Illinois Auditor General: 'Illinois Department on Aging – Compliance Examination'
* * *
Here are excerpts:
FINDINGS, CONCLUSIONS, AND RECOMMENDATIONS
INADEQUATE CONTROLS AND MONITORING OVER ENHANCED RATE PAYMENTS MADE TO COMMUNITY CARE PROGRAM SERVICE PROVIDERS
The Department lacked adequate controls and monitoring over eligibility determinations and payments made to service provider agencies that applied for and received a special hourly rate under the Community Care Program.
For the two fiscal years under examination, the Department paid all providers a total of
We recommended the Department strengthen controls to ensure initial and ongoing reviews of eligibility and annual reporting for the enhanced reimbursement rate are conducted and documented in a timely manner, and in accordance with the Code. We also recommended the Department obtain reimbursement from providers if determined to be ineligible.
The Department concurred with the finding and stated it is currently working to hire a manager to develop proper procedures and trainings for staff to create a cohesive area so initial and ongoing reviews of eligibility and annual reporting for the enhanced reimbursement rate are conducted and documented in a timely manner, and in accordance with the Illinois Administrative Code.
* * *
INADEQUATE MONITORING OF GRANTEES AND SERVICE PROVIDERS
The Department did not adequately monitor its grantees and service providers. The auditors noted the following exceptions:
* The Department had not received annual audit reports for 2 of 20 (10%) Fiscal Year 2019 grantees/service providers tested. The 2 grantees/service providers received
* Three of 25 (12%) home care aide providers tested had not submitted an audit to the Department since 2016.
* Of the 22 home care aide providers which did submit an audit, 19 (86%) did not include any evidence of assurance the provider's procedures were in compliance with the Department's financial reporting guidelines requiring an administrative and employee wage and benefits cost split. (Finding 4, pages 18-19) This finding has been repeated since 2016.
We recommended the Department designate sufficient staff to monitor grantees/service provider activities by identifying, following-up on and enforcing submission of delinquent audit reports in order to determine whether the funds were utilized in accordance with the purpose of the program.
The Department concurred with the finding and stated it is currently working to hire a manager to develop proper procedures and trainings for staff to ensure standardized monitoring of audit requirements to comply with the financial components of agreements and contracts. The Department also stated internal communication will be improved and will be inclusive of program managers to act when necessary for providers to become compliant.
* * *
FAILURE TO DEVELOP A PROGRAM TO IDENTIFY THE SPECIAL NEEDS AND PROBLEMS OF MINORITY SENIOR CITIZENS
The Department failed to develop a program to identify the special needs and problems of minority senior citizens as required by the Illinois Act on the Aging (Act)
The Department did not develop a prescribed program to identify the special needs and problems specific to minority senior citizens as opposed to all senior citizens. In addition, the Department had not promulgated any administrative rules to establish the responsibilities of the Department related to a separate program targeting minority senior citizens, and had not coordinated services specific to targeted minority senior citizens with the other named departments pursuant to the Act.
Annual reports with demographic information for the Department's existing programs for all senior citizens provided almost no information on programs and services specific to minorities as provided under Section 4.06 of the Act. The auditors also noted these annual reports were compiled and submitted 15 months, instead of 3 months, following completion of the State's fiscal year.
Department management stated they believe existing programs and outreach efforts satisfy the intent of the Act. (Finding 7, pages 24-26)
We recommended the Department comply with the Act or seek a statutory revision.
The Department partially concurred with the finding and stated it provides services to minority senior citizens through its inclusive approach to programming. The Department further stated it is presently working to evaluate its outreach to minority populations to determine a more effective means to target its outreach efforts to minority populations under-represented in its current programs and to plan for the projected changes in
In an Accountant's Comment, we stated if the Department believes a program, services, evaluation, administrative rules, and reporting specific to minority senior citizens pursuant to Section 4.06 are not necessary, or if the Department believes existing programs, services, and reporting are sufficient to satisfy the intent of the Act, the Department should seek a legislative remedy to either eliminate or amend the specific requirements of the Act.
* * *
WEAKNESSES IN CYBERSECURITY PROGRAMS AND PRACTICES
The Department had not implemented adequate internal controls related to cybersecurity programs and practices. We noted the Department:
* Had not developed a formal, comprehensive, adequate, and communicated security program (policies, procedures, and processes) to manage and monitor the regulatory, legal, environmental and operational requirements.
* Had not established and documented cybersecurity roles and responsibilities.
* Had not classified its data to identify and ensure adequate protection of information (i.e. confidential or personal information) most susceptible to attack.
* Had not evaluated and implemented appropriate controls to reduce the risk of attack.
* Had not ensured all the Department's employees completed cybersecurity training for calendar year 2019 in accordance with the Data Security on State Computers Act. (Finding 9, pages 28-29)
We recommended the Department:
* Establish and communicate the Department's security program (formal and comprehensive policies, procedures, and processes) to manage and monitor the regulatory, legal, environmental and operational requirements.
* Establish and document cybersecurity roles and responsibilities.
* Classify its data to identify and ensure adequate protection of information.
* Evaluate identified risks and implement appropriate controls to reduce risk.
* Monitor and follow up on employees who have not completed cybersecurity training as required by the Act in order to enforce the training requirement.
The Department concurred with the finding and stated it has complied with all needed actions identified by the
* * *
OTHER FINDINGS
The remaining findings pertain to fiscal and administrative responsibilities, statutory mandates, and information technology controls. We will review the Agency's progress towards the implementation of our recommendations in our next compliance examination.
* * *
ACCOUNTANT'S OPINION
The accountants conducted a compliance examination of the Department for the two years ended
This compliance examination was conducted by
* * *
View full report at http://www.auditor.illinois.gov/Audit-Reports/Compliance-Agency-List/Aging/FY20-Aging-Comp-Digest.pdf


Judicial Council of California Issues Opinion in Maryam Hedayati Vs. Interinsurance Exchange of Automobile Club Case
Sen. Cantwell Heralds Wildfire Response and Recovery Investments in Infrastructure Package
Advisor News
- How advisors can prepare clients for an uncertain retirement landscape
- Investors aren’t waiting out uncertainty
- Transamerica and Advo(k)ate Advisors launch pooled employer plan
- ‘I wish I’d met him sooner:’ Karlan Tucker remembered for integrity, faith
- Why women must be more engaged in investing
More Advisor NewsAnnuity News
- Lumos Insurance introduces the Immediate Care Plan to help families fund long-term care
- NAIC regulators begin consensus phase on annuity illustration overhaul
- AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
- Market-value adjusted annuities: Key considerations for advisors
- Private equity’s next play in insurance
More Annuity NewsHealth/Employee Benefits News
- 76% of Gen Z and 63% of millennials turn to AI for first line of primary healthcare
- Oregonians face health insurance premium hikes
- Federal Medicaid cuts threaten Va.
- Editorial: Passing it on
- New York made $21.6M in improper Medicaid payments
More Health/Employee Benefits NewsLife Insurance News
- Supporting small businesses starts with smarter benefits conversations
- Judge again tosses Penn Mutual whole life lawsuit alleging tax scam
- Declined by a machine? The end of the unexplainable no
- AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
- Court sides with Ameritas in denying $4M STOLI payout to Wells Fargo
More Life Insurance News