Said in CommitteeBeta

Exactly as spoken.

Legislative Joint Auditing-Educational Institutions

December 12, 2019 ·1:30 PM ·Room 138 ·1:29:40
Video Transcript 1 document

Transcript

Transcript available Whisper ✓ SliQ live captions: not yet available Download .txt
Machine transcript

May contain errors. Verify important quotations against the official video.

About transcript accuracy
Source
Whisper
Model
ggml-large-v3-turbo.bin RTX5060
Processing date
October 7, 2026
Representative Stan Berry Chair Unverified 0:00
off mr pitch would you like to say
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 0:04
anything no just welcome to the crowd and i think we've got several board or committee members in the building they're just not all here so
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 0:14
i think you're pretty good on a quorum so the chair is going to see the quorum and first over
▶ Play Suggest a correction Report an error
Michael White Unverified 0:20
business is uh item b adoption of minutes of the november 7th 2019 meeting and entertain a motion after you look Motion has been made. And second, all those in favor
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 0:33
say aye. Aye. Opposed? Motion carried. Okay, item number C, review of reports. Mr.
▶ Play Suggest a correction Report an error
Speaker 8 0:44
Newt. Thank you, Mr. Chair. Good afternoon to everybody. We kind of have a short agenda today. We have nine reports to review. Four of these reports include findings. Of the nine, four higher education audits, and that's the University of Arkansas system, the University of Arkansas for Medical Sciences, which is privately audited, and it's included in the information in the UA system audit report. We have Arkansas State University and Arkansas Tech University. Those three, higher ed, the UA system, ASU system, and Arkansas Tech audit information is needed for the state's comprehensive annual financial report, or better known as the CAFR. So their annual audit reports annually are presented at the December meeting. Also, two school districts classified in physical distress by the Arkansas Division of Elementary and Secondary Education, which used to be the Arkansas Department of Education, still have it, but we now have divisions within that. they're being presented today for review and the remaining three reports we have our special annual special report that we do for school districts receiving private audits. We have a charter school and then we have another school district that's in non-fiscal distress. So our first report is the University of Arkansas system. The first six findings are all referred to the applicable prosecuting attorney and they were all um detected by their internal audit office so the first finding has to is the university of arkansas fayetteville campus the university of arkansas system internal audit department conducted an audit to detect unauthorized changes to the university's vendor master file and and resulting losses primary for the period september 1st 2018 through november 30th 2018 after a suspected automated clearinghouse payment fraud management filed a report with the university police department internal audit found that one vendor's banking information was altered through a domain not belonging to the vendor resulting in 15 unauthorized unauthorized clearinghouse payments totaling $132,000 to an apparent fraudulent recipient. Of this amount, $13,000 was recovered by the bank leaving a loss of approximately $118,000 to the University. The second finding is the Little Rock Campus. The internal audit department conducted an audit of rental property agreements and payment information provided by management for the university's 17 rental properties for the period July 1st, 2017 through June 30th, 2018. Property management is handled by multiple departments and records are maintained manually. Internal audit noted the following. Six previous tenants owed $10,000 and one current tenant owed $148 for a total of $10,288 in past due rental payments. As of the report date, the six tenants still owe $10,140. Two current campus living employees did not transfer utilities into their names upon signing lease agreements, and the university improperly paid the utilities for these two properties for 10 months before the error was noted. The employees reimbursed the university through payroll deductions. The third finding is the Monticello Campus. The Internal Audit Department conducted an audit regarding a loss of $1,195 as a result of a payroll identity theft for the period December 14, 2018 through December 31, 2018. An employee contacted the payroll department after she did not receive her payroll direct deposit on December 14. After verifying that all payroll processes ran correctly and there were no issues with the direct deposit file sent to the bank, the payroll department staff inquired about the changes made to the employee's direct deposit information in the self-service portal and found out this information changed from a local bank to an online bank. The chief information officer noted the employee's self-service portal and email accounts were hacked and the employee