided after a beneficiary?s death, no medical services are allowable after a beneficiary?s death and, accordingly, payments for medical services claimed to have been provided after a beneficiary?s death are overpayments and should be recovered.Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.C. 1396b] requirements for Medicaid and CBHP, states have up to 1 year from the date of discovery of any overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to CMS, regardless of whether or not recovery is made from the provider.According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. Green Book, Paragraph 16.01, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation?.? Additionally, federal regulation [45 CFR 75.516] defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department made Medicaid and CBHP payments to providers for medical services claimed to have been rendered to Medicaid and CBHP beneficiaries after the months in which beneficiaries died. Specifically, the Department made payments on behalf of 1,059 beneficiaries after their date of death provided by CDPHE, resulting in overpayments of $185,265, of which $96,952 were paid with federal grant funds, as follows:MEDICAID FFS PAYMENTS. We identified 277 Medicaid beneficiaries whose SSN matched a death record from CDPHE and who had Medicaid FFS payments totaling $207,667 paid on their behalf to providers after their date of death.We reviewed payments for 21 of the 277 Medicaid beneficiaries and confirmed with the Department that 17 of the 21 beneficiaries (81 percent) were deceased and had payments made on their behalf after their date of death during Fiscal Year 2020. We also found that the Department had not recovered these improper FFS payments to ineligible beneficiaries as of the end of Fiscal Year 2020 and, therefore, these errors resulted in known questioned costs of $17,041, of which $8,654 was paid with federal grant funds. For the remaining four Medicaid beneficiaries, the Department researched and provided evidence that the beneficiaries were not deceased. Therefore, these four beneficiaries did not result in questioned costs. The remaining 256 beneficiaries whose SSN matched a death record from CDPHE and need to be researched and verified resulted in likely questioned costs of $77,840, of which $41,422 was paid with federal grant funds.MEDICAID AND CBHP CAPITATION PAYMENTS. We identified 846 Medicaid and CBHP beneficiaries whose SSN matched a death record from CDPHE and who had capitation payments paid on their behalf to providers after their date of death that had not been recovered as of the end of Fiscal Year 2020, totaling $222,630 for Medicaid and $194 for CBHP.We informed the Department of the issues we identified and provided them with the list of 846 beneficiaries. Department staff performed additional follow-up and confirmed that Colorado interChange had received verified death records for 747 of the 846 beneficiaries and a total of $170,747 in provider payments had been made on the beneficiaries? behalf after their dates of death during Fiscal Year 2020. These payments resulted in known questioned costs of $168,224, of which $88,150 was paid with Medicaid federal grant funds and $148 was paid with CBHP federal grant funds. For 12 out of the 747 beneficiaries, the date of death reported in Colorado interChange differed from the date of death provided by CDPHE. Part of the payments to these beneficiaries resulted in likely questioned costs of $2,524, of which $1,401 was paid with Medicaid federal grant funds. For the remaining 99 of the 846 beneficiaries, the Department reported that Colorado interChange did not have death information for these beneficiaries and had not researched these further. As a result, Medicaid payments for these 99 beneficiaries are reported as likely questioned costs of $52,076, of which $28,508 was paid with federal grant funds.The following table summarizes the issues we identified.See table in Schedule of Findings and Questioned Costs1 Total number of Medicaid FFS beneficiaries does not include the four beneficiaries who were cleared through our Medicaid FFS payments testing.2 Total number of beneficiaries within each type of payment does not match the total number of beneficiaries because some beneficiaries had FFS payments as well as capitation payments.WHY DID THESE PROBLEMS OCCUR?Overall, the Department lacked sufficient internal controls to ensure that medical assistance payments were not paid to deceased individuals during Fiscal Year 2020, as follows:LACK OF WRITTEN POLICIES AND PROCEDURES. The Department does not have written policies and procedures to monitor payments to deceased beneficiaries, to recover overpayments, and to ensure compliance with federal and state regulations related to medical assistance payments after a beneficiary?s date of death.SYSTEM ISSUES. We identified the following Colorado interChange system issues that caused the errors we identified:According to the Department, when Colorado interChange was implemented in 2017, it was programmed to only recover capitation payments in the current month and previous 2 months for Medicaid beneficiaries, and in the current month and previous 5 months for CBHP beneficiaries, after death information is received. As a result, for instances in which the Department received and verified beneficiaries? death information more than 3 months after the date of death for Medicaid and more than 6 months after the date of death for CBHP, the Department was not automatically recovering all improper capitation payments in accordance with federal and state regulations. According to the Department, in November 2020, the Department updated Colorado interChange to correct this system issue to recover all capitation payments after a beneficiary?s date of death.The Department lacks an effective internal control process for detecting when Colorado interChange is not recovering payments made on behalf of deceased beneficiaries. Specifically, we identified issues related to Medicaid FFS payments and followed up with the Department. Upon further review, the Department discovered a system defect that occurred from October 23, 2019, through April 23, 2020, which prevented Colorado interChange from carrying out the daily automated check and recovery process for FFS payments made on behalf of deceased beneficiaries. Due to this system defect, Colorado interChange did not recover any payments for deceased beneficiaries during this time. Although the system defect was fixed in April 2020, the Department was not aware of the issue and that payments were not being recovered for deceased beneficiaries until the Department researched the beneficiaries identified through the audit. According to the Department staff, as of May 2021, the Department was still researching the deceased beneficiaries impacted by the system defect and recovering payments.WHY DO THESE PROBLEMS MATTER?Without strong internal controls over Medicaid and CBHP eligibility, the Department increases the risk of improper payments due to fraud or error. Furthermore, making payments on behalf of ineligible individuals, including individuals who are deceased, can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018*XIX-MAP2019*XIX-MAP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.778*, MEDICAL ASSISTANCE PROGRAM; 93.767*, CHILDREN?S HEALTH INSURANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $185,265KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-035The Department of Health Care Policy and Financing should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) payments for deceased beneficiaries by:A Establishing and implementing written policies and procedures to monitor payments to deceased beneficiaries, recover any overpayments, and to ensure compliance with state and federal regulations.B Researching and resolving the Colorado interChange system (Colorado interChange) issues to ensure that all Medicaid and CBHP payments are stopped and recovered after a beneficiary?s date of death and developing a process to detect when Colorado interChange is not recovering payments on behalf of deceased beneficiaries.C Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with state requirements.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.B AGREE. IMPLEMENTATION DATE: JULY 2022.The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.AUDITOR?S ADDENDUMAs noted in the finding, the Colorado interChange system defect did not recover payments from October 23, 2019, through April 23, 2020. However, the Department was not aware of the system defect until it researched the beneficiaries identified through the audit. According to Department staff, as of May 2021, the Department was still researching the beneficiaries that were impacted by the system defect and recovering payments.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines.AUDITOR?S ADDENDUMAs noted in the finding, all known questioned were for deceased beneficiaries that were verified by the Department. All likely questioned costs were for beneficiaries that had yet to be researched and verified by the Department. According to Department staff, as of May 2021, the Department was still researching and recovering payments made on behalf of deceased beneficiaries.
(A) The Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.(B) The system issues described in this audit were resolved as of April 2020 for fee-for-service claims and November 2020 for capitation payments. Once a beneficiary's date-of-death is verified, payments that were made after to the date-of-death will be recovered through the Department's existing processes. As noted in the Department?s response to Recommendation (A), the Department will create written procedures documenting system and monitoring processes used to prevent claims from paying after a beneficiary?s date-of-death is verified. In addition, the procedures will document the processes used to recover payments made between a beneficiary?s verified date-of-death and the date the Colorado interChange system is updated with the date-of-death.(C) The Department will recover any overpayments made to providers on behalf of deceased beneficiaries once a beneficiary's date-of-death is verified based on our current processes and existing system functionality. The Department does not agree to the questioned costs identified by the auditors. When performing a review of the auditor?s data, several beneficiaries were found not to be deceased by the Department. The records provided by the auditors, like all records received from Colorado Department of Public Health and Environment (CDPHE) and the Social Security Administration (SSA), will go through the Department?s existing verification process. The Department performs the required research and outreach to beneficiaries to verify the date-of-death prior to updating the information in the Colorado interChange. In addition, the Department is not required to recover payments by the end of the state fiscal year, and reports any payments recovered to the Centers for Medicare and Medicaid Service (CMS) based on federal requirements. The Department?s source of beneficiary data, the verification processes, and recovery processes have already been established to satisfy this recommendation within federal guidelines.
CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTSThe Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income.Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020.We performed the following testwork:REVIEW OF CBHP ELIGIBILITY CASE FILESWe reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program.DATA ANALYSES OF CBHP BENEFICIARIESINELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits.CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits.CBHP ELIGIBILITY MONITORING AND REVIEWWe also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section.ELIGIBILITY CASE FILE ISSUESIn 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP.The following table outlines the types of issues we found.CBHP ELIGIBILITY DETERMINATIONSAMPLING RESULTS FOR FISCAL YEAR 2020See table in Schedule of Findings and Questioned Costs1Income includes ? Lack of Income Verification and Income Issues.The specific issues we identified and the breakdown of identified questioned costs are as follows:CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically:In seven cases, the Department did not assess an enrollment fee.In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries.Benefits were inappropriately paid on behalf of these10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260.State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program.LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546.State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines.In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level.MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows:In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs.In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs.According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].?State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country.ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSESWe identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows.CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020.We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds.According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)].Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....?Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider.CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange.We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS.In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020.Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP.The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004].The following table summarizes the eligibility issues we identified through our data analyses.See table in Schedule of Findings and Questioned CostsELIGIBILITY MONITORING ISSUESCBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures.Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action.According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHY DID THESE PROBLEMS OCCUR?Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified:CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations.CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income.MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations.SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year.Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations.WHY DO THESE PROBLEMS MATTER?Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals.Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.counties and Medical Assistance (MA) sites, to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required identity and citizenship status, and obtaining and verifying income reported by the beneficiary.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $169,326KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-043B, 2019-047A, AND 2019-047B*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-036The Department of Health Care Policy and Financing should improve its internal controls over Children?s Basic Health Plan (CBHP) payments by:A Resolving Colorado Benefits Management System (CBMS) programming issues to ensure that CBHP annual enrollment fees are being calculated correctly including when a beneficiary moves between programs, and to disallow benefits if the annual enrollment fee is not paid prior to enrollment in the program.B Educating caseworkers by incorporating the issues identified through the audit in training and support for the local counties and Medical Assistance (MA) sites, to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required identity and citizenship status, and obtaining and verifying income reported by the beneficiary.C Establishing an interim monitoring process over local counties and MA sites until the new oversight monitoring process is implemented, to ensure that CBHP eligibility is processed in accordance with federal regulations and federal grant requirements.D Researching and resolving the CBMS and Colorado interChange system interface issues to ensure that the Colorado interChange system only pays providers capitation payments on behalf of eligible beneficiaries.E Identifying and correcting any additional cases affected by the system issues noted in our audit.F Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with federal and state regulations.See additional information in Schedule of Findings and Questioned CostsSee additional text of this finding in Schedule of Findings and Questioned Costs
Show full finding ▾Hide full finding ▴CHILDREN?S BASIC HEALTH PLAN ELIGIBILITY AND IMPROPER PAYMENTSThe Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits through CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay a CBHP annual enrollment fee (enrollment fee) to the Department, based on the number of people in the family and the family?s income.Eligibility data in CBMS feeds into Colorado interChange, which issues payments to CBHP providers. For CBHP, the Department contracts with managed-care entities, which are groups or organizations of medical service providers that serve CBHP beneficiaries to provide capitation payments to CBHP providers. These capitation payments are paid regardless of whether the providers serve beneficiaries during the month or not. Colorado interChange is programmed to pay capitation payments only on behalf of beneficiaries that are deemed eligible in Colorado interChange based on eligibility information received from CBMS and requirements specified in federal and state regulations.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the CBHP eligibility determination process, as well as the capitation payment process, to determine whether the Department complied with applicable federal and state requirements, and whether payments were only made on behalf of eligible beneficiaries during Fiscal Year 2020. CMS suspended rules and provided waivers related to CBHP eligibility requirements in response to the COVID-19 PHE; as a result, our testwork was split into two periods for testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020.We performed the following testwork:REVIEW OF CBHP ELIGIBILITY CASE FILESWe reviewed the Department?s CBHP eligibility internal controls during Fiscal Year 2020. In addition, we tested a random sample of 25 beneficiaries who were deemed eligible for CBHP benefits and had capitation payments made on their behalf to a CBHP provider between July 1, 2019, and February 29, 2020, to determine whether those beneficiaries? eligibility determinations were appropriate. If beneficiaries were determined to be ineligible through our testwork, we performed further testing to determine whether the beneficiaries had additional payments made on their behalf from March 2020 through June 2020, and whether the individuals were eligible for those payments. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations; correctly entered eligibility data into CBMS; and properly assessed and collected enrollment fees.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to CBHP eligibility. During that audit, we recommended that the Department strengthen its internal controls over CBHP eligibility determinations by providing adequate training to caseworkers, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2019 audit. We also recommended that the Department ensure it disallows benefits if a beneficiary becomes ineligible and if the enrollment fee is not paid prior to enrollment in the program.DATA ANALYSES OF CBHP BENEFICIARIESINELIGIBLE CBHP BENEFICIARIES. During our audit, we obtained eligibility data for all individuals who were deemed by the Department, a local county, or an MA site to be eligible for CBHP benefits in Colorado interChange at any point during the period of July 1, 2019, through February 29, 2020. We also obtained data for all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. This data included a total of $124.7 million in capitation payments made on behalf of 117,222 beneficiaries. We compared the eligibility data to the capitation payment data to identify any instances in which the Department made capitation payments to providers on behalf of beneficiaries who did not appear to be eligible for CBHP benefits.CBHP BENEFICIARIES 19 YEARS OR OLDER. Federal and state regulations require an individual to be less than 19 years of age to be eligible for CBHP benefits. To determine the Department?s compliance with these regulations, we further analyzed the list of all CBHP capitation payments made through Colorado interChange by the Department from July 1, 2019, through February 29, 2020. Specifically, we reviewed the beneficiaries? dates of birth in Colorado interChange to identify any capitation payments made on behalf of beneficiaries who appeared to be 19 years or older when the payments were made and, therefore, would not have been eligible for CBHP benefits.CBHP ELIGIBILITY MONITORING AND REVIEWWe also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility determinations were made in accordance with federal and state regulations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state regulations for CBHP eligibility and made payments on behalf of ineligible beneficiaries during the fiscal year. The specific issues we identified through our analyses of CBHP eligibility data and case file reviews are outlined in more detail throughout this section.ELIGIBILITY CASE FILE ISSUESIn 16 of 25 case files tested (64 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2020, and total known questioned costs of $10,913, of which $8,449 was paid with federal grant funds; and total likely questioned costs of $3,805, of which $3,076 was paid with federal grant funds. A questioned cost, as defined in Uniform Guidance [45 CFR 75.2], is ?a cost that is questioned by the auditor ? (1) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (2) Where the costs, at the time of the audit, are not supported by adequate documentation.?? Federal regulation [45 CFR 75.516] further defines known questioned costs as questioned costs that are specifically identified by the auditor and likely questioned costs as the auditor?s best estimate of total questioned costs. During the COVID-19 PHE, CMS issued waivers that limited the Department?s ability to deny eligibility for enrolled beneficiaries. The Department also sought guidance from CMS on the treatment of beneficiaries who were ineligible prior to the COVID-19 PHE and receiving benefits during this period. Although CMS guidance indicated that the Department should keep these beneficiaries enrolled until the end of the COVID-19 PHE, we are reporting the costs incurred for the 12 ineligible beneficiaries in our sample during the period of the COVID-19 PHE of March 1, 2020, through June 30, 2020, as likely questioned costs since the beneficiaries were inappropriately deemed eligible prior to the COVID-19 PHE and should not have been enrolled in CBHP.The following table outlines the types of issues we found.CBHP ELIGIBILITY DETERMINATIONSAMPLING RESULTS FOR FISCAL YEAR 2020See table in Schedule of Findings and Questioned Costs1Income includes ? Lack of Income Verification and Income Issues.The specific issues we identified and the breakdown of identified questioned costs are as follows:CBHP ANNUAL ENROLLMENT FEE NOT PAID. In 10 cases, the Department either did not assess the required enrollment fee or the fee was assessed but was never collected. Specifically:In seven cases, the Department did not assess an enrollment fee.In the remaining three cases, the Department assessed the enrollment fees but did not collect the required fees from the beneficiaries.Benefits were inappropriately paid on behalf of these10 beneficiaries for all or part of Fiscal Year 2020. As a result, the Department was not in compliance with state regulations. These issues resulted in known questioned costs of $6,684 and likely questioned costs of $2,260.State regulations [10 CCR 2505-3, 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to enrollment in the program.LACK OF INCOME VERIFICATION. In three cases, the caseworkers failed to verify income reported by the beneficiary as required by state regulations. In all three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer. These errors resulted in known questioned costs of $2,854 and likely questioned costs of $1,546.State regulations [10 CCR 2505-10, 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer.INCOME ISSUES. In one case, the beneficiary?s income information received by the local county or MA site was more than the income limit set within the state regulation; however, the beneficiary was deemed eligible in CBMS and Colorado interChange paid capitation payments on behalf of the beneficiary. As a result, the beneficiary incorrectly received CBHP benefits during the fiscal year. These errors resulted in known questioned costs of $1,375. In another case, the caseworker incorrectly calculated self-employment income for the beneficiary, resulting in lower income. No questioned costs were identified in this instance because the beneficiary?s actual income was still within guidelines.In order to be eligible for CBHP, state regulation [10 CCR 2505-3, 110.1.D] requires an individual to have a household income greater than 133 percent of, but not exceeding, 250 percent of the federal poverty level.MISSING CASE DOCUMENTATION. In five cases, the Department was unable to provide documentation necessary to support the CBHP eligibility determination, including documentation to support income, such as wage stubs; and documentation to support identity and citizenship, such as birth certificates; as required by federal regulations, as follows:In three cases, the Department could not provide supporting documentation used by the caseworker in CBMS to verify income at the time of eligibility determination. Specifically, in all three cases, the Department was unable to provide copies of the beneficiary?s wage stubs that were noted as the source document in CBMS. However, the Department subsequently provided a hand-written statement from the employer and electronic income information from another data source interfaced with CBMS that indicated income was under the federal income threshold, resulting in no questioned costs.In two different cases, to determine beneficiaries? eligibility, a birth certificate was identified as the source used to verify identity and/or citizenship within CBMS; however, the Department was unable to provide these birth certificates to support their identity and/or citizenship for eligibility determinations. In both cases, there was other corroborating documentation in the case file that indicated the beneficiaries were eligible; however, the Department did not appropriately maintain the support used to determine the beneficiaries? eligibility as required by federal regulation. These errors did not result in questioned costs.According to federal regulation [42 CFR 457.965], ?The State must include in each applicant?s record facts to support the State?s determination of the applicant?s eligibility for [Children?s Health Insurance Program].?State regulations [10 CCR 2505-3, 110.1.A, 110.1.B, and 110.1.C] require the Department to ensure a beneficiary is either less than 19 years of age or a pregnant woman and a citizen of the United States or an individual who is legally allowed to be in the country.ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSESWe identified 53 ineligible beneficiaries through our data analyses of CBHP eligibility and capitation payment data from Colorado interChange for July 1, 2019, through February 29, 2020. The related overpayments resulted in known questioned costs of $158,413 for Fiscal Year 2020, of which $123,251 were paid with federal grant funds. The specific issues we found are discussed in more detail as follows.CBHP BENEFICIARIES NOT ON THE ELIGIBILITY LIST. We identified39 beneficiaries who were not listed as eligible beneficiaries in the CBHP eligibility data that we received from the Department. However, these beneficiaries had CBHP capitation payments paid on their behalf through Colorado interChange during Fiscal Year 2020.We informed the Department of the issues we identified and provided the list of all 39 identified beneficiaries. Department staff performed their review and confirmed that 38 of the 39 beneficiaries were not eligible in CBMS at some point during Fiscal Year 2020, but showed as eligible in Colorado interChange during that timeframe. For the remaining beneficiary, CBMS and Colorado interChange noted the beneficiary as eligible when payments occurred in July 2019; however, the Department?s review later determined that the beneficiary was ineligible during July 2019 after the payments had already been made through Colorado interChange. As a result, all payments made during July 1, 2019, through February 29, 2020, for these 39 ineligible CBHP beneficiaries were improper payments as defined by federal regulations and, therefore, should be recovered in accordance with state and federal regulations. These payments resulted in known questioned costs of $76,924, of which $59,423 were paid with federal grant funds; and likely questioned costs of $14,345 for March 1, 2020, through June 30, 2020, of which $11,596 were paid with federal grant funds.According to federal regulation [42 CFR 431.958], any payment to an ineligible beneficiary is considered an improper payment, which is any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments). Eligibility errors include ineligible individuals that were authorized as eligible when they received services [42 CFR 431.960 (d)(2)(i)].Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?are recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of human or social services, an entity acting on behalf of either department, or by the provider or any agent of the provider....?Pursuant to 1903(d)(2)(C) of the Social Security Act [42 U.S.S. 1396b], states have up to 1 year from the date of discovery of the overpayment to recover or attempt to recover the overpayment before the federal share must be refunded to the Centers for Medicare and Medicaid Services (CMS) regardless of whether recover is made from the provider.CBHP BENEFICIARIES 19 YEARS OR OLDER. We identified $853,422 in capitation payments made on behalf of 168 beneficiaries who appeared to be 19 years or older at the time of the CBHP capitation payments and, therefore, would not have been eligible for CBHP benefits. These beneficiaries were identified based on their dates of birth and the dates of capitation payments made on their behalf in Colorado interChange.We selected a random sample of 17 of the 168 beneficiaries to test whether or not the beneficiaries were ineligible to receive CBHP benefits based on their age. Using information contained in both Colorado interChange and CBMS, we confirmed that 14 of the 17 tested (82 percent) were 19 years or older when they had capitation payments paid on their behalf and, thus, were ineligible for these payments made through Colorado interChange. For example, we noted that based on the information in CBMS, 10 of the beneficiaries had not been eligible for CBHP benefits since 2017 even though Colorado interChange showed the beneficiaries as eligible. One of these beneficiaries had passed away in 2017, but had payments made on their behalf through September 2019. The remaining three of the 17 beneficiaries we tested were under the age of 19 at the time of the payments, but had an incorrect date of birth in Colorado interChange and/or CBMS.In total, for the 14 beneficiaries, we identified known questioned costs of $81,489 for Fiscal Year 2020, of which $63,828 were paid with federal grant funds. Additionally, for the remaining 151 beneficiaries with an age of 19 years or older based on their date of birth in Colorado interChange, we identified likely questioned costs of $775,470 for payments made on their behalf after they turned 19, of which $611,762 were paid with federal funds for Fiscal Year 2020.Federal regulation [42 CFR 457.320] defines children as up to, but not including, the age of 19. In addition, state regulation [10 CCR 2505-3, 101.1.A.1] states that an individual must be less than 19 years of age to be eligible for CBHP.The CBHP state plan amendment [CO-20-0031] approved by CMS, waives the requirement during the COVID-19 PHE, except for circumstances described in 42 CFR 435.926(d)(1) that states, the Department has to terminate a child?s eligibility during a continuous eligibility period once the child attains the maximum age of 19 years. Department policy further clarifies that beneficiaries enrolled in CBHP must meet age requirements [HCPF PM 20-004].The following table summarizes the eligibility issues we identified through our data analyses.See table in Schedule of Findings and Questioned CostsELIGIBILITY MONITORING ISSUESCBHP ELIGIBILITY QUALITY REVIEW REPORT. In addition, we identified problems with the Department?s monitoring of local counties and MA sites over CBHP eligibility determinations. Based on our inquiry, we found that the Department did not obtain any quarterly quality review reports from local counties and MA sites during Fiscal Year 2020, or monitor the local counties and MA sites through an alternative process. As a result, the Department did not monitor local counties and MA sites in accordance with federal regulations and Department procedures.Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of CBHP eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action.According to federal regulation [45 CFR 75.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book, Paragraph 16.01, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHY DID THESE PROBLEMS OCCUR?Overall, the Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements and to ensure that CBHP capitation payments were appropriately paid only on behalf of eligible beneficiaries during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified:CBHP ANNUAL ENROLLMENT FEE. CBMS was not programmed to calculate and assess the correct enrollment fee or disallow benefits if the enrollment fee was not paid prior to enrollment in the program. In addition, CBMS was not programmed to calculate and assess an enrollment fee when a beneficiary moves between programs, such as from other federal programs to CBHP. According to the Department, CBMS is programmed to only calculate and assess an enrollment fee at a beneficiary?s annual redetermination and does not assess a fee when beneficiaries move to CBHP in between annual redeterminations, as required by state regulations.CASEWORKER ERROR. Caseworkers did not ensure that they maintained the required documentation to support CBHP eligibility, such as citizenship and identity status; or obtained and verified beneficiary income.MONITORING AND REVIEWS. The Department reported that it discontinued its process of obtaining quarterly CBHP monitoring reports from local counties and MA sites during Fiscal Year 2020 because the process is not effective and it is creating a new oversight monitoring process; however, the Department did not implement an interim monitoring process to ensure compliance with federal regulations.SYSTEM INTERFACE ISSUES AND LACK OF RECONCILIATION PROCESS. CBMS failed to interface with Colorado interChange appropriately during Fiscal Year 2020 to update beneficiaries? eligibility information. As a result, some beneficiaries who were deemed ineligible for CBHP in CBMS were listed as eligible in Colorado interChange and capitation payments were made on their behalf during the fiscal year.Furthermore, the Department lacked an effective internal control process for reconciling CBHP beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure the information is consistent in both systems and the beneficiary is appropriately deemed either eligible or ineligible in accordance with federal and state regulations. The Department indicated that it developed a manual reconciliation process in October 2019 to correct the eligibility status of these beneficiaries from eligible to ineligible in Colorado interChange to stop any further payments. This manual reconciliation process, however, did not identify and stop all the overpayments to providers on behalf of ineligible beneficiaries noted in this audit. Additionally, the Department did not recover these overpayments as required by federal and state regulations.WHY DO THESE PROBLEMS MATTER?Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate, which can result in benefits being paid on behalf of ineligible individuals.Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Additionally, the federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.Because CBMS determines eligibility and Colorado interChange makes payments on behalf of other federal programs, system issues with CBMS and Colorado interChange could result in erroneous payments for other programs.counties and Medical Assistance (MA) sites, to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required identity and citizenship status, and obtaining and verifying income reported by the beneficiary.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $169,326KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-043B, 2019-047A, AND 2019-047B*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-036The Department of Health Care Policy and Financing should improve its internal controls over Children?s Basic Health Plan (CBHP) payments by:A Resolving Colorado Benefits Management System (CBMS) programming issues to ensure that CBHP annual enrollment fees are being calculated correctly including when a beneficiary moves between programs, and to disallow benefits if the annual enrollment fee is not paid prior to enrollment in the program.B Educating caseworkers by incorporating the issues identified through the audit in training and support for the local counties and Medical Assistance (MA) sites, to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required identity and citizenship status, and obtaining and verifying income reported by the beneficiary.C Establishing an interim monitoring process over local counties and MA sites until the new oversight monitoring process is implemented, to ensure that CBHP eligibility is processed in accordance with federal regulations and federal grant requirements.D Researching and resolving the CBMS and Colorado interChange system interface issues to ensure that the Colorado interChange system only pays providers capitation payments on behalf of eligible beneficiaries.E Identifying and correcting any additional cases affected by the system issues noted in our audit.F Researching and recovering any overpayments made to providers on behalf of ineligible beneficiaries noted through the audit in accordance with federal and state regulations.See additional information in Schedule of Findings and Questioned CostsSee additional text of this finding in Schedule of Findings and Questioned Costs
(A) The Department has already made some changes to the Colorado Benefits Management System (CBMS) to ensure that CHP+ annual enrollment fees are being calculated correctly including when a beneficiary moves between programs, and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. The Department will make additional system changes as necessary. Of the ten cases identified in this audit, seven cases have already been fixed.(B) The Department disagrees with the auditors' statements that the Department was unable to provide verification in several of the findings, since that information can be self-attested by the beneficiary and that the caseworker may have simply mislabeled the data verification or that documentation was not maintained due to documentation retention policies. Therefore, the documentation the auditor determined to be missing was not part of verifications needed to determine eligibility. Caseworker errors can be caused by an array of issues, including training material retention; a lack of adequate funding to balance caseload inventory versus available work hours and staffing levels; a lack of quality review and performance reinforcement; and an assortment of local issues that lead to employee turnover. The Department agrees with the six caseworker errors identified in this audit. These errors did not affect eligibility and had no questionable cost. The Department will continue to work with eligibility sites regarding caseworker errors identified through this audit.(C) The Department began the implementation of a new monitoring process called the Eligibility Site Oversight and Accountability Program in February 2021. This program includes strengthening performance measures, developing mechanisms for collecting performance data, developing eligibility site specific performance dashboards, and developing corrective action plans. The Department has developed internal processes and defined performance measures for which eligibility sites will be held accountable. The first iteration of these performance measures began in March of 2021 and will continue through July 2021. In addition, the Department has taken steps to ensure that we have ongoing systemic and dashboard monitoring for Medicaid and CHP+ programs that captures eligibility errors, eligibility system performance, and eligibility results. The state implemented the first phase of the monitoring dashboard in June 2020 with the second phase to be implemented by March 2022. All processes under the Eligibility Site Oversight and Accountability program will be implemented through enhanced administrative rules, which will implement Improvement Action Plans to eligibility sites that are out of compliance.(D) The Department disagrees with the auditor?s findings and questioned costs related to capitation payments under the Eligibility Issues Identified through Data Analyses section. These costs are related to cases that were ?not eligible? in CBMS but were showing as ?eligible? in Colorado interChange that were already identified by the Department. The Department was actively working to resolve these cases with CMS prior to the Public Health Emergency (PHE). The Department developed and implemented a reconciliation report that is used to research and resolve CBMS and Colorado interChange interface mismatches. Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS.(E) The Department has thoroughly researched the eligibility issues identified in this audit. Of the 16 cases identified in this audit, 12 cases were identified as system issues. Of those 12 cases, 9 have already been fixed with system updates made in November 2019, August 2020, or February 2021. The remaining 3 issues will be fixed with system updates made prior to July 2022.(F) The Department will make referrals to law enforcement in any cases involving credible allegations of fraud by the provider. At this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, the Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law.
2019-043, 2019-047
RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTSThe Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified.The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS.The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system.The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate.The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020.During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations.Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS.The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following:UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest.According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider.According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment.INACCURATE FEDERAL REPORTING. For all 13 Medicaid(100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance.Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections.EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired.According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division.INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS.Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors:LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports.LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet.LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports.LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments.WHY DO THESE PROBLEMS MATTER?Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations.Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018*XIX-MAP2019*XIX-MAP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767*, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)REPORTING (L)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $23,646**KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.**THE DEPARTMENT REFUNDED $23,646 IN KNOWN QUESTIONED COSTS TO CMS AFTER JUNE 30, 2020; HOWEVER, THE UNKNOWN INTEREST AMOUNT ON THESE KNOWN QUESTIONED COSTS HAS NOT BEEN REFUNDED AS OF MAY 2021.RECOMMENDATION2020-037The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by:A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports.B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations.C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports.D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports.D AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
Show full finding ▾Hide full finding ▴RECOVERING AND REFUNDING OF FEDERAL SHARE OF MEDICAID AND CBHP PROVIDERS? OVERPAYMENTSThe Department pays providers for services rendered to eligible beneficiaries of Medicaid and CBHP programs. In some cases, the Department may discover that it paid a provider for unallowed services, or that it paid more than the allowable amount, and will need to seek a recovery for the overpayment. In such cases, the Department is required to repay CMS for the portion of the overpayment that was funded by the federal government (federal share) within 1 year of the date the overpayment was identified.The Department?s Program Integrity (PI) Division identifies, receives, and tracks overpayments made to Medicaid and CBHP providers. An overpayment is identified once the PI Division sends a Demand Letter (date of discovery) to the provider or receives a self-disclosure identifying the amount of overpayment. The provider has a deadline of 30 days after receiving a Demand Letter or 60 days after submitting a self-disclosure to submit the overpayment or make arrangements for a payment plan with the PI Division. The PI Division uses a recovery tracking spreadsheet (Spreadsheet) to compile all necessary information for the recovery and refund of overpayments. The Spreadsheet is designed to contain information such as the amount of the overpayment, date of discovery, and deadlines for refunding to CMS.The federal share of overpayments that must be refunded to CMS depends upon the Federal Medical Assistance Percentage (FMAP) at which the Department was reimbursed. Once the PI Division recovers an overpayment from the provider, it determines the FMAP and includes it in a recovery form called the Colorado Authorization Document; PI Division staff then send it to the Controller?s Division for recording the recovery and refund information in the Colorado Operations Resource Engine (CORE), the State?s accounting system.The Department?s Controller?s Division uses summary data from CORE to report financial information for Medicaid and CBHP?including all overpayments and the associated federal share?to CMS in quarterly reports: Form CMS-64 for Medicaid and Form CMS-21 for CBHP. The Department has up to 1 year from the date of discovery of an overpayment to report the refund to CMS in one of these forms, as appropriate.The PI Division works with the Controller?s Division to ensure the timely reporting and refunding of the federal share of overpayments to CMS.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over processes for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments, as well as to determine whether the Department complied with applicable federal requirements and Department policies and procedures during Fiscal Year 2020.During our audit, we reviewed the Department?s Spreadsheet detailing all overpayment cases that appeared to be due for a refund of federal share to CMS during Fiscal Year 2020. The Spreadsheet included 50 Medicaid and seven CBHP overpayment cases, and from these, we selected and tested a sample of 13 Medicaid and five CBHP overpayments. We requested and reviewed supporting documentation for these overpayments to determine whether (1) the information recorded in the Spreadsheet was accurate, (2) the overpayment was recovered in a timely manner or recovery was attempted within 1 year from the date of discovery, and (3) the federal share was appropriately refunded through quarterly reports to CMS in accordance with federal regulations.Additionally, we requested the Department?s policies and procedures to ensure compliance with federal regulations governing the recovery, reporting, and refunding of Medicaid and CBHP overpayments to CMS.The process followed for recovery, reporting, and refunding the federal share of overpayments to providers is the same for both Medicaid and CBHP, and our testing was used to determine compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal regulations for recovering, reporting, and refunding the federal share of Medicaid and CBHP overpayments to providers during Fiscal Year 2020. We noted issues with the untimely recovery and refund of overpayments to CMS, inaccurate federal reporting to CMS, and untimely follow-up with the provider on outstanding overpayments and expired checks. Specifically, we identified the following:UNTIMELY RECOVERY AND REFUND. For six of the 13 Medicaid (46 percent) and two of five CBHP (40 percent) overpayments tested, the Department failed to recover, or seek to recover, the overpayments from the provider and failed to refund to CMS, the federal share, within 1 year of the date of discovery, as required by federal regulations. For example, an overpayment was identified on September 13, 2018, but the Department did not recover, or seek to recover, the overpayment until September 15, 2020, and did not refund the federal share to CMS until federal quarter ending September 30, 2020, which is 367 days past the 1 year recovery and refund period in accordance with the federal requirement. In addition, for one of the 13 Medicaid (8 percent) and one of five CBHP (20 percent) overpayments tested, the Department failed to refund the federal share of overpayment to CMS within 1 year of the date of discovery. As a result of untimely follow-up with the providers, the Department did not recover the overpayments amounting to $23,646 in known questioned costs; and did not refund $12,176 within the 1 year period of discovery. These errors resulted in underreporting of overpayments to CMS for Fiscal Year 2020. Additionally, the Department could be liable to CMS for the interest payments on these untimely refunds of overpayments. As of the end of our audit, the Department had not provided an estimated amount of interest that will be due to CMS so we were unable to report an estimated questioned costs amount for the interest.According to federal regulation [42 CFR 433.312(a)(1) and (2)], the Department has 1 year from the date of discovery of an overpayment to a provider to recover or seek to recover the overpayment before the Federal share must be refunded to CMS. In addition, the Department must refund the Federal share of overpayments at the end of the 1-year period following the date discovery of overpayment, whether or not the State has recovered the overpayment from the provider.According to federal regulation [42 CFR 433.320(a)(4)], if the Department does not refund the Federal share of such overpayment as indicated in the previous paragraph (a)(2), the State will be liable for interest on the amount equal to the Federal share of the non-recovered, non-refunded overpayment amount. Interest during this period will be at the Current Value of Funds Rate, and will accrue beginning on the day after the end of the 1-year period following discovery until the last day of the quarter for which the State submits a CMS-64 report refunding the Federal share of the overpayment.INACCURATE FEDERAL REPORTING. For all 13 Medicaid(100 percent) and all five CBHP (100 percent) overpayments we tested, the Controller?s Division reported the federal share of the overpayments made to providers on the wrong line of the CMS quarterly reports rather than on the line specified and required by Uniform Guidance.Uniform Guidance states that the Department must report the refund of the overpayment on CMS-64 for Medicaid on line 9C1- Fraud, Waste and Abuse and/or on CMS-21 for CBHP on line 4-Adjustments Decreasing Claims-Collections.EXPIRED CHECK AND UNTIMELY FOLLOW-UP. For one of the13 Medicaid overpayments tested (8 percent), the PI Division failed to timely process the overpayment recovery check received from the provider. Consequently, the check, which was received on September 5, 2019, expired and the Department did not take any actions to follow up with the provider at any time through the end of the fiscal year to obtain payment. After we brought this issue to the Department?s attention, they followed up on the outstanding payment in January 2021, which is more than 16 months since the check expired.According to the Department?s Policies and Procedures, Recovery Officer Check Processing, Section (V)(A), the PI Division within Audits and Compliance has to process the received check in a timely manner and provide a copy to the accounting or Controller Division.INCOMPLETE TRACKING SPREADSHEET. We found that the overpayment recovery and refund tracking Spreadsheet used by the PI Division was incomplete and missing important information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS.Green Book, Section 4, Paragraph OV4.08, states that documentation is required for the effective design, implementation, and operating effectiveness of an entity?s internal control system.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls, including policies and procedures, in place over the recovery, reporting, and refunding of Medicaid and CBHP overpayments during Fiscal Year 2020 to ensure compliance with federal regulations. Specifically, we noted the following causes for the identified errors:LACK OF TRAINING. The staff within the PI Division and the Controller?s Division lacked adequate training to document, communicate, and report details of overpayments to ensure compliance with federal regulations. Specifically, the Department?s PI Division did not timely create and provide the Colorado Authorization Document form to the Controller?s Division and the Controller?s Division did not report the refund of the overpayments within 1 year of the date of discovery to ensure compliance with federal regulations. Additionally, staff lacked training to properly track and report overpayments for Medicaid and CBHP; timely process recovery and refund of overpayments, processing checks timely, and correctly report overpayments on CMS quarterly reports.LACK OF POLICIES AND PROCEDURES. The Department lacked written policies and procedures to ensure that all necessary information such as the date of the discovery, the federal program reimbursement rate, and deadlines for refunding to CMS required to track, recover, report, and refund overpayments were documented within the Spreadsheet.LACK OF ACCOUNT CODES. According to the Controller Division staff, the correct accounting codes are not set up in CORE; therefore, the recovered overpayments are currently recorded under incorrect accounting codes in CORE. This led to the reporting of overpayments on the incorrect federal reporting lines in CMS quarterly reports.LACK OF SUPERVISORY REVIEW. The PI Division and Controller?s Division lacked supervisory review over the Spreadsheet and CORE account codes used on the recoveries to ensure completeness and accuracy of information to support timely recovery, refund, and reporting of overpayments.WHY DO THESE PROBLEMS MATTER?Strong internal controls over refunding and recovery of Medicaid and CBHP overpayments, including written policies and procedures; adequate staff training on those policies and procedures, and any related processes; a proper tracking mechanism; and a supervisory review process are necessary to ensure that Department is in compliance with federal and state regulations.Without a proper tracking mechanism for overpayments, the Department risks failing to timely recover state funds paid improperly, refund overpayments, and accurately report overpayment information to the federal government, potentially resulting in additional liability of interest on overpayments to the federal government.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018*CHIP2019*CHIP2020*XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018*XIX-MAP2019*XIX-MAP2020*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767*, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)REPORTING (L)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $23,646**KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.**THE DEPARTMENT REFUNDED $23,646 IN KNOWN QUESTIONED COSTS TO CMS AFTER JUNE 30, 2020; HOWEVER, THE UNKNOWN INTEREST AMOUNT ON THESE KNOWN QUESTIONED COSTS HAS NOT BEEN REFUNDED AS OF MAY 2021.RECOMMENDATION2020-037The Department of Health Care Policy and Financing (Department) should improve its internal controls over Medicaid and Children?s Basic Health Plan (CBHP) overpayments and comply with the related payment and reporting requirements by:A Providing adequate training to staff to ensure timely documentation and communication of recovery information between the Program Integrity Division and the Controller Division related to reporting and refunding of overpayments within 1 year of the date of discovery in accordance with federal regulation. Additionally, the training should focus on proper tracking and reporting of overpayments for Medicaid and CBHP, timely processing of recovery of overpayments, timely check processing, and correct refunding of the federal share of these overpayments on Centers for Medicare and Medicaid Services (CMS) quarterly reports.B Developing and implementing written policies and procedures to ensure that all necessary information required to correctly track Medicaid and CBHP overpayments is included on the tracking spreadsheet and recovered overpayments are refunded and reported to CMS within the 1 year of the discovery date, in accordance with federal regulations.C Creating overpayment account codes to report recovered overpayments accurately in the Colorado Operations Resource Engine (CORE) and subsequently under the correct federal reporting lines in CMS quarterly reports.D Implementing a supervisory review over the tracking spreadsheet and CORE overpayment recovery account codes to ensure completeness and accuracy of information to support timely recovery and reporting of overpayments by the divisions.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports.D AGREE. IMPLEMENTATION DATE: JULY 2022.The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
(A) The Program Integrity Division and Controller Division will develop and provide training to staff that covers the federal regulations surrounding reporting overpayments and returning the federal share, required information for tracking overpayments, processes for processing recovered funds in a timely manner, and processes for properly refunding the federal share on the CMS-64 and/or CMS-21.(B) The Program Integrity Division and Controller Division will draft and revise existing policies and procedures to ensure proper tracking of recovered overpayments, timely processing of those payments, and correct reporting on the CMS-64 and/or CMS-21.(C) The Department will implement procedures and coding sufficient to allow proper reporting of overpayments returned greater than one year from the date of discovery for the CMS quarterly reports.(D) The Program Integrity Division and Controller Division will develop and revise supervisory review processes for ensuring that the tracking spreadsheet is complete and accurate and that the CORE account codes are correctly reported.
PRESUMPTIVE ELIGIBILITYColorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible.To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases.The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020.During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews.In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange.The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following:UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits.Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made.LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site.LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following:For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020.11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes.Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored.Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?.According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed.Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations.MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible.Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible.SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs.CBMS is designed to display case and applicant information consistently between various screens within the system.WHY DID THESE PROBLEMS OCCUR?The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified:LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites.LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations.CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens.WHY DO THESE PROBLEMS MATTER?As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018CHIP2019CHIP2020XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018XIX-MAP2019XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0*KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*THE DEPARTMENT WAS UNABLE TO PROVIDE PRESUMPTIVE ELIGIBILITY BENEFITS PAYMENT INFORMATION FOR 314 CASES PROCESSED BY PE SITES THAT WERE NOT RE-CERTIFIED DURING FISCAL YEAR 2020.RECOMMENDATION2020-038The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by:A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites.B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed.C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it.C AGREE. IMPLEMENTATION DATE: IMPLEMENTED.Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it.AUDITOR?S ADDENDUM for Parts A, B, and CAs noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
Show full finding ▾Hide full finding ▴PRESUMPTIVE ELIGIBILITYColorado?s presumptive eligibility program is designed to give immediate, temporary medical coverage to children under 19 and pregnant women while they wait for a regular Medicaid or CBHP eligibility determination. Though there are fewer eligibility requirements for presumptive eligibility in comparison with regular Medicaid or CBHP coverage, beneficiaries must submit a Medical Assistance application (Application) and meet certain criteria to be eligible.To manage the application process and help ensure that only people meeting the basic eligibility criteria are enrolled in presumptive eligibility programs for children and pregnant women, the Department partners with clinics, health care centers, and community resource centers that are certified as presumptive eligibility sites (PE sites). Such PE sites must be re-certified by the Department every 2 years to maintain their active status as qualified PE sites in order to process presumptive eligibility. As part of the re-certification process, the Department conducts a sample of eligibility case reviews. During Fiscal Year 2020, there were 57 PE sites that together determined presumptive eligibility for 1,795 Medicaid cases and 875 CBHP cases.The process of enrolling an applicant into a presumptive eligibility program begins when a caseworker at a PE site collects minimum information needed to determine presumptive eligibility, including the applicant?s name, age, residency, citizenship, and income. The caseworker enters this information into CBMS, which determines whether the applicant is eligible to receive Medicaid or CBHP temporary benefits. If the applicant is deemed presumptively eligible, then CBMS feeds relevant data to Colorado interChange, which issues payments to CBHP and Medicaid providers on behalf of these beneficiaries. If the applicant?s reported information is not in compliance with state and federal requirements, CBMS is programmed to deny the eligibility and mark the applicant?s eligibility as fail within CBMS. As a result, the applicant would not be eligible to receive any payments on their behalf through Colorado interChange. Once an applicant?s presumptive eligibility has been determined, the PE site submits the Application along with a transmittal form detailing the beneficiary?s reported information to the appropriate local county or designated MA site, which then completes the application process to determine regular (i.e., not presumptive) eligibility for Medicaid or CBHP benefits. Once the applicant is enrolled in the regular Medicaid or CBHP program, the individual?s presumptive eligibility benefits should end.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to review the Department?s internal controls over the processing of presumptive eligibility for Medicaid and CBHP programs, as well as to determine whether the Department complied with the applicable federal and state requirements for Fiscal Year 2020.During our internal controls testing, we reviewed all 57 PE sites to determine whether they were due for re-certification and were appropriately re-certified to process presumptive eligibility by the Department during the fiscal year. Out of 57 PE sites, 39 were due for re-certification during Fiscal Year 2020. We also reviewed the Department?s case reviews of the presumptive eligibility determinations processed by 13 staff at five out of the 39 PE sites due for re-certification during Fiscal Year 2020 to determine whether reviews were performed and if the appropriate training was provided for those PE sites? staff that failed the Department?s review. The PE site?s staff fails the Department?s case reviews if the Department identifies a high amount of presumptive eligibility determination errors in accordance with federal and state requirements. If the PE site?s staff fails the review, the Department requires the staff to undergo customized Department training over the areas they failed within 6 months of the review. We also made inquiries with Department staff regarding their policies and procedures over monitoring of these PE sites and reviewed the Department?s process of case file reviews.In addition, we randomly selected a sample of 20 Medicaid and 20 CBHP cases for individuals who were deemed presumptively eligible by the Department during Fiscal Year 2020 to determine whether the Department complied with federal Medicaid and CBHP presumptive eligibility requirements. Our testing included reviewing the related supporting case file documentation, as well as the CBMS data fields related to presumptive eligibility determinations and payment information in Colorado interChange.The process followed for presumptive eligibility determination is the same for both Medicaid and CBHP, and therefore our testing was used to determine compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state regulations regarding Medicaid and CBHP presumptive eligibility requirements during Fiscal Year 2020. We noted issues regarding the Department?s timeliness of PE sites? re-certifications, failure to timely end beneficiaries? presumptive eligibility, a lack of review of PE sites, and missing documentation. Additionally, we found CBMS system issues related to the determination of applicant?s presumptive eligibility. Specifically, we identified the following:UNTIMELY END OF PRESUMPTIVE ELIGIBILITY. In eight out of 20 Medicaid (40 percent) and seven out of 20 CBHP (35 percent) cases, we found that the Department did not properly end presumptive eligibility within CBMS as required by the federal regulation. For example, in one CBHP case, the beneficiary?s presumptive eligibility did not end until 57 days after the beneficiary was determined to be eligible for regular CBHP benefits.Federal regulation [42 CFR 435.1101)] states that presumptive eligibility should end the day on which a decision is made on the application for Medical Assistance or the last day of the month following the month in which the determination of presumptive eligibility was made.LAPSED CERTIFICATIONS OF PE SITES. We found that five of the 57 PE sites (9 percent) were not re-certified within 2 years, as required, during Fiscal Year 2020, and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. Based on inquiry with the Department, these five PE sites processed a total of 314 presumptive eligibility determinations for Medicaid and CBHP after their re-certification due date during Fiscal Year 2020. The Department was unable to provide the total payments made on behalf of these beneficiaries during the presumptive eligibility period as of June 30, 2020, since these payments are not separately identified from regular Medicaid or CBHP payments in the system. As a result, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.State regulation [10 CCR 2505-10, 8.100.4.F (3)] requires the Department to re-certify the PE sites every 2 years to remain an approved site.LACK OF REVIEW OF PE SITES. We found several issues with the Department?s review of PE sites. Specifically we found the following:For 13 out of the 39 PE sites due for re-certification and a review (33 percent), the Department did not perform any case reviews to ensure that presumptive eligibility determinations were being made appropriately and in accordance with state and federal regulations by the PE site staff during Fiscal Year 2020.11 of 13 staff at three PE sites (85 percent) failed the Department?s review of presumptive eligibility determinations during the fiscal year. However, the Department was unable to provide adequate evidence that it provided training to these staff within 6 months of their failed reviews, as required by Department processes.Currently, for all 57 PE sites, the Department conducts reviews every 2 years, but only requires them to retain eligibility documentation for 1 year. As a result, the Department is able to monitor PE site?s eligibility determinations for only half of the period since the last review, leaving the other half unmonitored.Federal regulation (42 CFR 435.1102(b)(3)) requires the Department to ?establish oversight mechanisms to ensure that presumptive eligibility determinations are being made consistent with the statute and regulations?.According to the Department processes, staff are to review a sample of presumptive eligibility cases at PE site every 2 years when reviewing sites for re-certification. If a PE site?s staff fails a review, the Department requires the staff to undergo customized Department training within 6 months over the areas they failed.Green Book, Section 2, Paragraph OV2.02, states that the Green Book applies to all of an entity?s objectives: operations, reporting, and compliance. Additionally, Green Book, Paragraph 16.01, indicates that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations.MISSING DOCUMENTATION. In five of the 20 CBHP cases (25 percent) and five of the 20 Medicaid cases (25 percent) we tested, the Department was unable to provide evidence that the PE sites notified the counties or MA sites within five business days that the applicants were presumptively eligible.Federal regulation [42 CFR 435.1102(b)(2)(iii)] states that the presumptive eligibility sites are required to notify the local county or MA site within 5 business days that the client is presumptively eligible.SYSTEM DISPLAY ISSUE. In two of 20 CBHP cases (10 percent) and two of 20 Medicaid cases (10 percent), CBMS did not display the presumptive eligibility termination dates consistently between various screens. For example, in a Medicaid case, one screen showed a presumptive eligibility termination date of January 22, 2020, and the other screen showed a presumptive eligibility termination date of February 29, 2020. This system display issue did not affect the beneficiaries? presumptive eligibility and therefore there were no questioned costs.CBMS is designed to display case and applicant information consistently between various screens within the system.WHY DID THESE PROBLEMS OCCUR?The Department lacked sufficient internal controls to ensure that it complied with state and federal presumptive eligibility requirements during Fiscal Year 2020. Specifically, we noted the following causes for the errors we identified:LACK OF POLICIES AND PROCEDURES. The Department did not have written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, and the performance of timely re-certification of PE sites.LACK OF MONITORING. The Department lacked an effective tracking mechanism to monitor and identify PE sites that were due for re-certification every 2 years and to ensure presumptive eligibility determinations were in compliance with state and federal regulations.CBMS SYSTEM ISSUES. CBMS was not programmed to appropriately terminate presumptive eligibility when the beneficiary is enrolled in the regular Medicaid or CBHP program. In addition, CBMS has a system display issue that results in inconsistent applicant information being shown on various screens.WHY DO THESE PROBLEMS MATTER?As the State?s Medical Assistance agency, it is essential for the Department to ensure that PE sites? eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring benefits are paid only on behalf of eligible beneficiaries. Since CBMS determines eligibility for Medicaid and CBHP, the CBMS system issues we identified could result in erroneous eligibility determinations. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. By not ensuring that appropriate internal controls, including system controls, written policies and procedures, adequate reviews, and monitoring, are in place over the Medicaid and CBHP presumptive eligibility process, the Department cannot ensure that all Medicaid and CBHP beneficiaries are eligible to participate in the programs.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP2018CHIP2019CHIP2020XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018XIX-MAP2019XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0*KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*THE DEPARTMENT WAS UNABLE TO PROVIDE PRESUMPTIVE ELIGIBILITY BENEFITS PAYMENT INFORMATION FOR 314 CASES PROCESSED BY PE SITES THAT WERE NOT RE-CERTIFIED DURING FISCAL YEAR 2020.RECOMMENDATION2020-038The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over presumptive eligibility by:A Developing and implementing written policies and procedures detailing the requirements for completion of site reviews, maintenance of supporting documentation, timely training for failed presumptive eligibility (PE) site staff, and performance of timely re-certification of PE sites.B Developing an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every 2 years and ensuring the re-certifications are performed.C Resolving Colorado Benefits Management Systems (CBMS) programming and system issues to appropriately terminate applicants? presumptive eligibility when the beneficiaries are enrolled in regular Medicaid or Children?s Basic Health Plan program and ensuring CBMS displays consistent applicant information between various screens.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the re-certifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it.C AGREE. IMPLEMENTATION DATE: IMPLEMENTED.Implemented as of April 2021. The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it.AUDITOR?S ADDENDUM for Parts A, B, and CAs noted in the finding, we found five PE Sites that were not re-certified within the required 2 years and therefore, were not qualified to make presumptive eligibility determinations after their re-certification due date had passed. State regulation [10 CCR 2505-10, 8.100.4.F] requires the Department to re-certify the presumptive eligibility sites every 2 years to remain an approved site. The five PE sites processed a total of 314 presumptive eligibility determinations after their re-certification due date and before the Department re-certified the sites. The Department was unable to provide the total payments made on behalf of these 314 beneficiaries? prior to being enrolled in the regular Medicaid or CBHP program as of June 30, 2020. Therefore, we were unable to determine the amount of questioned costs the Department paid for these individuals during Fiscal Year 2020.
(A) The Department agrees with the audit recommendation to develop and implement formal written policies and procedures. Prior to this audit, the Department began creating formal written policies and procedures for site case reviews, maintenance of supporting documentation, timely training for failed workers, and performance of timely re-certification of presumptive eligibility sites (PE site). This finding had no known questionable cost associated with it.(B) The Department agrees with the audit recommendation to develop an effective tracking mechanism to identify and monitor PE sites that are due for re-certification every two years and ensuring that the recertifications are performed. Prior to this audit, the Department began developing a tracking mechanism for PE site re-certifications. This finding had no known questionable cost associated with it.(C) The Department has thoroughly researched the eligibility issues identified in this audit and made the changes to CBMS to ensure that applicants? presumptive eligibility has been appropriately terminated when the beneficiaries are enrolled in regular Medicaid or CBHP program, and that CBMS displays consistent applicant information between various screens. These issues were fixed through two system changes implemented in March 2020 and April 2021. This finding had no known questionable cost associated with it.
PROVIDER ELIGIBILITYThe providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP.Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible.In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020.Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers.We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year.We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations.In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment.In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020.The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.?STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license.FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services.CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP.FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s).WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section.ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSESINELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows:13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers.One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract.ELIGIBILITY CASE FILE ISSUESMISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations.INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner.POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance.LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020.WHY DO THESE PROBLEMS MATTER?By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs.Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP 2018CHIP2019CHIP2020XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018XIX-MAP2019XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-046B AND2019-046CRECOMMENDATION2020-039The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by:A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired.B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations.C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
Show full finding ▾Hide full finding ▴PROVIDER ELIGIBILITYThe providers of medical and related services covered under Medicaid and CBHP programs fall into a wide array of provider types that include clinics, hospitals, independent physicians, and medical technicians, as well as managed care organizations and health plans that contract with medical providers. As of June 30, 2020, approximately 76,960 entities and individuals were enrolled with the Department to provide services under Medicaid and CBHP.Although the Department is ultimately responsible for ensuring that only eligible providers participate in the Medicaid and CBHP programs, the Department has contracted with a fiscal agent to perform certain provider-enrollment and claims-processing activities, including accepting, processing, evaluating, and approving or rejecting applications. Providers that want to enroll must complete an online application within Colorado interChange and provide documentation, including a current medical license, showing that they fulfill all enrollment requirements based on their provider type. The fiscal agent is contractually responsible for evaluating the application and the relevant supporting documentation to ensure compliance with all state and federal enrollment requirements. The Department is responsible for maintaining current provider information in Colorado interChange. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible.In December 2019, the Department added a Department of Regulatory Agencies (DORA) license database interface within Colorado interChange in order to provide a mechanism for updating the provider?s medical license information including the expiration dates within Colorado interChange for any expired provider licenses. Department staff indicated that the provider licenses are manually reviewed at the time of enrollment by the fiscal agent and marked as active, meaning the providers are eligible to participate in the Medicaid and/or CBHP programs. On a monthly basis, the fiscal agent manually runs a report from the DORA database to identify the provider?s medical licenses that are about to expire and updates the renewed license information in Colorado interChange. If a provider?s license is expired, then the fiscal agent marks the provider for a review. Furthermore, the Department?s Program Integrity (PI) Division checks the DORA?s website monthly to determine if any action such as suspensions or revocations of licenses have been taken against a provider?s medical license. If the action taken against the provider affects the provider?s ability to participate in Medicaid or CBHP for a certain period, the PI Division then determines if the provider should be placed on a temporary restriction by suspending any payments, or be terminated within Colorado interChange to stop payments to the provider.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the enrollment and eligibility determinations of providers for Medicaid and CBHP services and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2020.Additionally, we assessed the Department?s progress in implementing our Fiscal Year 2019 recommendation related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls in this area to ensure that it complies with federal and state requirements related to data verification and maintenance of documentation, such as current provider licenses, to ensure payments are only made to eligible providers.We also obtained a detailed Suspension Listing from DORA, which contained provider medical licenses that were suspended during Fiscal Year 2020. We compared this Suspension Listing with provider information within Colorado interChange to determine whether the Department paid any providers with suspended licenses for claims during the fiscal year.We reviewed a sample of 45 provider applications for providers that were deemed eligible and received Medicaid and CBHP payments during Fiscal Year 2020 through Colorado interChange. We obtained and reviewed provider application information and relevant supporting documentation within Colorado interChange to determine whether these providers were accurately deemed eligible to receive Medicaid and CBHP payments and whether the required documents were maintained, in accordance with federal and state regulations.In addition, we conducted interviews with Department staff regarding its procedures over Medicaid and CBHP provider eligibility and enrollment.In March 2020, the Governor issued executive orders waiving Medicaid and CBHP provider licensing requirements for providers whose licenses expired during the COVID-19 PHE; as a result, our testwork was split into two periods of testing: (1) July 1, 2019, through February 29, 2020, and (2) March 1, 2020, through June 30, 2020.The process followed for provider eligibility and enrollment is the same for both Medicaid and CBHP providers, and our testing was used to determine compliance for both programs.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:FEDERAL REGULATION [42 CFR 455.412] requires that the Department have a method for verifying that any provider purporting to be licensed in accordance with the laws of any state is licensed by such state and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In May 2021, CMS provided clarification to the Department that ?not every condition on a provider?s license would be considered a limitation? and the PI Division within the Department needs to ?document in writing their determination to keep a provider enrolled when a license limitation does not restrict the provider?s ability to render services to Medicaid and CBHP beneficiaries to be in compliance with federal regulation.?STATE REGULATIONS [10 CCR 2505-10, 8.125.9 A AND B] require for current medical provider licenses, if a provider is required to possess a license or certification in order to provide services or supplies in the State, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.DEPARTMENT POLICY AND PROCEDURE. Provider Licensure Sanction Monitoring, Section III. A., states that in order for a provider to be eligible to render and bill for services, the provider must have an active license.FEDERAL CMS REQUIREMENTS [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001 (3))] state the Department must be able to produce documentation to support each of the provider screening and enrollment requirements under42 CFR 455 Subpart E, including documentation of the most current license to ensure the provider remains eligible to provide services.CONTRACT REQUIREMENTS. According to the contract agreement with the fiscal agent, the fiscal agent is required to maintain detailed documentation to support each of the provider screening and enrollment requirements, including documentation of the provider?s most current license to ensure the provider remains eligible to provide services for Medicaid and CBHP.FEDERAL REGULATION [45 CFR 75.303(a)] requires that the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book, Paragraph 16.01, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement(s).WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully comply with federal and state regulations for Medicaid and CBHP provider eligibility during Fiscal Year 2020. The specific issues we identified through our analyses of Medicaid and CBHP provider license data and case file reviews are outlined in more detail throughout this section.ELIGIBILITY ISSUES IDENTIFIED THROUGH DATA ANALYSESINELIGIBLE PROVIDERS?SUSPENDED LICENSES OR LICENSE WITH LIMITATIONS. Based on our comparison of the suspended provider license listing from DORA and provider information within Colorado interChange, we identified 13 ineligible providers who had their license suspended or had a license with limitations for part of Fiscal Year 2020, but continued to be shown as active, which means eligible, in Colorado interChange, as follows:13 providers had their licenses suspended by DORA during Fiscal Year 2020; however, instead of terminating these providers in accordance with federal and state regulations, the Department marked these providers as active within Colorado interChange. For four of the 13 providers, the Department did not take any action to prevent them from billing for services during the year. For the remaining nine providers, the Department placed billing restrictions on the providers after DORA?s suspension date. Specifically, for six of these nine providers, the Department placed billing restrictions on the providers within 1 to 2 months and for the remaining three providers, placed the billing restrictions on the providers between 3 to 12 months after DORA?s suspension date. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended by DORA and therefore, we did not identify any questioned costs associated with these providers.One provider had its license listed as active with conditions on DORA?s website from April 10, 2020, through June 30, 2020, but the Department did not terminate the provider due to current limitations on the license; instead, the provider was marked as active in Colorado interChange and continued to bill claims and receive payments during the fiscal year. We determined that the provider?s current license limitations did not restrict the provider?s ability to render services. Therefore, the provider was eligible and no questioned costs were noted. However, the Department did not document their determination to keep this provider enrolled with current license limitations. In addition, we noted that this provider?s license expired in Colorado interChange as of October 2016, however, DORA?s website showed the provider with an active license, or license with limitations, during Fiscal Year 2020. The fiscal agent did not update license information as required by the contract.ELIGIBILITY CASE FILE ISSUESMISSING DOCUMENTATION AND LICENSE INFORMATION. For five of 45 providers (11 percent), the Department did not ensure that the fiscal agent maintained the support of the most current medical license information as of June 30, 2020, within Colorado interChange to demonstrate that the provider was eligible to provide services. After we brought the issue to the Department?s attention, the Department provided the documentation. Additionally, for two of these five providers, we found that the medical license information maintained by the fiscal agent in Colorado interChange differed from the license information contained in the DORA database. For example, in one case, the provider?s license showed an expiration date of September 30, 2019, in Colorado interChange, while the accurate license expiration date in DORA?s database was September 30, 2021. Without the most current license information, the fiscal agent cannot appropriately verify ongoing eligibility for the providers.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place over the provider eligibility process during Fiscal Year 2020 to ensure that it complied with federal and state regulations.INEFFECTIVE REVIEW OF PROVIDER LICENSES. The Department lacks an effective review process to ensure the license information in DORA?s database matches the license information in Colorado interChange in order to identify suspended providers, to document their determination to keep a provider enrolled with license limitations, and providers with expired licenses. In addition, the Department?s manual review did not ensure that suspended providers, providers with license limitations and providers with expired licenses were terminated and restricted in a timely manner.POLICIES AND PROCEDURES NOT UPDATED. The Department did not obtain CMS guidance until May 2021 to document their determinations to keep providers with license limitations enrolled when a license limitation did not restrict provider?s ability to render services. Therefore, the Department?s current policies and procedures are not updated to match CMS guidance.LACK OF EFFECTIVE TRAINING AND MONITORING. The Department was not effectively training and monitoring its fiscal agent to ensure that copies of active medical licenses are maintained within providers? files in Colorado interChange. Additionally, the fiscal agent did not properly update the provider?s license information in Colorado interChange to match the DORA database during Fiscal Year 2020.WHY DO THESE PROBLEMS MATTER?By not ensuring that appropriate internal controls, including policies and procedures, reviews, training, and monitoring, are in place over the Medicaid and CBHP provider eligibility process, the Department cannot ensure that all Medicaid and CBHP providers are eligible to participate in the programs. Additionally, without an effective review process to update provider licensure information within Colorado interChange, the Department cannot ensure that the enrolled providers are eligible to receive payments. Ensuring that providers contained in Colorado interChange are eligible to provide services is especially important to prevent any improper payments. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows ineligible providers to bill and be paid for services provided for these programs.Furthermore, the State may lose federal Medicaid money if the Department does not recover any of the payments made to ineligible providers. State statute [Section 25.5-4-301(2), C.R.S.] indicates that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS CHIP 2018CHIP2019CHIP2020XIX-ADM2018XIX-ADM2019 XIX-ADM2020XIX-MAP2018XIX-MAP2019XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-046B AND2019-046CRECOMMENDATION2020-039The Department of Health Care Policy and Financing (Department) should improve its internal controls over the Medicaid and Children?s Basic Health Plan provider eligibility determination to ensure that it complies with federal and state requirements by:A Improving the Department?s review process of provider licenses to ensure the license information in the Department of Regulatory Agencies (DORA) license database matches the license information in the Colorado interChange system and ensuring timely termination and imposing restrictions for the provider?s whose licenses are suspended or expired.B Updating the current policies and procedures to match Centers for Medicare and Medicaid Services guidance to ensure there is adequate documentation of the determinations for providers with license limitations.C Effectively training and monitoring its fiscal agent to ensure that copies of active licenses are maintained and provider license information in the Colorado interChange system matches the information in DORA?s license database.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
(A) The Department will update its policies and procedures to ensure that the process for reviewing whether a license action requires termination or a restriction in the Colorado interChange, is documented and implemented in a timely manner to prevent payments to ineligible providers. As noted in OSA's finding, it is best practice for the Department to verify providers meet these standards on an ongoing basis between initial enrollment and revalidation to ensure there are no current limitations on the provider?s license, including those that have expired. The Department?s previous process was discontinued due to data matching issues between DORA and the Colorado interChange. However, letters continue to be sent to providers with upcoming expiring licenses prompting them to add current license information to their provider file. The Department plans to implement a system change that will make the data feed from DORA functional and install a front-end claims edit that will prevent claims from providers with an expired license from paying.(B) The Department will update its policies and procedures to ensure that all determinations made on whether a provider has a limitation on its license are properly documented.(C) The Department has an established process to train and monitor its fiscal agent. The Department will continue to monitor the Fiscal Agent through reports, meetings, and quarterly audit review processes. The Department and the Fiscal Agent will continue to collaborate to improve the process in which required documentation is collected and maintained.
2019-046
MEDICAID NATIONAL CORRECT CODING INITIATIVECMS launched the National Correct Coding Initiative (NCCI) in 2010 to promote national coding methodologies and to reduce improper coding, which may result in inappropriate payments of Medicaid claims. Through this initiative, CMS periodically creates edit files, which the states are required to incorporate into their claims processing systems, including Colorado interChange. These edit files contain sensitive information designed to identify and prevent improper payments, based on the types and amounts of services that are included in the claims. CMS has also issued a Medicaid NCCI Technical Guidance Manual (technical guidance) that provides information for state Medicaid agencies with specific instructions to implement these edit files.The Department contracts with a fiscal agent to execute the NCCI methodologies and incorporate the edit files into Colorado interChange. Given the sensitive nature of the information in the edit files, the Department is ultimately responsible for ensuring confidentiality and compliance with the NCCI technical guidance and program requirements.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the Medicaid NCCI process and to determine whether the Department complied with applicable federal requirements and technical guidance during Fiscal Year 2020. In addition, we reviewed the contract in place between the Department and the fiscal agent during Fiscal Year 2020 to determine whether the contract included a confidentiality agreement that has all of the provisions that CMS requires, as specified in technical guidance.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [Affordable Care Act (2010), Section 6507(2)(A)(iii)(I) and (II)] require that CMS informs states as to how they must incorporate the NCCI methodologies for claims filed under Medicaid. This regulation requires the Department to incorporate NCCI methodologies into claims processing for the Medicaid program.The technical guidance [Section 7.1.2] specifies seven minimum elements that must be included in each State?s confidentiality agreements, including those incorporated into contracts with any outside party, such as fiscal agents using the Medicaid NCCI edit files. These seven elements specify requirements, such as who may be granted access to the edit files, when the files may be implemented in the claims processing system, and penalties imposed for violations of any confidentiality agreement relating to the use of edit files.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department did not include five of the seven required provisions in the confidentiality agreement section of its contract in place during Fiscal Year 2020 with its fiscal agent as required by the technical guidance. Specifically, the contract did not include the following required elements for the fiscal agent:? Limiting the disclosures to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter.? After the start of the new calendar quarter, the fiscal agent may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage.? The fiscal agent shall not implement new, revised, or deleted Medicaid NCCI edits prior to the first day of the calendar quarter.? Only the Department has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the Medicaid Integrity Institute (MII).? The Department must impose penalties on the fiscal agent, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files.WHY DID THIS PROBLEM OCCUR?The Department lacked an adequate contract review process to ensure that the confidentiality-agreement section of the contract with the fiscal agent included all of the elements that are required to be in compliance with federal regulations and technical guidance.WHY DOES THIS PROBLEM MATTER?Because the Medicaid NCCI edit files contain sensitive information and are designed to identify and prevent improper payments, the Department risks the disclosure of confidential information without having a confidentiality agreement with all the requirements in place with its fiscal agent. Furthermore, by not including the confidentiality-agreement requirements that are specified in the technical guidance within the contract with the fiscal agent, the Department risks failing to comply with federal regulations and technical guidance.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-ADM2018 XIX-MAP2018XIX-ADM2019 XIX-MAP2019XIX-ADM2020 XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-040The Department of Health Care Policy and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: DECEMBER 2021.The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: DECEMBER 2021.The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
Show full finding ▾Hide full finding ▴MEDICAID NATIONAL CORRECT CODING INITIATIVECMS launched the National Correct Coding Initiative (NCCI) in 2010 to promote national coding methodologies and to reduce improper coding, which may result in inappropriate payments of Medicaid claims. Through this initiative, CMS periodically creates edit files, which the states are required to incorporate into their claims processing systems, including Colorado interChange. These edit files contain sensitive information designed to identify and prevent improper payments, based on the types and amounts of services that are included in the claims. CMS has also issued a Medicaid NCCI Technical Guidance Manual (technical guidance) that provides information for state Medicaid agencies with specific instructions to implement these edit files.The Department contracts with a fiscal agent to execute the NCCI methodologies and incorporate the edit files into Colorado interChange. Given the sensitive nature of the information in the edit files, the Department is ultimately responsible for ensuring confidentiality and compliance with the NCCI technical guidance and program requirements.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the Medicaid NCCI process and to determine whether the Department complied with applicable federal requirements and technical guidance during Fiscal Year 2020. In addition, we reviewed the contract in place between the Department and the fiscal agent during Fiscal Year 2020 to determine whether the contract included a confidentiality agreement that has all of the provisions that CMS requires, as specified in technical guidance.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [Affordable Care Act (2010), Section 6507(2)(A)(iii)(I) and (II)] require that CMS informs states as to how they must incorporate the NCCI methodologies for claims filed under Medicaid. This regulation requires the Department to incorporate NCCI methodologies into claims processing for the Medicaid program.The technical guidance [Section 7.1.2] specifies seven minimum elements that must be included in each State?s confidentiality agreements, including those incorporated into contracts with any outside party, such as fiscal agents using the Medicaid NCCI edit files. These seven elements specify requirements, such as who may be granted access to the edit files, when the files may be implemented in the claims processing system, and penalties imposed for violations of any confidentiality agreement relating to the use of edit files.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department did not include five of the seven required provisions in the confidentiality agreement section of its contract in place during Fiscal Year 2020 with its fiscal agent as required by the technical guidance. Specifically, the contract did not include the following required elements for the fiscal agent:? Limiting the disclosures to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter.? After the start of the new calendar quarter, the fiscal agent may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage.? The fiscal agent shall not implement new, revised, or deleted Medicaid NCCI edits prior to the first day of the calendar quarter.? Only the Department has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the Medicaid Integrity Institute (MII).? The Department must impose penalties on the fiscal agent, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files.WHY DID THIS PROBLEM OCCUR?The Department lacked an adequate contract review process to ensure that the confidentiality-agreement section of the contract with the fiscal agent included all of the elements that are required to be in compliance with federal regulations and technical guidance.WHY DOES THIS PROBLEM MATTER?Because the Medicaid NCCI edit files contain sensitive information and are designed to identify and prevent improper payments, the Department risks the disclosure of confidential information without having a confidentiality agreement with all the requirements in place with its fiscal agent. Furthermore, by not including the confidentiality-agreement requirements that are specified in the technical guidance within the contract with the fiscal agent, the Department risks failing to comply with federal regulations and technical guidance.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-ADM2018 XIX-MAP2018XIX-ADM2019 XIX-MAP2019XIX-ADM2020 XIX-MAP2020FEDERAL AWARD YEARS 2018, 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-040The Department of Health Care Policy and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: DECEMBER 2021.The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.and Financing should ensure it has strong internal controls over and complies with requirements related to the National Correct Coding Initiative (NCCI) process for the federal Medicaid program by incorporating all required confidentiality agreement provisions within its contract with its fiscal agent.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGAGREE. IMPLEMENTATION DATE: DECEMBER 2021.The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
The NCCI `Confidentiality Agreements Requirements for Contracted Parties? was first published in October 2018?s Medicaid NCCI Technical Guidance Manual. The current and previous guidance manual `Medicaid NCCI Edit Design Manual? has been used by the Department for technical assistance for implementing the NCCI edits correctly and completely. In addition, the Department's current Colorado interChange contract without these provisions was approved by CMS. Following the recommendation by the auditor, the Department is scheduled to include the five required provisions in the confidentiality agreement section in a future contract amendment with the Department?s Colorado interChange vendor.
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERSA beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS.The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange.Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe.During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries.From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons.After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.?Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program.State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states:An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows:i) that person cannot be determined eligible for the Medical Assistance Program; and/orii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated.The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.?Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange.MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted.In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year.The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received.Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019.We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that:? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange.? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019.? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions.The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS.WHY DID THESE PROBLEMS OCCUR?For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS.Other problems with missing SSNs were related to:? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file.? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations.? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program.WHY DO THESE PROBLEMS MATTER?As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $2,285,757THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-043The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by:A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number.B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems.C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program.D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021.D DISAGREE.The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process.AUDITOR?S ADDENDUM:The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf.In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERSA beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS.The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange.Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe.During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries.From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons.After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.?Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program.State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states:An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows:i) that person cannot be determined eligible for the Medical Assistance Program; and/orii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated.The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.?Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange.MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted.In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year.The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received.Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019.We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that:? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange.? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019.? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions.The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS.WHY DID THESE PROBLEMS OCCUR?For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS.Other problems with missing SSNs were related to:? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file.? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations.? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program.WHY DO THESE PROBLEMS MATTER?As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $2,285,757THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-043The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by:A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number.B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems.C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program.D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021.D DISAGREE.The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process.AUDITOR?S ADDENDUM:The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf.In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
(A) The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022.(C) Partial Implemented. Project 14361 was implemented 12/2020. reduce the invalid data changes from interfacing from SIDMOD (State?Identification?Module. Noted that?CDHS (Colorado Department of Health Services) systems and Colorado HCPF (Department of Health Care Policy and Financing) systems use?SIDMOD?to assign a State ID (State Identification Number (Medicaid #)?to a client to be used for a single Client Identifier for shared clients) to CBMS (adding or removing a SSN). Users now need to review and address the SSN discrepancy and approve/reject the changes. Another project that was implemented 6/28/2020, was Project 13889. This dashboard also identifies members that are active with no SSN without exemptions. The dashboard monitors eligibility errors, interfaces, data entry, eligibility results, etc. with each phase building upon the other. In the 2nd implementation phase we will build on elements to produce data. The 2nd phase is projected to be implemented by July 2022.
2019-043
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID CLAIMS PAYMENTSIndividuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS.Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive.CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019.During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid.Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments.Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable??According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows:? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289.? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031.These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs.PROJECTED SAMPLE RESULTSJULY 1, 2018, THROUGH MARCH 31, 2019Known Questioned Costs (Statistical Sample)(July 2018 through March 2019) $171,559Known Questioned Costs (Not Projected)(April 2019 through June 2019) $9,761TOTAL KNOWN QUESTIONED COSTS $181,320Total Projected Questioned Costs(July 2018 through March 2019) $1,007,146LESS: Known Questioned Costs(July 2018 through March 2019) ($171,559)LIKELY QUESTIONED COSTS $835,587TOTAL KNOWN AND LIKELY QUESTIONED COSTS $1,016,907SOURCE: Office of the State Auditor analysis of Department data.The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments.WHY DID THESE PROBLEMS OCCUR?Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries.After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute.WHY DO THESE PROBLEMS MATTER?Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $181,320THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-045A* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-044The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by:A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries.B Identifying and correcting any additional cases affected by the system issues noted in our audit.C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.C AGREE. IMPLEMENTATION DATE: JULY 2021.Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID CLAIMS PAYMENTSIndividuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS.Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive.CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019.During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid.Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments.Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.?Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable??According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows:? In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289.? In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031.These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs.PROJECTED SAMPLE RESULTSJULY 1, 2018, THROUGH MARCH 31, 2019Known Questioned Costs (Statistical Sample)(July 2018 through March 2019) $171,559Known Questioned Costs (Not Projected)(April 2019 through June 2019) $9,761TOTAL KNOWN QUESTIONED COSTS $181,320Total Projected Questioned Costs(July 2018 through March 2019) $1,007,146LESS: Known Questioned Costs(July 2018 through March 2019) ($171,559)LIKELY QUESTIONED COSTS $835,587TOTAL KNOWN AND LIKELY QUESTIONED COSTS $1,016,907SOURCE: Office of the State Auditor analysis of Department data.The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments.WHY DID THESE PROBLEMS OCCUR?Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries.After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute.WHY DO THESE PROBLEMS MATTER?Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $181,320THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-045A* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-044The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by:A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries.B Identifying and correcting any additional cases affected by the system issues noted in our audit.C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.C AGREE. IMPLEMENTATION DATE: JULY 2021.Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
(A) Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS.(B) Members identified on the reconciliation reports were being manually updated until March 2020. CMS instructed the Department to cease work on these cases when the PHE was implemented. During the PHE the Department was not allowed to terminate benefits for anyone receiving benefits prior to March 2020, even if eligibility was determined incorrectly prior to the PHE. During this unprecedented time, the authority and operations regarding these cases was not immediately available. The auditors? retrospective review fails to address the uncertainty that occurred during this period of the PHE. The Department agrees to resume work on the manual reconciliation process when authorized by CMS.(C) Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. This has been completed.
2019-044
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID ELIGIBILITY?DUPLICATE SSNS AND STATE IDSThe beneficiary?s application includes information, such as an SSN, birth certificate, and support for their income. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services.As each beneficiary has one SSN, similarly, each beneficiary in CBMS is assigned a unique State ID by a separate system managed by OIT. CBMS interfaces with Colorado interchange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had adequate internal controls in place over the Medicaid eligibility determination process during Fiscal Year 2019, including controls to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN in CBMS.During our audit, we requested a list of all Medicaid claims that were submitted and paid for medical services from July 1, 2018, through March 31, 2019, including the beneficiaries? names, SSNs, and State IDs. This list included approximately 1.1 million beneficiaries who had received benefits during the time period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN, and to determine if any claims payments were made on behalf of any such beneficiaries during Fiscal Year 2019. In addition, we analyzed the list of these Medicaid claims payments provided by the Department from Colorado interChange to identify any claims payments made on behalf of different beneficiary?s names with the same State ID and date of birth during Fiscal Year 2019.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish his or her SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified 131 instances in which 262 Medicaid claims payments in Colorado interChange were made on behalf of beneficiaries with the same SSN but a different State ID. In 67 of these instances, the beneficiaries had the same SSN and same name and in the remaining 64 instances, the beneficiaries had the same SSN but different names. In all 131 instances, the same SSN was linked to two different State IDs in Colorado interChange.See Table in Schedule of Findings and Questioned CostsAll of these cases were active and associated with claims paid through Colorado interChange from July 1, 2018, through March 31, 2019. We selected a random sample of 10 SSNs from 131 instances with multiple State IDs and determined that each of the 10 were associated with two individuals with either different names, genders, and/or dates of birth. These issues affected a total of 262 Medicaid cases representing 262 Medicaid claims payments totaling $53,171 from July 1, 2018, through March 31, 2019.We identified 118 additional claims that were paid on behalf of 62 different beneficiary names using the same State ID and date of birth combination. We specifically noted that 33 different providers submitted 118 separate claims to the Department for this State ID/SSN/date of birth on behalf of 62 different individuals with different names and genders during Fiscal Year 2019. The providers were paid a total of $16,678 for the claims during Fiscal Year 2019. For example, one claim of $226 was submitted and paid for an individual named ?A Test.?See Table in Schedule of Findings and Questioned CostsAs of the end of our audit, the Department was researching whether these 262 Medicaid cases of duplicate SSNs and State IDs that we identified, as well as the 118 claims paid under 62 different names with one State ID, were eligible for the services provided and that the payments were appropriate. Because of the issues noted above, at the time of our audit, we were unable to determine whether the payments were made on behalf of eligible Medicaid beneficiaries and therefore, consider all $69,849 of the payments to be known questioned costs; $34,925 of these costs were paid with federal grant funds.For the purposes of identifying and quantifying these amounts, we have applied the following definition included in our audit requirements:Questioned cost, as defined in Uniform Guidance [2 CFR 200.84], is ?a cost that is questioned by the auditor?(a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation...?We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [2 CFR 200.516] as questioned costs that are specifically identified by the auditor.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place during Fiscal Year 2019 to prevent or detect instances of duplicate SSNs and/or multiple State IDs in CBMS and Colorado interChange, as noted:? CBMS ALLOWED DUPLICATE SSNS AND MULTIPLE STATE IDS. CBMS allowed caseworkers to create more than one case for a Medicaid beneficiary; as a result, an individual beneficiary could be assigned more than one State ID in CBMS and the multiple State IDs wre uploaded to Colorado interChange and treated as two separate accounts with the ability to have claims paid against them. Furthermore, the Department reported that CBMS did not have a system edit check that would flag for review and disallow the same SSNs or multiple State IDs for the same SSN.? LACK OF TRAINING, MONITORING, AND REVIEW. The Department did not monitor and effectively train local county and MA site caseworkers regarding identifying and merging multiple State IDs for the same beneficiary in CBMS. Department staff reported that they did not have a monitoring process in place to review the data in CBMS to ensure that local counties and MA sites were properly identifying, investigating, and merging multiple State IDs for the same beneficiary. Furthermore, the Department did not have an effective review process to analyze CBMS data to identify multiple State IDs and duplicate SSNs and remove them appropriately.? INEFFECTIVE PAYMENT VERIFICATION PROCESS. The Department, through Colorado interChange, used only State ID and date of birth field matches to verify a beneficiary for claims payments. As a result, Colorado interChange was making payments on behalf of an eligible Medicaid beneficiary for individuals whose names differed from the eligible beneficiary. Based on our follow-up discussions with the Department, they indicated that it would be inefficient to verify claims using the name fields because the names could change during the year; however, in order to avoid the improper payment of Medicaid claims, the Department needed to develop a more effective beneficiary payment verification process in Colorado interChange to ensure that payments were not made on behalf of multiple individuals using the same State ID and date of birth. After we brought this to the Department?s attention, they began to review and investigate these claims for overpayments.WHY DO THESE PROBLEMS MATTER?Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the local counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, such as system edit functions, effective ongoing staff training, and reviewing the local counties and MA sites; the State cannot substantiate that eligibility determinations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. If an eligible individual has more than one State ID, providers could fraudulently submit duplicate claims under these IDs for the same services resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019* XIX-ADM2017XIX-ADM2018XIX-ADM2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $69,849THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-045The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by:A Working with the Department of Human Services and Governor?s Office of Information Technology, as appropriate, to evaluate and institute, if feasible, a system check within Colorado Benefits Management System (CBMS) to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS.B Improving the effectiveness of training and monitoring of the local counties and Medical Assistance (MA) sites to ensure that caseworkers are not creating new cases when they are attempting to update a beneficiary?s information to an already existing case file. This should include focused training for the local counties and MA sites on identifying and merging any duplicate case files existing within CBMS.C Working with the Department of Human Services, as appropriate, to evaluate and develop, if feasible, an effective beneficiary payment verification process in Colorado interChange to ensure that payments are not made on behalf of multiple individuals using the same State ID and date of birth. This should include researching the claims payments that were identified during our audit to determine whether or not these were appropriate payments in accordance with federal regulations.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to work with the Governor's Office of Information Technology (OIT) on the feasibility of instituting a system check within CBMS to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. Since CBMS is a shared system between the Department and the Department of Human Services, and that State IDs are generated by a separate system managed by OIT, the Department cannot guarantee that specific system checks as prescribed through this audit recommendation can be implemented and the timeline to implement a related system change is unknown. Therefore, the Department can agree to research on the feasibility, and if feasible, implement a system check by July 2022.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department provides training to counties and Medical Assistance sites on how to merge any duplicate case files existing within CBMS. There are multiple user manuals regarding this process and there are two specific web-based trainings which are both required for all caseworkers. The Department agrees to work with counties to identify any additional training, reporting, or monitoring related to the case file merge process that would be useful to caseworkers. The Department can agree to implement additional training by July 2021.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department's approach to claims editing using State ID and date-of-birth are Medicaid industry standards. The Department can agree to research how other payers edit claims for beneficiary information, such as name or other information that is available on a claim. Further, the Department's ability to modify claims editing based on beneficiary information has the potential to impact third-party claims submitted by other payers such as Medicare. Therefore, the Department cannot modify the Department's claims processing system until that research has been performed. The Department will research and report on the feasibility, and if feasible, implement any system change by July 2021. In addition, the Department agrees to research the claims payments that were identified through the audit to determine whether the payments were appropriate by July 2021.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID ELIGIBILITY?DUPLICATE SSNS AND STATE IDSThe beneficiary?s application includes information, such as an SSN, birth certificate, and support for their income. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services.As each beneficiary has one SSN, similarly, each beneficiary in CBMS is assigned a unique State ID by a separate system managed by OIT. CBMS interfaces with Colorado interchange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had adequate internal controls in place over the Medicaid eligibility determination process during Fiscal Year 2019, including controls to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN in CBMS.During our audit, we requested a list of all Medicaid claims that were submitted and paid for medical services from July 1, 2018, through March 31, 2019, including the beneficiaries? names, SSNs, and State IDs. This list included approximately 1.1 million beneficiaries who had received benefits during the time period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN, and to determine if any claims payments were made on behalf of any such beneficiaries during Fiscal Year 2019. In addition, we analyzed the list of these Medicaid claims payments provided by the Department from Colorado interChange to identify any claims payments made on behalf of different beneficiary?s names with the same State ID and date of birth during Fiscal Year 2019.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish his or her SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination.Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified 131 instances in which 262 Medicaid claims payments in Colorado interChange were made on behalf of beneficiaries with the same SSN but a different State ID. In 67 of these instances, the beneficiaries had the same SSN and same name and in the remaining 64 instances, the beneficiaries had the same SSN but different names. In all 131 instances, the same SSN was linked to two different State IDs in Colorado interChange.See Table in Schedule of Findings and Questioned CostsAll of these cases were active and associated with claims paid through Colorado interChange from July 1, 2018, through March 31, 2019. We selected a random sample of 10 SSNs from 131 instances with multiple State IDs and determined that each of the 10 were associated with two individuals with either different names, genders, and/or dates of birth. These issues affected a total of 262 Medicaid cases representing 262 Medicaid claims payments totaling $53,171 from July 1, 2018, through March 31, 2019.We identified 118 additional claims that were paid on behalf of 62 different beneficiary names using the same State ID and date of birth combination. We specifically noted that 33 different providers submitted 118 separate claims to the Department for this State ID/SSN/date of birth on behalf of 62 different individuals with different names and genders during Fiscal Year 2019. The providers were paid a total of $16,678 for the claims during Fiscal Year 2019. For example, one claim of $226 was submitted and paid for an individual named ?A Test.?See Table in Schedule of Findings and Questioned CostsAs of the end of our audit, the Department was researching whether these 262 Medicaid cases of duplicate SSNs and State IDs that we identified, as well as the 118 claims paid under 62 different names with one State ID, were eligible for the services provided and that the payments were appropriate. Because of the issues noted above, at the time of our audit, we were unable to determine whether the payments were made on behalf of eligible Medicaid beneficiaries and therefore, consider all $69,849 of the payments to be known questioned costs; $34,925 of these costs were paid with federal grant funds.For the purposes of identifying and quantifying these amounts, we have applied the following definition included in our audit requirements:Questioned cost, as defined in Uniform Guidance [2 CFR 200.84], is ?a cost that is questioned by the auditor?(a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation...?We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [2 CFR 200.516] as questioned costs that are specifically identified by the auditor.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place during Fiscal Year 2019 to prevent or detect instances of duplicate SSNs and/or multiple State IDs in CBMS and Colorado interChange, as noted:? CBMS ALLOWED DUPLICATE SSNS AND MULTIPLE STATE IDS. CBMS allowed caseworkers to create more than one case for a Medicaid beneficiary; as a result, an individual beneficiary could be assigned more than one State ID in CBMS and the multiple State IDs wre uploaded to Colorado interChange and treated as two separate accounts with the ability to have claims paid against them. Furthermore, the Department reported that CBMS did not have a system edit check that would flag for review and disallow the same SSNs or multiple State IDs for the same SSN.? LACK OF TRAINING, MONITORING, AND REVIEW. The Department did not monitor and effectively train local county and MA site caseworkers regarding identifying and merging multiple State IDs for the same beneficiary in CBMS. Department staff reported that they did not have a monitoring process in place to review the data in CBMS to ensure that local counties and MA sites were properly identifying, investigating, and merging multiple State IDs for the same beneficiary. Furthermore, the Department did not have an effective review process to analyze CBMS data to identify multiple State IDs and duplicate SSNs and remove them appropriately.? INEFFECTIVE PAYMENT VERIFICATION PROCESS. The Department, through Colorado interChange, used only State ID and date of birth field matches to verify a beneficiary for claims payments. As a result, Colorado interChange was making payments on behalf of an eligible Medicaid beneficiary for individuals whose names differed from the eligible beneficiary. Based on our follow-up discussions with the Department, they indicated that it would be inefficient to verify claims using the name fields because the names could change during the year; however, in order to avoid the improper payment of Medicaid claims, the Department needed to develop a more effective beneficiary payment verification process in Colorado interChange to ensure that payments were not made on behalf of multiple individuals using the same State ID and date of birth. After we brought this to the Department?s attention, they began to review and investigate these claims for overpayments.WHY DO THESE PROBLEMS MATTER?Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the local counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, such as system edit functions, effective ongoing staff training, and reviewing the local counties and MA sites; the State cannot substantiate that eligibility determinations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. If an eligible individual has more than one State ID, providers could fraudulently submit duplicate claims under these IDs for the same services resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019* XIX-ADM2017XIX-ADM2018XIX-ADM2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $69,849THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-045The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by:A Working with the Department of Human Services and Governor?s Office of Information Technology, as appropriate, to evaluate and institute, if feasible, a system check within Colorado Benefits Management System (CBMS) to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS.B Improving the effectiveness of training and monitoring of the local counties and Medical Assistance (MA) sites to ensure that caseworkers are not creating new cases when they are attempting to update a beneficiary?s information to an already existing case file. This should include focused training for the local counties and MA sites on identifying and merging any duplicate case files existing within CBMS.C Working with the Department of Human Services, as appropriate, to evaluate and develop, if feasible, an effective beneficiary payment verification process in Colorado interChange to ensure that payments are not made on behalf of multiple individuals using the same State ID and date of birth. This should include researching the claims payments that were identified during our audit to determine whether or not these were appropriate payments in accordance with federal regulations.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to work with the Governor's Office of Information Technology (OIT) on the feasibility of instituting a system check within CBMS to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. Since CBMS is a shared system between the Department and the Department of Human Services, and that State IDs are generated by a separate system managed by OIT, the Department cannot guarantee that specific system checks as prescribed through this audit recommendation can be implemented and the timeline to implement a related system change is unknown. Therefore, the Department can agree to research on the feasibility, and if feasible, implement a system check by July 2022.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department provides training to counties and Medical Assistance sites on how to merge any duplicate case files existing within CBMS. There are multiple user manuals regarding this process and there are two specific web-based trainings which are both required for all caseworkers. The Department agrees to work with counties to identify any additional training, reporting, or monitoring related to the case file merge process that would be useful to caseworkers. The Department can agree to implement additional training by July 2021.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department's approach to claims editing using State ID and date-of-birth are Medicaid industry standards. The Department can agree to research how other payers edit claims for beneficiary information, such as name or other information that is available on a claim. Further, the Department's ability to modify claims editing based on beneficiary information has the potential to impact third-party claims submitted by other payers such as Medicare. Therefore, the Department cannot modify the Department's claims processing system until that research has been performed. The Department will research and report on the feasibility, and if feasible, implement any system change by July 2021. In addition, the Department agrees to research the claims payments that were identified through the audit to determine whether the payments were appropriate by July 2021.
