State Education Department
|
|
|
- Winifred Greer
- 9 years ago
- Views:
Transcription
1 O FFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY State Education Department Security Over Online Registration Renewal and Teacher Certification Report 2008-S-154 Thomas P. DiNapoli
2
3 Table of Contents Page Authority Letter...5 Executive Summary...7 Introduction...9 Background...9 Audit Scope and Methodology...10 Authority...11 Reporting Requirements...11 Contributors to the Report...11 Audit Findings and Recommendation...13 Security Management...13 Recommendation...15 Agency Comments...17 State Comptroller s Comments...19 Division of State Government Accountability 3
4
5 Authority Letter State of New York Office of the State Comptroller Division of State Government Accountability February 10, 2010 Mr. David Steiner Commissioner New York State Education Department State Education Building - Rm Washington Avenue Albany, NY Dear Commissioner Steiner: Following is our report of Security Over Online Registration Renewal and Teacher Certification. Executive management took little action to ensure the Department met Payment Card Standards. By not complying with Payment Card Standards, the Department may be subject to data being improperly accessed and stolen. Significant fines could also be levied by the credit card vendors (e.g. VISA, MasterCard, etc.). We urge you and your managers to act immediately on the report s recommendation and make the needed changes. If you have any questions about this report, please feel free to contact us. Respectfully submitted, Offi ce of the State Comptroller Division of State Government Accountability Division of State Government Accountability 5
6
7 Executive Summary State of New York Office of the State Comptroller EXECUTIVE SUMMARY Audit Objectives Did Department managers guard against the various risks associated with improper access to the Registration Renewal and Teacher Certification applications? Did Department managers meet the various security r equirements for these applications? Audit Results - Summary Department managers do not guard against the various risks related to improper access to the Registration Renewal and Teacher Certification applications. Further, Department managers have not met the various security requirements for these applications. Managers have also not devoted sufficient resources to develop and implement a plan to meet the requirements for protecting customer data. In fact, Department managers did not have an adequate security organization in place. The organization should include resources for identifying risks, classifying data, and ensuring procedures exist for adhering to both the Payment Card Standards and Security Policy. Our report contains one recommendation to improve controls over the Department s Registration Renewal and Teacher Certification applications. This report, dated February 10, 2010, is available on our web site at: Add or update your mailing list address by contacting us at: (518) or Office of the State Comptroller Division of State Government Accountability 110 State Street, 11th Floor Albany, NY Division of State Government Accountability 7
8
9 Introduction Introduction Background The State Education Department (Department) governs 48 licensed professions. It is responsible for licensing nearly 750,000 individuals and more than 30,000 professional business entities. The Department s Office of the Professions (Office) provides a number of services to the public and the professions such as processing forms, reviewing qualifications, and issuing credentials for various professions. The Office s Registration Renewal web-based application has been available since September It enables those who have licenses in certain professions, who are in the final five months of their current registration period or no more than four months past the expiration of their last valid registration period, to perform the following tasks online: Complete a registration renewal application, Request an optional Professional Photo ID Card and pay with a credit card, Choose to become inactive in the new registration period, and Change their address. The Department also has a web-based application used by its Office of Teaching Initiatives called TEACH (Teacher Certification), which allows individuals to apply online for, and check the status of, teacher certifications (the focus of our review) and fingerprint clearances, among other services. Both applications were created by consultants and are maintained by the Department s Information Technology Services Application Development Unit (Application Development Unit). Department managers must comply with the New York State Office of Cyber Security and Critical Infrastructure Coordination s (CSCIC) Cyber Security Policy (Security Policy) which defines a set of minimum information security requirements that all State entities must meet related to securing systems and data. For example, the Security Policy indicates that entities should classify data based on its confidentiality and availability. The Security Policy also requires that each State entity establish a framework to initiate and control its information security. In addition, Department managers are required to adhere to Payment Card Industry Data Security Standards (Payment Card Standards) which were developed by members of the payment card industry such as Visa and Division of State Government Accountability 9