did not make the changes. The fourth finding is the Hope Texarkana campus. The internal audit conducted an audit regarding a loss of 1889 as a result of a payroll identity theft for the period February 26, 2019 through March 27, 2019. Working with their information technology department, management reported that an employee's email account was compromised, which the IIT director later confirmed. Through an email with documentation sent to the payroll department, the employee's direct deposit information was changed to an apparent fraudulent account. Management filed a report with the Hope Police Department and indicated they believe this was an isolated incident and no other systems or emails were affected. The fifth finding is the Cosita Community College campus. The internal audit department conducted an audit regarding a loss of $1,322 the result of a payroll identity theft for the period January 23, 2019 through March 31, 2019. Working with the Information Technology Department, management reported that an employee's email account was compromised, which the IT director later confirmed. Through an email with attached documentation sent to the payroll department, the employee's direct deposit information was changed to an apparent fraudulent account. filed a report with the University Police Department and indicated they believed this was an isolated incident and no other systems or emails were affected. Subsequently, on April 8th, 2019, the University received 1322 from the bank. Finding six was the Phillips Community College campus. Internal Audit Department conducted an audit regarding an allegation of identity theft for the period June 1st, 2018 through July 31st, 2018. University management reported that an employee did not receive her payroll deposit of $1,732 scheduled for June 28th, 2018. The information technology director discovered that the employee's email account was compromised and accessed through an unauthorized VPN. Management notified the bank of the theft. However, the transaction had already been processed and could not be recalled. Management stated they believe this is an isolated incident and no other systems or emails were affected. And finally, finding number seven, in accordance with Arkansas Cove, we perform tests of student enrollment data for the year ended June 30th, 2019, as reported to the Department of Higher Education to provide reasonable assurance that the data was properly reported. During our review, we noted the following items. At the Pine Buff campus, supporting documentation for 50 students was tested. However, one student, which was reported as enrolled in two courses as of the 11th class day for the fall 2018 semester, was determined to have never attended. At the Batesville campus, two students out of 79 students tested withdrew prior to the 11th class day but were included in the enrollment numbers submitted to the department of education and that concludes the findings for the university of
▶ Play Suggest a correction Report an error
Michael White Unverified 9:25
arkansas system okay do we have someone that uh is representing the university of arkansas federal on these if you would go to the end of the table and identify yourself and we'll see if the committee has any questions they would like to ask you Mr. Smith Just turn your mic on and identify yourself one at a time, please.
▶ Play Suggest a correction Report an error
Speaker 24 10:18
Good afternoon. My name is Michael White. I'm the Interim Vice Chancellor for Finance and Administration at the
▶ Play Suggest a correction Report an error
Speaker 26 10:25
University of Arkansas Fayetteville. Good afternoon. I'm Chuck Ramziar, Associate Comptroller for the
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 10:30
University of Arkansas Fayetteville. So before we ask questions, would you like to make a comment of any kind?
▶ Play Suggest a correction Report an error
Speaker 24 10:38
The only thing I can say about this particular issue that we're here to address is that after we reported to internal audit that we suspected there was a problem, internal audit came in with their, did their review and made their recommendations, and we have implemented all of their recommendations. and they have basically signed off on what we have done, and I'll be glad to describe what the situation was and the steps that we've taken to remedy this problem. We have basically had a breakdown of communication between our accounts payable department and our folks in our business services area that manage our vendor file. There was a seemingly legitimate request coming through the vendor portal that kind of fits the mold of a classic fraud scheme where everything appeared to be correct to the individuals that were responsible for updating the vendor file. So what happened was they changed the contact information and the bank account number and routing number, all of that information, and so that our, and the vendor that was targeted here was Dell. So it's a vendor that we do a lot of business with. For a period of time, electronic payments were being made as they normally would be through the ACH process. The funds were being deposited into