(A) In December 2020 Project 14361 was implemented to reduce the invalid data changes from interfacing from SIDMOD (State?Identification?Module. Noted that?CDHS (Colorado Department of Health Services) systems and Colorado HCPF (Department of Health Care Policy and Financing) systems use?SIDMOD?to assign a State ID (State Identification Number (Medicaid #)??to a client to be used for a single Client Identifier for shared clients) to CBMS (adding or removing a SSN). Users now need to review and address the SSN discrepancy and approve/reject the changes.(B) Duplicate IDs and Merge Process online training revised 11/20/2020. This web based training demonstrates the process for determining if a new customer already has a Client ID or a State ID in CBMS. Individuals completing this course will be able to define the term ?merge.? They will be prepared to search CBMS to determine if a new customer already has a Client ID or a State ID, and be able to choose which ID to use when multiple IDs are found.(C) In December 2020 Project 14361 was implemented to reduce the invalid data changes from interfacing from SIDMOD (State?Identification?Module. Noted that?CDHS (Colorado Department of Health Services) systems and Colorado HCPF (Department of Health Care Policy and Financing) systems use?SIDMOD?to assign a State ID (State Identification Number (Medicaid #)??to a client to be used for a single Client Identifier for shared clients) to CBMS (adding or removing a SSN). Users now need to review and address the SSN discrepancy and approve/reject the changes.
2019-045
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.PROVIDER ELIGIBILITYMedicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP.The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements.Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019.Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019.We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations.In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year.Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested:? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested:? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system.? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.?? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information.According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program.Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system.As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required.? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows:? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019.? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required.Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment.Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department.Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement.? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows:? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds.? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers.Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license.This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.?Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary??WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first.Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit.Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized.WHY DO THESE PROBLEMS MATTER?By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $15,061THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-046A, 2018-046B, 2018-046C, 2018-056A, 2018-056B, 2017-055A, AND 2017-055B* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-046The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by:A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers.B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance).C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance.D Ensuring that Colorado interChange displays provider information consistently throughout the system.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23.B DISAGREE.The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2).AUDITOR?S ADDENDUM:As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended.C AGREE. IMPLEMENTATION DATE: JULY 2020.The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21.D DISAGREE.There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually.AUDITOR?S ADDENDUM:The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.PROVIDER ELIGIBILITYMedicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP.The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements.Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019.Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019.We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations.In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year.Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested:? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested:? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system.? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.?? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information.According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program.Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system.As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required.? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows:? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019.? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required.Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment.Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department.Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement.? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows:? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds.? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers.Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license.This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.?Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary??WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first.Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit.Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized.WHY DO THESE PROBLEMS MATTER?By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017*XIX-MAP2018*XIX-MAP2019*XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $15,061THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-046A, 2018-046B, 2018-046C, 2018-056A, 2018-056B, 2017-055A, AND 2017-055B* ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2019-046The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by:A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers.B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance).C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance.D Ensuring that Colorado interChange displays provider information consistently throughout the system.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2022.The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23.B DISAGREE.The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2).AUDITOR?S ADDENDUM:As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended.C AGREE. IMPLEMENTATION DATE: JULY 2020.The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21.D DISAGREE.There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually.AUDITOR?S ADDENDUM:The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
(A) The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23.
2019-046
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MONITORING OF HEALTH AND SAFETY SURVEYS AND CERTIFICATIONSMedical providers, such as nursing facilities, intermediate care facilities for individuals with intellectual disabilities (ICF/IIDs), and hospitals providing nursing facility services, must meet minimum standards for certification by the state and/or federal governments to be eligible to receive payments for services provided to Medicaid-eligible beneficiaries. The Department and the Colorado Department of Public Health and Environment (CDPHE) are responsible under state statute for this work. The Department categorizes hospital providers of nursing facility services under Colorado Medicaid Skilled Nursing Facility providers.The Department, as the state agency that is ultimately responsible for administering Medicaid, has overall responsibility for ensuring that all medical providers receiving Medicaid funding comply with regulatory health and safety standards. The Department has an interagency agreement with CDPHE, the designated state survey agency, to conduct health care entity inspections, or surveys, of Medicaid providers as outlined in state statutes and in agreements with the Centers for Medicare and Medicaid Services (CMS).A standard survey is a type of survey conducted to assess compliance with federal regulations specific to health and safety. After conducting each survey, CDPHE staff enter information, such as survey date and deficiencies noted, into their database; this information is then extracted and compiled by CMS and displayed on CMS? Survey and Certification?s Quality, Certification and Oversight Reports website?CMS?s certification and reporting website. Once a health care facility passes its survey, CDPHE is responsible for making a recommendation for certification to the Department. The Department is responsible for monitoring CDPHE to ensure that the minimum standards for certification are met by each Medicaid-approved provider, and for approving CDPHE?s recommendations for certification. During Fiscal Year 2019, the Department paid CDPHE approximately $5.7 million for completing state surveys and certifications.The Department receives monthly reports from CDPHE detailing the results of the surveys and certifications performed on skilled nursing facilities and ICF/IIDs. In addition, the Department holds monthly meetings with CDPHE to discuss the surveys and certifications. The Department uses these reports and discussions to determine if there are any issues or deficiencies with any skilled nursing facilities and ICF/IIDs. Additionally, CDPHE is responsible for informing the Department directly if a facility has any critical violations because of a survey and the Department can then suspend payments to that facility.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department had adequate internal controls in place over the monitoring of CDPHE?s health and safety surveys for skilled nursing facilities and ICF/IIDs, and complied with the related federal and state requirements during Fiscal Year 2019.In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to monitoring of health and safety survey and certifications. During that audit, we recommended that the Department strengthen its internal controls over provider health and safety standards by following its current policy for monitoring CDPHE?s standard surveys and certifications, updating the policy to maintain monitoring documentation, and developing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities and ICF/IIDs.As part of our audit, we reviewed a sample of 40 skilled nursing facilities and ICF/IIDs that received a Medicaid payment for services provided during Fiscal Year 2019 in order to determine if the Department ensured that CDPHE performed the required surveys in accordance with federal and state regulations.For the sample of skilled nursing facilities and ICF/IIDs, we reviewed the date of the current standard survey and compared it to the date of the previous standard survey to determine whether the surveys were conducted within the required time interval per federal and state regulations. We also conducted inquiries with Department staff regarding policies and procedures over the monitoring of CDPHE.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:? ACCORDING TO FEDERAL REGULATION [42 CFR 442], providers must meet the prescribed health and safety standards for ICF/IIDs, nursing facilities, and hospitals providing nursing facility services. For example, each facility is subject to surveys that cover quality of care, written plans of care, and a review of compliance with residents? rights.? ACCORDING TO FEDERAL REGULATION [42 CFR 488.308(a)], the state survey agency must conduct a standard survey of each skilled nursing facility and nursing facility no later than 15 months after the last day of the previous survey.? ACCORDING TO DEPARTMENT POLICY [Policy SLO-001 Section V], Department staff must run an independent report from CMS?s certification and reporting website to identify any facilities that are overdue for a survey. Once these facilities are identified, Department staff then compare this report to the reports received from CDPHE to determine whether CDPHE completed the survey because the information on CMS?s certification and reporting website may not always be current. If the survey is not performed within the required timeframe of 15.9 months, Department staff should reach out to CDPHE to ensure that surveys are conducted. Department staff must then save documentation for all interactions with CDPHE. This policy also states that in order to ensure timely surveys, Department staff must use a tracking log to monitor survey completion dates by CDPHE.? ACCORDING TO FEDERAL REGULATION [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, observing operations, and ensuring that activities are carried out in accordance with any agreements in place with other entities.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Based on the issues identified, we determined that the Department did not fully implement all parts of the prior audit recommendation related to the monitoring of CDPHE?s health and safety standard surveys for skilled nursing facilities during Fiscal Year 2019. Specifically, we identified the following:UNTIMELY STANDARD SURVEYS. The Department did not ensure that CDPHE conducted standard surveys within required timeframes. We found that, for 13 of the 40 skilled nursing facilities and ICF/IIDs tested (33 percent), CDPHE did not properly survey the facility within a 15-month interval as required by federal regulations. Specifically, we found that the skilled nursing facilities were surveyed within an interval of 16 and 20 months, or 1 to 5 months beyond the required timeframe. In addition, the Department was unable to provide documentation that it had appropriately monitored CDPHE or that it had provided appropriate outreach to CDPHE to identify the reasons for the late processing and resolution of issues.DEPARTMENT NOT IN COMPLIANCE WITH ITS POLICY. The Department was unable to provide documented evidence that staff obtained reports from CMS?s certification and reporting website and compared them to CDPHE reports, as required by the Department?s policy, in order to identify overdue surveys of providers and follow up with CDPHE accordingly.WHY DID THESE PROBLEMS OCCUR?While the Department updated its policy to include a requirement for staff to maintain documentation of the meetings held with CDPHE and CMS as well as staff reviews of survey reports, we found that the Department?s policy was not updated until June 30, 2019, or the last day of Fiscal Year 2019. As a result, the Department did not have adequate internal controls in place during Fiscal Year 2019 over its monitoring of CDPHE?s health and safety surveys and certifications to ensure that CDPHE staff conducted timely standard surveys in compliance with state and federal regulations. In addition, the Department did not have an effective mechanism to proactively identify delayed standard surveys and certifications of skilled nursing facilities.WHY DO THESE PROBLEMS MATTER?By not performing appropriate and timely monitoring, or maintaining an internal survey tracking mechanism, the Department cannot demonstrate that it has adequate internal controls in place over Medicaid payments made to skilled nursing facilities, and therefore risks noncompliance with federal regulations.If the Department does not have a strong process in place to ensure that providers are properly surveyed and certified, the Department risks making payments to CDPHE for surveys and certifications that have not been completed. Additionally, the Department risks making payments to skilled nursing facilities that may not be eligible to participate as Medicaid providers and would therefore be out of compliance with federal and state requirements. Further, this could result in the Department having to pay CMS back the amounts paid to these providers during the time period.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 17S&CTITLE19MEDICAID18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAIDFEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS (TITLE XVIII) MEDICARECOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED AND UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-047A AND 2018-047BRECOMMENDATION2019-048The Department of Health Care Policy and Financing should strengthen its internal controls over the monitoring of provider health and safety standards by:A Implementing and following its current policy for monitoring the Colorado Department of Public Health and Environment?s standard surveys and certifications throughout the fiscal year to ensure compliance with state and federal regulations.B Developing and implementing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2020.The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MONITORING OF HEALTH AND SAFETY SURVEYS AND CERTIFICATIONSMedical providers, such as nursing facilities, intermediate care facilities for individuals with intellectual disabilities (ICF/IIDs), and hospitals providing nursing facility services, must meet minimum standards for certification by the state and/or federal governments to be eligible to receive payments for services provided to Medicaid-eligible beneficiaries. The Department and the Colorado Department of Public Health and Environment (CDPHE) are responsible under state statute for this work. The Department categorizes hospital providers of nursing facility services under Colorado Medicaid Skilled Nursing Facility providers.The Department, as the state agency that is ultimately responsible for administering Medicaid, has overall responsibility for ensuring that all medical providers receiving Medicaid funding comply with regulatory health and safety standards. The Department has an interagency agreement with CDPHE, the designated state survey agency, to conduct health care entity inspections, or surveys, of Medicaid providers as outlined in state statutes and in agreements with the Centers for Medicare and Medicaid Services (CMS).A standard survey is a type of survey conducted to assess compliance with federal regulations specific to health and safety. After conducting each survey, CDPHE staff enter information, such as survey date and deficiencies noted, into their database; this information is then extracted and compiled by CMS and displayed on CMS? Survey and Certification?s Quality, Certification and Oversight Reports website?CMS?s certification and reporting website. Once a health care facility passes its survey, CDPHE is responsible for making a recommendation for certification to the Department. The Department is responsible for monitoring CDPHE to ensure that the minimum standards for certification are met by each Medicaid-approved provider, and for approving CDPHE?s recommendations for certification. During Fiscal Year 2019, the Department paid CDPHE approximately $5.7 million for completing state surveys and certifications.The Department receives monthly reports from CDPHE detailing the results of the surveys and certifications performed on skilled nursing facilities and ICF/IIDs. In addition, the Department holds monthly meetings with CDPHE to discuss the surveys and certifications. The Department uses these reports and discussions to determine if there are any issues or deficiencies with any skilled nursing facilities and ICF/IIDs. Additionally, CDPHE is responsible for informing the Department directly if a facility has any critical violations because of a survey and the Department can then suspend payments to that facility.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department had adequate internal controls in place over the monitoring of CDPHE?s health and safety surveys for skilled nursing facilities and ICF/IIDs, and complied with the related federal and state requirements during Fiscal Year 2019.In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to monitoring of health and safety survey and certifications. During that audit, we recommended that the Department strengthen its internal controls over provider health and safety standards by following its current policy for monitoring CDPHE?s standard surveys and certifications, updating the policy to maintain monitoring documentation, and developing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities and ICF/IIDs.As part of our audit, we reviewed a sample of 40 skilled nursing facilities and ICF/IIDs that received a Medicaid payment for services provided during Fiscal Year 2019 in order to determine if the Department ensured that CDPHE performed the required surveys in accordance with federal and state regulations.For the sample of skilled nursing facilities and ICF/IIDs, we reviewed the date of the current standard survey and compared it to the date of the previous standard survey to determine whether the surveys were conducted within the required time interval per federal and state regulations. We also conducted inquiries with Department staff regarding policies and procedures over the monitoring of CDPHE.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:? ACCORDING TO FEDERAL REGULATION [42 CFR 442], providers must meet the prescribed health and safety standards for ICF/IIDs, nursing facilities, and hospitals providing nursing facility services. For example, each facility is subject to surveys that cover quality of care, written plans of care, and a review of compliance with residents? rights.? ACCORDING TO FEDERAL REGULATION [42 CFR 488.308(a)], the state survey agency must conduct a standard survey of each skilled nursing facility and nursing facility no later than 15 months after the last day of the previous survey.? ACCORDING TO DEPARTMENT POLICY [Policy SLO-001 Section V], Department staff must run an independent report from CMS?s certification and reporting website to identify any facilities that are overdue for a survey. Once these facilities are identified, Department staff then compare this report to the reports received from CDPHE to determine whether CDPHE completed the survey because the information on CMS?s certification and reporting website may not always be current. If the survey is not performed within the required timeframe of 15.9 months, Department staff should reach out to CDPHE to ensure that surveys are conducted. Department staff must then save documentation for all interactions with CDPHE. This policy also states that in order to ensure timely surveys, Department staff must use a tracking log to monitor survey completion dates by CDPHE.? ACCORDING TO FEDERAL REGULATION [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, observing operations, and ensuring that activities are carried out in accordance with any agreements in place with other entities.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Based on the issues identified, we determined that the Department did not fully implement all parts of the prior audit recommendation related to the monitoring of CDPHE?s health and safety standard surveys for skilled nursing facilities during Fiscal Year 2019. Specifically, we identified the following:UNTIMELY STANDARD SURVEYS. The Department did not ensure that CDPHE conducted standard surveys within required timeframes. We found that, for 13 of the 40 skilled nursing facilities and ICF/IIDs tested (33 percent), CDPHE did not properly survey the facility within a 15-month interval as required by federal regulations. Specifically, we found that the skilled nursing facilities were surveyed within an interval of 16 and 20 months, or 1 to 5 months beyond the required timeframe. In addition, the Department was unable to provide documentation that it had appropriately monitored CDPHE or that it had provided appropriate outreach to CDPHE to identify the reasons for the late processing and resolution of issues.DEPARTMENT NOT IN COMPLIANCE WITH ITS POLICY. The Department was unable to provide documented evidence that staff obtained reports from CMS?s certification and reporting website and compared them to CDPHE reports, as required by the Department?s policy, in order to identify overdue surveys of providers and follow up with CDPHE accordingly.WHY DID THESE PROBLEMS OCCUR?While the Department updated its policy to include a requirement for staff to maintain documentation of the meetings held with CDPHE and CMS as well as staff reviews of survey reports, we found that the Department?s policy was not updated until June 30, 2019, or the last day of Fiscal Year 2019. As a result, the Department did not have adequate internal controls in place during Fiscal Year 2019 over its monitoring of CDPHE?s health and safety surveys and certifications to ensure that CDPHE staff conducted timely standard surveys in compliance with state and federal regulations. In addition, the Department did not have an effective mechanism to proactively identify delayed standard surveys and certifications of skilled nursing facilities.WHY DO THESE PROBLEMS MATTER?By not performing appropriate and timely monitoring, or maintaining an internal survey tracking mechanism, the Department cannot demonstrate that it has adequate internal controls in place over Medicaid payments made to skilled nursing facilities, and therefore risks noncompliance with federal regulations.If the Department does not have a strong process in place to ensure that providers are properly surveyed and certified, the Department risks making payments to CDPHE for surveys and certifications that have not been completed. Additionally, the Department risks making payments to skilled nursing facilities that may not be eligible to participate as Medicaid providers and would therefore be out of compliance with federal and state requirements. Further, this could result in the Department having to pay CMS back the amounts paid to these providers during the time period.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 17S&CTITLE19MEDICAID18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAIDFEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS (TITLE XVIII) MEDICARECOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED AND UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-047A AND 2018-047BRECOMMENDATION2019-048The Department of Health Care Policy and Financing should strengthen its internal controls over the monitoring of provider health and safety standards by:A Implementing and following its current policy for monitoring the Colorado Department of Public Health and Environment?s standard surveys and certifications throughout the fiscal year to ensure compliance with state and federal regulations.B Developing and implementing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2020.The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.
(A) The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.(B) The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.
2019-048
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID MANAGED CARE ENTITIESThe Department had a total of seven contracts with external entities for coordinating services to Medicaid beneficiaries during Fiscal Year 2019. The providers consisted of two Managed Care Organizations (MCO) and seven Prepaid Inpatient Health Plans (PIHP)?two PIHPs and two MCOs shared a single contract with the Department. The MCOs and PIHPs are collectively referred to as Managed Care Entities (MCE), which are health care providers or a group or organization of medical service providers which offer managed care health plans and deliver health care services. MCOs have a comprehensive risk plan contract with the Department covering comprehensive services, such as inpatient hospital services, whereas PIHPs have a non-comprehensive risk plan contract covering inpatient or institutional services, such as inpatient behavioral healthcare.STRUCTURE OF HEALTH CARE POLICY AND FINANCING MANAGED CARE ENTITIESSOURCE: Office of the State Auditor analysis of Managed Care Entities.The Department makes set payments to each contracted MCE to coordinate services for eligible Medicaid beneficiaries every month. The MCEs are then responsible for paying Medicaid claims to providers. Providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid beneficiaries. The Department is ultimately responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions with the Department, including federal requirements that the MCOs pay timely Medicaid claims to the providers. During Fiscal Year 2019, the Department paid approximately $966,848,173 in Medicaid claims payments to MCEs.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over monitoring of MCEs to determine whether Medicaid claims were processed and paid in a timely manner by MCEs to the providers in accordance with federal requirements during Fiscal Year 2019.The audit work included interviewing Department staff regarding written policies and procedures over the monitoring of its MCEs. In addition, we reviewed all seven MCE contracts in place during Fiscal Year 2019 to determine whether they included timely processing provisions in accordance with Uniform Guidance.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?TIMELY CLAIMS PAYMENT. Federal regulation [42 CFR 447.46(C)(1)] states that the Department?s contracts with its MCOs must include a provision that the organization must pay 90 percent of all clean claims within 30 days of receipt from providers and 99 percent of all clean claims within 90 days of the date of receipt from providers. A ?clean claim? is one that can be processed without obtaining additional information from the provider for the services rendered. Based on inquiries with the Department, their processes require both MCOs and PIHPs to be in compliance with the timely claims payment regulation.INTERNAL CONTROLS. According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Principle 10, Design Control Activities, which states that management should design control activities to achieve the objectives and respond to risks. Management designs control activities in response to the entity?s objectives and risks to achieve an effective internal control system. Control activities are the policies, procedures, techniques, and mechanisms that enforce management?s directives to achieve the entity?s objectives and address related risks. Additionally, Green Book Paragraph 16.01, Perform Monitoring Activities, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the Department did not consistently have a contract provision requiring that PIHPs comply with timely claims payment regulations during Fiscal Year 2019. Specifically, we found that for five of seven contracts we reviewed (71 percent), the Department did not include a specific timely claims payment provision for Fiscal Year 2019. Additionally, the Department could not provide any evidence demonstrating that it monitored PIHPs during Fiscal Year 2019 to ensure that it (1) paid 90 percent of all clean claims from providers within 30 days of the date of receipt, and (2) paid 99 percent of all clean claims from providers within 90 days of the date of claims receipt in accordance with federal regulations. Furthermore, the Department could not provide any evidence demonstrating that it monitored two MCOs during Fiscal Year 2019 for timely claims payments as required by federal regulations.WHY DID THESE PROBLEMS OCCUR?The Department lacked adequate internal controls to ensure that it complied with federal regulations for timely claims payments to providers. Specifically, Department staff reported that all MCE contracts included a general provision requiring them to comply with all federal regulations. However, the Department lacked an adequate contract review process to ensure that all PIHP contracts included a provision requiring timely claims payments to providers.Additionally, the Department did not have formal written monitoring policies and procedures to ensure that PIHPs and MCOs made timely claims payments to providers. Department staff reported that they had an informal process of monitoring contracts by observing the operations but did not have a formal monitoring process, such as reviewing any type of report or performing reconciliations of claims payments made by MCEs. Furthermore, the Department?s contracts lacked a specific provision requiring MCEs to deliver any type of report to the Department for review to demonstrate the MCEs? compliance with federal regulations and Department processes.WHY DO THESE PROBLEMS MATTER?As a recipient of federal funds, the Department is ultimately responsible for ensuring that these funds are being paid in accordance with federal regulations. By not including the requirements for timely claims payments in the contracts with PIHPs and failing to have a formal monitoring process over PIHPs or MCOs, the Department risks failing to comply with federal regulations.Payments that are not made in accordance with these requirements could be subject to federal disallowances and recoveries from the State.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019 XIX-ADM2017XIX-ADM2018XIX-ADM2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-057B AND 2017-056BRECOMMENDATION2019-049The Department of Health Care Policy and Financing (Department) should improve its internal controls over the timely processing of medical claims paid by Medicaid Managed Care Entities (MCEs) by:A Instituting an adequate contract review process to ensure appropriate provisions, including timing specifications for claims payments to providers, are included in all Prepaid Inpatient Health Plan contracts to ensure compliance with Department requirements.B Developing and implementing formal written monitoring policies and procedures over the timely processing of claims payments to ensure that the Department and MCEs are in compliance with federal regulations and Department processes.C Incorporating provisions within all MCE contracts to deliver timely payment reports for the Department?s review to ensure compliance with federal regulations and Department processes.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The seven RAE contracts contain language that require them to strictly adhere to and comply with all applicable federal laws and regulations (see Regional Accountable Entity contracts base contract ?21.U.; Exhibit B, ?5.1., and ?17.1.). The Department agrees with the recommendation that the timely payment of clean claims is not specifically stated in the Prepaid Inpatient Health Plan section of the contracts. The Department will ensure an adequate contract review process is in place to ensure the timing specifications for the payment of claim payments to providers by documenting this requirement in program policy documentation.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department has documented policies for deliverables and federal regulatory requirements included in the Regional Accountable Entity contracts. The Department will document and implement the monitoring policy of the timely payment of clean claims language.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department will add new language to both the Prepaid Inpatient Health Plan and the Managed Care Organization authority sections of the Regional Accountable Entity contracts requiring reporting of the timely payment of clean claims.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.MEDICAID MANAGED CARE ENTITIESThe Department had a total of seven contracts with external entities for coordinating services to Medicaid beneficiaries during Fiscal Year 2019. The providers consisted of two Managed Care Organizations (MCO) and seven Prepaid Inpatient Health Plans (PIHP)?two PIHPs and two MCOs shared a single contract with the Department. The MCOs and PIHPs are collectively referred to as Managed Care Entities (MCE), which are health care providers or a group or organization of medical service providers which offer managed care health plans and deliver health care services. MCOs have a comprehensive risk plan contract with the Department covering comprehensive services, such as inpatient hospital services, whereas PIHPs have a non-comprehensive risk plan contract covering inpatient or institutional services, such as inpatient behavioral healthcare.STRUCTURE OF HEALTH CARE POLICY AND FINANCING MANAGED CARE ENTITIESSOURCE: Office of the State Auditor analysis of Managed Care Entities.The Department makes set payments to each contracted MCE to coordinate services for eligible Medicaid beneficiaries every month. The MCEs are then responsible for paying Medicaid claims to providers. Providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid beneficiaries. The Department is ultimately responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions with the Department, including federal requirements that the MCOs pay timely Medicaid claims to the providers. During Fiscal Year 2019, the Department paid approximately $966,848,173 in Medicaid claims payments to MCEs.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over monitoring of MCEs to determine whether Medicaid claims were processed and paid in a timely manner by MCEs to the providers in accordance with federal requirements during Fiscal Year 2019.The audit work included interviewing Department staff regarding written policies and procedures over the monitoring of its MCEs. In addition, we reviewed all seven MCE contracts in place during Fiscal Year 2019 to determine whether they included timely processing provisions in accordance with Uniform Guidance.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?TIMELY CLAIMS PAYMENT. Federal regulation [42 CFR 447.46(C)(1)] states that the Department?s contracts with its MCOs must include a provision that the organization must pay 90 percent of all clean claims within 30 days of receipt from providers and 99 percent of all clean claims within 90 days of the date of receipt from providers. A ?clean claim? is one that can be processed without obtaining additional information from the provider for the services rendered. Based on inquiries with the Department, their processes require both MCOs and PIHPs to be in compliance with the timely claims payment regulation.INTERNAL CONTROLS. According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Principle 10, Design Control Activities, which states that management should design control activities to achieve the objectives and respond to risks. Management designs control activities in response to the entity?s objectives and risks to achieve an effective internal control system. Control activities are the policies, procedures, techniques, and mechanisms that enforce management?s directives to achieve the entity?s objectives and address related risks. Additionally, Green Book Paragraph 16.01, Perform Monitoring Activities, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the Department did not consistently have a contract provision requiring that PIHPs comply with timely claims payment regulations during Fiscal Year 2019. Specifically, we found that for five of seven contracts we reviewed (71 percent), the Department did not include a specific timely claims payment provision for Fiscal Year 2019. Additionally, the Department could not provide any evidence demonstrating that it monitored PIHPs during Fiscal Year 2019 to ensure that it (1) paid 90 percent of all clean claims from providers within 30 days of the date of receipt, and (2) paid 99 percent of all clean claims from providers within 90 days of the date of claims receipt in accordance with federal regulations. Furthermore, the Department could not provide any evidence demonstrating that it monitored two MCOs during Fiscal Year 2019 for timely claims payments as required by federal regulations.WHY DID THESE PROBLEMS OCCUR?The Department lacked adequate internal controls to ensure that it complied with federal regulations for timely claims payments to providers. Specifically, Department staff reported that all MCE contracts included a general provision requiring them to comply with all federal regulations. However, the Department lacked an adequate contract review process to ensure that all PIHP contracts included a provision requiring timely claims payments to providers.Additionally, the Department did not have formal written monitoring policies and procedures to ensure that PIHPs and MCOs made timely claims payments to providers. Department staff reported that they had an informal process of monitoring contracts by observing the operations but did not have a formal monitoring process, such as reviewing any type of report or performing reconciliations of claims payments made by MCEs. Furthermore, the Department?s contracts lacked a specific provision requiring MCEs to deliver any type of report to the Department for review to demonstrate the MCEs? compliance with federal regulations and Department processes.WHY DO THESE PROBLEMS MATTER?As a recipient of federal funds, the Department is ultimately responsible for ensuring that these funds are being paid in accordance with federal regulations. By not including the requirements for timely claims payments in the contracts with PIHPs and failing to have a formal monitoring process over PIHPs or MCOs, the Department risks failing to comply with federal regulations.Payments that are not made in accordance with these requirements could be subject to federal disallowances and recoveries from the State.FEDERAL AGENCYDEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019 XIX-ADM2017XIX-ADM2018XIX-ADM2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-057B AND 2017-056BRECOMMENDATION2019-049The Department of Health Care Policy and Financing (Department) should improve its internal controls over the timely processing of medical claims paid by Medicaid Managed Care Entities (MCEs) by:A Instituting an adequate contract review process to ensure appropriate provisions, including timing specifications for claims payments to providers, are included in all Prepaid Inpatient Health Plan contracts to ensure compliance with Department requirements.B Developing and implementing formal written monitoring policies and procedures over the timely processing of claims payments to ensure that the Department and MCEs are in compliance with federal regulations and Department processes.C Incorporating provisions within all MCE contracts to deliver timely payment reports for the Department?s review to ensure compliance with federal regulations and Department processes.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The seven RAE contracts contain language that require them to strictly adhere to and comply with all applicable federal laws and regulations (see Regional Accountable Entity contracts base contract ?21.U.; Exhibit B, ?5.1., and ?17.1.). The Department agrees with the recommendation that the timely payment of clean claims is not specifically stated in the Prepaid Inpatient Health Plan section of the contracts. The Department will ensure an adequate contract review process is in place to ensure the timing specifications for the payment of claim payments to providers by documenting this requirement in program policy documentation.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Department has documented policies for deliverables and federal regulatory requirements included in the Regional Accountable Entity contracts. The Department will document and implement the monitoring policy of the timely payment of clean claims language.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department will add new language to both the Prepaid Inpatient Health Plan and the Managed Care Organization authority sections of the Regional Accountable Entity contracts requiring reporting of the timely payment of clean claims.
(A) This finding has been implemented. The Department has documented formal contract review and renewal process and procedures.(B) This finding has been implemented. The Department has developed formal written monitoring policies and procedures for reviewing the timely processing of claims payments reported by the MCEs.(C) This finding has been implemented. Contract language has been inserted in all MCE contracts at section 14.14.7-14.14.8.2.
2019-049
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.COMPLIANCE WITH FEDERAL SUBRECIPIENT MONITORING REQUIREMENTSThe Department receives federal Medicaid and CBHP grant funds directly from the federal government and then subgrants, or passes through, a portion of the funds to local counties, non-profit organizations, and for-profit organizations that are considered to be either a subrecipient or a contractor.A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required for the conduct of a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program.Under Uniform Guidance, the Department is responsible for identifying and monitoring entities that qualify as subrecipients of federal funds. For Medicaid and CBHP, the Department?s subrecipients either determine eligibility for the programs or provide services to individuals deemed eligible for program services. Examples of the Department?s subrecipients are local counties and MA sites, including Single Entry Points, which provide services for elderly and/or disabled people who are eligible for long-term care services; and Community Centered Boards, which provide services to individuals with developmental disabilities.Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA).This exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance, and should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants payments made by the Department to other State and/or non-state agencies.During Fiscal Year 2019, the Department paid approximately $18.5 million in federal Medicaid funds and approximately $500,000 in federal CBHP funds to 62 subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 recommendation related to Medicaid and CBHP subrecipient monitoring. In Fiscal Year 2018, we recommended that the Department improve its internal controls specific to subrecipient monitoring for the two programs by implementing its draft subrecipient monitoring policies and procedures and performing required risk assessments on its subrecipients to ensure compliance with Uniform Guidance. In response to our recommendation, the Department stated that it would revise its existing subrecipient policies and procedures to be compliant with federal Uniform Guidance and would conduct a risk assessment of each subrecipient as part of the monitoring process. We made a similar recommendation to the Department in Fiscal Year 2016 that we also determined the Department had not fully implemented at the time of our Fiscal Year 2018 audit.As part of our Fiscal Year 2019 audit, we obtained and reviewed the Department?s revised subrecipient monitoring policies and procedures. We selected a random sample of 16 out of 62 entities that were recorded and set up as subrecipients in the Colorado Operations Resource Engine (CORE), the State?s financial accounting system, and received Medicaid and CBHP payments during Fiscal Year 2019, to evaluate whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. Furthermore, we reviewed the Department?s Exhibit K1, submitted to the OSC for Fiscal Year 2019, to determine whether the Department accurately reported all subrecipient expenditures for Medicaid and CBHP.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Under Uniform Guidance, as a pass-through entity, the Department is required to monitor its subrecipients? use of federal awards.Federal regulation [2 CFR 200.331] requires the Department to conduct risk assessments based on each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of its Medicaid and CBHP subawards to determine the appropriate level of subrecipient monitoring for all of its subrecipients under these programs.The Department?s Subrecipient Monitoring Procedures (Procedures) that were in place during Fiscal Year 2019 split responsibilities between various divisions and staff as follows:? AUDITS AND COMPLIANCE DIVISION. Staff within this division oversee the local counties as subrecipients of Medicaid and CBHP and ensure that these subrecipients are in compliance with federal award requirements. Audits and Compliance Division staff is responsible for updating procedures, and providing training and guidance on subrecipient monitoring to program staff within the Department.? CONTROLLER DIVISION. Staff within this division are responsible for setting up the entity with the proper accounting codes in CORE. Based on the results of the assessment noted on the Subrecipient versus Contractor Determination Tool (Tool) for each entity, the Controller Division staff should establish either subrecipient or contractor coding for the entity?s expenditures.? VARIOUS OTHER DIVISIONS WITHIN THE DEPARTMENT. Procedures also state that the Department?s program contract administrators within its various program divisions are responsible for identifying its Medicaid and CBHP subrecipients by using the Tool. The Procedures require the contract administrators to forward the Tool for any identified subrecipients to the program division director for secondary review. The completed Tool is submitted for additional review to the Audits and Compliance Division. Final approval of the Tool is made by the controller of the Department. The Department procedure also states that the program contract administrator is required to assess each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the federal award as high, medium, or low risk. This assessment aids the Department in determining the appropriate level of monitoring. The risk assessment and the responsibility for monitoring the subrecipient?s compliance with federal award requirements rests with the contract administrator and their respective office or division management that operates the individual subrecipient award.State Fiscal Rule 1-2, Rule 3.5, Preaudit Responsibility for Accounting Documents and Financial Transactions, issued by the OSC, requires state departments to, ?Implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, and conform to state Fiscal Rules.?In addition, the Instructions for Exhibits published by the OSC provides specific directions for preparing financial exhibits that are to be submitted to the OSC at year-end. For example, the Exhibit K1 is used for preparing the SEFA, which includes a listing of federal assistance by Catalog of Federal Domestic Assistance number or other identifying number. The Instructions for Exhibits requires departments to separately report any federal assistance passed through to a subrecipient on the Exhibit K1 in the Expenditures-Passed Through to Subrecipient column, while payments to contractors are reported under the column titled Expenditures-Direct and Indirect. The Controller Division is responsible for preparing the Department?s Exhibit K1 each year.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully implement the Fiscal Year 2018 subrecipient monitoring recommendation for Medicaid and CBHP. Although the Department revised and implemented its Medicaid and CBHP subrecipient monitoring policies and procedures during Fiscal Year 2019, the Department did not evaluate all of its Medicaid and CBHP subrecipients? risk of noncompliance and did not determine the related level of subrecipient monitoring as required under Uniform Guidance and the Department?s procedures. We specifically noted the following problems:? For five of the 16 entities in our sample (31 percent), the program contract administrators identified them as contractors based on the results of the Tool assessment, but recorded them in CORE as subrecipients. Therefore, the Controller Division made payments totaling $166,870 to these five entities as subrecipient payments in CORE. Upon further inquiry with the Department, we found that the program contract administrators assessed all of its CBHP entities as contractors but recorded them in CORE as subrecipients. As a result, the Controller Division reported total payments of $415,378 to these entities on the Department?s Fiscal Year 2019 Exhibit K1 as Expenditures-Passed Through to Subrecipient, which contradicted the results of the Tool assessment.? Program contract administrators did not complete the required Tool assessments for three of 16 entities (19 percent) in our sample that were recorded as subrecipients in CORE and received payments under Medicaid and CBHP. Due to the lack of a completed Tool assessment for these entities, we could not determine whether the contract administrators should have identified them as subrecipients and, if so, whether they performed a risk assessment or any level of monitoring over these entities.As of the end of our audit, the Department was researching the discrepancies we identified to determine whether the entities should have been identified and reported as subrecipients or contractors.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place during Fiscal Year 2019 to ensure that it complied with federal subrecipient monitoring requirements. Specifically, we noted that there was an inefficient secondary review by the program division director over program contract administrators to ensure that the Tool assessment was completed properly, that entities were accurately reported as either a contractor or subrecipient in CORE, and that respective risk assessments were performed for all identified subrecipients as required by Uniform Guidance and Department procedures. In addition, we noted that the Department did not have a process in place to reconcile the Controller Division?s list of identified Medicaid and CBHP subrecipients with the subrecipient information in CORE. This reconciliation would ensure that Medicaid and CBHP payments made to subrecipents are reported accurately on the Exhibit K1 in accordance with the OSC?s Fiscal Rules and Instructions for Exhibits, and accurately reported to the federal government on the State?s SEFA.WHY DO THESE PROBLEMS MATTER?Without the proper internal controls in place to ensure compliance with federal subrecipient monitoring requirements, the Department ultimately risks federal sanctions. First, without evaluating its subrecipients? risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, the Department does not have assurance that it appropriately monitors its subrecipients and identifies issues. Further, because the Exhibit K1 is used by the OSC to prepare the SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds the Department pays annually to its subrecipients.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-049RECOMMENDATION2019-050The Department of Health Care Policy and Financing should improve its internal controls over subrecipient monitoring for Medicaid and the Children?s Basic Health Plan (CBHP) by:A Implementing an effective secondary review process by the program division directors over the Department?s program contract administrators to ensure that the Subrecipient versus Contractor Determination Tool is completed, subrecipient and contractor determinations are accurately reported in the State?s financial accounting system, the Colorado Operations Resource Engine, and that the required risk assessments are performed for all identified subrecipients as required by the federal Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards and the Department?s procedures.B Establishing a process to reconcile subrecipients identified by the program contract administrators with those identified by the Controller Division for Medicaid and CBHP prior to awarding federal funds to the subrecipients to ensure that payments are reported accurately on the Exhibit K1, Schedule of Federal Assistance, in accordance with the Office of the State Controller?s Fiscal Rules and Instructions for Exhibits and, ultimately, to the federal government on the State?s Schedule of Expenditures of Federal Awards.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department will conduct training with program management and division directors regarding the requirements for subrecipient monitoring and their responsibilities for secondary review.The training will include subrecipient versus contractor determination, the requirement of risk assessments and the importance of reporting determinations accurately in Colorado Operations Resource Engine.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly.The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.COMPLIANCE WITH FEDERAL SUBRECIPIENT MONITORING REQUIREMENTSThe Department receives federal Medicaid and CBHP grant funds directly from the federal government and then subgrants, or passes through, a portion of the funds to local counties, non-profit organizations, and for-profit organizations that are considered to be either a subrecipient or a contractor.A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required for the conduct of a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program.Under Uniform Guidance, the Department is responsible for identifying and monitoring entities that qualify as subrecipients of federal funds. For Medicaid and CBHP, the Department?s subrecipients either determine eligibility for the programs or provide services to individuals deemed eligible for program services. Examples of the Department?s subrecipients are local counties and MA sites, including Single Entry Points, which provide services for elderly and/or disabled people who are eligible for long-term care services; and Community Centered Boards, which provide services to individuals with developmental disabilities.Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA).This exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance, and should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants payments made by the Department to other State and/or non-state agencies.During Fiscal Year 2019, the Department paid approximately $18.5 million in federal Medicaid funds and approximately $500,000 in federal CBHP funds to 62 subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 recommendation related to Medicaid and CBHP subrecipient monitoring. In Fiscal Year 2018, we recommended that the Department improve its internal controls specific to subrecipient monitoring for the two programs by implementing its draft subrecipient monitoring policies and procedures and performing required risk assessments on its subrecipients to ensure compliance with Uniform Guidance. In response to our recommendation, the Department stated that it would revise its existing subrecipient policies and procedures to be compliant with federal Uniform Guidance and would conduct a risk assessment of each subrecipient as part of the monitoring process. We made a similar recommendation to the Department in Fiscal Year 2016 that we also determined the Department had not fully implemented at the time of our Fiscal Year 2018 audit.As part of our Fiscal Year 2019 audit, we obtained and reviewed the Department?s revised subrecipient monitoring policies and procedures. We selected a random sample of 16 out of 62 entities that were recorded and set up as subrecipients in the Colorado Operations Resource Engine (CORE), the State?s financial accounting system, and received Medicaid and CBHP payments during Fiscal Year 2019, to evaluate whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. Furthermore, we reviewed the Department?s Exhibit K1, submitted to the OSC for Fiscal Year 2019, to determine whether the Department accurately reported all subrecipient expenditures for Medicaid and CBHP.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Under Uniform Guidance, as a pass-through entity, the Department is required to monitor its subrecipients? use of federal awards.Federal regulation [2 CFR 200.331] requires the Department to conduct risk assessments based on each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of its Medicaid and CBHP subawards to determine the appropriate level of subrecipient monitoring for all of its subrecipients under these programs.The Department?s Subrecipient Monitoring Procedures (Procedures) that were in place during Fiscal Year 2019 split responsibilities between various divisions and staff as follows:? AUDITS AND COMPLIANCE DIVISION. Staff within this division oversee the local counties as subrecipients of Medicaid and CBHP and ensure that these subrecipients are in compliance with federal award requirements. Audits and Compliance Division staff is responsible for updating procedures, and providing training and guidance on subrecipient monitoring to program staff within the Department.? CONTROLLER DIVISION. Staff within this division are responsible for setting up the entity with the proper accounting codes in CORE. Based on the results of the assessment noted on the Subrecipient versus Contractor Determination Tool (Tool) for each entity, the Controller Division staff should establish either subrecipient or contractor coding for the entity?s expenditures.? VARIOUS OTHER DIVISIONS WITHIN THE DEPARTMENT. Procedures also state that the Department?s program contract administrators within its various program divisions are responsible for identifying its Medicaid and CBHP subrecipients by using the Tool. The Procedures require the contract administrators to forward the Tool for any identified subrecipients to the program division director for secondary review. The completed Tool is submitted for additional review to the Audits and Compliance Division. Final approval of the Tool is made by the controller of the Department. The Department procedure also states that the program contract administrator is required to assess each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the federal award as high, medium, or low risk. This assessment aids the Department in determining the appropriate level of monitoring. The risk assessment and the responsibility for monitoring the subrecipient?s compliance with federal award requirements rests with the contract administrator and their respective office or division management that operates the individual subrecipient award.State Fiscal Rule 1-2, Rule 3.5, Preaudit Responsibility for Accounting Documents and Financial Transactions, issued by the OSC, requires state departments to, ?Implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, and conform to state Fiscal Rules.?In addition, the Instructions for Exhibits published by the OSC provides specific directions for preparing financial exhibits that are to be submitted to the OSC at year-end. For example, the Exhibit K1 is used for preparing the SEFA, which includes a listing of federal assistance by Catalog of Federal Domestic Assistance number or other identifying number. The Instructions for Exhibits requires departments to separately report any federal assistance passed through to a subrecipient on the Exhibit K1 in the Expenditures-Passed Through to Subrecipient column, while payments to contractors are reported under the column titled Expenditures-Direct and Indirect. The Controller Division is responsible for preparing the Department?s Exhibit K1 each year.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully implement the Fiscal Year 2018 subrecipient monitoring recommendation for Medicaid and CBHP. Although the Department revised and implemented its Medicaid and CBHP subrecipient monitoring policies and procedures during Fiscal Year 2019, the Department did not evaluate all of its Medicaid and CBHP subrecipients? risk of noncompliance and did not determine the related level of subrecipient monitoring as required under Uniform Guidance and the Department?s procedures. We specifically noted the following problems:? For five of the 16 entities in our sample (31 percent), the program contract administrators identified them as contractors based on the results of the Tool assessment, but recorded them in CORE as subrecipients. Therefore, the Controller Division made payments totaling $166,870 to these five entities as subrecipient payments in CORE. Upon further inquiry with the Department, we found that the program contract administrators assessed all of its CBHP entities as contractors but recorded them in CORE as subrecipients. As a result, the Controller Division reported total payments of $415,378 to these entities on the Department?s Fiscal Year 2019 Exhibit K1 as Expenditures-Passed Through to Subrecipient, which contradicted the results of the Tool assessment.? Program contract administrators did not complete the required Tool assessments for three of 16 entities (19 percent) in our sample that were recorded as subrecipients in CORE and received payments under Medicaid and CBHP. Due to the lack of a completed Tool assessment for these entities, we could not determine whether the contract administrators should have identified them as subrecipients and, if so, whether they performed a risk assessment or any level of monitoring over these entities.As of the end of our audit, the Department was researching the discrepancies we identified to determine whether the entities should have been identified and reported as subrecipients or contractors.WHY DID THESE PROBLEMS OCCUR?The Department did not have adequate internal controls in place during Fiscal Year 2019 to ensure that it complied with federal subrecipient monitoring requirements. Specifically, we noted that there was an inefficient secondary review by the program division director over program contract administrators to ensure that the Tool assessment was completed properly, that entities were accurately reported as either a contractor or subrecipient in CORE, and that respective risk assessments were performed for all identified subrecipients as required by Uniform Guidance and Department procedures. In addition, we noted that the Department did not have a process in place to reconcile the Controller Division?s list of identified Medicaid and CBHP subrecipients with the subrecipient information in CORE. This reconciliation would ensure that Medicaid and CBHP payments made to subrecipents are reported accurately on the Exhibit K1 in accordance with the OSC?s Fiscal Rules and Instructions for Exhibits, and accurately reported to the federal government on the State?s SEFA.WHY DO THESE PROBLEMS MATTER?Without the proper internal controls in place to ensure compliance with federal subrecipient monitoring requirements, the Department ultimately risks federal sanctions. First, without evaluating its subrecipients? risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, the Department does not have assurance that it appropriately monitors its subrecipients and identifies issues. Further, because the Exhibit K1 is used by the OSC to prepare the SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds the Department pays annually to its subrecipients.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP2019FEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-049RECOMMENDATION2019-050The Department of Health Care Policy and Financing should improve its internal controls over subrecipient monitoring for Medicaid and the Children?s Basic Health Plan (CBHP) by:A Implementing an effective secondary review process by the program division directors over the Department?s program contract administrators to ensure that the Subrecipient versus Contractor Determination Tool is completed, subrecipient and contractor determinations are accurately reported in the State?s financial accounting system, the Colorado Operations Resource Engine, and that the required risk assessments are performed for all identified subrecipients as required by the federal Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards and the Department?s procedures.B Establishing a process to reconcile subrecipients identified by the program contract administrators with those identified by the Controller Division for Medicaid and CBHP prior to awarding federal funds to the subrecipients to ensure that payments are reported accurately on the Exhibit K1, Schedule of Federal Assistance, in accordance with the Office of the State Controller?s Fiscal Rules and Instructions for Exhibits and, ultimately, to the federal government on the State?s Schedule of Expenditures of Federal Awards.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department will conduct training with program management and division directors regarding the requirements for subrecipient monitoring and their responsibilities for secondary review.The training will include subrecipient versus contractor determination, the requirement of risk assessments and the importance of reporting determinations accurately in Colorado Operations Resource Engine.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly.The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions.
(A) Training of management and division directors completed - May 3, 2021.(B) The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly.The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions. Implemented 10/2020
2019-050
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.PERSONNEL COSTS FOR FEDERAL GRANT PROGRAMSFederal regulations require recipients of federal awards to develop adequate internal controls to ensure that personnel compensation expenditures are accurate, allowable, and properly allocated. The Department is required to follow Uniform Guidance when determining the Department?s federally-reimbursable costs, including personnel costs, for the federal programs it administers. The two largest federal programs the Department administered during Fiscal Year 2019 were Medicaid and CBHP.During Fiscal Year 2019, the Department used Clarity, a time reporting system, to track staff?s time and charge personnel costs to the respective federal grant program. During the year, the Department of Personnel & Administration (DPA) and OIT were continuing to pursue the implementation of HR Works, a statewide integrated human resources and payroll system. HR Works is expected to provide the Department with the ability to accurately track and report personnel costs for all staff. DPA and OIT would share the responsibility for implementing and managing HR Works.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to assess the Department?s internal controls over personnel costs associated with its administration of federal grants and to determine whether it complied with federal cost regulations under Uniform Guidance.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to federal grant personnel costs. Specifically, we recommended that the Department develop and implement interim policies and procedures to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations while it awaits the implementation of HR Works. The Department agreed with the recommendation and indicated that it would implement an interim process for those staff not currently using Clarity that complies with the federal cost regulation under Uniform Guidance. We first identified issues with the Department?s charging of personnel costs to its federal grants as a result of our Fiscal Year 2012 audit testwork.We performed testwork during our Fiscal Year 2019 audit to determine whether the Department implemented the prior audit recommendation and if it developed and implemented policies and procedures and an interim process to ensure that personnel costs were charged in accordance with federal regulations during Fiscal Year 2019. As part of our testing, we selected a random sample of 18 out of 81 semi-annual Periodic Time Certification Forms (Form) for the periods ending September 2018 and March 2019 (nine certifications from each period). These Forms are used by employees that worked on a single federal program during the fiscal year. We tested the sampled certifications to determine if they were signed in a timely manner by the employees? direct supervisors, as required by the Department?s internal policy.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [2 CFR 200.430] require that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award.The Department?s Time/Effort Reporting Policy (Policy) that was effective as of June 30, 2019, requires employees who work on multiple federal grant programs to complete a monthly Personnel Activity Report (Report) in order to allocate employees? salaries or wages to the various programs and activities. Employees who work solely on a single federal grant program must complete a semi-annual Form. The Form states that the supervisor has to sign the Form to certify the work performed by the employee.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully implement our Fiscal Year 2018 recommendation. Specifically, we found the following issues:? LACK OF TIME TRACKING. The Department did not require employees working on multiple federal grant programs to complete the Report on a monthly basis. As a result, the Department did not have information necessary to allocate the employees? time among the various programs.? LACK OF TIMELY CERTIFICATIONS. We found that in all 18 Forms we reviewed for employees who worked solely on a single federal grant program were not signed by the supervisors in a timely manner. Specifically, supervisors signed all 18 of the Forms in June or July 2019 for the semi-annual periods ending September 2018 and March 2019, or about 8 months and 3 months, respectively, after the end of the certified period and, in some cases, after the fiscal year-end. The timing of the signatures also occurred after we inquired of Department staff about their progress of implementing our Fiscal Year 2018 recommendation.WHY DID THESE PROBLEMS OCCUR?The Department did not implement an interim timekeeping mechanism during Fiscal Year 2019 to ensure that all personnel costs charged to Medicaid and CBHP were accurate, allowable, and properly allocated. Additionally, while the Department developed an interim policy for tracking all staff?s time, including employees who worked on multiple federal programs during Fiscal Year 2019, the Department did not implement this policy during Fiscal Year 2019 for all staff to ensure compliance with federal cost regulations under Uniform Guidance. Furthermore, the Department?s policies and procedures did not specify the time requirement for direct supervisors to review and sign periodic certifications in a timely manner.WHY DO THESE PROBLEMS MATTER?Lack of adequate internal controls over the charging of personnel costs to federal grants increases the risk that expenditures will be charged to the federal program incorrectly, and that the Department will not be in compliance with federal grant requirements. It is especially important that the Department take steps to demonstrate that it has fully implemented our prior audit recommendation, because the Department has been out of compliance for several years.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP201917S&CTITLE19MEDICAID18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAIDFEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-058 AND 2017-058RECOMMENDATION2019-051The Department of Health Care Policy and Financing (Department) should improve its internal controls over personnel costs by:A Implementing the Time/Effort Reporting Policy as an interim tracking mechanism for all staff time to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards while it awaits the implementation of the State?s new timekeeping system.B Updating the Department?s current policies and procedures to specify time requirements for the direct supervisors to review and sign periodic certifications.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2020.The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other.Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS or SIGNIFICANT DEFICIENCY were communicated to the Department of Health Care Policy and Financing (Department) in the previous year, and have not been remediated as of June 30, 2020, because the original implementation date provided by the Department is in a subsequent fiscal year. These recommendations can be found in the original report and SECTION III: PRIOR RECOMMENDATIONS of this report.PERSONNEL COSTS FOR FEDERAL GRANT PROGRAMSFederal regulations require recipients of federal awards to develop adequate internal controls to ensure that personnel compensation expenditures are accurate, allowable, and properly allocated. The Department is required to follow Uniform Guidance when determining the Department?s federally-reimbursable costs, including personnel costs, for the federal programs it administers. The two largest federal programs the Department administered during Fiscal Year 2019 were Medicaid and CBHP.During Fiscal Year 2019, the Department used Clarity, a time reporting system, to track staff?s time and charge personnel costs to the respective federal grant program. During the year, the Department of Personnel & Administration (DPA) and OIT were continuing to pursue the implementation of HR Works, a statewide integrated human resources and payroll system. HR Works is expected to provide the Department with the ability to accurately track and report personnel costs for all staff. DPA and OIT would share the responsibility for implementing and managing HR Works.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to assess the Department?s internal controls over personnel costs associated with its administration of federal grants and to determine whether it complied with federal cost regulations under Uniform Guidance.Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to federal grant personnel costs. Specifically, we recommended that the Department develop and implement interim policies and procedures to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations while it awaits the implementation of HR Works. The Department agreed with the recommendation and indicated that it would implement an interim process for those staff not currently using Clarity that complies with the federal cost regulation under Uniform Guidance. We first identified issues with the Department?s charging of personnel costs to its federal grants as a result of our Fiscal Year 2012 audit testwork.We performed testwork during our Fiscal Year 2019 audit to determine whether the Department implemented the prior audit recommendation and if it developed and implemented policies and procedures and an interim process to ensure that personnel costs were charged in accordance with federal regulations during Fiscal Year 2019. As part of our testing, we selected a random sample of 18 out of 81 semi-annual Periodic Time Certification Forms (Form) for the periods ending September 2018 and March 2019 (nine certifications from each period). These Forms are used by employees that worked on a single federal program during the fiscal year. We tested the sampled certifications to determine if they were signed in a timely manner by the employees? direct supervisors, as required by the Department?s internal policy.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [2 CFR 200.430] require that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award.The Department?s Time/Effort Reporting Policy (Policy) that was effective as of June 30, 2019, requires employees who work on multiple federal grant programs to complete a monthly Personnel Activity Report (Report) in order to allocate employees? salaries or wages to the various programs and activities. Employees who work solely on a single federal grant program must complete a semi-annual Form. The Form states that the supervisor has to sign the Form to certify the work performed by the employee.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully implement our Fiscal Year 2018 recommendation. Specifically, we found the following issues:? LACK OF TIME TRACKING. The Department did not require employees working on multiple federal grant programs to complete the Report on a monthly basis. As a result, the Department did not have information necessary to allocate the employees? time among the various programs.? LACK OF TIMELY CERTIFICATIONS. We found that in all 18 Forms we reviewed for employees who worked solely on a single federal grant program were not signed by the supervisors in a timely manner. Specifically, supervisors signed all 18 of the Forms in June or July 2019 for the semi-annual periods ending September 2018 and March 2019, or about 8 months and 3 months, respectively, after the end of the certified period and, in some cases, after the fiscal year-end. The timing of the signatures also occurred after we inquired of Department staff about their progress of implementing our Fiscal Year 2018 recommendation.WHY DID THESE PROBLEMS OCCUR?The Department did not implement an interim timekeeping mechanism during Fiscal Year 2019 to ensure that all personnel costs charged to Medicaid and CBHP were accurate, allowable, and properly allocated. Additionally, while the Department developed an interim policy for tracking all staff?s time, including employees who worked on multiple federal programs during Fiscal Year 2019, the Department did not implement this policy during Fiscal Year 2019 for all staff to ensure compliance with federal cost regulations under Uniform Guidance. Furthermore, the Department?s policies and procedures did not specify the time requirement for direct supervisors to review and sign periodic certifications in a timely manner.WHY DO THESE PROBLEMS MATTER?Lack of adequate internal controls over the charging of personnel costs to federal grants increases the risk that expenditures will be charged to the federal program incorrectly, and that the Department will not be in compliance with federal grant requirements. It is especially important that the Department take steps to demonstrate that it has fully implemented our prior audit recommendation, because the Department has been out of compliance for several years.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS XIX-MAP2017XIX-MAP2018XIX-MAP2019XIX-ADM2017XIX-ADM2018XIX-ADM2019 CHIP2017CHIP2018CHIP201917S&CTITLE19MEDICAID18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAIDFEDERAL AWARD YEARS 2017, 2018, AND 2019PASS THROUGH ENTITY NONECFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS; 93.778, MEDICAL ASSISTANCE PROGRAMCOMPLIANCE REQUIREMENTS ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-058 AND 2017-058RECOMMENDATION2019-051The Department of Health Care Policy and Financing (Department) should improve its internal controls over personnel costs by:A Implementing the Time/Effort Reporting Policy as an interim tracking mechanism for all staff time to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards while it awaits the implementation of the State?s new timekeeping system.B Updating the Department?s current policies and procedures to specify time requirements for the direct supervisors to review and sign periodic certifications.RESPONSEDEPARTMENT OF HEALTH CARE POLICY AND FINANCINGA AGREE. IMPLEMENTATION DATE: JULY 2020.The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other.Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs.B AGREE. IMPLEMENTATION DATE: JULY 2020.The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period.
(A) The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other.Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs.(B) The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period.
2019-051
INTERNAL CONTROLS OVER HIGHER EDUCATION EMERGENCY RELIEF FUNDS COMPLIANCE ALLOWABLE COSTS AND ACTIVITIES: COLORADO COMMUNITY COLLEGE SYSTEM?PUEBLO COMMUNITY COLLEGEThe Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was passed by Congress and signed by President Donald Trump on March 27, 2020. This bill allotted approximately $14 billion to the federal Office of Postsecondary Education as the Higher Education Emergency Relief Fund (HEERF). The majority of HEERF funding is broken into two main components, the Student Aid portion and the Institutional portion. The Student Aid portion provides funding to institutions to provide emergency financial aid grants to students whose lives have been disrupted due to the COVID-19 pandemic. The Institutional portion provides institutions the ability to cover any costs associated with significant changes to the delivery of instruction due to the coronavirus.The System received $35.1 million in HEERF funding during Fiscal Year 2020 through specific grant awards to schools within the System dated from April 25, 2020, to June 19, 2020. Due to the delays in receiving the federal grant award notifications, the Pueblo Community College (PCC) at the System initially charged grant-related expenses to general facilities funds. The final HEERF grant award noted colleges at the System were allowed to incur pre-award costs from March 13, 2020, the declaration of the national emergency due to the coronavirus, to the date of the HEERF grant award funds as long as those expenditures would have been allowable if incurred after the date of the HEERF grant award. Once the federal award notice was received, the System?s colleges began reclassifying allowable expenses to the HEERF grant award. PCC specifically reclassified amounts from the facilities funds to the HEERF grant funds.During the fiscal year ended June 30, 2020, the System expensed approximately $10.9 million of federal funds for this program. Of the $10.9 million expensed, $6.6 million related to the Student Aid portion and $4.3 million related to the Institutional portion.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2020.As part of our audit work we reviewed the System?s internal controls over allowable activities and allowable costs. In addition, we tested a random sample of 40 expenditure transactions charged to the HEERF program across nine schools, totaling $1,363,708, to determine whether the costs were necessary and reasonable under the HEERF program, and whether they complied with federal regulations and the System?s HEERF grant agreement.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following requirements:? The System previously established internal controls over its expenditure of federal funds, which were applied to the HEERF program. For example, the System?s internal control procedure requires that all grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and it must be reviewed for appropriateness and allowability under the applicable grant program by two individuals.? Section 18004 of the CARES Act details what is allowable to be expended under the grant. For the Institutional portion, an allowable grant expenditure must be to ?cover any costs associated with significant changes to the delivery of instruction due to the coronavirus ?.?? Federal Regulation [2 CFR 200.502, Basis for Determining Federal Awards Expended] states that ?the determination of when a Federal award is expended must be based on when the activity related to the Federal award occurs. Generally, the activity pertains to events that require the non-Federal entity to comply with Federal statutes, regulations, and the terms and conditions of Federal awards, such as ? the receipt of property?.?? Federal Regulation [2 CFR 200.303, Internal Controls] states that the System, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified one instance out of the 40 expenditure transactions tested (2.5 percent) that did not meet the requirements of the HEERF grant. Specifically, PCC combined a listing of 35 invoices and/or purchase orders totaling $77,598 into a single journal entry reclassification, but did not properly record 16 of the 34 invoices and 1 purchase order, totaling $57,118, in the accounting system, as noted below:? 10 invoices for face masks totaling $35,174 were reclassified from the facilities accounts twice, duplicating the correction in PCC?s accounting records; as a result, federal expenditures were overstated by $35,174, and facilities charges were understated by the same amount.? 6 invoices, primarily for hand sanitizer, totaling $11,888, were included in the reclassification journal entry as Fiscal Year 2020 federally-reimbursable expenditures, but were not received before June 30, 2020, as required by federal regulations; as a result, federal expenditures were overstated by $11,888. The original hand sanitizer order was cancelled, reordered, and paid for in Fiscal Year 2021 when different sanitizers became available.? One purchase order for disinfectant tablets, totaling $10,056, was included in the reclassification journal entry as a Fiscal Year 2020 federally-reimburseable expenditure, but the items were not available and the purchase order was cancelled. Thus, the amounts reclassified were for items that were not received before June 30, 2020, as required by federal regulations; as a result, federal expenditures were overstated by $10,056 and facilities charges were understated by the same amount.The errors we identified resulted in a total of $57,118 in known questioned costs for the HEERF grant for Fiscal Year 2020.We did not identify exceptions at any of the other System entities selected for testing.WHY DID THESE PROBLEMS OCCUR?The System did not ensure that PCC followed existing internal controls related to accounting for reclassification journal entries related to federal funds. Due to the initial uncertainty of HEERF funding and its requirements, PCC initially charged many expenditures to its general facilities fund and, upon formal grant award notification, subsequently reclassified the expenditures in bulk entries to the HEERF grant that were not adequately reviewed at an individual level for accuracy and appropriateness. Further, during April 2020, PCC experienced turnover within its Fiscal Office. As a result of the staff turnover and initial uncertainty of grant funding, PCC did not follow existing internal controls over federal expenditures to ensure that all federal program expenditures included required supporting documentation and were properly approved.WHY DO THESE PROBLEMS MATTER?The System?s failure to ensure PCC?s compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program at the System. In addition, corrections made by journal entry for large batches of transactions together could make it more difficult to support the proper redistribution of charges to federal programs.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425F202125*FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT ALLOWABLE ACTIVITIES (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $57,118KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $57,118THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-049The Colorado Community College System should ensure that PCC complies with federal requirements and grant agreements for the Higher Education Emergency Relief Fund by:A Enforcing internal controls which require that all expenditures charged to federal grants be for allowable expenditures, and that the expenditures be reviewed by two individuals and properly recorded in the accounting system.B Ensuring that all federal program expenditures include required supporting documentation.RESPONSECOLORADO COMMUNITY COLLEGE SYSTEMA AGREE. IMPLEMENTATION DATE: FEBRUARY 2021.PCC reviewed detailed transactions and postings related to HEERF from its inception through January 2021, making all corrections as needed from a cumulative perspective. Correcting entries were posted by the Controller and reviewed by the Business Officer as needed. Beginning February 2021, all journal entries will be approved by a supervisor at least one level higher than the preparer, ensuring allowability and appropriateness of the transaction.B AGREE. IMPLEMENTATION DATE: FEBRUARY 2021.PCC will ensure complete and accurate documentation is included as back up to support each journal entry. Each journal entry will indicate the reason for the adjustment and general ledger detail for the posted transactions being adjusted or corrected.
Show full finding ▾Hide full finding ▴INTERNAL CONTROLS OVER HIGHER EDUCATION EMERGENCY RELIEF FUNDS COMPLIANCE ALLOWABLE COSTS AND ACTIVITIES: COLORADO COMMUNITY COLLEGE SYSTEM?PUEBLO COMMUNITY COLLEGEThe Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was passed by Congress and signed by President Donald Trump on March 27, 2020. This bill allotted approximately $14 billion to the federal Office of Postsecondary Education as the Higher Education Emergency Relief Fund (HEERF). The majority of HEERF funding is broken into two main components, the Student Aid portion and the Institutional portion. The Student Aid portion provides funding to institutions to provide emergency financial aid grants to students whose lives have been disrupted due to the COVID-19 pandemic. The Institutional portion provides institutions the ability to cover any costs associated with significant changes to the delivery of instruction due to the coronavirus.The System received $35.1 million in HEERF funding during Fiscal Year 2020 through specific grant awards to schools within the System dated from April 25, 2020, to June 19, 2020. Due to the delays in receiving the federal grant award notifications, the Pueblo Community College (PCC) at the System initially charged grant-related expenses to general facilities funds. The final HEERF grant award noted colleges at the System were allowed to incur pre-award costs from March 13, 2020, the declaration of the national emergency due to the coronavirus, to the date of the HEERF grant award funds as long as those expenditures would have been allowable if incurred after the date of the HEERF grant award. Once the federal award notice was received, the System?s colleges began reclassifying allowable expenses to the HEERF grant award. PCC specifically reclassified amounts from the facilities funds to the HEERF grant funds.During the fiscal year ended June 30, 2020, the System expensed approximately $10.9 million of federal funds for this program. Of the $10.9 million expensed, $6.6 million related to the Student Aid portion and $4.3 million related to the Institutional portion.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the System had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the HEERF grant during Fiscal Year 2020.As part of our audit work we reviewed the System?s internal controls over allowable activities and allowable costs. In addition, we tested a random sample of 40 expenditure transactions charged to the HEERF program across nine schools, totaling $1,363,708, to determine whether the costs were necessary and reasonable under the HEERF program, and whether they complied with federal regulations and the System?s HEERF grant agreement.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following requirements:? The System previously established internal controls over its expenditure of federal funds, which were applied to the HEERF program. For example, the System?s internal control procedure requires that all grant expenditures must have adequate supporting documentation, such as an invoice and/or packing slip, included with the transaction and it must be reviewed for appropriateness and allowability under the applicable grant program by two individuals.? Section 18004 of the CARES Act details what is allowable to be expended under the grant. For the Institutional portion, an allowable grant expenditure must be to ?cover any costs associated with significant changes to the delivery of instruction due to the coronavirus ?.?? Federal Regulation [2 CFR 200.502, Basis for Determining Federal Awards Expended] states that ?the determination of when a Federal award is expended must be based on when the activity related to the Federal award occurs. Generally, the activity pertains to events that require the non-Federal entity to comply with Federal statutes, regulations, and the terms and conditions of Federal awards, such as ? the receipt of property?.?? Federal Regulation [2 CFR 200.303, Internal Controls] states that the System, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified one instance out of the 40 expenditure transactions tested (2.5 percent) that did not meet the requirements of the HEERF grant. Specifically, PCC combined a listing of 35 invoices and/or purchase orders totaling $77,598 into a single journal entry reclassification, but did not properly record 16 of the 34 invoices and 1 purchase order, totaling $57,118, in the accounting system, as noted below:? 10 invoices for face masks totaling $35,174 were reclassified from the facilities accounts twice, duplicating the correction in PCC?s accounting records; as a result, federal expenditures were overstated by $35,174, and facilities charges were understated by the same amount.? 6 invoices, primarily for hand sanitizer, totaling $11,888, were included in the reclassification journal entry as Fiscal Year 2020 federally-reimbursable expenditures, but were not received before June 30, 2020, as required by federal regulations; as a result, federal expenditures were overstated by $11,888. The original hand sanitizer order was cancelled, reordered, and paid for in Fiscal Year 2021 when different sanitizers became available.? One purchase order for disinfectant tablets, totaling $10,056, was included in the reclassification journal entry as a Fiscal Year 2020 federally-reimburseable expenditure, but the items were not available and the purchase order was cancelled. Thus, the amounts reclassified were for items that were not received before June 30, 2020, as required by federal regulations; as a result, federal expenditures were overstated by $10,056 and facilities charges were understated by the same amount.The errors we identified resulted in a total of $57,118 in known questioned costs for the HEERF grant for Fiscal Year 2020.We did not identify exceptions at any of the other System entities selected for testing.WHY DID THESE PROBLEMS OCCUR?The System did not ensure that PCC followed existing internal controls related to accounting for reclassification journal entries related to federal funds. Due to the initial uncertainty of HEERF funding and its requirements, PCC initially charged many expenditures to its general facilities fund and, upon formal grant award notification, subsequently reclassified the expenditures in bulk entries to the HEERF grant that were not adequately reviewed at an individual level for accuracy and appropriateness. Further, during April 2020, PCC experienced turnover within its Fiscal Office. As a result of the staff turnover and initial uncertainty of grant funding, PCC did not follow existing internal controls over federal expenditures to ensure that all federal program expenditures included required supporting documentation and were properly approved.WHY DO THESE PROBLEMS MATTER?The System?s failure to ensure PCC?s compliance with federal requirements for the HEERF program could result in disallowed costs and federal sanctions, including the termination of the federal program at the System. In addition, corrections made by journal entry for large batches of transactions together could make it more difficult to support the proper redistribution of charges to federal programs.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425F202125*FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT ALLOWABLE ACTIVITIES (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $57,118KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $57,118THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-049The Colorado Community College System should ensure that PCC complies with federal requirements and grant agreements for the Higher Education Emergency Relief Fund by:A Enforcing internal controls which require that all expenditures charged to federal grants be for allowable expenditures, and that the expenditures be reviewed by two individuals and properly recorded in the accounting system.B Ensuring that all federal program expenditures include required supporting documentation.RESPONSECOLORADO COMMUNITY COLLEGE SYSTEMA AGREE. IMPLEMENTATION DATE: FEBRUARY 2021.PCC reviewed detailed transactions and postings related to HEERF from its inception through January 2021, making all corrections as needed from a cumulative perspective. Correcting entries were posted by the Controller and reviewed by the Business Officer as needed. Beginning February 2021, all journal entries will be approved by a supervisor at least one level higher than the preparer, ensuring allowability and appropriateness of the transaction.B AGREE. IMPLEMENTATION DATE: FEBRUARY 2021.PCC will ensure complete and accurate documentation is included as back up to support each journal entry. Each journal entry will indicate the reason for the adjustment and general ledger detail for the posted transactions being adjusted or corrected.
(A) PCC reviewed detailed transactions and postings related to HEERF from its inception through January 2021, making all corrections as needed from a cumulative perspective. Correcting entries were posted by the Controller and reviewed by the Business Officer as needed. Beginning February 2021, all journal entries will be approved by a supervisor at least one level higher than the preparer, ensuring allowability and appropriateness of the transaction.(B) PCC will ensure complete and accurate documentation is included as back up to support each journal entry. Each journal entry will indicate the reason for the adjustment and general ledger detail for the posted transactions being adjusted or corrected.
EDUCATION STABILIZATION FUND?HIGHER EDUCATION EMERGENCY RELIEF FUND REPORTINGThe University received funds through the Education Stabilization Fund (ESF) that was established under the Coronavirus Aid, Relief and Economic Security Act (CARES Act). The ESF included the Higher Education Emergency Relief Fund (HEERF) program, which provided targeted aid to institutions of higher education directly from the U.S. Department of Education (DOE). The University spent funds under two portions of the HEERF program in Fiscal Year 2020, the Student Aid portion (CFDA No. 84.425E; award number P425E200411) and the Institutional portion (CFDA No. 84.425F; award number P425F201523). The University was awarded a total of approximately $14.4 million in HEERF funding in Fiscal Year 2020 and had spent approximately $6.8 million of the award as of June 30, 2020. The University plans to spend the remaining amount of funding during Fiscal Year 2021.The University signed an agreement called the Certification and Agreement with the federal DOE to indicate the University?s acceptance of the funding and the applicable terms and requirements under the HEERF grant. Under the Student Aid portion of the grant, the University was required to report to the Secretary of the DOE specified information related to HEERF Student Aid disbursed to students.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF reporting requirements related to the Student Aid Portion of the grant for Fiscal Year 2020.As part of our audit work, we inquired with University staff to understand the internal controls it had in place during Fiscal Year 2020 to ensure it complied with the reporting requirements. We also performed testing to determine whether the University met the requirement to report the information in a format and location that was easily accessible to the public (the University?s website) by the required due date and whether the information reported was accurate. Based on the timing of the University?s receipt of its allocation of HEERF Student Aid funds, the University was required to report twice prior toJune 30, 2020, and we tested both reports.HOW WERE THE RESULTS OF THEAUDIT WORK MEASURED?Section 18004(e) of the CARES Act requires each institution that received funds under Section 18004 to ?submit a report to the Secretary, at such time and in such manner as the Secretary may require." This reporting, as stated in the Certificate and Agreement, was due 30 days from the date of the Certification and Agreement and every 45 days thereafter. The DOE subsequently clarified the reporting requirements through its issuance of an Electronic Announcement (EA) onMay 6, 2020, which specified that the information must be posted ?in a location that is easily accessible to the public.? The EA also clarified the reporting timeframe to be ?30 days after the date when the institution received its allocation under the CARES Act and updated every 45 days thereafter?. The DoE obligated the Student Aid Portion of HEERF funds to the University on April 21, 2020, as listed in the Grant Award Notice; therefore, the University was required to post its initial report prior to May 21, 2020, and subsequent reports at least every 45 days thereafter. Because the University posted its initial report on May 11, 2020, the subsequent report should have been posted by June 25, 2020.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?Although the University initially reported the required elements publicly to its website on May 11, 2020, which was within the required timeframe, we found that the University did not post its second report to its website until January 15, 2021, or 204 days after the required due date of June 25, 2021. For both posts, we determined that the information was accurately reported and agreed to underlying supporting documentation.WHY DID THIS PROBLEM OCCUR?The University did not have adequate internal controls in place to ensure that it fully complied with the reporting requirements for the Student Aid portion of HEERF. Specifically, it did not have appropriate policies and procedures in place for identifying and researching the specific reporting requirements for the HEERF grant and to ensure that all reports were submitted by the due date.WHY DOES THIS PROBLEM MATTER?Federal oversight agencies, including DOE, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement, as clarified by the EA.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425E200411FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-050Metropolitan State University of Denver should strengthen its internal controls over and ensure it complies with federal Higher Education Emergency Relief Funds Program?s reporting requirements for the Student Aid portion of the HEERF grant by developing and implementing policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff submit the required reports within federally required timeframes.RESPONSEMETROPOLITAN STATE UNIVERSITYOF DENVERAGREE. IMPLEMENTATION DATE: JANUARY 2021.Distribution and compliance reporting on the student portion of the HEERF grant was delegated to the Office of Financial Aid and Scholarships (OFAS). OFAS did not adequately assign the responsibility to complete compliance reporting. This was an oversight exacerbated by significant loss in staff, adapting to a remote work environment and frequent changes to guidance surrounding HEERF funding. To address the issue OFAS created a centralized network folder to maintain data for periodic reporting and modified the OFAS CARES Act reporting website to appropriately display periodic reports and disclosures related to compliance. These adjustments to our process were implemented immediately in order to ensure an expedient resolution of the deficiency discovered by the auditors and continued adherence to the dynamic guidance offered by the US Department of Education. In order to better establish the responsibilities for procedures, awarding and reporting HEERF funds, we designated specific tasks to OFAS staff.? FA Accountant- tracking and reconciliation of the HEERF student share, data collection, collaboration on reporting? Associate Director of Reporting and Communication- website updates, assist data collection and collaboration on reporting? Director of FA Operations and Systems- oversight of awarding process and collaboration on reporting? Executive Director of Financial Aid- internal point of contact, oversight of administration, ED guidance review, compliance and reportingStaff will meet two weeks prior to the close of each quarter and again prior the reporting deadline to ensure timely and accurate compliance reporting through continuous review and implementation of ED guidance.
Show full finding ▾Hide full finding ▴EDUCATION STABILIZATION FUND?HIGHER EDUCATION EMERGENCY RELIEF FUND REPORTINGThe University received funds through the Education Stabilization Fund (ESF) that was established under the Coronavirus Aid, Relief and Economic Security Act (CARES Act). The ESF included the Higher Education Emergency Relief Fund (HEERF) program, which provided targeted aid to institutions of higher education directly from the U.S. Department of Education (DOE). The University spent funds under two portions of the HEERF program in Fiscal Year 2020, the Student Aid portion (CFDA No. 84.425E; award number P425E200411) and the Institutional portion (CFDA No. 84.425F; award number P425F201523). The University was awarded a total of approximately $14.4 million in HEERF funding in Fiscal Year 2020 and had spent approximately $6.8 million of the award as of June 30, 2020. The University plans to spend the remaining amount of funding during Fiscal Year 2021.The University signed an agreement called the Certification and Agreement with the federal DOE to indicate the University?s acceptance of the funding and the applicable terms and requirements under the HEERF grant. Under the Student Aid portion of the grant, the University was required to report to the Secretary of the DOE specified information related to HEERF Student Aid disbursed to students.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF reporting requirements related to the Student Aid Portion of the grant for Fiscal Year 2020.As part of our audit work, we inquired with University staff to understand the internal controls it had in place during Fiscal Year 2020 to ensure it complied with the reporting requirements. We also performed testing to determine whether the University met the requirement to report the information in a format and location that was easily accessible to the public (the University?s website) by the required due date and whether the information reported was accurate. Based on the timing of the University?s receipt of its allocation of HEERF Student Aid funds, the University was required to report twice prior toJune 30, 2020, and we tested both reports.HOW WERE THE RESULTS OF THEAUDIT WORK MEASURED?Section 18004(e) of the CARES Act requires each institution that received funds under Section 18004 to ?submit a report to the Secretary, at such time and in such manner as the Secretary may require." This reporting, as stated in the Certificate and Agreement, was due 30 days from the date of the Certification and Agreement and every 45 days thereafter. The DOE subsequently clarified the reporting requirements through its issuance of an Electronic Announcement (EA) onMay 6, 2020, which specified that the information must be posted ?in a location that is easily accessible to the public.? The EA also clarified the reporting timeframe to be ?30 days after the date when the institution received its allocation under the CARES Act and updated every 45 days thereafter?. The DoE obligated the Student Aid Portion of HEERF funds to the University on April 21, 2020, as listed in the Grant Award Notice; therefore, the University was required to post its initial report prior to May 21, 2020, and subsequent reports at least every 45 days thereafter. Because the University posted its initial report on May 11, 2020, the subsequent report should have been posted by June 25, 2020.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?Although the University initially reported the required elements publicly to its website on May 11, 2020, which was within the required timeframe, we found that the University did not post its second report to its website until January 15, 2021, or 204 days after the required due date of June 25, 2021. For both posts, we determined that the information was accurately reported and agreed to underlying supporting documentation.WHY DID THIS PROBLEM OCCUR?The University did not have adequate internal controls in place to ensure that it fully complied with the reporting requirements for the Student Aid portion of HEERF. Specifically, it did not have appropriate policies and procedures in place for identifying and researching the specific reporting requirements for the HEERF grant and to ensure that all reports were submitted by the due date.WHY DOES THIS PROBLEM MATTER?Federal oversight agencies, including DOE, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement, as clarified by the EA.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425E200411FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-050Metropolitan State University of Denver should strengthen its internal controls over and ensure it complies with federal Higher Education Emergency Relief Funds Program?s reporting requirements for the Student Aid portion of the HEERF grant by developing and implementing policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff submit the required reports within federally required timeframes.RESPONSEMETROPOLITAN STATE UNIVERSITYOF DENVERAGREE. IMPLEMENTATION DATE: JANUARY 2021.Distribution and compliance reporting on the student portion of the HEERF grant was delegated to the Office of Financial Aid and Scholarships (OFAS). OFAS did not adequately assign the responsibility to complete compliance reporting. This was an oversight exacerbated by significant loss in staff, adapting to a remote work environment and frequent changes to guidance surrounding HEERF funding. To address the issue OFAS created a centralized network folder to maintain data for periodic reporting and modified the OFAS CARES Act reporting website to appropriately display periodic reports and disclosures related to compliance. These adjustments to our process were implemented immediately in order to ensure an expedient resolution of the deficiency discovered by the auditors and continued adherence to the dynamic guidance offered by the US Department of Education. In order to better establish the responsibilities for procedures, awarding and reporting HEERF funds, we designated specific tasks to OFAS staff.? FA Accountant- tracking and reconciliation of the HEERF student share, data collection, collaboration on reporting? Associate Director of Reporting and Communication- website updates, assist data collection and collaboration on reporting? Director of FA Operations and Systems- oversight of awarding process and collaboration on reporting? Executive Director of Financial Aid- internal point of contact, oversight of administration, ED guidance review, compliance and reportingStaff will meet two weeks prior to the close of each quarter and again prior the reporting deadline to ensure timely and accurate compliance reporting through continuous review and implementation of ED guidance.
Distribution and compliance reporting on the student portion of the HEERF grant was delegated to the Office of Financial Aid and Scholarships (OFAS). OFAS did not adequately assign the responsibility to complete compliance reporting. This was an oversight exacerbated by significant loss in staff, adapting to a remote work environment and frequent changes to guidance surrounding HEERF funding. To address the issue OFAS created a centralized network folder to maintain data for periodic reporting and modified the OFAS CARES Act reporting website to appropriately display periodic reports and disclosures related to compliance. These adjustments to our process were implemented immediately in order to ensure an expedient resolution of the deficiency discovered by the auditors and continued adherence to the dynamic guidance offered by the US Department of Education. In order to better establish the responsibilities for procedures, awarding and reporting HEERF funds, we designated specific tasks to OFAS staff.- FA Accountant - tracking and reconciliation of the HEERF student share, data collection, collaboration on reporting- Associate Director of Reporting and Communication - website updates, assist data collection and collaboration on reporting- Director of FA Operations and Systems - oversight of awarding process and collaboration on reporting- Executive Director of Financial Aid - internal point of contact, oversight of administration, ED guidance review, compliance and reportingStaff will meet two weeks prior to the close of each quarter and again prior the reporting deadline to ensure timely and accurate compliance reporting through continuous review and implementation of ED guidance.
HIGHER EDUCATION EMERGENCY RELIEF FUND (HEERF) REPORTING COMPLIANCEThe Coronavirus Aid, Relief and Economic Security Act (CARES Act) appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF) Program. The HEERF program contains two portions, the Student Aid portion (CFDA No. 84.425E) and the Institutional portion (CFDA 84.425F). The University must use fifty percent of the total amount received under the HEERF program for the Student Aid portion of the grant. The University was awarded a total of $37.3 million in HEERF funding and must spend the total award by May 2, 2021, which represents one calendar year from the date of the award. As of June 30, 2020, the University spent approximately $12.7 million for the HEERF program Student Aid portion and $5.1 million for the HEERF program Institutional Portion. The remaining amount of funding will be spent during Fiscal Year 2021.The University campuses separately signed an agreement with the U.S. Department of Education (DOE) called the Certification and Agreement to indicate their acceptance of the funding and the applicable terms and requirements under the HEERF program. Under the Student Aid Portion, the University was required under the Certification and Agreement to report to the Secretary of the DOE specified information regarding amounts distributed to students. This reporting, as stated in the. Certificate and Agreement, was due 30 days from the date of the Certification and Agreement and every 45 days thereafter. The Certificate and Agreement was subsequently clarified by an Electronic Announcement (EA) issued by the DOE and specified that the information be posted to the applicable campus? website within 30 days after the date of the EA.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Student Aid Portion grant reporting requirements for Fiscal Year 2020.As part of our audit work, we inquired with University staff at the Boulder, Colorado Springs, and Denver/Anschutz campuses on their processes for completing the initial federal HEERF reports, and performed testing to determine whether the campuses posted the reports to their respective websites by the required due date. We obtained documentation from the University Information Services (UIS) department that indicated the date the campuses publicly posted the report information to their respective websites.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Section 18004(e) of the CARES Act requires each institution that received a 18004 (a)(1) Student Aid Portion of the HEERF program to submit a report detailing the amounts distributed to students and how the distribution was performed to the Secretary of the federal DOE ``at such time and in such manner as the Secretary may require.?? The DOE later clarified through an EA issued on May 6, 2020, that Institutions of Higher Education were required to publicly post the reported information on their websites within 30 days from the date of the EA, or 30 days from the date the federal DOE obligated funds, whichever is later. The federal DOE obligated the funds to the University of Colorado, Colorado Springs and Denver/Anschutz Medical campuses on April 24, 2020, and to the University of Colorado Boulder campus on May 2, 2020. The EA date of May 6, 2020, is later than the dates the funds were obligated to the campuses, therefore, each campus should have posted the report to its respective website by June 6, 2020, or 30 days from the date of the EA.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?The University of Colorado Colorado Springs campus did not post the required documentation on its website until July 7, 2020, or 31 days after the required deadline. The University of Colorado Boulder and University of Colorado Denver/Anschutz Medical campuses both posted the required information timely.WHY DID THIS PROBLEM OCCUR?The University did not have adequate internal controls in place at its Colorado Springs campus related to reporting requirements for the HEERF program. Specifically, although University staff responsible for the HEERF reporting indicated that they were initially confused as to when the 30-day reporting timeframe began and ended, the Colorado Springs campus did not have procedures in place for identifying and researching applicable requirements to ensure that any confusion regarding specific report due dates, including the initial report due date, was resolved before the due date.WHY DOES THIS PROBLEM MATTER?Federal oversight agencies, including DOE, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement, as clarified by the EA.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425E201676FEDERAL AWARD YEARS 2020 AND 2021PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-051The University of Colorado System should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Funds Program's reporting requirements by requiring the Colorado Springs campus to develop policies and procedures for identifying and researching the specific requirements and ensuring that staff submit the required reports within federally required timeframes.RESPONSEUNIVERSITY OF COLORADOAGREE. IMPLEMENTATION DATE: JANUARY 2021.The University concurs with the finding. Appropriate internal controls have been implemented as of January 2021 to ensure all required federal reporting under the HEERF program is completed in a timely and accurate manner.
Show full finding ▾Hide full finding ▴HIGHER EDUCATION EMERGENCY RELIEF FUND (HEERF) REPORTING COMPLIANCEThe Coronavirus Aid, Relief and Economic Security Act (CARES Act) appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF) Program. The HEERF program contains two portions, the Student Aid portion (CFDA No. 84.425E) and the Institutional portion (CFDA 84.425F). The University must use fifty percent of the total amount received under the HEERF program for the Student Aid portion of the grant. The University was awarded a total of $37.3 million in HEERF funding and must spend the total award by May 2, 2021, which represents one calendar year from the date of the award. As of June 30, 2020, the University spent approximately $12.7 million for the HEERF program Student Aid portion and $5.1 million for the HEERF program Institutional Portion. The remaining amount of funding will be spent during Fiscal Year 2021.The University campuses separately signed an agreement with the U.S. Department of Education (DOE) called the Certification and Agreement to indicate their acceptance of the funding and the applicable terms and requirements under the HEERF program. Under the Student Aid Portion, the University was required under the Certification and Agreement to report to the Secretary of the DOE specified information regarding amounts distributed to students. This reporting, as stated in the. Certificate and Agreement, was due 30 days from the date of the Certification and Agreement and every 45 days thereafter. The Certificate and Agreement was subsequently clarified by an Electronic Announcement (EA) issued by the DOE and specified that the information be posted to the applicable campus? website within 30 days after the date of the EA.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Student Aid Portion grant reporting requirements for Fiscal Year 2020.As part of our audit work, we inquired with University staff at the Boulder, Colorado Springs, and Denver/Anschutz campuses on their processes for completing the initial federal HEERF reports, and performed testing to determine whether the campuses posted the reports to their respective websites by the required due date. We obtained documentation from the University Information Services (UIS) department that indicated the date the campuses publicly posted the report information to their respective websites.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Section 18004(e) of the CARES Act requires each institution that received a 18004 (a)(1) Student Aid Portion of the HEERF program to submit a report detailing the amounts distributed to students and how the distribution was performed to the Secretary of the federal DOE ``at such time and in such manner as the Secretary may require.?? The DOE later clarified through an EA issued on May 6, 2020, that Institutions of Higher Education were required to publicly post the reported information on their websites within 30 days from the date of the EA, or 30 days from the date the federal DOE obligated funds, whichever is later. The federal DOE obligated the funds to the University of Colorado, Colorado Springs and Denver/Anschutz Medical campuses on April 24, 2020, and to the University of Colorado Boulder campus on May 2, 2020. The EA date of May 6, 2020, is later than the dates the funds were obligated to the campuses, therefore, each campus should have posted the report to its respective website by June 6, 2020, or 30 days from the date of the EA.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?The University of Colorado Colorado Springs campus did not post the required documentation on its website until July 7, 2020, or 31 days after the required deadline. The University of Colorado Boulder and University of Colorado Denver/Anschutz Medical campuses both posted the required information timely.WHY DID THIS PROBLEM OCCUR?The University did not have adequate internal controls in place at its Colorado Springs campus related to reporting requirements for the HEERF program. Specifically, although University staff responsible for the HEERF reporting indicated that they were initially confused as to when the 30-day reporting timeframe began and ended, the Colorado Springs campus did not have procedures in place for identifying and researching applicable requirements to ensure that any confusion regarding specific report due dates, including the initial report due date, was resolved before the due date.WHY DOES THIS PROBLEM MATTER?Federal oversight agencies, including DOE, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement, as clarified by the EA.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBER P425E201676FEDERAL AWARD YEARS 2020 AND 2021PASS THROUGH ENTITY NONECFDA NO. 84.425, EDUCATION STABILIZATION FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-051The University of Colorado System should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Funds Program's reporting requirements by requiring the Colorado Springs campus to develop policies and procedures for identifying and researching the specific requirements and ensuring that staff submit the required reports within federally required timeframes.RESPONSEUNIVERSITY OF COLORADOAGREE. IMPLEMENTATION DATE: JANUARY 2021.The University concurs with the finding. Appropriate internal controls have been implemented as of January 2021 to ensure all required federal reporting under the HEERF program is completed in a timely and accurate manner.
The University concurs with the finding. Appropriate internal controls have been implemented as of January 2021 to ensure all required federal reporting under the HEERF program is completed in a timely and accurate manner.
