Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

Internal audit reports 27% implementation rate; HIPAA governance and IT risks remain top outstanding issues

Audit & Compliance Committee, University of Minnesota Board of Regents · February 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The university’s Office of Internal Audit reported a 27% implementation rate for essential recommendations (below the 40% target), noted staffing challenges, and flagged HIPAA governance and distributed firewall management as persistent remediation priorities requiring multiunit coordination.

Chief Auditor Goswami briefed the Audit & Compliance Committee on internal audit work since October, highlighting staffing shortfalls, follow‑up results, and technology risks.

Goswami said internal audit is slightly behind schedule because of unexpected extended absences and staff turnover but expects to complete or initiate all planned audits this fiscal year. He reported one open financial auditor position and ongoing recruitment.

On follow‑up, Goswami said the implementation rate of essential recommendations during the period was 27%, below the committee’s expected 40% metric; 34% of outstanding essential items are past due. He explained much of the backlog stems from audits receiving first‑time follow‑up and that over half of unresolved recommendations relate to the HIPAA governance and oversight audit, a complex multiyear remediation requiring coordination across multiple units.

Goswami reviewed audit ratings: seven audits were issued this period, four rated 'good' (including men’s and women’s hockey compliance, CFANS environmental sciences and policy and management, the Center for Infectious Disease Research and Policy, and the College of Education and Human Development) and three rated lower because of information systems weaknesses (Neuroscience and the College of Pharmacy had elevated IT risks; firewall management was rated 'adequate' but nonpublic due to security sensitivity). He said affected units are working with the Office of Information Technology and a Health Sciences Technology unit to centralize expertise and reduce fragmented administration.

Committee members asked whether higher IT risk corresponds to monetary cost or personnel cost. Goswami said information security is expensive both for specialized equipment and for personnel (segregation of duties requires multiple skilled staff) and that centralizing services can create economies of scale.

On process, Goswami said ratings (good/adequate/needs improvement) signal attention but do not change follow‑up procedures: essential items are tracked and reported to the committee on a quarterly cadence until remediated. He pointed to three audits with items older than two years (detailed in the docket) and said administration will provide a May update on HIPAA remediation progress.