State Compliance Examination For The Two Years Ended June 30, 2025
Learn how the AI-generated research projects were createdOverall Conclusion
In our opinion, except for the material noncompliance with the specified requirements described in the accompanying Schedule of Findings as items 2025-001 and 2025-002, the Department complied with the specified requirements during the two years ended June 30, 2025, in all material respects. However, the results of our procedures disclosed instances of noncompliance with the specified requirements, which are described in items 2025-004 through 2025-013.
Source Document
Audit Scope
Two-year period ended June 30, 2025; testing performed in accordance with attestation standards and Audit Guide; covers compliance with specified requirements (A–E) and internal control over compliance for the Department of Healthcare and Family Services.
Key Findings Summary
2025-001 Inadequate Controls Over Eligibility Determinations and Redeterminations — Material Weakness and Material Noncompliance.
2025-002 Inadequate Controls Over Personal Services — Material Weakness and Material Noncompliance.
2025-003 Inadequate Controls Over Accounts Receivable — Material Weakness and Material Noncompliance.
View the Findings tab to see all 13 findings
AI-Assisted
AI Scope Summary
The audit aimed to assess whether the Illinois Department of Healthcare and Family Services complied with the specified state requirements and internal controls over compliance for the two years ended June 30, 2025, and to report the findings and recommendations. While the Department largely complied, the engagement identified 13 current findings indicating material weaknesses and significant deficiencies in areas such as eligibility determinations, personal services, accounts receivable, cybersecurity, reporting, and voucher processing. The report also notes noncompliance with data sharing, LTSS, and data protection regulations, with management responses proposing corrective actions and ERP implementation to address control gaps.
AI-Generated Insight
This Illinois State Compliance Examination identifies multiple material weaknesses and significant deficiencies in internal controls, notably in eligibility processing, personal services, accounts receivable, cybersecurity, and reporting. The report underscores ongoing challenges in IT governance, workforce management, and data protection, while acknowledging overall compliance with statutory requirements aside from the identified findings. The auditor also notes improvements and management responses, including ERP SuccessFactors implementation and new procedures to address population data discrepancies.
Audit Objectives
Evaluate whether the Department of Healthcare and Family Services obligated, expended, received, and used public funds in accordance with the purpose for which such funds have been appropriated or otherwise authorized by law (A).
Evaluate whether the Department obligated, expended, received, and used public funds in accordance with any limitations, restrictions, conditions, or mandatory directions imposed by law upon such obligation, expenditure, receipt, or use (B).
Evaluate whether the Department complied, in all material respects, with applicable laws and regulations, including the State uniform accounting system, in its financial and fiscal operations (C).
Evaluate whether State revenues and receipts collected by the Department are in accordance with applicable laws and regulations and the accounting and recordkeeping of such revenues and receipts is fair, accurate, and in accordance with law (D).
Evaluate whether money or negotiable securities or similar assets handled by the Department on behalf of the State or held in trust by the Department have been properly and legally administered, and the accounting and recordkeeping relating thereto is proper, accurate, and in accordance with law (E).
Audit Findings (13)
2025-001 Inadequate Controls Over Eligibility Determinations and Redeterminations — Material Weakness and Material Noncompliance.
2025-002 Inadequate Controls Over Personal Services — Material Weakness and Material Noncompliance.
2025-003 Inadequate Controls Over Accounts Receivable — Material Weakness and Material Noncompliance.
2025-004 Weaknesses in Cybersecurity Programs and Practices — Significant Deficiency and Noncompliance.
2025-005 Failure to Establish the Long-Term Services and Supports Workgroup — Significant Deficiency and Noncompliance.
2025-006 Inadequate Internal Controls Over Required Reporting — Significant Deficiency and Noncompliance.
2025-007 Voucher Processing Weakness — Significant Deficiency and Noncompliance.
2025-008 Inadequate Controls Over State Vehicles — Significant Deficiency and Noncompliance.
2025-009 Noncompliance with the Requirements of the Illinois Insurance Code — Significant Deficiency and Noncompliance.
2025-010 Inadequate Controls Over Agency Workforce Reports — Significant Deficiency and Noncompliance.
2025-011 Inadequate Information Technology General Controls — Significant Deficiency and Noncompliance.
2025-012 Failure to Share Leading Indicators — Significant Deficiency and Noncompliance.
2025-013 Inadequate Controls Over Data Protection — Significant Deficiency and Noncompliance.
Recommendations (13)
Strengthen internal controls to complete certification of applications and redeterminations timely.
Improve timeliness and accuracy of personnel evaluations and ensure HIPAA training and ANCRA documentation are completed.
Strengthen internal controls over accounts receivable processing and certify or offset uncollectible debts where appropriate.
Establish a comprehensive cybersecurity risk assessment and document data classifications and safeguards based on classifications.
Establish the LTSS Disparities Workgroup and perform statutory duties including annual reports.
Publish statutorily required reports on the Department's website, include required information in General Assembly submissions, file reports with the State Library distributions center, and maintain a complete publications population.
Improve voucher processing controls to ensure timely approval and prevent duplicate payments; recover any overpayments.
Maintain accurate vehicle populations and ensure timely vehicle maintenance and inspections.
Collaborate with the Department of Insurance to ensure timely submission of the annual insurance code reports and implement guidance for parity requirements.
Strengthen controls over the Agency Workforce Report preparation and file corrected reports as needed.
Improve IT general controls, including access provisioning and change management, with population completeness.
Share leading indicators with MCOs and care entities and implement guidance for responses to lead indicators.
Improve data protection controls and establish proper data wiping documentation and procedures.