COLORADO CHILD CARE ASSISTANCE PROGRAM? ELIGIBILITYThe federal Child Care and Development Fund Cluster [CFDA No. 93.575, Child Care and Development Block Grant; and CFDA No. 93.596, Child Care Mandatory and Matching Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents or adult caretakers of the children are working, or attending training or educational programs. The federal Child Care and Development Fund Cluster was enacted under Title IV-A of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP). During Fiscal Year 2020, due to the COVID-19 pandemic, the CCCAP received additional funding from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act).The Department?s Division of Early Care and Learning (Program Division) is responsible for overseeing the CCCAP and ensuring that the Department complies with federal and state requirements for this program. The CCCAP is administered at the local level by the county departments of human/social services, and the Department is responsible for monitoring the counties? administration of the CCCAP. County caseworkers enter a CCCAP adult caretaker?s application information, including household employment and income, household size, and the names and number of children needing care into the Department?s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker?s household income must not exceed 85 percent of the State?s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker.In addition to families that apply for child care assistance, the CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient.The Department?s Division of Quality Assurance and Quality Improvement (QA Division) is responsible for the CCCAP quality assurance review process. Specifically, the QA Division reviews a sample of case files from the counties to determine whether caseworkers maintained relevant and appropriate case file documentation, and properly entered required information, such as household income, into CHATS. The QA Division then provides identified exceptions to the reviewed counties and requires them to provide a corrective action plan to address the issues.The Program Division also performs on-site reviews of the counties, which include a review of the county?s policies and procedures, training, program operations, interviews with county staff, and correcting errors identified by the QA Division reviews.During Fiscal Year 2020, the Department provided approximately$116.5 million in child care benefits through the CCCAP for 26,541 children.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over CCCAP eligibility and enrollment processing, and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2020.During our audit, we reviewed the Department?s internal controls over CCCAP in place during Fiscal Year 2020. In addition, we performed testing of a sample of 25 children who were eligible for child care services through the CCCAP and received $86,404 in CCCAP child care benefits during Fiscal Year 2020 to determine whether the children?s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. We also reviewed the Department?s monitoring processes over the counties? administration of the CCCAP.We have identified eligibility errors for CCCAP through our financial and compliance audits at the Department since Fiscal Year 2013. As part of our Fiscal Year 2020 audit, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendations related to the CCCAP. During that audit, we recommended that the Department strengthen its internal controls over the CCCAP by ensuring that county caseworkers are appropriately trained on CCCAP areas and representatives from all counties attend training; working with counties to incorporate a secondary or supervisory review process over case files to ensure timely notification of eligibility decisions to adult caretakers, timely closure of cases, and parent fees are calculated correctly; and resolving CHATS issues that we identified through our audit related to eligibility notifications and CHATS parent-fee rounding errors. The Department agreed with those recommendations and stated that it would implement them by July 2020.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not comply with federal and state CCCAP requirements during Fiscal Year 2020. Specifically, in 10 of the 25 case files tested (40 percent), we identified at least one error. These errors resulted in a total of $4,421 in known questioned costs; $2,885 of these costs were paid with federal grant funds and $0 were paid with federal CARES Act funds. The errors we identified are outlined as follows:MISSING DOCUMENTATION. In four cases, the Department did not provide required supporting documentation for the case files. In three of these cases the Department did not provide support for the income and the parent-fee calculation, including verification of the adult caretaker?s employment and the amount of income earned. In the remaining case, the missing documentation included a utility bill used to determine the county residence. These errors resulted in known questioned costs of $4,085. In a separate case, a caseworker had granted benefits for a child in a protective services case, but the child?s name was not on the referral form; rather, the names of two of the child?s siblings were noted on the form. The Department subsequently provided documentation showing the child was eligible to receive child care benefits.The Department?s State Plan (Child Care and Development Fund Plan for Colorado 3.1.9) specifies the documentation requirements for eligibility determination or redetermination, which include for example, an application made on the behalf of a child to receive CCCAP benefits that identifies the child, family income documentation, and residency documentation. State regulation [Section 3.905.1.H.4, 9 CCR 2503-9] also specifies that earned income must be verified with either written documentation or verbal verification from the applicant?s employer that shall be documented in the case file including the date, the name of the individual who provided the information, and the phone number.ERRORS RELATED TO PARENT FEE AND ADULT CARETAKER INCOME. In nine cases, the parent fee and/or the adult caretaker?s income were not calculated correctly. For example, in three cases, the caseworker failed to include the appropriate amount of the adult caretaker?s provided income when determining the adult caretaker?s eligibility for their children to receive child care benefits. In two of these three cases, the exclusion of this income resulted in the adult caretakers being charged a lower parent fee. These errors resulted in four adult caretakers being underbilled by $342 and one adult caretaker being overbilled by $6. Since parent fees are required to be paid before CCCAP benefits are paid, this led to total known questioned costs of $336.State regulation [Section 3.905.1.I, 9 CCR 2503-9] specifies that gross earnings, including wages and child support payments, must be included in an adult caretaker?s income for the purposes of determining CCCAP eligibility and calculating parent fees. State regulation [Section 3.903, 9 CCR 2503-9] defines a parent fee as a copayment that must be made by an adult caretaker to the child care provider prior to any state/county child care funds payment. State regulation [Section 3.911.A, 9 CCR 2503-9] specifies that parent fees are based on gross countable income compared to the household size and the number of children using child care.ERRORS RELATED TO AUTHORIZATION NOTICES. In one case, the caseworker failed to send the state-prescribed authorization form to the adult caretaker and instead, the caseworker sent an email to the adult caretaker. This error did not result in known questioned costs because the error did not negatively affect the children?s eligibility.State regulation [Section 3.903, 9 CCR 2503-9] requires caseworkers to notify the adult caretaker of the approval and any change in their child care benefits, as applicable; this notification must be sent on the state-prescribed authorization form.Overall, we determined that the Department did not fully implement the Fiscal Year 2019 CCCAP recommendations. The Department did provide evidence that it conducted required CCCAP training, including optional monthly trainings and webinars, for all counties during the fiscal year and resolved the CHATS issues identified in the prior audit relating to eligibility notifications and parent fee rounding errors. During Fiscal Year 2020, the Department did not incorporate a secondary or supervisory review process, but started discussions with the counties to determine the feasibility of incorporating these reviews.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the U.S. Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book) under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHY DID THESE PROBLEMS OCCUR?The Department lacked sufficient internal controls to ensure compliance with state and federal requirements for the CCCAP during Fiscal Year 2020. We noted the following causes for the identified errors:LACK OF BACK-UP DOCUMENTATION PLAN. Based on discussion with the Program Division, some of the counties were unable to access their case files due to local shutdowns during the pandemic. In these cases, the counties maintained the case file documentation only in hardcopy. Therefore, the Program Division and these counties had no access to the supporting documentation we requested for the audit.SECONDARY REVIEWS NOT REQUIRED. Based on our testing, the Department has not instituted a required secondary review process at the counties over child care case files during Fiscal Year 2020, which we recommended as a result of our Fiscal Year 2019 audit testing. During Fiscal Year 2020, the Department conducted an assessment of county monitoring policies and had several meetings with the counties to discuss a secondary review process of case files and get feedback from the counties for the process, but had not implemented a required secondary review by the end of the fiscal year.INCOMPLETE STATE PLAN. The State Plan does not specify different documentation requirements for determining or redetermining eligibility for protective services child care and Colorado Works child care cases. The Department stated that it does not currently require counties to maintain any eligibility documentation, such as the referral form, to support the protective services child care and Colorado Works child care cases; however this is not stated or addressed in the State Plan or in state regulations. At the end of Fiscal Year 2020, there were 461 protective services children and 5,020 Colorado Works children receiving child care benefits.DEPARTMENT IS NOT MONITORING EFFECTIVELY. The Department does not have an effective and complete monitoring process as follows:? LACK OF PERFORMANCE MEASURES FOR COUNTY MONITORING. Federal regulation [45 CFR 98.11(a)(3)] requires the Department to have written agreements in place with the counties which describe the counties? roles and responsibilities, including indicators or measures to assess performance. During Fiscal Year 2020, the Department had not established CCCAP performance measures to evaluate and improve counties? performance. Specifically, the Program Division?s written agreements with counties in Fiscal Year 2020 did not include any indicators or measures to assess county performance as federally required, such as processing times for applications, response times for correcting the identified issues found during the Program Division?s monitoring and QA Division processes, or participation in trainings. Furthermore, the Department has not established overall CCCAP eligibility and redetermination error-rate thresholds for counties.? NO METHOD FOR ACCUMULATION OF DATA. The Department did not have a method to accumulate and assess the errors identified through its monitoring processes. As a result, the Department lacked valuable information for assessing county performance and identifying areas for increased monitoring and focused county training. Specifically, the QA Division?s reviews are not being used by the Department to assess county performance. We found that the QA Division had not accumulated the results of their quality assurance reviews in order to assess the county or overall state performance. We reviewed the QA Division?s Fiscal Year 2020 listing of quality assurance reviews and determined the QA Division conducted reviews of 299 CCCAP case files from 28 out of64 counties and found that 203 of these 299 cases (68 percent) contained at least one identified issue. We also reviewed the QA Division?s Fiscal Year 2019 listing of quality assurance reviews and found that the error rate for Fiscal Year 2020 has significantly increased from the QA Division?s 30-percent error rate during Fiscal Year 2019. The QA Division identified errors with the income calculation, the parent fee, missing documentation, errors in CHATS, errors due to not updating CHATS, incomplete applications, and incomplete employment verification.? FAILURE TO ENFORCE COUNTIES? CORRECTION OF ERRORS. The Department did not ensure that all counties were responding to errors identified in a timely manner. Specifically, during Fiscal Year 2020, the Program Division conducted on-site reviews in 19 counties. We selected five of the review reports and related documentation to determine whether the identified errors were corrected by the county after the review. We found that four of these counties corrected the errors between 7 and 145 days after the deadline.WHY DO THESE PROBLEMS MATTER?It is essential for the Department to ensure that child care eligibility is properly determined and in accordance with state and federal regulations. Inaccurate processing of case file information to determine eligibility can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures.Due to the COVID-19 pandemic, there has been an increase in individuals needing child care assistance. Therefore, when county caseworkers incorrectly determine eligibility, it can negatively affect other eligible children. Specifically, counties put newly eligible children on a waitlist if the county does not have enough resources to pay for their benefits. As of June 30, 2020, there were 54 children in four counties on a CCCAP waitlist in Colorado. In addition, two counties stopped processing applications during the fiscal year due to limited resources. When eligibility is improperly granted, eligible children on the waitlist are delayed from receiving benefits.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1801COCCDF*1901COCCDF*2001COCCC3*2001COCCDF*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.575*, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596*, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $4,013KNOWN QUESTIONED COSTS RELATED TO COVID EMERGENCY $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-058A AND 2019-058B*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-052The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Colorado Child Care Assistance Program (Program) requirements by:A Evaluating whether changes are necessary to policies and procedures to ensure that in the event of a local or statewide shutdown, the Department and the county departments of human/social services are still able to access their Program case files and documentation.B Continuing to work with counties to implement a secondary or supervisory review process over case files after eligibility is determined to address the issues identified in the audit and in quality assurance reviews.C Incorporating documentation requirements into the State Plan for protective services and Temporary Assistance for Needy Families child care cases and ensuring the Program case files include this required documentation.D Improving its monitoring processes by:i. Establishing indicators or measures to assess performance for counties in the annual written agreements and developing a monitoring program, to determine if the individual counties are in compliance with performance measures as well as Federal and State regulations.ii. Developing a formal method to accumulate and assess errors at each county that will allow the Department to analyze error rates for the entire state as well as on a county by county basis and using the information to implement a targeted training and improvement plan for all errors identified.iii. Enforcing counties? correction of errors in a timely manner.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department agrees to evaluate with internal leadership whether changes to policies and procedures are necessary for accessing program files for audit purposes during a local or statewide shutdown. The Department recognizes that the pandemic impacted the OSA test-work. Specifically, one county temporarily had to shut down its building due to the pandemic. Two of these cases accounted for $4,085, which represents 92% of the questioned costs noted in the audit.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to continue to work with counties on a secondary review process over case files after eligibility is determined.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees and will identify a process to incorporate and ensure compliance with documentation requirements in the updated State Plan for protective services and Temporary Assistance for Needy Families child care cases. Due to the sensitive nature of protective services child care cases, the Department will need to work internally with the Division of Child Welfare to define the documentation requirements for protective services cases.D AGREE. IMPLEMENTATION DATE: JULY 2022.i. AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to establish indicators or measures to assess performance for counties and will identify the county?s requirement to comply in the MOU. In addition, the Department will develop a monitoring program to determine if the individual counties are in compliance with performance measures, as well as Federal and State regulations. This implementation date aligns with the annual review of the CDHS CCCAP Colorado Works Memorandum of Understanding. Developing a formal method to accumulate and assess errors at each county that will allow the Department to analyze error rates for the entire state as well as on a county by county basis and using the information to implement a targeted training and improvement plan for all errors identified.ii. AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to develop a formal method to accumulate and assess errors through a variety of data points. The Department will evaluate each county and analyze error rates for the entire state, as well as on a county by county basis. The Department will then use this information to implement a targeted training and/or improvement plan.iii. AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department agrees to enforce counties? correction of errors in a timely manner as defined by the Department's updated policies and procedures.
Show full finding ▾Hide full finding ▴COLORADO CHILD CARE ASSISTANCE PROGRAM? ELIGIBILITYThe federal Child Care and Development Fund Cluster [CFDA No. 93.575, Child Care and Development Block Grant; and CFDA No. 93.596, Child Care Mandatory and Matching Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents or adult caretakers of the children are working, or attending training or educational programs. The federal Child Care and Development Fund Cluster was enacted under Title IV-A of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP). During Fiscal Year 2020, due to the COVID-19 pandemic, the CCCAP received additional funding from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act).The Department?s Division of Early Care and Learning (Program Division) is responsible for overseeing the CCCAP and ensuring that the Department complies with federal and state requirements for this program. The CCCAP is administered at the local level by the county departments of human/social services, and the Department is responsible for monitoring the counties? administration of the CCCAP. County caseworkers enter a CCCAP adult caretaker?s application information, including household employment and income, household size, and the names and number of children needing care into the Department?s Child Care Automated Tracking System (CHATS). CHATS aggregates the information for the county caseworker to determine whether an adult caretaker applying for benefits will be eligible for CCCAP assistance. For example, the adult caretaker?s household income must not exceed 85 percent of the State?s median household income. CHATS uses the household income and the household size entered by the county caseworker to calculate the copayment amount, or parent fee, the household must pay per month for child care services. CHATS then generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the adult caretaker.In addition to families that apply for child care assistance, the CCCAP also provides child care benefits for children in protective services and for families in the Temporary Assistance for Needy Families, or Colorado Works, program. Children in protective services have been placed by the county departments of human/social services in a foster care home. The Colorado Works program provides assistance to families in need by providing benefits to help families become self-sufficient.The Department?s Division of Quality Assurance and Quality Improvement (QA Division) is responsible for the CCCAP quality assurance review process. Specifically, the QA Division reviews a sample of case files from the counties to determine whether caseworkers maintained relevant and appropriate case file documentation, and properly entered required information, such as household income, into CHATS. The QA Division then provides identified exceptions to the reviewed counties and requires them to provide a corrective action plan to address the issues.The Program Division also performs on-site reviews of the counties, which include a review of the county?s policies and procedures, training, program operations, interviews with county staff, and correcting errors identified by the QA Division reviews.During Fiscal Year 2020, the Department provided approximately$116.5 million in child care benefits through the CCCAP for 26,541 children.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over CCCAP eligibility and enrollment processing, and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2020.During our audit, we reviewed the Department?s internal controls over CCCAP in place during Fiscal Year 2020. In addition, we performed testing of a sample of 25 children who were eligible for child care services through the CCCAP and received $86,404 in CCCAP child care benefits during Fiscal Year 2020 to determine whether the children?s eligibility was correctly determined. Our testing included reviewing the supporting documentation and the case files for each sample, along with the accuracy of data entered into CHATS. We performed testwork to determine whether the county caseworkers obtained and maintained the required documents supporting the eligibility determinations and annual redeterminations in the case files and determined eligibility in a timely manner. We also reviewed the Department?s monitoring processes over the counties? administration of the CCCAP.We have identified eligibility errors for CCCAP through our financial and compliance audits at the Department since Fiscal Year 2013. As part of our Fiscal Year 2020 audit, we reviewed the Department?s progress in implementing our Fiscal Year 2019 audit recommendations related to the CCCAP. During that audit, we recommended that the Department strengthen its internal controls over the CCCAP by ensuring that county caseworkers are appropriately trained on CCCAP areas and representatives from all counties attend training; working with counties to incorporate a secondary or supervisory review process over case files to ensure timely notification of eligibility decisions to adult caretakers, timely closure of cases, and parent fees are calculated correctly; and resolving CHATS issues that we identified through our audit related to eligibility notifications and CHATS parent-fee rounding errors. The Department agreed with those recommendations and stated that it would implement them by July 2020.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED?We found that the Department did not comply with federal and state CCCAP requirements during Fiscal Year 2020. Specifically, in 10 of the 25 case files tested (40 percent), we identified at least one error. These errors resulted in a total of $4,421 in known questioned costs; $2,885 of these costs were paid with federal grant funds and $0 were paid with federal CARES Act funds. The errors we identified are outlined as follows:MISSING DOCUMENTATION. In four cases, the Department did not provide required supporting documentation for the case files. In three of these cases the Department did not provide support for the income and the parent-fee calculation, including verification of the adult caretaker?s employment and the amount of income earned. In the remaining case, the missing documentation included a utility bill used to determine the county residence. These errors resulted in known questioned costs of $4,085. In a separate case, a caseworker had granted benefits for a child in a protective services case, but the child?s name was not on the referral form; rather, the names of two of the child?s siblings were noted on the form. The Department subsequently provided documentation showing the child was eligible to receive child care benefits.The Department?s State Plan (Child Care and Development Fund Plan for Colorado 3.1.9) specifies the documentation requirements for eligibility determination or redetermination, which include for example, an application made on the behalf of a child to receive CCCAP benefits that identifies the child, family income documentation, and residency documentation. State regulation [Section 3.905.1.H.4, 9 CCR 2503-9] also specifies that earned income must be verified with either written documentation or verbal verification from the applicant?s employer that shall be documented in the case file including the date, the name of the individual who provided the information, and the phone number.ERRORS RELATED TO PARENT FEE AND ADULT CARETAKER INCOME. In nine cases, the parent fee and/or the adult caretaker?s income were not calculated correctly. For example, in three cases, the caseworker failed to include the appropriate amount of the adult caretaker?s provided income when determining the adult caretaker?s eligibility for their children to receive child care benefits. In two of these three cases, the exclusion of this income resulted in the adult caretakers being charged a lower parent fee. These errors resulted in four adult caretakers being underbilled by $342 and one adult caretaker being overbilled by $6. Since parent fees are required to be paid before CCCAP benefits are paid, this led to total known questioned costs of $336.State regulation [Section 3.905.1.I, 9 CCR 2503-9] specifies that gross earnings, including wages and child support payments, must be included in an adult caretaker?s income for the purposes of determining CCCAP eligibility and calculating parent fees. State regulation [Section 3.903, 9 CCR 2503-9] defines a parent fee as a copayment that must be made by an adult caretaker to the child care provider prior to any state/county child care funds payment. State regulation [Section 3.911.A, 9 CCR 2503-9] specifies that parent fees are based on gross countable income compared to the household size and the number of children using child care.ERRORS RELATED TO AUTHORIZATION NOTICES. In one case, the caseworker failed to send the state-prescribed authorization form to the adult caretaker and instead, the caseworker sent an email to the adult caretaker. This error did not result in known questioned costs because the error did not negatively affect the children?s eligibility.State regulation [Section 3.903, 9 CCR 2503-9] requires caseworkers to notify the adult caretaker of the approval and any change in their child care benefits, as applicable; this notification must be sent on the state-prescribed authorization form.Overall, we determined that the Department did not fully implement the Fiscal Year 2019 CCCAP recommendations. The Department did provide evidence that it conducted required CCCAP training, including optional monthly trainings and webinars, for all counties during the fiscal year and resolved the CHATS issues identified in the prior audit relating to eligibility notifications and parent fee rounding errors. During Fiscal Year 2020, the Department did not incorporate a secondary or supervisory review process, but started discussions with the counties to determine the feasibility of incorporating these reviews.According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the U.S. Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book) under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations.WHY DID THESE PROBLEMS OCCUR?The Department lacked sufficient internal controls to ensure compliance with state and federal requirements for the CCCAP during Fiscal Year 2020. We noted the following causes for the identified errors:LACK OF BACK-UP DOCUMENTATION PLAN. Based on discussion with the Program Division, some of the counties were unable to access their case files due to local shutdowns during the pandemic. In these cases, the counties maintained the case file documentation only in hardcopy. Therefore, the Program Division and these counties had no access to the supporting documentation we requested for the audit.SECONDARY REVIEWS NOT REQUIRED. Based on our testing, the Department has not instituted a required secondary review process at the counties over child care case files during Fiscal Year 2020, which we recommended as a result of our Fiscal Year 2019 audit testing. During Fiscal Year 2020, the Department conducted an assessment of county monitoring policies and had several meetings with the counties to discuss a secondary review process of case files and get feedback from the counties for the process, but had not implemented a required secondary review by the end of the fiscal year.INCOMPLETE STATE PLAN. The State Plan does not specify different documentation requirements for determining or redetermining eligibility for protective services child care and Colorado Works child care cases. The Department stated that it does not currently require counties to maintain any eligibility documentation, such as the referral form, to support the protective services child care and Colorado Works child care cases; however this is not stated or addressed in the State Plan or in state regulations. At the end of Fiscal Year 2020, there were 461 protective services children and 5,020 Colorado Works children receiving child care benefits.DEPARTMENT IS NOT MONITORING EFFECTIVELY. The Department does not have an effective and complete monitoring process as follows:? LACK OF PERFORMANCE MEASURES FOR COUNTY MONITORING. Federal regulation [45 CFR 98.11(a)(3)] requires the Department to have written agreements in place with the counties which describe the counties? roles and responsibilities, including indicators or measures to assess performance. During Fiscal Year 2020, the Department had not established CCCAP performance measures to evaluate and improve counties? performance. Specifically, the Program Division?s written agreements with counties in Fiscal Year 2020 did not include any indicators or measures to assess county performance as federally required, such as processing times for applications, response times for correcting the identified issues found during the Program Division?s monitoring and QA Division processes, or participation in trainings. Furthermore, the Department has not established overall CCCAP eligibility and redetermination error-rate thresholds for counties.? NO METHOD FOR ACCUMULATION OF DATA. The Department did not have a method to accumulate and assess the errors identified through its monitoring processes. As a result, the Department lacked valuable information for assessing county performance and identifying areas for increased monitoring and focused county training. Specifically, the QA Division?s reviews are not being used by the Department to assess county performance. We found that the QA Division had not accumulated the results of their quality assurance reviews in order to assess the county or overall state performance. We reviewed the QA Division?s Fiscal Year 2020 listing of quality assurance reviews and determined the QA Division conducted reviews of 299 CCCAP case files from 28 out of64 counties and found that 203 of these 299 cases (68 percent) contained at least one identified issue. We also reviewed the QA Division?s Fiscal Year 2019 listing of quality assurance reviews and found that the error rate for Fiscal Year 2020 has significantly increased from the QA Division?s 30-percent error rate during Fiscal Year 2019. The QA Division identified errors with the income calculation, the parent fee, missing documentation, errors in CHATS, errors due to not updating CHATS, incomplete applications, and incomplete employment verification.? FAILURE TO ENFORCE COUNTIES? CORRECTION OF ERRORS. The Department did not ensure that all counties were responding to errors identified in a timely manner. Specifically, during Fiscal Year 2020, the Program Division conducted on-site reviews in 19 counties. We selected five of the review reports and related documentation to determine whether the identified errors were corrected by the county after the review. We found that four of these counties corrected the errors between 7 and 145 days after the deadline.WHY DO THESE PROBLEMS MATTER?It is essential for the Department to ensure that child care eligibility is properly determined and in accordance with state and federal regulations. Inaccurate processing of case file information to determine eligibility can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, or assessing an incorrect parent fee. The federal government can disallow the payment of federal funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures.Due to the COVID-19 pandemic, there has been an increase in individuals needing child care assistance. Therefore, when county caseworkers incorrectly determine eligibility, it can negatively affect other eligible children. Specifically, counties put newly eligible children on a waitlist if the county does not have enough resources to pay for their benefits. As of June 30, 2020, there were 54 children in four counties on a CCCAP waitlist in Colorado. In addition, two counties stopped processing applications during the fiscal year due to limited resources. When eligibility is improperly granted, eligible children on the waitlist are delayed from receiving benefits.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1801COCCDF*1901COCCDF*2001COCCC3*2001COCCDF*FEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.575*, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596*, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)ELIGIBILITY (E)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $4,013KNOWN QUESTIONED COSTS RELATED TO COVID EMERGENCY $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-058A AND 2019-058B*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-052The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Colorado Child Care Assistance Program (Program) requirements by:A Evaluating whether changes are necessary to policies and procedures to ensure that in the event of a local or statewide shutdown, the Department and the county departments of human/social services are still able to access their Program case files and documentation.B Continuing to work with counties to implement a secondary or supervisory review process over case files after eligibility is determined to address the issues identified in the audit and in quality assurance reviews.C Incorporating documentation requirements into the State Plan for protective services and Temporary Assistance for Needy Families child care cases and ensuring the Program case files include this required documentation.D Improving its monitoring processes by:i. Establishing indicators or measures to assess performance for counties in the annual written agreements and developing a monitoring program, to determine if the individual counties are in compliance with performance measures as well as Federal and State regulations.ii. Developing a formal method to accumulate and assess errors at each county that will allow the Department to analyze error rates for the entire state as well as on a county by county basis and using the information to implement a targeted training and improvement plan for all errors identified.iii. Enforcing counties? correction of errors in a timely manner.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department agrees to evaluate with internal leadership whether changes to policies and procedures are necessary for accessing program files for audit purposes during a local or statewide shutdown. The Department recognizes that the pandemic impacted the OSA test-work. Specifically, one county temporarily had to shut down its building due to the pandemic. Two of these cases accounted for $4,085, which represents 92% of the questioned costs noted in the audit.B AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to continue to work with counties on a secondary review process over case files after eligibility is determined.C AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees and will identify a process to incorporate and ensure compliance with documentation requirements in the updated State Plan for protective services and Temporary Assistance for Needy Families child care cases. Due to the sensitive nature of protective services child care cases, the Department will need to work internally with the Division of Child Welfare to define the documentation requirements for protective services cases.D AGREE. IMPLEMENTATION DATE: JULY 2022.i. AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to establish indicators or measures to assess performance for counties and will identify the county?s requirement to comply in the MOU. In addition, the Department will develop a monitoring program to determine if the individual counties are in compliance with performance measures, as well as Federal and State regulations. This implementation date aligns with the annual review of the CDHS CCCAP Colorado Works Memorandum of Understanding. Developing a formal method to accumulate and assess errors at each county that will allow the Department to analyze error rates for the entire state as well as on a county by county basis and using the information to implement a targeted training and improvement plan for all errors identified.ii. AGREE. IMPLEMENTATION DATE: JULY 2022.The Department agrees to develop a formal method to accumulate and assess errors through a variety of data points. The Department will evaluate each county and analyze error rates for the entire state, as well as on a county by county basis. The Department will then use this information to implement a targeted training and/or improvement plan.iii. AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department agrees to enforce counties? correction of errors in a timely manner as defined by the Department's updated policies and procedures.
(A) The Department agrees to evaluate with internal leadership whether changes to policies and procedures are necessary for accessing program files for audit purposes during a local or statewide shutdown. The Department recognizes that the pandemic impacted the OSA test-work. Specifically, one county temporarily had to shut down its building due to the pandemic. Two of these cases accounted for $4,085, which represents 92% of the questioned costs noted in the audit.(B) The Department agrees to continue to work with counties on a secondary review process over case files after eligibility is determined.(C) The Department agrees and will identify a process to incorporate and ensure compliance with documentation requirements in the updated State Plan for protective services and Temporary Assistance for Needy Families child care cases. Due to the sensitive nature of protective services child care cases, the Department will need to work internally with the Division of Child Welfare to define the documentation requirements for protective services cases.(D.i.) The Department agrees to establish indicators or measures to assess performance for counties and will identify the county?s requirement to comply in the MOU. In addition, the Department will develop a monitoring program to determine if the individual counties are in compliance with performance measures, as well as Federal and State regulations. This implementation date aligns with the annual review of the CDHS CCCAP Colorado Works Memorandum of Understanding. Developing a formal method to accumulate and assess errors at each county that will allow the Department to analyze error rates for the entire state as well as on a county by county basis and using the information to implement a targeted training and improvement plan for all errors identified.(D.ii.) The Department agrees to develop a formal method to accumulate and assess errors through a variety of data points. The Department will evaluate each county and analyze error rates for the entire state, as well as on a county by county basis. The Department will then use this information to implement a targeted training and/or improvement plan.(D.iii.) The Department agrees to enforce counties? correction of errors in a timely manner as defined by the Department's updated policies and procedures.
2019-058
COLORADO CHILD CARE ASSISTANCE PROGRAM? HEALTH AND SAFETY REQUIREMENTSThe Department?s Program Division is responsible for overseeing its Child Care Licensing and Administration Unit (Licensing Unit) and ensuring that it complies with federal and state requirements for child care providers? licensing and monitoring. The Department, as the lead agency, has designated the Program Division as the administrator of the CCCAP. Federal regulations require the Department to have a federally-approved State CCCAP Plan in place to address how the Department will ensure compliance with the program?s grant requirements.As part of the Department?s eligibility determination process for the program, an applicant for CCCAP benefits must specify the provider who will be providing the child care services for each child receiving the CCCAP benefits. The child care provider must be pre-approved by the Department and must meet health and safety requirements in order to be licensed and approved to receive the CCCAP payments for child care services.The Department is federally-required under the program to inspect child care providers who are applying for a new license or an annual renewal to their license, when the provider has an adverse action or probation, when the provider requests a change to their license, or when the provider requests technical assistance or a consultation. Licensing inspectors or other qualified inspectors, as determined by the Department, perform unannounced inspections of the providers. The Department reported that, during Fiscal Year 2020, its licensing specialists were a combination of state employees and contracted staff. The Department?s licensing inspectors review requirements to protect the health and safety of children, such as ensuring the children?s files at the child care provider contain each child?s immunization records, reviewing safety conditions of the buildings, and ensuring staff working at the providers have completed health and safety training.For each licensing inspection, the licensing specialist completes a Report of Inspection (Report). The Report includes any specific violations identified during the inspection, the rule or statute related to the violation(s), and a correction plan, including the required completion date for any correction(s). Once the providers have responded to the Report, the licensing specialist will fill out a verification form indicating that the review is complete and the provider has corrected all violations. In order to verify the violations are corrected, the licensing specialist will either perform a follow-up inspection, such as to confirm a safety issue has been corrected, or will obtain documentation to show the violation has been corrected, such as receiving a copy of an immunization or training record.Within the Licensing Unit, the Program Compliance Unit (Compliance Unit) reviews all of the completed Reports to monitor the licensing specialists? compliance with the Program Division?s internal Standard Operating Procedures (SOPs). This includes ensuring the licensing specialist has documented the Reports for each inspection, reviewing the information that is included in the Reports and violations noted, and ensuring that noted violations are corrected.The federal government issued a waiver for the annual inspections that did not require child care providers to have inspections starting April 1, 2020, ??through the duration of the state-declared emergency, not to exceed one year.? The Department continued to perform inspections with open providers and transitioned to virtual inspections during the remainder of the fiscal year.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to assess the Department?s internal controls over, and compliance with, federal and state CCCAP health and safety special tests and provisions requirements, including requirements related to the prevention and control of infectious diseases, building and physical premises safety, and basic health and safety training for providers.As part of our audit, we performed testing to determine whether the Licensing Unit ensured that child care providers serving children who receive CCCAP benefits met all applicable health and safety requirements during Fiscal Year 2020. We also reviewed the Licensing Unit?s procedures and relevant information related to provider health and safety requirements in the Department?s State CCCAP Plan in place during Fiscal Year 2020. We selected a sample of 40 children who received CCCAP benefits during the fiscal year identified in the previous finding. From that sample, we reviewed the 40 providers that provided child care services to the children selected to determine whether the Department had completed an inspection in accordance with federal requirements and the Department?s procedures; whether the Department had obtained the providers? responses to inspection reports; and whether the Department had verified the providers had corrected the violations in a timely manner.In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to CCCAP provider health and safety requirements. During that audit, we recommended that the Department improve its internal controls over licensed child care providers by strengthening its monitoring process to ensure that licensing staff follow up on untimely-submitted provider responses and ensure that providers acknowledge inspection reports at the time they receive the Reports. In Fiscal Year 2019, we determined that the Department had not fully implemented this recommendation and planned to fully implement it in July 2020.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:? PROVIDER RESPONSE TO VIOLATIONS. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that a provider must submit a response to the Report. The response must indicate how each violation identified was corrected. If the provider does not indicate that all the violations are corrected, then the response is considered incomplete. The requirements for an incomplete response are noted in the following bullet.? LATE OR INCOMPLETE RESPONSE. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that if the response is incomplete or is not received within 30 calendar days of the due date, the licensing specialist must send an adverse action letter to the provider within 10 business days to request written verification that the violations listed in the Report have been corrected.? REPORT SIGNATURE. The Licensing Unit?s procedure [SOP L-7, How to Write a Report of Inspection] requires the licensing specialist to complete the Report the day of the licensing visit. The licensing specialist must review the Report with the provider and the licensing specialist, and the provider must sign the Report within 3 business days.? DOCUMENTATION. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that once the Report, the provider?s written response, and any additional documentation obtained are complete, then the documentation must be scanned and uploaded into the Department?s imaging system.? POLICIES AND PROCEDURES. Federal Regulation [45 CFR 98.42(b)] requires the Department to certify in its State CCCAP Plan that policies are in place to monitor child care providers. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?For 10 of the 40 providers and the related inspections tested (25 percent), we identified at least one issue, as follows:? VIOLATIONS NOT CORRECTED. For four inspections, the provider?s response to the Report indicated that they had not corrected the violations identified during the inspection; however, the licensing specialists failed to send an incomplete response letter or follow up with any of the four providers, and documented each of the inspections as completed. Furthermore, the Licensing Unit could not provide support to show that the providers subsequently corrected these violations. The uncorrected violations included not having the required children?s health records, children?s immunization records, and staff health records, on file. The licensing specialists should have sent the follow-up letters for the incomplete responses between August 25, 2019, and May 17, 2020, but had not sent the letters by the time of our testing in March 2021.? LACK OF TIMELY FOLLOW-UP ON MISSING RESPONSES AND ADVERSE ACTION LETTERS. For four inspections, the Department did not receive a provider response by the due date and the licensing specialist did not follow up with a written adverse action letter within the required timeframe. The providers ultimately responded between 48 and 215 days after the deadline.? TIMELY ACKNOWLEDGEMENT OF INSPECTIONS. For two inspections, the licensing specialist did not ensure that the provider acknowledged the violations by signing the Report within 3 business days of the inspection. The providers signed the Reports 4 business days after the inspection.? MISSING DOCUMENTATION. In one inspection, the Department did not have documentation for when the licensing specialist received the provider?s response. The Department did receive the provider?s response, but no date was noted. Because we did not receive this documentation, we were unable to determine if the response was received on time. The licensing specialist performed this inspection on June 25, 2020.WHY DID THESE PROBLEMS OCCUR?We found that the Department had not fully implemented our Fiscal Year 2018 recommendation by the end of Fiscal Year 2020, and the Department?s monitoring processes were not effective in ensuring it complied with federal and state requirements during Fiscal Year 2020. Specifically, the Licensing Unit does not have policies and procedures that indicate what elements the Compliance Unit must review, including required timeframes for the follow ups and verification of correction of violations. Because the Licensing Unit does not have these policies and procedures, the Compliance Unit?s review is not ensuring that the licensing specialists are maintaining the required documentation or ensuring appropriate follow up is conducted on violations and correction of violations. In addition, the Compliance Unit is not currently reviewing the Report responses from the providers to ensure all violations have been corrected.The Department indicated that it prioritized licensing specialists? work related to assisting providers during the last several months of Fiscal Year 2020 during the COVID-19 pandemic; however, the Department did not waive requirements for the timeframes for licensing specialists to follow up with providers. For the 10 providers in our sample that we identified with issues, only one provider had an inspection afterApril 1, 2020, when the federal waiver of inspections became effective, and only four providers had an inspection response due after March 1, 2020?during the COVID-19 pandemic. Therefore, this indicates that the issues we found were not all related to the COVID-19 pandemic.WHY DO THESE PROBLEMS MATTER?Ensuring that providers correct all violations, maintaining accurate and complete inspection file documentation, following up on late providers? responses, and requiring that providers acknowledge receipt of licensing reports are essential for the Department to ensure that providers comply with federal and state health and safety requirements. Failure to comply with internal controls over federal and state health and safety requirements increases the risk that providers may be out of compliance with these requirements for an extended period of time, which may have a negative impact on children?s safety within the facilities. Specifically, two providers collectively had 19 violations noted, which included exceeding the allowed number of children, emergency drills not being practiced, electrical outlets not being covered, missing background checks, toys posing a choking hazard, and missing staff files. The licensing specialists performed these inspections in April 2019 and May 2019; these were the most recent inspections for the providers due to a federally issued COVID-19 waiver on inspections that was in place during April through June 2020. This creates additional risk that the providers may be out of compliance for extended lengths of time if the requirements are not followed.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1801COCCDF1901COCCDF2001COCCC32001COCCDFFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.575, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUNDCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-064ARECOMMENDATION2020-053The Department of Human Services should improve its internal controls over its provider inspection process for the Colorado Child Care Assistance Program by developing and implementing policies and procedures for the review of inspections and related documentation. These policies and procedures should include reviewing the provider responses for violations, enforcing adherence for follow-up, and ensuring that required documentation is obtained and maintained.RESPONSEDEPARTMENT OF HUMAN SERVICESPARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The Department partially agrees with this recommendation. The Department agrees to update its policies and procedures. The Program Compliance Unit (PCU) and supervisors will continue to review adherence to provider response completeness, timeliness, and timely licensing specialist follow-up. The Department will provide additional training for SOP L-7 and L-8.The Department disagrees with strict adherence to the SOPs. Specifically, the Department intentionally allows the modification of procedures to prioritize and protect the health and safety of children under the ?extenuating circumstances? provision. This provision was critical during the recent pandemic. The Department had classified the impacts of the pandemic as ?extenuating circumstances.? The Department prioritized its focus requiring Licensing Specialists to provide technical assistance and critical support to providers.Providers received guidance for operating their child care programs throughout the pandemic, including helping them navigate operations during numerous Executive and Public Health Orders. This helped ensure Colorado had child care for essential personnel, including health care workers and emergency responders. This change in focus was critical in supporting child care programs and families and ensuring they were not additionally impacted or negatively affected by the COVID-19 pandemic.AUDITOR?S ADDENDUMWhile the federal government provided a waiver on the conduct of annual inspections as of April 1, 2020, it did not waive other requirements or the Department?s policies and procedures. Therefore, the Department was still responsible for enforcing its documented policies and procedures as required by federal regulation [45 CFR 98.42(b)].
Show full finding ▾Hide full finding ▴COLORADO CHILD CARE ASSISTANCE PROGRAM? HEALTH AND SAFETY REQUIREMENTSThe Department?s Program Division is responsible for overseeing its Child Care Licensing and Administration Unit (Licensing Unit) and ensuring that it complies with federal and state requirements for child care providers? licensing and monitoring. The Department, as the lead agency, has designated the Program Division as the administrator of the CCCAP. Federal regulations require the Department to have a federally-approved State CCCAP Plan in place to address how the Department will ensure compliance with the program?s grant requirements.As part of the Department?s eligibility determination process for the program, an applicant for CCCAP benefits must specify the provider who will be providing the child care services for each child receiving the CCCAP benefits. The child care provider must be pre-approved by the Department and must meet health and safety requirements in order to be licensed and approved to receive the CCCAP payments for child care services.The Department is federally-required under the program to inspect child care providers who are applying for a new license or an annual renewal to their license, when the provider has an adverse action or probation, when the provider requests a change to their license, or when the provider requests technical assistance or a consultation. Licensing inspectors or other qualified inspectors, as determined by the Department, perform unannounced inspections of the providers. The Department reported that, during Fiscal Year 2020, its licensing specialists were a combination of state employees and contracted staff. The Department?s licensing inspectors review requirements to protect the health and safety of children, such as ensuring the children?s files at the child care provider contain each child?s immunization records, reviewing safety conditions of the buildings, and ensuring staff working at the providers have completed health and safety training.For each licensing inspection, the licensing specialist completes a Report of Inspection (Report). The Report includes any specific violations identified during the inspection, the rule or statute related to the violation(s), and a correction plan, including the required completion date for any correction(s). Once the providers have responded to the Report, the licensing specialist will fill out a verification form indicating that the review is complete and the provider has corrected all violations. In order to verify the violations are corrected, the licensing specialist will either perform a follow-up inspection, such as to confirm a safety issue has been corrected, or will obtain documentation to show the violation has been corrected, such as receiving a copy of an immunization or training record.Within the Licensing Unit, the Program Compliance Unit (Compliance Unit) reviews all of the completed Reports to monitor the licensing specialists? compliance with the Program Division?s internal Standard Operating Procedures (SOPs). This includes ensuring the licensing specialist has documented the Reports for each inspection, reviewing the information that is included in the Reports and violations noted, and ensuring that noted violations are corrected.The federal government issued a waiver for the annual inspections that did not require child care providers to have inspections starting April 1, 2020, ??through the duration of the state-declared emergency, not to exceed one year.? The Department continued to perform inspections with open providers and transitioned to virtual inspections during the remainder of the fiscal year.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to assess the Department?s internal controls over, and compliance with, federal and state CCCAP health and safety special tests and provisions requirements, including requirements related to the prevention and control of infectious diseases, building and physical premises safety, and basic health and safety training for providers.As part of our audit, we performed testing to determine whether the Licensing Unit ensured that child care providers serving children who receive CCCAP benefits met all applicable health and safety requirements during Fiscal Year 2020. We also reviewed the Licensing Unit?s procedures and relevant information related to provider health and safety requirements in the Department?s State CCCAP Plan in place during Fiscal Year 2020. We selected a sample of 40 children who received CCCAP benefits during the fiscal year identified in the previous finding. From that sample, we reviewed the 40 providers that provided child care services to the children selected to determine whether the Department had completed an inspection in accordance with federal requirements and the Department?s procedures; whether the Department had obtained the providers? responses to inspection reports; and whether the Department had verified the providers had corrected the violations in a timely manner.In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to CCCAP provider health and safety requirements. During that audit, we recommended that the Department improve its internal controls over licensed child care providers by strengthening its monitoring process to ensure that licensing staff follow up on untimely-submitted provider responses and ensure that providers acknowledge inspection reports at the time they receive the Reports. In Fiscal Year 2019, we determined that the Department had not fully implemented this recommendation and planned to fully implement it in July 2020.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We applied the following criteria during our testing:? PROVIDER RESPONSE TO VIOLATIONS. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that a provider must submit a response to the Report. The response must indicate how each violation identified was corrected. If the provider does not indicate that all the violations are corrected, then the response is considered incomplete. The requirements for an incomplete response are noted in the following bullet.? LATE OR INCOMPLETE RESPONSE. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that if the response is incomplete or is not received within 30 calendar days of the due date, the licensing specialist must send an adverse action letter to the provider within 10 business days to request written verification that the violations listed in the Report have been corrected.? REPORT SIGNATURE. The Licensing Unit?s procedure [SOP L-7, How to Write a Report of Inspection] requires the licensing specialist to complete the Report the day of the licensing visit. The licensing specialist must review the Report with the provider and the licensing specialist, and the provider must sign the Report within 3 business days.? DOCUMENTATION. The Licensing Unit?s procedure [SOP L-8, Corrections to ROI Violations] indicates that once the Report, the provider?s written response, and any additional documentation obtained are complete, then the documentation must be scanned and uploaded into the Department?s imaging system.? POLICIES AND PROCEDURES. Federal Regulation [45 CFR 98.42(b)] requires the Department to certify in its State CCCAP Plan that policies are in place to monitor child care providers. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and observing operations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?For 10 of the 40 providers and the related inspections tested (25 percent), we identified at least one issue, as follows:? VIOLATIONS NOT CORRECTED. For four inspections, the provider?s response to the Report indicated that they had not corrected the violations identified during the inspection; however, the licensing specialists failed to send an incomplete response letter or follow up with any of the four providers, and documented each of the inspections as completed. Furthermore, the Licensing Unit could not provide support to show that the providers subsequently corrected these violations. The uncorrected violations included not having the required children?s health records, children?s immunization records, and staff health records, on file. The licensing specialists should have sent the follow-up letters for the incomplete responses between August 25, 2019, and May 17, 2020, but had not sent the letters by the time of our testing in March 2021.? LACK OF TIMELY FOLLOW-UP ON MISSING RESPONSES AND ADVERSE ACTION LETTERS. For four inspections, the Department did not receive a provider response by the due date and the licensing specialist did not follow up with a written adverse action letter within the required timeframe. The providers ultimately responded between 48 and 215 days after the deadline.? TIMELY ACKNOWLEDGEMENT OF INSPECTIONS. For two inspections, the licensing specialist did not ensure that the provider acknowledged the violations by signing the Report within 3 business days of the inspection. The providers signed the Reports 4 business days after the inspection.? MISSING DOCUMENTATION. In one inspection, the Department did not have documentation for when the licensing specialist received the provider?s response. The Department did receive the provider?s response, but no date was noted. Because we did not receive this documentation, we were unable to determine if the response was received on time. The licensing specialist performed this inspection on June 25, 2020.WHY DID THESE PROBLEMS OCCUR?We found that the Department had not fully implemented our Fiscal Year 2018 recommendation by the end of Fiscal Year 2020, and the Department?s monitoring processes were not effective in ensuring it complied with federal and state requirements during Fiscal Year 2020. Specifically, the Licensing Unit does not have policies and procedures that indicate what elements the Compliance Unit must review, including required timeframes for the follow ups and verification of correction of violations. Because the Licensing Unit does not have these policies and procedures, the Compliance Unit?s review is not ensuring that the licensing specialists are maintaining the required documentation or ensuring appropriate follow up is conducted on violations and correction of violations. In addition, the Compliance Unit is not currently reviewing the Report responses from the providers to ensure all violations have been corrected.The Department indicated that it prioritized licensing specialists? work related to assisting providers during the last several months of Fiscal Year 2020 during the COVID-19 pandemic; however, the Department did not waive requirements for the timeframes for licensing specialists to follow up with providers. For the 10 providers in our sample that we identified with issues, only one provider had an inspection afterApril 1, 2020, when the federal waiver of inspections became effective, and only four providers had an inspection response due after March 1, 2020?during the COVID-19 pandemic. Therefore, this indicates that the issues we found were not all related to the COVID-19 pandemic.WHY DO THESE PROBLEMS MATTER?Ensuring that providers correct all violations, maintaining accurate and complete inspection file documentation, following up on late providers? responses, and requiring that providers acknowledge receipt of licensing reports are essential for the Department to ensure that providers comply with federal and state health and safety requirements. Failure to comply with internal controls over federal and state health and safety requirements increases the risk that providers may be out of compliance with these requirements for an extended period of time, which may have a negative impact on children?s safety within the facilities. Specifically, two providers collectively had 19 violations noted, which included exceeding the allowed number of children, emergency drills not being practiced, electrical outlets not being covered, missing background checks, toys posing a choking hazard, and missing staff files. The licensing specialists performed these inspections in April 2019 and May 2019; these were the most recent inspections for the providers due to a federally issued COVID-19 waiver on inspections that was in place during April through June 2020. This creates additional risk that the providers may be out of compliance for extended lengths of time if the requirements are not followed.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1801COCCDF1901COCCDF2001COCCC32001COCCDFFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NOS. 93.575, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUNDCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-064ARECOMMENDATION2020-053The Department of Human Services should improve its internal controls over its provider inspection process for the Colorado Child Care Assistance Program by developing and implementing policies and procedures for the review of inspections and related documentation. These policies and procedures should include reviewing the provider responses for violations, enforcing adherence for follow-up, and ensuring that required documentation is obtained and maintained.RESPONSEDEPARTMENT OF HUMAN SERVICESPARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The Department partially agrees with this recommendation. The Department agrees to update its policies and procedures. The Program Compliance Unit (PCU) and supervisors will continue to review adherence to provider response completeness, timeliness, and timely licensing specialist follow-up. The Department will provide additional training for SOP L-7 and L-8.The Department disagrees with strict adherence to the SOPs. Specifically, the Department intentionally allows the modification of procedures to prioritize and protect the health and safety of children under the ?extenuating circumstances? provision. This provision was critical during the recent pandemic. The Department had classified the impacts of the pandemic as ?extenuating circumstances.? The Department prioritized its focus requiring Licensing Specialists to provide technical assistance and critical support to providers.Providers received guidance for operating their child care programs throughout the pandemic, including helping them navigate operations during numerous Executive and Public Health Orders. This helped ensure Colorado had child care for essential personnel, including health care workers and emergency responders. This change in focus was critical in supporting child care programs and families and ensuring they were not additionally impacted or negatively affected by the COVID-19 pandemic.AUDITOR?S ADDENDUMWhile the federal government provided a waiver on the conduct of annual inspections as of April 1, 2020, it did not waive other requirements or the Department?s policies and procedures. Therefore, the Department was still responsible for enforcing its documented policies and procedures as required by federal regulation [45 CFR 98.42(b)].
The Department partially agrees with this recommendation. The Department agrees to update its policies and procedures. The Program Compliance Unit (PCU) and supervisors will continue to review adherence to provider response completeness, timeliness, and timely licensing specialist follow-up. The Department will provide additional training for SOP L-7 and L-8.The Department disagrees with strict adherence to the SOPs. Specifically, the Department intentionally allows the modification of procedures to prioritize and protect the health and safety of children under the ?extenuating circumstances? provision. This provision was critical during the recent pandemic. The Department had classified the impacts of the pandemic as ?extenuating circumstances.? The Department prioritized its focus requiring Licensing Specialists to provide technical assistance and critical support to providers.Providers received guidance for operating their child care programs throughout the pandemic, including helping them navigate operations during numerous Executive and Public Health Orders. This helped ensure Colorado had child care for essential personnel, including health care workers and emergency responders. This change in focus was critical in supporting child care programs and families and ensuring they were not additionally impacted or negatively affected by the COVID-19 pandemic.
INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORYThe Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food).Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens.The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods.Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs.During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program:? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report.? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)].The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions.The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed.Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically:EMERGENCY FOOD PROGRAM? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory.? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered.? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million.? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report.SUPPLEMENTAL FOOD PROGRAM? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000.WHY DID THESE PROBLEMS OCCUR?The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation.WHY DO THESE PROBLEMS MATTER?Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance.FEDERAL DEPARTMENT DEPARTMENT OF AGRICULTUREFEDERAL AWARD NUMBERS 3CO4304413CO810810FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NOS. 10.565, COMMODITY SUPPLEMENTAL FOOD PROGRAM;10.568, EMERGENCY FOOD ASSISTANCE PROGRAM(ADMINISTRATIVE COSTS)COVID-19 FUNDING YESCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-054The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by:A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate.B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate.C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management.Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.B AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate.Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022.C AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents.The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management.Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
Show full finding ▾Hide full finding ▴INTERNAL CONTROLS OVER FOOD DISTRIBUTION CLUSTER INVENTORYThe Food Distribution Cluster (Cluster) is a group of federal grant programs designed to strengthen the nutrition safety net through the provision of donated foods from the U.S. Department of Agriculture (USDA) to low-income persons. The Department, as the state agency responsible for the administration of the Cluster programs, works with emergency feeding organizations throughout Colorado to provide households in need with food commodities through specific federal programs within the Cluster, including the Emergency Food Assistance Program (Emergency Food), and the Commodity Supplemental Food Program (Supplemental Food).Emergency Food (CFDA 10.568) is a federally funded program that provides USDA foods to low-income households for home consumption or for use in prepared meals at emergency feeding sites for low-income persons. The Department enters into contracts with three Regional Food Banks to serve Colorado?s 64 counties. The Department determines an allocation of the emergency foods to each Regional Food Bank. The Regional Food Banks place orders in the Web Supply Chain Management (Web Chain) system, a web-based software managed by the USDA, against their allocation and the USDA then ships the food to the Regional Food Bank?s warehouse. Emergency assistance bonus foods, which are foods the USDA purchases each year to support agricultural markets that entities can receive in addition to their allocation, are offered to each state based on each state?s fair share of the federal application, or on an open-order basis. The Regional Food Banks determine and provide household allocations of emergency food based on need, and provide congregate meals served at local food pantries and soup kitchens.The Regional Food Banks are required to submit physical inventory forms (Form 152) on a monthly basis to the Department and to provide a physical inventory verification on an annual basis. The Form 152 includes information regarding the receipt, disposal, and inventory of USDA Foods.Supplemental Food [CFDA No. 10.565] is a federally funded program that provides USDA foods to low-income seniors who are a minimum of 60 years of age. The Department works with six recipient agencies, including various counties, to ensure distribution in all 64 counties. The recipient agencies enter into contracts with the Department to administer the Supplemental Food program. The recipient agencies order USDA food through Web Chain. Each month, the recipient agencies are required to complete a Supplemental Food Monthly Inventory Form (Form 153) and submit it to the Department. Form 153 includes sections for reporting USDA food receipts, ending inventory, and number of recipients, along with other information.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine if the Department had sufficient internal controls over, and complied with, federal requirements for the Supplemental Food and Emergency Food programs, including whether the Department maintained accurate and complete records with respect to the receipt and inventory of USDA food commodities provided through the Supplemental Food and Emergency Food programs.During our audit, we requested to review any Supplemental Food and Emergency Food inventory reconciliations performed by the Department for Fiscal Year 2020, and requested and obtained the Department?s prepared fiscal year-end inventory summary reports. We also performed the following specific testing for each program:? For Supplemental Food, we compared total shipment information reported by one food bank on its 12 monthly Form 153s to a Fiscal Year 2020 Web Chain report.? For Emergency Food, we recalculated 12 monthly Form 152s submitted by one Regional Food Bank during Fiscal Year 2020 for accuracy. We also compared the Regional Food Bank?s fiscal year-end reported inventory from its Form 152 to the Department-prepared fiscal year-end inventory summary report and the Regional Food Bank?s reported Fiscal Year 2020 USDA Emergency Food receipts to a Fiscal Year 2020 Web Chain report. Lastly, we compared bonus food orders contained on a Department-prepared tracking sheet to a Web Chain report on a sample basis.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations applicable to the Food Distribution Cluster programs [7 CFR 250.19(a)] require the Department, as a distributing agency, to keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16(a)].The Department?s Emergency Assistance Policy and Procedure Manual states that the Regional Food Banks are required to maintain records documenting the receipt, disposal, and inventory of USDA-provided food, including records documenting distributions.The Department?s Supplemental Food Policy and Procedure Manual states that the recipient agencies must maintain complete and accurate records of USDA foods received and distributed.Federal regulations [2 CFR 200.303] require the Department, as a recipient of federal funds, to establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports and performing reconciliations.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, the Department had not identified any of the errors or discrepancies we identified through our testing of both programs? inventory records or otherwise ensured they were investigated and corrected. Specifically:EMERGENCY FOOD PROGRAM? For seven of the 12 Form 152s we tested, the forms contained calculation errors, resulting in miscalculations of the beginning balance of the inventory, quantity received or distributed, and ending balance of the inventory.? The Regional Food Bank?s year-end Form 152 reported physical inventory of 50,306 cases, but the Department-prepared year-end inventory summary reported physical inventory of 27,000 cases, representing a discrepancy of 23,306 cases. We calculated an estimated dollar value for the discrepancy of approximately $578,000 by dividing the total value of orders received by the Food Bank during the fiscal year by the total number of cases ordered.? The Regional Food Bank?s year-end Form 152 reported that it received 446,420 cases of USDA foods in Fiscal Year 2020, but the Web Chain report indicated that the Food Bank received 533,597 cases during Fiscal Year 2020; this represented a discrepancy and possible under-reporting of inventory by the Food Bank of 87,177 cases, totaling an estimated amount of approximately $2.2 million.? Three of the nine (33 percent) sampled USDA foods listed on the Department?s bonus allocation report did not agree to bonus allocation orders listed on the Web Chain report.SUPPLEMENTAL FOOD PROGRAM? The recipient agency?s Fiscal Year 2020 Form 153s reported that the recipient agency received a total of 1,618,498 Supplemental Food units, but the Web Chain Report indicated that the recipient agency received 1,705,160 units, which represented a discrepancy and possible underreporting of inventory by the recipient agency of 86,662 units, totaling an estimated amount of $127,000.WHY DID THESE PROBLEMS OCCUR?The Department lacks strong internal controls over its administration of the programs? inventories, including review and reconciliation policies and procedures. First, the Department does not have policies and related procedures requiring Department staff to review monthly inventory reports provided by recipient agencies and Regional Food Banks to ensure the information provided is accurate. Second, the Department does not have policies and related procedures requiring Department staff to perform reconciliations of physical inventory to the USDA Web Chain report to ensure inventory records are complete and accurate. Third, the Department does not have a tracking system to track recipient agencies and Regional Food Banks activities in the Web Chain system or supporting documentation.WHY DO THESE PROBLEMS MATTER?Lack of review and monitoring processes could result in the Department not maintaining complete and accurate inventory records and failing to comply with federal regulations. Ultimately, the Department risks the improper distribution or loss of USDA foods and could owe USDA for inventory shortages. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide to individuals in need of food assistance.FEDERAL DEPARTMENT DEPARTMENT OF AGRICULTUREFEDERAL AWARD NUMBERS 3CO4304413CO810810FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NOS. 10.565, COMMODITY SUPPLEMENTAL FOOD PROGRAM;10.568, EMERGENCY FOOD ASSISTANCE PROGRAM(ADMINISTRATIVE COSTS)COVID-19 FUNDING YESCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-054The Department of Human Services (Department) should strengthen its internal controls over the Food Distribution Cluster?s U.S. Department of Agriculture foods inventory by:A Developing and implementing policies and procedures requiring Department staff to review monthly inventory reports received from recipient agencies and Regional Food Banks to ensure they are accurate.B Developing and implementing policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web Supply Chain Management system to ensure inventory records are complete and accurate.C Developing and implementing a tracking system to track recipient agencies and Regional Food Banks activities in the Web Supply Chain Management system and maintaining supporting documents.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management.Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.B AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate.Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022.C AGREE. IMPLEMENTATION DATE: DECEMBER 2022.The Department agrees to develop and implement a tracking system for food inventory at recipient agencies and Regional Food Banks using the Web Supply Chain Management system receipts as the basis of food received, including the maintenance of supporting documents.The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management.Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.
(A) The Department is undertaking an inventory overhaul which includes implementing a new inventory database and creating and hiring an Inventory Specialist. The Department recognized the need for inventory software and started the process of obtaining it in June 2020. In May 2021, the Department received a signed licensing agreement for a new database which is expected to be implemented in six months per an OIT timeline. In addition to the database, the Department recently hired a new Inventory Specialist position. This position will lead the development of policies, procedures, inventory reconciliations, and monthly report management.Once the Inventory Specialist has a comprehensive understanding of federal and state policy and the new database software, the Department will develop policies and procedures, training for partner agencies, and roll out new requirements for the tracking and reconciliation of program inventories.(B) The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate.Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022.(C) The Department agrees to develop and implement policies and procedures requiring Department staff to perform reconciliations of recipient agencies? and Regional Food Banks? physical inventories to the Web-based Supply Chain Management system to ensure inventory records are complete and accurate.Starting in January 2021 the Department began developing a position description for an Inventory Specialist with the focus of ensuring accurate and thorough accounting of all year-end inventory and reconciliations. The position was hired in April 2021. Due to the implementation of the inventory database and the timing of beginning and ending inventories, the Department anticipates being able to do a full reconciliation of inventories by December 2022.
INTERNAL CONTROLS OVER LEAP ELIGIBILITY DETERMINATIONThe Low-Income Home Energy Assistance Program (LEAP) is a federal program that helps eligible low-income Colorado families, seniors, and individuals pay a portion of their winter home heating costs. In most cases, the energy assistance benefit is paid directly to the household energy supplier. The Department?s Food and Energy Assistance Division is responsible for ensuring that the Department complies with federal and state requirements for this program. LEAP works to keep communities warm during the winter (November through April), which is also known as the LEAP season. In Fiscal Year 2020, the Department expended a total of $63.8 million in federal funds for LEAP.The Department has contracted with a vendor, Discover Goodwill, to process LEAP applications for 50 of the State?s 64 counties. Applications from the remaining 14 counties are processed at a local social/human services office or county, as applicable. Applications can be submitted online or dropped off at a local social/human services office, or mailed/emailed to the residing county or contractor, as applicable. A LEAP technician enters non-online application information into the LEAP system, Salesforce. Salesforce performs eligibility determinations based on information entered and schedules payments to energy providers for eligible recipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the LEAP eligibility determination process, as well as to determine whether the Department complied with applicable federal LEAP eligibility requirements, during Fiscal Year 2020.We reviewed the Department?s LEAP eligibility internal controls in place during Fiscal Year 2020. We also performed a walkthrough of the eligibility determination process. In addition, we performed testing over a sample of 40 out of 74,972 LEAP applicants? information and related eligibility determinations to determine whether information was input correctly into Salesforce, and if eligibility determinations were appropriate.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? The Department?s LEAP Training and Operations Manual [Version 2019-2020, Section 4: Household Income] states that child support income is countable in calculating the applicant?s gross income.? State regulation [9 CCR 2503-7 3.752.211.H] states that cents are not considered in the social security benefits in calculating gross income.? State regulation [9 CCR 2503-7 3.751.1] requires that applications for households in an emergency situation shall be ?processed expeditiously and eligibility determined within fourteen calendar days of notification of the emergency by the application to the county department.? An emergency application is a household which has had heat service discontinued or is threatened with discontinuance of heat service.? According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?In nine out of 40 cases tested (23 percent), we identified at least one error. These errors did not ultimately impact the applicant?s eligibility for LEAP benefits during the Fiscal Year 2020 LEAP season. Specifically, we found the following:? In three cases, gross income was not calculated correctly. Specifically, in one case, cents from the applicant?s social security benefit payment were incorrectly included in the gross income calculation; in a second case, the applicant?s gross income was overstated by $500; and in a third case, the applicant?s child support payments were erroneously excluded from gross income.? In one case, one individual was not included as a household member even though the applicant had provided the social security number for the individual.? In one case, a household?s emergency application was processed fifteen calendar days after receipt of the application, which was one day late.? In seven cases, information entered into Salesforce did not match the application documents. For example, one applicant?s birthday in Salesforce did not agree to the application document and another applicant?s address in Salesforce did not match the address in the application.WHY DID THESE PROBLEMS OCCUR?The Department did not adequately train its LEAP technicians to ensure that the entry of application data into Salesforce fully matched the supporting documentation, and that income and number of households were entered into the system accurately. Specifically, we noted that the nine cases with issues were approved solely by the LEAP technicians, but they did not identify and correct the errors.WHY DO THESE PROBLEMS MATTER?Failing to identify errors in Salesforce increases the risk that the Department will fail to provide LEAP benefits to eligible individuals and families, or will provide LEAP benefits to ineligible individuals and families. Furthermore, determining eligibility incorrectly may result in the Department being out of compliance with federal LEAP regulations.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1901COLIEA2001COESC32001COLIEAFEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.568, LOW-INCOME HOME ENERGY ASSISTANCECOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-055The Department of Human Services should strengthen its internal controls and ensure it complies with federal Low-Income Home Energy Assistance Program (LEAP) eligibility determination and documentation requirements by improving training of its technicians on data entry and review in the LEAP Salesforce system and making sure all the inputs agree to supporting documentation to ensure information in the Salesforce system is accurate.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: OCTOBER 2021.The Department of Human Services agrees to improve training in the areas of eligibility and income determinations when annual training is presented in fall of 2021 for all new and veteran technicians. The program realizes that accurate data entry into the LEAP Salesforce system is vital to help ensure accurate eligibility and payment determinations. The training will have added specialized training exercises to the training curriculum around correct data entry into the LEAP Salesforce System. Additionally, over the course of the FFY 2022 heating season the program will monitor QA/QI monthly findings for patterns of excessive data entry errors and if detected the program will offer mandatory targeted training in this area.Although the Department agrees with this recommendation, the Department wants to note that there were zero payment or eligibility errors in the sample reviewed, thus the program is complying with federal eligibility determination requirements. LEAP undergoes extensive monitoring by the Department?s Quality Assurance and Quality Improvement (QA/QI) Division. The goals for case accuracy and case payment accuracy are 97% and in our current program year, FFY 2021, case accuracy rate is 96.30% and the payment accuracy rate is 96.58%. This demonstrates that the program is very close to meeting/exceeding accuracy goals of the program and these rates are based upon a much larger scale sample size. This demonstrates the program is meeting the eligibility determination requirements.
Show full finding ▾Hide full finding ▴INTERNAL CONTROLS OVER LEAP ELIGIBILITY DETERMINATIONThe Low-Income Home Energy Assistance Program (LEAP) is a federal program that helps eligible low-income Colorado families, seniors, and individuals pay a portion of their winter home heating costs. In most cases, the energy assistance benefit is paid directly to the household energy supplier. The Department?s Food and Energy Assistance Division is responsible for ensuring that the Department complies with federal and state requirements for this program. LEAP works to keep communities warm during the winter (November through April), which is also known as the LEAP season. In Fiscal Year 2020, the Department expended a total of $63.8 million in federal funds for LEAP.The Department has contracted with a vendor, Discover Goodwill, to process LEAP applications for 50 of the State?s 64 counties. Applications from the remaining 14 counties are processed at a local social/human services office or county, as applicable. Applications can be submitted online or dropped off at a local social/human services office, or mailed/emailed to the residing county or contractor, as applicable. A LEAP technician enters non-online application information into the LEAP system, Salesforce. Salesforce performs eligibility determinations based on information entered and schedules payments to energy providers for eligible recipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over the LEAP eligibility determination process, as well as to determine whether the Department complied with applicable federal LEAP eligibility requirements, during Fiscal Year 2020.We reviewed the Department?s LEAP eligibility internal controls in place during Fiscal Year 2020. We also performed a walkthrough of the eligibility determination process. In addition, we performed testing over a sample of 40 out of 74,972 LEAP applicants? information and related eligibility determinations to determine whether information was input correctly into Salesforce, and if eligibility determinations were appropriate.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? The Department?s LEAP Training and Operations Manual [Version 2019-2020, Section 4: Household Income] states that child support income is countable in calculating the applicant?s gross income.? State regulation [9 CCR 2503-7 3.752.211.H] states that cents are not considered in the social security benefits in calculating gross income.? State regulation [9 CCR 2503-7 3.751.1] requires that applications for households in an emergency situation shall be ?processed expeditiously and eligibility determined within fourteen calendar days of notification of the emergency by the application to the county department.? An emergency application is a household which has had heat service discontinued or is threatened with discontinuance of heat service.? According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?In nine out of 40 cases tested (23 percent), we identified at least one error. These errors did not ultimately impact the applicant?s eligibility for LEAP benefits during the Fiscal Year 2020 LEAP season. Specifically, we found the following:? In three cases, gross income was not calculated correctly. Specifically, in one case, cents from the applicant?s social security benefit payment were incorrectly included in the gross income calculation; in a second case, the applicant?s gross income was overstated by $500; and in a third case, the applicant?s child support payments were erroneously excluded from gross income.? In one case, one individual was not included as a household member even though the applicant had provided the social security number for the individual.? In one case, a household?s emergency application was processed fifteen calendar days after receipt of the application, which was one day late.? In seven cases, information entered into Salesforce did not match the application documents. For example, one applicant?s birthday in Salesforce did not agree to the application document and another applicant?s address in Salesforce did not match the address in the application.WHY DID THESE PROBLEMS OCCUR?The Department did not adequately train its LEAP technicians to ensure that the entry of application data into Salesforce fully matched the supporting documentation, and that income and number of households were entered into the system accurately. Specifically, we noted that the nine cases with issues were approved solely by the LEAP technicians, but they did not identify and correct the errors.WHY DO THESE PROBLEMS MATTER?Failing to identify errors in Salesforce increases the risk that the Department will fail to provide LEAP benefits to eligible individuals and families, or will provide LEAP benefits to ineligible individuals and families. Furthermore, determining eligibility incorrectly may result in the Department being out of compliance with federal LEAP regulations.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1901COLIEA2001COESC32001COLIEAFEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.568, LOW-INCOME HOME ENERGY ASSISTANCECOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-055The Department of Human Services should strengthen its internal controls and ensure it complies with federal Low-Income Home Energy Assistance Program (LEAP) eligibility determination and documentation requirements by improving training of its technicians on data entry and review in the LEAP Salesforce system and making sure all the inputs agree to supporting documentation to ensure information in the Salesforce system is accurate.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: OCTOBER 2021.The Department of Human Services agrees to improve training in the areas of eligibility and income determinations when annual training is presented in fall of 2021 for all new and veteran technicians. The program realizes that accurate data entry into the LEAP Salesforce system is vital to help ensure accurate eligibility and payment determinations. The training will have added specialized training exercises to the training curriculum around correct data entry into the LEAP Salesforce System. Additionally, over the course of the FFY 2022 heating season the program will monitor QA/QI monthly findings for patterns of excessive data entry errors and if detected the program will offer mandatory targeted training in this area.Although the Department agrees with this recommendation, the Department wants to note that there were zero payment or eligibility errors in the sample reviewed, thus the program is complying with federal eligibility determination requirements. LEAP undergoes extensive monitoring by the Department?s Quality Assurance and Quality Improvement (QA/QI) Division. The goals for case accuracy and case payment accuracy are 97% and in our current program year, FFY 2021, case accuracy rate is 96.30% and the payment accuracy rate is 96.58%. This demonstrates that the program is very close to meeting/exceeding accuracy goals of the program and these rates are based upon a much larger scale sample size. This demonstrates the program is meeting the eligibility determination requirements.
The Department of Human Services agrees to improve training in the areas of eligibility and income determinations when annual training is presented in fall of 2021 for all new and veteran technicians. The program realizes that accurate data entry into the LEAP Salesforce system is vital to help ensure accurate eligibility and payment determinations. The training will have added specialized training exercises to the training curriculum around correct data entry into the LEAP Salesforce System. Additionally, over the course of the FFY 2022 heating season the program will monitor QA/QI monthly findings for patterns of excessive data entry errors and if detected the program will offer mandatory targeted training in this area.Although the Department agrees with this recommendation, the Department wants to note that there were zero payment or eligibility errors in the sample reviewed, thus the program is complying with federal eligibility determination requirements. LEAP undergoes extensive monitoring by the Department?s Quality Assurance and Quality Improvement (QA/QI) Division. The goals for case accuracy and case payment accuracy are 97% and in our current program year, FFY 2021, case accuracy rate is 96.30% and the payment accuracy rate is 96.58%. This demonstrates that the program is very close to meeting/exceeding accuracy goals of the program and these rates are based upon a much larger scale sample size. This demonstrates the program is meeting the eligibility determination requirements.
CHILD SUPPORT ENFORCEMENT PROGRAMThe federal Child Support Enforcement program provides financial assistance to states to enforce support obligations owed by non-custodial parents, locate absent parents, establish paternity, and obtain child and spousal support. The Child Support Enforcement program was enacted under Title IV-D of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as Child Support Enforcement (CSE or Program). During Fiscal Year 2020, CSE expenditures totaled approximately $73.1 million in federal and state funds.The Department?s Division of Child Support Services is responsible for overseeing CSE and ensuring that the Department complies with federal and state requirements for this program. CSE is administered at the local level by the county child support offices within the county departments of human/social services and the Department is responsible for monitoring the counties? administration of the Program. County workers enter CSE case information, such as child support payments received from a non-custodial parent and child support payments sent to a custodial parent, into the Automated Child Support Enforcement System (ACSES), a statewide computer system which provides case management and financial management for child support payments. ACSES processes case files automatically when information such as a child support payment is entered. The system will then allocate the payment as entered by the county worker based on the case documentation, such as court orders. Certain users within ACSES have the ability to manually override the system?s processes for calculating and recording child support payments. For example, in certain situations the system is unable to complete the payment allocation for a case and the caseworker must go into the system and manually allocate the payment to complete the transaction.The Department?s QA Division is responsible for the CSE quality review process, which is designed to ensure that counties are following federal requirements, as well as the Colorado Code of Regulations. Specifically, each month the QA Division reviews a sample of cases within ACSES to determine whether cases are being administered correctly.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over ACSES to determine whether the Department had adequate internal controls over the system during Fiscal Year 2020.The audit work included performing inquiries of Department staff to determine what processes they have in place for monitoring and reviewing manual overrides within ACSES. We also obtained and reviewed reports relating to overrides performed in ACSES and a listing of users who have access to perform overrides.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [45 CFR 307.13] related to the Child Support Enforcement information system indicate that state agencies shall ?monitor routine access to and use of the computerized support enforcement system through methods such as audit trails and feedback mechanisms to guard against, and promptly identify unauthorized access or use.?The Office of the State Controller?s Fiscal Procedures Manual[Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives and Section 3.7a, State of Colorado Accounting Organization Shares Responsibilities] requires state departments to ?establish internal controls for their departments? in order to ??maintain an internal control environment that enhances sound business practices, clearly defines roles, responsibilities, and accountability, and provides for the prevention and detection of fraudulent activity.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the Department did not have sufficient internal control processes in place during Fiscal Year 2020 related to manual overrides of ACSES system controls related to payment allocations. Specifically, Department staff indicated that they do not have processes in place to require county staff to review ACSES allocation overrides after they occur or to require Department staff to review or monitor overrides centrally.In Fiscal Year 2020, we found that a total of 16,186 overrides, with a net effect of approximately $4.6 million, were performed by 145 users within ACSES.WHY DID THESE PROBLEMS OCCUR?The Department lacked adequate internal controls to ensure that higher risk cases, such as those with manual overrides, are reviewed to ensure they are accurate. Specifically, the Department does not have a process to separately monitor or review override activity within ACSES. The Department?s existing review process does not include a specific review of manual overrides of the system, which may represent an increased fraud risk. Department staff indicated that cases with an override are included in the population of cases from which their QA Division selects for review. However, staff also indicated that the QA Division does not separately identify and select cases with overrides for review. We determined that the cases with manual overrides represented approximately 0.7 percent of the 2.4 million transactions logged in Fiscal Year 2020; this small proportion means that it is very unlikely that any cases with a manual override will be selected for review by the QA Division.WHY DO THESE PROBLEMS MATTER?Failing to monitor manual overrides increases the risk of errors not being corrected in the allocation and administration of child support payments and also presents an opportunity for fraud not being detected. Errors or fraud relating to child support payments can result in incorrect payments being sent on behalf of a child. Furthermore, the Department risks not being in compliance with federal regulations relating to CSE. This can result in federal disallowances and recoveries being imposed on the Department.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION 2020-056The Department of Human Services should improve its internal controls over the Automated Child Support Enforcement System (ACSES) by developing and implementing a formal written policy to ensure that manual override activity within ACSES is separately monitored and reviewed.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services agrees that it will improve its internal controls over the Automated Child Support Enforcement System (ACSES) by developing and implementing a formal written policy to ensure that manual override activity within ACSES is separately monitored and reviewed; however, the Department of Human Services would like to note that the cases with manual overrides are not considered higher risk cases and does not believe these are higher risk for fraud.
Show full finding ▾Hide full finding ▴CHILD SUPPORT ENFORCEMENT PROGRAMThe federal Child Support Enforcement program provides financial assistance to states to enforce support obligations owed by non-custodial parents, locate absent parents, establish paternity, and obtain child and spousal support. The Child Support Enforcement program was enacted under Title IV-D of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as Child Support Enforcement (CSE or Program). During Fiscal Year 2020, CSE expenditures totaled approximately $73.1 million in federal and state funds.The Department?s Division of Child Support Services is responsible for overseeing CSE and ensuring that the Department complies with federal and state requirements for this program. CSE is administered at the local level by the county child support offices within the county departments of human/social services and the Department is responsible for monitoring the counties? administration of the Program. County workers enter CSE case information, such as child support payments received from a non-custodial parent and child support payments sent to a custodial parent, into the Automated Child Support Enforcement System (ACSES), a statewide computer system which provides case management and financial management for child support payments. ACSES processes case files automatically when information such as a child support payment is entered. The system will then allocate the payment as entered by the county worker based on the case documentation, such as court orders. Certain users within ACSES have the ability to manually override the system?s processes for calculating and recording child support payments. For example, in certain situations the system is unable to complete the payment allocation for a case and the caseworker must go into the system and manually allocate the payment to complete the transaction.The Department?s QA Division is responsible for the CSE quality review process, which is designed to ensure that counties are following federal requirements, as well as the Colorado Code of Regulations. Specifically, each month the QA Division reviews a sample of cases within ACSES to determine whether cases are being administered correctly.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls over ACSES to determine whether the Department had adequate internal controls over the system during Fiscal Year 2020.The audit work included performing inquiries of Department staff to determine what processes they have in place for monitoring and reviewing manual overrides within ACSES. We also obtained and reviewed reports relating to overrides performed in ACSES and a listing of users who have access to perform overrides.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Federal regulations [45 CFR 307.13] related to the Child Support Enforcement information system indicate that state agencies shall ?monitor routine access to and use of the computerized support enforcement system through methods such as audit trails and feedback mechanisms to guard against, and promptly identify unauthorized access or use.?The Office of the State Controller?s Fiscal Procedures Manual[Chapter 1, Section 3.3, State of Colorado Accounting Organization Objectives and Section 3.7a, State of Colorado Accounting Organization Shares Responsibilities] requires state departments to ?establish internal controls for their departments? in order to ??maintain an internal control environment that enhances sound business practices, clearly defines roles, responsibilities, and accountability, and provides for the prevention and detection of fraudulent activity.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the Department did not have sufficient internal control processes in place during Fiscal Year 2020 related to manual overrides of ACSES system controls related to payment allocations. Specifically, Department staff indicated that they do not have processes in place to require county staff to review ACSES allocation overrides after they occur or to require Department staff to review or monitor overrides centrally.In Fiscal Year 2020, we found that a total of 16,186 overrides, with a net effect of approximately $4.6 million, were performed by 145 users within ACSES.WHY DID THESE PROBLEMS OCCUR?The Department lacked adequate internal controls to ensure that higher risk cases, such as those with manual overrides, are reviewed to ensure they are accurate. Specifically, the Department does not have a process to separately monitor or review override activity within ACSES. The Department?s existing review process does not include a specific review of manual overrides of the system, which may represent an increased fraud risk. Department staff indicated that cases with an override are included in the population of cases from which their QA Division selects for review. However, staff also indicated that the QA Division does not separately identify and select cases with overrides for review. We determined that the cases with manual overrides represented approximately 0.7 percent of the 2.4 million transactions logged in Fiscal Year 2020; this small proportion means that it is very unlikely that any cases with a manual override will be selected for review by the QA Division.WHY DO THESE PROBLEMS MATTER?Failing to monitor manual overrides increases the risk of errors not being corrected in the allocation and administration of child support payments and also presents an opportunity for fraud not being detected. Errors or fraud relating to child support payments can result in incorrect payments being sent on behalf of a child. Furthermore, the Department risks not being in compliance with federal regulations relating to CSE. This can result in federal disallowances and recoveries being imposed on the Department.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION 2020-056The Department of Human Services should improve its internal controls over the Automated Child Support Enforcement System (ACSES) by developing and implementing a formal written policy to ensure that manual override activity within ACSES is separately monitored and reviewed.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services agrees that it will improve its internal controls over the Automated Child Support Enforcement System (ACSES) by developing and implementing a formal written policy to ensure that manual override activity within ACSES is separately monitored and reviewed; however, the Department of Human Services would like to note that the cases with manual overrides are not considered higher risk cases and does not believe these are higher risk for fraud.
The Department of Human Services agrees that it will improve its internal controls over the Automated Child Support Enforcement System (ACSES) by developing and implementing a formal written policy to ensure that manual override activity within ACSES is separately monitored and reviewed; however, the Department of Human Services would like to note that the cases with manual overrides are not considered higher risk cases and does not believe these are higher risk for fraud.
NATIONAL SCHOOL LUNCH PROGRAM FOOD INVENTORY RECONCILIATIONThe Department is in-charge of managing the procurement, storage, and distribution of donated agricultural commodities provided through and administered by the USDA?s National School Lunch Program (Lunch Program) [CFDA No. 10.555]. This program is part of the USDA?s Child Nutrition Cluster programs.The federal Child Nutrition Cluster programs are intended to (1) assist states in administering food services that provide healthy, nutritious meals to eligible children in public and nonprofit private schools, residential child care institutions, and summer recreation programs; and (2) encourage the domestic consumption of nutritious agricultural commodities.USDA enters into agreements with states for the distribution of USDA- donated foods. The states, in turn, enter into agreements with local Lunch Program operators, which are defined collectively as recipient agencies. The Department?s responsibility under the Lunch Program includes hiring a food logistics vendor to purchase food products and deliver them to schools and child care centers (recipient agencies) throughout Colorado; and tracking, maintaining, and reconciling inventory records for the food products. The Department contracts with a warehouse in Colorado Springs to store its food inventory.Once a donated food shipment arrives at the Department-contracted warehouse, the warehouse staff count the food to compare it to the provided Bill of Lading (BOL), review it for good condition, and check the temperature of all cases. The food logistics vendor then picks up the donated food from the warehouse and delivers it to the schools. The schools are responsible for inspecting the load, counting the items received, and signing off on the BOL to certify that it is accurate. The food logistics vendor keeps a copy of the BOL.The Colorado Department of Education (CDE) is responsible for all non-inventory related federal requirements for the Lunch Program. For example, CDE is responsible for collecting and tracking total school lunches served, which dictates the volume of donated foods the State receives.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine if the Department had adequate internal controls over and complied with inventory-related requirements for the Lunch Program during Fiscal Year 2020, which included determining whether the Department maintained accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods through the Lunch Program and performed inventory reconciliations throughout the fiscal year.We obtained the Department?s procedures for preparing its fiscal year-end and monthly reconciliations of its Lunch Program inventory and documentation related to the receipt and shipment of the Lunch Program?s donated foods. We also requested that the Department provide its fiscal year-end inventory reconciliation. We obtained and tested two monthly inventory reconciliations prepared by the Department for Fiscal Year 2020.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against these requirements:Federal regulations [7 CFR 250.12(b)] for the Lunch Program require that the Department take a physical inventory of its Lunch Program donated foods at its warehouse and reconcile the results of the physical inventory annually with the warehouse?s inventory records. The Department must maintain the results of the inventory and the reconciliation itself or ensure the warehouse maintains the documentation. The regulations also require that the Department, as the distributing agency, report any donated food losses, and ensure that restitution is made for such losses.Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16 (a)]. Records relating to requirements for donated foods must be retained for a period of three years from the close of the fiscal or school year to which they pertain [7 CFR 250.19(b)].The Department?s Inventory Tracking and Reconciliation policy for the Lunch Program requires the Department to perform a reconciliation between incoming inventory from the USDA and shipping reports provided by the food logistics vendor. The procedure states that ?any variances between the Reconciliation Spreadsheet and Physical Inventory are given to the food logistics vendor to check and agree on. If there is a significant variance the program completes a food loss investigation which may result in financial reimbursement.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully reconcile its Lunch Program donated food inventory at fiscal year end to the underlying records. Specifically, the Department conducted a fiscal year end physical inventory at the warehouse and compared the physical inventory counts to the inventory provided by the USDA throughout the fiscal year and what was delivered to schools and child care centers by the food logistics vendor, but did not follow-up and resolve variances noted through the comparison. Specifically, we noted that 25 of the 30 (83 percent) food items the Department compared between the USDA-provided and food logistics vendor-provided documentation contained differences. The overall gross value of the variances totaled $4,507, with a net variance of $259.We also noted that the Department did not obtain from the warehouse or retain records of the receipt and distribution of the Lunch Program?s donated inventory during the fiscal year. Rather, at fiscal year end, Department staff obtained records from the USDA database and reports provided by the food logistics vendor, and compared the reports with the warehouse?s inventory for the Lunch Program?s inventory reconciliation.WHY DID THESE PROBLEMS OCCUR?The Department did not have sufficient internal controls in place over its Lunch Program inventory during Fiscal Year 2020. First, the Department failed to follow its Lunch Program procedures related to completing an annual reconciliation of Lunch Program-donated foods and to investigate any inventory variances. The Department stated that the reason for the variance was that the food logistics vendor did not provide final shipping reports; however, the Department did not follow up and obtain the final shipping reports from its food logistics vendor to determine if the variances were resolved.Second, the Department does not have policies and procedures requiring that Department staff obtain from the warehouse and retain Lunch Program receipts and distributions, such as BOLs for the USDA shipments received by the warehouse and the BOLs for the distributions made by the food logistics vendor to the schools, and therefore, did not have adequate information to complete the fiscal year-end reconciliation.WHY DO THESE PROBLEM MATTER?If the Department does not obtain and maintain the Lunch Program?s inventory records, it will be out of compliance with federal guidance. In addition, if the Department does not reconcile its food inventory and investigate variances, food loss or waste could occur and the Department would be required to pay the federal government for this loss. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide the schools for children.FEDERAL DEPARTMENT DEPARTMENT OF AGRICULTUREFEDERAL AWARD NUMBER 193CO002N2533FEDERAL AWARD YEAR 2019PASS THROUGH ENTITY NONECFDA NO. 10.555, NATIONAL SCHOOL LUNCH PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-057The Department of Human Services (Department) should ensure that it complies with U.S. Department of Agriculture?s (USDA) federal requirements for the National School Lunch program by:A Completing fiscal year-end reconciliations of its donated foods inventory, including investigating and resolving all identified variances.B Developing and implementing policies and procedures for the Department to obtain and maintain complete inventory records, including Bills of Lading for the USDA shipments received by the warehouse and for the distributions made by the food logistics vendor to the schools. This should include maintaining its own records for verifying USDA and vendor information.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory.B PARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level.AUDITOR?S ADDENDUMFederal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Although the Department contracts with a warehouse to maintain the donated foods inventory and to obtain and maintain complete inventory records, the requirement for proper maintenance of inventory records is ultimately the Department?s responsibility.
Show full finding ▾Hide full finding ▴NATIONAL SCHOOL LUNCH PROGRAM FOOD INVENTORY RECONCILIATIONThe Department is in-charge of managing the procurement, storage, and distribution of donated agricultural commodities provided through and administered by the USDA?s National School Lunch Program (Lunch Program) [CFDA No. 10.555]. This program is part of the USDA?s Child Nutrition Cluster programs.The federal Child Nutrition Cluster programs are intended to (1) assist states in administering food services that provide healthy, nutritious meals to eligible children in public and nonprofit private schools, residential child care institutions, and summer recreation programs; and (2) encourage the domestic consumption of nutritious agricultural commodities.USDA enters into agreements with states for the distribution of USDA- donated foods. The states, in turn, enter into agreements with local Lunch Program operators, which are defined collectively as recipient agencies. The Department?s responsibility under the Lunch Program includes hiring a food logistics vendor to purchase food products and deliver them to schools and child care centers (recipient agencies) throughout Colorado; and tracking, maintaining, and reconciling inventory records for the food products. The Department contracts with a warehouse in Colorado Springs to store its food inventory.Once a donated food shipment arrives at the Department-contracted warehouse, the warehouse staff count the food to compare it to the provided Bill of Lading (BOL), review it for good condition, and check the temperature of all cases. The food logistics vendor then picks up the donated food from the warehouse and delivers it to the schools. The schools are responsible for inspecting the load, counting the items received, and signing off on the BOL to certify that it is accurate. The food logistics vendor keeps a copy of the BOL.The Colorado Department of Education (CDE) is responsible for all non-inventory related federal requirements for the Lunch Program. For example, CDE is responsible for collecting and tracking total school lunches served, which dictates the volume of donated foods the State receives.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine if the Department had adequate internal controls over and complied with inventory-related requirements for the Lunch Program during Fiscal Year 2020, which included determining whether the Department maintained accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods through the Lunch Program and performed inventory reconciliations throughout the fiscal year.We obtained the Department?s procedures for preparing its fiscal year-end and monthly reconciliations of its Lunch Program inventory and documentation related to the receipt and shipment of the Lunch Program?s donated foods. We also requested that the Department provide its fiscal year-end inventory reconciliation. We obtained and tested two monthly inventory reconciliations prepared by the Department for Fiscal Year 2020.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against these requirements:Federal regulations [7 CFR 250.12(b)] for the Lunch Program require that the Department take a physical inventory of its Lunch Program donated foods at its warehouse and reconcile the results of the physical inventory annually with the warehouse?s inventory records. The Department must maintain the results of the inventory and the reconciliation itself or ensure the warehouse maintains the documentation. The regulations also require that the Department, as the distributing agency, report any donated food losses, and ensure that restitution is made for such losses.Federal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Failure to maintain these records shall be considered ?prima facie evidence of improper distribution or loss of donated foods.? The Department must ensure that ?restitution is made for the loss of donated foods, or for the loss or improper use of funds provided for, or obtained as an incident of, the distribution of donated foods? [7 CFR 250.16 (a)]. Records relating to requirements for donated foods must be retained for a period of three years from the close of the fiscal or school year to which they pertain [7 CFR 250.19(b)].The Department?s Inventory Tracking and Reconciliation policy for the Lunch Program requires the Department to perform a reconciliation between incoming inventory from the USDA and shipping reports provided by the food logistics vendor. The procedure states that ?any variances between the Reconciliation Spreadsheet and Physical Inventory are given to the food logistics vendor to check and agree on. If there is a significant variance the program completes a food loss investigation which may result in financial reimbursement.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department did not fully reconcile its Lunch Program donated food inventory at fiscal year end to the underlying records. Specifically, the Department conducted a fiscal year end physical inventory at the warehouse and compared the physical inventory counts to the inventory provided by the USDA throughout the fiscal year and what was delivered to schools and child care centers by the food logistics vendor, but did not follow-up and resolve variances noted through the comparison. Specifically, we noted that 25 of the 30 (83 percent) food items the Department compared between the USDA-provided and food logistics vendor-provided documentation contained differences. The overall gross value of the variances totaled $4,507, with a net variance of $259.We also noted that the Department did not obtain from the warehouse or retain records of the receipt and distribution of the Lunch Program?s donated inventory during the fiscal year. Rather, at fiscal year end, Department staff obtained records from the USDA database and reports provided by the food logistics vendor, and compared the reports with the warehouse?s inventory for the Lunch Program?s inventory reconciliation.WHY DID THESE PROBLEMS OCCUR?The Department did not have sufficient internal controls in place over its Lunch Program inventory during Fiscal Year 2020. First, the Department failed to follow its Lunch Program procedures related to completing an annual reconciliation of Lunch Program-donated foods and to investigate any inventory variances. The Department stated that the reason for the variance was that the food logistics vendor did not provide final shipping reports; however, the Department did not follow up and obtain the final shipping reports from its food logistics vendor to determine if the variances were resolved.Second, the Department does not have policies and procedures requiring that Department staff obtain from the warehouse and retain Lunch Program receipts and distributions, such as BOLs for the USDA shipments received by the warehouse and the BOLs for the distributions made by the food logistics vendor to the schools, and therefore, did not have adequate information to complete the fiscal year-end reconciliation.WHY DO THESE PROBLEM MATTER?If the Department does not obtain and maintain the Lunch Program?s inventory records, it will be out of compliance with federal guidance. In addition, if the Department does not reconcile its food inventory and investigate variances, food loss or waste could occur and the Department would be required to pay the federal government for this loss. By not having a proper tracking of inventory, this could also result in the Department not having sufficient food to provide the schools for children.FEDERAL DEPARTMENT DEPARTMENT OF AGRICULTUREFEDERAL AWARD NUMBER 193CO002N2533FEDERAL AWARD YEAR 2019PASS THROUGH ENTITY NONECFDA NO. 10.555, NATIONAL SCHOOL LUNCH PROGRAMCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-057The Department of Human Services (Department) should ensure that it complies with U.S. Department of Agriculture?s (USDA) federal requirements for the National School Lunch program by:A Completing fiscal year-end reconciliations of its donated foods inventory, including investigating and resolving all identified variances.B Developing and implementing policies and procedures for the Department to obtain and maintain complete inventory records, including Bills of Lading for the USDA shipments received by the warehouse and for the distributions made by the food logistics vendor to the schools. This should include maintaining its own records for verifying USDA and vendor information.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory.B PARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level.AUDITOR?S ADDENDUMFederal regulations [7 CFR 250.19(a)] require that the Department, as a distributing agency, keep complete records of donated foods. Although the Department contracts with a warehouse to maintain the donated foods inventory and to obtain and maintain complete inventory records, the requirement for proper maintenance of inventory records is ultimately the Department?s responsibility.