10 Master Card in The Payment Card Standards are a set of information security requirements that apply to all entities that process, transmit, or store cardholder data. They include requirements for security management, information security policies and procedures, network architecture, software design, and other critical measures to help organizations protect customer account data. Entities that fail to comply with Payment Card Standards could be subject to significant fines depending on the incident of noncompliance. Audit Scope and Methodology We audited selected aspects of the security controls in place over the Registration Renewal and Teacher Certification applications for the period October 17, 2008 through May 18, Our objectives were to determine whether Department managers: (1) guard against the various risks associated with improper access to the Registration Renewal and Teacher Certification applications and (2) meet the various security requirements for these applications. We reviewed policies and procedures that we deemed important to the control and maintenance of application security. We interviewed agency technical staff responsible for controlling web application security and operations. We also examined records and reports pertinent to our audit scope. We tested security controls by determining whether there is a risk someone could gain improper access to the data maintained by the applications. In performing these assessments, we used various tools and techniques to pro actively identify application weaknesses and to determine how these weaknesses could be exploited. Our testing included scanning for weaknesses on specific servers and network devices, and more in-depth testing where we deemed it appropriate. Testing for web application weaknesses was performed on the Teacher Certification application only; however scanning for weaknesses was done on all devices related to the Teacher Certification and Registration Renewal applications. All scans had all dangerous tests turned off. Further testing is defined throughout this document. We also consulted with a Certified Payment Card Security Assessor to confirm the implementation of technology and processes for complying with the Payment Card Standards. We did our performance audit according to generally accepted government auditing standards. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide a reasonable basis for our findings and conclusions based on our audit objectives. We believe that the evidence obtained provides a reasonable basis for our findings and conclusions based on our audit objectives. In addition to being the State Auditor, the Comptroller performs certain other constitutionally and statutorily mandated duties as the chief fiscal officer of New York State. These include operating the State s accounting system; 10 Office of the New York State Comptroller
11 preparing the State s financial statements; and approving State contracts, refunds, and other payments. In addition, the Comptroller appoints members to certain boards, commissions and public authorities, some of whom have minority voting rights. These duties may be considered management functions for purposes of evaluating organizational independence under generally accepted government auditing standards. In our opinion, these functions do not affect our ability to conduct independent audits of program performance. Authority Reporting Requirements The audit was done according to the State Comptroller s authority as set forth in Article V, Section 1 of the State Constitution and Article II, Section 8 of the State Finance Law. We provided a draft copy of this report to Department officials for their review and comment. We considered their comments in preparing this report. Department officials agree with our recommendation, but disagree with some of the findings which relate to compliance with Payment Card Standards. Officials believe that our criteria conflicts with advice they have received from other reputable sources. Regardless of this conflict, our report clearly shows Department managers are not meeting basic compliance requirements such as completing annual questionnaires and completing code reviews or installing necessary application firewalls. Within 90 days after final release of this report, as required by Section 170 of the Executive Law, the Commissioner of Education shall report to the Governor, the State Comptroller, and the leaders of the Legislature and fiscal committees, advising what steps were taken to implement the recommendations contained herein, and where recommendations were not implemented, the reasons why. Contributors to the Report Major contributors to this report include David R. Hancox, Brian Reilly, Nadine Morrell, Mark Ren, Corey Harrell, Jennifer Van Tassel, and Sue Gold. Division of State Government Accountability 11
12