the, what we now know as the fraudulent bank account. And by the time the fraud became aware, or we became aware of it, once Dell's Fraud Department informed us that they suspected there was a fraud here, within two days we had reported it to internal audit and reported it to legislative audit. We've implemented several procedures now to try to ensure that this sort of thing doesn't happen. training has been intensified in that area, specifically geared toward fraud detection. We now have a system where there has to be sign-off from both departments that are involved and a review, and if any kind of request for a change of this sort to the vendor file information, there has to be a verification done of that, and the easiest way to do that is to actually try to verify using the existing information that we know is legitimate to contact the vendor to see if that is indeed a legitimate request to change that. So at this point, we think that our controls have been greatly strengthened. We should not have an issue like this happen again, but that's where we are today. the uh unfortunately the way these things work when the money is electronically transferred to these other banks that's just the beginning of the process on their side so the money starts being passed around all over the place and they it ends up being basically hidden uh the money that we did recover i think related directly to the the last payment that we made and our banking partner was able to work with some other banks to be able to pull that money back. But by the time we had gotten to this point, all the other payments had been routed probably to some offshore accounts and all. So that's why we really don't expect there will be any additional recovery, but we did make
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 14:19
every attempt to recover as much as possible. Mr. Smith,
▶ Play Suggest a correction Report an error
Representative Stu Smith Unverified 14:27
did you have a question? Yes, sir. Thank you, Mr. Chair. I have two questions, actually. I'll do a follow-up. But given the fact that there have been several similar incidents where an account was hacked during the transfer of funds to an employee's bank account, have you all been able to trace back where maybe the hackers or collective, hacker collective, are gathering, or is this just broad all over the map? My instinct tells me it's broad all
▶ Play Suggest a correction Report an error
Speaker 24 15:03
over the map. I don't think that we haven't had an issue like some of the others that have been reported here today as far as the payroll is concerned. So I'm assuming that these were totally different types of schemes and they were coming
▶ Play Suggest a correction Report an error
Representative Stu Smith Unverified 15:26
from different places, but I don't know that for sure. Follow-up, sir? Follow-up? Okay, I appreciate that, and I think you've put some processes in place that can make things safer, safeguard the information, but a lot of times these groups will test to see how vulnerable a system is for getting into and breaching the firewalls and things. But if you continue to have these problems, is there an opportunity for you all or are you cooperating with the FBI to try to eliminate this concern? I know in this particular case
▶ Play Suggest a correction Report an error
Speaker 24 16:09
we did report to UA Police Department, and I don't remember. I think the FBI was informed of this, but i don't know that they actually did any kind of official inquiry or looking into this they relied on on what our internal audit group and ua police were able to do thank you thank you
▶ Play Suggest a correction Report an error
Senator Kim Hammer Unverified 16:36
mr chair mr hammer you're recognized thank you mr chair the uh the bank recovered 13,108 I'm curious, just educate me as to why they weren't able to
▶ Play Suggest a correction Report an error
Speaker 24 16:47
recover more. The accounts were closed by the time the fraud was discovered. In these types of fraud, what happens is the money tends to be deposited into one place or multiple places, and then they act very quickly and siphon that money out and send it in different places. So it becomes virtually untraceable within the banking system. So the $13,000 that we did recover, I believe, related probably to the last payments that we made to Dell or what we thought was Dell. And that money was still available for our banking partner to work with SunTrust, which I believe was the other institution that was involved there, to actually pull that back before the fraudsters had an opportunity to move
▶ Play Suggest a correction Report an error
Senator Kim Hammer Unverified 17:35
it. Okay. And I'd like a question on finding two appropriate times, Chair. All right. Thank you. On finding two, is that involving dorm fees or rental property for the students, or is that for commercial property owned by the university? Oh, that's the university. Little Rock. I'm sorry. You guys, sorry about that.
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 18:00