(A) The Department agrees with conducting an annual physical inventory as it has in other previous years. During the audit test period, this had not occurred due to the pandemic. The Department also agrees that the physical inventory will be reconciled to the book inventory.(B) The Department partially agrees with this recommendation. Specifically, the Department agrees to require its contracted warehouse to obtain and maintain complete inventory records, including Bill of Ladings for the USDA shipments received by the warehouse and the Bill of Ladings for the distributions made by the food logistics vendor to the schools. These records will be required to be furnished by the contracted warehouse when the Department or any other regulatory body perform reviews. The Department disagrees to obtain and maintain the complete inventory records at the state level.
AUTOMATED CHILD SUPPORT ENFORCEMENT SYSTEM (ACSES)?INFORMATION SECURITYGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and Governor?s Office of Information Technology (OIT) in separate, confidential memoranda.The Department?s Division of Child Support Services administers the State?s Child Support Services Program (Program), which is partially funded through the federal Child Support Enforcement grant [CFDA No. 93.563]. The purpose of the Program is to establish and enforce medical and financial support orders, and collect funds related to support orders. To meet the Program?s purpose, the Department relies on ACSES to support the State?s case management of 150,000 caseloads and process over $450 million in child support payments annually. ACSES has been operating since 1986 and also has a web-based portal, eCSE, allowing the public to request services and the ability to make child support payments, among other functionality. ACSES contains protected health information, personally identifiable information, and federal tax information that is governed by the IRS. As an essential application for the State, ACSES provides child support enforcement services that are critical for Colorado families. ACSES is supported by funding from the federal government and is subject to security compliance requirements related to protected health information, personally identifiable information, and federal tax information. The Department, its IT service provider?the Governor?s Office of Information Technology (OIT)?and external vendors are working together to modernize the ACSES application, as well as the responsibility for the information security of both the application and its data. Information security over ACSES is a shared responsibility between the Department, OIT, and an external vendor.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department and OIT had appropriate information security controls in place and operating effectively over the ACSES system. Our audit work involved interviews of Department and OIT staff, as well as reviews of relevant, supporting documentation.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? State information security policies developed and issued by the Department and OIT.? Federal information security requirements issued by the federal Office of Child Support Enforcement and the IRS.? Contractual requirements between OIT and the external vendors.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department and OIT were not complying with certain state, federal, and contractual information security requirements.WHY DID THESE PROBLEMS OCCUR?The Department and OIT did not provide explanations for the majority of the problems we found. In those instances where we were provided with explanations, OIT stated that staff were following state policies, instead of Department requirements, as well as the need to finish certain projects, and the Department stated that there was a misunderstanding of information security requirements and a lack of staff to enforce the requirements.WHY DO THESE PROBLEMS MATTER?In combination, the deficiencies we found could threaten the confidentiality, integrity, and availability of ACSES and the data in the system.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NoCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-058The Department of Human Services should improve the Automated Child Support Enforcement System?s information security controls by:A Mitigating the information security problems noted in the confidential finding PART A.B Mitigating the information security problems noted in the confidential finding PART B.C Mitigating the information security problems noted in the confidential finding PART C.D Mitigating the information security problems noted in the confidential finding PART D.E Mitigating the information security problems noted in the confidential finding PART E.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part A.B AGREE. IMPLEMENTATION DATE: APRIL 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part B.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part C.D AGREE. IMPLEMENTATION DATE: NOVEMBER 2020.The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part D.E AGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part E.
Show full finding ▾Hide full finding ▴AUTOMATED CHILD SUPPORT ENFORCEMENT SYSTEM (ACSES)?INFORMATION SECURITYGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and Governor?s Office of Information Technology (OIT) in separate, confidential memoranda.The Department?s Division of Child Support Services administers the State?s Child Support Services Program (Program), which is partially funded through the federal Child Support Enforcement grant [CFDA No. 93.563]. The purpose of the Program is to establish and enforce medical and financial support orders, and collect funds related to support orders. To meet the Program?s purpose, the Department relies on ACSES to support the State?s case management of 150,000 caseloads and process over $450 million in child support payments annually. ACSES has been operating since 1986 and also has a web-based portal, eCSE, allowing the public to request services and the ability to make child support payments, among other functionality. ACSES contains protected health information, personally identifiable information, and federal tax information that is governed by the IRS. As an essential application for the State, ACSES provides child support enforcement services that are critical for Colorado families. ACSES is supported by funding from the federal government and is subject to security compliance requirements related to protected health information, personally identifiable information, and federal tax information. The Department, its IT service provider?the Governor?s Office of Information Technology (OIT)?and external vendors are working together to modernize the ACSES application, as well as the responsibility for the information security of both the application and its data. Information security over ACSES is a shared responsibility between the Department, OIT, and an external vendor.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department and OIT had appropriate information security controls in place and operating effectively over the ACSES system. Our audit work involved interviews of Department and OIT staff, as well as reviews of relevant, supporting documentation.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following:? State information security policies developed and issued by the Department and OIT.? Federal information security requirements issued by the federal Office of Child Support Enforcement and the IRS.? Contractual requirements between OIT and the external vendors.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that the Department and OIT were not complying with certain state, federal, and contractual information security requirements.WHY DID THESE PROBLEMS OCCUR?The Department and OIT did not provide explanations for the majority of the problems we found. In those instances where we were provided with explanations, OIT stated that staff were following state policies, instead of Department requirements, as well as the need to finish certain projects, and the Department stated that there was a misunderstanding of information security requirements and a lack of staff to enforce the requirements.WHY DO THESE PROBLEMS MATTER?In combination, the deficiencies we found could threaten the confidentiality, integrity, and availability of ACSES and the data in the system.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NoCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-058The Department of Human Services should improve the Automated Child Support Enforcement System?s information security controls by:A Mitigating the information security problems noted in the confidential finding PART A.B Mitigating the information security problems noted in the confidential finding PART B.C Mitigating the information security problems noted in the confidential finding PART C.D Mitigating the information security problems noted in the confidential finding PART D.E Mitigating the information security problems noted in the confidential finding PART E.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part A.B AGREE. IMPLEMENTATION DATE: APRIL 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part B.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part C.D AGREE. IMPLEMENTATION DATE: NOVEMBER 2020.The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part D.E AGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services will improve ACSES information security controls by mitigating the problems noted in the confidential finding part E.
(A) The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part A.(B) The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part B.(C) The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part C.(D) The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part D.(E) The Department of Human Services has improved ACSES information security controls by mitigating the problems noted in the confidential finding part E.
RECOMMENDATION2020-059The Governor?s Office of Information Technology should improve the Automated Child Support Enforcement System information security controls by:A Mitigating the information security problems noted in the confidential finding PART A.B Mitigating the information security problems noted in the confidential finding PART B.C Mitigating the information security problems noted in the confidential finding PART C.D Mitigating the information security problems noted in the confidential finding PART D.E Mitigating the information security problems noted in the confidential finding PART E.F Mitigating the information security problems noted in the confidential finding PART F.G Mitigating the information security problems noted in the confidential finding PART G.H Mitigating the information security problems noted in the confidential finding PART H.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding and will work with the Department to mitigate the problems identified in Part D of the confidential finding.E AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part E of the confidential finding.F AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part F of the confidential finding.G AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part G of the confidential finding.H AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part H of the confidential finding.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-059The Governor?s Office of Information Technology should improve the Automated Child Support Enforcement System information security controls by:A Mitigating the information security problems noted in the confidential finding PART A.B Mitigating the information security problems noted in the confidential finding PART B.C Mitigating the information security problems noted in the confidential finding PART C.D Mitigating the information security problems noted in the confidential finding PART D.E Mitigating the information security problems noted in the confidential finding PART E.F Mitigating the information security problems noted in the confidential finding PART F.G Mitigating the information security problems noted in the confidential finding PART G.H Mitigating the information security problems noted in the confidential finding PART H.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.B AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding and will work with the Department to mitigate the problems identified in Part D of the confidential finding.E AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part E of the confidential finding.F AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part F of the confidential finding.G AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part G of the confidential finding.H AGREE. IMPLEMENTATION DATE: JULY 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part H of the confidential finding.
(A) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.(B) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.(C) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.(D) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part D of the confidential finding.(E) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part E of the confidential finding.(F) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part F of the confidential finding.(G) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part G of the confidential finding.(H) The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part H of the confidential finding.
ACSES?COMPUTER OPERATIONSGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.ACSES has been designated as an essential application for the State of Colorado, and the Department and OIT work to ensure that appropriate controls are in place for the ongoing operation and continuity of the application. The Department and OIT have entered into an interagency agreement to provide certain technological support for ACSES, in coordination with the ACSES vendors.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department and OIT had select operational controls designed, in place, and operating effectively over ACSES. We performed our audit work through inquiry of Department and OIT personnel and inspection of documentation within these process areas.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the federal Office of Child Support Enforcement security requirements and both the Colorado Information Security Policies and OIT Cyber Policies.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified problems related to the Department?s and OIT?s computer operations controls for ACSES.WHY DID THESE PROBLEMS OCCUR?The Department and OIT did not provide causes for all of the problems we identified. In those instances when causes were provided, the Department states that select IT procedures were not approved by management and in effect for Fiscal Year 2020, and OIT stated that it did not comply with federal and state requirements due to resource limitations caused by the COVID-19 pandemic.WHY DO THESE PROBLEMS MATTER?Without fully developed ACSES computer operational processes, the Department and OIT may be at risk of not being able to continue operating the ACSES system if a system disruption were to occur. This, in turn, could adversely impact the State?s ability to effectively administer its Child Support Enforcement program and could result in sanctions related to future federal funding that the ACSES program depends on to fulfill its mission.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-060The Department of Human Services should improve computer operations controls and processes for the Automated Child Support Enforcement System by:A Mitigating the problems identified in PART A of the confidential finding.B Mitigating the problems identified in PART B of the confidential finding.C Mitigating the problems identified in PART C of the confidential finding.D Mitigating the problems identified in PART D of the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to ensure the problems identified in Part A of the confidential finding are mitigated.B AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will create a process to ensure that problems identified in Part D of the confidential finding are mitigated.
Show full finding ▾Hide full finding ▴ACSES?COMPUTER OPERATIONSGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.ACSES has been designated as an essential application for the State of Colorado, and the Department and OIT work to ensure that appropriate controls are in place for the ongoing operation and continuity of the application. The Department and OIT have entered into an interagency agreement to provide certain technological support for ACSES, in coordination with the ACSES vendors.WHAT WAS THE PURPOSE OF OUR AUDITWORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department and OIT had select operational controls designed, in place, and operating effectively over ACSES. We performed our audit work through inquiry of Department and OIT personnel and inspection of documentation within these process areas.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the federal Office of Child Support Enforcement security requirements and both the Colorado Information Security Policies and OIT Cyber Policies.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified problems related to the Department?s and OIT?s computer operations controls for ACSES.WHY DID THESE PROBLEMS OCCUR?The Department and OIT did not provide causes for all of the problems we identified. In those instances when causes were provided, the Department states that select IT procedures were not approved by management and in effect for Fiscal Year 2020, and OIT stated that it did not comply with federal and state requirements due to resource limitations caused by the COVID-19 pandemic.WHY DO THESE PROBLEMS MATTER?Without fully developed ACSES computer operational processes, the Department and OIT may be at risk of not being able to continue operating the ACSES system if a system disruption were to occur. This, in turn, could adversely impact the State?s ability to effectively administer its Child Support Enforcement program and could result in sanctions related to future federal funding that the ACSES program depends on to fulfill its mission.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-060The Department of Human Services should improve computer operations controls and processes for the Automated Child Support Enforcement System by:A Mitigating the problems identified in PART A of the confidential finding.B Mitigating the problems identified in PART B of the confidential finding.C Mitigating the problems identified in PART C of the confidential finding.D Mitigating the problems identified in PART D of the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESA AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to ensure the problems identified in Part A of the confidential finding are mitigated.B AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: MARCH 2021.The Department agrees with this finding. The Department will create a process to ensure that problems identified in Part D of the confidential finding are mitigated.
(A) The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to ensure the problems identified in Part A of the confidential finding are mitigated.(B) The Department agrees with this finding. The Department will work with the Governor?s Office of Information Technology to mitigate the problems identified in Part B of the confidential finding.(C) The Department agrees with this finding. The Department will work to mitigate the problems identified in Part C of the confidential finding.(D) The Department agrees with this finding. The Department will create a process to ensure that problems identified in Part D of the confidential finding are mitigated.
RECOMMENDATION2020-061The Governor?s Office of Information Technology should improve computer operational processes of the Automated Child Support Enforcement System by reprioritizing staff and working with key Department of Human Services? personnel to ensure compliance with all applicable state and federal information security requirements by:A Mitigating the problems identified in PART A of the confidential finding.B Mitigating the problems identified in PART B of the confidential finding.C Mitigating the problems identified in PART C of the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part A of the confidential findings.B AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part B of the confidential findings.C AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will collaborate with stakeholders to mitigate part C of the confidential findings.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-061The Governor?s Office of Information Technology should improve computer operational processes of the Automated Child Support Enforcement System by reprioritizing staff and working with key Department of Human Services? personnel to ensure compliance with all applicable state and federal information security requirements by:A Mitigating the problems identified in PART A of the confidential finding.B Mitigating the problems identified in PART B of the confidential finding.C Mitigating the problems identified in PART C of the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part A of the confidential findings.B AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part B of the confidential findings.C AGREE. IMPLEMENTATION DATE: MARCH 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will collaborate with stakeholders to mitigate part C of the confidential findings.
(A) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part A of the confidential findings.(B) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work with the Department to mitigate part B of the confidential findings.(C) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will collaborate with stakeholders to mitigate part C of the confidential findings.
ACSES VENDOR MANAGEMENTGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.The Department has contracted with OIT to provide additional support for the Department?s continued ACSES modernization project. OIT, in turn, has contracted additional support of ACSES to external vendor contracts. OIT has responsibility for the performance of processes assigned to its vendors.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department?s and OIT?s ACSES vendors were complying with contractual, state, and federal information security requirements. We discussed this with the Department and OIT staff, as well as inspected related vendor management documentation from the Department and OIT.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the federal Office of Child Support Enforcement security requirements and both the Colorado Information Security Policies and OIT Cyber Policies.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified vendor management problems related to the Department?s and OIT?s oversight of ACSES vendors.WHY DID THESE PROBLEMS OCCUR?The Department and OIT stated that they believed their vendor management process was sufficient for holding the vendor accountable. However, the vendor management process did not cover all areas to ensure compliance with contractual, state, and federal security requirements. OIT did not provide explanations as to why certain other problems occurred.WHY DO THESE PROBLEMS MATTER?Without proper vendor management controls in place for ensuring ACSES vendors comply with contractual, state, and federal security requirements, the Department and OIT have an increased risk of adverse cyber incidents occurring that may impact ACSES and its data. Specifically, such incidents could affect mission critical areas such as the confidentiality, integrity, and availability of the system and its data.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-062The Department of Human Services should improve vendor management oversight of the Automated Child Support Enforcement System by mitigating the problem identified in the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: APRIL 2021.The Department of Human Services will improve vendor management oversight of ACSES by mitigating the problem identified in the confidential finding.
Show full finding ▾Hide full finding ▴ACSES VENDOR MANAGEMENTGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.The Department has contracted with OIT to provide additional support for the Department?s continued ACSES modernization project. OIT, in turn, has contracted additional support of ACSES to external vendor contracts. OIT has responsibility for the performance of processes assigned to its vendors.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department?s and OIT?s ACSES vendors were complying with contractual, state, and federal information security requirements. We discussed this with the Department and OIT staff, as well as inspected related vendor management documentation from the Department and OIT.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the federal Office of Child Support Enforcement security requirements and both the Colorado Information Security Policies and OIT Cyber Policies.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified vendor management problems related to the Department?s and OIT?s oversight of ACSES vendors.WHY DID THESE PROBLEMS OCCUR?The Department and OIT stated that they believed their vendor management process was sufficient for holding the vendor accountable. However, the vendor management process did not cover all areas to ensure compliance with contractual, state, and federal security requirements. OIT did not provide explanations as to why certain other problems occurred.WHY DO THESE PROBLEMS MATTER?Without proper vendor management controls in place for ensuring ACSES vendors comply with contractual, state, and federal security requirements, the Department and OIT have an increased risk of adverse cyber incidents occurring that may impact ACSES and its data. Specifically, such incidents could affect mission critical areas such as the confidentiality, integrity, and availability of the system and its data.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBER 2001COCSESFEDERAL AWARD YEARS 2018, 2019, AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.563, CHILD SUPPORT ENFORCEMENTCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-062The Department of Human Services should improve vendor management oversight of the Automated Child Support Enforcement System by mitigating the problem identified in the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: APRIL 2021.The Department of Human Services will improve vendor management oversight of ACSES by mitigating the problem identified in the confidential finding.
The Department of Human Services will improve vendor management oversight of ACSES by mitigating the problem identified in the confidential finding.
RECOMMENDATION2020-063The Governor?s Office of Information Technology should improve vendor management oversight of the Automated Child Support Enforcement System by:A Mitigating the problem identified in PART A of the confidential finding.B Mitigating the problem identified in PART B of the confidential finding.C Mitigating the problem identified in PART C of the confidential finding.D Mitigating the problem identified in PART D of the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.B AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part D of the confidential finding.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-063The Governor?s Office of Information Technology should improve vendor management oversight of the Automated Child Support Enforcement System by:A Mitigating the problem identified in PART A of the confidential finding.B Mitigating the problem identified in PART B of the confidential finding.C Mitigating the problem identified in PART C of the confidential finding.D Mitigating the problem identified in PART D of the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYA AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.B AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.C AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.D AGREE. IMPLEMENTATION DATE: APRIL 2021.The Governor's Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part D of the confidential finding.
(A) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part A of the confidential finding.(B) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part B of the confidential finding.(C) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part C of the confidential finding.(D) The Governor?s Office of Information Technology (OIT) agrees with this finding. OIT will work to mitigate the problems identified in Part D of the confidential finding.
LOW-INCOME HOME ENERGY ASSISTANCE PROGRAM (LEAP) SYSTEM AND DATA SECURITYGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.The Department utilizes the LEAP system to manage LEAP eligibility and data transfers.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department, with OIT involvement, performed certain system and data security requirements. We interviewed Department LEAP and OIT staff, as well as reviewed various security documents.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our work against OIT?s Cyber Policies and Technical Standards.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?The Department and OIT did not provide documentation to demonstrate whether the LEAP system had certain system and data security requirements established during the Fiscal Year 2020 audit.WHY DID THESE PROBLEMS OCCUR?By the end of our fieldwork in September 2020, the Department and OIT did not provide explanations for the information system and data problems we identified.WHY DO THESE PROBLEMS MATTER?Without system and data security requirements being established, the Department and OIT may not be able to adequately secure the LEAP system and its data or provide for the most appropriate levels of confidentiality, integrity, and availability over them. Ultimately, these problems increase the risk of unauthorized access and changes to the system and its data, which may also have an adverse impact on the reliability of the system and its data as it relates to financial reporting.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1901COLIEA2001COESC32001COLIEAFEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.568, LOW-INCOME HOME ENERGY ASSISTANCECOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-064The Department of Human Services should improve IT controls over its Low-Income Home Energy Assistance Program system by working with the Governor?s Office of Information Technology to mitigate the system and data security problems identified in the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services will work with OIT to mitigate the system and data security problems identified in this confidential finding.
Show full finding ▾Hide full finding ▴LOW-INCOME HOME ENERGY ASSISTANCE PROGRAM (LEAP) SYSTEM AND DATA SECURITYGovernment Auditing Standards allow for information that is considered sensitive in nature, such as detailed information related to IT system security, to be issued through a separate ?classified or limited use? report because of the potential damage that could be caused by the misuse of this information. We consider the specific technical details of this finding, along with the response, to be sensitive in nature and not appropriate for public disclosure. Therefore, the details of the following finding and response have been provided to the Department and OIT in separate, confidential memoranda.The Department utilizes the LEAP system to manage LEAP eligibility and data transfers.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the Department, with OIT involvement, performed certain system and data security requirements. We interviewed Department LEAP and OIT staff, as well as reviewed various security documents.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our work against OIT?s Cyber Policies and Technical Standards.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?The Department and OIT did not provide documentation to demonstrate whether the LEAP system had certain system and data security requirements established during the Fiscal Year 2020 audit.WHY DID THESE PROBLEMS OCCUR?By the end of our fieldwork in September 2020, the Department and OIT did not provide explanations for the information system and data problems we identified.WHY DO THESE PROBLEMS MATTER?Without system and data security requirements being established, the Department and OIT may not be able to adequately secure the LEAP system and its data or provide for the most appropriate levels of confidentiality, integrity, and availability over them. Ultimately, these problems increase the risk of unauthorized access and changes to the system and its data, which may also have an adverse impact on the reliability of the system and its data as it relates to financial reporting.FEDERAL DEPARTMENT DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS 1901COLIEA2001COESC32001COLIEAFEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.568, LOW-INCOME HOME ENERGY ASSISTANCECOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-064The Department of Human Services should improve IT controls over its Low-Income Home Energy Assistance Program system by working with the Governor?s Office of Information Technology to mitigate the system and data security problems identified in the confidential finding.RESPONSEDEPARTMENT OF HUMAN SERVICESAGREE. IMPLEMENTATION DATE: JUNE 2021.The Department of Human Services will work with OIT to mitigate the system and data security problems identified in this confidential finding.
The Department of Human Services will work with OIT to mitigate the system and data security problems identified in this confidential finding.
RECOMMENDATION2020-065The Governor?s Office of Information Technology should improve IT controls over the Low-Income Home Energy Assistance Program system by mitigating the system security problems identified in the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYAGREE. IMPLEMENTATION DATE: JUNE 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding and will work with the Department to mitigate the system and data security problems identified in the confidential finding.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-065The Governor?s Office of Information Technology should improve IT controls over the Low-Income Home Energy Assistance Program system by mitigating the system security problems identified in the confidential finding.RESPONSEGOVERNOR?S OFFICEOF INFORMATION TECHNOLOGYAGREE. IMPLEMENTATION DATE: JUNE 2021.The Governor?s Office of Information Technology (OIT) agrees with this finding and will work with the Department to mitigate the system and data security problems identified in the confidential finding.
The Governor?s Office of Information Technology (OIT) agrees with this finding and will work with the Department to mitigate the system and data security problems identified in the confidential finding.
UNEMPLOYMENT INSURANCEThe Unemployment Insurance (UI) program, created by the Social Security Act, provides benefits to unemployed workers for periods of involuntary unemployment and helps stabilize the economy by maintaining the spending power of workers while they are between jobs. The U.S. Department of Labor provides grant funding for each state to design and administer its own UI program within federal requirements. The Department?s Division of Unemployment Insurance is responsible for the administration and monitoring of Colorado's UI programs, including the establishment of policies and operating procedures which comply with federal requirements; determining claimant eligibility and making payment of UI benefits to claimants; and administering the programs in accordance with established policies and procedures. The regular UI program provides coverage to most salary and wage workers and is funded primarily by state UI taxes assessed on covered employers. These taxes are required to be deposited into the State?s Unemployment Trust Fund for the purpose of making UI payments under the federally approved state unemployment law. As part of the administration of this program, the Department uses the Colorado Unemployment Benefits System (CUBS) to aid in determining eligibility for UI benefits.On March 13, 2020, the President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, and Congress subsequently passed the Emergency Unemployment Insurance Stabilization and Access Act of 2020 (EUISAA) and the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). Both EUISAA and the CARES Act included additional federal funding for, and eased restrictions on, all states? UI programs. The CARES Act created three temporary unemployment compensation entitlement programs that are federally funded:? The Pandemic Unemployment Assistance (PUA) program provided assistance for individuals not eligible for regular UI, which includes self-employed individuals; gig workers, who are independent contractors who work temporary jobs, typically in the service sector; and other independent contractors. These benefit payments were available specifically for individuals who lost employment due to the COVID-19 pandemic.? The Pandemic Emergency Unemployment Compensation Program (PEUC) provided an additional 13 weeks of UI benefits for unemployed workers who have exhausted regular UI benefits.? Federal Pandemic Unemployment Compensation provided an additional $600 weekly to all unemployed workers receiving regular UI, PUA, or PEUC benefits.Also in March 2020, the Governor declared a state of emergency relating to COVID-19 and issued Executive Order 2020-12 (Executive Order) to expedite UI benefits claim processing and payment distributions. To accomplish the directive, the Executive Order suspended various statutory provisions, including the requirement for the Department to wait a specified number of days before paying a claim, which was part of the adjudication process.The Department is responsible for reviewing, or adjudicating, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wages reported by the claimant, other than the new PUA claims, are compared to employer reported wages submitted to the Department on a quarterly basis, and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In order to adjudicate PUA claims, the Department is required to review the self-employment income reported by the claimant. In addition, the Department performs additional procedures, such as requesting information from the claimant and claimant?s last employer, to identify potential issues with a claimant?s ability and availability to work, and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. Prior to the Executive Order going into effect, the Department adjudicated claims prior to payment, which the Department indicated was generally a 4- to 6-week process.The Department is responsible for identifying overpayments to allow the Department to take appropriate follow-up action. The Department has established procedures to assist with the identification of overpayments, including cross-matching of earnings and incarceration information. The Department is required to use the federal Treasury Offset Program (TOP) to recover debts that remain uncollected after one year of the establishment of the overpayment. These debts include benefit overpayments due to fraud and overpayments due to a claimant?s failure to report earnings.Because of the COVID-19 pandemic, during Fiscal Year 2020, the Department paid more than 15 times the annual benefits for unemployed individuals as in a typical year. During the fiscal year ended June 30, 2020, the Department expended approximately $2.9 billion of federal funds for this program and an additional $1.5 billion was paid from the regular UI program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements for the UI program during Fiscal Year 2020. These federal requirements consisted of eligibility and allowable costs for the UI program and special provision requirements for overpayments of UI benefits.As part of our testing procedures, we interviewed Department staff to gain an understanding of the Department?s internal controls over the processing of UI payments, and the impacts on UI as a result of the pandemic. We requested the listings of UI claims that had not been adjudicated as of June 30, 2020, and PUA overpayments that were identified in October 2020 but related to UI claims paid between March and June 2020, and the related support. In addition, we requested the detail of UI benefit payments that were processed by the Department from March to June 2020, the period during Fiscal Year 2020 in which additional UI payments were issued as a result of the COVID-19 pandemic. We received the detail of benefit payments for this time period in three different populations: standard UI payments, payments that could not be processed through CUBS?referred to as manual payments, and PUA payments.We also interviewed Department staff to gain an understanding of the Department?s internal controls over the establishment of overpayments and to determine whether they were using the TOP as required by federal regulations. In addition, we selected a sample of 60 overpayments that were identified by the Department during the fiscal year ended June 30, 2020, to ensure that the Department was properly identifying and handling overpayments in accordance with its procedures.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?The Department was not able to provide documentation for several areas of the UI program and we were unable to perform testing to determine the Department?s compliance for eligibility, allowable costs, and special provision requirements for overpayments of UI benefits. Specifically:? BACKLOG OF UI ADJUDICATION ISSUES. The Department could not provide a listing of the claims, either regular UI or PUA, that had not been adjudicated as of June 30, 2020. Therefore, we could not perform testing to determine if the individuals were eligible to receive benefits, received the appropriate amount of benefits, or needed to repay a portion of their benefits to the Department. In February 2021, the Department stated that it had not adjudicated, and still needed to review, approximately 206,000 standard UI issues, representing about 82,000 unique claimants, for payments that were processed prior to June 30, 2020, in order to determine whether the related claim was valid. However, the Department could not provide this listing of standard UI issues or a listing of the claimants that had gone through adjudication between July 2020 and February 2021. Furthermore, the Department could not provide the number of claims that still needed to be adjudicated for the PUA program.The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 23-20 in May 2020, to provide states with guidance regarding required program integrity functions for the UI programs under the CARES Act. The letter specifies that ?states must continue to operate their programs, both new and existing, in conformity and compliance with federal laws and guidance.?This issue was addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021.? PUA OVERPAYMENTS. The Department did not provide support for PUA overpayments that were identified by the Department in October 2020; therefore, we could not identify which claimants were associated with the overpayments or whether the overpayments were correctly calculated. According to the Department, it made an estimated $52.1 million in PUA overpayments to 11,445 claimants, or 13 percent of PUA claimants, during Fiscal Year 2020. Subsequent to fiscal year end, in October 2020, the Department determined it would not require the claimants to repay the funds due to confusion in the form requesting wage information from PUA claimants and therefore, removed this amount of overpayments from the PUA system. Because the payments resulted in an estimated $52.1 million in overpayments, we considered this amount to be questioned costs.We also identified the following problem during our testing:? PUA FRAUDULENT PAYMENTS. We identified approximately $243,000 in PUA fraudulent payments that the Department determined were the result of identity theft. Through our review of the benefit payment population, we identified an invalid social security number that appeared 151times. When we discussed these with Department staff, they stated that once they identified the fraudulent payment due to identity theft, they assigned an invalid social security number to identify these payments for tracking purposes. Because these payments of $243,000 were identified as fraudulent, we considered this amount to be questioned costs.The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 16-20 Change 1 in April 2020 to address questions and provide further guidance about the PUA program. An overpayment must be established for any benefits that were overpaid.Both of these issues were addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021.Furthermore, the Department inappropriately suspended certain procedures during the COVID-19 pandemic. Specifically:? SUSPENSION OF WAGE CROSSMATCH. The Department suspended the crossmatch process after March 31, 2020, for regular UI claims. Our testing of 60 overpayments noted that the Department identified 23 overpayments (38 percent) by performing the wage crossmatch prior to the suspension of the process.Section 20 CFR 603.23 specifies that the Department, as a state unemployment compensation agency, ?must crossmatch quarterly wage information with [Unemployment Compensation] payment information to the extent that such information is likely, as determined by the Secretary of Labor, to be productive in identifying ineligibility for benefits and preventing or discovering incorrect payments.?As part of the Department?s adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In addition, the Department reviews to identify potential issues with a claimant?s ability and availability to work and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate.? SUSPENSION OF TREASURY OFFSET PROGRAM. The Department did not use the TOP in June 2020.The Bipartisan Budget Act of 2013 requires states to use the TOP to recover covered unemployment compensation debts that remain uncollected one year after the debt was determined to be due.? LACK OF PRISON MATCH PROCEDURES OVER PUA CLAIMS. The Department did not use the Appriss system to crossmatch PUA claims to prison records prior to June 30, 2020. Per discussion with Department staff, this crossmatch began in January 2021 and, at the time of our audit, the Department had not performed this match procedure for payments issued prior to January 2021.The Division of Unemployment Insurance?s Regulations Concerning Unemployment Security [7 CCR 1101-2, Section 2.8.3.6] states that a ?claimant who is incarcerated and unable to accept employment under a work-release program is not available for work.? As the claimant would not be available for work, the claimant would not be entitled to benefits. The Department has documented incarceration procedures to identify and handle issues when a claimant is identified as being incarcerated while receiving UI benefits. Appriss is a system that is used by the Department to perform this cross-check with prison records. In addition, the U.S. Department of Labor strongly recommends an incarceration crossmatch as one of the activities a state should use as part of its integrity functions.WHY DID THESE PROBLEMS OCCUR?The Department lacked a business plan and internal controls to handle the significant increase in UI claims as a result of the COVID-19 pandemic, which contributed to the issues we identified, as follows:? LACK OF DISASTER PLAN. The Department did not have a plan in place to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. The Executive Order enacted in March 2020 directed the Department to expedite UI benefits claim processing and distribution of payments. Since the Department did not have a plan in place for addressing the significant increase in demand for benefits, it did not adjudicate all claims during the last 3 months of Fiscal Year 2020 during the start of the COVID-19 pandemic. This led to the backlog we noted.? LACK OF REPORTING. The Department did not have reports available regarding key areas of the UI programs, including listings of unadjudicated claims and overpayments, including PUA, by claimant as of any point in time. We also found inconsistencies in the data provided for the claimants and benefits paid during the fiscal year. For example, the detail of overpayments established during Fiscal Year 2020 did not provide information to identify the claimant associated with the overpayment; therefore, we could not compare these overpayments to the claimants that received payments during March to June 2020. In addition, as previously noted, we received the benefits paid data for the period March to June 2020 in three different populations. The information provided from these different populations did not contain the same elements; therefore, we could not perform procedures across all three populations.? FRAUDULENT PAYMENTS. Prior to June 2020, the Department did not have analytical procedures that used fraud indicators to assist with analyzing claims for the identification of potential fraudulent payments. The Department reported it began to experience an increase in suspected fraudulent payments in June 2020; at that point, the Department stated that it began developing data analytical tools to identify claims not yet paid for the presence of unique fraud indicators. Using these data analytical tools, around June 17, 2020, the Program Integrity Division established a process to place holds on claims relating to fraud (Program Integrity Hold). If a payment had fraud indicators identified, a Program Integrity Hold was established on the claim until the claimant information could be reviewed. As of June 30, 2020, there were eight fraud indicators in effect on COVID-19 pandemic claims. Per discussions with Department staff, the number of fraud indicators had increased to about 50 fraud indicators by February 2021.? DISCONTINUED WAGE CROSSMATCHES AND USE OF TOP. The Department reported that it stopped performing crossmatches due to the delayed implementation of the new unemployment system that replaced CUBS. In addition, the Department reported that TOP was not used due to the Department not using another state agency that had been collecting those payments on behalf of the Department.? ISSUES WITH NEW PUA SYSTEM. A fourth UI system, the PUA system, was implemented during April 2020 to handle these claims. This system was not integrated with Appriss to perform the crossmatch with prison records.WHY DO THESE PROBLEMS MATTER?Without the appropriate controls in place, the Department cannot ensure that only eligible claimants are receiving benefits in a timely manner. The significant backlog of adjudication issues did not permit us, nor was it practical to extend or apply other auditing procedures, to obtain sufficient, appropriate audit evidence to conclude whether the Department was in compliance with federal requirements for eligibility, allowable costs, and special provisions relating to overpayments. In addition, delayed adjudication can cause difficulties in obtaining evidence to make eligibility decisions and can result in potential improper payments. A significant backlog can also affect a claimant?s past, present, or future eligibility for benefits. Furthermore, suspending the quarterly wage crossmatch and not using TOP resulted in the Department not being in compliance with federal requirements relating to special tests and provisions for overpayments. The Department?s failure to ensure compliance with federal requirements for the UI program could result in disallowed costs and federal sanctions.FEDERAL AGENCY DEPARTMENT OF LABORFEDERAL AWARD NUMBERS UI-32693-19*UI-34154-20*FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 17.225, UNEMPLOYMENT INSURANCECOVID-19 FUNDING YESCOMPLIANCE REQUIREMENTS ALLOWABLE COSTS (B)ELIGIBILITY (E)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $52,306,535KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $52,306,535THIS FINDING DOES NOT APPLY TO A PRIOR YEAR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-066The Department of Labor and Employment should improve its internal controls over the Unemployment Insurance (UI) program and ensure it complies with the related federal and state requirements by:A Developing a disaster plan to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic.B Identifying the necessary reporting for the UI program and ensuring consistent reporting.C Continuing to use the data analytical tools to identify possible fraud that requires a Program Integrity Hold and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.D Resuming the quarterly wage crossmatch for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.E Resuming the Treasury Offset Program to recover allowable UI debt for all state and federal programs.F Performing crossmatch against prison records for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.RESPONSEDEPARTMENT OF LABOR AND EMPLOYMENTA AGREE. IMPLEMENTATION DATE: JUNE 2023.The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable. Implementation Date: June 2023B AGREE. IMPLEMENTATION DATE: JUNE 2023.The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments. Implementation Date: June 2023C AGREE. IMPLEMENTATION DATE: JANUARY 2021.The Unemployment Insurance Division agrees. The creation of Pandemic Unemployment Assistance (PUA) for individuals traditionally not eligible for the receipt of regular state unemployment benefits created an opportunity for fraudulent claims filed as the result of identity theft. The Division recognized PUA claim filing data inconsistent with general economic conditions in June, 2020 related to claims being filed with stolen identities. The Division created automated fraud holds for claims filed within the PUA system exhibiting suspicious characteristics but did not have that same capability in the legacy system for regular unemployment claims. Data analytics were used to improve the fraud holds in the PUA system and were used to review claims activity in the legacy system where minimal identity theft activity was discovered and claims were manually shut down. In December 2020 increased suspicious activity began occurring in the state legacy system, resulting in a decision to implement MyUI+ on January 10, 2021 for all UI programs in order to apply the same fraud holds to all claims filed. Over 150,000 holds were placed on suspicious state UI claims that came from the legacy system immediately after the new system went live. As of this date, data analysis occurs multiple times per week and will continue in the future as this more sophisticated type of fraud is not expected to stop once the pandemic ends. Implementation Date: January 2021D AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs. Implementation Date: December 2021E AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Unemployment Insurance Division agrees and is currently on a corrective action plan with USDOL related to its failure to continue use of the federal Treasury Offset Program (TOP) program and has until December 2021 to resolve this failure. The Division ceased using TOP in 2018 when it severed a relationship with another state agency, which had been collecting those intercepts on behalf of the Division. That relationship ended due to ongoing concerns about record keeping by that state agency and whether such intercepts were properly collected in cases where claimants were making payments towards debt owed. The intent had been for the Division to implement TOP with the original implementation date for MyUI+ that was ultimately delayed. The Division is working towards implementation of this required program before the 2021 tax season begins and anticipates its integration into MyUI+ at that time. Implementation Date: December 2021F AGREE. IMPLEMENTATION DATE: JANUARY 2021.The Unemployment Insurance Division understands and agrees that prison record crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The prison record crossmatch was continually run in the legacy system and all federal requirements were followed in for standard UI claims. This crossmatch did not initially occur in the PUA system due to the urgency to stand up the federal PUA program quickly at the beginning of the pandemic, a separate system was stood up outside the current legacy system and programming time was reduced by not including many interfaces and cross matches, including the prison cross match. However, once all UI programs were integrated with the implementation of MyUI+ into production on January 10, 2021, this crossmatch ran against all claims filed within that system, including claims initially filed in the original stand alone PUA system. As such, this crossmatch began in January, 2021 including all PUA claims that had been previously filed. All federal requirements associated with prison record crossmatch are currently being followed for all UI programs. Implementation Date: January 2021.
Show full finding ▾Hide full finding ▴UNEMPLOYMENT INSURANCEThe Unemployment Insurance (UI) program, created by the Social Security Act, provides benefits to unemployed workers for periods of involuntary unemployment and helps stabilize the economy by maintaining the spending power of workers while they are between jobs. The U.S. Department of Labor provides grant funding for each state to design and administer its own UI program within federal requirements. The Department?s Division of Unemployment Insurance is responsible for the administration and monitoring of Colorado's UI programs, including the establishment of policies and operating procedures which comply with federal requirements; determining claimant eligibility and making payment of UI benefits to claimants; and administering the programs in accordance with established policies and procedures. The regular UI program provides coverage to most salary and wage workers and is funded primarily by state UI taxes assessed on covered employers. These taxes are required to be deposited into the State?s Unemployment Trust Fund for the purpose of making UI payments under the federally approved state unemployment law. As part of the administration of this program, the Department uses the Colorado Unemployment Benefits System (CUBS) to aid in determining eligibility for UI benefits.On March 13, 2020, the President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, and Congress subsequently passed the Emergency Unemployment Insurance Stabilization and Access Act of 2020 (EUISAA) and the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). Both EUISAA and the CARES Act included additional federal funding for, and eased restrictions on, all states? UI programs. The CARES Act created three temporary unemployment compensation entitlement programs that are federally funded:? The Pandemic Unemployment Assistance (PUA) program provided assistance for individuals not eligible for regular UI, which includes self-employed individuals; gig workers, who are independent contractors who work temporary jobs, typically in the service sector; and other independent contractors. These benefit payments were available specifically for individuals who lost employment due to the COVID-19 pandemic.? The Pandemic Emergency Unemployment Compensation Program (PEUC) provided an additional 13 weeks of UI benefits for unemployed workers who have exhausted regular UI benefits.? Federal Pandemic Unemployment Compensation provided an additional $600 weekly to all unemployed workers receiving regular UI, PUA, or PEUC benefits.Also in March 2020, the Governor declared a state of emergency relating to COVID-19 and issued Executive Order 2020-12 (Executive Order) to expedite UI benefits claim processing and payment distributions. To accomplish the directive, the Executive Order suspended various statutory provisions, including the requirement for the Department to wait a specified number of days before paying a claim, which was part of the adjudication process.The Department is responsible for reviewing, or adjudicating, claims to ensure that claimants are eligible and entitled to receive UI benefits. As part of the adjudication process, wages reported by the claimant, other than the new PUA claims, are compared to employer reported wages submitted to the Department on a quarterly basis, and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In order to adjudicate PUA claims, the Department is required to review the self-employment income reported by the claimant. In addition, the Department performs additional procedures, such as requesting information from the claimant and claimant?s last employer, to identify potential issues with a claimant?s ability and availability to work, and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate. Prior to the Executive Order going into effect, the Department adjudicated claims prior to payment, which the Department indicated was generally a 4- to 6-week process.The Department is responsible for identifying overpayments to allow the Department to take appropriate follow-up action. The Department has established procedures to assist with the identification of overpayments, including cross-matching of earnings and incarceration information. The Department is required to use the federal Treasury Offset Program (TOP) to recover debts that remain uncollected after one year of the establishment of the overpayment. These debts include benefit overpayments due to fraud and overpayments due to a claimant?s failure to report earnings.Because of the COVID-19 pandemic, during Fiscal Year 2020, the Department paid more than 15 times the annual benefits for unemployed individuals as in a typical year. During the fiscal year ended June 30, 2020, the Department expended approximately $2.9 billion of federal funds for this program and an additional $1.5 billion was paid from the regular UI program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal requirements for the UI program during Fiscal Year 2020. These federal requirements consisted of eligibility and allowable costs for the UI program and special provision requirements for overpayments of UI benefits.As part of our testing procedures, we interviewed Department staff to gain an understanding of the Department?s internal controls over the processing of UI payments, and the impacts on UI as a result of the pandemic. We requested the listings of UI claims that had not been adjudicated as of June 30, 2020, and PUA overpayments that were identified in October 2020 but related to UI claims paid between March and June 2020, and the related support. In addition, we requested the detail of UI benefit payments that were processed by the Department from March to June 2020, the period during Fiscal Year 2020 in which additional UI payments were issued as a result of the COVID-19 pandemic. We received the detail of benefit payments for this time period in three different populations: standard UI payments, payments that could not be processed through CUBS?referred to as manual payments, and PUA payments.We also interviewed Department staff to gain an understanding of the Department?s internal controls over the establishment of overpayments and to determine whether they were using the TOP as required by federal regulations. In addition, we selected a sample of 60 overpayments that were identified by the Department during the fiscal year ended June 30, 2020, to ensure that the Department was properly identifying and handling overpayments in accordance with its procedures.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?The Department was not able to provide documentation for several areas of the UI program and we were unable to perform testing to determine the Department?s compliance for eligibility, allowable costs, and special provision requirements for overpayments of UI benefits. Specifically:? BACKLOG OF UI ADJUDICATION ISSUES. The Department could not provide a listing of the claims, either regular UI or PUA, that had not been adjudicated as of June 30, 2020. Therefore, we could not perform testing to determine if the individuals were eligible to receive benefits, received the appropriate amount of benefits, or needed to repay a portion of their benefits to the Department. In February 2021, the Department stated that it had not adjudicated, and still needed to review, approximately 206,000 standard UI issues, representing about 82,000 unique claimants, for payments that were processed prior to June 30, 2020, in order to determine whether the related claim was valid. However, the Department could not provide this listing of standard UI issues or a listing of the claimants that had gone through adjudication between July 2020 and February 2021. Furthermore, the Department could not provide the number of claims that still needed to be adjudicated for the PUA program.The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 23-20 in May 2020, to provide states with guidance regarding required program integrity functions for the UI programs under the CARES Act. The letter specifies that ?states must continue to operate their programs, both new and existing, in conformity and compliance with federal laws and guidance.?This issue was addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021.? PUA OVERPAYMENTS. The Department did not provide support for PUA overpayments that were identified by the Department in October 2020; therefore, we could not identify which claimants were associated with the overpayments or whether the overpayments were correctly calculated. According to the Department, it made an estimated $52.1 million in PUA overpayments to 11,445 claimants, or 13 percent of PUA claimants, during Fiscal Year 2020. Subsequent to fiscal year end, in October 2020, the Department determined it would not require the claimants to repay the funds due to confusion in the form requesting wage information from PUA claimants and therefore, removed this amount of overpayments from the PUA system. Because the payments resulted in an estimated $52.1 million in overpayments, we considered this amount to be questioned costs.We also identified the following problem during our testing:? PUA FRAUDULENT PAYMENTS. We identified approximately $243,000 in PUA fraudulent payments that the Department determined were the result of identity theft. Through our review of the benefit payment population, we identified an invalid social security number that appeared 151times. When we discussed these with Department staff, they stated that once they identified the fraudulent payment due to identity theft, they assigned an invalid social security number to identify these payments for tracking purposes. Because these payments of $243,000 were identified as fraudulent, we considered this amount to be questioned costs.The U.S. Department of Labor issued Unemployment Insurance Program Letter No. 16-20 Change 1 in April 2020 to address questions and provide further guidance about the PUA program. An overpayment must be established for any benefits that were overpaid.Both of these issues were addressed in the Department of Labor and Employment chapter of our STATEWIDE FINANCIAL AUDIT REPORT, RECOMMENDATION NO. 2020-023, released in March 2021.Furthermore, the Department inappropriately suspended certain procedures during the COVID-19 pandemic. Specifically:? SUSPENSION OF WAGE CROSSMATCH. The Department suspended the crossmatch process after March 31, 2020, for regular UI claims. Our testing of 60 overpayments noted that the Department identified 23 overpayments (38 percent) by performing the wage crossmatch prior to the suspension of the process.Section 20 CFR 603.23 specifies that the Department, as a state unemployment compensation agency, ?must crossmatch quarterly wage information with [Unemployment Compensation] payment information to the extent that such information is likely, as determined by the Secretary of Labor, to be productive in identifying ineligibility for benefits and preventing or discovering incorrect payments.?As part of the Department?s adjudication process, wage checks for claimants are compared to employer reported wages submitted to the Department on a quarterly basis and the Department sends a notification to the last employer to determine the validity and reason for the claimant leaving the workplace. In addition, the Department reviews to identify potential issues with a claimant?s ability and availability to work and to ensure that the claimant is actively looking for work. If information provided by an interested party relating to the reason for leaving the workforce does not agree to the claimant information, the Department follows up on the information and issues eligibility determinations, as appropriate.? SUSPENSION OF TREASURY OFFSET PROGRAM. The Department did not use the TOP in June 2020.The Bipartisan Budget Act of 2013 requires states to use the TOP to recover covered unemployment compensation debts that remain uncollected one year after the debt was determined to be due.? LACK OF PRISON MATCH PROCEDURES OVER PUA CLAIMS. The Department did not use the Appriss system to crossmatch PUA claims to prison records prior to June 30, 2020. Per discussion with Department staff, this crossmatch began in January 2021 and, at the time of our audit, the Department had not performed this match procedure for payments issued prior to January 2021.The Division of Unemployment Insurance?s Regulations Concerning Unemployment Security [7 CCR 1101-2, Section 2.8.3.6] states that a ?claimant who is incarcerated and unable to accept employment under a work-release program is not available for work.? As the claimant would not be available for work, the claimant would not be entitled to benefits. The Department has documented incarceration procedures to identify and handle issues when a claimant is identified as being incarcerated while receiving UI benefits. Appriss is a system that is used by the Department to perform this cross-check with prison records. In addition, the U.S. Department of Labor strongly recommends an incarceration crossmatch as one of the activities a state should use as part of its integrity functions.WHY DID THESE PROBLEMS OCCUR?The Department lacked a business plan and internal controls to handle the significant increase in UI claims as a result of the COVID-19 pandemic, which contributed to the issues we identified, as follows:? LACK OF DISASTER PLAN. The Department did not have a plan in place to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic. The Executive Order enacted in March 2020 directed the Department to expedite UI benefits claim processing and distribution of payments. Since the Department did not have a plan in place for addressing the significant increase in demand for benefits, it did not adjudicate all claims during the last 3 months of Fiscal Year 2020 during the start of the COVID-19 pandemic. This led to the backlog we noted.? LACK OF REPORTING. The Department did not have reports available regarding key areas of the UI programs, including listings of unadjudicated claims and overpayments, including PUA, by claimant as of any point in time. We also found inconsistencies in the data provided for the claimants and benefits paid during the fiscal year. For example, the detail of overpayments established during Fiscal Year 2020 did not provide information to identify the claimant associated with the overpayment; therefore, we could not compare these overpayments to the claimants that received payments during March to June 2020. In addition, as previously noted, we received the benefits paid data for the period March to June 2020 in three different populations. The information provided from these different populations did not contain the same elements; therefore, we could not perform procedures across all three populations.? FRAUDULENT PAYMENTS. Prior to June 2020, the Department did not have analytical procedures that used fraud indicators to assist with analyzing claims for the identification of potential fraudulent payments. The Department reported it began to experience an increase in suspected fraudulent payments in June 2020; at that point, the Department stated that it began developing data analytical tools to identify claims not yet paid for the presence of unique fraud indicators. Using these data analytical tools, around June 17, 2020, the Program Integrity Division established a process to place holds on claims relating to fraud (Program Integrity Hold). If a payment had fraud indicators identified, a Program Integrity Hold was established on the claim until the claimant information could be reviewed. As of June 30, 2020, there were eight fraud indicators in effect on COVID-19 pandemic claims. Per discussions with Department staff, the number of fraud indicators had increased to about 50 fraud indicators by February 2021.? DISCONTINUED WAGE CROSSMATCHES AND USE OF TOP. The Department reported that it stopped performing crossmatches due to the delayed implementation of the new unemployment system that replaced CUBS. In addition, the Department reported that TOP was not used due to the Department not using another state agency that had been collecting those payments on behalf of the Department.? ISSUES WITH NEW PUA SYSTEM. A fourth UI system, the PUA system, was implemented during April 2020 to handle these claims. This system was not integrated with Appriss to perform the crossmatch with prison records.WHY DO THESE PROBLEMS MATTER?Without the appropriate controls in place, the Department cannot ensure that only eligible claimants are receiving benefits in a timely manner. The significant backlog of adjudication issues did not permit us, nor was it practical to extend or apply other auditing procedures, to obtain sufficient, appropriate audit evidence to conclude whether the Department was in compliance with federal requirements for eligibility, allowable costs, and special provisions relating to overpayments. In addition, delayed adjudication can cause difficulties in obtaining evidence to make eligibility decisions and can result in potential improper payments. A significant backlog can also affect a claimant?s past, present, or future eligibility for benefits. Furthermore, suspending the quarterly wage crossmatch and not using TOP resulted in the Department not being in compliance with federal requirements relating to special tests and provisions for overpayments. The Department?s failure to ensure compliance with federal requirements for the UI program could result in disallowed costs and federal sanctions.FEDERAL AGENCY DEPARTMENT OF LABORFEDERAL AWARD NUMBERS UI-32693-19*UI-34154-20*FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 17.225, UNEMPLOYMENT INSURANCECOVID-19 FUNDING YESCOMPLIANCE REQUIREMENTS ALLOWABLE COSTS (B)ELIGIBILITY (E)SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $52,306,535KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $52,306,535THIS FINDING DOES NOT APPLY TO A PRIOR YEAR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-066The Department of Labor and Employment should improve its internal controls over the Unemployment Insurance (UI) program and ensure it complies with the related federal and state requirements by:A Developing a disaster plan to address the adjudication of claims in the event of a significant increase in demand resulting from a disaster, such as the COVID-19 pandemic.B Identifying the necessary reporting for the UI program and ensuring consistent reporting.C Continuing to use the data analytical tools to identify possible fraud that requires a Program Integrity Hold and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.D Resuming the quarterly wage crossmatch for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.E Resuming the Treasury Offset Program to recover allowable UI debt for all state and federal programs.F Performing crossmatch against prison records for all UI claims and, for any benefits that were paid in error and/or fraud, identifying overpayments and seeking recovery from the claimants.RESPONSEDEPARTMENT OF LABOR AND EMPLOYMENTA AGREE. IMPLEMENTATION DATE: JUNE 2023.The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable. Implementation Date: June 2023B AGREE. IMPLEMENTATION DATE: JUNE 2023.The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments. Implementation Date: June 2023C AGREE. IMPLEMENTATION DATE: JANUARY 2021.The Unemployment Insurance Division agrees. The creation of Pandemic Unemployment Assistance (PUA) for individuals traditionally not eligible for the receipt of regular state unemployment benefits created an opportunity for fraudulent claims filed as the result of identity theft. The Division recognized PUA claim filing data inconsistent with general economic conditions in June, 2020 related to claims being filed with stolen identities. The Division created automated fraud holds for claims filed within the PUA system exhibiting suspicious characteristics but did not have that same capability in the legacy system for regular unemployment claims. Data analytics were used to improve the fraud holds in the PUA system and were used to review claims activity in the legacy system where minimal identity theft activity was discovered and claims were manually shut down. In December 2020 increased suspicious activity began occurring in the state legacy system, resulting in a decision to implement MyUI+ on January 10, 2021 for all UI programs in order to apply the same fraud holds to all claims filed. Over 150,000 holds were placed on suspicious state UI claims that came from the legacy system immediately after the new system went live. As of this date, data analysis occurs multiple times per week and will continue in the future as this more sophisticated type of fraud is not expected to stop once the pandemic ends. Implementation Date: January 2021D AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs. Implementation Date: December 2021E AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Unemployment Insurance Division agrees and is currently on a corrective action plan with USDOL related to its failure to continue use of the federal Treasury Offset Program (TOP) program and has until December 2021 to resolve this failure. The Division ceased using TOP in 2018 when it severed a relationship with another state agency, which had been collecting those intercepts on behalf of the Division. That relationship ended due to ongoing concerns about record keeping by that state agency and whether such intercepts were properly collected in cases where claimants were making payments towards debt owed. The intent had been for the Division to implement TOP with the original implementation date for MyUI+ that was ultimately delayed. The Division is working towards implementation of this required program before the 2021 tax season begins and anticipates its integration into MyUI+ at that time. Implementation Date: December 2021F AGREE. IMPLEMENTATION DATE: JANUARY 2021.The Unemployment Insurance Division understands and agrees that prison record crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The prison record crossmatch was continually run in the legacy system and all federal requirements were followed in for standard UI claims. This crossmatch did not initially occur in the PUA system due to the urgency to stand up the federal PUA program quickly at the beginning of the pandemic, a separate system was stood up outside the current legacy system and programming time was reduced by not including many interfaces and cross matches, including the prison cross match. However, once all UI programs were integrated with the implementation of MyUI+ into production on January 10, 2021, this crossmatch ran against all claims filed within that system, including claims initially filed in the original stand alone PUA system. As such, this crossmatch began in January, 2021 including all PUA claims that had been previously filed. All federal requirements associated with prison record crossmatch are currently being followed for all UI programs. Implementation Date: January 2021.
(A) The Unemployment Insurance Division agrees. The dramatic increase in claims load resulted from the unprecedented disaster of the Coronavirus COVID-19 Pandemic. Immediate claim load increased over 1,100% just for ?regular? state unemployment claims and increased in a similar manner for all 53 jurisdictions administering unemployment programs throughout the United States. Compounding this was the creation of a new large-scale unemployment program designed for individuals traditionally considered ineligible for the receipt of unemployment benefits in the form of Pandemic Unemployment Assistance (PUA). Based on the disaster data from the Great Recession, and Hurricane Katrina, it was readily apparent that claim load growth would be too large to follow normal claim processing procedures and provide funds available to help stabilize the local economy, resulting in Executive Order 2020-012. Within the first weeks of the pandemic, the UI Division determined that future review of data trends would also need to include the potential for the impact from a major national disaster. Such planning will be ongoing in nature and be adjusted based on ongoing lessons learned from the pandemic and will include development of processes that need to be repeatable and readily scalable.(B) The Unemployment Insurance Division agrees and is working with Deloitte, the Division?s vendor for the MyUI+ Benefits system, to ensure the development of appropriate UI Program reports. The UI Division and Finance team meet weekly to review and refine the data requests and submit these requests to the vendor to produce reports that will capture claims adjudicated, payments, overpayments and fraud for all state and federal UI programs in FY2021 at the claimant level. In addition, having moved to a modernized benefits system, the UI Division now has a single source of record for all claims data. Finally, with measures taken over the past year to address fraudulent activity in the UI Program, CDLE will be better prepared to report data on fraud and overpayments. Moving forward, once the Executive Order expires, UI will resume standard federal program standards of determining monetary and nonmonetary eligibility prior to provision of benefits. This will allow for more accurate UI Program reports in the long term, reducing estimations and overpayments.(C) The Unemployment Insurance Division agrees. The creation of Pandemic Unemployment Assistance (PUA) for individuals traditionally not eligible for the receipt of regular state unemployment benefits created an opportunity for fraudulent claims filed as the result of identity theft. The Division recognized PUA claim filing data inconsistent with general economic conditions in June 2020 related to claims being filed with stolen identities. The Division created automated fraud holds for claims filed within the PUA system exhibiting suspicious characteristics but did not have that same capability in the legacy system for regular unemploymentclaims. Data analytics were used to improve the fraud holds in the PUA system and were used to review claims activity in the legacy system where minimal identity theft activity was discovered and claims were manually shut down. In December 2020 increased suspicious activity began occurring in the state legacy system, resulting in a decision to implement MyUI+ on January 10, 2021 for all UI programs in order to apply the same fraud holds to all claims filed. Over 150,000 holds were placed on suspicious state UI claims that came from the legacy system immediately after the new system went live. As of this date, data analysis occurs multiple times per week and will continue in the future as this more sophisticated type of fraud is not expected to stop once the pandemic ends.(D) The Unemployment Insurance Division understands and agrees that quarterly wage crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The Division currently is awaiting programming to be released into production on June 9, 2021 in order to resume these crossmatch activities and will run its first cross match for first quarter 2021. The failure to perform cross match activities after March 31, 2020, was not a result of the pandemic volume but was an unfortunate circumstance related to delayed implementation of the Division's original planned launch date for MyUI+ in 2020. The original scheduled go live was scheduled for Spring 2020 but was not able to be implemented until January 10, 2021 due to the need to stand up new federal pandemic programs.(E) The Unemployment Insurance Division agrees and is currently on a corrective action plan with USDOL related to its failure to continue use of the federal Treasury Offset Program (TOP) program and has until December 2021 to resolve this failure. The Division ceased using TOP in 2018 when it severed a relationship with another state agency, which had been collecting those intercepts on behalf of the Division. That relationship ended due to ongoing concerns about record keeping by that state agency and whether such intercepts were properly collected in cases where claimants were making payments towards debt owed. The intent had been for the Division to implement TOP with the original implementation date for MyUI+ that was ultimately delayed. The Division is working towards implementation of this required program before the 2021 tax season begins and anticipates its integration into MyUI+ at that time.(F) The Unemployment Insurance Division understands and agrees that prison record crossmatch is a requirement for the program and plays a vital role in ensuring program integrity. The prison record crossmatch was continually run in the legacy system and all federal requirements were followed in for standard UI claims. This crossmatch did not initially occur in the PUA system due to the urgency to stand up the federal PUA program quickly at the beginning of the pandemic, a separate system was stood up outside the current legacy system and programming time was reduced by not including many interfaces and cross matches, including the prison cross match. However, once all UI programs were integrated with the implementation of MyUI+ into production on January 10, 2021, this crossmatch ran against all claims filed within that system, including claims initially filed in the original stand alone PUA system. As such, this crossmatch began in January, 2021 including all PUA claims that had been previously filed. All federal requirements associated with prison record crossmatch are currently being followed for all UI programs.
VOCATIONAL REHABILITATION ALLOWABLE COSTSThe U.S. Department of Education created the Rehabilitation Services Vocational Rehabilitation Grants to States program for the operation of vocational rehabilitation programs, assisting people with disabilities to succeed at work and live independently. In Colorado, the Department?s Division of Vocational Rehabilitation is responsible for administering the Vocational Rehabilitation Program (Program).The Department is responsible for ensuring that Program expenditures are allowable. The most common Program expenditures include personnel costs and related fringe benefits, supplies, utilities, and other costs. During Fiscal Year 2020, the Department expended approximately $42.7 million of federal funds for this program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the Program during Fiscal Year 2020. We tested 40 payroll transactions totaling approximately $144,000 that were charged to the Program during Fiscal Year 2020, out of a total population of $15.9 million in salaries and benefits, to determine whether the costs were necessary and reasonable for administering the Program, and whether they complied with federal regulations and Department policy.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following criteria:? DEPARTMENT POLICY. Department policy [SPP 1060 Attendance, Leave Tracking and KRONOS Timekeeping Policy] states that ??all KRONOS timesheets require the approval of the employee and the approval of the supervisor/manager at the end of each pay period.? The sign off is evidenced in the audit trail of the KRONOS system. This policy covers all of the Department?s payroll transactions, including those charged to federal grants.? FEDERAL REGULATION [2 CFR 200.430] requires that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award.? FEDERAL REGULATION [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We tested 40 payroll transactions charged to the Program and identified the following issues with nine of the transactions (23 percent):? Three did not contain evidence of approval by either the employee or the supervisor/manager as required by Department policy. These three payroll transactions totaled $10,158. Because the payroll costs were not supported by any approvals, we considered that amount to be questioned costs.? Three did not contain evidence of approval of the employee?s timesheet by the supervisor/manager in accordance with Department policy; these three transactions did contain evidence of the employee?s approval of the timesheet.? Three did not contain evidence of the employee?s approval of the timesheet in accordance with Department policy; these transactions did include evidence of the manager/supervisor?s approval of the timesheet.WHY DID THESE PROBLEMS OCCUR?The Department did not enforce its timekeeping policy regarding approval of employee timesheets.WHY DO THESE PROBLEMS MATTER?The Department?s failure to ensure compliance with federal requirements for the Program could result in disallowed costs and federal sanctions.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBERS 9V1220*9V1269*FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 84.126, REHABILITATION SERVICES VOCATIONAL REHABILITATION GRANTS TO STATESCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $10,158KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR YEAR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-067The Department of Labor and Employment should improve its internal controls over the federal Rehabilitation Services Vocational Rehabilitation Grants to States program by enforcing its timekeeping policies that require employee approval and a supervisor/manager approval of all employee timesheets, in order to ensure that payroll expenditures charged to the program are allowable.RESPONSEDEPARTMENT OF LABOR AND EMPLOYMENTAGREE. IMPLEMENTATION DATE: JUNE 2021.CDLE and the Division of Vocational Rehabilitation are committed to ensuring compliance with federal requirements and enforcing policies regarding approval of employee timesheets (CDLE Standard Policy and Procedure SPP 1060 Attendance, Leave and KRONOS). DVR will hold its employees accountable for reviewing and approving timesheets by adding language to all employee annual Employee Performance plans (EQEP?s = Employee Quality and Excellence Plan). In addition, the CDLE Payroll Unit will provide reports regularly to the Deputy Executive Director/CFO and Division Directors of employees and supervisors who have not signed timesheets. This will help identify missed timesheets in order for them to be immediately addressed. Lastly, key CDLE employees will work with Human Resources and the Payroll Unit to require employees who leave the agency to sign their timesheets before their last day of work.
Show full finding ▾Hide full finding ▴VOCATIONAL REHABILITATION ALLOWABLE COSTSThe U.S. Department of Education created the Rehabilitation Services Vocational Rehabilitation Grants to States program for the operation of vocational rehabilitation programs, assisting people with disabilities to succeed at work and live independently. In Colorado, the Department?s Division of Vocational Rehabilitation is responsible for administering the Vocational Rehabilitation Program (Program).The Department is responsible for ensuring that Program expenditures are allowable. The most common Program expenditures include personnel costs and related fringe benefits, supplies, utilities, and other costs. During Fiscal Year 2020, the Department expended approximately $42.7 million of federal funds for this program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal allowable activities and allowable cost requirements for the Program during Fiscal Year 2020. We tested 40 payroll transactions totaling approximately $144,000 that were charged to the Program during Fiscal Year 2020, out of a total population of $15.9 million in salaries and benefits, to determine whether the costs were necessary and reasonable for administering the Program, and whether they complied with federal regulations and Department policy.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following criteria:? DEPARTMENT POLICY. Department policy [SPP 1060 Attendance, Leave Tracking and KRONOS Timekeeping Policy] states that ??all KRONOS timesheets require the approval of the employee and the approval of the supervisor/manager at the end of each pay period.? The sign off is evidenced in the audit trail of the KRONOS system. This policy covers all of the Department?s payroll transactions, including those charged to federal grants.? FEDERAL REGULATION [2 CFR 200.430] requires that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award.? FEDERAL REGULATION [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We tested 40 payroll transactions charged to the Program and identified the following issues with nine of the transactions (23 percent):? Three did not contain evidence of approval by either the employee or the supervisor/manager as required by Department policy. These three payroll transactions totaled $10,158. Because the payroll costs were not supported by any approvals, we considered that amount to be questioned costs.? Three did not contain evidence of approval of the employee?s timesheet by the supervisor/manager in accordance with Department policy; these three transactions did contain evidence of the employee?s approval of the timesheet.? Three did not contain evidence of the employee?s approval of the timesheet in accordance with Department policy; these transactions did include evidence of the manager/supervisor?s approval of the timesheet.WHY DID THESE PROBLEMS OCCUR?The Department did not enforce its timekeeping policy regarding approval of employee timesheets.WHY DO THESE PROBLEMS MATTER?The Department?s failure to ensure compliance with federal requirements for the Program could result in disallowed costs and federal sanctions.FEDERAL AGENCY DEPARTMENT OF EDUCATIONFEDERAL AWARD NUMBERS 9V1220*9V1269*FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 84.126, REHABILITATION SERVICES VOCATIONAL REHABILITATION GRANTS TO STATESCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $10,158KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR YEAR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS.RECOMMENDATION2020-067The Department of Labor and Employment should improve its internal controls over the federal Rehabilitation Services Vocational Rehabilitation Grants to States program by enforcing its timekeeping policies that require employee approval and a supervisor/manager approval of all employee timesheets, in order to ensure that payroll expenditures charged to the program are allowable.RESPONSEDEPARTMENT OF LABOR AND EMPLOYMENTAGREE. IMPLEMENTATION DATE: JUNE 2021.CDLE and the Division of Vocational Rehabilitation are committed to ensuring compliance with federal requirements and enforcing policies regarding approval of employee timesheets (CDLE Standard Policy and Procedure SPP 1060 Attendance, Leave and KRONOS). DVR will hold its employees accountable for reviewing and approving timesheets by adding language to all employee annual Employee Performance plans (EQEP?s = Employee Quality and Excellence Plan). In addition, the CDLE Payroll Unit will provide reports regularly to the Deputy Executive Director/CFO and Division Directors of employees and supervisors who have not signed timesheets. This will help identify missed timesheets in order for them to be immediately addressed. Lastly, key CDLE employees will work with Human Resources and the Payroll Unit to require employees who leave the agency to sign their timesheets before their last day of work.
CDLE and the Division of Vocational Rehabilitation are committed to ensuring compliance with federal requirements and enforcing policies regarding approval of employee timesheets (CDLE Standard Policy and Procedure SPP 1060 Attendance, Leave and KRONOS). DVR will hold its employees accountable for reviewing and approving timesheets by adding language to all employee annual Employee Performance plans (EQEP?s = Employee Quality and Excellence Plan). In addition, the CDLE Payroll Unit will provide reports regularly to the Deputy Executive Director/CFO and Division Directors of employees and supervisors who have not signed timesheets. This will help identify missed timesheets in order for them to be immediately addressed. Lastly, key CDLE employees will work with Human Resources and the Payroll Unit to require employees who leave the agency to sign their timesheets before their last day of work.
SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS?QUALITY ASSURANCE REVIEWSThe Department contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the U.S. Code of Federal Regulations, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for federal reporting purposes, to determine eligibility for the Housing Voucher Programs. The Department is responsible for supervising and monitoring its subrecipients? eligibility determinations. This responsibility includes ensuring that the subrecipients obtain and maintain documentation to support households? eligibility in the respective tenant files including, but not limited to, applications, birth certificates, social security numbers, photo identification, income verification, and rental assistance payment calculations.As part of the Department?s monitoring of subrecipients to ensure appropriate eligibility determinations, the Department performs quality assurance (QA) reviews of tenant files. Through each QA review, the Department reviews the related file to determine whether all relevant and necessary documentation is present in the tenant file to support the eligibility determination. For Fiscal Year 2020, the Department completed 234 QA reviews of 53 subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal eligibility requirements for the Housing Voucher Programs during Fiscal Year 2020.We reviewed a sample of 28 of the Department?s 234 QA reviews during Fiscal Year 2020 to determine whether the Department found that the tenant files contained proper support for eligibility determinations and demonstrated that the determinations were made in accordance with compliance requirements for the Housing Voucher Programs. For instances in which appropriate support was not maintained in tenant files, we determined whether the Department performed necessary follow-up actions with its subrecipients to address issues identified during the QA reviews.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:Federal regulations [24 CFR 982] list eligibility-related requirements which the Department and its subrecipients must abide by in order to ensure compliance with the Housing Voucher Programs. Specifically, federal regulations [24 CFR 982.54] require the Department, as the State?s primary Public Housing Agency for the Housing Voucher Programs, to adopt an administrative plan which covers topics including selection and admission of applicants, issuing or denying vouchers, and other rules that could affect applicant eligibility. Furthermore, in accordance with these regulations, the Department must maintain support related to its QA reviews of its subrecipients, which provides evidence that subrecipients obtained baseline documentation, verified earned income, and appropriately completed housing assistance payment contracts and lease information, among other criteria, to support the eligibility determination.The Department?s Quality Control and Improvement Plan for the Housing Voucher Programs requires that, after a QA review occurs, ?all actual file deficiencies will be identified as findings for the purposes of QA reviews. Subrecipients will be notified in writing of any findings within 15 days of the completion of the audit. They will have 30 days to correct the findings, or explain why the error(s) cannot be corrected.?Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We determined that the Department identified issues that required corrective action by subrecipients in 26 of the 28 QA reviews we tested (93 percent), but failed to perform follow-up procedures as required on any of the 26 QA reviews. Specifically, in all 26 instances, the Department did not ensure the subrecipients took steps to address the issues within the 30-day timeframe. While the Department notified the subrecipients of the findings within 15 days of the completed QA review in all 26 instances, the Department did not obtain responses from the subrecipients within the following 30 days indicating the findings had been corrected or otherwise confirm that the issues were addressed. The most common errors identified in the QA reviews related to missing or incorrect documentation in tenant files, including completed applications, birth certificates, and rent reasonableness forms.Subsequent to our testwork, the Department requested and obtained documentation from the applicable subrecipients to verify tenants? eligibility in all 26 cases.WHY DID THE PROBLEM OCCUR?The Department lacked sufficient internal controls over its QA review process to ensure eligibility requirements for the Housing Voucher Programs are met by the Department?s subrecipients. According to the Department, in September 2019, its QA review team underwent a substantial restructure which reassigned file audit responsibility to one person rather than multiple staff members; however, the Department failed to update policies and procedures surrounding the restructuring, which led to staff failing to ensure subrecipients corrected the errors identified during the QA reviews.WHY DOES THIS PROBLEM MATTER?By not ensuring that appropriate internal controls are in place over the Housing Voucher Programs eligibility processes, the Department cannot ensure that all tenants are eligible or qualified to participate in the Housing Voucher Programs. The Department must ensure that subrecipients maintain accurate and complete tenant files to demonstrate compliance with federal requirements.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-068The Department of Local Affairs should improve its quality assurance internal controls and ensure it complies with eligibility requirements for the Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include updating quality assurance procedures and aligning these procedures with responsibilities of the restructured team.RESPONSEDEPARTMENT OF LOCAL AFFAIRSAGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Local Affairs will improve its quality assurance internal controls to ensure future compliance with eligibility requirements through a revamped quality assurance process that clearly outlines the roles and responsibilities of internal staff and subrecipients as well as timelines and acceptable documentation required to complete the quality assurance review. Training for internal staff and subrecipients will be provided through a process sheet published on the website as well as presented in the monthly webinar training series. In addition, the Director of the Office of Rental Assistance will publish a ?policies and procedures? manual specifically related to the quality assurance and monitoring program for subrecipients.
Show full finding ▾Hide full finding ▴SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS?QUALITY ASSURANCE REVIEWSThe Department contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the U.S. Code of Federal Regulations, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) for federal reporting purposes, to determine eligibility for the Housing Voucher Programs. The Department is responsible for supervising and monitoring its subrecipients? eligibility determinations. This responsibility includes ensuring that the subrecipients obtain and maintain documentation to support households? eligibility in the respective tenant files including, but not limited to, applications, birth certificates, social security numbers, photo identification, income verification, and rental assistance payment calculations.As part of the Department?s monitoring of subrecipients to ensure appropriate eligibility determinations, the Department performs quality assurance (QA) reviews of tenant files. Through each QA review, the Department reviews the related file to determine whether all relevant and necessary documentation is present in the tenant file to support the eligibility determination. For Fiscal Year 2020, the Department completed 234 QA reviews of 53 subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal eligibility requirements for the Housing Voucher Programs during Fiscal Year 2020.We reviewed a sample of 28 of the Department?s 234 QA reviews during Fiscal Year 2020 to determine whether the Department found that the tenant files contained proper support for eligibility determinations and demonstrated that the determinations were made in accordance with compliance requirements for the Housing Voucher Programs. For instances in which appropriate support was not maintained in tenant files, we determined whether the Department performed necessary follow-up actions with its subrecipients to address issues identified during the QA reviews.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:Federal regulations [24 CFR 982] list eligibility-related requirements which the Department and its subrecipients must abide by in order to ensure compliance with the Housing Voucher Programs. Specifically, federal regulations [24 CFR 982.54] require the Department, as the State?s primary Public Housing Agency for the Housing Voucher Programs, to adopt an administrative plan which covers topics including selection and admission of applicants, issuing or denying vouchers, and other rules that could affect applicant eligibility. Furthermore, in accordance with these regulations, the Department must maintain support related to its QA reviews of its subrecipients, which provides evidence that subrecipients obtained baseline documentation, verified earned income, and appropriately completed housing assistance payment contracts and lease information, among other criteria, to support the eligibility determination.The Department?s Quality Control and Improvement Plan for the Housing Voucher Programs requires that, after a QA review occurs, ?all actual file deficiencies will be identified as findings for the purposes of QA reviews. Subrecipients will be notified in writing of any findings within 15 days of the completion of the audit. They will have 30 days to correct the findings, or explain why the error(s) cannot be corrected.?Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over federal awards that provide reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We determined that the Department identified issues that required corrective action by subrecipients in 26 of the 28 QA reviews we tested (93 percent), but failed to perform follow-up procedures as required on any of the 26 QA reviews. Specifically, in all 26 instances, the Department did not ensure the subrecipients took steps to address the issues within the 30-day timeframe. While the Department notified the subrecipients of the findings within 15 days of the completed QA review in all 26 instances, the Department did not obtain responses from the subrecipients within the following 30 days indicating the findings had been corrected or otherwise confirm that the issues were addressed. The most common errors identified in the QA reviews related to missing or incorrect documentation in tenant files, including completed applications, birth certificates, and rent reasonableness forms.Subsequent to our testwork, the Department requested and obtained documentation from the applicable subrecipients to verify tenants? eligibility in all 26 cases.WHY DID THE PROBLEM OCCUR?The Department lacked sufficient internal controls over its QA review process to ensure eligibility requirements for the Housing Voucher Programs are met by the Department?s subrecipients. According to the Department, in September 2019, its QA review team underwent a substantial restructure which reassigned file audit responsibility to one person rather than multiple staff members; however, the Department failed to update policies and procedures surrounding the restructuring, which led to staff failing to ensure subrecipients corrected the errors identified during the QA reviews.WHY DOES THIS PROBLEM MATTER?By not ensuring that appropriate internal controls are in place over the Housing Voucher Programs eligibility processes, the Department cannot ensure that all tenants are eligible or qualified to participate in the Housing Voucher Programs. The Department must ensure that subrecipients maintain accurate and complete tenant files to demonstrate compliance with federal requirements.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ELIGIBILITY (E)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-068The Department of Local Affairs should improve its quality assurance internal controls and ensure it complies with eligibility requirements for the Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. Specifically, this should include updating quality assurance procedures and aligning these procedures with responsibilities of the restructured team.RESPONSEDEPARTMENT OF LOCAL AFFAIRSAGREE. IMPLEMENTATION DATE: JULY 2021.The Department of Local Affairs will improve its quality assurance internal controls to ensure future compliance with eligibility requirements through a revamped quality assurance process that clearly outlines the roles and responsibilities of internal staff and subrecipients as well as timelines and acceptable documentation required to complete the quality assurance review. Training for internal staff and subrecipients will be provided through a process sheet published on the website as well as presented in the monthly webinar training series. In addition, the Director of the Office of Rental Assistance will publish a ?policies and procedures? manual specifically related to the quality assurance and monitoring program for subrecipients.
The Department of Local Affairs will improve its quality assurance internal controls to ensure future compliance with eligibility requirements through a revamped quality assurance process that clearly outlines the roles and responsibilities of internal staff and subrecipients as well as timelines and acceptable documentation required to complete the quality assurance review. Training for internal staff and subrecipients will be provided through a process sheet published on the website as well as presented in the monthly webinar training series. In addition, the Director of the Office of Rental Assistance will publish a ?policies and procedures? manual specifically related to the quality assurance and monitoring program for subrecipients.
SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS?ADMINISTRATIVE COSTSThe Department annually receives advance payments from theHousing Voucher Programs to cover rental payments as well as the costs of administering the programs. The Department passes some of these funds through to subrecipients operating on behalf of the Department. During Fiscal Year 2020, the Department incurred approximately $59.3 million in federal costs for the Housing Voucher Programs?$56.8 million for direct expenditures and $2.5 million passed through to subrecipients for their administrative costs. Neither the Section 8 Housing Choice Voucher nor Mainstream Voucher programs have a matching requirement that subrecipients must expend state general funds in order to receive the federal funds.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal activities allowed and allowable cost requirements for the Housing Voucher Programs during Fiscal Year 2020.We tested 40 administrative cost transactions totaling $195,000 that were expended under the Housing Voucher Programs during Fiscal Year 2020 to determine whether the related administrative costs were allowable under the grants.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:In accordance with the Housing Voucher Programs? grant requirements, administrative fees are paid to the Department by HUD and, if applicable, passed through by the Department to subrecipients operating on behalf of the Department. Amounts paid are based on the number of units leased to eligible tenants as of the first day of each month.Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, it must be determined that costs were necessary and reasonable for the performance of the federal award and adequately documented. Therefore, the Department must maintain appropriate support to verify administrative costs were properly charged to the grants.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department could not provide underlying support for three of the 40 (8 percent) administrative cost transactions charged to the Housing Voucher Programs that we tested; all three of the transactions represented payments made by the Department to the same subrecipient. As an example, for one payment, the subrecipient was paid a fee based on 38 tenants, but the payment support provided by the Department only included 34 tenants. The questioned costs for this issue totaled $773.WHY DID THE PROBLEM OCCUR?The Department lacked sufficient internal controls during Fiscal Year 2020 over administrative costs charged to the Housing Voucher Programs. Specifically, the Department did not have a requirement to maintain reports supporting administrative costs for its subrecipients. As a result, Department staff had to recreate system reports to provide documentation for the transactions we tested during the audit.WHY DOES THIS PROBLEM MATTER?The Department?s failure to maintain complete and accurate records for the Housing Voucher Programs could result in inadequate documentation to support its administrative payments and ultimately, disallowed federal costs and potential sanctions.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911*FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871*, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879*, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $773KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-069The Department of Local Affairs (Department) should implement internal controls to ensure it complies with administrative costs for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. This should include instituting a requirement that Department staff maintain reports supporting administrative costs for all agencies.RESPONSEDEPARTMENT OF LOCAL AFFAIRSAGREE. IMPLEMENTATION DATE: NOVEMBER 2020.This issue was brought to the Department?s attention during a meeting with auditors in October 2020. The Department of Local Affairs, immediately implemented internal controls to ensure compliance with administrative costs. In November 2020, Department staff began saving administrative fee support associated with each month?s payment. This supporting documentation is saved on a secure drive and will be available for future audits or other applicable requests.
Show full finding ▾Hide full finding ▴SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMS?ADMINISTRATIVE COSTSThe Department annually receives advance payments from theHousing Voucher Programs to cover rental payments as well as the costs of administering the programs. The Department passes some of these funds through to subrecipients operating on behalf of the Department. During Fiscal Year 2020, the Department incurred approximately $59.3 million in federal costs for the Housing Voucher Programs?$56.8 million for direct expenditures and $2.5 million passed through to subrecipients for their administrative costs. Neither the Section 8 Housing Choice Voucher nor Mainstream Voucher programs have a matching requirement that subrecipients must expend state general funds in order to receive the federal funds.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, federal activities allowed and allowable cost requirements for the Housing Voucher Programs during Fiscal Year 2020.We tested 40 administrative cost transactions totaling $195,000 that were expended under the Housing Voucher Programs during Fiscal Year 2020 to determine whether the related administrative costs were allowable under the grants.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:In accordance with the Housing Voucher Programs? grant requirements, administrative fees are paid to the Department by HUD and, if applicable, passed through by the Department to subrecipients operating on behalf of the Department. Amounts paid are based on the number of units leased to eligible tenants as of the first day of each month.Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.? Furthermore, in accordance with 2 CFR part 200, subpart E, it must be determined that costs were necessary and reasonable for the performance of the federal award and adequately documented. Therefore, the Department must maintain appropriate support to verify administrative costs were properly charged to the grants.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department could not provide underlying support for three of the 40 (8 percent) administrative cost transactions charged to the Housing Voucher Programs that we tested; all three of the transactions represented payments made by the Department to the same subrecipient. As an example, for one payment, the subrecipient was paid a fee based on 38 tenants, but the payment support provided by the Department only included 34 tenants. The questioned costs for this issue totaled $773.WHY DID THE PROBLEM OCCUR?The Department lacked sufficient internal controls during Fiscal Year 2020 over administrative costs charged to the Housing Voucher Programs. Specifically, the Department did not have a requirement to maintain reports supporting administrative costs for its subrecipients. As a result, Department staff had to recreate system reports to provide documentation for the transactions we tested during the audit.WHY DOES THIS PROBLEM MATTER?The Department?s failure to maintain complete and accurate records for the Housing Voucher Programs could result in inadequate documentation to support its administrative payments and ultimately, disallowed federal costs and potential sanctions.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911*FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871*, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879*, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A)ALLOWABLE COSTS/COST PRINCIPLES (B)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $773KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION*ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTSRECOMMENDATION2020-069The Department of Local Affairs (Department) should implement internal controls to ensure it complies with administrative costs for the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers programs. This should include instituting a requirement that Department staff maintain reports supporting administrative costs for all agencies.RESPONSEDEPARTMENT OF LOCAL AFFAIRSAGREE. IMPLEMENTATION DATE: NOVEMBER 2020.This issue was brought to the Department?s attention during a meeting with auditors in October 2020. The Department of Local Affairs, immediately implemented internal controls to ensure compliance with administrative costs. In November 2020, Department staff began saving administrative fee support associated with each month?s payment. This supporting documentation is saved on a secure drive and will be available for future audits or other applicable requests.
This issue was brought to the Department?s attention during a meeting with auditors in October 2020. The Department of Local Affairs, immediately implemented internal controls to ensure compliance with administrative costs. In November 2020, Department staff began saving administrative fee support associated with each month?s payment. This supporting documentation is saved on a secure drive and will be available for future audits or other applicable requests.
SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMSThe Housing Voucher Programs provide tenant-based subsidies for rents paid by low-income households based upon their income. A housing subsidy, or housing assistance payment, is paid to the landlord directly by the Department on behalf of the participating family. The family pays the difference between the actual rent charged by the landlord and the amount subsidized by the program. The Department, as the designated Public Housing Agency for the State, contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the Uniform Guidance for federal reporting purposes, to run the Housing Voucher Programs.To ensure housing assistance payments are allowable under the federal Housing Voucher Programs? requirements, the Department is required to inspect or oversee inspection of units leased to a family at initial occupancy and at least annually thereafter to determine if the unit meets Housing Quality Standards (HQS). HQS are HUD?s minimum quality standards for tenant-based programs to ensure the units are safe and sanitary. Department staff who act as contract managers generate lists of upcoming inspections that are required to be completed, and provide this listing to subrecipients to identify units to be inspected. The Department?s subrecipients must complete the inspection and a unit inspection report prior to the deadline for each inspection. For any failed inspections, the Department must mail a notice of failure along with an abatement letter to the landlord and participant to inform them of the violations identified. This letter will indicate the items in fail status and specify the time frame in which items must be resolved.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, HQS requirements for the Housing Voucher Programs during Fiscal Year 2020.We performed testing related to 68 HQS inspections conducted by the Department?s 53 subrecipients during Fiscal Year 2020 to determine whether the Department complied with the related Housing Voucher Programs? requirements.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:Federal regulations [24 CFR 982.158(d) and 982.404] state that for units that fail to meet HQS, the subrecipients must require the owner to correct any life-threatening HQS deficiencies within 24 hours after the inspections and all other HQS deficiencies within 30 calendar days or within a specified subrecipient-approved extension. Additionally, if the owner does not correct the cited HQS deficiencies within the specified correction period, the Department must stop, or abate, the housing assistance payments beginning no later than the first of the month following the specified correction period. If failed items are not resolved and the housing assistance payment is abated, the Department must send a notice of a Housing Assistance Payment Contract Termination Letter to the landlord and participant. If failed items are not resolved during the abatement period, the Department must terminate the housing assistance payment contract on the first of the following month.Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department did not take appropriate action related to three of the 68 (4 percent) HQS inspections we tested. Failed inspections resulted from items such as ceilings, walls, or window conditions not meeting safety standards, as well as electrical hazards requiring corrections. In two of these instances, the Department failed to enter the property into abatement by placing a temporary hold on the property?s housing assistance payments after issues identified through a failed inspection were not corrected. In the third instance, the Department did not properly terminate the housing assistance contract after 30 days, as required, so the property remained in abatement beyond that time period.WHY DID THIS PROBLEM OCCUR?The Department lacked sufficient controls over HQS enforcement to ensure requirements under the Housing Voucher Programs were met during Fiscal Year 2020. Specifically, the Department lacked policies and procedures for the HQS process and did not provide sufficient training on HQS processes to ensure its subrecipients were aware of and met Housing Voucher Programs? requirements. The Department reported that it had staff turnover during the fiscal year which resulted in a loss of institutional knowledge and further contributed to the problems identified.WHY DOES THIS PROBLEM MATTER?By failing to meet federal HQS requirements, the Department could be subject to disallowed costs and federal sanctions for the Housing Voucher Programs. Furthermore, the Department cannot ensure that property owners participating in the Housing Voucher Programs address inspection issues.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-070The Department of Local Affairs (Department) should strengthen its internal controls over the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs to ensure it complies with Housing Quality Standards (HQS)-related requirements. This should include:A Having documented policies and procedures in place and implemented for both Department staff and subrecipients.B Developing and providing training to staff and subrecipients on the HQS enforcement process.RESPONSEDEPARTMENT OF LOCAL AFFAIRSA AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series.B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
Show full finding ▾Hide full finding ▴SECTION 8 HOUSING CHOICE VOUCHERS AND MAINSTREAM VOUCHERS PROGRAMSThe Housing Voucher Programs provide tenant-based subsidies for rents paid by low-income households based upon their income. A housing subsidy, or housing assistance payment, is paid to the landlord directly by the Department on behalf of the participating family. The family pays the difference between the actual rent charged by the landlord and the amount subsidized by the program. The Department, as the designated Public Housing Agency for the State, contracts with public housing authorities and nonprofit organizations, which are both considered subrecipients under Title 2, Part 200 of the Uniform Guidance for federal reporting purposes, to run the Housing Voucher Programs.To ensure housing assistance payments are allowable under the federal Housing Voucher Programs? requirements, the Department is required to inspect or oversee inspection of units leased to a family at initial occupancy and at least annually thereafter to determine if the unit meets Housing Quality Standards (HQS). HQS are HUD?s minimum quality standards for tenant-based programs to ensure the units are safe and sanitary. Department staff who act as contract managers generate lists of upcoming inspections that are required to be completed, and provide this listing to subrecipients to identify units to be inspected. The Department?s subrecipients must complete the inspection and a unit inspection report prior to the deadline for each inspection. For any failed inspections, the Department must mail a notice of failure along with an abatement letter to the landlord and participant to inform them of the violations identified. This letter will indicate the items in fail status and specify the time frame in which items must be resolved.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place over, and complied with, HQS requirements for the Housing Voucher Programs during Fiscal Year 2020.We performed testing related to 68 HQS inspections conducted by the Department?s 53 subrecipients during Fiscal Year 2020 to determine whether the Department complied with the related Housing Voucher Programs? requirements.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our testwork against the following requirements:Federal regulations [24 CFR 982.158(d) and 982.404] state that for units that fail to meet HQS, the subrecipients must require the owner to correct any life-threatening HQS deficiencies within 24 hours after the inspections and all other HQS deficiencies within 30 calendar days or within a specified subrecipient-approved extension. Additionally, if the owner does not correct the cited HQS deficiencies within the specified correction period, the Department must stop, or abate, the housing assistance payments beginning no later than the first of the month following the specified correction period. If failed items are not resolved and the housing assistance payment is abated, the Department must send a notice of a Housing Assistance Payment Contract Termination Letter to the landlord and participant. If failed items are not resolved during the abatement period, the Department must terminate the housing assistance payment contract on the first of the following month.Uniform Guidance [2 CFR 200.303] requires that the Department, as a federal grant recipient, ?establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.?WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?We found that the Department did not take appropriate action related to three of the 68 (4 percent) HQS inspections we tested. Failed inspections resulted from items such as ceilings, walls, or window conditions not meeting safety standards, as well as electrical hazards requiring corrections. In two of these instances, the Department failed to enter the property into abatement by placing a temporary hold on the property?s housing assistance payments after issues identified through a failed inspection were not corrected. In the third instance, the Department did not properly terminate the housing assistance contract after 30 days, as required, so the property remained in abatement beyond that time period.WHY DID THIS PROBLEM OCCUR?The Department lacked sufficient controls over HQS enforcement to ensure requirements under the Housing Voucher Programs were met during Fiscal Year 2020. Specifically, the Department lacked policies and procedures for the HQS process and did not provide sufficient training on HQS processes to ensure its subrecipients were aware of and met Housing Voucher Programs? requirements. The Department reported that it had staff turnover during the fiscal year which resulted in a loss of institutional knowledge and further contributed to the problems identified.WHY DOES THIS PROBLEM MATTER?By failing to meet federal HQS requirements, the Department could be subject to disallowed costs and federal sanctions for the Housing Voucher Programs. Furthermore, the Department cannot ensure that property owners participating in the Housing Voucher Programs address inspection issues.FEDERAL AGENCY DEPARTMENT OF HOUSING AND URBAN DEVELOPMENTFEDERAL AWARD NUMBER CO911FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NOS. 14.871, SECTION 8 HOUSING CHOICE VOUCHERS; 14.879, MAINSTREAM VOUCHERSCOVID-19 FUNDING NOCOMPLIANCE REQUIREMENT SPECIAL TESTS AND PROVISIONS (N)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-070The Department of Local Affairs (Department) should strengthen its internal controls over the federal Section 8 Housing Choice Vouchers and Mainstream Vouchers Programs to ensure it complies with Housing Quality Standards (HQS)-related requirements. This should include:A Having documented policies and procedures in place and implemented for both Department staff and subrecipients.B Developing and providing training to staff and subrecipients on the HQS enforcement process.RESPONSEDEPARTMENT OF LOCAL AFFAIRSA AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series.B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
(A) The Department of Local Affairs will strengthen its internal controls to ensure compliance with HQS-related requirements moving forward. As recommended, the existing policies and procedures related to HQS Enforcement will be reviewed, updated with clarifying guidance, and presented to both internal staff and subrecipients via a process sheet published on the website and referenced in the Administrative Plan. In addition, HQS Enforcement will be included as a mandatory training for new staff at subrecipient agencies as well as through our monthly webinar series.(B) As an additional compliance measure, the Rental Assistance Program Manager will review the inspection result status reports sent to subrecipients with their team monthly to ensure the information is being shared with subrecipients for follow up.