13 Audit Findings and Recommendations Audit Findings and Recommendation Security Management The Department is required to identify and manage risks to its data. It is also required to adhere to policies and regulations such as the Payment Card Standards and Security Policy. We reviewed the Department s procedures relating to data security for the Registration Renewal and Teacher Certification applications. Department managers did not have an adequate security structure in place. This structure should include identifying risks, classifying data and procedures for adhering to both the Payment Card Standards and Security Policy. Further, executive management devoted insufficient resources to developing and implementing a plan to meet Payment Card Standards, and no guidance was provided to the staff charged with ensuring the Department met applicable standards for handling credit card transactions. We also found that the Chief Information Officer assigned the position of Information Security Officer but did not give the person the authority to assign duties to other staff. The Information Security Officer has not been provided the resources necessary to complete all the functions required of an Information Security Officer by the Security Policy, including proper data classification. Payment Card Standards The information security requirements outlined in the Payment Card Standards apply to all system components that are included in or connected to the cardholder data environment (e.g., network components, servers and applications). We found Department managers did not meet all Payment Card Standards requirements. For example, as of December 31, 2008, the Department should have completed two annual self-assessment questionnaires. However, neither of them was completed. In addition, Department managers did not adequately complete code reviews or install an application layer firewall, as required. Nor did they have the required quarterly scans done on network devices. Department technology managers have had an agreement with CSCIC since November 2007 to scan for weaknesses on certain network devices on a monthly basis. However, we found that most devices involved in the processing of credit card payments have not been scanned, as required. We conducted our own scans on the servers and other devices that support the Registration Renewal and Teacher Certification applications. We found that Division of State Government Accountability 13
14 four of the eight network devices scanned had weaknesses that would cause them to fail a Payment Card Standards security test. In addition, in March 2009, we scanned the Teacher Certification application. We found weaknesses that may allow unauthorized persons to access server setup data, modify web pages, cause a denial of service, or perform other harmful actions. Department Application Development Unit staff were not aware of these weaknesses and were not aware of the risks linked with some of their settings. These staff, along with the Information Security Officer also could not explain to us how credit card information flowed through their system when payments were authorized. We, along with a Certified Payment Card Security Assessor, had to re-create the steps to determine how the credit card information was processed so we could perform the appropriate testing. These issues occurred because executive management took little action to ensure they met Payment Card Standards. For example, executive management devoted insufficient resources to developing and implementing a plan to meet Payment Card Standards. Also, no guidance was provided to the staff charged with ensuring the Department met applicable standards for handling credit card transactions. Department management assumed that certain Payment Card Standards did not apply to the Department and that sensitive customer data was secure without knowing their own systems. In response to our findings, Department officials indicated that they have recently sought guidance from another State agency on how to comply with Payment Card Standards. By not complying with Payment Card Standards, the Department may be subject to various consequences such as data being improperly accessed and stolen. In addition, the Department could be subject to significant fines. In response to our findings, Department officials stated CSCIC will continue to scan on a monthly basis the externally accessible network devices that support the Registration Renewal and Teacher Certification applications. They also said they had taken steps to address several of the weaknesses we found during our scanning. Department officials state they do not have the needed resources to scan all of the network devices that support the Registration Renewal and Teacher Certification applications. By not doing so, weaknesses could exist on these devices that Department managers may not be aware of and, therefore, the risk of improper access increases. Security Policy - Data Classifi cation The Security Policy indicates that all agency information should be classified and managed based on its confidentiality, integrity and availability. Data 14 Office of the New York State Comptroller
