Finance and Audit Committee FY2013 Risk Assessment and Internal Audit and Compliance Plan August 27, 2012.

Slides:



Advertisements
Similar presentations
INTERNAL CONTROLS.
Advertisements

St. Louis Public Schools Human Resources Support for District Improvement Initiatives (Note: The bullets beneath each initiative indicate actions taken.
Office of the General Counsel (OGC) Strategy Map FY 11 August 2011 University Strategic Goals 1. Ensuring student success OGC Strategic Directions OGC.
Lessons Learned from Financial Management Reviews May 15, 2008 Bruce Robinson FTA Office of Research, Demonstration and Innovation.
University Data Classification Table* Level 5Level 4 Information that would cause severe harm to individuals or the University if disclosed. Level 5 information.
Red Flag Rules: What they are? & What you need to do
What is GARP®? GARP® is an Acronym for Generally Accepted Recordkeeping Principles ARMA understands that records must be.
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
Bodnar/Hopwood AIS 7th Ed1 Chapter 5 u TRANSACTION PROCESSING AND INTERNAL CONTROL PROCESS.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
Privacy Laws & Higher Education. Agenda 1.Five Privacy Laws a.FERPA b.HIPAA c.GLB d.FACTA Disposal Rule e.CAN-SPAM 2.Overview of the Laws a.What does.
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
HIPAA: FEDERAL REGULATIONS REGARDING PATIENT SECURITY.
Are you ready for HIPPO??? Welcome to HIPAA
The importance of a Compliance program is to ensure that our agency meets the highest possible standards for all relevant federal, state and local regulations,
Chapter 43 An Act Relative to Improving Accountability and Oversight of Education Collaboratives Presentation to Board of Elementary and Secondary Education.
1 INTERNAL CONTROLS A PRACTICAL GUIDE TO HELP ENSURE FINANCIAL INTEGRITY.
The Islamic University of Gaza
Health Center Revenue and Reimbursement Management
Information Security Policies Larry Conrad September 29, 2009.
Security Controls – What Works
Developing a Records & Information Retention & Disposition Program:
2/16/2010 The Family Educational Records and Privacy Act.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Informed Consent and HIPAA Tim Noe Coordinating Center.
{ Understanding Disability Services By Holly Zuckerman – Access Coordinator Disability Resource Center.
(rev 3/09) Stewardship, Accountability and Regulatory Compliance Jim Corkill Sandra Featherson Office of the Controller.
Minnesota Law and Health Information Exchange Oversight Activities James I. Golden, PhD State Government Health IT Coordinator Director, Health Policy.
Chapter 7 Database Auditing Models
Internal Auditing and Outsourcing
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
Goal Areas for Academic Performance Finances Competitive Environment Equity and Diversity Involvement Facilities Development Marketing Sales.
An Educational Computer Based Training Program CBTCBT.
Business Operations Meeting “Audit Updates” David Cutri, CPA, CISA, CIA (Dave) Director of Internal Audit The University of Toledo The University of Toledo.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
Effective Management and Compliance 1 ANA GRANTEE MEETING  FEBRUARY 5, 2015.
Compliance Issues for Medical Research at Healthcare Systems Jerry Castellano, Pharm.D., CIP Corporate Director Institutional Review Board Christiana Care.
Trusteeship, Governance, and Audit Committee FY2012 Risk Assessment and Audit Plan August 15, 2011.
Finance and Audit Committee FY2014 Risk Assessment and Internal Audit and Compliance Plan August 12, 2013.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Best Practices: Financial Resource Management February 2011.
Our Mission Intercollegiate Athletics at CU Boulder provides student-athletes a rewarding academic and athletic opportunity while embracing the principles.
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 7 Database Auditing Models.
Practice Management Quality Control
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
U.S. DEPARTMENT OF LABOR EMPLOYMENT AND TRAINING ADMINISTRATION ARRA GREEN JOB AND HEALTH CARE / EMERGING INDUSTRIES NEW GRANTEE POST AWARD FORUM JUNE.
Webinar for FY 2011 i3 Grantees February 9, 2012 Fiscal Oversight of i3 Grants Erin McHughJames Evans, CPA, CGFM, CGMA Office of Innovation and Improvement.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
NCAA Working Group on the Collegiate Model – Rules Overview March 2012.
Evaluation of the Strategic Plan How did we grade out?
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Welcome….!!! CORPORATE COMPLIANCE PROGRAM Presented by The Office of Corporate Integrity 1.
Purchasing Forum – May The integration of the activities, plans, attitudes, policies, and efforts of the people of an organization working together.
N A T I O N A L A S S O C I A T I O N O F I N T E R C O L L E G I A T E A T H L E T I C S Amateurism.
The University of Toledo Finance and Audit Committee Meeting “Internal Audit and Compliance Update” September 21, 2015.
The University of Toledo Finance and Audit Committee Meeting “Internal Audit and Compliance Update” August 12, 2013.
BUILDING BLOCKS TO EVALUATE MEASURABLE PROGRAM OUTCOMES AKA: PROGRAM MONITORING.
Copyright © Texas Education Agency Accounting for Grant Funds, including Documentation for Expenditures.
Trade Compliance Considerations April 13, © 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network.
BUILDING BLOCKS TO EVALUATE MEASURABLE PROGRAM OUTCOMES
Lessons Learned from Financial Management Reviews
Managing Chapter Funds
Sponsored Programs at Penn
Internal controls 01-Nov-2017.
Internal Controls Policies and Procedures
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
University of Pittsburgh
Presentation transcript:

Finance and Audit Committee FY2013 Risk Assessment and Internal Audit and Compliance Plan August 27, 2012

2 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY ACADEMIC ENTERPRISE: STUDENT- AND FACULTY-BASED PROCESSES Does the research and innovation division of the University conduct its financial business in a responsible and transparent manner, consistent with appropriate accounting principles? Review financial transactions of the University of Toledo Innovation Enterprises. Ensure that appropriated amounts were used for their intended purposes. Is financial aid awarded only to eligible students consistent with the terms of the various award programs? Review student financial aid procedures and test a sample of loans to ensure that eligibility requirements are met and financial aid is disbursed accurately. Are faculty members utilized to their fullest potential, consistent with University policy and expectations? Are academic programs meeting the financial and societal goals established for them? Advise in the development of a methodology for confirming the achievement of faculty workload goals. Support the University-wide initiative for evaluating the viability of academic programs.