COMPLIANCE WITH FEDERAL CORONAVIRUS RELIEF FUND SUBRECIPIENT MONITORING REQUIREMENTSThe President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020, and Congress subsequently passed the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The CARES Act provided emergency assistance in response to the COVID-19 pandemic, and established the Coronavirus Relief Fund program (CRF or Program), which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of Program funds, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the Program funds to several state agencies and departments.State departments that received Program funds per the Executive Order were allowed to subgrant, or pass through, the Program funds to subrecipients. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program. In Colorado, the local district colleges, such as Colorado Mountain College, technical schools, and local school districts qualify as subrecipients. The departments and, ultimately, the State as a whole, however, are responsible for ensuring the funds expended by the State and any subrecipients complied with Program requirements.The Executive Order transferred approximately $510.0 million of Program funds to the Colorado Department of Education (CDE) to distribute to the local school districts on a per pupil basis using district-specific factors and by student population to the Charter School Institute and the Colorado School for the Deaf and Blind. The Executive Order also directed CDE to provide $25,000 of Program funds to each Board of Cooperative Educational Services. In total, CDE subgranted, or passed through, $500.9 million of Program funds to local school districts and the 21 Boards of Cooperative Educational Services (BOCES), and provided more than $9.0 million to other state agencies.In addition, the Executive Order transferred $450.0 million of Program funds to the Department of Higher Education (DHE) for expenditures associated with the COVID-19 public health emergency. The Department then subgranted, or passed through, nearly $17.8 million of Program funds to local district colleges and technical schools, and provided more than $432.2 million of Program funds to State Higher Education Institutions.State departments are responsible for reporting to the OSC the amount of Program expenditures they passed through to subrecipients on their Exhibit K1, Schedule of Federal Assistance. The OSC uses the Exhibit K1s to aid them in preparing the State?s SEFA. The State reports expenditures for all federal programs on its SEFA, which is used to report all federal expenditures to the federal government.WHAT WAS THE PURPOSE OF OURAUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the OSC communicated Program subrecipient monitoring requirements to departments. In addition, the purpose of the audit work was to determine whether DHE and CDE had adequate internal controls in place over, and complied with, federal subrecipient monitoring requirements for the Program. We also evaluated whether DHE?s Exhibit K1 that was submitted to the OSC for Fiscal Year 2020 was accurate.As part of our testing, we performed the following procedures at the three departments:? OSC?We conducted interviews with OSC staff regarding the Office?s policies and procedures over the communication of Program monitoring requirements to State agencies during Fiscal Year 2020.? CDE?We conducted interviews with CDE staff regarding CDE?s policies and procedures over the monitoring of Program funds to ensure they were allowable for the Program during Fiscal Year 2020. In addition, we tested 25 of CDE?s subrecipients to determine whether CDE obtained the subrecipient?s State of Colorado CARES Act Notice of Award and Certification Letter (Certification Letter), which was required to be certified by the chief executive of the school district or BOCES to request the transfer of Program funds from the State.? DHE?We conducted interviews with DHE staff regarding DHE?s policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed DHE?s Exhibit K1 to verify the accuracy of the information reported to the OSC.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We based our audit work on the following Uniform Guidance requirements:? Federal regulation [2 CFR 200.303(a)] requires that the departments, as federal grant recipients, must establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award.? Federal regulation [2 CFR 200.331(b)] requires that departments conduct risk assessments for each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the departments should use the risk assessments to determine the appropriate level of subrecipient monitoring the department should perform on each subrecipient.? Federal regulation [2 CFR 200.331(d)] requires that departments ?monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward.?In addition, we also based our audit work on the following:? The Executive Order directed the OSC to issue instructions regarding the distribution of the funds described in the Executive Order, and to monitor their expenditures.? The OSC requires non-state subrecipients that received Program funds to sign the Certification Letter.? The OSC posted the Certification Letters to its website where subrecipients, including the school districts and BOCES, could obtain and certify the Certification Letter. Each Certification Letter was required to be signed and certified by the chief executive of the subrecipient. These Certification Letters were to be returned to the OSC and/or CDE.? The Exhibit K1 is used to report departments? federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA, which reports federal program information, such as expenditures, to the federal government.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the State did not ensure that Program funds passed through to subrecipients were monitored as required. We specifically identified the following issues:? OSC?Although the Executive Order directed the OSC to monitor the Program expenditures, OSC staff did not perform adequate monitoring activities over any of the State?s CRF subrecipients during Fiscal Year 2020. Instead, the OSC indicated that subrecipient monitoring was the responsibility of the various state departments that directly passed CRF funds through to subrecipients. The OSC worked with the Governor?s Office and the departments to distribute the funds and develop guidance on eligible uses of CRF funds.? CDE?CDE did not fully comply with federal subrecipient monitoring requirements for the Program during Fiscal Year 2020. Our testing of 25 subrecipients found that CDE did not obtain the signed Certification Letter from one subrecipient and a second subrecipient returned the Certification Letter, but did not sign it. CDE staff were not aware that these Certification Letters were not received or signed until we brought the issues to their attention. CDE subsequently obtained the signed Certification Letters from the subrecipients. In addition, while CDE provided training and technical assistance on CRF allowable uses to its subrecipients, CDE did not monitor the subrecipients? transactions to confirm the appropriate use of CRF funds during the fiscal year.? DHE?DHE did not comply with federal subrecipient monitoring requirements for the Program during Fiscal Year 2020. Specifically, the Department did not evaluate its subrecipients? risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate level of monitoring or otherwise monitor the subrecipients? use of CRF funds during the fiscal year.Additionally, DHE improperly excluded $17.8 million in CRF that it distributed to local district colleges and technical schools from its Exhibit K1 until we notified them of the omission. The Department subsequently corrected and submitted a revised Exhibit K1 to the OSC.WHY DID THESE PROBLEMS OCCUR?The State did not have adequate internal controls over the Program during Fiscal Year 2020 to ensure that subrecipients? spending of CRF was appropriately monitored and that subrecipient risk assessments were performed in all instances as required. Specifically, the State lacked clear communication and coordination to ensure CRF subrecipients were monitored, as discussed in the following bullets:? OSC?The OSC did not have adequate discussions with CDE and DHE staff regarding CRF monitoring responsibilities, and did not clearly communicate and clarify the monitoring requirements of Executive Order to CDE or DHE staff.? CDE?CDE staff indicated that they believed the OSC was responsible for the subrecipient monitoring requirement for the Program, including subrecipients? signing of the Certification Letters, so CDE relied on the OSC for the tracking of the Certification Letters signed by the subrecipients and did not coordinate with the OSC to ensure all Certification Letters were signed by the subrecipients and returned to the OSC and/or CDE. In addition, CDE staff indicated that they believed the OSC was responsible for monitoring the expenditures incurred by the subrecipients; however, portions of communication from both the OSC and CDE indicated that CDE was responsible for monitoring the subrecipients. Specifically, the OSC provided a notification to CDE?s subrecipients of the grant award requirements, and indicated in the notification that the ?performance measures will be monitored by CDE as a condition for receiving and expending monies;? these performance measures included support of expenses to recover lost time due to COVID-19 and expense reports for other allowable costs. In addition, in June 2020, CDE communicated in a presentation to its subrecipients that ?CDE will monitor allowable uses of funds, compliance with all statutory and regulatory requirements, and performance measures, subject to additional monitoring by the Office of the State Controller.? CDE was unable to provide evidence that the OSC ultimately communicated to CDE that the OSC would take full responsibility for the subrecipient monitoring requirements.CDE did not have documented procedures in place for reviewing subrecipients? expenditures to ensure they were allowable for the Program.? DHE?DHE did not have documented procedures in place for monitoring its subrecipients, including a requirement to conduct risk assessments for each subrecipient to determine the appropriate level of monitoring. Department staff indicated that they believed the Executive Order relieved them of their subrecipient monitoring requirement for CRF, but did not reach out to, or work with, the OSC to confirm or clarify the Executive Order.In addition, DHE staff indicated that they did not reach out to the OSC for guidance on whether the subrecipient distribution of the funds should be included on the Exhibit K1 until we notified them because it was new federal funding and rare circumstances surrounding the Program funds.WHY DO THESE PROBLEMS MATTER?Without the proper communication and controls in place, the OSC, CDE, and DHE cannot ensure that they comply with federal subrecipient monitoring compliance requirements, which could result in future federal funding being reduced. In addition, if DHE does not evaluate the subrecipients? risks of noncompliance, DHE may continue providing funding to high-risk subrecipients that will not be monitored in a way that ensures the funds are being used in accordance with federal statutes, regulations, and the terms and conditions of the federal award.Additionally, failing to properly report federal funds that were passed through to subrecipients on Exhibit K1s, if uncorrected, will cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations.FEDERAL AGENCY DEPARTMENT OF TREASURYFEDERAL AWARD NUMBERS SLT0033SLT0225FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 21.019, CORONAVIRUS RELIEF FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 RELATED $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-071The Office of the State Controller (OSC) should improve its internal controls over the Coronavirus Relief Fund (CRF) program by clarifying the monitoring requirements of Executive Order 2020-070 to state departments and coordinating with the other state department recipients of CRF to ensure CRF subrecipient monitoring requirements under 2 CFR 200.331 are met.RESPONSEOFFICE OF THE STATE CONTROLLERPARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The OSC partially agrees because the OSC's position is that the State was in compliance with 2 CFR 200.329 regarding monitoring and 2 CFR 200.332 requirements for pass through entities for FY2020. Neither the Uniform Guidance nor the Governor's Executive Order required that the monitoring be performed in Fiscal Year 2020. The Uniform Guidance states that "Monitoring by the non-Federal entity must cover each program, function or activity" (2 CFR 200.329). Monitoring is based on a program, function, or activity, not on a fiscal year.Due to the timing of receiving CRF monies near the end of FY2020, along with lagging federal guidance, the process of establishing and formally communicating subrecipient monitoring responsibilities occurred after June 30, 2020. The OSC hired a consultant to perform risk assessments and performed point in time monitoring for the entities identified as high risk. Based on results of the consultant's monitoring, formal recommendations were made to CDE and DHE regarding areas of focus in their continuing monitoring efforts. While subrecipient monitoring responsibilities were not fully defined by June 30, they were substantially defined within the performance period of the funds. To finalize the implementation of this recommendation, the OSC will issue an Alert, or equivalent authoritative guidance, stating monitoring requirements of state agencies that further pass CRF monies through to external subrecipients.AUDITOR?S ADDENDUMWhile the OSC hired a contractor to perform monitoring procedures, the OSC did not hire the contractor until October 2021. In addition, the OSC did not clearly communicate to the state department that even
Show full finding ▾Hide full finding ▴COMPLIANCE WITH FEDERAL CORONAVIRUS RELIEF FUND SUBRECIPIENT MONITORING REQUIREMENTSThe President of the United States issued the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak on March 13, 2020, and Congress subsequently passed the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The CARES Act provided emergency assistance in response to the COVID-19 pandemic, and established the Coronavirus Relief Fund program (CRF or Program), which provided payments to state, local, and tribal governments navigating the impact of COVID-19. The State of Colorado received approximately $1.67 billion of Program funds, and the Governor issued Executive Order 2020-070 (Executive Order) in May 2020 to disburse the Program funds to several state agencies and departments.State departments that received Program funds per the Executive Order were allowed to subgrant, or pass through, the Program funds to subrecipients. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program. In Colorado, the local district colleges, such as Colorado Mountain College, technical schools, and local school districts qualify as subrecipients. The departments and, ultimately, the State as a whole, however, are responsible for ensuring the funds expended by the State and any subrecipients complied with Program requirements.The Executive Order transferred approximately $510.0 million of Program funds to the Colorado Department of Education (CDE) to distribute to the local school districts on a per pupil basis using district-specific factors and by student population to the Charter School Institute and the Colorado School for the Deaf and Blind. The Executive Order also directed CDE to provide $25,000 of Program funds to each Board of Cooperative Educational Services. In total, CDE subgranted, or passed through, $500.9 million of Program funds to local school districts and the 21 Boards of Cooperative Educational Services (BOCES), and provided more than $9.0 million to other state agencies.In addition, the Executive Order transferred $450.0 million of Program funds to the Department of Higher Education (DHE) for expenditures associated with the COVID-19 public health emergency. The Department then subgranted, or passed through, nearly $17.8 million of Program funds to local district colleges and technical schools, and provided more than $432.2 million of Program funds to State Higher Education Institutions.State departments are responsible for reporting to the OSC the amount of Program expenditures they passed through to subrecipients on their Exhibit K1, Schedule of Federal Assistance. The OSC uses the Exhibit K1s to aid them in preparing the State?s SEFA. The State reports expenditures for all federal programs on its SEFA, which is used to report all federal expenditures to the federal government.WHAT WAS THE PURPOSE OF OURAUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of our audit work was to determine whether the OSC communicated Program subrecipient monitoring requirements to departments. In addition, the purpose of the audit work was to determine whether DHE and CDE had adequate internal controls in place over, and complied with, federal subrecipient monitoring requirements for the Program. We also evaluated whether DHE?s Exhibit K1 that was submitted to the OSC for Fiscal Year 2020 was accurate.As part of our testing, we performed the following procedures at the three departments:? OSC?We conducted interviews with OSC staff regarding the Office?s policies and procedures over the communication of Program monitoring requirements to State agencies during Fiscal Year 2020.? CDE?We conducted interviews with CDE staff regarding CDE?s policies and procedures over the monitoring of Program funds to ensure they were allowable for the Program during Fiscal Year 2020. In addition, we tested 25 of CDE?s subrecipients to determine whether CDE obtained the subrecipient?s State of Colorado CARES Act Notice of Award and Certification Letter (Certification Letter), which was required to be certified by the chief executive of the school district or BOCES to request the transfer of Program funds from the State.? DHE?We conducted interviews with DHE staff regarding DHE?s policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed DHE?s Exhibit K1 to verify the accuracy of the information reported to the OSC.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We based our audit work on the following Uniform Guidance requirements:? Federal regulation [2 CFR 200.303(a)] requires that the departments, as federal grant recipients, must establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award.? Federal regulation [2 CFR 200.331(b)] requires that departments conduct risk assessments for each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward. In addition, the departments should use the risk assessments to determine the appropriate level of subrecipient monitoring the department should perform on each subrecipient.? Federal regulation [2 CFR 200.331(d)] requires that departments ?monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward.?In addition, we also based our audit work on the following:? The Executive Order directed the OSC to issue instructions regarding the distribution of the funds described in the Executive Order, and to monitor their expenditures.? The OSC requires non-state subrecipients that received Program funds to sign the Certification Letter.? The OSC posted the Certification Letters to its website where subrecipients, including the school districts and BOCES, could obtain and certify the Certification Letter. Each Certification Letter was required to be signed and certified by the chief executive of the subrecipient. These Certification Letters were to be returned to the OSC and/or CDE.? The Exhibit K1 is used to report departments? federal expenditure information to the OSC to aid the OSC in preparing the State?s SEFA, which reports federal program information, such as expenditures, to the federal government.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?Overall, we found that the State did not ensure that Program funds passed through to subrecipients were monitored as required. We specifically identified the following issues:? OSC?Although the Executive Order directed the OSC to monitor the Program expenditures, OSC staff did not perform adequate monitoring activities over any of the State?s CRF subrecipients during Fiscal Year 2020. Instead, the OSC indicated that subrecipient monitoring was the responsibility of the various state departments that directly passed CRF funds through to subrecipients. The OSC worked with the Governor?s Office and the departments to distribute the funds and develop guidance on eligible uses of CRF funds.? CDE?CDE did not fully comply with federal subrecipient monitoring requirements for the Program during Fiscal Year 2020. Our testing of 25 subrecipients found that CDE did not obtain the signed Certification Letter from one subrecipient and a second subrecipient returned the Certification Letter, but did not sign it. CDE staff were not aware that these Certification Letters were not received or signed until we brought the issues to their attention. CDE subsequently obtained the signed Certification Letters from the subrecipients. In addition, while CDE provided training and technical assistance on CRF allowable uses to its subrecipients, CDE did not monitor the subrecipients? transactions to confirm the appropriate use of CRF funds during the fiscal year.? DHE?DHE did not comply with federal subrecipient monitoring requirements for the Program during Fiscal Year 2020. Specifically, the Department did not evaluate its subrecipients? risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate level of monitoring or otherwise monitor the subrecipients? use of CRF funds during the fiscal year.Additionally, DHE improperly excluded $17.8 million in CRF that it distributed to local district colleges and technical schools from its Exhibit K1 until we notified them of the omission. The Department subsequently corrected and submitted a revised Exhibit K1 to the OSC.WHY DID THESE PROBLEMS OCCUR?The State did not have adequate internal controls over the Program during Fiscal Year 2020 to ensure that subrecipients? spending of CRF was appropriately monitored and that subrecipient risk assessments were performed in all instances as required. Specifically, the State lacked clear communication and coordination to ensure CRF subrecipients were monitored, as discussed in the following bullets:? OSC?The OSC did not have adequate discussions with CDE and DHE staff regarding CRF monitoring responsibilities, and did not clearly communicate and clarify the monitoring requirements of Executive Order to CDE or DHE staff.? CDE?CDE staff indicated that they believed the OSC was responsible for the subrecipient monitoring requirement for the Program, including subrecipients? signing of the Certification Letters, so CDE relied on the OSC for the tracking of the Certification Letters signed by the subrecipients and did not coordinate with the OSC to ensure all Certification Letters were signed by the subrecipients and returned to the OSC and/or CDE. In addition, CDE staff indicated that they believed the OSC was responsible for monitoring the expenditures incurred by the subrecipients; however, portions of communication from both the OSC and CDE indicated that CDE was responsible for monitoring the subrecipients. Specifically, the OSC provided a notification to CDE?s subrecipients of the grant award requirements, and indicated in the notification that the ?performance measures will be monitored by CDE as a condition for receiving and expending monies;? these performance measures included support of expenses to recover lost time due to COVID-19 and expense reports for other allowable costs. In addition, in June 2020, CDE communicated in a presentation to its subrecipients that ?CDE will monitor allowable uses of funds, compliance with all statutory and regulatory requirements, and performance measures, subject to additional monitoring by the Office of the State Controller.? CDE was unable to provide evidence that the OSC ultimately communicated to CDE that the OSC would take full responsibility for the subrecipient monitoring requirements.CDE did not have documented procedures in place for reviewing subrecipients? expenditures to ensure they were allowable for the Program.? DHE?DHE did not have documented procedures in place for monitoring its subrecipients, including a requirement to conduct risk assessments for each subrecipient to determine the appropriate level of monitoring. Department staff indicated that they believed the Executive Order relieved them of their subrecipient monitoring requirement for CRF, but did not reach out to, or work with, the OSC to confirm or clarify the Executive Order.In addition, DHE staff indicated that they did not reach out to the OSC for guidance on whether the subrecipient distribution of the funds should be included on the Exhibit K1 until we notified them because it was new federal funding and rare circumstances surrounding the Program funds.WHY DO THESE PROBLEMS MATTER?Without the proper communication and controls in place, the OSC, CDE, and DHE cannot ensure that they comply with federal subrecipient monitoring compliance requirements, which could result in future federal funding being reduced. In addition, if DHE does not evaluate the subrecipients? risks of noncompliance, DHE may continue providing funding to high-risk subrecipients that will not be monitored in a way that ensures the funds are being used in accordance with federal statutes, regulations, and the terms and conditions of the federal award.Additionally, failing to properly report federal funds that were passed through to subrecipients on Exhibit K1s, if uncorrected, will cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations.FEDERAL AGENCY DEPARTMENT OF TREASURYFEDERAL AWARD NUMBERS SLT0033SLT0225FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 21.019, CORONAVIRUS RELIEF FUNDCOVID-19 FUNDING YESCOMPLIANCE REQUIREMENT REPORTING (L)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 RELATED $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-071The Office of the State Controller (OSC) should improve its internal controls over the Coronavirus Relief Fund (CRF) program by clarifying the monitoring requirements of Executive Order 2020-070 to state departments and coordinating with the other state department recipients of CRF to ensure CRF subrecipient monitoring requirements under 2 CFR 200.331 are met.RESPONSEOFFICE OF THE STATE CONTROLLERPARTIALLY AGREE. IMPLEMENTATION DATE: JULY 2021.The OSC partially agrees because the OSC's position is that the State was in compliance with 2 CFR 200.329 regarding monitoring and 2 CFR 200.332 requirements for pass through entities for FY2020. Neither the Uniform Guidance nor the Governor's Executive Order required that the monitoring be performed in Fiscal Year 2020. The Uniform Guidance states that "Monitoring by the non-Federal entity must cover each program, function or activity" (2 CFR 200.329). Monitoring is based on a program, function, or activity, not on a fiscal year.Due to the timing of receiving CRF monies near the end of FY2020, along with lagging federal guidance, the process of establishing and formally communicating subrecipient monitoring responsibilities occurred after June 30, 2020. The OSC hired a consultant to perform risk assessments and performed point in time monitoring for the entities identified as high risk. Based on results of the consultant's monitoring, formal recommendations were made to CDE and DHE regarding areas of focus in their continuing monitoring efforts. While subrecipient monitoring responsibilities were not fully defined by June 30, they were substantially defined within the performance period of the funds. To finalize the implementation of this recommendation, the OSC will issue an Alert, or equivalent authoritative guidance, stating monitoring requirements of state agencies that further pass CRF monies through to external subrecipients.AUDITOR?S ADDENDUMWhile the OSC hired a contractor to perform monitoring procedures, the OSC did not hire the contractor until October 2021. In addition, the OSC did not clearly communicate to the state department that even
The OSC partially agrees because the OSC's position is that the State was in compliance with 2 CFR 200.329 regarding monitoring and 2 CFR 200.332 requirements for pass through entities for FY2020. Neither the Uniform Guidance nor the Governor's Executive Order required that the monitoring be performed in Fiscal Year 2020. The Uniform Guidance states that "Monitoring by the non-Federal entity must cover each program, function or activity" (2 CFR 200.329). Monitoring is based on a program, function, or activity, not on a fiscal year.Due to the timing of receiving CRF monies near the end of FY2020, along with lagging federal guidance, the process of establishing and formally communicating subrecipient monitoring responsibilities occurred after June 30, 2020. The OSC hired a consultant to perform risk assessments and performed point in time monitoring for the entities identified as high risk. Based on results of the consultant's monitoring, formal recommendations were made to CDE and DHE regarding areas of focus in their continuing monitoring efforts. While subrecipient monitoring responsibilities were not fully defined by June 30, they were substantially defined within the performance period of the funds. To finalize the implementation of this recommendation, the OSC will issue an Alert, or equivalent authoritative guidance, stating monitoring requirements of state agencies that further pass CRF monies through to external subrecipients.
RECOMMENDATION2020-072The Department of Education (CDE) should improve its controls over the Coronavirus Relief Fund (CRF) program by developing, documenting, and implementing subrecipient monitoring procedures to ensure compliance with the federal subrecipient monitoring requirements. This should include:A Communicating with the Office of the State Controller (OSC) to confirm the specific monitoring procedures the OSC is performing, and modifying CDE?s procedures as necessary.B Documenting procedures for reviewing subrecipients? expenditures to ensure they were allowable for the CRF program.RESPONSEDEPARTMENT OF EDUCATIONA AGREE. IMPLEMENTATION DATE: DECEMBER 2021.Pursuant to ? 2 CFR 332(e)(1), providing subrecipients with training and technical assistance is one of the monitoring tools to ensure proper accountability and compliance. CDE, in collaboration with the OSC developed detailed guidance on allowable uses of CRF funds by June 19, 2020. The department began providing weekly training and technical assistance on CRF on June 18, 2020. Therefore, monitoring of CRF funds began within FY 2019-20.B AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department of Education will develop, document, and implement monitoring procedures which complement the monitoring already performed by the Department of Education and the Office of the State Controller and ensure compliance with the federal requirements. This monitoring will be completed within the performance period of the funds.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-072The Department of Education (CDE) should improve its controls over the Coronavirus Relief Fund (CRF) program by developing, documenting, and implementing subrecipient monitoring procedures to ensure compliance with the federal subrecipient monitoring requirements. This should include:A Communicating with the Office of the State Controller (OSC) to confirm the specific monitoring procedures the OSC is performing, and modifying CDE?s procedures as necessary.B Documenting procedures for reviewing subrecipients? expenditures to ensure they were allowable for the CRF program.RESPONSEDEPARTMENT OF EDUCATIONA AGREE. IMPLEMENTATION DATE: DECEMBER 2021.Pursuant to ? 2 CFR 332(e)(1), providing subrecipients with training and technical assistance is one of the monitoring tools to ensure proper accountability and compliance. CDE, in collaboration with the OSC developed detailed guidance on allowable uses of CRF funds by June 19, 2020. The department began providing weekly training and technical assistance on CRF on June 18, 2020. Therefore, monitoring of CRF funds began within FY 2019-20.B AGREE. IMPLEMENTATION DATE: DECEMBER 2021.The Department of Education will develop, document, and implement monitoring procedures which complement the monitoring already performed by the Department of Education and the Office of the State Controller and ensure compliance with the federal requirements. This monitoring will be completed within the performance period of the funds.
(A) Pursuant to ? 2 CFR 332(e)(1), providing subrecipients with training and technical assistance is one of the monitoring tools to ensure proper accountability and compliance. CDE, in collaboration with the OSC developed detailed guidance on allowable uses of CRF funds by June 19, 2020. The department began providing weekly training and technical assistance on CRF on June 18, 2020. Therefore, monitoring of CRF funds began within FY 2019-20. Monitoring continued in FY 2020-21, including work performed by KPMG under the direction of the OSC. The department will perform additional monitoring during FY 2021-22.(B) The Department of Education will develop, document, and implement monitoring procedures which complement the monitoring already performed by the Department of Education and the Office of the State Controller and ensure compliance with the federal requirements. This monitoring will be completed within the performance period of the funds.
RECOMMENDATION2020-073The Department of Higher Education (DHE) should improve its controls over the Coronavirus Relief Fund program by developing, documenting, and implementing subrecipient monitoring procedures to ensure compliance with the federal subrecipient monitoring requirements. This should include:A Performing risk assessments over its subrecipients to determine the appropriate level of monitoring.B Communicating with the Office of the State Controller (OSC) to confirm the DHE?s understanding of the specific monitoring procedures the OSC is performing, if any, and modifying DHE?s procedures as necessary.C Reviewing the information on the Exhibit K1 to ensure it is accurate and complete, and coordinating with the OSC when they receive new federal funding to determine how they should report the information on the Exhibit K1.RESPONSEDEPARTMENT OF HIGHER EDUCATIONA AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.DHE will further refine documented results of risk assessments, expenditure reviews, and scaling of the monitoring. DHE will continue to collaborate with OSC to further refine.The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the Subrecipents (Local district colleges (LDCs) and Area Technical Colleges (ATCs)). The entities conducted their own monitoring of their expenditures using their processes and procedures based on the guidance provided by the Governor's office and the OSC.Risk assessments are typically done before funds are expended. Due to the uniqueness of the situation and the timing of the distribution of the CARES Act funds, a risk assessment of the funds from the Governor's Office required external assistance with a risk assessment. The OSC contracted with KPMG to perform monitoring, risk assessment and review of a portion of CRF expenditures. In addition to the monitoring performed by KPMG, the department also monitored and responded to questions on subrecipient expenditures on a continual basis. DHE worked directly with its subrecipients (LDCs and ATCs) to ensure they used their CARES Act funds for authorized purposes. DHE reviewed quarterly expenditure reports before submitted to OSC.B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.DHE will continually refining monitoring procedures as necessary. DHE will continue to collaborate with OSC to further refine. The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the subrecipients (Local district colleges (LDCs) and Area Technical Colleges (ATCs).C AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.The Department of Higher Education will ensure the Exhibit K is accurate and complete when receiving new federal funding. The department will coordinate with the OSC prior to the submission date of the Exhibit K on how those new federal funds should be reported on the Exhibit K, especially on unique funds such as the Coronavirus Relief Funds.
Show full finding ▾Hide full finding ▴RECOMMENDATION2020-073The Department of Higher Education (DHE) should improve its controls over the Coronavirus Relief Fund program by developing, documenting, and implementing subrecipient monitoring procedures to ensure compliance with the federal subrecipient monitoring requirements. This should include:A Performing risk assessments over its subrecipients to determine the appropriate level of monitoring.B Communicating with the Office of the State Controller (OSC) to confirm the DHE?s understanding of the specific monitoring procedures the OSC is performing, if any, and modifying DHE?s procedures as necessary.C Reviewing the information on the Exhibit K1 to ensure it is accurate and complete, and coordinating with the OSC when they receive new federal funding to determine how they should report the information on the Exhibit K1.RESPONSEDEPARTMENT OF HIGHER EDUCATIONA AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.DHE will further refine documented results of risk assessments, expenditure reviews, and scaling of the monitoring. DHE will continue to collaborate with OSC to further refine.The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the Subrecipents (Local district colleges (LDCs) and Area Technical Colleges (ATCs)). The entities conducted their own monitoring of their expenditures using their processes and procedures based on the guidance provided by the Governor's office and the OSC.Risk assessments are typically done before funds are expended. Due to the uniqueness of the situation and the timing of the distribution of the CARES Act funds, a risk assessment of the funds from the Governor's Office required external assistance with a risk assessment. The OSC contracted with KPMG to perform monitoring, risk assessment and review of a portion of CRF expenditures. In addition to the monitoring performed by KPMG, the department also monitored and responded to questions on subrecipient expenditures on a continual basis. DHE worked directly with its subrecipients (LDCs and ATCs) to ensure they used their CARES Act funds for authorized purposes. DHE reviewed quarterly expenditure reports before submitted to OSC.B AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.DHE will continually refining monitoring procedures as necessary. DHE will continue to collaborate with OSC to further refine. The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the subrecipients (Local district colleges (LDCs) and Area Technical Colleges (ATCs).C AGREE. IMPLEMENTATION DATE: SEPTEMBER 2021.The Department of Higher Education will ensure the Exhibit K is accurate and complete when receiving new federal funding. The department will coordinate with the OSC prior to the submission date of the Exhibit K on how those new federal funds should be reported on the Exhibit K, especially on unique funds such as the Coronavirus Relief Funds.
(A) DHE will further refine documented results of risk assessments, expenditure reviews, and scaling of the monitoring. DHE will continue to collaborate with OSC to further refine.The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the Subrecipients (Local district colleges (LDCs) and Area Technical Colleges (ATCs)). The entities conducted their own monitoring of their expenditures using their processes and procedures based on the guidance provided by the Governor's office and the OSC.Risk assessments are typically done before funds are expended. Due to the uniqueness of the situation and the timing of the distribution of the CARES Act funds, a risk assessment of the funds from the Governor's Office required external assistance with a risk assessment. The OSC contracted with KPMG to perform monitoring, risk assessment and review of a portion of CRF expenditures. In addition to the monitoring performed by KPMG, the department also monitored and responded to questions on subrecipient expenditures on a continual basis. DHE worked directly with its subrecipients (LDCs and ATCs) to ensure they used their CARES Act funds for authorized purposes. DHE reviewed quarterly expenditure reports before submitted to OSC.(B) DHE will continually refining monitoring procedures as necessary. DHE will continue to collaborate with OSC to further refine. The Department of Higher Education (DHE) collaborated with the OSC and the Governor's Office on the guidance of allowable costs and reporting requirements that was provided to the subrecipients (Local district colleges (LDCs) and Area Technical Colleges (ATCs).(C) The Department of Higher Education will ensure the Exhibit K is accurate and complete when receiving new federal funding. The department will coordinate with the OSC prior to the submission date of the Exhibit K on how those new federal funds should be reported on the Exhibit K, especially on unique funds such as the Coronavirus Relief Funds.
HIV CARE FORMULA GRANTS (RYAN WHITE HIV/AIDS PROGRAMPART B)?EARMARKING REQUIREMENTSThe objective of the federal HIV Care Formula Grants, known as the Ryan White HIV/AIDS Program Part B (RWHAP or Program), is to improve the quality, availability, and organization of healthcare and support services for low-income, uninsured, and underinsured people who have Human Immunodeficiency Virus (HIV), and also includes support through the Acquired Immunodeficiency Syndrome (AIDS) Drug Assistance Program (ADAP). The federal awarding agency for the Program is the Health Resources and Services Administration (HRSA). The Department, as the State?s administrator of the Program, is subject to seven different spending limitation, or earmarking, requirements[42 USC 300ff] that specify the minimum or maximum amount or percentage of the Program?s funding that is required or allowed to be used for specified activities.One of these earmarking requirements specifies a minimum percentage of total funds that the Department must expend for providing health and support services to women, youth, infants, and children who have been diagnosed with HIV. The Department must either demonstrate compliance with or request a waiver for the Program?s minimum expenditure earmarking requirement from the federal government in its annual progress report.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls that were in place over the Program?s expenditure earmarking requirements and to determine whether internal controls were appropriate and the Department complied with the applicable federal requirements during Fiscal Year 2020.We performed testing on the Program?s Fiscal Year 2019 RWHAPPart B Women Infants Children and Youth Expenditure Report Worksheet (Report) that was filed by the Department during State Fiscal Year 2020 as part of the Program?s annual progress report. The Report contained Program expenditure information for the period from April 1, 2019, through March 31, 2020. We recalculated and requested supporting documentation for the actual expenditure percentages for each target population reported by the Department in the Report.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?For the requirements specified in federal regulations [42 USC 300ff-22e], the HRSA provided minimum required spending percentages for the Department?s ratios of spending on women, infants, children, and youth populations with AIDS in the State through its Notice of Award. The minimum expenditure percentages for each population were as follows:? Women ? 11.88 percent? Infants ? 0.00 percent? Children ? 0.24 percent? Youth ? 1.97 percentFederal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that reported expenditure amounts and the related calculations are accurate. Appropriate supporting documentation is evidence of such internal controls.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?While the Department reported expenditure percentages on its Report that met the Program?s earmarking requirements, the Department could not provide appropriate supporting documentation for the actual detailed expenditures by population that it used for its related calculations. As a result, we were unable to determine if the Department?s reporting was accurate and whether it complied with the Program?s applicable spending requirements during the period ofApril 1, 2019, through March 31, 2020.WHY DID THIS PROBLEM OCCUR?The Department did not have appropriate policies and procedures in place to ensure that supporting documentation was maintained for its Program reporting. Employee turnover and departmental restructuring further contributed to the Department?s inability to locate or recreate the supporting documentation related to the Program?s earmarking requirement requested during the audit.WHY DOES THIS PROBLEM MATTER?It is important for the Department to ensure that it obtains and maintains appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining the Department?s compliance with specific program requirements. This issue could lead to inaccurate reporting and potential noncompliance, which could result in the federal government requiring the Department to return funds or a negative impact to the Department?s future federal program funding.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS X07HA00056-29-00X07HA00056-30-00FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.917, HIV CARE FORMULA GRANTSCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT MATCHING, LEVEL OF EFFORT, EARMARKING (G)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-074The Department of Public Health and Environment should ensure it has appropriate internal controls over federal Ryan White HIV/AIDS Program (RWHAP) Part B earmarking requirements. This should include developing policies and procedures that include detailed instructions for obtaining the amounts to be categorized and used in the RWHAP Part B Women Infants Children and Youth Expenditure Report Worksheet, and for the required maintenance of all related supporting documentation.RESPONSEDEPARTMENT OF PUBLIC HEALTHAND ENVIRONMENTAGREE. IMPLEMENTATION DATE: APRIL 2021.The Office of STI/HIV/VH agrees with this audit finding. The Office has developed a procedure to report on the RWHAP Part B WICY Expenditure Report Worksheet. Specifically, we are requesting quarterly WICY reports from Ramsell, an outsourced consultant that provides Pharmacy Benefit Management and data system management for the program that include the total number of women, infant, children, and youth served and the associated claims. This will allow us to track the number of clients in each category that are served, the percentage they represent of overall claims within WICY, the number of claims, and the total amount for the claims. We requested they capture the following groups in the report:? Total client base (including women, infants, children, and youth)? Total overall clients that are women? Total overall clients that are infants (up to 2 years)? Total overall clients that are children (ages 3-12)? Total overall clients that are youth (ages 13-24)We asked for this data to be represented quarterly as listed below:? Quarter 1: April - June, with a due date to us of July 15.? Quarter 2: July - September, with a due date to us of October 15.? Quarter 3: October - December, with a due date to us ofJanuary 15.? Quarter 4: January - March, with a due date to us of April 15.By April 1, 2021, we will finalize a written policy to accompany the procedure to include the maintenance of supporting documentation
Show full finding ▾Hide full finding ▴HIV CARE FORMULA GRANTS (RYAN WHITE HIV/AIDS PROGRAMPART B)?EARMARKING REQUIREMENTSThe objective of the federal HIV Care Formula Grants, known as the Ryan White HIV/AIDS Program Part B (RWHAP or Program), is to improve the quality, availability, and organization of healthcare and support services for low-income, uninsured, and underinsured people who have Human Immunodeficiency Virus (HIV), and also includes support through the Acquired Immunodeficiency Syndrome (AIDS) Drug Assistance Program (ADAP). The federal awarding agency for the Program is the Health Resources and Services Administration (HRSA). The Department, as the State?s administrator of the Program, is subject to seven different spending limitation, or earmarking, requirements[42 USC 300ff] that specify the minimum or maximum amount or percentage of the Program?s funding that is required or allowed to be used for specified activities.One of these earmarking requirements specifies a minimum percentage of total funds that the Department must expend for providing health and support services to women, youth, infants, and children who have been diagnosed with HIV. The Department must either demonstrate compliance with or request a waiver for the Program?s minimum expenditure earmarking requirement from the federal government in its annual progress report.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to review the Department?s internal controls that were in place over the Program?s expenditure earmarking requirements and to determine whether internal controls were appropriate and the Department complied with the applicable federal requirements during Fiscal Year 2020.We performed testing on the Program?s Fiscal Year 2019 RWHAPPart B Women Infants Children and Youth Expenditure Report Worksheet (Report) that was filed by the Department during State Fiscal Year 2020 as part of the Program?s annual progress report. The Report contained Program expenditure information for the period from April 1, 2019, through March 31, 2020. We recalculated and requested supporting documentation for the actual expenditure percentages for each target population reported by the Department in the Report.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?For the requirements specified in federal regulations [42 USC 300ff-22e], the HRSA provided minimum required spending percentages for the Department?s ratios of spending on women, infants, children, and youth populations with AIDS in the State through its Notice of Award. The minimum expenditure percentages for each population were as follows:? Women ? 11.88 percent? Infants ? 0.00 percent? Children ? 0.24 percent? Youth ? 1.97 percentFederal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that reported expenditure amounts and the related calculations are accurate. Appropriate supporting documentation is evidence of such internal controls.WHAT PROBLEM DID THE AUDIT WORK IDENTIFY?While the Department reported expenditure percentages on its Report that met the Program?s earmarking requirements, the Department could not provide appropriate supporting documentation for the actual detailed expenditures by population that it used for its related calculations. As a result, we were unable to determine if the Department?s reporting was accurate and whether it complied with the Program?s applicable spending requirements during the period ofApril 1, 2019, through March 31, 2020.WHY DID THIS PROBLEM OCCUR?The Department did not have appropriate policies and procedures in place to ensure that supporting documentation was maintained for its Program reporting. Employee turnover and departmental restructuring further contributed to the Department?s inability to locate or recreate the supporting documentation related to the Program?s earmarking requirement requested during the audit.WHY DOES THIS PROBLEM MATTER?It is important for the Department to ensure that it obtains and maintains appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining the Department?s compliance with specific program requirements. This issue could lead to inaccurate reporting and potential noncompliance, which could result in the federal government requiring the Department to return funds or a negative impact to the Department?s future federal program funding.FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICESFEDERAL AWARD NUMBERS X07HA00056-29-00X07HA00056-30-00FEDERAL AWARD YEARS 2019 AND 2020PASS THROUGH ENTITY NONECFDA NO. 93.917, HIV CARE FORMULA GRANTSCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT MATCHING, LEVEL OF EFFORT, EARMARKING (G)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-074The Department of Public Health and Environment should ensure it has appropriate internal controls over federal Ryan White HIV/AIDS Program (RWHAP) Part B earmarking requirements. This should include developing policies and procedures that include detailed instructions for obtaining the amounts to be categorized and used in the RWHAP Part B Women Infants Children and Youth Expenditure Report Worksheet, and for the required maintenance of all related supporting documentation.RESPONSEDEPARTMENT OF PUBLIC HEALTHAND ENVIRONMENTAGREE. IMPLEMENTATION DATE: APRIL 2021.The Office of STI/HIV/VH agrees with this audit finding. The Office has developed a procedure to report on the RWHAP Part B WICY Expenditure Report Worksheet. Specifically, we are requesting quarterly WICY reports from Ramsell, an outsourced consultant that provides Pharmacy Benefit Management and data system management for the program that include the total number of women, infant, children, and youth served and the associated claims. This will allow us to track the number of clients in each category that are served, the percentage they represent of overall claims within WICY, the number of claims, and the total amount for the claims. We requested they capture the following groups in the report:? Total client base (including women, infants, children, and youth)? Total overall clients that are women? Total overall clients that are infants (up to 2 years)? Total overall clients that are children (ages 3-12)? Total overall clients that are youth (ages 13-24)We asked for this data to be represented quarterly as listed below:? Quarter 1: April - June, with a due date to us of July 15.? Quarter 2: July - September, with a due date to us of October 15.? Quarter 3: October - December, with a due date to us ofJanuary 15.? Quarter 4: January - March, with a due date to us of April 15.By April 1, 2021, we will finalize a written policy to accompany the procedure to include the maintenance of supporting documentation
The Office of STI/HIV/VH agrees with this audit finding. The Office has developed a procedure to report on the RWHAP Part B WICY Expenditure Report Worksheet. Specifically, we are requesting quarterly WICY reports from Ramsell, an outsourced consultant that provides Pharmacy Benefit Management and data system management for the program that include the total number of women, infant, children, and youth served and the associated claims. This will allow us to track the number of clients in each category that are served, the percentage they represent of overall claims within WICY, the number of claims, and the total amount for the claims. We requested they capture the following groups in the report:- Total client base (including women, infants, children, and youth)- Total overall clients that are women- Total overall clients that are infants (up to 2 years)- Total overall clients that are children (ages 3-12)- Total overall clients that are youth (ages 13-24)We asked for this data to be represented quarterly as listed below:- Quarter 1: April - June, with a due date to us of July 15.- Quarter 2: July - September, with a due date to us of October 15.- Quarter 3: October - December, with a due date to us of January 15.- Quarter 4: January - March, with a due date to us of April 15.By April 1, 2021, we will finalize a written policy to accompany the procedure to include the maintenance of supporting documentation.
FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORINGThe Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research.Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities.As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Our audit work was designed to measure the results of compliance with the following criteria:? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations[2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include:? Reviewing financial and programmatic reports.? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award.? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521.? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings.? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows:? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient.? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC.WHY DID THESE PROBLEMS OCCUR?The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts.WHY DO THESE PROBLEMS MATTER?Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government.FEDERAL AGENCY DEPARTMENT OF TRANSPORTATIONFEDERAL AWARD NUMBER CO-2020-028-000FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 20.509, FORMULA GRANTS FOR RURAL AREAS AND TRIBAL TRANSIT PROGRAMCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-075The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by:A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures.B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment.RESPONSEDEPARTMENT OF TRANSPORTATIONA AGREE. IMPLEMENTATION DATE: JULY 2022.CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance.B AGREE. IMPLEMENTATION DATE: JULY 2022.CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
Show full finding ▾Hide full finding ▴FORMULA GRANTS FOR RURAL AREAS?INTERNAL CONTROLS AND COMPLIANCE WITH SUBRECIPIENT MONITORINGThe Department received funding from the Federal Transit Authority (FTA) for the Program during Fiscal Year 2020 and expended approximately $26.8 million under the Program; the expenditures included approximately $16.9 million from the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). The objective of this Program is to initiate, improve, or continue public transportation services in rural areas. FTA provides financial and technical assistance to local public transit systems, including buses, subways, light rail, commuter rail, trolleys, and ferries. FTA also oversees safety measures and helps develop next-generation technology research.Approximately $26.0 million (97 percent) of the Program funds expended by the Department were passed through to subrecipients in order to carry out a portion of the Program.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether the Department had effective internal controls in place during Fiscal Year 2020 over the Program, and complied with the Program?s subrecipient monitoring activities.As part of our audit work, we reviewed the Department?s internal controls over compliance for the Program?s subrecipient monitoring. In addition, we tested a random sample of five of 45 Program subrecipients for Fiscal Year 2020 to determine whether the subrecipient monitoring procedures the Department performed during the year were compliant with federal requirements.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?Our audit work was designed to measure the results of compliance with the following criteria:? Federal regulations [2 CFR 200.332(b)] require that the Department evaluate each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward and may include various factors. Federal regulations[2 CFR 200.332(d)-(f)] also require the Department to monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. Monitoring must include:? Reviewing financial and programmatic reports.? Following up and ensuring the subrecipient takes timely and appropriate action on all deficiencies pertaining to the federal award.? Issuing a management decision for audit findings pertaining to the federal award provided to the subrecipient from the pass-through entity, as required by 2 CFR 200.521.? Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The Department?s internal control policies and procedures require the Internal Audit Division to obtain and review single audit certification forms, whereby subrecipients are required to certify whether they are subject to a Single Audit. Internal Audit Division staff are required to review each certification and related Single Audit report, as applicable, and perform follow-up activities related to deficiencies and audit findings.? Additionally, the Department is required to report the total amount of federal awards expended to the Office of the State Controller (OSC) via the Exhibit K1, Schedule of Federal Assistance. The Exhibit K1 is the document through which state departments report federal expenditure information to the OSC, including separate columns to indicate types of expenditures, for statewide compilation and reporting.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We identified issues related to two of the five (40 percent) Program subrecipients identified by the Department for Fiscal Year 2020 as follows:? The Department did not take sufficient steps to address one subrecipient?s failure to obtain a 2019 Single Audit. Specifically, the subrecipient received approximately $78,500 in pass-through Program funding from the Department and communicated to the Department in its single audit certification for the year ending December 31, 2019, that it was subject to a Single Audit; however, that audit had not been conducted as of the completion of our Fiscal Year 2020 audit testwork in April 2021. While it appeared that the Department communicated various times with the subrecipient about the missing audit, the Department did not assess possible impacts from the missing audit or take any action to institute alternate monitoring procedures of the subrecipient.? For the second subrecipient tested, the Department inappropriately considered the entity to be a subrecipient rather than a vendor and incorrectly reported $20,936 in funds paid to the entity as subrecipient expenditures on its Exhibit K1 submitted to the OSC.WHY DID THESE PROBLEMS OCCUR?The Department?s subrecipient policies and procedures are voluminous and performed throughout multiple divisions within the Department. Therefore, the results of monitoring procedures performed are documented in various areas and not contained in one central location. The Department also does not have policies and procedures in place to identify appropriate actions to be taken when issues are identified. In addition, the Department lacks a process for analyzing the types of entities it is contracting with for the Program in order to separately identify the entities as vendors or subrecipients; rather, staff indicated that, during the contracting process, all contract expenditures related to this Program are recorded as subrecipient expenditures, including service-related or vendor contracts.WHY DO THESE PROBLEMS MATTER?Performing timely and appropriate identification and monitoring of subrecipients, including ensuring that they undergo required Single Audits, provides the Department with a method to identify federal grant-related issues and to ensure its compliance with federal subrecipient monitoring requirements. By taking appropriate actions to address the results of its monitoring, the Department can mitigate the risk of providing continuing funding to entities that may not be using funds in accordance with Program requirements. This is particularly important because the Department passes 97 percent of these Program funds to subrecipients. The Department?s failure to comply with federal requirements could result in a loss of funding from the federal government.FEDERAL AGENCY DEPARTMENT OF TRANSPORTATIONFEDERAL AWARD NUMBER CO-2020-028-000FEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 20.509, FORMULA GRANTS FOR RURAL AREAS AND TRIBAL TRANSIT PROGRAMCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCYTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATIONRECOMMENDATION2020-075The Department of Transportation (Department) should ensure that it improves its internal controls over, and complies with, federal Formula Grants for Rural Areas and Tribal Transit Program requirements for subrecipient monitoring by:A Ensuring that subrecipient monitoring policies and procedures are centralized, condensed, and available to all personnel who are responsible for performing subrecipient monitoring activities. The policies and procedures should clearly list responsibilities for each division within the Department and be inclusive of all monitoring activities performed and contain clear directives for acting on subrecipients? failure to comply with requirements, including providing its single audit report, by assessing possible impacts from the noncompliance and instituting appropriate alternative procedures.B Implementing a process for analyzing its contracted entities during the contracting and awarding process by reviewing the nature and terms of contracts, separately identifying the contracted entities as vendors or subrecipients, and recording the contract expenditures appropriately based on this assessment.RESPONSEDEPARTMENT OF TRANSPORTATIONA AGREE. IMPLEMENTATION DATE: JULY 2022.CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance.B AGREE. IMPLEMENTATION DATE: JULY 2022.CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
(A) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include identifying a centralized location for all policies and procedures related to subrecipient monitoring. We will look at all policies and procedures to ensure they clearly identify responsibilities and requirements for non-compliance.(B) CDOT will work with various divisions to devise a plan that will comply with this finding and the recommendations noted within. This plan shall include establishing a process by which an analysis of contracted entities will be performed to identify and properly record entities as a vendor or subrecipient.
MINERALS LEASING ACT?SUBRECIPIENT MONITORING AND REPORTINGIn 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals.For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.?During Fiscal Year 2020, ONRR distributed approximately$62.6 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $21.8 million of the $24.6 million in Program funds it received through to local government subrecipients. DOLA retained the remaining $2.8 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program. We also evaluated whether Treasury?s Exhibit K1, Schedule of Federal Assistance, submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2020 was accurate.As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal requirements and the OSC?s instructions.Additionally, we reviewed Treasury?s progress in implementing our Fiscal Year 2018 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by communicating required federal award information and reporting requirements for the grant when passing funds through to other state agencies or non-state subrecipients, and by developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds communicate the required federal award information to their subrecipients.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following requirements:Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provide specific information about the Program to the subrecipients, including, but not limited to, the following:? Catalog of Federal Domestic Assistance (CFDA) number? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies? Contact information for Treasury? Dollar amount made available? Reporting requirementsThe State and any local governments receiving federal funds are required to present their Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit.In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. Per the OSC?s Fiscal Procedures Manual (Manual), all federal award amounts passed through to a subrecipient should be reported in the Expenditures-Passed Through to Subrecipient column of the Exhibit K1. This should include any funds passed through to another state agency, which that state agency then ultimately passed on to subrecipients outside of the State (e.g., at the local government level.) Federal awards that are only passed through from one state agency to another are to be reported in the Expenditures-Direct and Indirect column, rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be subrecipient expenditures. Because Treasury maintains the reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2020. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, required award information to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury provided some Program information to county subrecipients with its annual Payments In Lieu of Taxes (PILT) confirmation letters; however, the counties that received the PILT confirmation letters only represented about 62 of 338 (18 percent) of the Program subrecipients and the letters did not communicate all required federal award information. In addition, DOLA did not communicate any of the required award information with its Fiscal Year 2020 Program distributions to the remaining local government subrecipients.We also found that Treasury misclassified approximately $21.8 million in federal Program funds that it passed to DOLA, which DOLA subsequently passed to local governments as direct expenditures rather than subrecipient expenditures for the Program on its Fiscal Year 2020 Exhibit K1. As a result, the direct expenditures for the Program were overstated on the exhibit by approximately $21.8 million and the Program?s subrecipient expenditures were understated by $21.8 million. If not corrected, this misclassification would have caused the State?s direct expenditures and subrecipient expenditures for the Program to be misstated on the State?s SEFA.WHY DID THESE PROBLEMS OCCUR?Treasury did not have adequate internal controls in place during Fiscal Year 2020 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, Treasury staff did not effectively communicate with DOLA staff about responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information to all subrecipients of Program funds.Additionally, Treasury did not have adequate procedures in place to ensure its Exhibit K1 was prepared in accordance with federal requirements and the Manual. Treasury did not communicate with the pass-through agencies in order to properly determine whether Program funds ultimately flowed through to subrecipients, and should have been reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.WHY DO THESE PROBLEMS MATTER?By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not receiving Single Audits, as required.By failing to properly report federal funds that were passed to subrecipients on its Exhibit K1, Treasury was out of compliance with the Manual. Furthermore, this type of error, if uncorrected, would cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations.FEDERAL AGENCY DEPARTMENT OF THE INTERIORFEDERAL AWARD NUMBER N/AFEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 15.437, MINERALS LEASING ACTCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT REPORTING (L)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-059A,2019-059B, 2018-067A, AND 2018-067BRECOMMENDATION2020-076The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by:A Developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Catalog of Federal Domestic Assistance number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount; as well as reporting requirements for the funds, including the requirement to report Program expenditures on the subrecipients? Schedule of Expenditures of Federal Awards.B Implementing procedures to ensure the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures. This should include developing and implementing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine whether those funds ultimately flow through to subrecipients and should therefore be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.RESPONSEDEPARMENT OF THE TREASURYA AGREE. IMPLEMENTATION DATE: JUNE 2022.Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards.B AGREE. IMPLEMENTATION DATE: JUNE 2022.Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
Show full finding ▾Hide full finding ▴MINERALS LEASING ACT?SUBRECIPIENT MONITORING AND REPORTINGIn 1920, the U.S. Congress passed the Minerals Leasing Act. This Act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Mineral lease revenue results from payments made to the federal government by companies that lease federal land for the right to extract minerals from that land. According to the Act, revenue is to be used by states as each individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the extraction of minerals.For Colorado, ONRR distributes Program funds to Treasury, which subgrants?or passes through?Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE), as prescribed by Section 34-63-102, C.R.S. In turn, DOLA passes the majority of the Program funds it receives to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the Program, and may use Program monies for ??planning; construction and maintenance of public facilities; and provision of public services.?During Fiscal Year 2020, ONRR distributed approximately$62.6 million in Program revenue to Treasury. Treasury passed all of the Program funds to DOLA, DNR, DHE, and DOE. DOLA then passed approximately $21.8 million of the $24.6 million in Program funds it received through to local government subrecipients. DOLA retained the remaining $2.8 million in Program funds to cover administrative costs. DNR, DOE, and DHE spent the Program funds at the state level and did not pass any of the funds through to subrecipients.WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED?The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the Program. We also evaluated whether Treasury?s Exhibit K1, Schedule of Federal Assistance, submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2020 was accurate.As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2020. We also reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with federal requirements and the OSC?s instructions.Additionally, we reviewed Treasury?s progress in implementing our Fiscal Year 2018 audit recommendation related to subrecipient monitoring and reporting requirements for the Program. During that audit, we recommended that Treasury strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Program by communicating required federal award information and reporting requirements for the grant when passing funds through to other state agencies or non-state subrecipients, and by developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds communicate the required federal award information to their subrecipients.HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED?We measured the results of our audit work against the following requirements:Federal regulations [2 CFR 200.303] require that Treasury, as a federal grant recipient, establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation, and the terms and conditions of the federal award. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program monies, ensure that every subaward it makes is clearly identified to the subrecipient as a subaward, and that Treasury provide specific information about the Program to the subrecipients, including, but not limited to, the following:? Catalog of Federal Domestic Assistance (CFDA) number? Name of the program, name of the federal awarding agency, and name of the department awarding the Program monies? Contact information for Treasury? Dollar amount made available? Reporting requirementsThe State and any local governments receiving federal funds are required to present their Schedule of Expenditures of Federal Awards (SEFA) in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.332] further require that Treasury, as the primary recipient of the Program funds, ensure that any non-state subrecipients receiving federal funds from the State during a given fiscal year report the funds on their respective SEFAs and, if applicable, undergo a Single Audit.In order to prepare the State?s SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. Per the OSC?s Fiscal Procedures Manual (Manual), all federal award amounts passed through to a subrecipient should be reported in the Expenditures-Passed Through to Subrecipient column of the Exhibit K1. This should include any funds passed through to another state agency, which that state agency then ultimately passed on to subrecipients outside of the State (e.g., at the local government level.) Federal awards that are only passed through from one state agency to another are to be reported in the Expenditures-Direct and Indirect column, rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be subrecipient expenditures. Because Treasury maintains the reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State.WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY?We found that Treasury did not fully implement our prior audit recommendation related to federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2020. Specifically, we found that Treasury did not communicate, or ensure that DOLA communicated, required award information to all Program subrecipients in accordance with federal regulations. In response to our prior audit recommendation, Treasury provided some Program information to county subrecipients with its annual Payments In Lieu of Taxes (PILT) confirmation letters; however, the counties that received the PILT confirmation letters only represented about 62 of 338 (18 percent) of the Program subrecipients and the letters did not communicate all required federal award information. In addition, DOLA did not communicate any of the required award information with its Fiscal Year 2020 Program distributions to the remaining local government subrecipients.We also found that Treasury misclassified approximately $21.8 million in federal Program funds that it passed to DOLA, which DOLA subsequently passed to local governments as direct expenditures rather than subrecipient expenditures for the Program on its Fiscal Year 2020 Exhibit K1. As a result, the direct expenditures for the Program were overstated on the exhibit by approximately $21.8 million and the Program?s subrecipient expenditures were understated by $21.8 million. If not corrected, this misclassification would have caused the State?s direct expenditures and subrecipient expenditures for the Program to be misstated on the State?s SEFA.WHY DID THESE PROBLEMS OCCUR?Treasury did not have adequate internal controls in place during Fiscal Year 2020 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, Treasury staff did not effectively communicate with DOLA staff about responsibility for subrecipient reporting or have a monitoring process in place to ensure that either Treasury or DOLA staff communicated required federal award information to all subrecipients of Program funds.Additionally, Treasury did not have adequate procedures in place to ensure its Exhibit K1 was prepared in accordance with federal requirements and the Manual. Treasury did not communicate with the pass-through agencies in order to properly determine whether Program funds ultimately flowed through to subrecipients, and should have been reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.WHY DO THESE PROBLEMS MATTER?By not communicating required information to subrecipients, Treasury failed to comply with federal subrecipient monitoring requirements for the Program. This communication is necessary to ensure that subrecipients are aware of the federal requirements for the funds, including the requirement that local governments properly report federal expenditures on their SEFAs. Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate SEFA reporting requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in local governments not receiving Single Audits, as required.By failing to properly report federal funds that were passed to subrecipients on its Exhibit K1, Treasury was out of compliance with the Manual. Furthermore, this type of error, if uncorrected, would cause the State?s overall SEFA to be inaccurate and out of compliance with federal regulations.FEDERAL AGENCY DEPARTMENT OF THE INTERIORFEDERAL AWARD NUMBER N/AFEDERAL AWARD YEAR 2020PASS THROUGH ENTITY NONECFDA NO. 15.437, MINERALS LEASING ACTCOVID-19 FUNDING YES/NOCOMPLIANCE REQUIREMENT REPORTING (L)SUBRECIPIENT MONITORING (M)CLASSIFICATION OF FINDING MATERIAL WEAKNESSTOTAL KNOWN QUESTIONED COSTS $0KNOWN QUESTIONED COSTS RELATED TO COVID-19 FUNDING $0THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2019-059A,2019-059B, 2018-067A, AND 2018-067BRECOMMENDATION2020-076The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by:A Developing an effective monitoring process to ensure that required federal award information is communicated to Program subrecipients, including the Catalog of Federal Domestic Assistance number, program name, federal awarding agency, name of the department awarding the Program monies, Treasury department contact information, and dollar amount; as well as reporting requirements for the funds, including the requirement to report Program expenditures on the subrecipients? Schedule of Expenditures of Federal Awards.B Implementing procedures to ensure the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures. This should include developing and implementing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine whether those funds ultimately flow through to subrecipients and should therefore be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.RESPONSEDEPARMENT OF THE TREASURYA AGREE. IMPLEMENTATION DATE: JUNE 2022.Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards.B AGREE. IMPLEMENTATION DATE: JUNE 2022.Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
(A) Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the sub award, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards.(B) Implementing a supervisory review process to ensure that the Exhibit K1, Schedule of Federal Assistance, accurately reflects Program expenditures, developing a process to communicate with the state departments which receive Program funds from Treasury, in order to determine that those funds flow through to subrecipients and thus be reported as Expenditures-Passed Through to Subrecipient on Treasury?s Exhibit K1.
2019-059
FAC accepted this audit on June 17, 2020 — management decision was due December 17, 2020.
WILD HORSE AND BURRO RESOURCE MANAGEMENT?CASH MANAGEMENT AND FEDERAL REPORTING The federal Bureau of Land Management (BLM) created WHIP [CFDA No. 15.229] to implement the Wild-Free Roaming Horses and Burros Act, passed by Congress in 1971. Broadly, the law declares wild horses and burros to be ?living symbols of the historic and pioneer spirit of the West? and stipulates that the BLM and the U.S. Forest Service have the responsibility to manage and protect herds in their respective jurisdictions within areas where wild horses and burros were found roaming in 1971. In order to maintain wild horses and burros in good condition and protect the health of federal public lands, the BLM must manage the population growth of wild horse and burro herds. To carry out this mission, the BLM controls herd growth through the application of fertility measures, such as birth control, and through the periodic removal of excess animals and the placement of those animals into the care of the Department?s WHIP program. The Department uses WHIP funds primarily for the care and training of the animals placed within their program. The Department operates on a reimbursement basis with the federal government for its federal grants. Thus, the Department expends Correctional Industries cash funds for WHIP prior to requesting reimbursement from the federal government. During Fiscal Year 2019, the Department expended approximately $500,000 for WHIP. BLM notified the Department on March 16, 2017, that it was placing the Department on an ?agency review? due to concerns BLM had with the Department?s administration of the program. BLM further notified the Department that it would be required to substantiate the actual costs of the program by submitting specific federal reimbursement forms documenting actual program expenditures, less any program income received by the Department for WHIP, as well as supporting documentation for all expenditures included on the reimbursement requests. During Fiscal Year 2019, the Department was also asked by BLM to submit corrected federal reports for the entire grant period from June 2014 through June 2019. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 audit recommendations related to cash management and federal reporting. At that time, we recommended that the Department strengthen its internal controls to ensure it complied with the cash management requirements for WHIP by revising its policies and procedures to align with BLM?s WHIP requirements, as well as submitting corrected reimbursement requests based on actual costs incurred, and working with BLM staff to resolve identified differences in reimbursements. For federal reporting, we recommended that the Department strengthen its internal controls related to WHIP federal reporting requirements by updating and implementing its federal reporting procedures, and by working with BLM to provide accurate cumulative expenditure information. The Department agreed with both of our recommendations and stated that it would work with BLM to provide actual allowable and authorized costs for reimbursement. Additionally, the Department indicated that it would improve its federal reporting process by implementing reconciliations, review, and approval processes; and retaining documentation for its reports. As part of our Fiscal Year 2019 audit work, we requested the Department?s updated cash management and federal reporting policies and procedures. We also requested for review any corrected reimbursement requests and/or any corrected federal reports the Department submitted to BLM during Fiscal Year 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulation 45 CFR, 92.20(b)(1), related to federal reporting, states, ?Accurate, current and complete disclosure of the financial results of financially assisted activities must be made in accordance with the financial reporting requirements of the grant or subgrant.? Per the Federal Financial Report Instructions, quarterly reports, including the SF-425?Federal Financial Report (SF-425), shall be submitted no later than 30 days after the end of each reporting quarter. The SF-425 reports on the total cumulative cash receipts, cash disbursements, federal funds authorized, the federal funds expended, and the total program income for the grant period. Federal regulations [2 CFR 200.345] related to cash management indicate that ?when entities are funded on a reimbursement basis, program costs must be paid by the entity before reimbursement is requested from the federal government.? Reimbursement requests are to be made through submission to BLM of the SF-270?Request for Advance of Reimbursement report detailing expenditures made for the period. Federal regulations [2 CFR 200.303] related to internal controls require that the Department, as a federal grant recipient, ?establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation and the terms and conditions of the federal award.? WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement our Fiscal Year 2018 recommendations during Fiscal Year 2019. Specifically, we found that the Department did not submit updated SF-425 reports or corrected reimbursement requests based on actual costs incurred for Fiscal Years 2014 through 2019. Although the Department did update both its cash management and federal reporting policies during the fiscal year, we were unable to determine if the new policies fully align with BLM guidelines because the BLM audit is ongoing. WHY DID THESE PROBLEMS OCCUR? While Department staff reported that they completed and submitted revised reimbursement requests and SF-425 reports in November 2019 for WHIP for Fiscal Years 2014 through 2019, they indicated that they were still awaiting BLM?s approval of the resubmitted documents to allow for reimbursement of outstanding reimbursement costs. The Department indicated that it had continued to work with BLM to ensure that it was addressing BLM?s concerns in a timely manner, but BLM had continued to delay payments to the Department until the audit of the program was fully complete. WHY DO THESE PROBLEMS MATTER? Because of the issues identified and the ongoing BLM audit, the Department has not yet been fully reimbursed for Correctional Industries cash funds expended throughout the grant period from June 2014 through June 2019. As of June 30, 2019, the Department was still owed approximately $1.2 million from BLM for expenditures made for WHIP during that time period. The Department?s internal control weaknesses for WHIP have resulted in the Department fronting Correctional Industries cash funds without receiving federal reimbursement for significant periods of time, which results in missed opportunities for the use of and interest on state general funds. Further, if the Department does not take active steps to address its weaknesses in WHIP and submit corrected federal reports, it may incur monetary penalties, interest and other federal sanctions, including the termination of WHIP. FEDERAL AGENCY DEPARTMENT OF INTERIOR?BUREAU OF LAND MANAGEMENT FEDERAL AWARD NUMBER L14AC00056 FEDERAL AWARD YEARS 2014 WITH AMENDMENTS IN 2015, 2016, AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 15.229, WILD HORSE AND BURRO RESOURCE MANAGEMENT PROGRAM COMPLIANCE REQUIREMENT CASH MANAGEMENT (C) REPORTING (L) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-043A AND 2018-043B RECOMMENDATION 2019-041 The Department of Corrections (Department) should strengthen its internal controls to ensure that it complies with the cash management and federal reporting requirements for the Wild Horse and Burro Resource Management program (WHIP) by: A Ensuring that corrected reimbursement requests and updated federal reports for Fiscal Years 2014 through 2019, as applicable, are submitted to the federal Bureau of Land Management (BLM) and continuing to work with BLM staff to resolve identified differences. B Taking additional steps to proactively work with BLM to ensure that the BLM audit is finalized, that the Department?s updated WHIP policies and procedures align with BLM requirements, and that the Department obtains reimbursement for prior year and future WHIP costs, as appropriate. RESPONSE DEPARTMENT OF CORRECTIONS A AGREE. IMPLEMENTATION DATE: MAY 2020. The Department of Corrections (Department) has submitted corrected reimbursement requests and updated federal reports to the federal Bureau of Land Management (BLM) for Fiscal Years 2014 through 2019. The Department will continue to work with the BLM to resolve any identified differences. B AGREE. IMPLEMENTATION DATE: MAY 2020. The Department will continue to proactively work with the BLM to finalize BLM?s payment review audit and obtain reimbursement for prior years expenditures. The Department has updated policies and procedures relating to cash management and federal reporting to align with BLM requirements.
Show full finding ▾Hide full finding ▴WILD HORSE AND BURRO RESOURCE MANAGEMENT?CASH MANAGEMENT AND FEDERAL REPORTING The federal Bureau of Land Management (BLM) created WHIP [CFDA No. 15.229] to implement the Wild-Free Roaming Horses and Burros Act, passed by Congress in 1971. Broadly, the law declares wild horses and burros to be ?living symbols of the historic and pioneer spirit of the West? and stipulates that the BLM and the U.S. Forest Service have the responsibility to manage and protect herds in their respective jurisdictions within areas where wild horses and burros were found roaming in 1971. In order to maintain wild horses and burros in good condition and protect the health of federal public lands, the BLM must manage the population growth of wild horse and burro herds. To carry out this mission, the BLM controls herd growth through the application of fertility measures, such as birth control, and through the periodic removal of excess animals and the placement of those animals into the care of the Department?s WHIP program. The Department uses WHIP funds primarily for the care and training of the animals placed within their program. The Department operates on a reimbursement basis with the federal government for its federal grants. Thus, the Department expends Correctional Industries cash funds for WHIP prior to requesting reimbursement from the federal government. During Fiscal Year 2019, the Department expended approximately $500,000 for WHIP. BLM notified the Department on March 16, 2017, that it was placing the Department on an ?agency review? due to concerns BLM had with the Department?s administration of the program. BLM further notified the Department that it would be required to substantiate the actual costs of the program by submitting specific federal reimbursement forms documenting actual program expenditures, less any program income received by the Department for WHIP, as well as supporting documentation for all expenditures included on the reimbursement requests. During Fiscal Year 2019, the Department was also asked by BLM to submit corrected federal reports for the entire grant period from June 2014 through June 2019. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 audit recommendations related to cash management and federal reporting. At that time, we recommended that the Department strengthen its internal controls to ensure it complied with the cash management requirements for WHIP by revising its policies and procedures to align with BLM?s WHIP requirements, as well as submitting corrected reimbursement requests based on actual costs incurred, and working with BLM staff to resolve identified differences in reimbursements. For federal reporting, we recommended that the Department strengthen its internal controls related to WHIP federal reporting requirements by updating and implementing its federal reporting procedures, and by working with BLM to provide accurate cumulative expenditure information. The Department agreed with both of our recommendations and stated that it would work with BLM to provide actual allowable and authorized costs for reimbursement. Additionally, the Department indicated that it would improve its federal reporting process by implementing reconciliations, review, and approval processes; and retaining documentation for its reports. As part of our Fiscal Year 2019 audit work, we requested the Department?s updated cash management and federal reporting policies and procedures. We also requested for review any corrected reimbursement requests and/or any corrected federal reports the Department submitted to BLM during Fiscal Year 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulation 45 CFR, 92.20(b)(1), related to federal reporting, states, ?Accurate, current and complete disclosure of the financial results of financially assisted activities must be made in accordance with the financial reporting requirements of the grant or subgrant.? Per the Federal Financial Report Instructions, quarterly reports, including the SF-425?Federal Financial Report (SF-425), shall be submitted no later than 30 days after the end of each reporting quarter. The SF-425 reports on the total cumulative cash receipts, cash disbursements, federal funds authorized, the federal funds expended, and the total program income for the grant period. Federal regulations [2 CFR 200.345] related to cash management indicate that ?when entities are funded on a reimbursement basis, program costs must be paid by the entity before reimbursement is requested from the federal government.? Reimbursement requests are to be made through submission to BLM of the SF-270?Request for Advance of Reimbursement report detailing expenditures made for the period. Federal regulations [2 CFR 200.303] related to internal controls require that the Department, as a federal grant recipient, ?establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation and the terms and conditions of the federal award.? WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement our Fiscal Year 2018 recommendations during Fiscal Year 2019. Specifically, we found that the Department did not submit updated SF-425 reports or corrected reimbursement requests based on actual costs incurred for Fiscal Years 2014 through 2019. Although the Department did update both its cash management and federal reporting policies during the fiscal year, we were unable to determine if the new policies fully align with BLM guidelines because the BLM audit is ongoing. WHY DID THESE PROBLEMS OCCUR? While Department staff reported that they completed and submitted revised reimbursement requests and SF-425 reports in November 2019 for WHIP for Fiscal Years 2014 through 2019, they indicated that they were still awaiting BLM?s approval of the resubmitted documents to allow for reimbursement of outstanding reimbursement costs. The Department indicated that it had continued to work with BLM to ensure that it was addressing BLM?s concerns in a timely manner, but BLM had continued to delay payments to the Department until the audit of the program was fully complete. WHY DO THESE PROBLEMS MATTER? Because of the issues identified and the ongoing BLM audit, the Department has not yet been fully reimbursed for Correctional Industries cash funds expended throughout the grant period from June 2014 through June 2019. As of June 30, 2019, the Department was still owed approximately $1.2 million from BLM for expenditures made for WHIP during that time period. The Department?s internal control weaknesses for WHIP have resulted in the Department fronting Correctional Industries cash funds without receiving federal reimbursement for significant periods of time, which results in missed opportunities for the use of and interest on state general funds. Further, if the Department does not take active steps to address its weaknesses in WHIP and submit corrected federal reports, it may incur monetary penalties, interest and other federal sanctions, including the termination of WHIP. FEDERAL AGENCY DEPARTMENT OF INTERIOR?BUREAU OF LAND MANAGEMENT FEDERAL AWARD NUMBER L14AC00056 FEDERAL AWARD YEARS 2014 WITH AMENDMENTS IN 2015, 2016, AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 15.229, WILD HORSE AND BURRO RESOURCE MANAGEMENT PROGRAM COMPLIANCE REQUIREMENT CASH MANAGEMENT (C) REPORTING (L) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-043A AND 2018-043B RECOMMENDATION 2019-041 The Department of Corrections (Department) should strengthen its internal controls to ensure that it complies with the cash management and federal reporting requirements for the Wild Horse and Burro Resource Management program (WHIP) by: A Ensuring that corrected reimbursement requests and updated federal reports for Fiscal Years 2014 through 2019, as applicable, are submitted to the federal Bureau of Land Management (BLM) and continuing to work with BLM staff to resolve identified differences. B Taking additional steps to proactively work with BLM to ensure that the BLM audit is finalized, that the Department?s updated WHIP policies and procedures align with BLM requirements, and that the Department obtains reimbursement for prior year and future WHIP costs, as appropriate. RESPONSE DEPARTMENT OF CORRECTIONS A AGREE. IMPLEMENTATION DATE: MAY 2020. The Department of Corrections (Department) has submitted corrected reimbursement requests and updated federal reports to the federal Bureau of Land Management (BLM) for Fiscal Years 2014 through 2019. The Department will continue to work with the BLM to resolve any identified differences. B AGREE. IMPLEMENTATION DATE: MAY 2020. The Department will continue to proactively work with the BLM to finalize BLM?s payment review audit and obtain reimbursement for prior years expenditures. The Department has updated policies and procedures relating to cash management and federal reporting to align with BLM requirements.
(A) The Department of Corrections (Department) has submitted corrected reimbursement requests and updated federal reports to the federal Bureau of Land Management (BLM) for Fiscal Years 2014 through 2019. The Department will continue to work with the BLM to resolve any identified differences (Agency Contact Person: Bradley Duca, Anticipated Completion Date: May 2020). (B) The Department will continue to proactively work with the BLM to finalize BLM?s payment review audit and obtain reimbursement for prior years expenditures. The Department has updated policies and procedures relating to cash management and federal reporting to align with BLM requirements (Bradley Duca, May 2020).