15 classification is a critical step that allows organizations to better understand the information that they actually have and then apply needed security measures to ensure sensitive information is protected appropriately. The Department s own procedures define three categories of data: public, restricted, and confidential. During the course of our audit, Department officials stated that data owners have been assigned, data has been classified, and controls have been implemented based on these classifications. However, we were provided with no evidence that data was classified in either the Registration Renewal or Teacher Certification applications. In response to our preliminary audit findings, the Department did provide a data classification for Teacher Certification. Department officials stated that all data within Teacher Certification is public with the exception of 12 fields. However, we determined that not all of the data was classified appropriately. We believe there are additional fields contained within the database that may be sensitive, including data related to criminal background checks, child abuse, and child support. In reviewing the Department s security management organization, we found that the Chief Information Officer assigned the position of Information Security Officer but did not give the person the authority to assign duties to other staff. As a result, the Information Security Officer has not been provided the resources necessary to complete all the functions required of an Information Security Officer by the Security Policy, including proper data classification. The Registration Renewal and Teacher Certification applications are supported by a database which contains various forms of sensitive and personally identifiable information. Without classifying the data residing on its network, management has no assurance that they are adequately protecting all of the Department s customer data. Recommendation 1. Department managers should provide proper security over the sensitive data in the Registration Renewal and Teacher Certification applications. This includes providing adequate oversight and guidance to implement the necessary controls and procedures to address the findings noted in this report. Division of State Government Accountability 15
16
17 Agency Comments Agency Comments * Comment 1 * Comment 2 *See State Comptroller s Comments on page 19. Division of State Government Accountability 17
18 * Comment 3 * Comment 3 *See State Comptroller s Comments on page Office of the New York State Comptroller
19 State Comptroller s Comments State Comptroller s Comments 1. We do not state that the Department stores or retains credit card information. We simply state that, The Payment Card Standards are a set of information security requirements that apply to all entities that process, transmit, or store cardholder data. The web-based applications we examined clearly process card holder data. 2. Contrary to the Department s comment, we found the Chief Information Officer did not give the Information Security Officer appropriate authority to fulfill her responsibilities. For example, the Information Security Officer could not assign duties to staff in the technical units. 3. We reviewed and analyzed the criteria as required by audit standards. In addition, we consulted with a Certified Payment Card Security Assessor to confirm the implementation of technology and processes for complying with Payment Card standards. The Assessor confirmed OSC s assessment of the Payment Card standards as they relate to the Department. Our audit report clearly shows that the Department does not meet all Payment Card standards. For example, they did not complete two years of the Payment Card questionnaires, and did not complete code reviews or install application layer firewalls. Division of State Government Accountability 19
OFFICE OF TEMPORARY AND DISABILITY ASSISTANCE NATIONAL DIRECTORY OF NEW HIRES DATA SECURITY. Report 2008-S-49 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 2 Audit Findings and
July 6, 2015. Mr. Michael L. Joseph Chairman of the Board Roswell Park Cancer Institute Elm & Carlton Streets Buffalo, NY 14263
July 6, 2015 Mr. Michael L. Joseph Chairman of the Board Roswell Park Cancer Institute Elm & Carlton Streets Buffalo, NY 14263 Re: Security Over Electronic Protected Health Information Report 2014-S-67
New York State University of Academic Majors and Undergraduate Programs
O FFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY State University of New York Assessments of Academic Majors for Undergraduate Programs at Selected Campuses Report
DEPARTMENT OF TAXATION AND FINANCE SECURITY OVER PERSONAL INFORMATION. Report 2007-S-77 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objectives... 2 Audit Results - Summary... 2 Background... 2 Audit Findings...
Oversight of Private Career Schools. State Education Department
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Oversight of Private Career Schools State Education Department Report 2011-S-51 August 2013
New York City Department of Buildings
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability New York City Department of Buildings Outstanding Violations Report 2010-N-5 Thomas P. DiNapoli
Department of Environmental Conservation
