An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Department of Health & Human Services
Medicare Improperly Paid Millions of Dollars for Unlawfully Present Beneficiaries for 2013 and 2014
The Centers for Medicare & Medicaid Services (CMS) had policies and procedures to ensure that payments were not made for Medicare services rendered to unlawfully present beneficiaries in accordance with Federal requirements, but it did not always follow those policies and procedures. When CMS's data systems indicated that at the time a claim was processed the beneficiary was unlawfully present, CMS had policies and procedures to prevent payment for Medicare services, and CMS followed those procedures.
Our audit found that the Oregon Department of Education (Oregon) Consolidated Collection System, Oregon’s Statewide Longitudinal Data System, had a lack of documented internal controls in the system that increases the risk that Oregon will be unable to prevent or detectunauthorized access and disclosure of personally identifiable information. Specifically, we found that Oregon did not ensure that the Consolidated Collection System met the minimum requirements in Oregon’s Department of Administrative Services State Standards, which require the system controls and documentation of those controls. Since Oregon did not meet the minimum State requirements, it was notin compliance with Statewide Longitudinal Data Systems grant requirements. In addition, Oregon had policies and procedures that address reporting and responding to unauthorized access and disclosure of personally identifiable information in its data system. However, we could not determine whether the procedures were effective because Oregon had not reported any system breaches in the Consolidated CollectionSystem.