2018-043
MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Caseworkers at local counties and MA sites collect required documentation from applicants, including the applicant?s birth certificate, a level-of-care assessment, and support for income and the value of resources, such as bank account balances. The caseworkers enter the applicant-provided data into CBMS in order to determine applicants? eligibility to receive Medicaid benefits. An eligible beneficiary?s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as ?fail? if the applicant?s reported income exceeds the limit. The eligibility data in CBMS feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2019. During our audit, we reviewed the Department?s Medicaid eligibility internal controls in place during Fiscal Year 2019. In addition, we performed testing on a statistical sample of 125 beneficiaries who were eligible for Medicaid during Fiscal Year 2019 and had a payment made on their behalf to a Medicaid provider between July 1, 2018, and March 31, 2019, to determine whether those individuals? Medicaid eligibility determination was appropriate. In addition, for these 125 beneficiaries, we performed testing to determine whether the individuals had additional payments made on their behalf between April 1, 2019, and June 30, 2019, and whether the individuals were eligible for those payments. Our testing included reviewing the supporting documentation, including the case files, CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers had obtained and maintained the required documents supporting eligibility determinations and annual redeterminations in the case files, performed level-of-care determinations for Home and Community Based Service beneficiaries in a timely manner, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to Medicaid eligibility. During that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2018 audit. STATISTICAL SAMPLING METHODOLOGY. To estimate the proportion of the overall Medicaid benefit payments that were paid to providers on behalf of beneficiaries inappropriately determined as eligible during the period of July 1, 2018, to March 31, 2019, we performed the following procedures: 1 We received from Department staff a listing of all Medicaid payments with a date of service during the period and a listing of all benefit recipients with State ID numbers (ID) who were classified as eligible at any point during the same timeframe. 2 We summarized all Medicaid payments made during this period by ID and eliminated any IDs with no payments. This resulted in a population of $5,054,525,817 in payments made to 1,048,064 unique IDs. 3 From this population, we randomly selected a statistical sample of 125 IDs using Probability-Proportional-to-Size (PPS) sampling with benefit payments totaling $7,598,396 to test for eligibility. The PPS sampling methodology ensured that any individual who was considered eligible and received benefits that were paid from July 1, 2018, through March 31, 2019, had a chance for selection. The chance of selection was greater for those individuals with larger payment amounts made for their benefit. Furthermore, the Medicaid program from which benefits were paid had no bearing on an individual ID?s chances of selection. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? In 32 of the 125 Medicaid case files tested (26 percent), we identified at least one error with each case file. In total, we identified 45 errors within these 32 case files. These errors resulted in a total of $124,012 in known questioned costs for the entire Fiscal Year 2019, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. Questioned cost, as defined in federal regulation [2 CFR 200.84], is ?a cost that is questioned by the auditor? (a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation?? We have identified these questioned costs as known questioned costs that are further defined in federal regulation [2 CFR 200.516] as questioned costs that are specifically identified by the auditor. Based on the results of the statistical sampling testwork, we identified $95,785 in known questioned costs, or misstatements, for the period July 1, 2018, through March 31, 2019. The American Institute of Certified Public Accountants (AICPA) Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and the sample was not representative.? In accordance with this guidance, we projected the known questioned costs from July 1, 2018, through March 31, 2019, to the population, regardless of the details of the nature of the error or the program involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. When these known questioned costs are projected to the population, we estimate with 90 percent confidence that the Department paid at least $80,255,528, but not more than $485,851,363, with projected questioned costs of $283,053,446, on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The projected questioned costs amount of $283,053,446 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $80,255,528 and $485,851,363 and would most likely be close to $283,053,446 in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $80,255,528 and a 5 percent chance the true amount is over $485,851,363. We also estimate with 90 percent confidence that at least 27,878 (2.66 percent) but not more than 107,531 (10.26 percent) beneficiaries in our total population of 1,048,064 are likely ineligible. In addition, we identified $28,227 in known questioned costs paid on behalf of beneficiaries between April 1, 2019, and June 30, 2019. These are known errors that affected beneficiaries? eligibility or adjustments to payments that the Department processed after April 1, 2019, that could not be extrapolated to the population since this was not selected as a statistically valid sample. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: * MISSING CASE DOCUMENTATION. Eleven case files were missing documentation necessary to support the Medicaid eligibility determination including documentation to support resources, such as bank statements or tax documents, and documentation to support identity and/or citizenship, such as birth certificates or other allowable records, as required by federal regulations. Specifically, these case files were missing the birth certificate used as the source for citizenship verification and a level-of-care assessment for 4 days of the fiscal year. These errors resulted in known questioned costs of $8,622. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Federal regulation [42 CFR 441. 352(c)] requires the Department to perform a level-of-care assessment for any individual aged 65 or older who lives in a nursing facility or who might need those services in the near future. A reevaluation of the level-of-care assessment must be performed on an annual basis. * INCOME EXCEEDING THRESHOLD. In one case, the beneficiary?s income information received by the local county or MA site through its interface with other systems was over the income limit set under federal regulation for the entire fiscal year; however, Colorado interChange paid claims on behalf of the beneficiary. As a result, the beneficiary incorrectly received benefits during the fiscal year. These errors resulted in known questioned costs of $11,482. Federal regulation [42 USC 1395w-114a] requires an individual to meet income limits in order to receive Medicaid benefits. Income limits are set based on a threshold of 150 percent of the poverty line. * TRANSFER OF RESOURCES (Comprehensive Services). Medicaid covers certain Comprehensive Services known as ?institutional benefits? that are authorized under the Social Security Act. Examples of these services include hospital services, nursing facility services, inpatient psychiatric services for individuals under the age of 21, and services for individuals aged 65 and older who reside in an institution for mental diseases. A beneficiary receiving these services is referred to as an ?institutionalized individual? and the spouse of this beneficiary, who is not receiving these Comprehensive Services, is referred to as the ?community spouse.? In one case, the caseworker did not ensure that the beneficiary, as an institutionalized individual in a medical facility, transferred resources such as the bank account balance to the individual?s community spouse, as required by the state regulation. As a result, the beneficiary?s income was over the resource limit and the beneficiary should not have received Medicaid benefits during the fiscal year. These errors resulted in known questioned costs of $86,365. State regulation [10 CCR 2505-10 8.100.7.M.3] requires the institutionalized individual to complete the transfer of resources to the individual?s community spouse as soon as possible but no later than the individual?s next annual eligibility redetermination. If the transfer is not completed within the required timeframe, the resources shall be attributed to the institutionalized individual and shall affect his/her Medical Assistance eligibility. * INCOME VERIFICATION. In two cases, the caseworker failed to obtain and/or maintain adequate supporting documentation, such as a ledger, to ensure that the self-employment income reported on the application by the beneficiary was appropriately verified, as required by the state regulation. These errors resulted in known questioned costs of $17,543. State regulation [10 CCR 2505-10 8.100.5.B.1.c.i] requires the caseworker to verify an applicant?s self-employment income either through self-employment ledgers or receipts when a ledger is not available. * UNTIMELY REDETERMINATION PROCESS. In two cases, the redetermination process was not performed in a timely manner. Specifically, in one case, the beneficiary?s continuous eligibility was not terminated after the 12-month period, as required by state regulation, and the Department failed to send a redetermination form to the beneficiary and redetermine his or her eligibility for Medicaid once every 12 months, as required. Continuous eligibility provides Medicaid-eligible children with up to 12 months of continuous coverage through Medicaid, regardless of changes in the family's circumstances, such as changes to household income or household size. The beneficiary?s continuous eligibility was in place from September 2016 through November 2019, or 26 months more than the 12-month allowed timeframe. This error did not result in any additional known questioned costs. In another case, the caseworker processed the redetermination a month after the federally-required 12-month period. No questioned costs were identified for this instance because processing time did not affect the beneficiary?s eligibility. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. State regulation [10 CCR 2505-10 8.100.3.P.4] requires the caseworker to mail a redetermination form, approved by the Department, at least 30 days prior to the first of the month in which the eligibility redetermination is due. State regulation [10 CCR 2505-10 8.100.3.Q.1] requires the Department to apply continuous eligibility for up to 12 months to children under the age of 19 who are found eligible for a Medical Assistance program through an eligibility determination, reassessment, or redetermination. * DATA ENTRY. In 20 cases, the information in CBMS did not match the supporting documentation in the case file due to caseworker error. Specifically, in 19 cases, the caseworker entered either the incorrect income and/or resource amount in CBMS. In the last case, the caseworker entered the incorrect name in CBMS. No questioned costs were identified in these instances because they did not negatively affect the beneficiaries? eligibility. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. * INCORRECT INCOME. We identified the following issues: ? In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker included income that should have been excluded for determining eligibility, and in the remaining case, the caseworker excluded income when it should have been included for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within income guidelines. Federal regulation [42 USC 1395w-114a] requires an individual to meet income limits in order to receive Medicaid benefits. Income limits are set based on a threshold of 150 percent of the poverty line. ? In two cases, the caseworker initially applied the Community Spouse Resource Allowance (CSRA) limit in accordance with the state regulation to determine eligibility. CSRA is the amount of resources that the community spouse can retain to allow the beneficiary to qualify for Medicaid eligibility. However, at the annual renewal, the caseworker used the incorrect CSRA limit to determine eligibility. We did not identify any questioned costs or any inappropriate payments made to providers for these beneficiaries during the time period audited. State regulation [10 CCR 2505-10 8.100.7.M] requires the caseworker to apply the CSRA for an institutionalized individual who is over the resource limit set by state regulation [10 CCR 2505-10 8.100.5.M.1]. The transfer of the CSRA shall be completed as soon as possible but no later than their annual renewal to transfer. ? In one case, the caseworker did not use the beneficiary?s most currently reported and verified income to redetermine eligibility; instead, the caseworker used the beneficiary?s income from prior months. No questioned costs were identified in this instance because the beneficiary?s income was still within income guidelines. State regulation [10 CCR 2505-10 8.100.5.F.2] requires the caseworker to use either the income amount which is received by an individual or family in the month in which they are applying for benefits, or the income amount from the previous month if the income for the current month is not yet available. *HOUSEHOLD COMPOSITION. In one case, the Department used the incorrect household composition count to determine eligibility. No questioned costs were identified in this instance because the incorrect household composition did not negatively affect eligibility. State regulation [10 CCR 2505-10 8.100.4.E] defines household composition based on the beneficiary?s tax filing status (for example, single, married filing jointly, or tax dependent). The caseworker uses the applicable tax filing status to determine household composition and eligibility for the Medicaid program. * NURSING FACILITY INAPPROPRIATE TERMINATION OF BENEFITS (Home and Community Based Service waiver programs). These programs allow eligible individuals to remain in their own home or live in a community setting while receiving medical care. In two instances within one case, the beneficiary?s Medicaid benefits were incorrectly terminated for two programs at two different times during Fiscal Year 2019 and the beneficiary was inappropriately moved to a different Medicaid program. No questioned costs were identified in these instances because there was no impact to the beneficiaries? overall Medicaid eligibility. * MEDICAID ELIGIBILITY QUALITY REVIEW REPORT. Local counties and MA sites are required to perform their own quality reviews of Medicaid eligibility case files and submit their quality review reports to the Department on a quarterly basis. The Department did not ensure that quality review reports were submitted as required during Fiscal Year 2019. Specifically, we identified that local counties and MA sites did not submit 50 quarterly reports, submitted 22 reports late, and submitted seven incomplete reports. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of Medicaid eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal Medicaid eligibility requirements during Fiscal Year 2019. Specifically, we noted the following causes for the errors we identified: * TRAINING. The Department did not adequately train local counties and MA sites on issues specifically identified in our audits to ensure that the required documentation to support eligibility was maintained within the case file, information in CBMS was updated in a timely manner, income was verified to the supporting documentation, redeterminations were performed in a timely manner, resources were transferred appropriately, information was entered correctly into CBMS, benefits were terminated appropriately, and beneficiaries were enrolled in the correct Medicaid program. Although the Department provided various trainings to county and MA staff during the fiscal year, as confirmed by our audit work, the training was not effective in ensuring that eligibility determinations were consistently appropriate. * MONITORING AND REVIEWS. The Department did not adequately monitor local counties and MA sites to ensure that their Medicaid eligibility determinations were appropriate and supported with adequate documentation. Specifically, the Department did not ensure that quality review reports from local counties and MA sites were submitted on a quarterly basis as required by the Department procedures during Fiscal Year 2019 and did not have a formal, documented process in place to take corrective actions against local counties and MA sites for late, missing, or incomplete quarterly reports. Additionally, the Department reported that they experienced staff turnover and, therefore, did not review any of the quarterly reports submitted by local counties and MA sites for Fiscal Year 2019. * SYSTEM ISSUES. The Department had not ensured that CBMS uses income information appropriately to determine eligibility. Specifically: ? The system check within CBMS did not mark eligibility as ?fail? when the beneficiary?s income exceeded the federal income limit. ? The Department reported that CBMS had programming issues that caused it to fail to update the CSRA limit amount once the transfer period of 1 year of comprehensive benefits had ended. ? The system check within CBMS did not alert the caseworker when the beneficiary?s 12-month continuous eligibility ended or when the redetermination process was required, in accordance with federal regulations. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $124,012 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over, and ensure it complies with, state and federal regulations for Medicaid by: A Providing adequate training to local counties and Medical Assistance (MA) sites to ensure that caseworkers are updating information in the Colorado Benefits Management System (CBMS) in a timely manner, maintaining the required documentation to support eligibility, entering information correctly into CBMS, verifying income to the supporting documentation, performing redeterminations on a timely basis, transferring resources appropriately, terminating benefits appropriately, and enrolling beneficiaries in the correct Medicaid program. The training should focus on and target local counties and MA sites with issues identified in the audit. B Reinstituting a monitoring process over local counties and MA sites to ensure that the Medicaid eligibility quarterly review reports are submitted in a timely manner, including establishing a formal documented process for corrective actions that must be taken against local counties and MA sites that fail to submit review reports on a timely basis, as required; and ensuring that Department staff perform reviews of the MA site- and local county-submitted review reports and perform follow-ups, as appropriate. C Researching and resolving CBMS system issues to ensure that it is appropriately marking eligibility as ?fail? when the beneficiary?s reported income exceeds the federal income limit, fixing programming issues to update the Community Spouse Resource Allowance limit amount once the transfer period of 1 year of comprehensive benefits has ended, and alerting the caseworker when the 12 month continuous eligibility ends and the redetermination process begins. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to provide these findings to the CBMS training team, which already has intensive training available to caseworkers, and these findings have been sent to the counties with findings. In addition, the Department is implementing a new county oversight and accountability model for eligibility determinations that is targeted to begin by July 2020. The implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. Regarding the extrapolation calculation, the Department agrees with the statement made by auditors within the report that the Projected Likely Questioned Costs are a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific over expenditures of state General Funds or federal funds that can be recovered or potential budget savings. The Department has concerns that the extrapolation calculation result is significantly biased upwards due to sampling criteria and an over sampling of high cost claims relative to the total Medicaid population. In addition, the Department cannot validate the extrapolation calculation or result. The Department is working with our actuaries to provide alternatives to the auditors on how to sample Medicaid cases. Further, once the errors identified in this audit are resolved, the vast majority of individuals remain eligible for Medicaid; the true error rate is significantly lower at 3%. AUDITOR?S ADDENDUM: Generally accepted government auditing standards (GAGAS) [paragraph 3.18], requires that, ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that, ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and sampling methods be made without department influence or persuasion. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to reinstitute a monitoring process by implementing a new eligibility site oversight and accountability model for eligibility determinations. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: * Enhancing county administration rules to improve county accountability; * Changing quality review method and implementing performance measurements through scorecards; * Implementing management evaluation reviews and providing technical assistance to address issues; and * Implementing changes to quality control processes as dictated by the federal government. This county oversight and accountability model is targeted to begin in FY 2020-21. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve as necessary any CBMS issues related to this recommendation. When the 12 months of continuous eligibility ends, CBMS begins the redetermination process by automatically sending the redetermination packet to the member. When the member returns the packet, the caseworker processes the redetermination to determine eligibility. The Department has reached out to the county identified through this audit to ensure that the yearly redetermination of eligibility is processed timely and if a system issue is found that the county submits the issue to the help desk to be researched and resolved. In addition, the Department has initiated a CBMS project that will ensure that Community Spouse Resource Allowance (CSRA) limit is applied in CBMS with an implementation date by no later than July 2021. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
Show full finding ▾Hide full finding ▴MEDICAID CONTROLS OVER ELIGIBILITY DETERMINATIONS Caseworkers at local counties and MA sites collect required documentation from applicants, including the applicant?s birth certificate, a level-of-care assessment, and support for income and the value of resources, such as bank account balances. The caseworkers enter the applicant-provided data into CBMS in order to determine applicants? eligibility to receive Medicaid benefits. An eligible beneficiary?s income and countable resources cannot exceed a limit set by federal and state regulations. CBMS has a system check to mark eligibility as ?fail? if the applicant?s reported income exceeds the limit. The eligibility data in CBMS feeds into the Colorado interChange system (Colorado interChange), which pays providers for the services that they provide to Medicaid beneficiaries. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to review the Department?s internal controls over the Medicaid eligibility determination process as well as to determine whether the Department complied with applicable federal and state Medicaid eligibility requirements during Fiscal Year 2019. During our audit, we reviewed the Department?s Medicaid eligibility internal controls in place during Fiscal Year 2019. In addition, we performed testing on a statistical sample of 125 beneficiaries who were eligible for Medicaid during Fiscal Year 2019 and had a payment made on their behalf to a Medicaid provider between July 1, 2018, and March 31, 2019, to determine whether those individuals? Medicaid eligibility determination was appropriate. In addition, for these 125 beneficiaries, we performed testing to determine whether the individuals had additional payments made on their behalf between April 1, 2019, and June 30, 2019, and whether the individuals were eligible for those payments. Our testing included reviewing the supporting documentation, including the case files, CBMS data fields related to eligibility determination/redetermination, and Medicaid payment information in Colorado interChange. We performed testwork to determine whether the Department ensured that local county and MA site caseworkers had obtained and maintained the required documents supporting eligibility determinations and annual redeterminations in the case files, performed level-of-care determinations for Home and Community Based Service beneficiaries in a timely manner, correctly entered eligibility data into CBMS, and determined eligibility in a timely manner. We also inquired about the Department?s monitoring procedures over local counties and MA sites that were designed to ensure that eligibility is determined in accordance with federal and state regulations. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to Medicaid eligibility. During that audit, we recommended that the Department strengthen its internal controls over Medicaid by providing adequate training, monitoring local counties and MA sites, and researching and resolving CBMS system issues identified in our Fiscal Year 2018 audit. STATISTICAL SAMPLING METHODOLOGY. To estimate the proportion of the overall Medicaid benefit payments that were paid to providers on behalf of beneficiaries inappropriately determined as eligible during the period of July 1, 2018, to March 31, 2019, we performed the following procedures: 1 We received from Department staff a listing of all Medicaid payments with a date of service during the period and a listing of all benefit recipients with State ID numbers (ID) who were classified as eligible at any point during the same timeframe. 2 We summarized all Medicaid payments made during this period by ID and eliminated any IDs with no payments. This resulted in a population of $5,054,525,817 in payments made to 1,048,064 unique IDs. 3 From this population, we randomly selected a statistical sample of 125 IDs using Probability-Proportional-to-Size (PPS) sampling with benefit payments totaling $7,598,396 to test for eligibility. The PPS sampling methodology ensured that any individual who was considered eligible and received benefits that were paid from July 1, 2018, through March 31, 2019, had a chance for selection. The chance of selection was greater for those individuals with larger payment amounts made for their benefit. Furthermore, the Medicaid program from which benefits were paid had no bearing on an individual ID?s chances of selection. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? In 32 of the 125 Medicaid case files tested (26 percent), we identified at least one error with each case file. In total, we identified 45 errors within these 32 case files. These errors resulted in a total of $124,012 in known questioned costs for the entire Fiscal Year 2019, as shown in the following table. See Schedule of Findings and Questioned Costs for chart/table. Questioned cost, as defined in federal regulation [2 CFR 200.84], is ?a cost that is questioned by the auditor? (a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation?? We have identified these questioned costs as known questioned costs that are further defined in federal regulation [2 CFR 200.516] as questioned costs that are specifically identified by the auditor. Based on the results of the statistical sampling testwork, we identified $95,785 in known questioned costs, or misstatements, for the period July 1, 2018, through March 31, 2019. The American Institute of Certified Public Accountants (AICPA) Audit Sampling, May 1, 2017, Audit Guide [AAG-SAM 4.95] advises, ?Even if the misstatement appears to be from an unusual source, that does not mean that other unusual items are not in the population and the sample was not representative.? In accordance with this guidance, we projected the known questioned costs from July 1, 2018, through March 31, 2019, to the population, regardless of the details of the nature of the error or the program involved, since the Department is ultimately responsible for all payments made to providers on behalf of eligible beneficiaries. When these known questioned costs are projected to the population, we estimate with 90 percent confidence that the Department paid at least $80,255,528, but not more than $485,851,363, with projected questioned costs of $283,053,446, on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The projected questioned costs amount of $283,053,446 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State?s General Fund or federal funds. However, this calculation indicates that if we tested the entire population, there is a 90 percent likelihood of finding the true amount of questioned costs to be between $80,255,528 and $485,851,363 and would most likely be close to $283,053,446 in erroneous payments. There is a 5 percent chance that the true amount of questioned costs is less than $80,255,528 and a 5 percent chance the true amount is over $485,851,363. We also estimate with 90 percent confidence that at least 27,878 (2.66 percent) but not more than 107,531 (10.26 percent) beneficiaries in our total population of 1,048,064 are likely ineligible. In addition, we identified $28,227 in known questioned costs paid on behalf of beneficiaries between April 1, 2019, and June 30, 2019. These are known errors that affected beneficiaries? eligibility or adjustments to payments that the Department processed after April 1, 2019, that could not be extrapolated to the population since this was not selected as a statistically valid sample. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for chart/table. DETAILS OF ERRORS IDENTIFIED. In some case files, we identified multiple instances of errors. Specifically, we found the following: * MISSING CASE DOCUMENTATION. Eleven case files were missing documentation necessary to support the Medicaid eligibility determination including documentation to support resources, such as bank statements or tax documents, and documentation to support identity and/or citizenship, such as birth certificates or other allowable records, as required by federal regulations. Specifically, these case files were missing the birth certificate used as the source for citizenship verification and a level-of-care assessment for 4 days of the fiscal year. These errors resulted in known questioned costs of $8,622. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. State regulation [10 CCR 2505-10 8.100.3.G.1.g] requires all individuals who apply for Medicaid to be either a citizen of the United States or its Territories, or be a qualified non-citizen. Citizenship or nationality along with identity status must be verified unless satisfactory documentary evidence has already been provided. Federal regulation [42 CFR 441. 352(c)] requires the Department to perform a level-of-care assessment for any individual aged 65 or older who lives in a nursing facility or who might need those services in the near future. A reevaluation of the level-of-care assessment must be performed on an annual basis. * INCOME EXCEEDING THRESHOLD. In one case, the beneficiary?s income information received by the local county or MA site through its interface with other systems was over the income limit set under federal regulation for the entire fiscal year; however, Colorado interChange paid claims on behalf of the beneficiary. As a result, the beneficiary incorrectly received benefits during the fiscal year. These errors resulted in known questioned costs of $11,482. Federal regulation [42 USC 1395w-114a] requires an individual to meet income limits in order to receive Medicaid benefits. Income limits are set based on a threshold of 150 percent of the poverty line. * TRANSFER OF RESOURCES (Comprehensive Services). Medicaid covers certain Comprehensive Services known as ?institutional benefits? that are authorized under the Social Security Act. Examples of these services include hospital services, nursing facility services, inpatient psychiatric services for individuals under the age of 21, and services for individuals aged 65 and older who reside in an institution for mental diseases. A beneficiary receiving these services is referred to as an ?institutionalized individual? and the spouse of this beneficiary, who is not receiving these Comprehensive Services, is referred to as the ?community spouse.? In one case, the caseworker did not ensure that the beneficiary, as an institutionalized individual in a medical facility, transferred resources such as the bank account balance to the individual?s community spouse, as required by the state regulation. As a result, the beneficiary?s income was over the resource limit and the beneficiary should not have received Medicaid benefits during the fiscal year. These errors resulted in known questioned costs of $86,365. State regulation [10 CCR 2505-10 8.100.7.M.3] requires the institutionalized individual to complete the transfer of resources to the individual?s community spouse as soon as possible but no later than the individual?s next annual eligibility redetermination. If the transfer is not completed within the required timeframe, the resources shall be attributed to the institutionalized individual and shall affect his/her Medical Assistance eligibility. * INCOME VERIFICATION. In two cases, the caseworker failed to obtain and/or maintain adequate supporting documentation, such as a ledger, to ensure that the self-employment income reported on the application by the beneficiary was appropriately verified, as required by the state regulation. These errors resulted in known questioned costs of $17,543. State regulation [10 CCR 2505-10 8.100.5.B.1.c.i] requires the caseworker to verify an applicant?s self-employment income either through self-employment ledgers or receipts when a ledger is not available. * UNTIMELY REDETERMINATION PROCESS. In two cases, the redetermination process was not performed in a timely manner. Specifically, in one case, the beneficiary?s continuous eligibility was not terminated after the 12-month period, as required by state regulation, and the Department failed to send a redetermination form to the beneficiary and redetermine his or her eligibility for Medicaid once every 12 months, as required. Continuous eligibility provides Medicaid-eligible children with up to 12 months of continuous coverage through Medicaid, regardless of changes in the family's circumstances, such as changes to household income or household size. The beneficiary?s continuous eligibility was in place from September 2016 through November 2019, or 26 months more than the 12-month allowed timeframe. This error did not result in any additional known questioned costs. In another case, the caseworker processed the redetermination a month after the federally-required 12-month period. No questioned costs were identified for this instance because processing time did not affect the beneficiary?s eligibility. Federal regulation [42 CFR 435.916(a)] requires the Department to renew or redetermine Medicaid eligibility once every 12 months but no more frequently than once every 12 months. State regulation [10 CCR 2505-10 8.100.3.P.4] requires the caseworker to mail a redetermination form, approved by the Department, at least 30 days prior to the first of the month in which the eligibility redetermination is due. State regulation [10 CCR 2505-10 8.100.3.Q.1] requires the Department to apply continuous eligibility for up to 12 months to children under the age of 19 who are found eligible for a Medical Assistance program through an eligibility determination, reassessment, or redetermination. * DATA ENTRY. In 20 cases, the information in CBMS did not match the supporting documentation in the case file due to caseworker error. Specifically, in 19 cases, the caseworker entered either the incorrect income and/or resource amount in CBMS. In the last case, the caseworker entered the incorrect name in CBMS. No questioned costs were identified in these instances because they did not negatively affect the beneficiaries? eligibility. Federal regulation [42 CFR 435.914] requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. * INCORRECT INCOME. We identified the following issues: ? In three cases, the caseworker used the incorrect income amount to determine eligibility. Specifically, in two cases, the caseworker included income that should have been excluded for determining eligibility, and in the remaining case, the caseworker excluded income when it should have been included for determining eligibility. No questioned costs were identified in these instances because the beneficiaries? income was still within income guidelines. Federal regulation [42 USC 1395w-114a] requires an individual to meet income limits in order to receive Medicaid benefits. Income limits are set based on a threshold of 150 percent of the poverty line. ? In two cases, the caseworker initially applied the Community Spouse Resource Allowance (CSRA) limit in accordance with the state regulation to determine eligibility. CSRA is the amount of resources that the community spouse can retain to allow the beneficiary to qualify for Medicaid eligibility. However, at the annual renewal, the caseworker used the incorrect CSRA limit to determine eligibility. We did not identify any questioned costs or any inappropriate payments made to providers for these beneficiaries during the time period audited. State regulation [10 CCR 2505-10 8.100.7.M] requires the caseworker to apply the CSRA for an institutionalized individual who is over the resource limit set by state regulation [10 CCR 2505-10 8.100.5.M.1]. The transfer of the CSRA shall be completed as soon as possible but no later than their annual renewal to transfer. ? In one case, the caseworker did not use the beneficiary?s most currently reported and verified income to redetermine eligibility; instead, the caseworker used the beneficiary?s income from prior months. No questioned costs were identified in this instance because the beneficiary?s income was still within income guidelines. State regulation [10 CCR 2505-10 8.100.5.F.2] requires the caseworker to use either the income amount which is received by an individual or family in the month in which they are applying for benefits, or the income amount from the previous month if the income for the current month is not yet available. *HOUSEHOLD COMPOSITION. In one case, the Department used the incorrect household composition count to determine eligibility. No questioned costs were identified in this instance because the incorrect household composition did not negatively affect eligibility. State regulation [10 CCR 2505-10 8.100.4.E] defines household composition based on the beneficiary?s tax filing status (for example, single, married filing jointly, or tax dependent). The caseworker uses the applicable tax filing status to determine household composition and eligibility for the Medicaid program. * NURSING FACILITY INAPPROPRIATE TERMINATION OF BENEFITS (Home and Community Based Service waiver programs). These programs allow eligible individuals to remain in their own home or live in a community setting while receiving medical care. In two instances within one case, the beneficiary?s Medicaid benefits were incorrectly terminated for two programs at two different times during Fiscal Year 2019 and the beneficiary was inappropriately moved to a different Medicaid program. No questioned costs were identified in these instances because there was no impact to the beneficiaries? overall Medicaid eligibility. * MEDICAID ELIGIBILITY QUALITY REVIEW REPORT. Local counties and MA sites are required to perform their own quality reviews of Medicaid eligibility case files and submit their quality review reports to the Department on a quarterly basis. The Department did not ensure that quality review reports were submitted as required during Fiscal Year 2019. Specifically, we identified that local counties and MA sites did not submit 50 quarterly reports, submitted 22 reports late, and submitted seven incomplete reports. Department procedures require local counties and MA sites to compile and submit the results of their own quality reviews of Medicaid eligibility case files to the Department on a quarterly basis. In addition, local counties and MA sites that do not submit their quality review reports on a timely basis are subject to corrective action. WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal Medicaid eligibility requirements during Fiscal Year 2019. Specifically, we noted the following causes for the errors we identified: * TRAINING. The Department did not adequately train local counties and MA sites on issues specifically identified in our audits to ensure that the required documentation to support eligibility was maintained within the case file, information in CBMS was updated in a timely manner, income was verified to the supporting documentation, redeterminations were performed in a timely manner, resources were transferred appropriately, information was entered correctly into CBMS, benefits were terminated appropriately, and beneficiaries were enrolled in the correct Medicaid program. Although the Department provided various trainings to county and MA staff during the fiscal year, as confirmed by our audit work, the training was not effective in ensuring that eligibility determinations were consistently appropriate. * MONITORING AND REVIEWS. The Department did not adequately monitor local counties and MA sites to ensure that their Medicaid eligibility determinations were appropriate and supported with adequate documentation. Specifically, the Department did not ensure that quality review reports from local counties and MA sites were submitted on a quarterly basis as required by the Department procedures during Fiscal Year 2019 and did not have a formal, documented process in place to take corrective actions against local counties and MA sites for late, missing, or incomplete quarterly reports. Additionally, the Department reported that they experienced staff turnover and, therefore, did not review any of the quarterly reports submitted by local counties and MA sites for Fiscal Year 2019. * SYSTEM ISSUES. The Department had not ensured that CBMS uses income information appropriately to determine eligibility. Specifically: ? The system check within CBMS did not mark eligibility as ?fail? when the beneficiary?s income exceeded the federal income limit. ? The Department reported that CBMS had programming issues that caused it to fail to update the CSRA limit amount once the transfer period of 1 year of comprehensive benefits had ended. ? The system check within CBMS did not alert the caseworker when the beneficiary?s 12-month continuous eligibility ended or when the redetermination process was required, in accordance with federal regulations. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring that inaccurate processing of information used to determine Medicaid eligibility does not result in Medicaid benefits being provided to, and paid on behalf of, ineligible individuals. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $124,012 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-042 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over, and ensure it complies with, state and federal regulations for Medicaid by: A Providing adequate training to local counties and Medical Assistance (MA) sites to ensure that caseworkers are updating information in the Colorado Benefits Management System (CBMS) in a timely manner, maintaining the required documentation to support eligibility, entering information correctly into CBMS, verifying income to the supporting documentation, performing redeterminations on a timely basis, transferring resources appropriately, terminating benefits appropriately, and enrolling beneficiaries in the correct Medicaid program. The training should focus on and target local counties and MA sites with issues identified in the audit. B Reinstituting a monitoring process over local counties and MA sites to ensure that the Medicaid eligibility quarterly review reports are submitted in a timely manner, including establishing a formal documented process for corrective actions that must be taken against local counties and MA sites that fail to submit review reports on a timely basis, as required; and ensuring that Department staff perform reviews of the MA site- and local county-submitted review reports and perform follow-ups, as appropriate. C Researching and resolving CBMS system issues to ensure that it is appropriately marking eligibility as ?fail? when the beneficiary?s reported income exceeds the federal income limit, fixing programming issues to update the Community Spouse Resource Allowance limit amount once the transfer period of 1 year of comprehensive benefits has ended, and alerting the caseworker when the 12 month continuous eligibility ends and the redetermination process begins. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to provide these findings to the CBMS training team, which already has intensive training available to caseworkers, and these findings have been sent to the counties with findings. In addition, the Department is implementing a new county oversight and accountability model for eligibility determinations that is targeted to begin by July 2020. The implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. Regarding the extrapolation calculation, the Department agrees with the statement made by auditors within the report that the Projected Likely Questioned Costs are a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific over expenditures of state General Funds or federal funds that can be recovered or potential budget savings. The Department has concerns that the extrapolation calculation result is significantly biased upwards due to sampling criteria and an over sampling of high cost claims relative to the total Medicaid population. In addition, the Department cannot validate the extrapolation calculation or result. The Department is working with our actuaries to provide alternatives to the auditors on how to sample Medicaid cases. Further, once the errors identified in this audit are resolved, the vast majority of individuals remain eligible for Medicaid; the true error rate is significantly lower at 3%. AUDITOR?S ADDENDUM: Generally accepted government auditing standards (GAGAS) [paragraph 3.18], requires that, ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that, ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and sampling methods be made without department influence or persuasion. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to reinstitute a monitoring process by implementing a new eligibility site oversight and accountability model for eligibility determinations. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: * Enhancing county administration rules to improve county accountability; * Changing quality review method and implementing performance measurements through scorecards; * Implementing management evaluation reviews and providing technical assistance to address issues; and * Implementing changes to quality control processes as dictated by the federal government. This county oversight and accountability model is targeted to begin in FY 2020-21. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve as necessary any CBMS issues related to this recommendation. When the 12 months of continuous eligibility ends, CBMS begins the redetermination process by automatically sending the redetermination packet to the member. When the member returns the packet, the caseworker processes the redetermination to determine eligibility. The Department has reached out to the county identified through this audit to ensure that the yearly redetermination of eligibility is processed timely and if a system issue is found that the county submits the issue to the help desk to be researched and resolved. In addition, the Department has initiated a CBMS project that will ensure that Community Spouse Resource Allowance (CSRA) limit is applied in CBMS with an implementation date by no later than July 2021. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
(A) The Department agrees to provide these findings to the CBMS training team, which already has intensive training available to caseworkers, and these findings have been sent to the counties with findings. In addition, the Department is implementing a new county oversight and accountability model for eligibility determinations that is targeted to begin by July 2020. The implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. Regarding the extrapolation calculation, the Department agrees with the statement made by auditors within the report that the Projected Likely Questioned Costs are a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific over expenditures of state General Funds or federal funds that can be recovered or potential budget savings. The Department has concerns that the extrapolation calculation result is significantly biased upwards due to sampling criteria and an over sampling of high cost claims relative to the total Medicaid population. In addition, the Department cannot validate the extrapolation calculation or result. The Department is working with our actuaries to provide alternatives to the auditors on how to sample Medicaid cases. Further, once the errors identified in this audit are resolved, the vast majority of individuals remain eligible for Medicaid; the true error rate is significantly lower at 3% (Donna Kellow, Greg Tanner, July 2021). (B) The Department agrees to reinstitute a monitoring process by implementing a new eligibility site oversight and accountability model for eligibility determinations. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: - Enhancing county administration rules to improve county accountability; - Changing quality review method and implementing performance measurements through scorecards; - Implementing management evaluation reviews and providing technical assistance to address issues; and - Implementing changes to quality control processes as dictated by the federal government. This county oversight and accountability model is targeted to begin in FY 2020-21. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021). (C) The Department agrees to research and resolve as necessary any CBMS issues related to this recommendation. When the 12 months of continuous eligibility ends, CBMS begins the redetermination process by automatically sending the redetermination packet to the member. When the member returns the packet, the caseworker processes the redetermination to determine eligibility. The Department has reached out to the county identified through this audit to ensure that the yearly redetermination of eligibility is processed timely and if a system issue is found that the county submits the issue to the help desk to be researched and resolved. In addition, the Department has initiated a CBMS project that will ensure that Community Spouse Resource Allowance (CSRA) limit is applied in CBMS with an implementation date by no later than July 2021. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021).
2018-044
MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: * Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. * Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. * Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: * CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. * SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. * LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $2,285,757 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Show full finding ▾Hide full finding ▴MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: * Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. * Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. * Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: * CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. * SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. * LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $2,285,757 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-044A, 2018-044B, AND 2018-044C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
(A) The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022 (Donna Kellow, Greg Tanner, July 2022). (B) The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021). (C) The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021 (Donna Kellow, Greg Tanner, July 2021). (D) The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process (Donna Kellow, Greg Tanner, N/A).
2018-044
MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: * In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. * In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for the table. The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments. WHY DID THESE PROBLEMS OCCUR? Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries. After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute. WHY DO THESE PROBLEMS MATTER? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $181,320 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-045A * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-044 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by: A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B Identifying and correcting any additional cases affected by the system issues noted in our audit. C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
Show full finding ▾Hide full finding ▴MEDICAID CLAIMS PAYMENTS Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid claims payment process in place during Fiscal Year 2019 to determine whether payments were only made on behalf of eligible beneficiaries and whether the Department complied with applicable federal and state requirements during Fiscal Year 2019. During our audit, we obtained a list of all individuals who were noted as eligible for Medicaid in Colorado interChange from July 1, 2018, through March 31, 2019. We also obtained a list of all Medicaid claims that were submitted and paid by the Department from July 1, 2018, through March 31, 2019. We compared these two listings and identified 907 beneficiaries that did not appear on the Department?s Medicaid eligibility listing but had approximately $2.1 million in payments made on their behalf during the fiscal year. We randomly selected a statistical sample of 20 beneficiaries out of the 907 beneficiaries to determine whether these individuals were eligible for Medicaid during the timeframe and whether approximately $639,000 in payments made on their behalf during Fiscal Year 2019 were allowable under federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. Federal regulation [2 CFR 200.53, Improper Payment] defines an improper payment as a payment that ?should not have been made or that was made in an incorrect amount.? This includes any payments made to, or on behalf of, an individual who is not eligible to receive these payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable. These overpayments ?shall be recoverable regardless of whether the overpayment is the result of an error by the state department, a county department of social services, an entity acting on behalf of either department, or by the provider or any agent of the provider.? Section 25.5-4-301(2)(a)(II), C.R.S., further states that, ?If the state department makes a determination that such overpayment has been made for some other reason than a false representation by the provider?, the state department may collect the amount of overpayment, plus interest accruing at the statutory rate from the date the provider is notified of such overpayment?. Pursuant to the criteria established in rules promulgated by the state board, the state department may waive the recovery or adjustment of all or part of the overpayment and accrued interest specified in this subparagraph (II) if it would be inequitable, uncollectible or administratively impracticable?? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department made payments to providers on behalf of beneficiaries who were deemed ineligible for Medicaid at the time services were provided. Specifically, in 10 of the 20 samples tested (50 percent), the Department inappropriately paid providers $181,320 for services provided to the individuals even though they were not eligible for Medicaid; $90,660 of these costs were paid with federal grant funds, as follows: * In nine cases, CBMS indicated that the individuals were not eligible for benefits; however, Colorado interChange indicated that the individuals were eligible and paid claims for the cases totaling $160,289. * In one case, TRAILS indicated that the individual was not eligible for benefits; however, Colorado interChange indicated that the individual was eligible and paid claims for the cases totaling $21,031. These errors resulted in a total of $181,320 in known questioned costs for the entire Fiscal Year 2019, and includes $171,559 in known questioned costs for the period July 1, 2018, through March 31, 2019, that were subjected to statistical sampling. When $171,559 in known questioned costs are projected to the population, we estimate, with 90 percent confidence, that the Department paid at least $619,829 but not more than $1,394,464, with projected questioned costs of $1,007,146 on behalf of ineligible beneficiaries between July 1, 2018, and March 31, 2019. The following table demonstrates the known and likely questioned costs. See Schedule of Findings and Questioned Costs for the table. The projected questioned costs amount of $1,007,146 is based on a mathematical calculation of costs that does not correlate to specific payments made to providers. This does not result in specific overexpenditures of the State General Fund or federal funds. However, this calculation indicates that if we tested the entire population, we would have a 90 percent likelihood of finding approximately $1,007,146 in erroneous payments. WHY DID THESE PROBLEMS OCCUR? Overall, the Department had system interface issues between CBMS, TRAILS, and Colorado interChange during Fiscal Year 2019. In addition, the Department lacked adequate internal controls in place to ensure that Medicaid claims were appropriately paid only on behalf of eligible beneficiaries. After we brought these payment errors to the Department?s attention, they conducted additional research and reported that the daily interfaces between CBMS and Colorado interchange, and between TRAILS and Colorado interchange, were not working appropriately. The Department indicated that, as a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department manually corrected the eligibility status of these beneficiaries from eligible to ineligible to stop any further payments. As of the end of our audit, the Department reported that it had not fully researched the errors or identified and corrected all of the cases affected by the errors. The Department had not determined if any of the overpayments to providers on behalf of ineligible beneficiaries noted in this audit were recoverable and, therefore, did not collect the overpayments in accordance with state statute. WHY DO THESE PROBLEMS MATTER? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778*, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $181,320 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-045A * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-044 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid claims payments by: A Researching and resolving the Colorado Benefits Management System, TRAILS, and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B Identifying and correcting any additional cases affected by the system issues noted in our audit. C Determining if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with state statute. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22.
(A) The Department agrees to research and resolve Colorado Benefits Management System (CBMS), Trails, and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021). (B) The Department agrees to identify and correct any additional cases affected by the system issues noted in the audit. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to caseworkers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021). (C) Department agrees to determine if any of the overpayments made to providers on behalf of ineligible beneficiaries noted through the audit are recoverable and, if so, collect them in accordance with the state regulation. The Department will seek recoveries if any of these cases resulted in identifiable fraud by the provider. As this time, the Department has determined that these beneficiaries were displayed as eligible when the provider checked the beneficiaries' eligibility status. Therefore, Department will waive the recovery as such action would be inequitable to the providers and administratively impracticable by the Department as allowed under state law. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22 (Donna Kellow, Greg Tanner, July 2021).
2018-045
MEDICAID ELIGIBILITY?DUPLICATE SSNS AND STATE IDS The beneficiary?s application includes information, such as an SSN, birth certificate, and support for their income. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, each beneficiary in CBMS is assigned a unique State ID by a separate system managed by OIT. CBMS interfaces with Colorado interchange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over the Medicaid eligibility determination process during Fiscal Year 2019, including controls to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN in CBMS. During our audit, we requested a list of all Medicaid claims that were submitted and paid for medical services from July 1, 2018, through March 31, 2019, including the beneficiaries? names, SSNs, and State IDs. This list included approximately 1.1 million beneficiaries who had received benefits during the time period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN, and to determine if any claims payments were made on behalf of any such beneficiaries during Fiscal Year 2019. In addition, we analyzed the list of these Medicaid claims payments provided by the Department from Colorado interChange to identify any claims payments made on behalf of different beneficiary?s names with the same State ID and date of birth during Fiscal Year 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish his or her SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 131 instances in which 262 Medicaid claims payments in Colorado interChange were made on behalf of beneficiaries with the same SSN but a different State ID. In 67 of these instances, the beneficiaries had the same SSN and same name and in the remaining 64 instances, the beneficiaries had the same SSN but different names. In all 131 instances, the same SSN was linked to two different State IDs in Colorado interChange. See Schedule of Findings and Questioned Costs for chart. All of these cases were active and associated with claims paid through Colorado interChange from July 1, 2018, through March 31, 2019. We selected a random sample of 10 SSNs from 131 instances with multiple State IDs and determined that each of the 10 were associated with two individuals with either different names, genders, and/or dates of birth. These issues affected a total of 262 Medicaid cases representing 262 Medicaid claims payments totaling $53,171 from July 1, 2018, through March 31, 2019. We identified 118 additional claims that were paid on behalf of 62 different beneficiary names using the same State ID and date of birth combination. We specifically noted that 33 different providers submitted 118 separate claims to the Department for this State ID/SSN/date of birth on behalf of 62 different individuals with different names and genders during Fiscal Year 2019. The providers were paid a total of $16,678 for the claims during Fiscal Year 2019. For example, one claim of $226 was submitted and paid for an individual named ?A Test.? See Schedule of Findings and Questioned Costs for chart. As of the end of our audit, the Department was researching whether these 262 Medicaid cases of duplicate SSNs and State IDs that we identified, as well as the 118 claims paid under 62 different names with one State ID, were eligible for the services provided and that the payments were appropriate. Because of the issues noted above, at the time of our audit, we were unable to determine whether the payments were made on behalf of eligible Medicaid beneficiaries and therefore, consider all $69,849 of the payments to be known questioned costs; $34,925 of these costs were paid with federal grant funds. For the purposes of identifying and quantifying these amounts, we have applied the following definition included in our audit requirements: Questioned cost, as defined in Uniform Guidance [2 CFR 200.84], is ?a cost that is questioned by the auditor?(a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation...? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [2 CFR 200.516] as questioned costs that are specifically identified by the auditor. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2019 to prevent or detect instances of duplicate SSNs and/or multiple State IDs in CBMS and Colorado interChange, as noted: * CBMS ALLOWED DUPLICATE SSNS AND MULTIPLE STATE IDS. CBMS allowed caseworkers to create more than one case for a Medicaid beneficiary; as a result, an individual beneficiary could be assigned more than one State ID in CBMS and the multiple State IDs wre uploaded to Colorado interChange and treated as two separate accounts with the ability to have claims paid against them. Furthermore, the Department reported that CBMS did not have a system edit check that would flag for review and disallow the same SSNs or multiple State IDs for the same SSN. * LACK OF TRAINING, MONITORING, AND REVIEW. The Department did not monitor and effectively train local county and MA site caseworkers regarding identifying and merging multiple State IDs for the same beneficiary in CBMS. Department staff reported that they did not have a monitoring process in place to review the data in CBMS to ensure that local counties and MA sites were properly identifying, investigating, and merging multiple State IDs for the same beneficiary. Furthermore, the Department did not have an effective review process to analyze CBMS data to identify multiple State IDs and duplicate SSNs and remove them appropriately. * INEFFECTIVE PAYMENT VERIFICATION PROCESS. The Department, through Colorado interChange, used only State ID and date of birth field matches to verify a beneficiary for claims payments. As a result, Colorado interChange was making payments on behalf of an eligible Medicaid beneficiary for individuals whose names differed from the eligible beneficiary. Based on our follow-up discussions with the Department, they indicated that it would be inefficient to verify claims using the name fields because the names could change during the year; however, in order to avoid the improper payment of Medicaid claims, the Department needed to develop a more effective beneficiary payment verification process in Colorado interChange to ensure that payments were not made on behalf of multiple individuals using the same State ID and date of birth. After we brought this to the Department?s attention, they began to review and investigate these claims for overpayments. WHY DO THESE PROBLEMS MATTER? Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the local counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, such as system edit functions, effective ongoing staff training, and reviewing the local counties and MA sites; the State cannot substantiate that eligibility determinations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. If an eligible individual has more than one State ID, providers could fraudulently submit duplicate claims under these IDs for the same services resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $69,849 THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-045 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Working with the Department of Human Services and Governor?s Office of Information Technology, as appropriate, to evaluate and institute, if feasible, a system check within Colorado Benefits Management System (CBMS) to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. B Improving the effectiveness of training and monitoring of the local counties and Medical Assistance (MA) sites to ensure that caseworkers are not creating new cases when they are attempting to update a beneficiary?s information to an already existing case file. This should include focused training for the local counties and MA sites on identifying and merging any duplicate case files existing within CBMS. C Working with the Department of Human Services, as appropriate, to evaluate and develop, if feasible, an effective beneficiary payment verification process in Colorado interChange to ensure that payments are not made on behalf of multiple individuals using the same State ID and date of birth. This should include researching the claims payments that were identified during our audit to determine whether or not these were appropriate payments in accordance with federal regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to work with the Governor's Office of Information Technology (OIT) on the feasibility of instituting a system check within CBMS to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. Since CBMS is a shared system between the Department and the Department of Human Services, and that State IDs are generated by a separate system managed by OIT, the Department cannot guarantee that specific system checks as prescribed through this audit recommendation can be implemented and the timeline to implement a related system change is unknown. Therefore, the Department can agree to research on the feasibility, and if feasible, implement a system check by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites on how to merge any duplicate case files existing within CBMS. There are multiple user manuals regarding this process and there are two specific web-based trainings which are both required for all caseworkers. The Department agrees to work with counties to identify any additional training, reporting, or monitoring related to the case file merge process that would be useful to caseworkers. The Department can agree to implement additional training by July 2021. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department's approach to claims editing using State ID and date-of-birth are Medicaid industry standards. The Department can agree to research how other payers edit claims for beneficiary information, such as name or other information that is available on a claim. Further, the Department's ability to modify claims editing based on beneficiary information has the potential to impact third-party claims submitted by other payers such as Medicare. Therefore, the Department cannot modify the Department's claims processing system until that research has been performed. The Department will research and report on the feasibility, and if feasible, implement any system change by July 2021. In addition, the Department agrees to research the claims payments that were identified through the audit to determine whether the payments were appropriate by July 2021.
Show full finding ▾Hide full finding ▴MEDICAID ELIGIBILITY?DUPLICATE SSNS AND STATE IDS The beneficiary?s application includes information, such as an SSN, birth certificate, and support for their income. The local counties and MA sites are responsible for administering the benefits application process, including entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. CBMS is a shared eligibility system between the Department and the Department of Human Services. As each beneficiary has one SSN, similarly, each beneficiary in CBMS is assigned a unique State ID by a separate system managed by OIT. CBMS interfaces with Colorado interchange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. Colorado interChange uses this information to process and pay claims for services provided to eligible Medicaid beneficiaries. When a provider submits a claim to the Department, Colorado interChange checks the State ID and the date of birth submitted with the claim against the beneficiary?s information on file. If the State ID and the date of birth match an eligible beneficiary within Colorado interChange and the claim is otherwise appropriate, then the claim will be processed and paid through the system. Department requires local counties or MA site caseworkers to call the OIT Service Desk to obtain approval for changing or updating an SSN in CBMS. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether the Department had adequate internal controls in place over the Medicaid eligibility determination process during Fiscal Year 2019, including controls to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN in CBMS. During our audit, we requested a list of all Medicaid claims that were submitted and paid for medical services from July 1, 2018, through March 31, 2019, including the beneficiaries? names, SSNs, and State IDs. This list included approximately 1.1 million beneficiaries who had received benefits during the time period. We analyzed this listing to identify any beneficiaries whose SSN was linked to more than one State ID or whose State ID was linked to more than one SSN, and to determine if any claims payments were made on behalf of any such beneficiaries during Fiscal Year 2019. In addition, we analyzed the list of these Medicaid claims payments provided by the Department from Colorado interChange to identify any claims payments made on behalf of different beneficiary?s names with the same State ID and date of birth during Fiscal Year 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 435.910] states that the Department must require, as a condition of eligibility, that each individual (including children) seeking Medicaid services furnish his or her SSN. Federal regulation [42 CFR 435.914] further requires the Department to obtain and maintain documentation to support each beneficiary?s Medicaid eligibility determination. Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 131 instances in which 262 Medicaid claims payments in Colorado interChange were made on behalf of beneficiaries with the same SSN but a different State ID. In 67 of these instances, the beneficiaries had the same SSN and same name and in the remaining 64 instances, the beneficiaries had the same SSN but different names. In all 131 instances, the same SSN was linked to two different State IDs in Colorado interChange. See Schedule of Findings and Questioned Costs for chart. All of these cases were active and associated with claims paid through Colorado interChange from July 1, 2018, through March 31, 2019. We selected a random sample of 10 SSNs from 131 instances with multiple State IDs and determined that each of the 10 were associated with two individuals with either different names, genders, and/or dates of birth. These issues affected a total of 262 Medicaid cases representing 262 Medicaid claims payments totaling $53,171 from July 1, 2018, through March 31, 2019. We identified 118 additional claims that were paid on behalf of 62 different beneficiary names using the same State ID and date of birth combination. We specifically noted that 33 different providers submitted 118 separate claims to the Department for this State ID/SSN/date of birth on behalf of 62 different individuals with different names and genders during Fiscal Year 2019. The providers were paid a total of $16,678 for the claims during Fiscal Year 2019. For example, one claim of $226 was submitted and paid for an individual named ?A Test.? See Schedule of Findings and Questioned Costs for chart. As of the end of our audit, the Department was researching whether these 262 Medicaid cases of duplicate SSNs and State IDs that we identified, as well as the 118 claims paid under 62 different names with one State ID, were eligible for the services provided and that the payments were appropriate. Because of the issues noted above, at the time of our audit, we were unable to determine whether the payments were made on behalf of eligible Medicaid beneficiaries and therefore, consider all $69,849 of the payments to be known questioned costs; $34,925 of these costs were paid with federal grant funds. For the purposes of identifying and quantifying these amounts, we have applied the following definition included in our audit requirements: Questioned cost, as defined in Uniform Guidance [2 CFR 200.84], is ?a cost that is questioned by the auditor?(a) Which resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds; [or] (b) Where the costs, at the time of the audit, are not supported by adequate documentation...? We have identified these questioned costs as known questioned costs that are further defined in Uniform Guidance [2 CFR 200.516] as questioned costs that are specifically identified by the auditor. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2019 to prevent or detect instances of duplicate SSNs and/or multiple State IDs in CBMS and Colorado interChange, as noted: * CBMS ALLOWED DUPLICATE SSNS AND MULTIPLE STATE IDS. CBMS allowed caseworkers to create more than one case for a Medicaid beneficiary; as a result, an individual beneficiary could be assigned more than one State ID in CBMS and the multiple State IDs wre uploaded to Colorado interChange and treated as two separate accounts with the ability to have claims paid against them. Furthermore, the Department reported that CBMS did not have a system edit check that would flag for review and disallow the same SSNs or multiple State IDs for the same SSN. * LACK OF TRAINING, MONITORING, AND REVIEW. The Department did not monitor and effectively train local county and MA site caseworkers regarding identifying and merging multiple State IDs for the same beneficiary in CBMS. Department staff reported that they did not have a monitoring process in place to review the data in CBMS to ensure that local counties and MA sites were properly identifying, investigating, and merging multiple State IDs for the same beneficiary. Furthermore, the Department did not have an effective review process to analyze CBMS data to identify multiple State IDs and duplicate SSNs and remove them appropriately. * INEFFECTIVE PAYMENT VERIFICATION PROCESS. The Department, through Colorado interChange, used only State ID and date of birth field matches to verify a beneficiary for claims payments. As a result, Colorado interChange was making payments on behalf of an eligible Medicaid beneficiary for individuals whose names differed from the eligible beneficiary. Based on our follow-up discussions with the Department, they indicated that it would be inefficient to verify claims using the name fields because the names could change during the year; however, in order to avoid the improper payment of Medicaid claims, the Department needed to develop a more effective beneficiary payment verification process in Colorado interChange to ensure that payments were not made on behalf of multiple individuals using the same State ID and date of birth. After we brought this to the Department?s attention, they began to review and investigate these claims for overpayments. WHY DO THESE PROBLEMS MATTER? Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the local counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, such as system edit functions, effective ongoing staff training, and reviewing the local counties and MA sites; the State cannot substantiate that eligibility determinations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. As the state Medicaid agency, it is essential for the Department to ensure that Medicaid benefits are paid only for eligible beneficiaries. If an eligible individual has more than one State ID, providers could fraudulently submit duplicate claims under these IDs for the same services resulting in improper payments. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $69,849 THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-045 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Working with the Department of Human Services and Governor?s Office of Information Technology, as appropriate, to evaluate and institute, if feasible, a system check within Colorado Benefits Management System (CBMS) to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. B Improving the effectiveness of training and monitoring of the local counties and Medical Assistance (MA) sites to ensure that caseworkers are not creating new cases when they are attempting to update a beneficiary?s information to an already existing case file. This should include focused training for the local counties and MA sites on identifying and merging any duplicate case files existing within CBMS. C Working with the Department of Human Services, as appropriate, to evaluate and develop, if feasible, an effective beneficiary payment verification process in Colorado interChange to ensure that payments are not made on behalf of multiple individuals using the same State ID and date of birth. This should include researching the claims payments that were identified during our audit to determine whether or not these were appropriate payments in accordance with federal regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to work with the Governor's Office of Information Technology (OIT) on the feasibility of instituting a system check within CBMS to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. Since CBMS is a shared system between the Department and the Department of Human Services, and that State IDs are generated by a separate system managed by OIT, the Department cannot guarantee that specific system checks as prescribed through this audit recommendation can be implemented and the timeline to implement a related system change is unknown. Therefore, the Department can agree to research on the feasibility, and if feasible, implement a system check by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites on how to merge any duplicate case files existing within CBMS. There are multiple user manuals regarding this process and there are two specific web-based trainings which are both required for all caseworkers. The Department agrees to work with counties to identify any additional training, reporting, or monitoring related to the case file merge process that would be useful to caseworkers. The Department can agree to implement additional training by July 2021. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department's approach to claims editing using State ID and date-of-birth are Medicaid industry standards. The Department can agree to research how other payers edit claims for beneficiary information, such as name or other information that is available on a claim. Further, the Department's ability to modify claims editing based on beneficiary information has the potential to impact third-party claims submitted by other payers such as Medicare. Therefore, the Department cannot modify the Department's claims processing system until that research has been performed. The Department will research and report on the feasibility, and if feasible, implement any system change by July 2021. In addition, the Department agrees to research the claims payments that were identified through the audit to determine whether the payments were appropriate by July 2021.
(A) The Department agrees to work with the Governor's Office of Information Technology (OIT) on the feasibility of instituting a system check within CBMS to flag for review or disallow the same Social Security Number or multiple State IDs to be used by more than one beneficiary to prevent multiple accounts within CBMS. Since CBMS is a shared system between the Department and the Department of Human Services, and that State IDs are generated by a separate system managed by OIT, the Department cannot guarantee that specific system checks as prescribed through this audit recommendation can be implemented and the timeline to implement a related system change is unknown. Therefore, the Department can agree to research on the feasibility, and if feasible, implement a system check by July 2022 (Donna Kellow, Greg Tanner, July 2022). (B) The Department provides training to counties and Medical Assistance sites on how to merge any duplicate case files existing within CBMS. There are multiple user manuals regarding this process and there are two specific web-based trainings which are both required for all caseworkers. The Department agrees to work with counties to identify any additional training, reporting, or monitoring related to the case file merge process that would be useful to caseworkers. The Department can agree to implement additional training by July 2021 (Donna Kellow, Greg Tanner, July 2021). (C) The Department's approach to claims editing using State ID and date-of-birth are Medicaid industry standards. The Department can agree to research how other payers edit claims for beneficiary information, such as name or other information that is available on a claim. Further, the Department's ability to modify claims editing based on beneficiary information has the potential to impact thirdparty claims submitted by other payers such as Medicare. Therefore, the Department cannot modify the Department's claims processing system until that research has been performed. The Department will research and report on the feasibility, and if feasible, implement any system change by July 2021. In addition, the Department agrees to research the claims payments that were identified through the audit to determine whether the payments were appropriate by July 2021 (Donna Kellow, Greg Tanner, July 2021).
PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: * DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. * DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. * INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $15,061 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-046A, 2018-046B, 2018-046C, 2018-056A, 2018-056B, 2017-055A, AND 2017-055B * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Show full finding ▾Hide full finding ▴PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: * DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. * DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. * INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017* XIX-MAP2018* XIX-MAP2019* XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $15,061 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-046A, 2018-046B, 2018-046C, 2018-056A, 2018-056B, 2017-055A, AND 2017-055B * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
(A) The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23 (Donna Kellow, Greg Tanner, July 2022). (B) The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2) (Donna Kellow, Greg Tanner, N/A). (C) The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21 (Donna Kellow, Greg Tanner, July 2020). (D) There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually (Donna Kellow, Greg Tanner, N/A).
2018-046, 2018-056
CBHP CONTROLS OVER ELIGIBILITY DETERMINATIONS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay an annual enrollment fee to the Department that is based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. Colorado interChange is programmed to determine whether CBHP claims are allowable for payment based on requirements specified in federal and state CBHP rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the eligibility determination process for CBHP as well as to determine the Department?s compliance with applicable federal and state requirements for CBHP during Fiscal Year 2019. We reviewed the Department?s CBHP eligibility internal controls in place during Fiscal Year 2019. In addition, we tested a sample of 25 CBHP beneficiaries who were deemed eligible for CBHP during Fiscal Year 2019 and had a payment made on their behalf to a CBHP provider between July 1, 2018, and April 30, 2019, to determine whether those CBHP beneficiaries? eligibility determinations were appropriate. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations, correctly entered eligibility data into CBMS, and properly assessed and collected the annual enrollment fee. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? In 13 of 25 case files tested (52 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2019, and total known questioned costs of $11,895; $10,467 of these costs were paid with federal grant funds. Specifically, we found the following: * INACCURATE ANNUAL FEE. In eight cases, the Department either did not assess the annual enrollment fee or assessed an incorrect fee amount for the beneficiary, as follows: ? In four cases the Department incorrectly assessed annual fees as $0; however, the annual fees should have been assessed between $35 and $105. ? In one case the Department incorrectly assessed a fee of $25 instead of $105. ? In two cases the Department did not assess any annual fee, as required by state regulation. Additionally, in one of these cases, and in a separate case, the Department assessed the annual enrollment fees but did not collect the required fees from the beneficiaries, rendering them ineligible, but continued to pay benefits on behalf of these beneficiaries during Fiscal Year 2019. As a result, the Department was not in compliance with state regulations. These issues resulted in questioned costs of $7,952. State regulations [10 CCR 2505-3 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to the enrollment in the program. * LACK OF SSN. In two cases, the Department did not obtain an SSN when determining beneficiaries? eligibility. These errors resulted in questioned costs of $231. State regulation [10 CCR 2505-10 8.100.4.B.1.a] requires all individuals who apply for CBHP to provide a valid SSN to the eligibility site. If the applicant does not have an SSN then they must submit an application for an SSN. * LACK OF INCOME VERIFICATION. In four cases, the caseworkers failed to verify income reported by the beneficiary as required by state and federal regulations. Specifically, in three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer in accordance with state regulations. In the remaining one case, the client was self-employed but the Department did not obtain a self-employment ledger to support the individual?s earnings as required by state regulations. As a result, we were unable to determine whether beneficiaries were appropriately eligible and whether the Department was in compliance with regulations. These errors resulted in questioned costs of $2,689. State regulations [10 CCR 2505-10 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. In addition, state regulation [10 CCR 2505-10 8.100.4.C.3] states that the Department must verify a beneficiary?s self-employed reported income through a ledger of their earnings provided by the beneficiary. * LACK OF CITIZENSHIP VERIFICATION. In one instance, the caseworker did not verify the beneficiary?s citizenship through either an interface check or through supporting documentation, such as a birth certificate, in accordance with state regulations. This resulted in questioned costs of $365. State regulations [10 CCR 2505-3 110.1.B and 110.1.C] require the Department to ensure that a beneficiary is a citizen of the U.S. or an individual who is legally allowed to be in the country. * IMPROPER PAYMENTS FOR INELIGIBLE BENEFICIARIES. In three cases, the Department processed payments to providers for services provided on behalf of individuals who were not eligible for CBHP at the time of service. The Department conducted additional research and determined that these beneficiaries were eligible under Medicaid, rather than CBHP, during that time. This resulted in questioned costs for CBHP of $658. Federal regulation Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958] states that, ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements, resulting in payments on behalf of ineligible beneficiaries during Fiscal Year 2019. Specifically, we noted that: * CBMS was not programmed to calculate and assess the correct annual enrollment fee, or to disallow benefits if the annual enrollment fee was not paid prior to enrollment in the program. * The Department did not have adequate monitoring or training processes in place to ensure that local counties and MA sites maintained the required documentation to support CBHP eligibility such as citizenship status, or that caseworkers obtained SSNs, or obtained and verified beneficiary income. In addition, CBMS lacked a programming check to identify individuals whose eligibility for CBHP had ended and, in the cases we noted, continued to allow CBHP payments to be made on behalf of the ineligible beneficiaries. In the instances we noted, the caseworker did not identify the individuals as ineligible for CBHP until 1 to 2 months after their eligibility had ended. The caseworker then backdated the individuals? eligibility for Medicaid in CBMS, as allowed under Medicaid, but did not reclassify CBHP payments to Medicaid. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, such as citizenship status; obtaining an SSN; obtaining and verifying income; and instituting appropriate programming checks to identify ineligible beneficiaries, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate. This can result in benefits being paid on behalf of ineligible individuals. Further, because CBHP had a higher federal reimbursement rate than Medicaid during Fiscal Year 2019?88 percent versus 50 percent?the Department received a higher reimbursement from the federal government than it was entitled to receive for services provided to the three individuals we identified were in the incorrect program. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS CHIP2017* CHIP2018* CHIP2019* FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.767, Children?s Health Insurance Program COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $11,895 THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-047 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Children?s Basic Health Plan (CBHP) eligibility determinations to ensure that payments are only made on behalf of eligible beneficiaries by: A Resolving Colorado Benefits Management System (CBMS) programming issues to ensure that correct annual enrollment fees are being calculated, and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. B Training and monitoring the local counties and Medical Assistance sites to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required Social Security Numbers, and obtaining and verifying income reported by the beneficiary. C Implementing a programming check within CBMS to alert caseworkers of CBHP beneficiaries who become ineligible for CBHP benefits and disallowing CBHP payments to be made on behalf of the ineligible beneficiaries. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to research if CBMS is programmed correctly to ensure correct annual enrollment fees are being calculated and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. Once this research is complete, the Department will take the necessary actions, if any, to make system changes to CBMS. The Department will complete the research by July 2020, and if CBMS system changes are necessary, they will be completed by July 2021. The Department's implementation date is based on the expectation that the Department will be compliant for the entirety of Fiscal Year 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to provide findings from this audit report to the CBMS training team, which already has intensive training available to caseworkers, and will also be sent to the counties involved in the findings. In addition to this work, the Department is implementing a new county oversight and accountability model for eligibility. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: * Enhancing county administration rules to improve county accountability. * Improving quality/performance metrics and information sharing through scorecards * Implementing management evaluation reviews and providing technical assistance to address issues * Implementing changes to quality control processes as dictated by the federal government This county oversight and accountability model is targeted to begin by July 2020. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of Fiscal Year 2021-22. C DISAGREE. The Department has determined that the payments were made correctly and that no CBMS changes are necessary. The audit finding does not correctly explain how retroactive eligibility changes impact a beneficiary's eligibility for Medicaid and CHP+, nor does the audit findings correctly provide the timeline when payments were made for these beneficiaries relative on the retroactive eligibility changes. When payments were made, the payments were classified to the correct eligibility category. The Department does not reclassify payments to a different eligibility category when retroactive eligibility changes occur. To reflect the correct eligibility category at the time when payments are made, the Department specifies that information on the claim payment record, so auditors have traceability. The Department has explained and documented the timeline and policy to the OSA; however, the write-up in the finding and recommendation remain incorrect. AUDITOR?S ADDENDUM: Federal regulations for CBHP as noted in this finding [42 CFR 431.958] states that, ?Improper payment means any payment that should not have been made or that was made in an incorrect amount?and includes any payment to an ineligible beneficiary?? The three individuals we identified through our audit did not meet eligibility requirements for CBHP, and the payments, therefore, should not have been made on their behalf under CBHP. The Department?s subsequent research and conclusion that the individuals were eligible for Medicaid rather than CBHP at the time does not refute our finding. Further, because the Department did not reclassify the payments from CBHP to Medicaid, the Department received a higher reimbursement from the federal government than it was entitled to for services provided to these individuals.
Show full finding ▾Hide full finding ▴CBHP CONTROLS OVER ELIGIBILITY DETERMINATIONS The Department, local counties, and MA sites share responsibility for ensuring that only eligible beneficiaries receive public assistance benefits under CBHP. Individuals and families apply for CBHP eligibility at their local county departments of human/social services or at MA sites. The local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. Once approved for eligibility, the beneficiary is required to pay an annual enrollment fee to the Department that is based on the number of people in the family and the family?s income. Eligibility data in CBMS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. Colorado interChange is programmed to determine whether CBHP claims are allowable for payment based on requirements specified in federal and state CBHP rules and regulations. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the eligibility determination process for CBHP as well as to determine the Department?s compliance with applicable federal and state requirements for CBHP during Fiscal Year 2019. We reviewed the Department?s CBHP eligibility internal controls in place during Fiscal Year 2019. In addition, we tested a sample of 25 CBHP beneficiaries who were deemed eligible for CBHP during Fiscal Year 2019 and had a payment made on their behalf to a CBHP provider between July 1, 2018, and April 30, 2019, to determine whether those CBHP beneficiaries? eligibility determinations were appropriate. Our testing included a review of the related supporting documentation, including the case files; CBMS data fields related to eligibility determination/redetermination; and CBHP payment information in Colorado interChange. We performed testing to determine whether the Department ensured that local county and MA site caseworkers obtained, verified, and maintained in the case files the required documents supporting eligibility determinations and annual redeterminations, correctly entered eligibility data into CBMS, and properly assessed and collected the annual enrollment fee. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? In 13 of 25 case files tested (52 percent), we identified at least one error. These errors resulted in a total of 12 ineligible beneficiaries during all or part of Fiscal Year 2019, and total known questioned costs of $11,895; $10,467 of these costs were paid with federal grant funds. Specifically, we found the following: * INACCURATE ANNUAL FEE. In eight cases, the Department either did not assess the annual enrollment fee or assessed an incorrect fee amount for the beneficiary, as follows: ? In four cases the Department incorrectly assessed annual fees as $0; however, the annual fees should have been assessed between $35 and $105. ? In one case the Department incorrectly assessed a fee of $25 instead of $105. ? In two cases the Department did not assess any annual fee, as required by state regulation. Additionally, in one of these cases, and in a separate case, the Department assessed the annual enrollment fees but did not collect the required fees from the beneficiaries, rendering them ineligible, but continued to pay benefits on behalf of these beneficiaries during Fiscal Year 2019. As a result, the Department was not in compliance with state regulations. These issues resulted in questioned costs of $7,952. State regulations [10 CCR 2505-3 310.1-310.2] require the Department to collect an annual enrollment fee from the beneficiary prior to enrollment in the CBHP. The actual fee is determined based on the number of eligible children within the family. Benefits should be denied if the annual enrollment fee is not paid prior to the enrollment in the program. * LACK OF SSN. In two cases, the Department did not obtain an SSN when determining beneficiaries? eligibility. These errors resulted in questioned costs of $231. State regulation [10 CCR 2505-10 8.100.4.B.1.a] requires all individuals who apply for CBHP to provide a valid SSN to the eligibility site. If the applicant does not have an SSN then they must submit an application for an SSN. * LACK OF INCOME VERIFICATION. In four cases, the caseworkers failed to verify income reported by the beneficiary as required by state and federal regulations. Specifically, in three cases, the beneficiary reported income; however, the caseworker did not verify the reported income through an electronic data source, wage stubs, tax documents, or through the employer in accordance with state regulations. In the remaining one case, the client was self-employed but the Department did not obtain a self-employment ledger to support the individual?s earnings as required by state regulations. As a result, we were unable to determine whether beneficiaries were appropriately eligible and whether the Department was in compliance with regulations. These errors resulted in questioned costs of $2,689. State regulations [10 CCR 2505-10 8.100.4.B.1.c and 8.100.4.B.1.d] require the Department to verify income reported by a beneficiary through an electronic data source, wage stubs, tax documents, or verification with the employer. In addition, state regulation [10 CCR 2505-10 8.100.4.C.3] states that the Department must verify a beneficiary?s self-employed reported income through a ledger of their earnings provided by the beneficiary. * LACK OF CITIZENSHIP VERIFICATION. In one instance, the caseworker did not verify the beneficiary?s citizenship through either an interface check or through supporting documentation, such as a birth certificate, in accordance with state regulations. This resulted in questioned costs of $365. State regulations [10 CCR 2505-3 110.1.B and 110.1.C] require the Department to ensure that a beneficiary is a citizen of the U.S. or an individual who is legally allowed to be in the country. * IMPROPER PAYMENTS FOR INELIGIBLE BENEFICIARIES. In three cases, the Department processed payments to providers for services provided on behalf of individuals who were not eligible for CBHP at the time of service. The Department conducted additional research and determined that these beneficiaries were eligible under Medicaid, rather than CBHP, during that time. This resulted in questioned costs for CBHP of $658. Federal regulation Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958] states that, ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and includes any payment to an ineligible beneficiary, any duplicate payment, any payment for services not received, any payment incorrectly denied, and any payment that does not account for credits or applicable discounts.? WHY DID THESE PROBLEMS OCCUR? The Department lacked sufficient internal controls to ensure that it complied with state and federal CBHP eligibility requirements, resulting in payments on behalf of ineligible beneficiaries during Fiscal Year 2019. Specifically, we noted that: * CBMS was not programmed to calculate and assess the correct annual enrollment fee, or to disallow benefits if the annual enrollment fee was not paid prior to enrollment in the program. * The Department did not have adequate monitoring or training processes in place to ensure that local counties and MA sites maintained the required documentation to support CBHP eligibility such as citizenship status, or that caseworkers obtained SSNs, or obtained and verified beneficiary income. In addition, CBMS lacked a programming check to identify individuals whose eligibility for CBHP had ended and, in the cases we noted, continued to allow CBHP payments to be made on behalf of the ineligible beneficiaries. In the instances we noted, the caseworker did not identify the individuals as ineligible for CBHP until 1 to 2 months after their eligibility had ended. The caseworker then backdated the individuals? eligibility for Medicaid in CBMS, as allowed under Medicaid, but did not reclassify CBHP payments to Medicaid. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in the local counties and MA sites granting CBHP benefits to ineligible individuals. Without maintaining the required documentation to support eligibility, such as citizenship status; obtaining an SSN; obtaining and verifying income; and instituting appropriate programming checks to identify ineligible beneficiaries, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for CBHP are accurate. This can result in benefits being paid on behalf of ineligible individuals. Further, because CBHP had a higher federal reimbursement rate than Medicaid during Fiscal Year 2019?88 percent versus 50 percent?the Department received a higher reimbursement from the federal government than it was entitled to receive for services provided to the three individuals we identified were in the incorrect program. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS CHIP2017* CHIP2018* CHIP2019* FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.767, Children?s Health Insurance Program COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $11,895 THIS FINDING DOES NOT APPLY TO A PRIOR AUDIT RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-047 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls over the Children?s Basic Health Plan (CBHP) eligibility determinations to ensure that payments are only made on behalf of eligible beneficiaries by: A Resolving Colorado Benefits Management System (CBMS) programming issues to ensure that correct annual enrollment fees are being calculated, and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. B Training and monitoring the local counties and Medical Assistance sites to ensure that caseworkers are maintaining the required documentation to support eligibility, obtaining required Social Security Numbers, and obtaining and verifying income reported by the beneficiary. C Implementing a programming check within CBMS to alert caseworkers of CBHP beneficiaries who become ineligible for CBHP benefits and disallowing CBHP payments to be made on behalf of the ineligible beneficiaries. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to research if CBMS is programmed correctly to ensure correct annual enrollment fees are being calculated and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. Once this research is complete, the Department will take the necessary actions, if any, to make system changes to CBMS. The Department will complete the research by July 2020, and if CBMS system changes are necessary, they will be completed by July 2021. The Department's implementation date is based on the expectation that the Department will be compliant for the entirety of Fiscal Year 2021-22. B AGREE. IMPLEMENTATION DATE: JULY 2022. The Department agrees to provide findings from this audit report to the CBMS training team, which already has intensive training available to caseworkers, and will also be sent to the counties involved in the findings. In addition to this work, the Department is implementing a new county oversight and accountability model for eligibility. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: * Enhancing county administration rules to improve county accountability. * Improving quality/performance metrics and information sharing through scorecards * Implementing management evaluation reviews and providing technical assistance to address issues * Implementing changes to quality control processes as dictated by the federal government This county oversight and accountability model is targeted to begin by July 2020. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of Fiscal Year 2021-22. C DISAGREE. The Department has determined that the payments were made correctly and that no CBMS changes are necessary. The audit finding does not correctly explain how retroactive eligibility changes impact a beneficiary's eligibility for Medicaid and CHP+, nor does the audit findings correctly provide the timeline when payments were made for these beneficiaries relative on the retroactive eligibility changes. When payments were made, the payments were classified to the correct eligibility category. The Department does not reclassify payments to a different eligibility category when retroactive eligibility changes occur. To reflect the correct eligibility category at the time when payments are made, the Department specifies that information on the claim payment record, so auditors have traceability. The Department has explained and documented the timeline and policy to the OSA; however, the write-up in the finding and recommendation remain incorrect. AUDITOR?S ADDENDUM: Federal regulations for CBHP as noted in this finding [42 CFR 431.958] states that, ?Improper payment means any payment that should not have been made or that was made in an incorrect amount?and includes any payment to an ineligible beneficiary?? The three individuals we identified through our audit did not meet eligibility requirements for CBHP, and the payments, therefore, should not have been made on their behalf under CBHP. The Department?s subsequent research and conclusion that the individuals were eligible for Medicaid rather than CBHP at the time does not refute our finding. Further, because the Department did not reclassify the payments from CBHP to Medicaid, the Department received a higher reimbursement from the federal government than it was entitled to for services provided to these individuals.
(A) The Department agrees to research if CBMS is programmed correctly to ensure correct annual enrollment fees are being calculated and to disallow benefits if the annual enrollment fee is not paid prior to the enrollment in the program. Once this research is complete, the Department will take the necessary actions, if any, to make system changes to CBMS. The Department will complete the research by July 2020, and if CBMS system changes are necessary, they will be completed by July 2021. The Department's implementation date is based on the expectation that the Department will be compliant for the entirety of Fiscal Year 2021-22 (Donna Kellow, Greg Tanner, July 2022). (B) The Department agrees to provide findings from this audit report to the CBMS training team, which already has intensive training available to caseworkers, and will also be sent to the counties involved in the findings. In addition to this work, the Department is implementing a new county oversight and accountability model for eligibility. The model is based on a partnership with the Colorado Department Human Services and leveraging their processes for oversight and accountability. This includes the following initiatives: - Enhancing county administration rules to improve county accountability. - Improving quality/performance metrics and information sharing through scorecards. - Implementing management evaluation reviews and providing technical assistance to address issues. - Implementing changes to quality control processes as dictated by the federal government. This county oversight and accountability model is targeted to begin by July 2020. The Department's implementation date is based on the expectation that the Department's new county oversight and accountability model for eligibility will be effective for the entirety of Fiscal Year 2021-22 (Donna Kellow, Greg Tanner, July 2022). (C) The Department has determined that the payments were made correctly and that no CBMS changes are necessary. The audit finding does not correctly explain how retroactive eligibility changes impact a beneficiary's eligibility for Medicaid and CHP+, nor does the audit findings correctly provide the timeline when payments were made for these beneficiaries relative on the retroactive eligibility changes. When payments were made, the payments were classified to the correct eligibility category. The Department does not reclassify payments to a different eligibility category when retroactive eligibility changes occur. To reflect the correct eligibility category at the time when payments are made, the Department specifies that information on the claim payment record, so auditors have traceability. The Department has explained and documented the timeline and policy to the OSA; however, the write-up in the finding and recommendation remain incorrect (Donna Kellow, Greg Tanner, N/A).
MONITORING OF HEALTH AND SAFETY SURVEYS AND CERTIFICATIONS Medical providers, such as nursing facilities, intermediate care facilities for individuals with intellectual disabilities (ICF/IIDs), and hospitals providing nursing facility services, must meet minimum standards for certification by the state and/or federal governments to be eligible to receive payments for services provided to Medicaid-eligible beneficiaries. The Department and the Colorado Department of Public Health and Environment (CDPHE) are responsible under state statute for this work. The Department categorizes hospital providers of nursing facility services under Colorado Medicaid Skilled Nursing Facility providers. The Department, as the state agency that is ultimately responsible for administering Medicaid, has overall responsibility for ensuring that all medical providers receiving Medicaid funding comply with regulatory health and safety standards. The Department has an interagency agreement with CDPHE, the designated state survey agency, to conduct health care entity inspections, or surveys, of Medicaid providers as outlined in state statutes and in agreements with the Centers for Medicare and Medicaid Services (CMS). A standard survey is a type of survey conducted to assess compliance with federal regulations specific to health and safety. After conducting each survey, CDPHE staff enter information, such as survey date and deficiencies noted, into their database; this information is then extracted and compiled by CMS and displayed on CMS? Survey and Certification?s Quality, Certification and Oversight Reports website?CMS?s certification and reporting website. Once a health care facility passes its survey, CDPHE is responsible for making a recommendation for certification to the Department. The Department is responsible for monitoring CDPHE to ensure that the minimum standards for certification are met by each Medicaid-approved provider, and for approving CDPHE?s recommendations for certification. During Fiscal Year 2019, the Department paid CDPHE approximately $5.7 million for completing state surveys and certifications. The Department receives monthly reports from CDPHE detailing the results of the surveys and certifications performed on skilled nursing facilities and ICF/IIDs. In addition, the Department holds monthly meetings with CDPHE to discuss the surveys and certifications. The Department uses these reports and discussions to determine if there are any issues or deficiencies with any skilled nursing facilities and ICF/IIDs. Additionally, CDPHE is responsible for informing the Department directly if a facility has any critical violations because of a survey and the Department can then suspend payments to that facility. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over the monitoring of CDPHE?s health and safety surveys for skilled nursing facilities and ICF/IIDs, and complied with the related federal and state requirements during Fiscal Year 2019. In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to monitoring of health and safety survey and certifications. During that audit, we recommended that the Department strengthen its internal controls over provider health and safety standards by following its current policy for monitoring CDPHE?s standard surveys and certifications, updating the policy to maintain monitoring documentation, and developing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities and ICF/IIDs. As part of our audit, we reviewed a sample of 40 skilled nursing facilities and ICF/IIDs that received a Medicaid payment for services provided during Fiscal Year 2019 in order to determine if the Department ensured that CDPHE performed the required surveys in accordance with federal and state regulations. For the sample of skilled nursing facilities and ICF/IIDs, we reviewed the date of the current standard survey and compared it to the date of the previous standard survey to determine whether the surveys were conducted within the required time interval per federal and state regulations. We also conducted inquiries with Department staff regarding policies and procedures over the monitoring of CDPHE. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: * ACCORDING TO FEDERAL REGULATION [42 CFR 442], providers must meet the prescribed health and safety standards for ICF/IIDs, nursing facilities, and hospitals providing nursing facility services. For example, each facility is subject to surveys that cover quality of care, written plans of care, and a review of compliance with residents? rights. *ACCORDING TO FEDERAL REGULATION [42 CFR 488.308(a)], the state survey agency must conduct a standard survey of each skilled nursing facility and nursing facility no later than 15 months after the last day of the previous survey. * ACCORDING TO DEPARTMENT POLICY [Policy SLO-001 Section V], Department staff must run an independent report from CMS?s certification and reporting website to identify any facilities that are overdue for a survey. Once these facilities are identified, Department staff then compare this report to the reports received from CDPHE to determine whether CDPHE completed the survey because the information on CMS?s certification and reporting website may not always be current. If the survey is not performed within the required timeframe of 15.9 months, Department staff should reach out to CDPHE to ensure that surveys are conducted. Department staff must then save documentation for all interactions with CDPHE. This policy also states that in order to ensure timely surveys, Department staff must use a tracking log to monitor survey completion dates by CDPHE. * ACCORDING TO FEDERAL REGULATION [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, observing operations, and ensuring that activities are carried out in accordance with any agreements in place with other entities. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Based on the issues identified, we determined that the Department did not fully implement all parts of the prior audit recommendation related to the monitoring of CDPHE?s health and safety standard surveys for skilled nursing facilities during Fiscal Year 2019. Specifically, we identified the following: UNTIMELY STANDARD SURVEYS. The Department did not ensure that CDPHE conducted standard surveys within required timeframes. We found that, for 13 of the 40 skilled nursing facilities and ICF/IIDs tested (33 percent), CDPHE did not properly survey the facility within a 15-month interval as required by federal regulations. Specifically, we found that the skilled nursing facilities were surveyed within an interval of 16 and 20 months, or 1 to 5 months beyond the required timeframe. In addition, the Department was unable to provide documentation that it had appropriately monitored CDPHE or that it had provided appropriate outreach to CDPHE to identify the reasons for the late processing and resolution of issues. DEPARTMENT NOT IN COMPLIANCE WITH ITS POLICY. The Department was unable to provide documented evidence that staff obtained reports from CMS?s certification and reporting website and compared them to CDPHE reports, as required by the Department?s policy, in order to identify overdue surveys of providers and follow up with CDPHE accordingly. WHY DID THESE PROBLEMS OCCUR? While the Department updated its policy to include a requirement for staff to maintain documentation of the meetings held with CDPHE and CMS as well as staff reviews of survey reports, we found that the Department?s policy was not updated until June 30, 2019, or the last day of Fiscal Year 2019. As a result, the Department did not have adequate internal controls in place during Fiscal Year 2019 over its monitoring of CDPHE?s health and safety surveys and certifications to ensure that CDPHE staff conducted timely standard surveys in compliance with state and federal regulations. In addition, the Department did not have an effective mechanism to proactively identify delayed standard surveys and certifications of skilled nursing facilities. WHY DO THESE PROBLEMS MATTER? By not performing appropriate and timely monitoring, or maintaining an internal survey tracking mechanism, the Department cannot demonstrate that it has adequate internal controls in place over Medicaid payments made to skilled nursing facilities, and therefore risks noncompliance with federal regulations. If the Department does not have a strong process in place to ensure that providers are properly surveyed and certified, the Department risks making payments to CDPHE for surveys and certifications that have not been completed. Additionally, the Department risks making payments to skilled nursing facilities that may not be eligible to participate as Medicaid providers and would therefore be out of compliance with federal and state requirements. Further, this could result in the Department having to pay CMS back the amounts paid to these providers during the time period. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS 17S&CTITLE19MEDICAID 18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAID FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS (TITLE XVIII) MEDICARE COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED AND UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-047A AND 2018-047B RECOMMENDATION 2019-048 The Department of Health Care Policy and Financing should strengthen its internal controls over the monitoring of provider health and safety standards by: A Implementing and following its current policy for monitoring the Colorado Department of Public Health and Environment?s standard surveys and certifications throughout the fiscal year to ensure compliance with state and federal regulations. B Developing and implementing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.
Show full finding ▾Hide full finding ▴MONITORING OF HEALTH AND SAFETY SURVEYS AND CERTIFICATIONS Medical providers, such as nursing facilities, intermediate care facilities for individuals with intellectual disabilities (ICF/IIDs), and hospitals providing nursing facility services, must meet minimum standards for certification by the state and/or federal governments to be eligible to receive payments for services provided to Medicaid-eligible beneficiaries. The Department and the Colorado Department of Public Health and Environment (CDPHE) are responsible under state statute for this work. The Department categorizes hospital providers of nursing facility services under Colorado Medicaid Skilled Nursing Facility providers. The Department, as the state agency that is ultimately responsible for administering Medicaid, has overall responsibility for ensuring that all medical providers receiving Medicaid funding comply with regulatory health and safety standards. The Department has an interagency agreement with CDPHE, the designated state survey agency, to conduct health care entity inspections, or surveys, of Medicaid providers as outlined in state statutes and in agreements with the Centers for Medicare and Medicaid Services (CMS). A standard survey is a type of survey conducted to assess compliance with federal regulations specific to health and safety. After conducting each survey, CDPHE staff enter information, such as survey date and deficiencies noted, into their database; this information is then extracted and compiled by CMS and displayed on CMS? Survey and Certification?s Quality, Certification and Oversight Reports website?CMS?s certification and reporting website. Once a health care facility passes its survey, CDPHE is responsible for making a recommendation for certification to the Department. The Department is responsible for monitoring CDPHE to ensure that the minimum standards for certification are met by each Medicaid-approved provider, and for approving CDPHE?s recommendations for certification. During Fiscal Year 2019, the Department paid CDPHE approximately $5.7 million for completing state surveys and certifications. The Department receives monthly reports from CDPHE detailing the results of the surveys and certifications performed on skilled nursing facilities and ICF/IIDs. In addition, the Department holds monthly meetings with CDPHE to discuss the surveys and certifications. The Department uses these reports and discussions to determine if there are any issues or deficiencies with any skilled nursing facilities and ICF/IIDs. Additionally, CDPHE is responsible for informing the Department directly if a facility has any critical violations because of a survey and the Department can then suspend payments to that facility. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine whether the Department had adequate internal controls in place over the monitoring of CDPHE?s health and safety surveys for skilled nursing facilities and ICF/IIDs, and complied with the related federal and state requirements during Fiscal Year 2019. In addition, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to monitoring of health and safety survey and certifications. During that audit, we recommended that the Department strengthen its internal controls over provider health and safety standards by following its current policy for monitoring CDPHE?s standard surveys and certifications, updating the policy to maintain monitoring documentation, and developing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities and ICF/IIDs. As part of our audit, we reviewed a sample of 40 skilled nursing facilities and ICF/IIDs that received a Medicaid payment for services provided during Fiscal Year 2019 in order to determine if the Department ensured that CDPHE performed the required surveys in accordance with federal and state regulations. For the sample of skilled nursing facilities and ICF/IIDs, we reviewed the date of the current standard survey and compared it to the date of the previous standard survey to determine whether the surveys were conducted within the required time interval per federal and state regulations. We also conducted inquiries with Department staff regarding policies and procedures over the monitoring of CDPHE. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: * ACCORDING TO FEDERAL REGULATION [42 CFR 442], providers must meet the prescribed health and safety standards for ICF/IIDs, nursing facilities, and hospitals providing nursing facility services. For example, each facility is subject to surveys that cover quality of care, written plans of care, and a review of compliance with residents? rights. *ACCORDING TO FEDERAL REGULATION [42 CFR 488.308(a)], the state survey agency must conduct a standard survey of each skilled nursing facility and nursing facility no later than 15 months after the last day of the previous survey. * ACCORDING TO DEPARTMENT POLICY [Policy SLO-001 Section V], Department staff must run an independent report from CMS?s certification and reporting website to identify any facilities that are overdue for a survey. Once these facilities are identified, Department staff then compare this report to the reports received from CDPHE to determine whether CDPHE completed the survey because the information on CMS?s certification and reporting website may not always be current. If the survey is not performed within the required timeframe of 15.9 months, Department staff should reach out to CDPHE to ensure that surveys are conducted. Department staff must then save documentation for all interactions with CDPHE. This policy also states that in order to ensure timely surveys, Department staff must use a tracking log to monitor survey completion dates by CDPHE. * ACCORDING TO FEDERAL REGULATION [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, observing operations, and ensuring that activities are carried out in accordance with any agreements in place with other entities. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Based on the issues identified, we determined that the Department did not fully implement all parts of the prior audit recommendation related to the monitoring of CDPHE?s health and safety standard surveys for skilled nursing facilities during Fiscal Year 2019. Specifically, we identified the following: UNTIMELY STANDARD SURVEYS. The Department did not ensure that CDPHE conducted standard surveys within required timeframes. We found that, for 13 of the 40 skilled nursing facilities and ICF/IIDs tested (33 percent), CDPHE did not properly survey the facility within a 15-month interval as required by federal regulations. Specifically, we found that the skilled nursing facilities were surveyed within an interval of 16 and 20 months, or 1 to 5 months beyond the required timeframe. In addition, the Department was unable to provide documentation that it had appropriately monitored CDPHE or that it had provided appropriate outreach to CDPHE to identify the reasons for the late processing and resolution of issues. DEPARTMENT NOT IN COMPLIANCE WITH ITS POLICY. The Department was unable to provide documented evidence that staff obtained reports from CMS?s certification and reporting website and compared them to CDPHE reports, as required by the Department?s policy, in order to identify overdue surveys of providers and follow up with CDPHE accordingly. WHY DID THESE PROBLEMS OCCUR? While the Department updated its policy to include a requirement for staff to maintain documentation of the meetings held with CDPHE and CMS as well as staff reviews of survey reports, we found that the Department?s policy was not updated until June 30, 2019, or the last day of Fiscal Year 2019. As a result, the Department did not have adequate internal controls in place during Fiscal Year 2019 over its monitoring of CDPHE?s health and safety surveys and certifications to ensure that CDPHE staff conducted timely standard surveys in compliance with state and federal regulations. In addition, the Department did not have an effective mechanism to proactively identify delayed standard surveys and certifications of skilled nursing facilities. WHY DO THESE PROBLEMS MATTER? By not performing appropriate and timely monitoring, or maintaining an internal survey tracking mechanism, the Department cannot demonstrate that it has adequate internal controls in place over Medicaid payments made to skilled nursing facilities, and therefore risks noncompliance with federal regulations. If the Department does not have a strong process in place to ensure that providers are properly surveyed and certified, the Department risks making payments to CDPHE for surveys and certifications that have not been completed. Additionally, the Department risks making payments to skilled nursing facilities that may not be eligible to participate as Medicaid providers and would therefore be out of compliance with federal and state requirements. Further, this could result in the Department having to pay CMS back the amounts paid to these providers during the time period. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS 17S&CTITLE19MEDICAID 18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAID FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS (TITLE XVIII) MEDICARE COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED AND UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-047A AND 2018-047B RECOMMENDATION 2019-048 The Department of Health Care Policy and Financing should strengthen its internal controls over the monitoring of provider health and safety standards by: A Implementing and following its current policy for monitoring the Colorado Department of Public Health and Environment?s standard surveys and certifications throughout the fiscal year to ensure compliance with state and federal regulations. B Developing and implementing a mechanism to proactively identify delays in standard surveys and certifications of skilled nursing facilities. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website.
(A) The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website (Donna Kellow, Greg Tanner, July 2020). (B) The Department implemented a new Standard Operating Procedure (SOP) on July 1, 2019. The new SOP details the process for pulling and storing CDPHE's survey and certification reports for long-term care facilities from the federal reporting website. It also provides for Department staff to maintain documentation of their review of these reports and of the CMS reports, and to proactively identify delays in standard surveys and certifications of long-term care facilities. Additionally, the updated SOP includes formalized follow-up with CDPHE to identify inaccuracies in the federal reporting website (Donna Kellow, Greg Tanner, July 2020).
2018-047
MEDICAID MANAGED CARE ENTITIES The Department had a total of seven contracts with external entities for coordinating services to Medicaid beneficiaries during Fiscal Year 2019. The providers consisted of two Managed Care Organizations (MCO) and seven Prepaid Inpatient Health Plans (PIHP)?two PIHPs and two MCOs shared a single contract with the Department. The MCOs and PIHPs are collectively referred to as Managed Care Entities (MCE), which are health care providers or a group or organization of medical service providers which offer managed care health plans and deliver health care services. MCOs have a comprehensive risk plan contract with the Department covering comprehensive services, such as inpatient hospital services, whereas PIHPs have a non-comprehensive risk plan contract covering inpatient or institutional services, such as inpatient behavioral healthcare. See Schedule of Findings and Questioned Costs for chart/table. The Department makes set payments to each contracted MCE to coordinate services for eligible Medicaid beneficiaries every month. The MCEs are then responsible for paying Medicaid claims to providers. Providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid beneficiaries. The Department is ultimately responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions with the Department, including federal requirements that the MCOs pay timely Medicaid claims to the providers. During Fiscal Year 2019, the Department paid approximately $966,848,173 in Medicaid claims payments to MCEs. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over monitoring of MCEs to determine whether Medicaid claims were processed and paid in a timely manner by MCEs to the providers in accordance with federal requirements during Fiscal Year 2019. The audit work included interviewing Department staff regarding written policies and procedures over the monitoring of its MCEs. In addition, we reviewed all seven MCE contracts in place during Fiscal Year 2019 to determine whether they included timely processing provisions in accordance with Uniform Guidance. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? TIMELY CLAIMS PAYMENT. Federal regulation [42 CFR 447.46(C)(1)] states that the Department?s contracts with its MCOs must include a provision that the organization must pay 90 percent of all clean claims within 30 days of receipt from providers and 99 percent of all clean claims within 90 days of the date of receipt from providers. A ?clean claim? is one that can be processed without obtaining additional information from the provider for the services rendered. Based on inquiries with the Department, their processes require both MCOs and PIHPs to be in compliance with the timely claims payment regulation. INTERNAL CONTROLS. According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Principle 10, Design Control Activities, which states that management should design control activities to achieve the objectives and respond to risks. Management designs control activities in response to the entity?s objectives and risks to achieve an effective internal control system. Control activities are the policies, procedures, techniques, and mechanisms that enforce management?s directives to achieve the entity?s objectives and address related risks. Additionally, Green Book Paragraph 16.01, Perform Monitoring Activities, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, we found that the Department did not consistently have a contract provision requiring that PIHPs comply with timely claims payment regulations during Fiscal Year 2019. Specifically, we found that for five of seven contracts we reviewed (71 percent), the Department did not include a specific timely claims payment provision for Fiscal Year 2019. Additionally, the Department could not provide any evidence demonstrating that it monitored PIHPs during Fiscal Year 2019 to ensure that it (1) paid 90 percent of all clean claims from providers within 30 days of the date of receipt, and (2) paid 99 percent of all clean claims from providers within 90 days of the date of claims receipt in accordance with federal regulations. Furthermore, the Department could not provide any evidence demonstrating that it monitored two MCOs during Fiscal Year 2019 for timely claims payments as required by federal regulations. WHY DID THESE PROBLEMS OCCUR? The Department lacked adequate internal controls to ensure that it complied with federal regulations for timely claims payments to providers. Specifically, Department staff reported that all MCE contracts included a general provision requiring them to comply with all federal regulations. However, the Department lacked an adequate contract review process to ensure that all PIHP contracts included a provision requiring timely claims payments to providers. Additionally, the Department did not have formal written monitoring policies and procedures to ensure that PIHPs and MCOs made timely claims payments to providers. Department staff reported that they had an informal process of monitoring contracts by observing the operations but did not have a formal monitoring process, such as reviewing any type of report or performing reconciliations of claims payments made by MCEs. Furthermore, the Department?s contracts lacked a specific provision requiring MCEs to deliver any type of report to the Department for review to demonstrate the MCEs? compliance with federal regulations and Department processes. WHY DO THESE PROBLEMS MATTER? As a recipient of federal funds, the Department is ultimately responsible for ensuring that these funds are being paid in accordance with federal regulations. By not including the requirements for timely claims payments in the contracts with PIHPs and failing to have a formal monitoring process over PIHPs or MCOs, the Department risks failing to comply with federal regulations. Payments that are not made in accordance with these requirements could be subject to federal disallowances and recoveries from the State. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-057B AND 2017-056B RECOMMENDATION 2019-049 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the timely processing of medical claims paid by Medicaid Managed Care Entities (MCEs) by: A Instituting an adequate contract review process to ensure appropriate provisions, including timing specifications for claims payments to providers, are included in all Prepaid Inpatient Health Plan contracts to ensure compliance with Department requirements. B Developing and implementing formal written monitoring policies and procedures over the timely processing of claims payments to ensure that the Department and MCEs are in compliance with federal regulations and Department processes. C Incorporating provisions within all MCE contracts to deliver timely payment reports for the Department?s review to ensure compliance with federal regulations and Department processes. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The seven RAE contracts contain language that require them to strictly adhere to and comply with all applicable federal laws and regulations (see Regional Accountable Entity contracts base contract ?21.U.; Exhibit B, ?5.1., and ?17.1.). The Department agrees with the recommendation that the timely payment of clean claims is not specifically stated in the Prepaid Inpatient Health Plan section of the contracts. The Department will ensure an adequate contract review process is in place to ensure the timing specifications for the payment of claim payments to providers by documenting this requirement in program policy documentation. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department has documented policies for deliverables and federal regulatory requirements included in the Regional Accountable Entity contracts. The Department will document and implement the monitoring policy of the timely payment of clean claims language. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department will add new language to both the Prepaid Inpatient Health Plan and the Managed Care Organization authority sections of the Regional Accountable Entity contracts requiring reporting of the timely payment of clean claims.
Show full finding ▾Hide full finding ▴MEDICAID MANAGED CARE ENTITIES The Department had a total of seven contracts with external entities for coordinating services to Medicaid beneficiaries during Fiscal Year 2019. The providers consisted of two Managed Care Organizations (MCO) and seven Prepaid Inpatient Health Plans (PIHP)?two PIHPs and two MCOs shared a single contract with the Department. The MCOs and PIHPs are collectively referred to as Managed Care Entities (MCE), which are health care providers or a group or organization of medical service providers which offer managed care health plans and deliver health care services. MCOs have a comprehensive risk plan contract with the Department covering comprehensive services, such as inpatient hospital services, whereas PIHPs have a non-comprehensive risk plan contract covering inpatient or institutional services, such as inpatient behavioral healthcare. See Schedule of Findings and Questioned Costs for chart/table. The Department makes set payments to each contracted MCE to coordinate services for eligible Medicaid beneficiaries every month. The MCEs are then responsible for paying Medicaid claims to providers. Providers participating in the managed care system bill the MCEs directly for any medical services provided to Medicaid beneficiaries. The Department is ultimately responsible for monitoring the MCEs to ensure they are complying with federal regulations and their contract provisions with the Department, including federal requirements that the MCOs pay timely Medicaid claims to the providers. During Fiscal Year 2019, the Department paid approximately $966,848,173 in Medicaid claims payments to MCEs. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over monitoring of MCEs to determine whether Medicaid claims were processed and paid in a timely manner by MCEs to the providers in accordance with federal requirements during Fiscal Year 2019. The audit work included interviewing Department staff regarding written policies and procedures over the monitoring of its MCEs. In addition, we reviewed all seven MCE contracts in place during Fiscal Year 2019 to determine whether they included timely processing provisions in accordance with Uniform Guidance. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? TIMELY CLAIMS PAYMENT. Federal regulation [42 CFR 447.46(C)(1)] states that the Department?s contracts with its MCOs must include a provision that the organization must pay 90 percent of all clean claims within 30 days of receipt from providers and 99 percent of all clean claims within 90 days of the date of receipt from providers. A ?clean claim? is one that can be processed without obtaining additional information from the provider for the services rendered. Based on inquiries with the Department, their processes require both MCOs and PIHPs to be in compliance with the timely claims payment regulation. INTERNAL CONTROLS. According to Uniform Guidance [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Principle 10, Design Control Activities, which states that management should design control activities to achieve the objectives and respond to risks. Management designs control activities in response to the entity?s objectives and risks to achieve an effective internal control system. Control activities are the policies, procedures, techniques, and mechanisms that enforce management?s directives to achieve the entity?s objectives and address related risks. Additionally, Green Book Paragraph 16.01, Perform Monitoring Activities, states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, we found that the Department did not consistently have a contract provision requiring that PIHPs comply with timely claims payment regulations during Fiscal Year 2019. Specifically, we found that for five of seven contracts we reviewed (71 percent), the Department did not include a specific timely claims payment provision for Fiscal Year 2019. Additionally, the Department could not provide any evidence demonstrating that it monitored PIHPs during Fiscal Year 2019 to ensure that it (1) paid 90 percent of all clean claims from providers within 30 days of the date of receipt, and (2) paid 99 percent of all clean claims from providers within 90 days of the date of claims receipt in accordance with federal regulations. Furthermore, the Department could not provide any evidence demonstrating that it monitored two MCOs during Fiscal Year 2019 for timely claims payments as required by federal regulations. WHY DID THESE PROBLEMS OCCUR? The Department lacked adequate internal controls to ensure that it complied with federal regulations for timely claims payments to providers. Specifically, Department staff reported that all MCE contracts included a general provision requiring them to comply with all federal regulations. However, the Department lacked an adequate contract review process to ensure that all PIHP contracts included a provision requiring timely claims payments to providers. Additionally, the Department did not have formal written monitoring policies and procedures to ensure that PIHPs and MCOs made timely claims payments to providers. Department staff reported that they had an informal process of monitoring contracts by observing the operations but did not have a formal monitoring process, such as reviewing any type of report or performing reconciliations of claims payments made by MCEs. Furthermore, the Department?s contracts lacked a specific provision requiring MCEs to deliver any type of report to the Department for review to demonstrate the MCEs? compliance with federal regulations and Department processes. WHY DO THESE PROBLEMS MATTER? As a recipient of federal funds, the Department is ultimately responsible for ensuring that these funds are being paid in accordance with federal regulations. By not including the requirements for timely claims payments in the contracts with PIHPs and failing to have a formal monitoring process over PIHPs or MCOs, the Department risks failing to comply with federal regulations. Payments that are not made in accordance with these requirements could be subject to federal disallowances and recoveries from the State. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-057B AND 2017-056B RECOMMENDATION 2019-049 The Department of Health Care Policy and Financing (Department) should improve its internal controls over the timely processing of medical claims paid by Medicaid Managed Care Entities (MCEs) by: A Instituting an adequate contract review process to ensure appropriate provisions, including timing specifications for claims payments to providers, are included in all Prepaid Inpatient Health Plan contracts to ensure compliance with Department requirements. B Developing and implementing formal written monitoring policies and procedures over the timely processing of claims payments to ensure that the Department and MCEs are in compliance with federal regulations and Department processes. C Incorporating provisions within all MCE contracts to deliver timely payment reports for the Department?s review to ensure compliance with federal regulations and Department processes. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The seven RAE contracts contain language that require them to strictly adhere to and comply with all applicable federal laws and regulations (see Regional Accountable Entity contracts base contract ?21.U.; Exhibit B, ?5.1., and ?17.1.). The Department agrees with the recommendation that the timely payment of clean claims is not specifically stated in the Prepaid Inpatient Health Plan section of the contracts. The Department will ensure an adequate contract review process is in place to ensure the timing specifications for the payment of claim payments to providers by documenting this requirement in program policy documentation. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department has documented policies for deliverables and federal regulatory requirements included in the Regional Accountable Entity contracts. The Department will document and implement the monitoring policy of the timely payment of clean claims language. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department will add new language to both the Prepaid Inpatient Health Plan and the Managed Care Organization authority sections of the Regional Accountable Entity contracts requiring reporting of the timely payment of clean claims.
(A) The seven RAE contracts contain language that require them to strictly adhere to and comply with all applicable federal laws and regulations (see Regional Accountable Entity contracts base contract ?21.U.; Exhibit B, ?5.1., and ?17.1.). The Department agrees with the recommendation that the timely payment of clean claims is not specifically stated in the Prepaid Inpatient Health Plan section of the contracts. The Department will ensure an adequate contract review process is in place to ensure the timing specifications for the payment of claim payments to providers by documenting this requirement in program policy documentation (Donna Kellow, Greg Tanner, July 2021). (B) The Department has documented policies for deliverables and federal regulatory requirements included in the Regional Accountable Entity contracts. The Department will document and implement the monitoring policy of the timely payment of clean claims language (Donna Kellow, Greg Tanner, July 2021). (C) The Department will add new language to both the Prepaid Inpatient Health Plan and the Managed Care Organization authority sections of the Regional Accountable Entity contracts requiring reporting of the timely payment of clean claims (Donna Kellow, Greg Tanner, July 2021).