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability Department of Environmental Conservation Collection of Petroleum Bulk Storage Fees Report
September 19, 2005. Mr. Edward Cox Chairman State University Construction Fund State University Plaza Albany, New York 12201
ALAN G. HEVESI COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER September 19, 2005 Mr. Edward Cox Chairman State University Construction Fund State
Department of Motor Vehicles
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Motor Vehicle Financial Security and Safety Responsibility Acts: Assessable Expenses for the
New York State Office of Alcoholism and Substance Abuse Services
O FFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY New York State Office of Alcoholism and Substance Abuse Services Chemical Dependency Program Payments to Selected Contractors
October 21, 2004. Ms. Joan A. Cusack Chairwoman NYS Crime Victims Board 845 Central Avenue, Room 107 Albany, New York 12206-1588
ALAN G. HEVESI COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER October 21, 2004 Ms. Joan A. Cusack Chairwoman NYS Crime Victims Board 845 Central Avenue,
New York State Division of State Police
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability New York State Division of State Police Interest Earned on Seized Assets Report 2009-S-57
CITY UNIVERSITY OF NEW YORK EMPLOYEE ACCESS TO THE STUDENT INFORMATION MANAGEMENT SYSTEM AT SELECTED CAMPUSES. Report 2007-S-23
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 3 Audit Findings and
STATE LIQUOR AUTHORITY: DIVISION OF ALCOHOLIC BEVERAGE CONTROL OVERSIGHT OF WHOLESALERS COMPLIANCE WITH THE ALCOHOLIC BEVERAGE CONTROL LAW
Alan G. Hevesi COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES Audit Objectives... 2 Audit Results Summary... 2 Background... 3 Audit Findings and Recommendations... 3 Oversight
Department of Health
O FFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Department of Health Clinical Laboratory Evaluation Program Report 2008-S-88 Thomas P. DiNapoli Table Of Contents
Medgar Evers College: Controls Over Bank Accounts. City University of New York
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Medgar Evers College: Controls Over Bank Accounts City University of New York Report 2015-S-92
Department of Civil Service
O FFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Department of Civil Service Management of the Health Insurance Fund Balance Report 2009-S-48 Thomas P. DiNapoli Table
Seized Assets Program. Division of State Police
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Seized Assets Program Division of State Police Report 2013-S-46 December 2014 Executive Summary
MULTI-AGENCY EMERGENCY PREPAREDNESS AT SELECTED STATE AGENCIES. Report 2007-S-29 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 3 Audit Findings and
New York State Department of Taxation and Finance
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability New York State Department of Taxation and Finance Minority and Women s Business Enterprise
DEPARTMENT OF CIVIL SERVICE HEALTH INSURANCE PREMIUMS FOR PARTICIPATING EMPLOYERS. Report 2007-S-83 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objectives... 2 Audit Results - Summary... 2 Background... 3 Audit Findings and
Compliance With Payment Card Industry Standards. State University of New York
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Compliance With Payment Card Industry Standards State University of New York Report 2015-S-65
June 4, 2009. Mr. Eric R. Dinallo Superintendent NYS Insurance Department 25 Beaver Street New York, NY 10004
THOMAS P. DiNAPOLI COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER June 4, 2009 Mr. Eric R. Dinallo Superintendent NYS Insurance Department 25 Beaver
December 7, 2009. Re: ASA Institute of Business and Computer Technology Report 2008-T-4
THOMAS P. DiNAPOLI STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER December 7, 2009 Mr. David Steiner Commissioner State Education Department
Collection and Use of the Motor Vehicle Law Enforcement Fee
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Collection and Use of the Motor Vehicle Law Enforcement Fee Department of Financial Services
Office of Children and Family Services
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability Office of Children and Family Services Adoption Subsidy Program Report 2008-S-106 Thomas
STATE UNIVERSITY OF NEW YORK EDUCATIONAL OPPORTUNITY PROGRAM. Report 2007-S-99 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objectives...2 Audit Results - Summary...2 Background...3 STATE UNIVERSITY OF NEW
Disposal of Electronic Devices. Office of General Services
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Disposal of Electronic Devices Office of General Services Report 2012-S-4 December 2012 Executive
DEPARTMENT OF HEALTH MEDICAID OVERPAYMENTS FOR MENTAL HEALTH SERVICES. Report 2006-S-53 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 3 Audit Findings and
DEPARTMENT OF HEALTH INAPPROPRIATE MEDICAID PAYMENTS FOR DENTAL SERVICES PROVIDED TO PATIENTS WITH DENTURES. Report 2008-S-125
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 2 Audit Findings and