3 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY ACADEMIC ENTRPRISE: INFORMATION TECHNOLOGY Is access to Electronic Protected Health Information restricted only to employees and clinical business partners on a need to know basis ? Evaluate procedures and controls over information security administered by the Information Technology Department. Evaluate the effectiveness of provisioning and de-provisioning access privileges to the various clinical systems. Are The Universitys operating practices well- aligned regarding recent changes to information security and privacy regulations? Collaborate with the IT Department to identify areas of required federal or state compliance across functional and administrative boundaries, such as: HIPAA Privacy and Security Rules FERPA Identity Theft Red Flags Records Retention Use of Electronic Signatures and Records Gramm–Leach–Bliley Act Authenticating Health Care Records Does the University comply with Payment Card Industry standards for network security when processing University credit card transactions at all locations? Self-Assess security and application controls over the computer networks that process student and patient credit card transactions. Independently evaluate compliance with these controls. Have the system implications of the recent changes to the academic advising process been fully tested prior to implementation? Participate in the student advising new systems development project as a controls consultant and review the nature and extent of user testing and acceptance.

4 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY ACADEMIC ENTERPRISE: INTERCOLLEGIATE ATHLETICS Are revenues and expenses pertaining to intercollegiate athletics accounted for properly according to National Collegiate athletics Association (NCAA) rules and University policy? Evaluate the quality of financial controls over athletic student aid; guarantees; support staff/administrative salaries, benefits and bonuses paid by the University and related entities; and recruiting. Do student-athletes meet all applicable academic eligibility requirements, and if the student does not, are they prohibited from representing The University in intercollegiate athletics competition? Determine the level of compliance with NCAA regulations pertaining to academic and general requirements. These include general eligibility requirements, seasons of competition, freshmen academic requirements, progress-toward-degree requirements, transfer regulations, high school all-star games, and outside competition. Does The University limit its organized practice activities, the length of its playing seasons and number of its regular-season contests and/or dates of competition in all sports, as well as the extent of its participation in non-collegiate sponsored athletics activities, to minimize interference with the academic programs of its student-athletes. Determine the level of compliance with NCAA regulations pertaining to playing and practice sessions. These include general playing-season regulations, foreign tours, and playing rules. Are football attendance statistics accurately recorded and reported in a timely manner to the NCAA? Review and certify attendance counts for all University home football games per NCAA regulations.

5 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY ACADEMIC ENTERPRISE: CROSS-FUNCTIONAL ACTIVITIES Does The University provide reasonable accommodations to students, patients, and staff that have a form of disability. Establish a comprehensive Americans with Disabilities Act compliance program, which includes a comprehensive series of audits in the following areas … Employment Public Accommodations (and commercial facilities) Public Entities (and public transportation) Telecommunications Do campus-wide enterprises such as meal plans, parking permits, Rocket ID cards, campus bookstore, Rocket Wireless, vending/copy machines, UT Medical Center gift shop, on-campus banking, and affiliate UTAD creation capture the revenue they receive in a controlled manner? Assess the accuracy and integrity of the components of miscellaneous income as reported in The University of Toledo financial statements. Review compliance with key terms of various services contracts in this area. Are employees paid only for time worked, and are the associated expenses accurately recorded in the general ledger. Comprehensively evaluate procedures and controls pertaining to payroll processing, including reporting and monitoring procedures. Develop a risk and controls assessment for payroll processing.

6 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY CLINICAL ENTERPRISE: UNIVERSITY OF TOLEDO MEDICAL CENTER Are all billable transactions captured at the time of inpatient diagnosis and fully reflected in customer bills? Review the accuracy and reliability of the charge master databases, the charge capture process, and procedures for maximizing inpatient margins. Do construction and supply chain vendors doing business with the University comply with the provisions of their contracts? Review commercial contracts of selected vendors and projects at The University of Toledo Medical Center. Is UTMC taking appropriate steps to ensure compliance with Joint Commission accreditation standards as they pertain to human resource support on an ongoing basis? Review Joint Commission standards pertaining to human resource support, determining whether effective UTMC problem identification/resolution procedures are in place relative to these standards.

7 FY2013 Internal Audit Risk Assessment KEY RISK AREASBUSINESS RISKPLANNED ACTIVITY CLINICAL ENTERPRISE: CLINICAL COMPLIANCE Is UTMC prepared for upcoming changes to coding of medical transactions? Review system and documentation requirements to ensure readiness for future ICD-10 coding classifications. Do the hospital and clinic computer systems under development promote a streamlined and secure process flow between the patient, Information Technology, and operating departments? Participate in the various Meaningful Use new clinical systems development projects as a controls consultant and identify opportunities for system and process integration between diverse stakeholder business functions. Does the compliance plan protect the academic and clinical enterprises from significant violations of the law and internal policies, as well as preserve the confidentiality of patient and student information? Update the Finance and Audit Committee on the nature and resolution of clinical and academic compliance and privacy events processed by the University, including … HIPAA FERPA Stark Law Other aspects of clinical compliance