2018-057
COMPLIANCE WITH FEDERAL SUBRECIPIENT MONITORING REQUIREMENTS The Department receives federal Medicaid and CBHP grant funds directly from the federal government and then subgrants, or passes through, a portion of the funds to local counties, non-profit organizations, and for-profit organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required for the conduct of a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program. Under Uniform Guidance, the Department is responsible for identifying and monitoring entities that qualify as subrecipients of federal funds. For Medicaid and CBHP, the Department?s subrecipients either determine eligibility for the programs or provide services to individuals deemed eligible for program services. Examples of the Department?s subrecipients are local counties and MA sites, including Single Entry Points, which provide services for elderly and/or disabled people who are eligible for long-term care services; and Community Centered Boards, which provide services to individuals with developmental disabilities. Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA).This exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance, and should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants payments made by the Department to other State and/or non-state agencies. During Fiscal Year 2019, the Department paid approximately $18.5 million in federal Medicaid funds and approximately $500,000 in federal CBHP funds to 62 subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 recommendation related to Medicaid and CBHP subrecipient monitoring. In Fiscal Year 2018, we recommended that the Department improve its internal controls specific to subrecipient monitoring for the two programs by implementing its draft subrecipient monitoring policies and procedures and performing required risk assessments on its subrecipients to ensure compliance with Uniform Guidance. In response to our recommendation, the Department stated that it would revise its existing subrecipient policies and procedures to be compliant with federal Uniform Guidance and would conduct a risk assessment of each subrecipient as part of the monitoring process. We made a similar recommendation to the Department in Fiscal Year 2016 that we also determined the Department had not fully implemented at the time of our Fiscal Year 2018 audit. As part of our Fiscal Year 2019 audit, we obtained and reviewed the Department?s revised subrecipient monitoring policies and procedures. We selected a random sample of 16 out of 62 entities that were recorded and set up as subrecipients in the Colorado Operations Resource Engine (CORE), the State?s financial accounting system, and received Medicaid and CBHP payments during Fiscal Year 2019, to evaluate whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. Furthermore, we reviewed the Department?s Exhibit K1, submitted to the OSC for Fiscal Year 2019, to determine whether the Department accurately reported all subrecipient expenditures for Medicaid and CBHP. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Under Uniform Guidance, as a pass-through entity, the Department is required to monitor its subrecipients? use of federal awards. Federal regulation [2 CFR 200.331] requires the Department to conduct risk assessments based on each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of its Medicaid and CBHP subawards to determine the appropriate level of subrecipient monitoring for all of its subrecipients under these programs. The Department?s Subrecipient Monitoring Procedures (Procedures) that were in place during Fiscal Year 2019 split responsibilities between various divisions and staff as follows: * AUDITS AND COMPLIANCE DIVISION. Staff within this division oversee the local counties as subrecipients of Medicaid and CBHP and ensure that these subrecipients are in compliance with federal award requirements. Audits and Compliance Division staff is responsible for updating procedures, and providing training and guidance on subrecipient monitoring to program staff within the Department. * CONTROLLER DIVISION. Staff within this division are responsible for setting up the entity with the proper accounting codes in CORE. Based on the results of the assessment noted on the Subrecipient versus Contractor Determination Tool (Tool) for each entity, the Controller Division staff should establish either subrecipient or contractor coding for the entity?s expenditures. *VARIOUS OTHER DIVISIONS WITHIN THE DEPARTMENT. Procedures also state that the Department?s program contract administrators within its various program divisions are responsible for identifying its Medicaid and CBHP subrecipients by using the Tool. The Procedures require the contract administrators to forward the Tool for any identified subrecipients to the program division director for secondary review. The completed Tool is submitted for additional review to the Audits and Compliance Division. Final approval of the Tool is made by the controller of the Department. The Department procedure also states that the program contract administrator is required to assess each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the federal award as high, medium, or low risk. This assessment aids the Department in determining the appropriate level of monitoring. The risk assessment and the responsibility for monitoring the subrecipient?s compliance with federal award requirements rests with the contract administrator and their respective office or division management that operates the individual subrecipient award. State Fiscal Rule 1-2, Rule 3.5, Preaudit Responsibility for Accounting Documents and Financial Transactions, issued by the OSC, requires state departments to, ?Implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, and conform to state Fiscal Rules.? In addition, the Instructions for Exhibits published by the OSC provides specific directions for preparing financial exhibits that are to be submitted to the OSC at year-end. For example, the Exhibit K1 is used for preparing the SEFA, which includes a listing of federal assistance by Catalog of Federal Domestic Assistance number or other identifying number. The Instructions for Exhibits requires departments to separately report any federal assistance passed through to a subrecipient on the Exhibit K1 in the Expenditures-Passed Through to Subrecipient column, while payments to contractors are reported under the column titled Expenditures-Direct and Indirect. The Controller Division is responsible for preparing the Department?s Exhibit K1 each year. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement the Fiscal Year 2018 subrecipient monitoring recommendation for Medicaid and CBHP. Although the Department revised and implemented its Medicaid and CBHP subrecipient monitoring policies and procedures during Fiscal Year 2019, the Department did not evaluate all of its Medicaid and CBHP subrecipients? risk of noncompliance and did not determine the related level of subrecipient monitoring as required under Uniform Guidance and the Department?s procedures. We specifically noted the following problems: * For five of the 16 entities in our sample (31 percent), the program contract administrators identified them as contractors based on the results of the Tool assessment, but recorded them in CORE as subrecipients. Therefore, the Controller Division made payments totaling $166,870 to these five entities as subrecipient payments in CORE. Upon further inquiry with the Department, we found that the program contract administrators assessed all of its CBHP entities as contractors but recorded them in CORE as subrecipients. As a result, the Controller Division reported total payments of $415,378 to these entities on the Department?s Fiscal Year 2019 Exhibit K1 as Expenditures-Passed Through to Subrecipient, which contradicted the results of the Tool assessment. * Program contract administrators did not complete the required Tool assessments for three of 16 entities (19 percent) in our sample that were recorded as subrecipients in CORE and received payments under Medicaid and CBHP. Due to the lack of a completed Tool assessment for these entities, we could not determine whether the contract administrators should have identified them as subrecipients and, if so, whether they performed a risk assessment or any level of monitoring over these entities. As of the end of our audit, the Department was researching the discrepancies we identified to determine whether the entities should have been identified and reported as subrecipients or contractors. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2019 to ensure that it complied with federal subrecipient monitoring requirements. Specifically, we noted that there was an inefficient secondary review by the program division director over program contract administrators to ensure that the Tool assessment was completed properly, that entities were accurately reported as either a contractor or subrecipient in CORE, and that respective risk assessments were performed for all identified subrecipients as required by Uniform Guidance and Department procedures. In addition, we noted that the Department did not have a process in place to reconcile the Controller Division?s list of identified Medicaid and CBHP subrecipients with the subrecipient information in CORE. This reconciliation would ensure that Medicaid and CBHP payments made to subrecipents are reported accurately on the Exhibit K1 in accordance with the OSC?s Fiscal Rules and Instructions for Exhibits, and accurately reported to the federal government on the State?s SEFA. WHY DO THESE PROBLEMS MATTER? Without the proper internal controls in place to ensure compliance with federal subrecipient monitoring requirements, the Department ultimately risks federal sanctions. First, without evaluating its subrecipients? risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, the Department does not have assurance that it appropriately monitors its subrecipients and identifies issues. Further, because the Exhibit K1 is used by the OSC to prepare the SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds the Department pays annually to its subrecipients. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-049 RECOMMENDATION 2019-050 The Department of Health Care Policy and Financing should improve its internal controls over subrecipient monitoring for Medicaid and the Children?s Basic Health Plan (CBHP) by: A Implementing an effective secondary review process by the program division directors over the Department?s program contract administrators to ensure that the Subrecipient versus Contractor Determination Tool is completed, subrecipient and contractor determinations are accurately reported in the State?s financial accounting system, the Colorado Operations Resource Engine, and that the required risk assessments are performed for all identified subrecipients as required by the federal Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards and the Department?s procedures. B Establishing a process to reconcile subrecipients identified by the program contract administrators with those identified by the Controller Division for Medicaid and CBHP prior to awarding federal funds to the subrecipients to ensure that payments are reported accurately on the Exhibit K1, Schedule of Federal Assistance, in accordance with the Office of the State Controller?s Fiscal Rules and Instructions for Exhibits and, ultimately, to the federal government on the State?s Schedule of Expenditures of Federal Awards. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department will conduct training with program management and division directors regarding the requirements for subrecipient monitoring and their responsibilities for secondary review. The training will include subrecipient versus contractor determination, the requirement of risk assessments and the importance of reporting determinations accurately in Colorado Operations Resource Engine. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly. The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions.
Show full finding ▾Hide full finding ▴COMPLIANCE WITH FEDERAL SUBRECIPIENT MONITORING REQUIREMENTS The Department receives federal Medicaid and CBHP grant funds directly from the federal government and then subgrants, or passes through, a portion of the funds to local counties, non-profit organizations, and for-profit organizations that are considered to be either a subrecipient or a contractor. A subrecipient is a non-federal entity that expends federal awards received from a pass-through entity to carry out a federal program, but does not include an individual that is a beneficiary receiving direct payments from such a program. A contractor is a dealer, distributor, merchant, or other seller providing goods or services that are required for the conduct of a federal program; these goods or services may be for an organization?s own use or for the use of beneficiaries of the federal program. Under Uniform Guidance, the Department is responsible for identifying and monitoring entities that qualify as subrecipients of federal funds. For Medicaid and CBHP, the Department?s subrecipients either determine eligibility for the programs or provide services to individuals deemed eligible for program services. Examples of the Department?s subrecipients are local counties and MA sites, including Single Entry Points, which provide services for elderly and/or disabled people who are eligible for long-term care services; and Community Centered Boards, which provide services to individuals with developmental disabilities. Each year, the Department is required to prepare an exhibit containing the Department?s federal expenditures and related reimbursements to aid the Colorado Office of the State Controller (OSC) in the preparation of the State?s Schedule of Expenditures of Federal Awards (SEFA).This exhibit is referred to as the Exhibit K1, Schedule of Federal Assistance, and should include expenditures for grants received directly from the federal government and expended by the Department (direct expenditures), as well as expenditures for federal grants payments made by the Department to other State and/or non-state agencies. During Fiscal Year 2019, the Department paid approximately $18.5 million in federal Medicaid funds and approximately $500,000 in federal CBHP funds to 62 subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine the Department?s progress in implementing our Fiscal Year 2018 recommendation related to Medicaid and CBHP subrecipient monitoring. In Fiscal Year 2018, we recommended that the Department improve its internal controls specific to subrecipient monitoring for the two programs by implementing its draft subrecipient monitoring policies and procedures and performing required risk assessments on its subrecipients to ensure compliance with Uniform Guidance. In response to our recommendation, the Department stated that it would revise its existing subrecipient policies and procedures to be compliant with federal Uniform Guidance and would conduct a risk assessment of each subrecipient as part of the monitoring process. We made a similar recommendation to the Department in Fiscal Year 2016 that we also determined the Department had not fully implemented at the time of our Fiscal Year 2018 audit. As part of our Fiscal Year 2019 audit, we obtained and reviewed the Department?s revised subrecipient monitoring policies and procedures. We selected a random sample of 16 out of 62 entities that were recorded and set up as subrecipients in the Colorado Operations Resource Engine (CORE), the State?s financial accounting system, and received Medicaid and CBHP payments during Fiscal Year 2019, to evaluate whether the Department performed risk assessments and determined the appropriate level of subrecipient monitoring for the entities, as required by federal Uniform Guidance. Furthermore, we reviewed the Department?s Exhibit K1, submitted to the OSC for Fiscal Year 2019, to determine whether the Department accurately reported all subrecipient expenditures for Medicaid and CBHP. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Under Uniform Guidance, as a pass-through entity, the Department is required to monitor its subrecipients? use of federal awards. Federal regulation [2 CFR 200.331] requires the Department to conduct risk assessments based on each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of its Medicaid and CBHP subawards to determine the appropriate level of subrecipient monitoring for all of its subrecipients under these programs. The Department?s Subrecipient Monitoring Procedures (Procedures) that were in place during Fiscal Year 2019 split responsibilities between various divisions and staff as follows: * AUDITS AND COMPLIANCE DIVISION. Staff within this division oversee the local counties as subrecipients of Medicaid and CBHP and ensure that these subrecipients are in compliance with federal award requirements. Audits and Compliance Division staff is responsible for updating procedures, and providing training and guidance on subrecipient monitoring to program staff within the Department. * CONTROLLER DIVISION. Staff within this division are responsible for setting up the entity with the proper accounting codes in CORE. Based on the results of the assessment noted on the Subrecipient versus Contractor Determination Tool (Tool) for each entity, the Controller Division staff should establish either subrecipient or contractor coding for the entity?s expenditures. *VARIOUS OTHER DIVISIONS WITHIN THE DEPARTMENT. Procedures also state that the Department?s program contract administrators within its various program divisions are responsible for identifying its Medicaid and CBHP subrecipients by using the Tool. The Procedures require the contract administrators to forward the Tool for any identified subrecipients to the program division director for secondary review. The completed Tool is submitted for additional review to the Audits and Compliance Division. Final approval of the Tool is made by the controller of the Department. The Department procedure also states that the program contract administrator is required to assess each subrecipient?s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the federal award as high, medium, or low risk. This assessment aids the Department in determining the appropriate level of monitoring. The risk assessment and the responsibility for monitoring the subrecipient?s compliance with federal award requirements rests with the contract administrator and their respective office or division management that operates the individual subrecipient award. State Fiscal Rule 1-2, Rule 3.5, Preaudit Responsibility for Accounting Documents and Financial Transactions, issued by the OSC, requires state departments to, ?Implement internal accounting and administrative controls that reasonably ensure that financial transactions are accurate, reliable, and conform to state Fiscal Rules.? In addition, the Instructions for Exhibits published by the OSC provides specific directions for preparing financial exhibits that are to be submitted to the OSC at year-end. For example, the Exhibit K1 is used for preparing the SEFA, which includes a listing of federal assistance by Catalog of Federal Domestic Assistance number or other identifying number. The Instructions for Exhibits requires departments to separately report any federal assistance passed through to a subrecipient on the Exhibit K1 in the Expenditures-Passed Through to Subrecipient column, while payments to contractors are reported under the column titled Expenditures-Direct and Indirect. The Controller Division is responsible for preparing the Department?s Exhibit K1 each year. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement the Fiscal Year 2018 subrecipient monitoring recommendation for Medicaid and CBHP. Although the Department revised and implemented its Medicaid and CBHP subrecipient monitoring policies and procedures during Fiscal Year 2019, the Department did not evaluate all of its Medicaid and CBHP subrecipients? risk of noncompliance and did not determine the related level of subrecipient monitoring as required under Uniform Guidance and the Department?s procedures. We specifically noted the following problems: * For five of the 16 entities in our sample (31 percent), the program contract administrators identified them as contractors based on the results of the Tool assessment, but recorded them in CORE as subrecipients. Therefore, the Controller Division made payments totaling $166,870 to these five entities as subrecipient payments in CORE. Upon further inquiry with the Department, we found that the program contract administrators assessed all of its CBHP entities as contractors but recorded them in CORE as subrecipients. As a result, the Controller Division reported total payments of $415,378 to these entities on the Department?s Fiscal Year 2019 Exhibit K1 as Expenditures-Passed Through to Subrecipient, which contradicted the results of the Tool assessment. * Program contract administrators did not complete the required Tool assessments for three of 16 entities (19 percent) in our sample that were recorded as subrecipients in CORE and received payments under Medicaid and CBHP. Due to the lack of a completed Tool assessment for these entities, we could not determine whether the contract administrators should have identified them as subrecipients and, if so, whether they performed a risk assessment or any level of monitoring over these entities. As of the end of our audit, the Department was researching the discrepancies we identified to determine whether the entities should have been identified and reported as subrecipients or contractors. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2019 to ensure that it complied with federal subrecipient monitoring requirements. Specifically, we noted that there was an inefficient secondary review by the program division director over program contract administrators to ensure that the Tool assessment was completed properly, that entities were accurately reported as either a contractor or subrecipient in CORE, and that respective risk assessments were performed for all identified subrecipients as required by Uniform Guidance and Department procedures. In addition, we noted that the Department did not have a process in place to reconcile the Controller Division?s list of identified Medicaid and CBHP subrecipients with the subrecipient information in CORE. This reconciliation would ensure that Medicaid and CBHP payments made to subrecipents are reported accurately on the Exhibit K1 in accordance with the OSC?s Fiscal Rules and Instructions for Exhibits, and accurately reported to the federal government on the State?s SEFA. WHY DO THESE PROBLEMS MATTER? Without the proper internal controls in place to ensure compliance with federal subrecipient monitoring requirements, the Department ultimately risks federal sanctions. First, without evaluating its subrecipients? risks of noncompliance and using the results of that assessment to target monitoring of higher-risk entities, the Department does not have assurance that it appropriately monitors its subrecipients and identifies issues. Further, because the Exhibit K1 is used by the OSC to prepare the SEFA, errors on the Exhibit K1 can lead to the SEFA being misstated and the Department reporting erroneous information to the federal government. This is particularly important given the large amount of federal funds the Department pays annually to its subrecipients. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATION 2018-049 RECOMMENDATION 2019-050 The Department of Health Care Policy and Financing should improve its internal controls over subrecipient monitoring for Medicaid and the Children?s Basic Health Plan (CBHP) by: A Implementing an effective secondary review process by the program division directors over the Department?s program contract administrators to ensure that the Subrecipient versus Contractor Determination Tool is completed, subrecipient and contractor determinations are accurately reported in the State?s financial accounting system, the Colorado Operations Resource Engine, and that the required risk assessments are performed for all identified subrecipients as required by the federal Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards and the Department?s procedures. B Establishing a process to reconcile subrecipients identified by the program contract administrators with those identified by the Controller Division for Medicaid and CBHP prior to awarding federal funds to the subrecipients to ensure that payments are reported accurately on the Exhibit K1, Schedule of Federal Assistance, in accordance with the Office of the State Controller?s Fiscal Rules and Instructions for Exhibits and, ultimately, to the federal government on the State?s Schedule of Expenditures of Federal Awards. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department will conduct training with program management and division directors regarding the requirements for subrecipient monitoring and their responsibilities for secondary review. The training will include subrecipient versus contractor determination, the requirement of risk assessments and the importance of reporting determinations accurately in Colorado Operations Resource Engine. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly. The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions.
(A) The Department will conduct training with program management and division directors regarding the requirements for subrecipient monitoring and their responsibilities for secondary review. The training will include subrecipient versus contractor determination, the requirement of risk assessments and the importance of reporting determinations accurately in Colorado Operations Resource Engine (Donna Kellow, Greg Tanner, July 2021). (B) The Department is modifying its procurement and contracting process to require subrecipient determinations to be completed by the contract manager, Audits and Compliance designee and Controller on the front end of this process. This will be accomplished through a newly developed SharePoint form and workflow that will automatically route the determination to the individuals noted above and to Accounting staff so the appropriate coding can be applied and the Exhibit K1, Schedule of Federal Assistance is prepared and presented correctly. The SharePoint tool also automatically populates a database of subrecipients to ensure that program contract administrators, the Controller Division (including Procurement), and the Audits Division are all using the same source for determining and documenting subrecipients alleviating the need to reconcile different systems and determinations across divisions (Donna Kellow, Greg Tanner, July 2020).
2018-049
PERSONNEL COSTS FOR FEDERAL GRANT PROGRAMS Federal regulations require recipients of federal awards to develop adequate internal controls to ensure that personnel compensation expenditures are accurate, allowable, and properly allocated. The Department is required to follow Uniform Guidance when determining the Department?s federally-reimbursable costs, including personnel costs, for the federal programs it administers. The two largest federal programs the Department administered during Fiscal Year 2019 were Medicaid and CBHP. During Fiscal Year 2019, the Department used Clarity, a time reporting system, to track staff?s time and charge personnel costs to the respective federal grant program. During the year, the Department of Personnel & Administration (DPA) and OIT were continuing to pursue the implementation of HR Works, a statewide integrated human resources and payroll system. HR Works is expected to provide the Department with the ability to accurately track and report personnel costs for all staff. DPA and OIT would share the responsibility for implementing and managing HR Works. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to assess the Department?s internal controls over personnel costs associated with its administration of federal grants and to determine whether it complied with federal cost regulations under Uniform Guidance. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to federal grant personnel costs. Specifically, we recommended that the Department develop and implement interim policies and procedures to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations while it awaits the implementation of HR Works. The Department agreed with the recommendation and indicated that it would implement an interim process for those staff not currently using Clarity that complies with the federal cost regulation under Uniform Guidance. We first identified issues with the Department?s charging of personnel costs to its federal grants as a result of our Fiscal Year 2012 audit testwork. We performed testwork during our Fiscal Year 2019 audit to determine whether the Department implemented the prior audit recommendation and if it developed and implemented policies and procedures and an interim process to ensure that personnel costs were charged in accordance with federal regulations during Fiscal Year 2019. As part of our testing, we selected a random sample of 18 out of 81 semi-annual Periodic Time Certification Forms (Form) for the periods ending September 2018 and March 2019 (nine certifications from each period). These Forms are used by employees that worked on a single federal program during the fiscal year. We tested the sampled certifications to determine if they were signed in a timely manner by the employees? direct supervisors, as required by the Department?s internal policy. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations [2 CFR 200.430] require that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award. The Department?s Time/Effort Reporting Policy (Policy) that was effective as of June 30, 2019, requires employees who work on multiple federal grant programs to complete a monthly Personnel Activity Report (Report) in order to allocate employees? salaries or wages to the various programs and activities. Employees who work solely on a single federal grant program must complete a semi-annual Form. The Form states that the supervisor has to sign the Form to certify the work performed by the employee. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement our Fiscal Year 2018 recommendation. Specifically, we found the following issues: * LACK OF TIME TRACKING. The Department did not require employees working on multiple federal grant programs to complete the Report on a monthly basis. As a result, the Department did not have information necessary to allocate the employees? time among the various programs. * LACK OF TIMELY CERTIFICATIONS. We found that in all 18 Forms we reviewed for employees who worked solely on a single federal grant program were not signed by the supervisors in a timely manner. Specifically, supervisors signed all 18 of the Forms in June or July 2019 for the semi-annual periods ending September 2018 and March 2019, or about 8 months and 3 months, respectively, after the end of the certified period and, in some cases, after the fiscal year-end. The timing of the signatures also occurred after we inquired of Department staff about their progress of implementing our Fiscal Year 2018 recommendation. WHY DID THESE PROBLEMS OCCUR? The Department did not implement an interim timekeeping mechanism during Fiscal Year 2019 to ensure that all personnel costs charged to Medicaid and CBHP were accurate, allowable, and properly allocated. Additionally, while the Department developed an interim policy for tracking all staff?s time, including employees who worked on multiple federal programs during Fiscal Year 2019, the Department did not implement this policy during Fiscal Year 2019 for all staff to ensure compliance with federal cost regulations under Uniform Guidance. Furthermore, the Department?s policies and procedures did not specify the time requirement for direct supervisors to review and sign periodic certifications in a timely manner. WHY DO THESE PROBLEMS MATTER? Lack of adequate internal controls over the charging of personnel costs to federal grants increases the risk that expenditures will be charged to the federal program incorrectly, and that the Department will not be in compliance with federal grant requirements. It is especially important that the Department take steps to demonstrate that it has fully implemented our prior audit recommendation, because the Department has been out of compliance for several years. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 17S&CTITLE19MEDICAID 18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAID FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ALLOWABLE COSTS/COST PRINCIPLES (B) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-058 AND 2017-058 RECOMMENDATION 2019-051 The Department of Health Care Policy and Financing (Department) should improve its internal controls over personnel costs by: A Implementing the Time/Effort Reporting Policy as an interim tracking mechanism for all staff time to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards while it awaits the implementation of the State?s new timekeeping system. B Updating the Department?s current policies and procedures to specify time requirements for the direct supervisors to review and sign periodic certifications. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other. Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period.
Show full finding ▾Hide full finding ▴PERSONNEL COSTS FOR FEDERAL GRANT PROGRAMS Federal regulations require recipients of federal awards to develop adequate internal controls to ensure that personnel compensation expenditures are accurate, allowable, and properly allocated. The Department is required to follow Uniform Guidance when determining the Department?s federally-reimbursable costs, including personnel costs, for the federal programs it administers. The two largest federal programs the Department administered during Fiscal Year 2019 were Medicaid and CBHP. During Fiscal Year 2019, the Department used Clarity, a time reporting system, to track staff?s time and charge personnel costs to the respective federal grant program. During the year, the Department of Personnel & Administration (DPA) and OIT were continuing to pursue the implementation of HR Works, a statewide integrated human resources and payroll system. HR Works is expected to provide the Department with the ability to accurately track and report personnel costs for all staff. DPA and OIT would share the responsibility for implementing and managing HR Works. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to assess the Department?s internal controls over personnel costs associated with its administration of federal grants and to determine whether it complied with federal cost regulations under Uniform Guidance. Additionally, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendation related to federal grant personnel costs. Specifically, we recommended that the Department develop and implement interim policies and procedures to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations while it awaits the implementation of HR Works. The Department agreed with the recommendation and indicated that it would implement an interim process for those staff not currently using Clarity that complies with the federal cost regulation under Uniform Guidance. We first identified issues with the Department?s charging of personnel costs to its federal grants as a result of our Fiscal Year 2012 audit testwork. We performed testwork during our Fiscal Year 2019 audit to determine whether the Department implemented the prior audit recommendation and if it developed and implemented policies and procedures and an interim process to ensure that personnel costs were charged in accordance with federal regulations during Fiscal Year 2019. As part of our testing, we selected a random sample of 18 out of 81 semi-annual Periodic Time Certification Forms (Form) for the periods ending September 2018 and March 2019 (nine certifications from each period). These Forms are used by employees that worked on a single federal program during the fiscal year. We tested the sampled certifications to determine if they were signed in a timely manner by the employees? direct supervisors, as required by the Department?s internal policy. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulations [2 CFR 200.430] require that charges to federal awards for salaries and wages be based on records that accurately reflect the work performed. These records must (1) be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (2) be incorporated into the official records; (3) reasonably reflect the total activity for which the employee is compensated; and (4) support the distribution of the employee?s salary or wages among specific activities if the employee works on more than one federal award. The Department?s Time/Effort Reporting Policy (Policy) that was effective as of June 30, 2019, requires employees who work on multiple federal grant programs to complete a monthly Personnel Activity Report (Report) in order to allocate employees? salaries or wages to the various programs and activities. Employees who work solely on a single federal grant program must complete a semi-annual Form. The Form states that the supervisor has to sign the Form to certify the work performed by the employee. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department did not fully implement our Fiscal Year 2018 recommendation. Specifically, we found the following issues: * LACK OF TIME TRACKING. The Department did not require employees working on multiple federal grant programs to complete the Report on a monthly basis. As a result, the Department did not have information necessary to allocate the employees? time among the various programs. * LACK OF TIMELY CERTIFICATIONS. We found that in all 18 Forms we reviewed for employees who worked solely on a single federal grant program were not signed by the supervisors in a timely manner. Specifically, supervisors signed all 18 of the Forms in June or July 2019 for the semi-annual periods ending September 2018 and March 2019, or about 8 months and 3 months, respectively, after the end of the certified period and, in some cases, after the fiscal year-end. The timing of the signatures also occurred after we inquired of Department staff about their progress of implementing our Fiscal Year 2018 recommendation. WHY DID THESE PROBLEMS OCCUR? The Department did not implement an interim timekeeping mechanism during Fiscal Year 2019 to ensure that all personnel costs charged to Medicaid and CBHP were accurate, allowable, and properly allocated. Additionally, while the Department developed an interim policy for tracking all staff?s time, including employees who worked on multiple federal programs during Fiscal Year 2019, the Department did not implement this policy during Fiscal Year 2019 for all staff to ensure compliance with federal cost regulations under Uniform Guidance. Furthermore, the Department?s policies and procedures did not specify the time requirement for direct supervisors to review and sign periodic certifications in a timely manner. WHY DO THESE PROBLEMS MATTER? Lack of adequate internal controls over the charging of personnel costs to federal grants increases the risk that expenditures will be charged to the federal program incorrectly, and that the Department will not be in compliance with federal grant requirements. It is especially important that the Department take steps to demonstrate that it has fully implemented our prior audit recommendation, because the Department has been out of compliance for several years. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 CHIP2017 CHIP2018 CHIP2019 17S&CTITLE19MEDICAID 18S&CTITLE19MEDICAID 19S&CTITLE19MEDICAID FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.767, CHILDREN?S HEALTH INSURANCE PROGRAM; 93.777, STATE SURVEY AND CERTIFICATION OF HEALTH CARE PROVIDERS AND SUPPLIERS; 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ALLOWABLE COSTS/COST PRINCIPLES (B) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-058 AND 2017-058 RECOMMENDATION 2019-051 The Department of Health Care Policy and Financing (Department) should improve its internal controls over personnel costs by: A Implementing the Time/Effort Reporting Policy as an interim tracking mechanism for all staff time to ensure that personnel costs charged to federal grant programs are compliant with federal cost regulations under Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards while it awaits the implementation of the State?s new timekeeping system. B Updating the Department?s current policies and procedures to specify time requirements for the direct supervisors to review and sign periodic certifications. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other. Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period.
(A) The Department will continue with its implementation of an interim tracking mechanism through either semi-annual time certifications or 100%-time tracking. The Department will compare those staff currently tracking time under each mechanism to a list of all Department staff to identify those positions not currently covered by one mechanism or the other. Staff who are not covered by one of the above mechanisms will be required to either (a) to begin submitting semi-annual time certifications if they are dedicated to a single federal award or state program or (b) complete 100%-time tracking if they work on multiple federal awards and/or state programs (Donna Kellow, Greg Tanner, July 2020). (B) The Department will update its current semi-annual time certification policy and procedure to require direct supervisors to review and sign their staff's semi-annual time certifications within 30 days from the end of the certification period (Donna Kellow, Greg Tanner, July 2020).
2018-058
SERVICE ORGANIZATION CONTROLS REPORTS In 2017, the Health First Colorado program implemented the Colorado interChange System to replace the legacy Medicaid Management Information System. The Health First Colorado program is the State?s program, funded through the federal Medicaid grant, to provide public health insurance to eligible low-income citizens. The Health First Colorado program and the Colorado interChange system are the responsibility of the Department. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is DXC. The Colorado interChange system is currently hosted by DXC, who manages IT services related to the system infrastructure, software upgrades, and maintenance for the system. Therefore, DXC is considered a third-party service organization for the Department. The Department?s contractual agreement with DXC requires the third-party service organization to have an annual audit performed by an independent service auditor. Examinations of this type are governed by the AICPA, and result in one of various types of System and Organization Controls (SOC) reports. For the Department, DXC provides a SOC 1, Type II report, which provides the service auditors? opinion as to whether the service organization?s internal controls over the system have been suitably designed and are operating effectively, over a specified period of time, for the Department to rely on those controls as they relate to financial reporting. Service organizations can then subcontract services performed for a user entity, in this case the Department, to a subservice organization. If a service organization subcontracts services, a SOC 1, Type II report is also needed to provide assurance over the internal controls over financial reporting of the subservice organization for its respective system responsibilities. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine whether the Department had implemented the Fiscal Year 2017 recommendation to improve financial reporting internal controls and ensure compliance with federal regulations by holding vendors accountable for contract provisions regarding SOC reporting requirements, specifically related to the Colorado interChange system, on an annual basis. As noted by our prior audit recommendation, the SOC 1, Type II reports provided by the primary service organization, DXC, and any of its subservice organizations, should cover relevant information security processes for the Department?s Colorado interChange system that may impact internal controls over financial reporting, including database controls. We obtained and reviewed DXC?s Colorado interChange SOC 1, Type II report for Fiscal Year 2019. Within the report, we specifically reviewed the service auditor?s opinion on the presentation and suitability of the design and operating effectiveness of DXC?s internal controls. We analyzed the individual internal controls reported within the report, to ensure that database controls, relevant to the internal controls over financial reporting, were tested for operating effectiveness by the service auditor for Fiscal Year 2019. We also requested the relevant subservice organization reports to review for the same purpose. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following criteria: * The Manual, Section 3.4.1, Statewide Component Unit SOC Reviews, includes agency responsibilities related to the receipt of SOC reports. Specifically, agencies are to annually review the report and determine whether any actions are necessary to remediate issues noted. * The OSC?s policy, Internal Control System, requires state agencies to use the Green Book as its framework for its system of internal control. Specifically: ? Section 4, Additional Considerations, Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations and further states that management needs to understand the controls that each service organization has designed, has implemented, and operates for the assigned operational process and how the service organization?s internal control system impacts the entity?s internal control system. ? Principle 11, Design Activities for the Information System, Paragraph 11.15, Design of Information Technology Acquisition, Development, and Maintenance, states that management designs control activities over changes to technology. Paragraph 11.10, Design of Information Technology Infrastructure, indicates that management also designs control activities needed to maintain the IT infrastructure, which often includes backup and recovery procedures. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department held their service organization accountable for contract provisions for providing a SOC 1, Type II report for its service organization and the related subservice organizations to improve internal controls over its financial reporting. We also determined that some database controls, such as logical access controls, were added to the scope of the Fiscal Year 2019 DXC SOC 1, Type II report and tested. However, other relevant controls, such as database change management controls and database backup and recovery controls, both appropriate controls to include in a SOC report, were not specifically identified by DXC as being in scope in the SOC 1, Type II report. Therefore, we were unable to determine whether these database controls were tested for effectiveness, or opined on by the service auditor. This scope issue was not addressed by Department staff until after we notified them of the deficiency. WHY DID THESE PROBLEMS OCCUR? Department staff did not have a process in place to review and determine whether their service organizations have an effective internal control environment in place, including adequate IT internal control coverage in respective SOC 1, Type II reports. Specifically, Department staff failed to recognize that certain Colorado interChange system controls, such as database change management and database backup and recovery controls, were not clearly identified as being in the scope of controls tested and opined on in the SOC 1, Type II report. WHY DO THESE PROBLEMS MATTER? Failing to have a process in place that analyzes a service organization?s controls, as it relates to a SOC 1, Type II report and the Department?s relevant internal controls over financial reporting, could result in an incomplete scope of controls that should be tested for effectiveness and reported on. This, in turn, can cause uncertainty in user entities of the service organization, including the Department, in terms of whether the appropriate internal controls over financial reporting are in place and operating effectively over all of the system components, including the Colorado interChange database. Ultimately, without obtaining appropriate assurance over the database controls, this can adversely impact the reliability of the data within the State?s financial statements. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-055 AND 2017-053 RECOMMENDATION 2019-052 The Department of Health Care Policy and Financing should improve controls over its financial reporting by: A Working with its service organization, DXC Technology Services, LLC, to ensure that Colorado interChange SOC 1, Type II reports clearly state the system components and controls that are in scope, such as database change management and database backup and recovery controls. B Developing, documenting, implementing, and communicating a process for conducting reviews of the SOC 1, Type II reports, to ensure that all appropriate database internal controls impacting financial reporting are identified by the service organization, tested for effectiveness, and opined on by the service auditor in its SOC 1, Type II report. RESPONSE DEPARTMENT OF HEALTH CARE FINANCING AND POLICY A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate system components and controls that are in scope are clearly identified in future SOC 1, Type II reports. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate database internal controls are identified by the service organization, tested for effectiveness and opined on by the service auditor in its SOC 1, Type II report. The Department notes that the SOC 1, Type II audits are completed by service organizations for multiple lines of business beyond the Department's specific account. In addition, the service auditor is certified and all appropriate controls are included in their SOC reports. If the Department requests that the items outside of those audits are customized reports to meet these requirements there will be an additional cost to the State.
Show full finding ▾Hide full finding ▴SERVICE ORGANIZATION CONTROLS REPORTS In 2017, the Health First Colorado program implemented the Colorado interChange System to replace the legacy Medicaid Management Information System. The Health First Colorado program is the State?s program, funded through the federal Medicaid grant, to provide public health insurance to eligible low-income citizens. The Health First Colorado program and the Colorado interChange system are the responsibility of the Department. The fiscal agent responsible for performing internal controls and processing claims and payments, significant to the Department?s administration of the federal Medicaid program, is DXC. The Colorado interChange system is currently hosted by DXC, who manages IT services related to the system infrastructure, software upgrades, and maintenance for the system. Therefore, DXC is considered a third-party service organization for the Department. The Department?s contractual agreement with DXC requires the third-party service organization to have an annual audit performed by an independent service auditor. Examinations of this type are governed by the AICPA, and result in one of various types of System and Organization Controls (SOC) reports. For the Department, DXC provides a SOC 1, Type II report, which provides the service auditors? opinion as to whether the service organization?s internal controls over the system have been suitably designed and are operating effectively, over a specified period of time, for the Department to rely on those controls as they relate to financial reporting. Service organizations can then subcontract services performed for a user entity, in this case the Department, to a subservice organization. If a service organization subcontracts services, a SOC 1, Type II report is also needed to provide assurance over the internal controls over financial reporting of the subservice organization for its respective system responsibilities. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of our audit work was to determine whether the Department had implemented the Fiscal Year 2017 recommendation to improve financial reporting internal controls and ensure compliance with federal regulations by holding vendors accountable for contract provisions regarding SOC reporting requirements, specifically related to the Colorado interChange system, on an annual basis. As noted by our prior audit recommendation, the SOC 1, Type II reports provided by the primary service organization, DXC, and any of its subservice organizations, should cover relevant information security processes for the Department?s Colorado interChange system that may impact internal controls over financial reporting, including database controls. We obtained and reviewed DXC?s Colorado interChange SOC 1, Type II report for Fiscal Year 2019. Within the report, we specifically reviewed the service auditor?s opinion on the presentation and suitability of the design and operating effectiveness of DXC?s internal controls. We analyzed the individual internal controls reported within the report, to ensure that database controls, relevant to the internal controls over financial reporting, were tested for operating effectiveness by the service auditor for Fiscal Year 2019. We also requested the relevant subservice organization reports to review for the same purpose. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following criteria: * The Manual, Section 3.4.1, Statewide Component Unit SOC Reviews, includes agency responsibilities related to the receipt of SOC reports. Specifically, agencies are to annually review the report and determine whether any actions are necessary to remediate issues noted. * The OSC?s policy, Internal Control System, requires state agencies to use the Green Book as its framework for its system of internal control. Specifically: ? Section 4, Additional Considerations, Paragraph OV4.01, Service Organizations, states that management retains responsibility for the performance of processes assigned to service organizations and further states that management needs to understand the controls that each service organization has designed, has implemented, and operates for the assigned operational process and how the service organization?s internal control system impacts the entity?s internal control system. ? Principle 11, Design Activities for the Information System, Paragraph 11.15, Design of Information Technology Acquisition, Development, and Maintenance, states that management designs control activities over changes to technology. Paragraph 11.10, Design of Information Technology Infrastructure, indicates that management also designs control activities needed to maintain the IT infrastructure, which often includes backup and recovery procedures. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We determined that the Department held their service organization accountable for contract provisions for providing a SOC 1, Type II report for its service organization and the related subservice organizations to improve internal controls over its financial reporting. We also determined that some database controls, such as logical access controls, were added to the scope of the Fiscal Year 2019 DXC SOC 1, Type II report and tested. However, other relevant controls, such as database change management controls and database backup and recovery controls, both appropriate controls to include in a SOC report, were not specifically identified by DXC as being in scope in the SOC 1, Type II report. Therefore, we were unable to determine whether these database controls were tested for effectiveness, or opined on by the service auditor. This scope issue was not addressed by Department staff until after we notified them of the deficiency. WHY DID THESE PROBLEMS OCCUR? Department staff did not have a process in place to review and determine whether their service organizations have an effective internal control environment in place, including adequate IT internal control coverage in respective SOC 1, Type II reports. Specifically, Department staff failed to recognize that certain Colorado interChange system controls, such as database change management and database backup and recovery controls, were not clearly identified as being in the scope of controls tested and opined on in the SOC 1, Type II report. WHY DO THESE PROBLEMS MATTER? Failing to have a process in place that analyzes a service organization?s controls, as it relates to a SOC 1, Type II report and the Department?s relevant internal controls over financial reporting, could result in an incomplete scope of controls that should be tested for effectiveness and reported on. This, in turn, can cause uncertainty in user entities of the service organization, including the Department, in terms of whether the appropriate internal controls over financial reporting are in place and operating effectively over all of the system components, including the Colorado interChange database. Ultimately, without obtaining appropriate assurance over the database controls, this can adversely impact the reliability of the data within the State?s financial statements. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2017 XIX-MAP2018 XIX-MAP2019 XIX-ADM2017 XIX-ADM2018 XIX-ADM2019 FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SPECIAL TESTS AND PROVISIONS (N) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-055 AND 2017-053 RECOMMENDATION 2019-052 The Department of Health Care Policy and Financing should improve controls over its financial reporting by: A Working with its service organization, DXC Technology Services, LLC, to ensure that Colorado interChange SOC 1, Type II reports clearly state the system components and controls that are in scope, such as database change management and database backup and recovery controls. B Developing, documenting, implementing, and communicating a process for conducting reviews of the SOC 1, Type II reports, to ensure that all appropriate database internal controls impacting financial reporting are identified by the service organization, tested for effectiveness, and opined on by the service auditor in its SOC 1, Type II report. RESPONSE DEPARTMENT OF HEALTH CARE FINANCING AND POLICY A AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate system components and controls that are in scope are clearly identified in future SOC 1, Type II reports. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate database internal controls are identified by the service organization, tested for effectiveness and opined on by the service auditor in its SOC 1, Type II report. The Department notes that the SOC 1, Type II audits are completed by service organizations for multiple lines of business beyond the Department's specific account. In addition, the service auditor is certified and all appropriate controls are included in their SOC reports. If the Department requests that the items outside of those audits are customized reports to meet these requirements there will be an additional cost to the State.
(A) The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate system components and controls that are in scope are clearly identified in future SOC 1, Type II reports (Donna Kellow, Greg Tanner, July 2021). (B) The Department agrees to work with its service organization, DXC Technology Services, to ensure that the appropriate database internal controls are identified by the service organization, tested for effectiveness and opined on by the service auditor in its SOC 1, Type II report. The Department notes that the SOC 1, Type II audits are completed by service organizations for multiple lines of business beyond the Department's specific account. In addition, the service auditor is certified and all appropriate controls are included in their SOC reports. If the Department requests that the items outside of those audits are customized reports to meet these requirements there will be an additional cost to the State (Donna Kellow, Greg Tanner, July 2021).
2018-055
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. MEDICAID ELIGIBILITY?SYSTEM ISSUES The Colorado interChange system pays providers for the services that beneficiaries receive. Colorado interChange is programmed to determine whether Medicaid claims are allowable for payment based on requirements specified in federal and state Medicaid rules and regulations. During Fiscal Year 2018, the Department contracted with two fiscal agents to perform CBMS support services and Medicaid payment activities on behalf of the Department. Specifically, the Department contracted with DXC Technology to process and pay all claims within Colorado interChange and contracted with Deloitte Consulting, LLP (Deloitte) to manage CBMS. A fiscal agent is a contractor that performs certain eligibility and/or claims processing activities including accepting, processing, evaluating, and approving or rejecting applications. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as eligibility termination, new eligibility, and changes in Medicaid and CBHP programs. In addition, Colorado interChange is programmed to review the information uploaded from CBMS to ensure that all of the required information is provided. For example, Colorado interChange reviews for missing information such as a name, SSN, and/or date of birth. In addition, if there is an issue with the uploaded information, Colorado interChange rejects the information and creates an error report file that is sent to Deloitte. Deloitte reviews and separates the information in the error report based on responsibility for resolution, and sends the rejected information to either the Department, local county, or MA site, as applicable, to address the issues. The Department, local counties, and MA sites are responsible for investigating the reasons for the errors and addressing these issues either by updating the information in CBMS and/or Colorado interChange, or sending it to the applicable fiscal agent to correct any identified system issues. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid eligibility determination process as well as to determine whether the Department complied with applicable federal and state requirements during Fiscal Year 2018. During our audit, we reviewed the Department?s internal controls over Medicaid eligibility, and performed testing of a sample of 29 beneficiaries to determine whether the Department made inappropriate payments during Fiscal Year 2018 on behalf of the beneficiaries after their eligibility ended. We also reviewed the Medicaid payment information in Colorado interChange. In addition, we inquired about the Department?s monitoring procedures over counties and MA sites to ensure Medicaid payments are made in accordance with federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. According to federal regulation [2 CFR 200.303], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), issued by the Comptroller General of the United States, or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Under Principle 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, we identified data discrepancies between CBMS and Colorado interChange with four beneficiaries tested. These errors resulted in a total of $742 in known questioned costs; $371 of these costs were paid with federal grant funds. Specifically, we identified the following: * In one case, the Department paid claims totaling $359 through Colorado interChange after the beneficiary?s eligibility had ended and was discontinued in CBMS. The eligibility status in CBMS did not agree to the eligibility status in Colorado interChange, resulting in payments being made to providers on behalf of an individual that was not eligible for Medicaid benefits as required by federal and state regulations. After we notified the Department about the discrepancy, they indicated that this issue is isolated to beneficiaries that are enrolled in a specific program and have an Alternative Benefit Plan (ABP) in Colorado interChange. We inquired about the impact of this apparent system issue over other payments made through Colorado interChange and the Department provided a list of an additional 16,653 cases that had an ABP in Colorado interChange, and therefore, may potentially have the same issue. As of the end of our audit testwork in December 2018, the Department had not performed further research to determine whether any of these cases represented beneficiaries whose eligibility had ended but had payments inappropriately made on their behalf. In January 2019, Department staff reported that, based on their additional research, they determined that 1,517 of the 16,653 cases had an eligibility status in CBMS that did not agree to the eligibility status in Colorado interChange and that the Department did not pay medical claims inappropriately for these individuals but paid 105 pharmacy claims, totaling $5,298 inappropriately on those individuals? behalf. Because the Department provided this information after the completion of our audit, we were unable to determine the accuracy of this information. * In two cases, the Department paid claims totaling $139 through Colorado interChange after the participant?s eligibility ended and was discontinued in CBMS. As part of the daily system interface, the eligibility end date information from CBMS did not get uploaded to Colorado interChange. * In one case, the beneficiary was no longer eligible for the Medicaid program and moved into the CBHP program. Eligibility was appropriately updated in CBMS; however, Colorado interChange paid Medicaid claims totaling $244 even though the beneficiary was enrolled in the CBHP program. Based on the issues we identified, it appears that the error reports sent by Deloitte to the Department, local counties, and MA sites are not being reviewed, investigated, and addressed by updating the information in the applicable system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2018 to ensure that the information in Colorado interChange was appropriately updated with information in CBMS. The Department stated that the issues we identified were due to two Colorado interChange programming issues. First, Colorado interChange was not properly programmed upon implementation in March 2017 to close all eligibility fields completely when eligibility was ended in CBMS. Therefore, Colorado interChange continued to show the beneficiary as eligible for Medicaid and Colorado interChange continued making payments to providers. Upon follow-up, Department staff indicated that they identified this issue in October 2017 and the Colorado interChange system was modified in June 2018 to prevent this issue from happening in the future. However, the Department did not correct the issue for the cases that were affected prior to the system modification until after the end of Fiscal Year 2018. Second, the Department stated that Colorado interChange is not programmed to accept eligibility end dates uploaded from CBMS if the end date in CBMS is before the date of the daily interface with Colorado interChange. For example, if a beneficiary became ineligible for Medicaid on January 1 but the caseworker did not update the eligibility status in CBMS until January 15, when Colorado interChange interfaced with CBMS on January 15, it would not accept the January 1 end date noted in CBMS for the beneficiary. As a result, Colorado interChange would still show the beneficiary as eligible for Medicaid benefits. Because of this programming issue, Colorado interChange will note these individuals as eligible even though they are noted as ineligible in CBMS. The Department stated that it identified and corrected this system programming issue in June 2018; however, the Department has not researched or identified all of the cases affected by this issue. We also noted that the Department is lacking an internal control process for reconciling Medicaid eligibility information in CBMS and Colorado interChange to ensure that the information is consistent in both systems. Furthermore, the Department is not monitoring the counties and MA sites to ensure they are addressing any issues identified by Deloitte, the fiscal agent, in its error report. WHY DO THESE PROBLEMS MATTER? Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. In addition, Colorado interChange makes payments on behalf of other programs, such as CBHP, that have different federal reimbursement percentages. If beneficiaries? transfer information is not appropriately reflected in Colorado interChange, then the payments could be recorded in the wrong federal program with different reimbursement rates. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2016* XIX-ADM2016 XIX-MAP2017* XIX-ADM2017 XIX-MAP2018* XIX-ADM2018 FEDERAL AWARD YEARS 2016, 2017, AND 2018 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $742 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-045 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C Establishing a reconciliation process between CBMS and Colorado interChange to ensure that the eligibility information in CBMS is correctly reflected in Colorado interChange. D Monitoring the local counties and Medical Assistance eligibility sites to ensure that they are addressing any issues identified by the fiscal agent through error reports. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C AGREE. IMPLEMENTATION DATE: DECEMBER 2019. The Department has a team that evaluates beneficiary records in the Colorado interChange to ensure accuracy with CBMS, and if any discrepancies are identified they can be updated to ensure correct eligibility information is displayed in both systems. In addition, the Department plans to implement a system change that will eliminate the need to evaluate and manually update the beneficiary records by December 2019. D AGREE. IMPLEMENTATION DATE: JULY 2019. The Department will provide additional instructions to counties and Medical Assistance sites to ensure they are addressing any issues identified through error reports.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. MEDICAID ELIGIBILITY?SYSTEM ISSUES The Colorado interChange system pays providers for the services that beneficiaries receive. Colorado interChange is programmed to determine whether Medicaid claims are allowable for payment based on requirements specified in federal and state Medicaid rules and regulations. During Fiscal Year 2018, the Department contracted with two fiscal agents to perform CBMS support services and Medicaid payment activities on behalf of the Department. Specifically, the Department contracted with DXC Technology to process and pay all claims within Colorado interChange and contracted with Deloitte Consulting, LLP (Deloitte) to manage CBMS. A fiscal agent is a contractor that performs certain eligibility and/or claims processing activities including accepting, processing, evaluating, and approving or rejecting applications. CBMS interfaces with Colorado interChange on a daily basis to update eligibility information, such as eligibility termination, new eligibility, and changes in Medicaid and CBHP programs. In addition, Colorado interChange is programmed to review the information uploaded from CBMS to ensure that all of the required information is provided. For example, Colorado interChange reviews for missing information such as a name, SSN, and/or date of birth. In addition, if there is an issue with the uploaded information, Colorado interChange rejects the information and creates an error report file that is sent to Deloitte. Deloitte reviews and separates the information in the error report based on responsibility for resolution, and sends the rejected information to either the Department, local county, or MA site, as applicable, to address the issues. The Department, local counties, and MA sites are responsible for investigating the reasons for the errors and addressing these issues either by updating the information in CBMS and/or Colorado interChange, or sending it to the applicable fiscal agent to correct any identified system issues. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over the Medicaid eligibility determination process as well as to determine whether the Department complied with applicable federal and state requirements during Fiscal Year 2018. During our audit, we reviewed the Department?s internal controls over Medicaid eligibility, and performed testing of a sample of 29 beneficiaries to determine whether the Department made inappropriate payments during Fiscal Year 2018 on behalf of the beneficiaries after their eligibility ended. We also reviewed the Medicaid payment information in Colorado interChange. In addition, we inquired about the Department?s monitoring procedures over counties and MA sites to ensure Medicaid payments are made in accordance with federal and state regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? Federal regulation [42 CFR 447.56(e)(2)] states that federal funding will not be provided for payments made by the Department to providers for services provided on behalf of individuals who are not eligible for Medicaid. According to federal regulation [2 CFR 200.303], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government (Green Book), issued by the Comptroller General of the United States, or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Under Principle 16.01 of the Green Book, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? Overall, we identified data discrepancies between CBMS and Colorado interChange with four beneficiaries tested. These errors resulted in a total of $742 in known questioned costs; $371 of these costs were paid with federal grant funds. Specifically, we identified the following: * In one case, the Department paid claims totaling $359 through Colorado interChange after the beneficiary?s eligibility had ended and was discontinued in CBMS. The eligibility status in CBMS did not agree to the eligibility status in Colorado interChange, resulting in payments being made to providers on behalf of an individual that was not eligible for Medicaid benefits as required by federal and state regulations. After we notified the Department about the discrepancy, they indicated that this issue is isolated to beneficiaries that are enrolled in a specific program and have an Alternative Benefit Plan (ABP) in Colorado interChange. We inquired about the impact of this apparent system issue over other payments made through Colorado interChange and the Department provided a list of an additional 16,653 cases that had an ABP in Colorado interChange, and therefore, may potentially have the same issue. As of the end of our audit testwork in December 2018, the Department had not performed further research to determine whether any of these cases represented beneficiaries whose eligibility had ended but had payments inappropriately made on their behalf. In January 2019, Department staff reported that, based on their additional research, they determined that 1,517 of the 16,653 cases had an eligibility status in CBMS that did not agree to the eligibility status in Colorado interChange and that the Department did not pay medical claims inappropriately for these individuals but paid 105 pharmacy claims, totaling $5,298 inappropriately on those individuals? behalf. Because the Department provided this information after the completion of our audit, we were unable to determine the accuracy of this information. * In two cases, the Department paid claims totaling $139 through Colorado interChange after the participant?s eligibility ended and was discontinued in CBMS. As part of the daily system interface, the eligibility end date information from CBMS did not get uploaded to Colorado interChange. * In one case, the beneficiary was no longer eligible for the Medicaid program and moved into the CBHP program. Eligibility was appropriately updated in CBMS; however, Colorado interChange paid Medicaid claims totaling $244 even though the beneficiary was enrolled in the CBHP program. Based on the issues we identified, it appears that the error reports sent by Deloitte to the Department, local counties, and MA sites are not being reviewed, investigated, and addressed by updating the information in the applicable system. WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place during Fiscal Year 2018 to ensure that the information in Colorado interChange was appropriately updated with information in CBMS. The Department stated that the issues we identified were due to two Colorado interChange programming issues. First, Colorado interChange was not properly programmed upon implementation in March 2017 to close all eligibility fields completely when eligibility was ended in CBMS. Therefore, Colorado interChange continued to show the beneficiary as eligible for Medicaid and Colorado interChange continued making payments to providers. Upon follow-up, Department staff indicated that they identified this issue in October 2017 and the Colorado interChange system was modified in June 2018 to prevent this issue from happening in the future. However, the Department did not correct the issue for the cases that were affected prior to the system modification until after the end of Fiscal Year 2018. Second, the Department stated that Colorado interChange is not programmed to accept eligibility end dates uploaded from CBMS if the end date in CBMS is before the date of the daily interface with Colorado interChange. For example, if a beneficiary became ineligible for Medicaid on January 1 but the caseworker did not update the eligibility status in CBMS until January 15, when Colorado interChange interfaced with CBMS on January 15, it would not accept the January 1 end date noted in CBMS for the beneficiary. As a result, Colorado interChange would still show the beneficiary as eligible for Medicaid benefits. Because of this programming issue, Colorado interChange will note these individuals as eligible even though they are noted as ineligible in CBMS. The Department stated that it identified and corrected this system programming issue in June 2018; however, the Department has not researched or identified all of the cases affected by this issue. We also noted that the Department is lacking an internal control process for reconciling Medicaid eligibility information in CBMS and Colorado interChange to ensure that the information is consistent in both systems. Furthermore, the Department is not monitoring the counties and MA sites to ensure they are addressing any issues identified by Deloitte, the fiscal agent, in its error report. WHY DO THESE PROBLEMS MATTER? Failing to institute appropriate system controls over the processing of Medicaid eligibility can result in the counties and MA sites granting Medicaid benefits to ineligible individuals. Without appropriate internal controls, the local counties, MA sites, and ultimately the State cannot substantiate that eligibility determinations and redeterminations for Medicaid are accurate, which can result in benefits being paid on behalf of ineligible individuals. In addition, Colorado interChange makes payments on behalf of other programs, such as CBHP, that have different federal reimbursement percentages. If beneficiaries? transfer information is not appropriately reflected in Colorado interChange, then the payments could be recorded in the wrong federal program with different reimbursement rates. The federal government can disallow federal funds for program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS XIX-MAP2016* XIX-ADM2016 XIX-MAP2017* XIX-ADM2017 XIX-MAP2018* XIX-ADM2018 FEDERAL AWARD YEARS 2016, 2017, AND 2018 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENTS ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $742 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-045 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C Establishing a reconciliation process between CBMS and Colorado interChange to ensure that the eligibility information in CBMS is correctly reflected in Colorado interChange. D Monitoring the local counties and Medical Assistance eligibility sites to ensure that they are addressing any issues identified by the fiscal agent through error reports. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C AGREE. IMPLEMENTATION DATE: DECEMBER 2019. The Department has a team that evaluates beneficiary records in the Colorado interChange to ensure accuracy with CBMS, and if any discrepancies are identified they can be updated to ensure correct eligibility information is displayed in both systems. In addition, the Department plans to implement a system change that will eliminate the need to evaluate and manually update the beneficiary records by December 2019. D AGREE. IMPLEMENTATION DATE: JULY 2019. The Department will provide additional instructions to counties and Medical Assistance sites to ensure they are addressing any issues identified through error reports.
(A) In June 2018, the Department implemented a system change that allows the Colorado interChange to process retroactive eligibility changes to resolve eligibility end date information from CBMS that does not get uploaded to the Colorado interChange. In addition, the Department has a team that evaluates beneficiary records in the Colorado interChange to ensure accuracy with CBMS, and if any discrepancies are identified they can be updated to ensure correct eligibility information is displayed in both systems (Donna Kellow, Greg Tanner, July 2021). (B) In June 2018, the Department started a data cleanup project to correct the Alternative Benefit Plan beneficiary's eligibility spans, which was completed in September 2018. The data cleanup identified the beneficiaries that had an eligibility discrepancy between CBMS and Colorado interChange and resolved any discrepancies (Donna Kellow, Greg Tanner, Implemented). (C) The Department has a team that evaluates beneficiary records in the Colorado interChange to ensure accuracy with CBMS, and if any discrepancies are identified they can be updated to ensure correct eligibility information is displayed in both systems. In addition, the Department plans to implement a system change that will eliminate the need to evaluate and manually update the beneficiary records after the National Emergency related to COVID ends . The Department was scheduled to implement the reconciliation process on March 31, 2020 but was notified by CMS that Medicaid members eligibility could not be closed until after the National Emergency concludes (Donna Kellow, Greg Tanner, August 2020). (D) The Department will provide additional instructions to counties and Medical Assistance sites to ensure they are addressing any issues identified through error reports (Donna Kellow, Greg Tanner, July 2019).
2018-045
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. UNSUPPORTED CLAIMS FOR TARGETED CASE MANAGEMENT The CCBs provide ?Targeted Case Management? to individuals within a CCBs? service area who are enrolled in one of the State?s three Medicaid HCBS waiver programs for persons with intellectual and developmental disabilities reviewed by this audit. Federal law defines Targeted Case Management as case management services that are furnished ?to specific classes of individuals or to individuals who reside in specified areas? [42 USC 1396n(g)(2)(B)]. The CCBs bill for their Targeted Case Management services through the Department?s automated claims processing system, the Colorado interChange. CCB case managers are responsible for creating a log note for each Targeted Case Management activity and contact that is conducted on behalf of a recipient in the Department?s BUS. The log notes include details such as the date of the activity, the type of activity (e.g., face-to-face meeting, case documentation), who was contacted (e.g., recipient, direct service provider), the amount of time spent broken down into 15-minute units, and a narrative describing what occurred during the contact. Because the Department?s BUS system and the Colorado interChange do not interface with one another, the CCBs use monthly BUS reports, or other reports they generate in-house, to determine how many units of case management they can claim for reimbursement for each recipient. The CCBs submit claims for reimbursement, usually monthly, to the Colorado interChange. In Fiscal Year 2017, CCBs billed the State for an average of 30 hours, or 120 units, of Targeted Case Management, for each of the 12,456 waiver program recipients. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed all of the 127,793 Targeted Case Management claims submitted for services provided to 12,456 recipients, for which the Department paid $24 million to the CCBs during Fiscal Year 2017. We compared the monthly amount the Department paid the CCBs for these claims for each recipient to the billable Targeted Case Management activity that was recorded in 1,074,613 log note entries in the BUS. In this analysis, we also checked whether the log notes used to support claims were unduplicated and included a description of the case management activity in the narrative field. The purpose of this audit work was to determine whether the CCBs documented in the BUS all Targeted Case Management activities for HCBS waiver program recipients for which they claimed and received Medicaid reimbursement during State Fiscal Year 2017. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? The CCBs and the Department share responsibility for ensuring the accuracy of claims submitted through the Colorado interChange, as described below. CCBS MUST FULLY DOCUMENT TARGETED CASE MANAGEMENT ACTIVITIES. According to the Department?s Provider Participation Agreement, which is legally binding for each CCB, the CCBs are responsible for ensuring that all claims paid through Medicaid are compliant with all federal and state laws and regulations. This responsibility includes ensuring that every unit of Targeted Case Management a CCB claims for HCBS waiver program recipients is documented in the BUS, which the Department has designated as the system of record for log notes supporting billing claims. In accordance with federal documentation requirements, state regulations require CCBs to document specific elements of each Targeted Case Management activity, such as ?the name of the client; the date of the activity; the nature of the activity including whether it is direct or indirect contact;? and ?the content of the activity including the relevant observations, assessments, [and] findings? [10 CCR 2505-10 8.761.41]. State regulations further require that Targeted Case Management providers ?put documentation in log notes and enter it into the state data system? [10 CCR 2505-10 8.761.42]. THE DEPARTMENT SHOULD ENSURE THAT CCBS HAVE INFORMATION TO COMPLY WITH THE DOCUMENTATION REQUIREMENTS. Federal regulations [42 CFR 433.32] require the Department to ?maintain an accounting system and supporting fiscal records to assure that claims for federal funds are in accord with all applicable federal requirements.? Since the Department has designated the BUS as the official system of record for documentation to support billing within the HCBS waiver programs, the Department has an obligation to ensure that the BUS provides the necessary information to the CCBs for them to submit accurate claims, and to ensure that BUS features do not contribute to claims errors. The Department also has a responsibility to ensure that only accurate and compliant claims are paid. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We identified 5,784 claims for which the CCBs claimed and received payment for Targeted Case Management units during Fiscal Year 2017 that were not supported by case managers? log notes in the BUS. These unsupported claims occurred at each of the 20 CCBs, affected 3,374 recipients, and resulted in $432,363 in known questioned costs for Fiscal Year 2017, as explained in the bullets below. * CLAIMS WITH NO SUPPORTING LOG NOTES AT 18 CCBS. Eighteen of the 20 CCBs received reimbursement for a total of 3,951 claims for Targeted Case Management that had no log notes to support some or all of the units in the claim, resulting in $324,986 in known questioned costs. * CLAIMS BASED ON DUPLICATE LOG NOTES AT 19 CCBS. Nineteen CCBs received reimbursement for a total of 1,265 claims for Targeted Case Management for which some of the units in the claim were based on duplicate log notes, resulting in $54,228 in known questioned costs. The duplicate log notes consisted of entries where the name of the recipient, date, and narrative exactly matched another log note. We found that 70 percent of these duplicate log notes were recorded in the BUS within 1 minute of the prior entry. * CLAIMS BASED ON LOG NOTES WITH NO OR UNINTELLIGIBLE NARRATIVE AT ONE CCB. One CCB received reimbursement for 637 claims based on log notes that had no text or unintelligible text, such as the single letters ?f,? ?s,? ?v,? or ellipses, in the narrative section, resulting in $53,149 in known questioned costs. EXHIBIT 3.1 provides details of the unsupported claims. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the exhibit. WHY DID THIS PROBLEM OCCUR? We found that both the Department and the CCBs lack processes to ensure that only fully supported claims are submitted for reimbursement. Specifically, we found that the BUS, which is managed by the Department, lacked accurate information and reporting capabilities for use by the CCBs to ensure proper documentation for supporting Targeted Case Management claims. We also found issues with all 20 CCBs? billing practices that contributed to unsupported claims. INADEQUATE INFORMATION AVAILABLE FROM THE BUS All of the CCBs told us that limitations and errors in the information they could extract from the BUS in Fiscal Year 2017, as well as problems with the BUS?s user interface, created obstacles to ensuring that their billing was fully documented in the BUS. During the period covered by our audit, the BUS did not allow the CCBs to download their entire log notes for a specified timeframe (e.g., a month) so they could review them and verify that their claims were not based on missing or duplicate log notes or notes that lack descriptions of the case management activity. Although the BUS generated a monthly log note report for each CCB, the report only showed the number of service units each case manager entered for each recipient in the month, not the content of the associated log notes, such as the narrative text describing the nature of the activity. The report also did not show the total number of units of service for a recipient that had two or more case managers entering log notes. Furthermore, the report could not be exported into a data format, such as Excel, making it inefficient for the CCBs to review for completeness and accuracy. Finally, the CCBs told us that there are sometimes errors in the monthly log note reports; they had reported these to the Department on nine occasions in Fiscal Year 2017. Although the Department told us it corrected these errors, errors in the reports reduce their usefulness for ensuring billing accuracy and the frequency of such errors may indicate underlying problems in the BUS. The Department told us that in September 2018 it made new BUS reports available to the CCBs that can be downloaded in a number of formats, including Excel. According to the Department, one of these reports shows log note details for a selected timeframe, including recipients? identification numbers, indicators of whether the log note units can be billed for Targeted Case Management, and the narrative text. Because this change occurred near the end of our audit, we did not include a review of these reports in our audit scope. BUS USER INTERFACE PROBLEMS Sixteen of the 20 CCBs told us that the BUS sometimes generates duplicate log notes without the case manager?s awareness. Based on discussions with staff of the CCBs and the Department, it appears that this problem may be fairly common. Department staff stated that duplicates could be generated when a user clicks the ?Save? button more than once when entering a single log note. Several case managers described common situations that may lead to multiple saves, such as the system not always responding when they first click ?Save,? so they click the button again or re-enter the log note. Some case managers also said that the BUS sometimes logs them out or crashes while they are saving log notes, leading to them re-entering the notes, potentially causing duplicate entries. The Department told us that during our audit, in June 2018, it made enhancements to the BUS user interface that are designed to improve processing speed and may address these problems. PROBLEMS WITH CCB BILLING PROCEDURES The CCBs indicated that the actions described below also contributed to the problems we found. In these instances, routinely reviewing accurate and detailed BUS reports may be one of the most efficient ways for the CCBs to identify and prevent these actions to ensure that they only bill for services that are adequately supported. ERRORS IN THE CLAIMS. Some CCBs cited human or technology errors as contributing to the unsupported claims we found. Specifically: * Nine CCBs (Blue Peaks Developmental Services; Developmental Disabilities Resource Center; Imagine!; Mesa Developmental Services (Strive); Mountain Valley Developmental Services; North Metro Community Services, Inc.; Rocky Mountain Human Services; Southern Colorado Developmental Disabilities Services; and The Resource Exchange) erroneously submitted two or more claims covering the same case management activity for a recipient. Only the original claims for each recipient were supported by log notes in the BUS. * Three CCBs (Developmental Disabilities Resource Center, Developmental Pathways, and Envision) sometimes submitted Targeted Case Management claims for the wrong recipient in error, either because two recipients shared the same name and the BUS reports did not provide enough information to distinguish them, or because CCB staff made data-entry errors. As of September 1, 2018, the Department?s new BUS log note report includes recipients? identification numbers, which will help distinguish recipients that share the same first and last names. * One CCB (Developmental Disabilities Resource Center) mistakenly over-billed during a 2-month period when its new billing software automatically added an extra digit to the number of Targeted Case Management units claimed for some recipients. ROUTINE PRACTICES. Some CCBs reported the following practices that contributed to the unsupported claims we found. The CCBs should modify practices that may contribute to, or prevent detection of, billing errors. * At one CCB (The Resource Exchange), case managers documented activities that spanned several days, such as revising a recipient?s Service Plan, by entering identical log notes for each day they spent on the activity, causing the multiple log notes to appear to be errors. The CCB should develop guidance for case managers on entering activities that span several days to clearly indicate the entries are not duplicates. * AT Four CCBs (Developmental Pathways, Envision, Mesa Developmental Services (Strive), and The Resource Exchange) case management supervisors and other administrators sometimes delete log notes that they find to be inaccurate after billing claims have been submitted, and the CCBs do not have effective processes for ensuring that the claims are adjusted accordingly. The CCBs should develop guidance and procedures for post-billing reviews of accuracy to ensure that all changes to log notes in the BUS are also reflected in billing claims, as appropriate. * ONE CCB (COMMUNITY CONNECTIONS, INC.) ATTEMPTED TO CORRECT CASES OF INADVERTENT UNDER-BILLING BY INCREASING THE AMOUNT IT CLAIMED FOR A RECIPIENT IN THE FOLLOWING MONTH, RESULTING IN THE APPEARANCE OF OVER-BILLING. The CCB should discontinue this practice and work with the Department, as needed, to implement other methods to correct errors in billing. * Three CCBs that used in-house systems for recording log notes (Developmental Disabilities Resource Center, Imagine!, and Rocky Mountain Human Services) sometimes encountered system errors when uploading log notes to the BUS, resulting in some log notes not being uploaded and others having blanks in the narrative fields. According to the three CCBs, they have the supporting notes for some of the claims we identified in their own databases. However, since state regulations require that all Targeted Case Management activity be documented in the BUS, only BUS log notes can serve as valid support for Targeted Case Management claims. As of September 2018, the Department stopped allowing CCBs to upload notes into the BUS, requiring all log notes to be manually entered. Routinely reviewing the log note reports that the Department made available from the BUS in September 2018 could help the CCBs monitor whether log notes have been changed or deleted after billing, whether the log notes in the BUS are complete and unduplicated, and whether there are other errors in billing, to better ensure that their claims are fully supported by log notes. WHY DOES THIS PROBLEM MATTER? The unsupported claims we identified inflate the state and federal government costs of providing Targeted Case Management Services and indicate that all 20 CCBs failed to fully comply with federal law and/or contracts between the State and the CCBs. Specifically, we identified $432,363 in known questioned costs. Since Colorado?s Federal Medicaid Assistance Percentage was 50.72 and 50.02 percent in Federal Fiscal Years 2016 and 2017, respectively, the federal portion of these questioned costs is $217,306 and Colorado?s portion is $215,057. When CCBs are reimbursed for Targeted Case Management claims that lack supporting documentation, there is a risk that they could be paid federal and state Medicaid funds for services that were never provided to waiver program recipients. In addition, if the CCBs did provide the services but did not document them as required by federal and state regulations, the recipients? continuity of care and case managers? ability to monitor their health and safety could be compromised. For example, when the CCB assigns a new case manager to a recipient, the new case manager relies on log notes to understand the activities conducted for the recipient, the recipient?s needs, and any issues to be aware of that were discovered during face-to-face meetings or over phone and e-mail communication. When CCBs do not document log notes for Targeted Case Management activities conducted on behalf of the recipient, important details that could affect the recipient?s support needs, health, and progress toward goals will be lost. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $432,363 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-051 The Department of Health Care Policy and Financing should take steps to ensure that all claims paid to the Community-Centered Boards (CCBs) for Targeted Case Management are supported by documentation in the Benefits Utilization System (BUS) or its successor system, including: A Investigating the claims we identified as lacking supporting documentation in the BUS and recovering any overpayments, as appropriate. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2019. The Department has already begun investigating claims identified as lacking supporting documentation and initiate recoveries, as appropriate. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. UNSUPPORTED CLAIMS FOR TARGETED CASE MANAGEMENT The CCBs provide ?Targeted Case Management? to individuals within a CCBs? service area who are enrolled in one of the State?s three Medicaid HCBS waiver programs for persons with intellectual and developmental disabilities reviewed by this audit. Federal law defines Targeted Case Management as case management services that are furnished ?to specific classes of individuals or to individuals who reside in specified areas? [42 USC 1396n(g)(2)(B)]. The CCBs bill for their Targeted Case Management services through the Department?s automated claims processing system, the Colorado interChange. CCB case managers are responsible for creating a log note for each Targeted Case Management activity and contact that is conducted on behalf of a recipient in the Department?s BUS. The log notes include details such as the date of the activity, the type of activity (e.g., face-to-face meeting, case documentation), who was contacted (e.g., recipient, direct service provider), the amount of time spent broken down into 15-minute units, and a narrative describing what occurred during the contact. Because the Department?s BUS system and the Colorado interChange do not interface with one another, the CCBs use monthly BUS reports, or other reports they generate in-house, to determine how many units of case management they can claim for reimbursement for each recipient. The CCBs submit claims for reimbursement, usually monthly, to the Colorado interChange. In Fiscal Year 2017, CCBs billed the State for an average of 30 hours, or 120 units, of Targeted Case Management, for each of the 12,456 waiver program recipients. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed all of the 127,793 Targeted Case Management claims submitted for services provided to 12,456 recipients, for which the Department paid $24 million to the CCBs during Fiscal Year 2017. We compared the monthly amount the Department paid the CCBs for these claims for each recipient to the billable Targeted Case Management activity that was recorded in 1,074,613 log note entries in the BUS. In this analysis, we also checked whether the log notes used to support claims were unduplicated and included a description of the case management activity in the narrative field. The purpose of this audit work was to determine whether the CCBs documented in the BUS all Targeted Case Management activities for HCBS waiver program recipients for which they claimed and received Medicaid reimbursement during State Fiscal Year 2017. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? The CCBs and the Department share responsibility for ensuring the accuracy of claims submitted through the Colorado interChange, as described below. CCBS MUST FULLY DOCUMENT TARGETED CASE MANAGEMENT ACTIVITIES. According to the Department?s Provider Participation Agreement, which is legally binding for each CCB, the CCBs are responsible for ensuring that all claims paid through Medicaid are compliant with all federal and state laws and regulations. This responsibility includes ensuring that every unit of Targeted Case Management a CCB claims for HCBS waiver program recipients is documented in the BUS, which the Department has designated as the system of record for log notes supporting billing claims. In accordance with federal documentation requirements, state regulations require CCBs to document specific elements of each Targeted Case Management activity, such as ?the name of the client; the date of the activity; the nature of the activity including whether it is direct or indirect contact;? and ?the content of the activity including the relevant observations, assessments, [and] findings? [10 CCR 2505-10 8.761.41]. State regulations further require that Targeted Case Management providers ?put documentation in log notes and enter it into the state data system? [10 CCR 2505-10 8.761.42]. THE DEPARTMENT SHOULD ENSURE THAT CCBS HAVE INFORMATION TO COMPLY WITH THE DOCUMENTATION REQUIREMENTS. Federal regulations [42 CFR 433.32] require the Department to ?maintain an accounting system and supporting fiscal records to assure that claims for federal funds are in accord with all applicable federal requirements.? Since the Department has designated the BUS as the official system of record for documentation to support billing within the HCBS waiver programs, the Department has an obligation to ensure that the BUS provides the necessary information to the CCBs for them to submit accurate claims, and to ensure that BUS features do not contribute to claims errors. The Department also has a responsibility to ensure that only accurate and compliant claims are paid. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We identified 5,784 claims for which the CCBs claimed and received payment for Targeted Case Management units during Fiscal Year 2017 that were not supported by case managers? log notes in the BUS. These unsupported claims occurred at each of the 20 CCBs, affected 3,374 recipients, and resulted in $432,363 in known questioned costs for Fiscal Year 2017, as explained in the bullets below. * CLAIMS WITH NO SUPPORTING LOG NOTES AT 18 CCBS. Eighteen of the 20 CCBs received reimbursement for a total of 3,951 claims for Targeted Case Management that had no log notes to support some or all of the units in the claim, resulting in $324,986 in known questioned costs. * CLAIMS BASED ON DUPLICATE LOG NOTES AT 19 CCBS. Nineteen CCBs received reimbursement for a total of 1,265 claims for Targeted Case Management for which some of the units in the claim were based on duplicate log notes, resulting in $54,228 in known questioned costs. The duplicate log notes consisted of entries where the name of the recipient, date, and narrative exactly matched another log note. We found that 70 percent of these duplicate log notes were recorded in the BUS within 1 minute of the prior entry. * CLAIMS BASED ON LOG NOTES WITH NO OR UNINTELLIGIBLE NARRATIVE AT ONE CCB. One CCB received reimbursement for 637 claims based on log notes that had no text or unintelligible text, such as the single letters ?f,? ?s,? ?v,? or ellipses, in the narrative section, resulting in $53,149 in known questioned costs. EXHIBIT 3.1 provides details of the unsupported claims. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the exhibit. WHY DID THIS PROBLEM OCCUR? We found that both the Department and the CCBs lack processes to ensure that only fully supported claims are submitted for reimbursement. Specifically, we found that the BUS, which is managed by the Department, lacked accurate information and reporting capabilities for use by the CCBs to ensure proper documentation for supporting Targeted Case Management claims. We also found issues with all 20 CCBs? billing practices that contributed to unsupported claims. INADEQUATE INFORMATION AVAILABLE FROM THE BUS All of the CCBs told us that limitations and errors in the information they could extract from the BUS in Fiscal Year 2017, as well as problems with the BUS?s user interface, created obstacles to ensuring that their billing was fully documented in the BUS. During the period covered by our audit, the BUS did not allow the CCBs to download their entire log notes for a specified timeframe (e.g., a month) so they could review them and verify that their claims were not based on missing or duplicate log notes or notes that lack descriptions of the case management activity. Although the BUS generated a monthly log note report for each CCB, the report only showed the number of service units each case manager entered for each recipient in the month, not the content of the associated log notes, such as the narrative text describing the nature of the activity. The report also did not show the total number of units of service for a recipient that had two or more case managers entering log notes. Furthermore, the report could not be exported into a data format, such as Excel, making it inefficient for the CCBs to review for completeness and accuracy. Finally, the CCBs told us that there are sometimes errors in the monthly log note reports; they had reported these to the Department on nine occasions in Fiscal Year 2017. Although the Department told us it corrected these errors, errors in the reports reduce their usefulness for ensuring billing accuracy and the frequency of such errors may indicate underlying problems in the BUS. The Department told us that in September 2018 it made new BUS reports available to the CCBs that can be downloaded in a number of formats, including Excel. According to the Department, one of these reports shows log note details for a selected timeframe, including recipients? identification numbers, indicators of whether the log note units can be billed for Targeted Case Management, and the narrative text. Because this change occurred near the end of our audit, we did not include a review of these reports in our audit scope. BUS USER INTERFACE PROBLEMS Sixteen of the 20 CCBs told us that the BUS sometimes generates duplicate log notes without the case manager?s awareness. Based on discussions with staff of the CCBs and the Department, it appears that this problem may be fairly common. Department staff stated that duplicates could be generated when a user clicks the ?Save? button more than once when entering a single log note. Several case managers described common situations that may lead to multiple saves, such as the system not always responding when they first click ?Save,? so they click the button again or re-enter the log note. Some case managers also said that the BUS sometimes logs them out or crashes while they are saving log notes, leading to them re-entering the notes, potentially causing duplicate entries. The Department told us that during our audit, in June 2018, it made enhancements to the BUS user interface that are designed to improve processing speed and may address these problems. PROBLEMS WITH CCB BILLING PROCEDURES The CCBs indicated that the actions described below also contributed to the problems we found. In these instances, routinely reviewing accurate and detailed BUS reports may be one of the most efficient ways for the CCBs to identify and prevent these actions to ensure that they only bill for services that are adequately supported. ERRORS IN THE CLAIMS. Some CCBs cited human or technology errors as contributing to the unsupported claims we found. Specifically: * Nine CCBs (Blue Peaks Developmental Services; Developmental Disabilities Resource Center; Imagine!; Mesa Developmental Services (Strive); Mountain Valley Developmental Services; North Metro Community Services, Inc.; Rocky Mountain Human Services; Southern Colorado Developmental Disabilities Services; and The Resource Exchange) erroneously submitted two or more claims covering the same case management activity for a recipient. Only the original claims for each recipient were supported by log notes in the BUS. * Three CCBs (Developmental Disabilities Resource Center, Developmental Pathways, and Envision) sometimes submitted Targeted Case Management claims for the wrong recipient in error, either because two recipients shared the same name and the BUS reports did not provide enough information to distinguish them, or because CCB staff made data-entry errors. As of September 1, 2018, the Department?s new BUS log note report includes recipients? identification numbers, which will help distinguish recipients that share the same first and last names. * One CCB (Developmental Disabilities Resource Center) mistakenly over-billed during a 2-month period when its new billing software automatically added an extra digit to the number of Targeted Case Management units claimed for some recipients. ROUTINE PRACTICES. Some CCBs reported the following practices that contributed to the unsupported claims we found. The CCBs should modify practices that may contribute to, or prevent detection of, billing errors. * At one CCB (The Resource Exchange), case managers documented activities that spanned several days, such as revising a recipient?s Service Plan, by entering identical log notes for each day they spent on the activity, causing the multiple log notes to appear to be errors. The CCB should develop guidance for case managers on entering activities that span several days to clearly indicate the entries are not duplicates. * AT Four CCBs (Developmental Pathways, Envision, Mesa Developmental Services (Strive), and The Resource Exchange) case management supervisors and other administrators sometimes delete log notes that they find to be inaccurate after billing claims have been submitted, and the CCBs do not have effective processes for ensuring that the claims are adjusted accordingly. The CCBs should develop guidance and procedures for post-billing reviews of accuracy to ensure that all changes to log notes in the BUS are also reflected in billing claims, as appropriate. * ONE CCB (COMMUNITY CONNECTIONS, INC.) ATTEMPTED TO CORRECT CASES OF INADVERTENT UNDER-BILLING BY INCREASING THE AMOUNT IT CLAIMED FOR A RECIPIENT IN THE FOLLOWING MONTH, RESULTING IN THE APPEARANCE OF OVER-BILLING. The CCB should discontinue this practice and work with the Department, as needed, to implement other methods to correct errors in billing. * Three CCBs that used in-house systems for recording log notes (Developmental Disabilities Resource Center, Imagine!, and Rocky Mountain Human Services) sometimes encountered system errors when uploading log notes to the BUS, resulting in some log notes not being uploaded and others having blanks in the narrative fields. According to the three CCBs, they have the supporting notes for some of the claims we identified in their own databases. However, since state regulations require that all Targeted Case Management activity be documented in the BUS, only BUS log notes can serve as valid support for Targeted Case Management claims. As of September 2018, the Department stopped allowing CCBs to upload notes into the BUS, requiring all log notes to be manually entered. Routinely reviewing the log note reports that the Department made available from the BUS in September 2018 could help the CCBs monitor whether log notes have been changed or deleted after billing, whether the log notes in the BUS are complete and unduplicated, and whether there are other errors in billing, to better ensure that their claims are fully supported by log notes. WHY DOES THIS PROBLEM MATTER? The unsupported claims we identified inflate the state and federal government costs of providing Targeted Case Management Services and indicate that all 20 CCBs failed to fully comply with federal law and/or contracts between the State and the CCBs. Specifically, we identified $432,363 in known questioned costs. Since Colorado?s Federal Medicaid Assistance Percentage was 50.72 and 50.02 percent in Federal Fiscal Years 2016 and 2017, respectively, the federal portion of these questioned costs is $217,306 and Colorado?s portion is $215,057. When CCBs are reimbursed for Targeted Case Management claims that lack supporting documentation, there is a risk that they could be paid federal and state Medicaid funds for services that were never provided to waiver program recipients. In addition, if the CCBs did provide the services but did not document them as required by federal and state regulations, the recipients? continuity of care and case managers? ability to monitor their health and safety could be compromised. For example, when the CCB assigns a new case manager to a recipient, the new case manager relies on log notes to understand the activities conducted for the recipient, the recipient?s needs, and any issues to be aware of that were discovered during face-to-face meetings or over phone and e-mail communication. When CCBs do not document log notes for Targeted Case Management activities conducted on behalf of the recipient, important details that could affect the recipient?s support needs, health, and progress toward goals will be lost. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $432,363 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-051 The Department of Health Care Policy and Financing should take steps to ensure that all claims paid to the Community-Centered Boards (CCBs) for Targeted Case Management are supported by documentation in the Benefits Utilization System (BUS) or its successor system, including: A Investigating the claims we identified as lacking supporting documentation in the BUS and recovering any overpayments, as appropriate. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2019. The Department has already begun investigating claims identified as lacking supporting documentation and initiate recoveries, as appropriate. B This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation.
(A) Implemented. The Department?s Audits and Compliance Division reviewed the identified claims from the audit findings and sent out demand letters. Some of those demands for payment have been paid to the Department while others are in the appeal process (Donna Kellow, Greg Tanner, July 2019). (B) Implemented. The additional Log Notes reports created in September 2018 is working as designed and is being utilized by the Case Management Agencies. In February 2019, the Department began running a monthly duplicate log note report designed to identify potential duplicate log notes created by case managers at Community Centered Boards (CCBs). The Department shares the findings of this report with the CCBs monthly so that they can validate whether or not these identified log notes are duplicates. If the CCB confirms that they are duplicates, the Department has asked the case managers to delete all such notes. The BUS was upgraded to a 64-bit environment in June 2018, and users are not currently experiencing any significant lag time while using the BUS. The BUS is also more reliable, experiencing only 10 minutes of unscheduled downtime in the last 3 months (Donna Kellow, Greg Tanner, Implemented). (C) Implemented. Fully implemented - In June 2019, OIT completed a system fix to eliminate system-generated log notes, this fix also identified any system-generated duplicate notes dating back 3 years and deleted those as well. To prevent future system-generated notes, a nightly maintenance run in the BUS deletes any system-generated log notes created that day (Donna Kellow, Greg Tanner, Implemented).