A REPORT BY THE NEW YORK STATE OFFICE OF THE STATE COMPTROLLER
A REPORT BY THE NEW YORK STATE OFFICE OF THE STATE COMPTROLLER Alan G. Hevesi COMPTROLLER OFFICE OF CHILDREN AND FAMILY SERVICES GOSHEN RESIDENTIAL CENTER SHIFT EXCHANGE PRACTICES 2002-S-17 DIVISION OF
Payments for Inmate Health Care Services. Department of Corrections and Community Supervision
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Payments for Inmate Health Care Services Department of Corrections and Community Supervision
DEPARTMENT OF MOTOR VEHICLES VEHICLE EMISSIONS TESTING PROGRAM. Report 2008-S-47 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objectives... 2 Audit Results - Summary... 2 Background... 2 DEPARTMENT OF MOTOR
FASHION INSTITUTE OF TECHNOLOGY SELECTED FINANCIAL MANAGEMENT PRACTICES. Report 2006-S-71 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 3 FASHION INSTITUTE OF
United HealthCare: Certain Claim Payments for Evaluation and Management Services
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability United HealthCare: Certain Claim Payments for Evaluation and Management Services New York State
October 28, 2014. Ann Marie T. Sullivan, M.D. Commissioner New York State Office of Mental Health 44 Holland Avenue Albany, NY 12229
October 28, 2014 Ann Marie T. Sullivan, M.D. Commissioner New York State Office of Mental Health 44 Holland Avenue Albany, NY 12229 Re: OMH Contract With Shorefront Mental Health Board - Compliance With
OFFICE FOR TECHNOLOGY ADMINISTRATION OF CONTRACT CM00664 UNISYS - ENTERPRISE HELP DESK. Report 2005-R-7 OFFICE OF THE NEW YORK STATE COMPTROLLER
Alan G. Hevesi COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES Audit Objective... 2 Audit Results - Summary... 2 Background... 3 Audit Findings and Recommendations... 3
New York State Medicaid Program
O f f i c e o f t h e N e w Y o r k S t a t e C o m p t r o l l e r Division of State Government Accountability New York State Medicaid Program Department of Health Under Reporting of Net Available Monthly
STATE EDUCATION DEPARTMENT WRITTEN SUPPORT OF INTERNAL CONTROLS OVER THE STATE AID MANAGEMENT SYSTEM. Report 2006-S-32
Alan G. Hevesi COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES Audit Objective... 2 Audit Results - Summary... 2 Background... 2 Audit Findings... 3 Control Environment...
January 17, 2007. Re: New York State Psychiatric Institute- Selected Financial Management Practices Report 2006-S-2
OFFICE OF THE STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER January 17, 2007 Sharon E. Carpinello, R.N., Ph.D. Commissioner New York State
Rebates and Discounts on Physician-Administered Drugs. Medicaid Program Department of Health
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Rebates and Discounts on Physician-Administered Drugs Medicaid Program Department of Health
September 25, 2014. Mr. Michael C. Green Executive Deputy Commissioner Division of Criminal Justice Services 4 Tower Place Albany, NY 12203
September 25, 2014 Mr. Michael C. Green Executive Deputy Commissioner Division of Criminal Justice Services 4 Tower Place Albany, NY 12203 Re: Hate Crime Reporting Report 2013-S-67 Dear Mr. Green: According
Improper Payments to a Physical Therapist. Medicaid Program Department of Health
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Improper Payments to a Physical Therapist Medicaid Program Department of Health Report 2013-S-15
July 22, 2015. Ms. MaryEllen Elia Commissioner State Education Department State Education Building 89 Washington Avenue Albany, NY 12234
July 22, 2015 Ms. MaryEllen Elia Commissioner State Education Department State Education Building 89 Washington Avenue Albany, NY 12234 Ms. Arlene Balestra-Marko Director Hear 2 Learn PLLC 6575 Kirkville
HUDSON RIVER-BLACK RIVER REGULATING DISTRICT ELIGIBILITY FOR HEALTH INSURANCE COVERAGE. Report 2008-S-51 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 Background... 2 Audit Findings and
DEPARTMENT OF HEALTH DETERMINING MEDICAID ELIGIBILITY. Report 2005-S-42 OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES
Alan G. Hevesi COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES Audit Objective...2 Audit Results - Summary...2 Background...3 Audit Findings and Recommendations...4 Deceased
DEPARTMENT OF HEALTH MULTIPLE MEDICAID PAYMENTS FOR MANAGED CARE RECIPIENTS. Report 2004-S-48 OFFICE NEW YORK STATE DIVISION OF STATE SERVICES
Alan G. Hevesi COMPTROLLER OFFICE NEW YORK STATE COMPTROLLER DIVISION OF STATE SERVICES Audit Objective...2 Audit Results - Summary... 2 Background... 3 Audit Findings and Recommendations...4 Identifying
State Education Department Whitestone School for Child Development
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Compliance With the Reimbursable Cost Manual State Education Department Whitestone School for
Costs to Administer the Insurance Division Operations for the Three Fiscal Years Ended March 31, 2012. Department of Financial Services
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Costs to Administer the Insurance Division Operations for the Three Fiscal Years Ended March
UNITED HEALTHCARE NEW YORK STATE HEALTH INSURANCE PROGRAM - OVERPAYMENTS FOR SERVICES AT THE EYE SURGERY CENTER OF WESTCHESTER.
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objective... 2 Audit Results - Summary... 2 UNITED HEALTHCARE Background... 2 Audit
August 15, 1997. Mr. Carl T. Hayden Chancellor The University of the State of New York State Education Building Albany, NY 12234
H. CARL McCALL STATE COMPTROLLER A.E. SMITH STATE OFFICE BUILDING ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER August 15, 1997 Mr. Carl T. Hayden Chancellor The University of
Metropolitan Transportation Authority Metro-North Railroad
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Overtime and Other Time and Attendance Matters Found in the Use of Certain Federal Funds Metropolitan
FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY
FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY Page 1 of 6 Summary The Payment Card Industry Data Security Standard (PCI DSS), a set of comprehensive requirements for enhancing payment account
How To Audit A Health Insurance Program
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability UnitedHealthcare: Improper Payments for Medical Services Designated By Modifier Code 59 New
August 18, 2011. Ms. Elsa Magee Acting President Higher Education Services Corporation 99 Washington Avenue Albany, New York 12255
THOMAS P. DiNAPOLI STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER August 18, 2011 Dr. John B. King, Jr. Acting Commissioner State Education
Appendix 1 Payment Card Industry Data Security Standards Program
Appendix 1 Payment Card Industry Data Security Standards Program PCI security standards are technical and operational requirements set by the Payment Card Industry Security Standards Council to protect
CITY OF SAN DIEGO ADMINISTRATIVE REGULATION Number 95.51 PAYMENT CARD INDUSTRY (PCI) COMPLIANCE POLICY. Page 1 of 9.
95.5 of 9. PURPOSE.. To establish a policy that outlines the requirements for compliance to the Payment Card Industry Data Security Standards (PCI-DSS). Compliance with this standard is a condition of
NEW YORK STATE DEPARTMENT OF ENVIRONMENTAL CONSERVATION RECYCLING PROGRAM. Report 2008-S-142 OFFICE OF THE NEW YORK STATE COMPTROLLER
Thomas P. DiNapoli COMPTROLLER OFFICE OF THE NEW YORK STATE COMPTROLLER DIVISION OF STATE GOVERNMENT ACCOUNTABILITY Audit Objectives...2 Audit Results - Summary...2 Background...3 Audit Findings and Recommendations...4
POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants
POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101 DIVISION: Finance & Administration TITLE: Policy & Procedures for Credit Card Merchants DATE: October 24, 2011 Authorized by: K. Ann Mead, VP for Finance & Administration
STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236. February 25, 2011
THOMAS P. DiNAPOLI COMPTROLLER STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STEVEN J. HANCOX DEPUTY COMPTROLLER DIVISION OF LOCAL GOVERNMENT AND SCHOOL ACCOUNTABILITY
February 14, 2014. Dear Mr. John Renner and Members of the Board of Fire Commissioners:
THOMAS P. DiNAPOLI COMPTROLLER STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 February 14, 2014 GABRIEL F. DEYO DEPUTY COMPTROLLER DIVISION OF LOCAL GOVERNMENT
Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014
Official Audit Report Issued March 6, 2015 Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 State House Room 230 Boston, MA 02133 [email protected] www.mass.gov/auditor
April 6, 2015. Ms. Elsa Magee Acting President Higher Education Services Corporation 99 Washington Avenue Albany, NY 12255
April 6, 2015 Ms. Elsa Magee Acting President Higher Education Services Corporation 99 Washington Avenue Albany, NY 12255 Ms. Elizabeth R. Berlin Acting Commissioner State Education Department State Education
Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008
Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements
Assessment and Collection of Selected Penalties. Workers Compensation Board
New York State Office of the State Comptroller Thomas P. DiNapoli Division of State Government Accountability Assessment and Collection of Selected Penalties Workers Compensation Board Report 2011-S-3