2018-051
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. UNREASONABLE TARGETED CASE MANAGEMENT BILLING Targeted Case Management work carried out by the CCBs includes sending emails, making phone calls, and conducting in-person visits to identify direct service providers and monitor how well the provider is meeting each recipient?s needs. CCBs bill the Department for providing Targeted Case Management to HCBS waiver recipients in 15-minute units using the Colorado interChange. CCB case managers are responsible for tracking Targeted Case Management time for each recipient on their caseload, using the Department?s system for documenting recipient files, the BUS. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed log notes in the BUS for Fiscal Year 2017 to identify the Targeted Case Management activities and time CCB case managers logged and CCBs billed in a workday. We then compared this BUS information to the Targeted Case Management claims that the CCBs submitted and the Department paid through the Colorado interChange. The purpose of the audit work was to determine whether the CCBs billed and the Department paid for Targeted Case Management in accordance with federal and state rules and guidance, and to assess whether the bills and payments were reasonable. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? THE STATE SHOULD ONLY PAY FOR THE AMOUNT OF TIME A CASE MANAGER CAN REASONABLY PROVIDE SERVICES. ALTHOUGH NEITHER Federal nor state requirements explicitly limit the number of Targeted Case Management units that case managers can log and CCBs can bill for in a day, both federal and state guidance indicate that payment for Targeted Case Management should be based on the amount of work that is reasonable, feasible, and does not exceed the total amount of time the person worked. *CMS has issued guidance on acceptable practices for states that use 15-minute units for Targeted Case Management billing to ensure that states do not pay ?for more 15-minute units than [case management agencies] can feasibly deliver.? CMS? guidance states, ?Billable units are for time spent delivering a case management service? and provides examples of the methods some states have implemented to help them adhere to this guidance, such as requiring that case management agencies implement processes for a case management supervisor to certify the number of hours each day that the case manager was available to provide Targeted Case Management services and compare that hourly data to the number of 15-minute units that were billed and paid. When constructing the per unit payment rate for Targeted Case Management, some states have also adjusted the 15-minute unit rate to account for the ?non-productive time? in a case manager?s workday. The Department reported that it established its 15-minute unit rate based on a caseload of 40 recipients per case manager, devoting about 4 hours to each case per month and working a 40-hour week. * Under federal regulations ?a cost is reasonable if, in its nature and amount, it does not exceed that which would be incurred by a prudent person under the circumstances? [2 CFR 200.404]. * The Department provided written guidance to CCBs in July 2009 regarding reasonable billing, stating that, ?The number of units claimed by a case manager in a given time period cannot exceed the total amount of time worked. For example, a case manager who works 8 hours a day cannot exceed 32 units of claimable activities in that day.? The Department?s guidance also provides other examples of how CCBs should determine the number of units to bill based on time worked, including the following examples: * CCBs should claim two units when 25 minutes is spent one day to write a letter, and 5 minutes is spent the next day to mail the letter. * CCBs should claim four units when 1 hour is spent visiting a group of four recipients (because ?the total claimed units cannot exceed the total amount of time spent? and claiming the full hour for each of the four recipients ?exceeds the amount of time spent by that case manage by 3 hours? and ?the additional time is not claimable.?) This guidance was in effect during our audit review period (Fiscal Year 2017). CCBS SHOULD DOCUMENT THE DETAILS OF THE TOTAL CASE MANAGEMENT ACTIVITIES THEY BILL FOR. As a condition for payment, federal regulations require that Targeted Case Management log note documentation include the ?dates of the case management services? [42 CFR 441.18(a)(7)(ii)]. State regulations mirror that requirement and state that Targeted Case Management is only payable when it is supported by documentation that shows the date of the activity, among other pieces of information [10 CCR 2505-10-8.761.41.b]. Because the Department has not set an explicit limit or a standard as to a reasonable and feasible number of units a CCB may bill for per case manager per day, we considered claims that indicated a single case manager provided services for 24 hours or more in a day to be extreme examples of billing that was not based on a feasible or reasonable amount of time worked. Therefore, we reviewed whether any CCBs submitted claims for instances when a case manager entered log notes that represented 24 hours or more of work in a single day. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that 12 CCBs billed for at least one instance each of a single case manager providing 24 hours or more of Targeted Case Management services in a single day in Fiscal Year 2017, which is not feasible. EXHIBIT 3.3 shows that these 12 CCBs billed, and the Department paid, a total of $150,730 for 202 occasions on which the billing implies that case managers provided 24 hours or more of Targeted Case Management in a single day. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. We reviewed the log notes for a sample of 48 (24 percent) of these 202 days where case managers logged 24 hours or more of Targeted Case Management work in one day to determine whether these instances were due to data entry errors, and found none were. We then discussed these instances with the CCBs, who reported that, in general, they occurred when case managers performed a repetitive activity for many recipients in one day, such as mailing correspondence, updating recipient files, and reviewing documentation. For example: * A CASE MANAGER AT DEVELOPMENTAL PATHWAYS logged 112 hours of Targeted Case Management on February 27, 2017, for sending emails summarizing scheduling outcomes for 179 recipients? Service Plan meetings, and notifying 45 recipients that they were assigned a new case manager, along with writing log notes for each of these activities in the BUS. This case manager billed two 15-minute units for each of the email recipients, resulting in a total cost of about $7,100 for these notifications. * A CASE MANAGER AT THE RESOURCE EXCHANGE logged 51 hours and 15 minutes of Targeted Case Management on December 28, 2016, for receiving and reviewing documentation regarding 191 program recipients and sending notifications to their service providers. The case manager billed one 15-minute unit per recipient for conducting this review and sending emails, resulting in a total cost of about $3,200. * A CASE MANAGER AT MOUNTAIN VALLEY DEVELOPMENTAL SERVICES logged 59 hours and 45 minutes of Targeted Case Management on April 28, 2017, for activities which included reviewing and responding to direct service provider notes related to 37 recipients. The case manager billed 1 hour and 15 minutes for each recipient, resulting in a total cost of about $3,800. * A CASE MANAGER AT ROCKY MOUNTAIN HUMAN SERVICES logged 38 hours of Targeted Case Management on June 30, 2017, to mail bus passes to 152 recipients. The case manager billed one 15-minute unit for each bus pass mailed, resulting in a total cost of about $2,400. Of the 12 CCBs that billed 15-minute units for at least one case manager providing 24 hours or more of Targeted Case Management services in 1 day, seven CCBs agreed that it is never reasonable for staff to log that they worked more than 24 hours in a day. The other five CCBs told us that they believe that the practice is reasonable based on what the Department allows for billing, as described below. WHY DID THIS PROBLEM OCCUR? THE DEPARTMENT HAS NOT ESTABLISHED CONTROLS TO ENSURE THE REASONABLENESS OF TIME BILLED. The Department has not set a limit on the number of Targeted Case Management units or amount of time a CCB can bill per case manager per day and the billing be considered feasible. The Department stated that it has not implemented a daily billing limit because this limit is not a requirement in the guidance it received from CMS for the waiver programs that use 15-minute units for billing. The Department?s 2009 guidance states the CCBs should not bill for more Targeted Case Management than an individual worked, but does not provide a unit amount to limit billing. In October 2017, after our audit review period, the Department issued guidance stating that to calculate Targeted Case Management units, ?case managers are to accurately reflect the actual time it took to complete the [Targeted Case Management] activity.? The October 2017 guidance also states that for activities that do not take a full 15 minutes, CCBs may ?calculate one unit.? A few of the CCBs have interpreted this language to mean that if a case manager spends 1 minute on a Targeted Case Management service, such as sending an email, the case manager is authorized to log one 15-minute unit and the CCB is allowed to bill for much more time for an activity than was actually spent. Establishing guidance that CCBs may only bill for a full 15-minute unit when a case manager has spent a specified minimum time on an activity would be one way to help ensure that the State is not paying significantly more for case management than is being delivered. The Department of Human Services has implemented this methodology for reimbursing CCBs for Targeted Case Management for a different program. Specifically, the Department of Human Services requires case managers to spend at least 7.5 minutes in an activity before billing for a 15-minute unit. Although the Department stated that it already conducts periodic reviews to look for reasonableness of billing, establishing daily limits and stricter guidance to address when CCBs are allowed to bill one 15-minute unit would strengthen the Department?s overall controls for billing. CCBS DO NOT TRACK OR LIMIT TARGETED CASE MANAGEMENT BILLING BY CASE MANAGER. The 12 CCBs who billed for case managers? time exceeding 24 hours in a day have not established any limits on the number of Targeted Case Management units they bill per case manager per day, and do not track Targeted Case Management billing by case manager. In addition, none of these CCBs have review processes to ensure that case managers only bill for the amount of hours they can reasonably work in a day. The CCBs reported a number of reasons they sometimes bill for a case manager working more than 24 hours in a day as follows: * Eleven CCBs (Colorado Bluesky Enterprises, Inc.; Community Options, Inc.; Developmental Pathways; Developmental Disabilities Resource Center; Envision; Imagine!; Inspiration Field; Mesa Developmental Services (Strive); Mountain Valley Developmental Services; North Metro Community Services, Inc.; and The Resource Exchange) indicated the instances we identified occurred because of the timing of case managers entering their log notes in the BUS. Seven of these 11 CCBs reported that their case managers often conduct activities for several recipients over a number of days or weeks, and then summarize this work in log notes that are entered in the BUS on the same day, otherwise known as ?summary noting.? The BUS only allows for one date of contact to be entered, not a span of time, so summary noting makes it difficult for the CCBs and the Department to ensure that billing is accurate. For example, when we asked, management at the CCB Imagine! could not ascertain how a case manager determined the number of units to log for contacts that took several days. Additionally, five of the 11 CCBs indicated that the case managers may have entered all of their log notes at the end of the week or month, and did not manually change the date of service field in the BUS to reflect the actual dates of service, causing the BUS record to show that the case manager provided all of the services on the date the log notes were entered. After we discussed these issues with the Department, it set a new requirement, effective on September 1, 2018, that case managers must enter log notes within 5 Business Days, which the Department states will limit the CCBs? practice of summary noting. * Four CCBs (Colorado Bluesky Enterprises, Inc.; Developmental Disabilities Resource Center; Developmental Pathways; and Rocky Mountain Human Services) told us that they tell their case managers to bill for the actual time spent doing Targeted Case Management activities and for activities that take less than 15 minutes, to bill for a one 15-minute unit per recipient, such as when they are performing repetitive work that is more efficient to do for many recipients at once, because the Department?s requirements allow this practice. WHY DOES THIS PROBLEM MATTER? When a CCB bills for more time than case managers actually spend and the Department approves and pays the bills, the State?s cost for case management is artificially inflated. For example, if a case manager spends 5 minutes to talk with one recipient and document the conversation, then repeats this process with two additional recipients, the Department requires the case manager to create three individual log notes?one for each recipient. Although each activity only took 5 minutes, the CCB may then use each log note to bill a separate 15-minute unit. Thus, the CCB may bill for a total of three units (45 minutes) when only 15 minutes of total Targeted Case Management was provided. In this example, the bill would be $47.61, for three units, rather than $15.87 for the actual 15 minutes of time spent. Our analysis identified 3,409 instances across all 20 CCBs in which case managers documented providing more than 12 hours of Targeted Case Management in 1 day. This includes the 202 instances of CCBs billing for a case manager who documented working more than 24 hours in a day, plus another 2,847 instances where CCBs billed for case managers documenting having provided between 12 and 24 hours in a single day. If the Department had set a limit on the number of units per day per case manager that CCBs could bill based on hours worked, the State may have saved about $1 million dollars in Fiscal Year 2017. For example, if the Department had set a cap allowing billing for only 12 hours per day, the State would have saved about $1 million in state and federal funds that it paid for hours in excess of 12 per day per case manager. Further, billing for more than 24 hours of Targeted Case Management in a day tends to undermine the Department?s Targeted Case Management payment rate. The Department staff reported that when it set $15.87 as the rate for every 15-minute unit, the Department assumed that case managers would bill for an average of 7 hours of case management per workday. This daily average was based on underlying assumptions that case managers would (1) work a 40-hour week, (2) have about 40 recipients on their caseloads, and (3) provide an average of 3.67 hours of Targeted Case Management per month to each recipient. According to the Department, the rate accounts for all case management costs: direct personnel, supervision, benefits, and indirect costs such as administrative support. This methodology aligns with the 2008 CMS guidance on establishing controls over Targeted Case Management reimbursement. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02 DD: CO.0007.R07.02 SLS: CO.0293.R04.02 FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION RECOMMENDATION 2018-052 The Department of Health Care Policy and Financing should implement written billing guidance and controls to help ensure that its payments to Community-Centered Boards (CCBs) for Targeted Case Management are reasonable. The guidance and controls should (1) help ensure that the CCBs do not bill for case manager time that is not worked and (2) clarify how the CCBs should bill for small time increments. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: JULY 2020. The Department is working on redesigning case management, which includes the potential for new rates along with a new payment methodology. The Department is exploring ways in which Targeted Case Management can be reimbursed to help ensure that the CCBs bill in the most cost effective way that best reflects the actual time worked, and is considering a per-member per-month method to alleviate the need for case managers to track their time and associate units with tasks. Depending on rates and payment methodology, the Department may need to seek budgetary approval for changes, which would not be in effect until July 2020, if approved. In the interim, the Department will provide clarification to CCBs regarding Targeted Case Management billing practices, time increments, including mass documenting and mass billing. The Department has already implemented changes to assist in this effort, requiring case managers to document activities within five business days of the date of activity. The Department?s training on Targeted Case Management addresses these concerns by providing guidance on the four components of Targeted Case Management, with examples of what does and does not constitute a billable Targeted Case Management activity.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. UNREASONABLE TARGETED CASE MANAGEMENT BILLING Targeted Case Management work carried out by the CCBs includes sending emails, making phone calls, and conducting in-person visits to identify direct service providers and monitor how well the provider is meeting each recipient?s needs. CCBs bill the Department for providing Targeted Case Management to HCBS waiver recipients in 15-minute units using the Colorado interChange. CCB case managers are responsible for tracking Targeted Case Management time for each recipient on their caseload, using the Department?s system for documenting recipient files, the BUS. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed log notes in the BUS for Fiscal Year 2017 to identify the Targeted Case Management activities and time CCB case managers logged and CCBs billed in a workday. We then compared this BUS information to the Targeted Case Management claims that the CCBs submitted and the Department paid through the Colorado interChange. The purpose of the audit work was to determine whether the CCBs billed and the Department paid for Targeted Case Management in accordance with federal and state rules and guidance, and to assess whether the bills and payments were reasonable. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? THE STATE SHOULD ONLY PAY FOR THE AMOUNT OF TIME A CASE MANAGER CAN REASONABLY PROVIDE SERVICES. ALTHOUGH NEITHER Federal nor state requirements explicitly limit the number of Targeted Case Management units that case managers can log and CCBs can bill for in a day, both federal and state guidance indicate that payment for Targeted Case Management should be based on the amount of work that is reasonable, feasible, and does not exceed the total amount of time the person worked. *CMS has issued guidance on acceptable practices for states that use 15-minute units for Targeted Case Management billing to ensure that states do not pay ?for more 15-minute units than [case management agencies] can feasibly deliver.? CMS? guidance states, ?Billable units are for time spent delivering a case management service? and provides examples of the methods some states have implemented to help them adhere to this guidance, such as requiring that case management agencies implement processes for a case management supervisor to certify the number of hours each day that the case manager was available to provide Targeted Case Management services and compare that hourly data to the number of 15-minute units that were billed and paid. When constructing the per unit payment rate for Targeted Case Management, some states have also adjusted the 15-minute unit rate to account for the ?non-productive time? in a case manager?s workday. The Department reported that it established its 15-minute unit rate based on a caseload of 40 recipients per case manager, devoting about 4 hours to each case per month and working a 40-hour week. * Under federal regulations ?a cost is reasonable if, in its nature and amount, it does not exceed that which would be incurred by a prudent person under the circumstances? [2 CFR 200.404]. * The Department provided written guidance to CCBs in July 2009 regarding reasonable billing, stating that, ?The number of units claimed by a case manager in a given time period cannot exceed the total amount of time worked. For example, a case manager who works 8 hours a day cannot exceed 32 units of claimable activities in that day.? The Department?s guidance also provides other examples of how CCBs should determine the number of units to bill based on time worked, including the following examples: * CCBs should claim two units when 25 minutes is spent one day to write a letter, and 5 minutes is spent the next day to mail the letter. * CCBs should claim four units when 1 hour is spent visiting a group of four recipients (because ?the total claimed units cannot exceed the total amount of time spent? and claiming the full hour for each of the four recipients ?exceeds the amount of time spent by that case manage by 3 hours? and ?the additional time is not claimable.?) This guidance was in effect during our audit review period (Fiscal Year 2017). CCBS SHOULD DOCUMENT THE DETAILS OF THE TOTAL CASE MANAGEMENT ACTIVITIES THEY BILL FOR. As a condition for payment, federal regulations require that Targeted Case Management log note documentation include the ?dates of the case management services? [42 CFR 441.18(a)(7)(ii)]. State regulations mirror that requirement and state that Targeted Case Management is only payable when it is supported by documentation that shows the date of the activity, among other pieces of information [10 CCR 2505-10-8.761.41.b]. Because the Department has not set an explicit limit or a standard as to a reasonable and feasible number of units a CCB may bill for per case manager per day, we considered claims that indicated a single case manager provided services for 24 hours or more in a day to be extreme examples of billing that was not based on a feasible or reasonable amount of time worked. Therefore, we reviewed whether any CCBs submitted claims for instances when a case manager entered log notes that represented 24 hours or more of work in a single day. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that 12 CCBs billed for at least one instance each of a single case manager providing 24 hours or more of Targeted Case Management services in a single day in Fiscal Year 2017, which is not feasible. EXHIBIT 3.3 shows that these 12 CCBs billed, and the Department paid, a total of $150,730 for 202 occasions on which the billing implies that case managers provided 24 hours or more of Targeted Case Management in a single day. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. We reviewed the log notes for a sample of 48 (24 percent) of these 202 days where case managers logged 24 hours or more of Targeted Case Management work in one day to determine whether these instances were due to data entry errors, and found none were. We then discussed these instances with the CCBs, who reported that, in general, they occurred when case managers performed a repetitive activity for many recipients in one day, such as mailing correspondence, updating recipient files, and reviewing documentation. For example: * A CASE MANAGER AT DEVELOPMENTAL PATHWAYS logged 112 hours of Targeted Case Management on February 27, 2017, for sending emails summarizing scheduling outcomes for 179 recipients? Service Plan meetings, and notifying 45 recipients that they were assigned a new case manager, along with writing log notes for each of these activities in the BUS. This case manager billed two 15-minute units for each of the email recipients, resulting in a total cost of about $7,100 for these notifications. * A CASE MANAGER AT THE RESOURCE EXCHANGE logged 51 hours and 15 minutes of Targeted Case Management on December 28, 2016, for receiving and reviewing documentation regarding 191 program recipients and sending notifications to their service providers. The case manager billed one 15-minute unit per recipient for conducting this review and sending emails, resulting in a total cost of about $3,200. * A CASE MANAGER AT MOUNTAIN VALLEY DEVELOPMENTAL SERVICES logged 59 hours and 45 minutes of Targeted Case Management on April 28, 2017, for activities which included reviewing and responding to direct service provider notes related to 37 recipients. The case manager billed 1 hour and 15 minutes for each recipient, resulting in a total cost of about $3,800. * A CASE MANAGER AT ROCKY MOUNTAIN HUMAN SERVICES logged 38 hours of Targeted Case Management on June 30, 2017, to mail bus passes to 152 recipients. The case manager billed one 15-minute unit for each bus pass mailed, resulting in a total cost of about $2,400. Of the 12 CCBs that billed 15-minute units for at least one case manager providing 24 hours or more of Targeted Case Management services in 1 day, seven CCBs agreed that it is never reasonable for staff to log that they worked more than 24 hours in a day. The other five CCBs told us that they believe that the practice is reasonable based on what the Department allows for billing, as described below. WHY DID THIS PROBLEM OCCUR? THE DEPARTMENT HAS NOT ESTABLISHED CONTROLS TO ENSURE THE REASONABLENESS OF TIME BILLED. The Department has not set a limit on the number of Targeted Case Management units or amount of time a CCB can bill per case manager per day and the billing be considered feasible. The Department stated that it has not implemented a daily billing limit because this limit is not a requirement in the guidance it received from CMS for the waiver programs that use 15-minute units for billing. The Department?s 2009 guidance states the CCBs should not bill for more Targeted Case Management than an individual worked, but does not provide a unit amount to limit billing. In October 2017, after our audit review period, the Department issued guidance stating that to calculate Targeted Case Management units, ?case managers are to accurately reflect the actual time it took to complete the [Targeted Case Management] activity.? The October 2017 guidance also states that for activities that do not take a full 15 minutes, CCBs may ?calculate one unit.? A few of the CCBs have interpreted this language to mean that if a case manager spends 1 minute on a Targeted Case Management service, such as sending an email, the case manager is authorized to log one 15-minute unit and the CCB is allowed to bill for much more time for an activity than was actually spent. Establishing guidance that CCBs may only bill for a full 15-minute unit when a case manager has spent a specified minimum time on an activity would be one way to help ensure that the State is not paying significantly more for case management than is being delivered. The Department of Human Services has implemented this methodology for reimbursing CCBs for Targeted Case Management for a different program. Specifically, the Department of Human Services requires case managers to spend at least 7.5 minutes in an activity before billing for a 15-minute unit. Although the Department stated that it already conducts periodic reviews to look for reasonableness of billing, establishing daily limits and stricter guidance to address when CCBs are allowed to bill one 15-minute unit would strengthen the Department?s overall controls for billing. CCBS DO NOT TRACK OR LIMIT TARGETED CASE MANAGEMENT BILLING BY CASE MANAGER. The 12 CCBs who billed for case managers? time exceeding 24 hours in a day have not established any limits on the number of Targeted Case Management units they bill per case manager per day, and do not track Targeted Case Management billing by case manager. In addition, none of these CCBs have review processes to ensure that case managers only bill for the amount of hours they can reasonably work in a day. The CCBs reported a number of reasons they sometimes bill for a case manager working more than 24 hours in a day as follows: * Eleven CCBs (Colorado Bluesky Enterprises, Inc.; Community Options, Inc.; Developmental Pathways; Developmental Disabilities Resource Center; Envision; Imagine!; Inspiration Field; Mesa Developmental Services (Strive); Mountain Valley Developmental Services; North Metro Community Services, Inc.; and The Resource Exchange) indicated the instances we identified occurred because of the timing of case managers entering their log notes in the BUS. Seven of these 11 CCBs reported that their case managers often conduct activities for several recipients over a number of days or weeks, and then summarize this work in log notes that are entered in the BUS on the same day, otherwise known as ?summary noting.? The BUS only allows for one date of contact to be entered, not a span of time, so summary noting makes it difficult for the CCBs and the Department to ensure that billing is accurate. For example, when we asked, management at the CCB Imagine! could not ascertain how a case manager determined the number of units to log for contacts that took several days. Additionally, five of the 11 CCBs indicated that the case managers may have entered all of their log notes at the end of the week or month, and did not manually change the date of service field in the BUS to reflect the actual dates of service, causing the BUS record to show that the case manager provided all of the services on the date the log notes were entered. After we discussed these issues with the Department, it set a new requirement, effective on September 1, 2018, that case managers must enter log notes within 5 Business Days, which the Department states will limit the CCBs? practice of summary noting. * Four CCBs (Colorado Bluesky Enterprises, Inc.; Developmental Disabilities Resource Center; Developmental Pathways; and Rocky Mountain Human Services) told us that they tell their case managers to bill for the actual time spent doing Targeted Case Management activities and for activities that take less than 15 minutes, to bill for a one 15-minute unit per recipient, such as when they are performing repetitive work that is more efficient to do for many recipients at once, because the Department?s requirements allow this practice. WHY DOES THIS PROBLEM MATTER? When a CCB bills for more time than case managers actually spend and the Department approves and pays the bills, the State?s cost for case management is artificially inflated. For example, if a case manager spends 5 minutes to talk with one recipient and document the conversation, then repeats this process with two additional recipients, the Department requires the case manager to create three individual log notes?one for each recipient. Although each activity only took 5 minutes, the CCB may then use each log note to bill a separate 15-minute unit. Thus, the CCB may bill for a total of three units (45 minutes) when only 15 minutes of total Targeted Case Management was provided. In this example, the bill would be $47.61, for three units, rather than $15.87 for the actual 15 minutes of time spent. Our analysis identified 3,409 instances across all 20 CCBs in which case managers documented providing more than 12 hours of Targeted Case Management in 1 day. This includes the 202 instances of CCBs billing for a case manager who documented working more than 24 hours in a day, plus another 2,847 instances where CCBs billed for case managers documenting having provided between 12 and 24 hours in a single day. If the Department had set a limit on the number of units per day per case manager that CCBs could bill based on hours worked, the State may have saved about $1 million dollars in Fiscal Year 2017. For example, if the Department had set a cap allowing billing for only 12 hours per day, the State would have saved about $1 million in state and federal funds that it paid for hours in excess of 12 per day per case manager. Further, billing for more than 24 hours of Targeted Case Management in a day tends to undermine the Department?s Targeted Case Management payment rate. The Department staff reported that when it set $15.87 as the rate for every 15-minute unit, the Department assumed that case managers would bill for an average of 7 hours of case management per workday. This daily average was based on underlying assumptions that case managers would (1) work a 40-hour week, (2) have about 40 recipients on their caseloads, and (3) provide an average of 3.67 hours of Targeted Case Management per month to each recipient. According to the Department, the rate accounts for all case management costs: direct personnel, supervision, benefits, and indirect costs such as administrative support. This methodology aligns with the 2008 CMS guidance on establishing controls over Targeted Case Management reimbursement. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02 DD: CO.0007.R07.02 SLS: CO.0293.R04.02 FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION RECOMMENDATION 2018-052 The Department of Health Care Policy and Financing should implement written billing guidance and controls to help ensure that its payments to Community-Centered Boards (CCBs) for Targeted Case Management are reasonable. The guidance and controls should (1) help ensure that the CCBs do not bill for case manager time that is not worked and (2) clarify how the CCBs should bill for small time increments. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: JULY 2020. The Department is working on redesigning case management, which includes the potential for new rates along with a new payment methodology. The Department is exploring ways in which Targeted Case Management can be reimbursed to help ensure that the CCBs bill in the most cost effective way that best reflects the actual time worked, and is considering a per-member per-month method to alleviate the need for case managers to track their time and associate units with tasks. Depending on rates and payment methodology, the Department may need to seek budgetary approval for changes, which would not be in effect until July 2020, if approved. In the interim, the Department will provide clarification to CCBs regarding Targeted Case Management billing practices, time increments, including mass documenting and mass billing. The Department has already implemented changes to assist in this effort, requiring case managers to document activities within five business days of the date of activity. The Department?s training on Targeted Case Management addresses these concerns by providing guidance on the four components of Targeted Case Management, with examples of what does and does not constitute a billable Targeted Case Management activity.
On March 6, 2019 the Department sent an Operational Memo to Community Centered Boards (CCB) regarding billing and claims submissions for Targeted Case Management (TCM). The memo directs CCBs to discontinue billing TCM for mass documented case management activities. The memo also directs CCBs to only submit claims for the actual time an activity took when conducting the same activity for multiple individuals. The memo states that the TCM units associated with a single CCB case manager's log notes shall not exceed 24 hours in a single day. This completes the "interim" part of the Department's work described at left. The case-management redesign work is on track for completion as stated at left (Donna Kellow, Greg Tanner, July 2020).
2018-052
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. DIRECT SERVICE CLAIMS PAID WITHOUT PRIOR AUTHORIZATION The specific services that people with intellectual and developmental disabilities may receive through the State?s HCBS waiver programs depend on several factors, including the waiver program (HCBS-DD, SLS, or CES); the recipient?s support-level needs, goals, and desires; and applicable service caps. Adult recipients are assigned support levels (ranging from 1 to 7) based on their assessed needs. Recipients with higher support levels might require additional supervision, medical and behavioral supports, or assistance with activities related to home and community living. A recipient?s specific service needs and required levels of support are described in their Service Plan. Prior authorization requests for planned services are entered into the Colorado interChange using the Department?s coding system, which includes a unique procedure code for each service category as well as procedure code modifiers that identify the waiver program, level of support the recipient needs, and other details such as whether the service is provided in a group setting and whether it is medically necessary. For example, a prior authorization for specialized habilitation services for an adult could have a code of T2021.U8.TF.HQ. The first set of five characters indicates that the prior authorization is for the service category of Day Habilitation. The second set of two characters indicates that the recipient is enrolled in the HCBS-SLS waiver program. The third set of two characters indicates that an intermediate level of care (level 3) is required, and the fourth set of two characters indicates that the service will be provided in a group setting. In this example, the last modifier (HQ) distinguishes this specialized habilitation service from another type of day habilitation service called supported community connections. Each element of the code is important to ensure that providers are only paid for services that are defined in the recipients? Service Plans and that they are paid the correct amount. EXHIBIT 3.4 shows an example of the coding for Host Home Services at different levels and the payment rates for each. Although all seven levels of host home services share the same procedure code (T2016), they are distinguished by the string of procedure code modifiers. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. Certain services or service categories, such as assistive technology services and behavioral services, have limits on the total dollar amount that can be spent or on the total number of units that can be provided. Additionally, the HCBS-SLS waiver program has limits on the total amount that can be spent on a recipient?s entire Service Plan, depending on their support level. For example, support level 3 of the HCBS-SLS waiver specified a Fiscal Year 2017 Service Plan authorization limit of $19,882 that recipients could not exceed during their Service Plan year. There are about 160 combinations of procedure codes and modifiers for which the Department has established payment rates. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed the Department?s Medicaid data from the Colorado interChange including all claims for services provided during Fiscal Year 2017 and all prior authorizations for recipients who were enrolled in HCBS waiver programs for people with intellectual and developmental disabilities at any time during Fiscal Year 2017. We compared 1,781,214 paid claims totaling $53,866,835 with 140,371 prior authorizations in the Colorado interChange. The purpose of the audit work was to determine whether the services in the claims had been authorized before the claims were paid. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? PAYMENTS FOR SERVICE CLAIMS REQUIRE PRIOR AUTHORIZATIONS. State regulations [10 CCR 2505-10, Sections 8.500.14.B, 8.500.104.B, and 8.503.140.A] require that provider claims for reimbursement be made only when ?services have been prior authorized.? This requirement is based on federal regulations that state ?the [Department] must conduct prepayment claims review consisting of verification?that the provider was authorized to furnish the service at the time the service was furnished [42 CFR 447.45(f)(1)(i)].? According to the Department, when a provider submits a claim, the Colorado interChange should check whether the recipient has prior authorizations for the services and amounts in the claim and whether the service dates fall within the authorized time span. The Department told us that all of the codes from prior authorizations and claims should match exactly before the claims are paid. Thus, if a provider submits a claim for a service that does not precisely match a prior authorization, the Colorado interChange should reject the claim, thereby prompting the provider to resubmit the claim with corrected information. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department paid 6,130 claims that lacked prior authorization for the specific service and support level in the claim during Fiscal Year 2017, resulting in $344,302 in known questioned costs. For all 6,130 claims, the recipient had authorization for a similar service or different support level but did not have prior authorization for the specific service and support level in the claim. For example, one of these claims was for the service ?individual residential services and supports in a host home setting? at support level 4, with a rate of $144.67 per day. The Colorado interChange did not have a prior authorization for that service at support level 4 for this recipient, but did have a prior authorization for the service at support level 1, which has a rate of $60.19 per day. Due to the difference in rates between the services that were paid for and the services that were approved in the prior authorizations, these 6,130 claims resulted in overpayments of $344,302, which are known questioned costs, and potential underpayments of $73,950. The 6,130 claim payments ranged from $1.46 to about $14,956, with an average of about $352. WHY DID THIS PROBLEM OCCUR? The Department reported to us that the problems we found with the 6,130 claims were due to the Colorado interChange NOT BEING PROGRAMMED TO REQUIRE CLAIMS CODING TO EXACTLY MATCH PRIOR AUTHORIZATION CODING. Specifically, the Colorado interChange was designed to pay claims for which a prior authorization had the same procedure code and at least one modifier in common, even if the remaining three modifiers did not match. Examples include: * Claims the Department paid for Specialized Habilitation instead of Supported Community Connections, because these services share the procedure code T2021 (Day Habilitation) and the first modifier U8 that indicates which waiver program the recipient is in. * Claims the Department paid for residential services in a host home setting at support level 6, whereas the prior authorizations for the recipients were for level 5 support needs. Nearly all (98 percent) of the payments we identified that did not exactly match a prior authorization were paid after March 1, 2017, when the Department transitioned to the Colorado interChange. The Department reported to us that it had discovered in December 2017 that the Colorado interChange was erroneously paying claims that only partially matched the procedure codes and modifiers in prior authorizations. At that time, the Department requested an estimate of the cost to fix the problem from the system?s vendor. Once the Department receives an estimate it will determine its priority for implementing system changes. WHY DOES THIS PROBLEM MATTER? FEDERAL COST RECOVERIES. When the Department allows payments for unauthorized service claims, it is in violation of federal and state regulations and could be liable for federal cost recovery of a portion of the $344,302 in known questioned costs we identified. Based on a federal contribution rate of 50.72 percent [79 FR 71427] and 50.02 percent [80 FR 73781] for Federal Fiscal Years ending September 30, 2016, and September 30, 2017, for the State?s Medicaid program, the Department may have to repay up to $172,220 to the federal Centers for Medicare and Medicaid Services. POTENTIAL FOR WASTE. When the Department pays claims for services that are similar to, but not the same as, those specified in the prior authorizations, it risks overpaying for some services. For example, if the Department pays a claim for Supported Community Connections level 6 for someone who was only approved for level 1, the Department pays more than 2 times the approved rate. In total, we found that due to the provider billing for a service level that was higher than the service level authorized, the Department paid higher rates for 2,768 claims in Fiscal Year 2017 compared to the rates in prior authorizations, resulting in the $344,302 in overpayments. INCREASED RISK OF FRAUD. When the Department overpays providers, the risk of fraud and abuse increases because providers are incentivized to bill for services that are not authorized or bill for a service with a higher payment rate than the service actually provided. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $344,302 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-053 The Department of Health Care Policy and Financing should strengthen its controls in the Colorado interChange to ensure that claims for services provided through Medicaid Home and Community-Based Services waiver programs are paid only when there is a proper prior authorization. Such controls should be designed to prevent paying claims that do not have coding that exactly matches a prior authorization for the program recipient. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: SEPTEMBER 2019. The Department already identified this issue and is working to implement a system change to modify the Colorado interChange edits to ensure that claims for services provided through Medicaid Home and Community-Based Services Waivers are paid only when the provider?s coding on a claim exactly matches a prior authorization for the program recipient.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. DIRECT SERVICE CLAIMS PAID WITHOUT PRIOR AUTHORIZATION The specific services that people with intellectual and developmental disabilities may receive through the State?s HCBS waiver programs depend on several factors, including the waiver program (HCBS-DD, SLS, or CES); the recipient?s support-level needs, goals, and desires; and applicable service caps. Adult recipients are assigned support levels (ranging from 1 to 7) based on their assessed needs. Recipients with higher support levels might require additional supervision, medical and behavioral supports, or assistance with activities related to home and community living. A recipient?s specific service needs and required levels of support are described in their Service Plan. Prior authorization requests for planned services are entered into the Colorado interChange using the Department?s coding system, which includes a unique procedure code for each service category as well as procedure code modifiers that identify the waiver program, level of support the recipient needs, and other details such as whether the service is provided in a group setting and whether it is medically necessary. For example, a prior authorization for specialized habilitation services for an adult could have a code of T2021.U8.TF.HQ. The first set of five characters indicates that the prior authorization is for the service category of Day Habilitation. The second set of two characters indicates that the recipient is enrolled in the HCBS-SLS waiver program. The third set of two characters indicates that an intermediate level of care (level 3) is required, and the fourth set of two characters indicates that the service will be provided in a group setting. In this example, the last modifier (HQ) distinguishes this specialized habilitation service from another type of day habilitation service called supported community connections. Each element of the code is important to ensure that providers are only paid for services that are defined in the recipients? Service Plans and that they are paid the correct amount. EXHIBIT 3.4 shows an example of the coding for Host Home Services at different levels and the payment rates for each. Although all seven levels of host home services share the same procedure code (T2016), they are distinguished by the string of procedure code modifiers. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. Certain services or service categories, such as assistive technology services and behavioral services, have limits on the total dollar amount that can be spent or on the total number of units that can be provided. Additionally, the HCBS-SLS waiver program has limits on the total amount that can be spent on a recipient?s entire Service Plan, depending on their support level. For example, support level 3 of the HCBS-SLS waiver specified a Fiscal Year 2017 Service Plan authorization limit of $19,882 that recipients could not exceed during their Service Plan year. There are about 160 combinations of procedure codes and modifiers for which the Department has established payment rates. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed the Department?s Medicaid data from the Colorado interChange including all claims for services provided during Fiscal Year 2017 and all prior authorizations for recipients who were enrolled in HCBS waiver programs for people with intellectual and developmental disabilities at any time during Fiscal Year 2017. We compared 1,781,214 paid claims totaling $53,866,835 with 140,371 prior authorizations in the Colorado interChange. The purpose of the audit work was to determine whether the services in the claims had been authorized before the claims were paid. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? PAYMENTS FOR SERVICE CLAIMS REQUIRE PRIOR AUTHORIZATIONS. State regulations [10 CCR 2505-10, Sections 8.500.14.B, 8.500.104.B, and 8.503.140.A] require that provider claims for reimbursement be made only when ?services have been prior authorized.? This requirement is based on federal regulations that state ?the [Department] must conduct prepayment claims review consisting of verification?that the provider was authorized to furnish the service at the time the service was furnished [42 CFR 447.45(f)(1)(i)].? According to the Department, when a provider submits a claim, the Colorado interChange should check whether the recipient has prior authorizations for the services and amounts in the claim and whether the service dates fall within the authorized time span. The Department told us that all of the codes from prior authorizations and claims should match exactly before the claims are paid. Thus, if a provider submits a claim for a service that does not precisely match a prior authorization, the Colorado interChange should reject the claim, thereby prompting the provider to resubmit the claim with corrected information. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department paid 6,130 claims that lacked prior authorization for the specific service and support level in the claim during Fiscal Year 2017, resulting in $344,302 in known questioned costs. For all 6,130 claims, the recipient had authorization for a similar service or different support level but did not have prior authorization for the specific service and support level in the claim. For example, one of these claims was for the service ?individual residential services and supports in a host home setting? at support level 4, with a rate of $144.67 per day. The Colorado interChange did not have a prior authorization for that service at support level 4 for this recipient, but did have a prior authorization for the service at support level 1, which has a rate of $60.19 per day. Due to the difference in rates between the services that were paid for and the services that were approved in the prior authorizations, these 6,130 claims resulted in overpayments of $344,302, which are known questioned costs, and potential underpayments of $73,950. The 6,130 claim payments ranged from $1.46 to about $14,956, with an average of about $352. WHY DID THIS PROBLEM OCCUR? The Department reported to us that the problems we found with the 6,130 claims were due to the Colorado interChange NOT BEING PROGRAMMED TO REQUIRE CLAIMS CODING TO EXACTLY MATCH PRIOR AUTHORIZATION CODING. Specifically, the Colorado interChange was designed to pay claims for which a prior authorization had the same procedure code and at least one modifier in common, even if the remaining three modifiers did not match. Examples include: * Claims the Department paid for Specialized Habilitation instead of Supported Community Connections, because these services share the procedure code T2021 (Day Habilitation) and the first modifier U8 that indicates which waiver program the recipient is in. * Claims the Department paid for residential services in a host home setting at support level 6, whereas the prior authorizations for the recipients were for level 5 support needs. Nearly all (98 percent) of the payments we identified that did not exactly match a prior authorization were paid after March 1, 2017, when the Department transitioned to the Colorado interChange. The Department reported to us that it had discovered in December 2017 that the Colorado interChange was erroneously paying claims that only partially matched the procedure codes and modifiers in prior authorizations. At that time, the Department requested an estimate of the cost to fix the problem from the system?s vendor. Once the Department receives an estimate it will determine its priority for implementing system changes. WHY DOES THIS PROBLEM MATTER? FEDERAL COST RECOVERIES. When the Department allows payments for unauthorized service claims, it is in violation of federal and state regulations and could be liable for federal cost recovery of a portion of the $344,302 in known questioned costs we identified. Based on a federal contribution rate of 50.72 percent [79 FR 71427] and 50.02 percent [80 FR 73781] for Federal Fiscal Years ending September 30, 2016, and September 30, 2017, for the State?s Medicaid program, the Department may have to repay up to $172,220 to the federal Centers for Medicare and Medicaid Services. POTENTIAL FOR WASTE. When the Department pays claims for services that are similar to, but not the same as, those specified in the prior authorizations, it risks overpaying for some services. For example, if the Department pays a claim for Supported Community Connections level 6 for someone who was only approved for level 1, the Department pays more than 2 times the approved rate. In total, we found that due to the provider billing for a service level that was higher than the service level authorized, the Department paid higher rates for 2,768 claims in Fiscal Year 2017 compared to the rates in prior authorizations, resulting in the $344,302 in overpayments. INCREASED RISK OF FRAUD. When the Department overpays providers, the risk of fraud and abuse increases because providers are incentivized to bill for services that are not authorized or bill for a service with a higher payment rate than the service actually provided. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $344,302 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-053 The Department of Health Care Policy and Financing should strengthen its controls in the Colorado interChange to ensure that claims for services provided through Medicaid Home and Community-Based Services waiver programs are paid only when there is a proper prior authorization. Such controls should be designed to prevent paying claims that do not have coding that exactly matches a prior authorization for the program recipient. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: SEPTEMBER 2019. The Department already identified this issue and is working to implement a system change to modify the Colorado interChange edits to ensure that claims for services provided through Medicaid Home and Community-Based Services Waivers are paid only when the provider?s coding on a claim exactly matches a prior authorization for the program recipient.
The Department completed a system change to require an exact match on all PAR modifiers in Fall 2019. The change was communicated out to case management and providers and has been a successful system modification. This issue is complete and implemented (Donna Kellow, Greg Tanner, September 2019).
2018-053
The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. DIRECT SERVICE CLAIMS PAID WITHOUT PRIOR AUTHORIZATION The specific services that people with intellectual and developmental disabilities may receive through the State?s HCBS waiver programs depend on several factors, including the waiver program (HCBS-DD, SLS, or CES); the recipient?s support-level needs, goals, and desires; and applicable service caps. Adult recipients are assigned support levels (ranging from 1 to 7) based on their assessed needs. Recipients with higher support levels might require additional supervision, medical and behavioral supports, or assistance with activities related to home and community living. A recipient?s specific service needs and required levels of support are described in their Service Plan. Prior authorization requests for planned services are entered into the Colorado interChange using the Department?s coding system, which includes a unique procedure code for each service category as well as procedure code modifiers that identify the waiver program, level of support the recipient needs, and other details such as whether the service is provided in a group setting and whether it is medically necessary. For example, a prior authorization for specialized habilitation services for an adult could have a code of T2021.U8.TF.HQ. The first set of five characters indicates that the prior authorization is for the service category of Day Habilitation. The second set of two characters indicates that the recipient is enrolled in the HCBS-SLS waiver program. The third set of two characters indicates that an intermediate level of care (level 3) is required, and the fourth set of two characters indicates that the service will be provided in a group setting. In this example, the last modifier (HQ) distinguishes this specialized habilitation service from another type of day habilitation service called supported community connections. Each element of the code is important to ensure that providers are only paid for services that are defined in the recipients? Service Plans and that they are paid the correct amount. EXHIBIT 3.4 shows an example of the coding for Host Home Services at different levels and the payment rates for each. Although all seven levels of host home services share the same procedure code (T2016), they are distinguished by the string of procedure code modifiers. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. Certain services or service categories, such as assistive technology services and behavioral services, have limits on the total dollar amount that can be spent or on the total number of units that can be provided. Additionally, the HCBS-SLS waiver program has limits on the total amount that can be spent on a recipient?s entire Service Plan, depending on their support level. For example, support level 3 of the HCBS-SLS waiver specified a Fiscal Year 2017 Service Plan authorization limit of $19,882 that recipients could not exceed during their Service Plan year. There are about 160 combinations of procedure codes and modifiers for which the Department has established payment rates. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed the Department?s Medicaid data from the Colorado interChange including all claims for services provided during Fiscal Year 2017 and all prior authorizations for recipients who were enrolled in HCBS waiver programs for people with intellectual and developmental disabilities at any time during Fiscal Year 2017. We compared 1,781,214 paid claims totaling $53,866,835 with 140,371 prior authorizations in the Colorado interChange. The purpose of the audit work was to determine whether the services in the claims had been authorized before the claims were paid. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? PAYMENTS FOR SERVICE CLAIMS REQUIRE PRIOR AUTHORIZATIONS. State regulations [10 CCR 2505-10, Sections 8.500.14.B, 8.500.104.B, and 8.503.140.A] require that provider claims for reimbursement be made only when ?services have been prior authorized.? This requirement is based on federal regulations that state ?the [Department] must conduct prepayment claims review consisting of verification?that the provider was authorized to furnish the service at the time the service was furnished [42 CFR 447.45(f)(1)(i)].? According to the Department, when a provider submits a claim, the Colorado interChange should check whether the recipient has prior authorizations for the services and amounts in the claim and whether the service dates fall within the authorized time span. The Department told us that all of the codes from prior authorizations and claims should match exactly before the claims are paid. Thus, if a provider submits a claim for a service that does not precisely match a prior authorization, the Colorado interChange should reject the claim, thereby prompting the provider to resubmit the claim with corrected information. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department paid 6,130 claims that lacked prior authorization for the specific service and support level in the claim during Fiscal Year 2017, resulting in $344,302 in known questioned costs. For all 6,130 claims, the recipient had authorization for a similar service or different support level but did not have prior authorization for the specific service and support level in the claim. For example, one of these claims was for the service ?individual residential services and supports in a host home setting? at support level 4, with a rate of $144.67 per day. The Colorado interChange did not have a prior authorization for that service at support level 4 for this recipient, but did have a prior authorization for the service at support level 1, which has a rate of $60.19 per day. Due to the difference in rates between the services that were paid for and the services that were approved in the prior authorizations, these 6,130 claims resulted in overpayments of $344,302, which are known questioned costs, and potential underpayments of $73,950. The 6,130 claim payments ranged from $1.46 to about $14,956, with an average of about $352. WHY DID THIS PROBLEM OCCUR? The Department reported to us that the problems we found with the 6,130 claims were due to the Colorado interChange NOT BEING PROGRAMMED TO REQUIRE CLAIMS CODING TO EXACTLY MATCH PRIOR AUTHORIZATION CODING. Specifically, the Colorado interChange was designed to pay claims for which a prior authorization had the same procedure code and at least one modifier in common, even if the remaining three modifiers did not match. Examples include: * Claims the Department paid for Specialized Habilitation instead of Supported Community Connections, because these services share the procedure code T2021 (Day Habilitation) and the first modifier U8 that indicates which waiver program the recipient is in. * Claims the Department paid for residential services in a host home setting at support level 6, whereas the prior authorizations for the recipients were for level 5 support needs. Nearly all (98 percent) of the payments we identified that did not exactly match a prior authorization were paid after March 1, 2017, when the Department transitioned to the Colorado interChange. The Department reported to us that it had discovered in December 2017 that the Colorado interChange was erroneously paying claims that only partially matched the procedure codes and modifiers in prior authorizations. At that time, the Department requested an estimate of the cost to fix the problem from the system?s vendor. Once the Department receives an estimate it will determine its priority for implementing system changes. WHY DOES THIS PROBLEM MATTER? FEDERAL COST RECOVERIES. When the Department allows payments for unauthorized service claims, it is in violation of federal and state regulations and could be liable for federal cost recovery of a portion of the $344,302 in known questioned costs we identified. Based on a federal contribution rate of 50.72 percent [79 FR 71427] and 50.02 percent [80 FR 73781] for Federal Fiscal Years ending September 30, 2016, and September 30, 2017, for the State?s Medicaid program, the Department may have to repay up to $172,220 to the federal Centers for Medicare and Medicaid Services. POTENTIAL FOR WASTE. When the Department pays claims for services that are similar to, but not the same as, those specified in the prior authorizations, it risks overpaying for some services. For example, if the Department pays a claim for Supported Community Connections level 6 for someone who was only approved for level 1, the Department pays more than 2 times the approved rate. In total, we found that due to the provider billing for a service level that was higher than the service level authorized, the Department paid higher rates for 2,768 claims in Fiscal Year 2017 compared to the rates in prior authorizations, resulting in the $344,302 in overpayments. INCREASED RISK OF FRAUD. When the Department overpays providers, the risk of fraud and abuse increases because providers are incentivized to bill for services that are not authorized or bill for a service with a higher payment rate than the service actually provided. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $344,302 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-054 The Department of Health Care Policy and Financing should review the payments made for the 6,130 service claims without matching prior authorization identified in the audit to determine whether the payments were allowable and recover unallowable payments and over-payments, as appropriate. Until the Department implements RECOMMENDATION 2018-053, it should also review claims that were paid after the audit review period to determine whether any lacked prior authorization and recover unallowable payments and over-payments, as appropriate. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: SEPTEMBER 2019. The Department will review the payments made for the service claims that were identified in the audit to determine whether the payments were allowable. Until the Department implements a system change to modify the Colorado interChange edits to ensure that claims for services provided through Medicaid Home and Community-Based Services Waivers are paid only when the provider?s coding on a claim exactly matches a prior authorization for the program recipient, the Department will review claims and recover unallowable payments and over-payments, as appropriate.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies each classified as a MATERIAL WEAKNESS were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendation can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. DIRECT SERVICE CLAIMS PAID WITHOUT PRIOR AUTHORIZATION The specific services that people with intellectual and developmental disabilities may receive through the State?s HCBS waiver programs depend on several factors, including the waiver program (HCBS-DD, SLS, or CES); the recipient?s support-level needs, goals, and desires; and applicable service caps. Adult recipients are assigned support levels (ranging from 1 to 7) based on their assessed needs. Recipients with higher support levels might require additional supervision, medical and behavioral supports, or assistance with activities related to home and community living. A recipient?s specific service needs and required levels of support are described in their Service Plan. Prior authorization requests for planned services are entered into the Colorado interChange using the Department?s coding system, which includes a unique procedure code for each service category as well as procedure code modifiers that identify the waiver program, level of support the recipient needs, and other details such as whether the service is provided in a group setting and whether it is medically necessary. For example, a prior authorization for specialized habilitation services for an adult could have a code of T2021.U8.TF.HQ. The first set of five characters indicates that the prior authorization is for the service category of Day Habilitation. The second set of two characters indicates that the recipient is enrolled in the HCBS-SLS waiver program. The third set of two characters indicates that an intermediate level of care (level 3) is required, and the fourth set of two characters indicates that the service will be provided in a group setting. In this example, the last modifier (HQ) distinguishes this specialized habilitation service from another type of day habilitation service called supported community connections. Each element of the code is important to ensure that providers are only paid for services that are defined in the recipients? Service Plans and that they are paid the correct amount. EXHIBIT 3.4 shows an example of the coding for Host Home Services at different levels and the payment rates for each. Although all seven levels of host home services share the same procedure code (T2016), they are distinguished by the string of procedure code modifiers. See Fiscal Year 2018 Schedule of Findings and Questioned Costs for the Exhibit. Certain services or service categories, such as assistive technology services and behavioral services, have limits on the total dollar amount that can be spent or on the total number of units that can be provided. Additionally, the HCBS-SLS waiver program has limits on the total amount that can be spent on a recipient?s entire Service Plan, depending on their support level. For example, support level 3 of the HCBS-SLS waiver specified a Fiscal Year 2017 Service Plan authorization limit of $19,882 that recipients could not exceed during their Service Plan year. There are about 160 combinations of procedure codes and modifiers for which the Department has established payment rates. WHAT AUDIT WORK WAS PERFORMED AND WHAT WAS THE PURPOSE? We analyzed the Department?s Medicaid data from the Colorado interChange including all claims for services provided during Fiscal Year 2017 and all prior authorizations for recipients who were enrolled in HCBS waiver programs for people with intellectual and developmental disabilities at any time during Fiscal Year 2017. We compared 1,781,214 paid claims totaling $53,866,835 with 140,371 prior authorizations in the Colorado interChange. The purpose of the audit work was to determine whether the services in the claims had been authorized before the claims were paid. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? PAYMENTS FOR SERVICE CLAIMS REQUIRE PRIOR AUTHORIZATIONS. State regulations [10 CCR 2505-10, Sections 8.500.14.B, 8.500.104.B, and 8.503.140.A] require that provider claims for reimbursement be made only when ?services have been prior authorized.? This requirement is based on federal regulations that state ?the [Department] must conduct prepayment claims review consisting of verification?that the provider was authorized to furnish the service at the time the service was furnished [42 CFR 447.45(f)(1)(i)].? According to the Department, when a provider submits a claim, the Colorado interChange should check whether the recipient has prior authorizations for the services and amounts in the claim and whether the service dates fall within the authorized time span. The Department told us that all of the codes from prior authorizations and claims should match exactly before the claims are paid. Thus, if a provider submits a claim for a service that does not precisely match a prior authorization, the Colorado interChange should reject the claim, thereby prompting the provider to resubmit the claim with corrected information. WHAT PROBLEM DID THE AUDIT WORK IDENTIFY? We found that the Department paid 6,130 claims that lacked prior authorization for the specific service and support level in the claim during Fiscal Year 2017, resulting in $344,302 in known questioned costs. For all 6,130 claims, the recipient had authorization for a similar service or different support level but did not have prior authorization for the specific service and support level in the claim. For example, one of these claims was for the service ?individual residential services and supports in a host home setting? at support level 4, with a rate of $144.67 per day. The Colorado interChange did not have a prior authorization for that service at support level 4 for this recipient, but did have a prior authorization for the service at support level 1, which has a rate of $60.19 per day. Due to the difference in rates between the services that were paid for and the services that were approved in the prior authorizations, these 6,130 claims resulted in overpayments of $344,302, which are known questioned costs, and potential underpayments of $73,950. The 6,130 claim payments ranged from $1.46 to about $14,956, with an average of about $352. WHY DID THIS PROBLEM OCCUR? The Department reported to us that the problems we found with the 6,130 claims were due to the Colorado interChange NOT BEING PROGRAMMED TO REQUIRE CLAIMS CODING TO EXACTLY MATCH PRIOR AUTHORIZATION CODING. Specifically, the Colorado interChange was designed to pay claims for which a prior authorization had the same procedure code and at least one modifier in common, even if the remaining three modifiers did not match. Examples include: * Claims the Department paid for Specialized Habilitation instead of Supported Community Connections, because these services share the procedure code T2021 (Day Habilitation) and the first modifier U8 that indicates which waiver program the recipient is in. * Claims the Department paid for residential services in a host home setting at support level 6, whereas the prior authorizations for the recipients were for level 5 support needs. Nearly all (98 percent) of the payments we identified that did not exactly match a prior authorization were paid after March 1, 2017, when the Department transitioned to the Colorado interChange. The Department reported to us that it had discovered in December 2017 that the Colorado interChange was erroneously paying claims that only partially matched the procedure codes and modifiers in prior authorizations. At that time, the Department requested an estimate of the cost to fix the problem from the system?s vendor. Once the Department receives an estimate it will determine its priority for implementing system changes. WHY DOES THIS PROBLEM MATTER? FEDERAL COST RECOVERIES. When the Department allows payments for unauthorized service claims, it is in violation of federal and state regulations and could be liable for federal cost recovery of a portion of the $344,302 in known questioned costs we identified. Based on a federal contribution rate of 50.72 percent [79 FR 71427] and 50.02 percent [80 FR 73781] for Federal Fiscal Years ending September 30, 2016, and September 30, 2017, for the State?s Medicaid program, the Department may have to repay up to $172,220 to the federal Centers for Medicare and Medicaid Services. POTENTIAL FOR WASTE. When the Department pays claims for services that are similar to, but not the same as, those specified in the prior authorizations, it risks overpaying for some services. For example, if the Department pays a claim for Supported Community Connections level 6 for someone who was only approved for level 1, the Department pays more than 2 times the approved rate. In total, we found that due to the provider billing for a service level that was higher than the service level authorized, the Department paid higher rates for 2,768 claims in Fiscal Year 2017 compared to the rates in prior authorizations, resulting in the $344,302 in overpayments. INCREASED RISK OF FRAUD. When the Department overpays providers, the risk of fraud and abuse increases because providers are incentivized to bill for services that are not authorized or bill for a service with a higher payment rate than the service actually provided. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBER CES: CO.4180.R04.02* DD: CO.0007.R07.02* SLS: CO.0293.R04.02* FEDERAL AWARD YEARS 2016 AND 2017 PASS THROUGH ENTITY NONE CFDA NO. 93.778, MEDICAL ASSISTANCE PROGRAM COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $344,302 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2018-054 The Department of Health Care Policy and Financing should review the payments made for the 6,130 service claims without matching prior authorization identified in the audit to determine whether the payments were allowable and recover unallowable payments and over-payments, as appropriate. Until the Department implements RECOMMENDATION 2018-053, it should also review claims that were paid after the audit review period to determine whether any lacked prior authorization and recover unallowable payments and over-payments, as appropriate. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING AGREE. IMPLEMENTATION DATE: SEPTEMBER 2019. The Department will review the payments made for the service claims that were identified in the audit to determine whether the payments were allowable. Until the Department implements a system change to modify the Colorado interChange edits to ensure that claims for services provided through Medicaid Home and Community-Based Services Waivers are paid only when the provider?s coding on a claim exactly matches a prior authorization for the program recipient, the Department will review claims and recover unallowable payments and over-payments, as appropriate.
The Department reviewed the 6,130 claims identified by the OSA for SFY 2017. Demand letters were sent out to providers who had identified overpayments in May and June of 2019. Several providers filed Informal Reconsiderations and Appeals with the Office of the Administrative Courts. The last Appeal was resolved in February of 2020. The Department is currently in the process of recovering funds related to Demand letters where no response was received. For the period after the audit and prior to when the system edit was implemented, the Department is in the process of determining how the review will be conducted and plans to review and recover any identified overpayments (Donna Kellow, Greg Tanner, September 2019).
2018-054
COLORADO CHILD CARE ASSISTANCE PROGRAM? ELIGIBILITY The federal Child Care and Development Fund Cluster [CFDA No. 93.575, Child Care and Development Block Grant; and CFDA No. 93.596, Child Care Mandatory and Matching Trust Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents are working or attending training or educational programs. The federal Child Care and Development Fund Cluster was enacted under Title IV-A of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP or Program). During Fiscal Year 2019, CCCAP expenditures totaled approximately $115 million in federal and state funds. The Department?s Division of Early Care and Learning is responsible for overseeing CCCAP and ensuring that the Department complies with federal and state requirements for this Program. CCCAP is administered at the local level by the county departments of human/social services and the Department is responsible for monitoring the counties? administration of the Program. County caseworkers enter CCCAP applicant information, including household employment and income, household composition, and the names and number of children needing care into the Department?s Child Care Automated Tracking System (CHATS). CHATS aggregates the information input by the county caseworker to determine whether an applicant will be eligible for CCCAP assistance. For example, the adult caretaker?s household income must not exceed 85 percent of the State?s median household income. CHATS uses the household income entered by the county caseworker to calculate the copayment amount or ?parent fee? the household must pay per month for child care services. CHATS then automatically generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the applicant. Any changes are required to be reported back to the county so that the county can update CHATS to reflect any revised information and redetermine eligibility. In September 2018 (during Fiscal Year 2019), the Department converted from the CHATS Legacy system to an upgraded CHATS Modernization system. The Department?s Division of Quality Assurance and Quality Improvement (Division) is responsible for the CCCAP quality assurance review process, which is designed to determine whether county caseworkers have determined eligibility appropriately, including whether they have followed the Colorado Code of Regulations (CCR). Specifically, the Division reviews a sample of case files from the counties to determine whether caseworkers maintained relevant and appropriate case file documentation and properly entered required information, such as household income, into CHATS. The Division then provides identified exceptions to the reviewed counties and requires them to provide a corrective action plan to address the issues. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over CCCAP eligibility and enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2019. Our testing specifically included reviewing the accuracy of county departments of human/social services? eligibility determinations, including the accuracy of data in CHATS; reviewing and assessing the Department?s internal controls over compliance with federal and state program eligibility requirements, including any policy and procedure manuals in place during Fiscal Year 2019; and the Department?s monitoring processes over the counties? departments of human/social services? administration of CCCAP. We reviewed a sample of 30 open CCCAP case files for child care assistance during Fiscal Year 2019. We reviewed the data entered into CHATS for the cases, as well as the supporting documentation within the case files, to determine whether participant data was properly entered into CHATS, the sampled participants were accurately deemed eligible for benefits, and notices/actions related to the participants? cases were provided in a timely manner. We have identified eligibility errors for the CCCAP program through our financial and compliance audits at the Department since Fiscal Year 2013. As part of our Fiscal Year 2019 audit, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendations related to CCCAP. During that audit, we recommended that the Department strengthen its internal controls over CCCAP by ensuring that county caseworkers are appropriately trained on CCCAP areas and representatives from all counties attend training. In addition, we recommended improving the Program?s county review process to ensure that caseworkers follow CCCAP?s policies and procedures regarding case file documentation, timely processing of applications and redeterminations, case closures, and income calculations; and resolving CHATS issues that we identified through our audit related to the parent fee calculation. The Department agreed with our prior recommendations and stated that it would implement them by July 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: *TIMELY PROCESSING OF ELIGIBILITY. State regulation [Section 3.911.R, 9 CCR 2503-9] requires that county caseworkers review any original or redetermination eligibility application for completeness, approve or deny the application, and provide written notice to the applicant of approval or of missing supporting documentation no more than 15 calendar days from the date the application was received by the county. If supporting documents are not received within this 15-day period, the application for original or redetermined eligibility will be denied. If supporting documentation is received within 60 calendar days of the application date, and the eligibility criteria is met, counties will determine eligibility from the date the current supporting documents were received. If sufficient supporting documentation has not been completely submitted within 60 calendar days of the application date, the county shall require a new application. State regulation [Section 3.903, 9 CCR 2503-9] also requires that caseworkers redetermine and update an applicant?s original eligibility for CCCAP based on current information, including appropriate supporting documentation, every 12 months. State regulation [Section 3.905.5.A.4, 9 CCR 2503-9] requires that county caseworkers terminate a case that exceeds activity time limits, such as the amount of time the applicant may receive benefits while searching for employment. State regulation [Section 3.903, 9 CCR 2503-9] also allows applicants to receive child care benefits for 13 weeks, within a 12 month period, while searching for employment. Any adverse action by caseworkers is preceded by a notice period of 15 calendar days. This 15-day notice period constitutes a period during which assistance is continued and no adverse action takes place. * APPLICANT INCOME AND PARENT FEES. State regulation [Section 3.905.1.I, 9 CCR 2503-9] specifies that gross earnings, including wages and child support payments, must be included in an applicant?s income for the purposes of determining CCCAP eligibility and calculating parent fees. State regulation [Section 3.903, 9 CCR 2503-9] defines a parent fee as a copayment that must be made by a parent to the child care provider prior to any state/county child care funds payment. Effective September 30, 2018, state regulation [Section 3.910.A, 9 CCR 2503-9] requires that the parent fee be calculated as a rounded whole dollar amount. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department had not fully implemented our Fiscal Year 2018 recommendation by the end of Fiscal Year 2019 and did not comply with federal and state CCCAP requirements during Fiscal Year 2019. Specifically, in 11 of the 30 case files tested (37 percent), we identified at least one error. These errors resulted in a total of $188 in known questioned costs; $74 of these costs were paid with federal grant funds. The errors we identified are outlined below. TIMELY NOTIFICATION OF ELIGIBILITY AND TIMELY CASE CLOSURE. In four cases, the caseworker either did not notify the applicant of his or her eligibility determination within the 15-day requirement or did not close the applicant?s case and end the applicant?s child care eligibility in a timely manner, as required. For example, in two of the four cases, the applicants had not been notified of their eligibility determinations as of the time of our audit?over 100 days after they applied for benefits. In one of these four cases, the caseworker did not close the case after the applicant?s 13-week job search period until 5 calendar days after the allowed 15-day notice period. Because the Department did not make payments for any of these four cases during Fiscal Year 2019, we did not identify questioned costs resulting from the errors. CASEWORKER AND CHATS ERRORS RELATED TO PARENT FEE AND APPLICANT INCOME. In 10 instances, the parent fee and/or applicant income were not calculated correctly. For example, in two instances, the caseworker failed to include the appropriate amount of applicant-provided income when determining the applicant?s eligibility for the program; this resulted in the applicants being charged a lower parent fee than appropriate. In two other instances, CHATS did not round the parent fee to the nearest whole dollar amount, as required by Department policy. These errors resulted in known questioned costs of $188. WHY DID THESE PROBLEMS OCCUR? The Department?s current training and monitoring processes had not been effective in ensuring that county caseworkers complied with all Program requirements. For example, we found that the Department only held one required online training for county caseworkers during Fiscal Year 2019; furthermore, five of the 64 counties completed the training late, between 64 and 70 days after the training was held. We also noted that the trainings given in Fiscal Year 2019 were not revised based on the results of the Department?s quality assurance reviews. We noted that the Department did not require counties to have a secondary review process over child care case files; rather, the need for these reviews was determined and applied at each county?s discretion. The Department explained that counties should have had their own internal controls in place, but the Department did not track or monitor these controls or reviews. We noted that many of the errors identified by our audit could have been identified and corrected through a secondary review process at the county level. The Department conducted a quality assurance review of 276 CCCAP case files from 26 out of 64 counties during Fiscal Year 2019 and found that 113 of these cases (41 percent) contained at least one identified issue. The results of our testing, as well as the high error rate identified through the Department?s quality assurance review, indicated that the Department?s processes and trainings had not effectively ensured that caseworkers were complying with CCCAP policies. The Department also experienced issues with CHATS. Regarding the applicants who were not notified of their eligibility determinations, the Department indicated that conversion-related errors that occurred after the CHATS Modernization upgrade resulted in CHATS failing to generate a letter notifying applicants of their eligibility. Regarding the CHATS system parent fee rounding error, the Department indicated that they were aware that the issue existed in CHATS but that it was fixed in the CHATS Modernization upgrade during Fiscal Year 2019. Department staff believe that fixes made to the system as part of the upgrade will prevent additional parent fee rounding errors. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, and/or assessing an incorrect parent fee. In addition, the federal government can disallow the payment of federal matching funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Furthermore, improving the Program?s review process and providing more frequent and effective training on eligibility determination based on the results of the quality assurance reviews, and requiring all counties to attend at the time of training or shortly thereafter, will aid in reducing errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS G1701COCCDF* G1801COCCDF* G1901COCCDF* FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.575, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUND COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $188 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-063A, 2018-063B, AND 2018-063C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-058 The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Colorado Child Care Assistance Program (CCCAP) requirements by: A Providing periodic training to county caseworkers to ensure caseworkers are appropriately trained on CCCAP areas including income calculations and timely processing and notifications, and enforcing the Department?s requirement that representatives from all counties attend the trainings in a timely manner. Training should be targeted to address problem areas identified through the Department?s quality assurance review process. B Working with counties to incorporate a secondary or supervisory review process over case files after eligibility is determined to ensure timely applicant notification of eligibility decisions, timely closure of cases, and that parent fees are calculated appropriately. C Monitoring the upgraded Child Care Automated Tracking System to ensure that all identified system upgrade issues are addressed. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will identify and continue developing training in key areas of CCCAP program policy such as income calculation, timely processing, timely noticing and other policy areas identified through quality assurance reviews. These trainings will be delivered via face to face training; virtual training or web based training modules. When training has been identified as required, at least one representative from each county will be required to attend. To ensure representatives from all counties obtain proper training, county representation will be tracked and the Department will follow up with county representatives to ensure training is completed within a timely manner. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will work with county departments of human/social services to determine the feasibility of incorporating a secondary or supervisory review of select case files after eligibility has been determined, including ensuring applicants are notified timely of eligibility decisions, parent fees are calculated appropriately and cases are closed timely. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will continue to monitor the Child Care Automated Tracking System (CHATS) through help desk tickets that identify possible system issues. Help desk tickets are submitted by state and county workers when it is suspected that the system is not functioning as it should. It is through this process we are able to identify, prioritize and correct system issues.
Show full finding ▾Hide full finding ▴COLORADO CHILD CARE ASSISTANCE PROGRAM? ELIGIBILITY The federal Child Care and Development Fund Cluster [CFDA No. 93.575, Child Care and Development Block Grant; and CFDA No. 93.596, Child Care Mandatory and Matching Trust Funds of the Child Care and Development Fund] provides financial assistance to states to increase the availability, affordability, and quality of child care services for low-income families in which the parents are working or attending training or educational programs. The federal Child Care and Development Fund Cluster was enacted under Title IV-A of the Social Security Act and is administered at the federal level by the U.S. Department of Health and Human Services. In Colorado, this program is referred to as the Colorado Child Care Assistance Program (CCCAP or Program). During Fiscal Year 2019, CCCAP expenditures totaled approximately $115 million in federal and state funds. The Department?s Division of Early Care and Learning is responsible for overseeing CCCAP and ensuring that the Department complies with federal and state requirements for this Program. CCCAP is administered at the local level by the county departments of human/social services and the Department is responsible for monitoring the counties? administration of the Program. County caseworkers enter CCCAP applicant information, including household employment and income, household composition, and the names and number of children needing care into the Department?s Child Care Automated Tracking System (CHATS). CHATS aggregates the information input by the county caseworker to determine whether an applicant will be eligible for CCCAP assistance. For example, the adult caretaker?s household income must not exceed 85 percent of the State?s median household income. CHATS uses the household income entered by the county caseworker to calculate the copayment amount or ?parent fee? the household must pay per month for child care services. CHATS then automatically generates a letter that must be sent by the county caseworker to the household that summarizes the information and must be verified by the applicant. Any changes are required to be reported back to the county so that the county can update CHATS to reflect any revised information and redetermine eligibility. In September 2018 (during Fiscal Year 2019), the Department converted from the CHATS Legacy system to an upgraded CHATS Modernization system. The Department?s Division of Quality Assurance and Quality Improvement (Division) is responsible for the CCCAP quality assurance review process, which is designed to determine whether county caseworkers have determined eligibility appropriately, including whether they have followed the Colorado Code of Regulations (CCR). Specifically, the Division reviews a sample of case files from the counties to determine whether caseworkers maintained relevant and appropriate case file documentation and properly entered required information, such as household income, into CHATS. The Division then provides identified exceptions to the reviewed counties and requires them to provide a corrective action plan to address the issues. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over CCCAP eligibility and enrollment processing and to determine whether the Department complied with federal and state CCCAP requirements during Fiscal Year 2019. Our testing specifically included reviewing the accuracy of county departments of human/social services? eligibility determinations, including the accuracy of data in CHATS; reviewing and assessing the Department?s internal controls over compliance with federal and state program eligibility requirements, including any policy and procedure manuals in place during Fiscal Year 2019; and the Department?s monitoring processes over the counties? departments of human/social services? administration of CCCAP. We reviewed a sample of 30 open CCCAP case files for child care assistance during Fiscal Year 2019. We reviewed the data entered into CHATS for the cases, as well as the supporting documentation within the case files, to determine whether participant data was properly entered into CHATS, the sampled participants were accurately deemed eligible for benefits, and notices/actions related to the participants? cases were provided in a timely manner. We have identified eligibility errors for the CCCAP program through our financial and compliance audits at the Department since Fiscal Year 2013. As part of our Fiscal Year 2019 audit, we reviewed the Department?s progress in implementing our Fiscal Year 2018 audit recommendations related to CCCAP. During that audit, we recommended that the Department strengthen its internal controls over CCCAP by ensuring that county caseworkers are appropriately trained on CCCAP areas and representatives from all counties attend training. In addition, we recommended improving the Program?s county review process to ensure that caseworkers follow CCCAP?s policies and procedures regarding case file documentation, timely processing of applications and redeterminations, case closures, and income calculations; and resolving CHATS issues that we identified through our audit related to the parent fee calculation. The Department agreed with our prior recommendations and stated that it would implement them by July 2019. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We applied the following criteria during our testing: *TIMELY PROCESSING OF ELIGIBILITY. State regulation [Section 3.911.R, 9 CCR 2503-9] requires that county caseworkers review any original or redetermination eligibility application for completeness, approve or deny the application, and provide written notice to the applicant of approval or of missing supporting documentation no more than 15 calendar days from the date the application was received by the county. If supporting documents are not received within this 15-day period, the application for original or redetermined eligibility will be denied. If supporting documentation is received within 60 calendar days of the application date, and the eligibility criteria is met, counties will determine eligibility from the date the current supporting documents were received. If sufficient supporting documentation has not been completely submitted within 60 calendar days of the application date, the county shall require a new application. State regulation [Section 3.903, 9 CCR 2503-9] also requires that caseworkers redetermine and update an applicant?s original eligibility for CCCAP based on current information, including appropriate supporting documentation, every 12 months. State regulation [Section 3.905.5.A.4, 9 CCR 2503-9] requires that county caseworkers terminate a case that exceeds activity time limits, such as the amount of time the applicant may receive benefits while searching for employment. State regulation [Section 3.903, 9 CCR 2503-9] also allows applicants to receive child care benefits for 13 weeks, within a 12 month period, while searching for employment. Any adverse action by caseworkers is preceded by a notice period of 15 calendar days. This 15-day notice period constitutes a period during which assistance is continued and no adverse action takes place. * APPLICANT INCOME AND PARENT FEES. State regulation [Section 3.905.1.I, 9 CCR 2503-9] specifies that gross earnings, including wages and child support payments, must be included in an applicant?s income for the purposes of determining CCCAP eligibility and calculating parent fees. State regulation [Section 3.903, 9 CCR 2503-9] defines a parent fee as a copayment that must be made by a parent to the child care provider prior to any state/county child care funds payment. Effective September 30, 2018, state regulation [Section 3.910.A, 9 CCR 2503-9] requires that the parent fee be calculated as a rounded whole dollar amount. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that the Department had not fully implemented our Fiscal Year 2018 recommendation by the end of Fiscal Year 2019 and did not comply with federal and state CCCAP requirements during Fiscal Year 2019. Specifically, in 11 of the 30 case files tested (37 percent), we identified at least one error. These errors resulted in a total of $188 in known questioned costs; $74 of these costs were paid with federal grant funds. The errors we identified are outlined below. TIMELY NOTIFICATION OF ELIGIBILITY AND TIMELY CASE CLOSURE. In four cases, the caseworker either did not notify the applicant of his or her eligibility determination within the 15-day requirement or did not close the applicant?s case and end the applicant?s child care eligibility in a timely manner, as required. For example, in two of the four cases, the applicants had not been notified of their eligibility determinations as of the time of our audit?over 100 days after they applied for benefits. In one of these four cases, the caseworker did not close the case after the applicant?s 13-week job search period until 5 calendar days after the allowed 15-day notice period. Because the Department did not make payments for any of these four cases during Fiscal Year 2019, we did not identify questioned costs resulting from the errors. CASEWORKER AND CHATS ERRORS RELATED TO PARENT FEE AND APPLICANT INCOME. In 10 instances, the parent fee and/or applicant income were not calculated correctly. For example, in two instances, the caseworker failed to include the appropriate amount of applicant-provided income when determining the applicant?s eligibility for the program; this resulted in the applicants being charged a lower parent fee than appropriate. In two other instances, CHATS did not round the parent fee to the nearest whole dollar amount, as required by Department policy. These errors resulted in known questioned costs of $188. WHY DID THESE PROBLEMS OCCUR? The Department?s current training and monitoring processes had not been effective in ensuring that county caseworkers complied with all Program requirements. For example, we found that the Department only held one required online training for county caseworkers during Fiscal Year 2019; furthermore, five of the 64 counties completed the training late, between 64 and 70 days after the training was held. We also noted that the trainings given in Fiscal Year 2019 were not revised based on the results of the Department?s quality assurance reviews. We noted that the Department did not require counties to have a secondary review process over child care case files; rather, the need for these reviews was determined and applied at each county?s discretion. The Department explained that counties should have had their own internal controls in place, but the Department did not track or monitor these controls or reviews. We noted that many of the errors identified by our audit could have been identified and corrected through a secondary review process at the county level. The Department conducted a quality assurance review of 276 CCCAP case files from 26 out of 64 counties during Fiscal Year 2019 and found that 113 of these cases (41 percent) contained at least one identified issue. The results of our testing, as well as the high error rate identified through the Department?s quality assurance review, indicated that the Department?s processes and trainings had not effectively ensured that caseworkers were complying with CCCAP policies. The Department also experienced issues with CHATS. Regarding the applicants who were not notified of their eligibility determinations, the Department indicated that conversion-related errors that occurred after the CHATS Modernization upgrade resulted in CHATS failing to generate a letter notifying applicants of their eligibility. Regarding the CHATS system parent fee rounding error, the Department indicated that they were aware that the issue existed in CHATS but that it was fixed in the CHATS Modernization upgrade during Fiscal Year 2019. Department staff believe that fixes made to the system as part of the upgrade will prevent additional parent fee rounding errors. WHY DO THESE PROBLEMS MATTER? Inaccurate processing of case file information to determine eligibility can result in counties improperly granting CCCAP benefits to ineligible individuals, denying benefits to eligible individuals who rely on those benefits in order to work and provide for their families, and/or assessing an incorrect parent fee. In addition, the federal government can disallow the payment of federal matching funds for program expenditures that do not adhere to regulations, which would require the State to use General Funds to cover the expenditures. Furthermore, improving the Program?s review process and providing more frequent and effective training on eligibility determination based on the results of the quality assurance reviews, and requiring all counties to attend at the time of training or shortly thereafter, will aid in reducing errors. FEDERAL AGENCY DEPARTMENT OF HEALTH AND HUMAN SERVICES FEDERAL AWARD NUMBERS G1701COCCDF* G1801COCCDF* G1901COCCDF* FEDERAL AWARD YEARS 2017, 2018, AND 2019 PASS THROUGH ENTITY NONE CFDA NOS. 93.575, CHILD CARE AND DEVELOPMENT BLOCK GRANT; 93.596, CHILD CARE MANDATORY AND MATCHING FUNDS OF THE CHILD CARE AND DEVELOPMENT FUND COMPLIANCE REQUIREMENT ACTIVITIES ALLOWED OR UNALLOWED (A) ALLOWABLE COSTS/COST PRINCIPLES (B) ELIGIBILITY (E) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING SIGNIFICANT DEFICIENCY TOTAL KNOWN QUESTIONED COSTS $188 THIS FINDING APPLIES TO PRIOR AUDIT RECOMMENDATIONS 2018-063A, 2018-063B, AND 2018-063C * ITEMS ASSOCIATED WITH KNOWN QUESTIONED COSTS RECOMMENDATION 2019-058 The Department of Human Services (Department) should strengthen its internal controls over, and ensure compliance with, the Colorado Child Care Assistance Program (CCCAP) requirements by: A Providing periodic training to county caseworkers to ensure caseworkers are appropriately trained on CCCAP areas including income calculations and timely processing and notifications, and enforcing the Department?s requirement that representatives from all counties attend the trainings in a timely manner. Training should be targeted to address problem areas identified through the Department?s quality assurance review process. B Working with counties to incorporate a secondary or supervisory review process over case files after eligibility is determined to ensure timely applicant notification of eligibility decisions, timely closure of cases, and that parent fees are calculated appropriately. C Monitoring the upgraded Child Care Automated Tracking System to ensure that all identified system upgrade issues are addressed. RESPONSE DEPARTMENT OF HUMAN SERVICES A AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will identify and continue developing training in key areas of CCCAP program policy such as income calculation, timely processing, timely noticing and other policy areas identified through quality assurance reviews. These trainings will be delivered via face to face training; virtual training or web based training modules. When training has been identified as required, at least one representative from each county will be required to attend. To ensure representatives from all counties obtain proper training, county representation will be tracked and the Department will follow up with county representatives to ensure training is completed within a timely manner. B AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will work with county departments of human/social services to determine the feasibility of incorporating a secondary or supervisory review of select case files after eligibility has been determined, including ensuring applicants are notified timely of eligibility decisions, parent fees are calculated appropriately and cases are closed timely. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department will continue to monitor the Child Care Automated Tracking System (CHATS) through help desk tickets that identify possible system issues. Help desk tickets are submitted by state and county workers when it is suspected that the system is not functioning as it should. It is through this process we are able to identify, prioritize and correct system issues.
(A) The Department will identify and continue developing training in key areas of CCCAP program policy such as income calculation, timely processing, timely noticing and other policy areas identified through quality assurance reviews. These trainings will be delivered via face to face training; virtual training or web based training modules. When training has been identified as required, at least one representative from each county will be required to attend. To ensure representatives from all counties obtain proper training, county representation will be tracked and the Department will follow up with county representatives to ensure training is completed within a timely manner (Tamara Schmidt, July 2020). (B) The Department will work with county departments of human/social services to determine the feasibility of incorporating a secondary or supervisory review of select case files after eligibility has been determined, including ensuring applicants are notified timely of eligibility decisions, parent fees are calculated appropriately and cases are closed timely (Tamara Schmidt, July 2020). (C) The Department will continue to monitor the Child Care Automated Tracking System (CHATS) through help desk tickets that identify possible system issues. Help desk tickets are submitted by state and county workers when it is suspected that the system is not functioning as it should. It is through this process we are able to identify, prioritize and correct system issues (Tamara Schmidt, July 2020).
2018-063
The following recommendations relating to internal control deficiencies classified as MATERIAL WEAKNESSES were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendations can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. MINERALS LEASING ACT? SUBRECIPIENT MONITORING AND REPORTING In 1920, the United States Congress passed the Minerals Leasing Act. This act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Program revenue is revenue that companies pay to the federal government for leasing federal land and for the right to extract minerals from that land. According to the act, revenue is to be used by states as the individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the development of minerals leased for planning, construction and maintenance of public facilities, and provision of public service. For Colorado, ONRR distributes Program funds [CFDA NO. 15.437] to Treasury, which subgrants, or passes through, Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE) as prescribed by Section 34-63-102, C.R.S. DOLA then passes Program funds through to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the grant, and may use the Program monies for planning, construction, and maintenance of public facilities and for public services. During Fiscal Year 2018, ONRR distributed $102.9 million in Program revenue to Treasury. Treasury passed $85.9 million of the Program funds to DOLA, DNR, DHE, and DOE; and $17.0 million of the Program funds to local government subrecipients. DOLA then passed $33.1 million of Program funds through to local government subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the federal Minerals Leasing Act. We also sought to determine whether Treasury?s Exhibit K1, Schedule of Federal Assistance (Exhibit K1), submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2018, was accurate. As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2018, and reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with OSC instructions. Additionally, we tested a sample of five local governments to determine whether each of the local government subrecipients properly reported Program monies received from DOLA on its Schedule of Expenditures of Federal Awards (SEFA), and if each local government received a Single Audit as required by federal regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation and the terms and conditions of the federal award.? Federal regulations [2 CFR 200.331] further require that the Department, as the primary recipient of the Program monies, ensure that every subaward made by Treasury is clearly identified to the subrecipient as a subaward and include the following: * Catalog of Federal Domestic Assistance (CFDA) number * Name of the program, name of the federal awarding agency, and the name of the department awarding the Program monies * Contact information for the department * Dollar amount made available The State, as well as any local governments receiving federal funds, are required to present their SEFA in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.331(f)] further require that Treasury, as the primary recipient, ensure that any non-state subrecipients receiving Program funds from the State during a given fiscal year report the funds on their respective SEFAs and, if the subrecipient expends $750,000 or more in total federal awards during the year, undergo a Single Audit. In order to prepare the state SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. The OSC indicates in its Fiscal Procedures Manual (Manual) and exhibit instructions that federal grants passed through to another state agency by a department must only be reported on the Exhibit K1 of the department that received the award ?from an entity external to the state government of Colorado? in order to ensure that federal awards are not improperly duplicated on the SEFA. Furthermore, federal awards passed through to another state department or institution are to be reported in the Expenditures-Direct and Indirect column of the Exhibit K1 rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be expenditures by subrecipients. Because Treasury maintains the Exhibit K1 reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State (e.g., at the local government level.) WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that Treasury did not comply with federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2018. Specifically, we identified the following: * Treasury did not ensure that Treasury or DOLA staff communicated required subaward information to its Program subrecipients in accordance with federal regulations. Specifically, we determined that DOLA made a total of $33.1 million in Program payments to 341 local governments during Fiscal Year 2018, but did not indicate to the local governments that the payments represented federal grant funds or provide required information including: ? Catalog of Federal Domestic Assistance (CFDA) number ? Name of the program, name of the federal awarding agency, and the name of the department awarding the Program monies ? Contact information for the department ? Dollar amount made available * Treasury did not ensure that it or DOLA had procedures in place to ensure that its Program subrecipients appropriately reported Program money on their SEFAs. Specifically, none of the five local governments we tested (100 percent) reported any Program monies on their most recently issued SEFAs. * Treasury improperly classified approximately $11.5 million in federal funding as monies passed through to local governments for the Program [CFDA NO. 15.437] on the Exhibit K1 that Treasury submitted to the OSC for Fiscal Year 2018. Specifically, Treasury erroneously included the full amount of Program funds it passed through to other state agencies as subrecipient expenditures when it should have only recorded the amount passed through by any of the state agencies to agencies outside of the state. As a result, the State?s direct expenditures for the Program were understated on the SEFA by $11.5 million and the State?s subrecipient expenditures were overstated by $11.5 million. WHY DID THESE PROBLEMS OCCUR? Treasury did not have adequate internal controls in place during Fiscal Year 2018 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, it did not have formal processes in place to ensure that Treasury staff and DOLA staff communicated required information to the local government Program funds recipients; local government subrecipients reported Program grant money on their SEFAs; and that local governments received a Single Audit, if applicable, as required by federal regulations. Additionally, Treasury did not have adequate procedures in place to ensure it followed the Manual and exhibit instructions when the Treasury Exhibit K1 was prepared. WHY DO THESE PROBLEMS MATTER? By failing to ensure that Treasury and DOLA staff communicated the required information to the local governments, and not properly preparing the Exhibit K1, Treasury failed to comply with federal subrecipient and reporting requirements in relation to the Program. Furthermore, we found that one of the five local governments we sampled (20 percent) failed to undergo a Single Audit. The local government received approximately $900,000 in Program monies that exceeded the $750,000 threshold requiring a Single Audit; however, because the local government was unaware that the Program funds received were required to be reported on the SEFA, it did not receive a Single Audit. Overall, Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate federal grant award requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in other local governments not receiving Single Audits, as required. FEDERAL AGENCY DEPARTMENT OF THE INTERIOR FEDERAL AWARD NUMBER N/A FEDERAL AWARD YEARS 2018 PASS THROUGH ENTITY NONE CFDA NO. 15.437, MINERALS LEASING ACT COMPLIANCE REQUIREMENT REPORTING (L) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION RECOMMENDATION 2018-067 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by: A Communicating required federal award information, including the Catalog of Federal Domestic Assistance number, program name and federal awarding agency, department contact information, and dollar amount, as well as reporting and other requirements for the grant, when passing funds through to other state agencies or non-state subrecipients. B Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the subaward, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. RESPONSE DEPARTMENT OF THE TREASURY A AGREE. IMPLEMENTATION DATE: NOVEMBER 2019. Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements. B AGREE. IMPLEMENTATION DATE: NOVEMBER 2019. Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements. The Department of Treasury will follow up with any entities that do not return their letter to ensure that they have the information they need and are aware of their reporting requirements. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation.
Show full finding ▾Hide full finding ▴The following recommendations relating to internal control deficiencies classified as MATERIAL WEAKNESSES were communicated to the Department in the previous year, and have not been remediated as of June 30, 2019, because the original implementation dates provided by the Department are in a subsequent fiscal year. These recommendations can be found in the original report and SECTION IV: PRIOR RECOMMENDATIONS of this report. See Schedule of Findings and Questioned Costs for chart/table. See Schedule of Findings and Questioned Costs for footnote. MINERALS LEASING ACT? SUBRECIPIENT MONITORING AND REPORTING In 1920, the United States Congress passed the Minerals Leasing Act. This act directs the federal Office of Natural Resources Revenue (ONRR) within the U.S. Department of the Interior to share 50 percent of mineral leasing revenue received by the ONRR with states that generate mineral lease revenue. Program revenue is revenue that companies pay to the federal government for leasing federal land and for the right to extract minerals from that land. According to the act, revenue is to be used by states as the individual state?s legislature directs, giving priority to those sections of the state that are socially or economically impacted by the development of minerals leased for planning, construction and maintenance of public facilities, and provision of public service. For Colorado, ONRR distributes Program funds [CFDA NO. 15.437] to Treasury, which subgrants, or passes through, Program funds to the Department of Local Affairs (DOLA), the Department of Natural Resources (DNR), the Department of Higher Education (DHE), and the Department of Education (DOE) as prescribed by Section 34-63-102, C.R.S. DOLA then passes Program funds through to local governments impacted by mineral leasing, such as cities and counties. These local governments are considered subrecipients of the grant, and may use the Program monies for planning, construction, and maintenance of public facilities and for public services. During Fiscal Year 2018, ONRR distributed $102.9 million in Program revenue to Treasury. Treasury passed $85.9 million of the Program funds to DOLA, DNR, DHE, and DOE; and $17.0 million of the Program funds to local government subrecipients. DOLA then passed $33.1 million of Program funds through to local government subrecipients. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to determine whether Treasury had adequate internal controls in place over, and complied with, federal subrecipient monitoring and reporting requirements for the federal Minerals Leasing Act. We also sought to determine whether Treasury?s Exhibit K1, Schedule of Federal Assistance (Exhibit K1), submitted to the Department of Personnel & Administration?s Office of the State Controller (OSC) for Fiscal Year 2018, was accurate. As part of our testing, we conducted interviews with Treasury staff regarding its policies and procedures over the monitoring of Program funds during Fiscal Year 2018, and reviewed Treasury?s Exhibit K1 to verify the accuracy of the information reported to the OSC and to assess Treasury?s compliance with OSC instructions. Additionally, we tested a sample of five local governments to determine whether each of the local government subrecipients properly reported Program monies received from DOLA on its Schedule of Expenditures of Federal Awards (SEFA), and if each local government received a Single Audit as required by federal regulations. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? We measured the results of our audit work against the following requirements: Federal regulations [2 CFR 200.303] require that the Department, as a federal grant recipient, must ?establish and maintain effective internal controls over federal awards that provide reasonable assurance that awards are being managed in compliance with federal statutes, regulation and the terms and conditions of the federal award.? Federal regulations [2 CFR 200.331] further require that the Department, as the primary recipient of the Program monies, ensure that every subaward made by Treasury is clearly identified to the subrecipient as a subaward and include the following: * Catalog of Federal Domestic Assistance (CFDA) number * Name of the program, name of the federal awarding agency, and the name of the department awarding the Program monies * Contact information for the department * Dollar amount made available The State, as well as any local governments receiving federal funds, are required to present their SEFA in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Federal regulations [2 CFR 200.510(b)] specifically require that the SEFA include information on each federal award expended during the year, including the total amount provided to subrecipients from each federal award. Any non-federal entity that expends $750,000 or more in total federal awards during the entity?s fiscal year must undergo a Single Audit or program-specific audit for that year. Federal regulations [2 CFR 200.331(f)] further require that Treasury, as the primary recipient, ensure that any non-state subrecipients receiving Program funds from the State during a given fiscal year report the funds on their respective SEFAs and, if the subrecipient expends $750,000 or more in total federal awards during the year, undergo a Single Audit. In order to prepare the state SEFA, the OSC requires state departments to submit an Exhibit K1 each year to report expenditures, receipts, and receivables for each federal grant program administered by the department during the fiscal year. The OSC indicates in its Fiscal Procedures Manual (Manual) and exhibit instructions that federal grants passed through to another state agency by a department must only be reported on the Exhibit K1 of the department that received the award ?from an entity external to the state government of Colorado? in order to ensure that federal awards are not improperly duplicated on the SEFA. Furthermore, federal awards passed through to another state department or institution are to be reported in the Expenditures-Direct and Indirect column of the Exhibit K1 rather than the Expenditures-Passed Through to Subrecipient column because the federal government does not consider expenditures at the same level of government (e.g., State) to be expenditures by subrecipients. Because Treasury maintains the Exhibit K1 reporting responsibility for the Program, it is responsible for reporting the appropriate split between funds expended at the state level by any department and funds passed through to subrecipients outside of the State (e.g., at the local government level.) WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We found that Treasury did not comply with federal subrecipient monitoring and reporting requirements for the Program during Fiscal Year 2018. Specifically, we identified the following: * Treasury did not ensure that Treasury or DOLA staff communicated required subaward information to its Program subrecipients in accordance with federal regulations. Specifically, we determined that DOLA made a total of $33.1 million in Program payments to 341 local governments during Fiscal Year 2018, but did not indicate to the local governments that the payments represented federal grant funds or provide required information including: ? Catalog of Federal Domestic Assistance (CFDA) number ? Name of the program, name of the federal awarding agency, and the name of the department awarding the Program monies ? Contact information for the department ? Dollar amount made available * Treasury did not ensure that it or DOLA had procedures in place to ensure that its Program subrecipients appropriately reported Program money on their SEFAs. Specifically, none of the five local governments we tested (100 percent) reported any Program monies on their most recently issued SEFAs. * Treasury improperly classified approximately $11.5 million in federal funding as monies passed through to local governments for the Program [CFDA NO. 15.437] on the Exhibit K1 that Treasury submitted to the OSC for Fiscal Year 2018. Specifically, Treasury erroneously included the full amount of Program funds it passed through to other state agencies as subrecipient expenditures when it should have only recorded the amount passed through by any of the state agencies to agencies outside of the state. As a result, the State?s direct expenditures for the Program were understated on the SEFA by $11.5 million and the State?s subrecipient expenditures were overstated by $11.5 million. WHY DID THESE PROBLEMS OCCUR? Treasury did not have adequate internal controls in place during Fiscal Year 2018 to ensure that it complied with federal subrecipient monitoring and reporting requirements. Specifically, it did not have formal processes in place to ensure that Treasury staff and DOLA staff communicated required information to the local government Program funds recipients; local government subrecipients reported Program grant money on their SEFAs; and that local governments received a Single Audit, if applicable, as required by federal regulations. Additionally, Treasury did not have adequate procedures in place to ensure it followed the Manual and exhibit instructions when the Treasury Exhibit K1 was prepared. WHY DO THESE PROBLEMS MATTER? By failing to ensure that Treasury and DOLA staff communicated the required information to the local governments, and not properly preparing the Exhibit K1, Treasury failed to comply with federal subrecipient and reporting requirements in relation to the Program. Furthermore, we found that one of the five local governments we sampled (20 percent) failed to undergo a Single Audit. The local government received approximately $900,000 in Program monies that exceeded the $750,000 threshold requiring a Single Audit; however, because the local government was unaware that the Program funds received were required to be reported on the SEFA, it did not receive a Single Audit. Overall, Treasury?s insufficient monitoring of Program subrecipients could result in future federal funding being reduced. In addition, if Treasury does not appropriately communicate federal grant award requirements to other state agencies and non-state subrecipients in the future, it could ultimately result in other local governments not receiving Single Audits, as required. FEDERAL AGENCY DEPARTMENT OF THE INTERIOR FEDERAL AWARD NUMBER N/A FEDERAL AWARD YEARS 2018 PASS THROUGH ENTITY NONE CFDA NO. 15.437, MINERALS LEASING ACT COMPLIANCE REQUIREMENT REPORTING (L) SUBRECIPIENT MONITORING (M) CLASSIFICATION OF FINDING MATERIAL WEAKNESS TOTAL KNOWN QUESTIONED COSTS $0 THIS FINDING DOES NOT APPLY TO A PRIOR YEAR RECOMMENDATION RECOMMENDATION 2018-067 The Department of the Treasury (Treasury) should strengthen its internal controls to ensure that it complies with federal requirements for subrecipient monitoring and reporting for the Minerals Leasing Act program (Program) by: A Communicating required federal award information, including the Catalog of Federal Domestic Assistance number, program name and federal awarding agency, department contact information, and dollar amount, as well as reporting and other requirements for the grant, when passing funds through to other state agencies or non-state subrecipients. B Developing a monitoring process to ensure that any state agencies to which Treasury passes Program funds, including the Department of Local Affairs, communicate the required federal award information to their subrecipients. This monitoring process should be detailed enough to provide reasonable assurance that subrecipients understand the terms and conditions of the subaward, that they appropriately report the Program grant receipts and expenditures on their Schedule of Expenditures of Federal Awards, and that they follow any other federal auditing requirements related to the grant awards. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation. RESPONSE DEPARTMENT OF THE TREASURY A AGREE. IMPLEMENTATION DATE: NOVEMBER 2019. Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements. B AGREE. IMPLEMENTATION DATE: NOVEMBER 2019. Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements. The Department of Treasury will follow up with any entities that do not return their letter to ensure that they have the information they need and are aware of their reporting requirements. C This part of the recommendation has been implemented, partially implemented, not implemented, or is no longer applicable. See FY19 SECTION IV: PRIOR RECOMMENDATIONS for information regarding this part of the recommendation.
(A) Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements (Charles Scheibe, November 2019). (B) Following distribution of funds to subrecipients in September, the Department of Treasury will communicate required federal award information, CFDA number, program name and federal awarding agency, department contact information, and dollar amount when passing funds through to other state agencies or non-state subrecipients in the form of a confirmation letter to be signed and returned to the Department of Treasury by the subrecipients to ensure reasonable assurance of compliance with monitoring and reporting requirements. The Department of Treasury will follow up with any entities that do not return their letter to ensure that they have the information they need and are aware of their reporting requirements (Charles Scheibe, November 2019). (C) The Department of Treasury will ensure that the Department of Local Affairs and other state agencies have the necessary information to appropriately report funds distributed to non-state subrecipients. The Department of Treasury Controller will record the distributions on the SEFA (Exhibit K1) and the Department of Treasury CFO will review and confirm the accuracy of the numbers reported (Charles Scheibe, Implemented).
2018-067
FAC accepted this audit on March 19, 2019 — management decision was due September 19, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-050, 2017-051
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-054
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-059
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-061
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-053
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-055
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-056
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-058
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-066
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-065
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-067
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-070
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on March 21, 2018 — management decision was due September 21, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-058
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-055
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-051
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-052
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-053
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-065
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-075
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-076
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-074
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴FAC accepted this audit on March 20, 2017 — management decision was due September 20, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-040, 2015-041
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-031
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-033
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-034
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-035
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-036
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-037
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-038
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-039
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-047
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-043
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-044
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-050
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-042
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-054
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-056
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-052
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-053
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-055
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-057
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Colorado →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.