I just saw that. I'll get that. Thank you. Mr. Pitts. My question is, it's a benefit to have a large audience here. What would you do different to prevent a portal entry into your system? And maybe you need to understand I'm an electrical engineer, and I'm very interested in the technical prohibition of doing this across all of our spectrum of universities. Because I think that's a very fertile ground for
▶ Play Suggest a correction Report an error
Speaker 53 18:29
hackers to find large amounts of money.
▶ Play Suggest a correction Report an error
Speaker 24 18:33
So comments? Well, in this case, I mean, this was the normal accepted process for vendors to be able to request changes to their vendor files. Vendors are always changing banking information or they're changing mailing addresses or even contact information as far as an individual being to be contacted. What should have happened and what we are doing now is whenever those requests come in electronically through the portal is we are verifying those on the back end before any changes are actually made. And those changes are being signed off on by appropriate level of management. So the way I've described before is you would go back with the last reliable information that we know we had with the proper contact information and verify through that avenue before we would actually go into the vendor file and make those changes. And that is what we're attempting to do now. That is what we're doing. Okay.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 19:36
Any other questions from the committee? If not, Mr. Hammer. So I noticed, you
▶ Play Suggest a correction Report an error
Senator Kim Hammer Unverified 19:48
know, what do you do as far as a university system that if this happened at Fayetteville, How do you communicate it out to the other schools within the system so that they're not targeted and it can be prevented? Well, I believe some of our system folks
▶ Play Suggest a correction Report an error
Speaker 24 20:04
that are here could probably describe that process more in depth than I can. But I do know that when internal audit is brought in and they find a particular case like this, I know that that is kind of communicated out across the system. But Laura Cheek is here and can actually speak to that. She's from our internal audit department. Okay, Mr. Chair.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 20:29
Do you have something to add? If you do, introduce yourself. Yes. My name is Laura
▶ Play Suggest a correction Report an error
Laura Cheek Unverified 20:34
Cheek, and I'm the Interim Chief Audit Executive for the University of Arkansas. Pull your microphone down
▶ Play Suggest a correction Report an error
Michael White Unverified 20:39
just a little bit and speak a little closer to it, if you would.
▶ Play Suggest a correction Report an error
Speaker 60 20:44
I'm Laura Cheek. I'm the Interim Chief Audit Executive for the University of Arkansas system. And when this happened at the University of Arkansas, the internal audit sent out a fraud risk alert notification to all of our campuses and asked them to certify that they had controls in place to prevent it. Okay.
▶ Play Suggest a correction Report an error
Michael White Unverified 21:07
Thank you. Thank you, Mr. Chair. Any other questions? If not, entertain a motion to file this report. If there's any other questions for any of the other campuses, I do it out. We've been asked, too, is there any other questions from any of the other campuses about this issue? Okay. All right. If not, I'll entertain a motion to file the report. The motion's been made. You need a second? Second. We'll run through these individually. Okay. All those in favor of the motion say aye. Opposed? Motion carried. Thank you very much. Thank you. Do we have representatives from the University of Arkansas, Little Rock? If you
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 22:15
would, at the proper time, identify yourself. Good afternoon.
▶ Play Suggest a correction Report an error
Speaker 74 22:36
Identify yourself. Yes, I am Steve McClellan, the Vice Chancellor for Finance Administration at the University of Arkansas
▶ Play Suggest a correction Report an error
Michael White Unverified 22:43
at Little Rock. Okay. Mr. Newt has read the findings. Do you like to have a comment on those findings? Sure, I will
▶ Play Suggest a correction Report an error
Speaker 75 22:52
lead up with that. The university has several houses that we buy up
▶ Play Suggest a correction Report an error
Speaker 74 22:56
in a period of time. We're really looking for the land of one of them versus the houses. But as we buy them, we shift the management of them to the housing department. I think the number of houses have grown to like 17 houses. We're not actually pursuing that market now. But the housing department is in the business for running residence halls but really has not practiced good business or has not had good business policies in place for the management of their rental houses. Due to a change in administration and no written policies, the new employees that came in were doing what they thought were friendly, these to help people out, but it left us with invoices that were not being paid. Now, we have changed the process totally now. There's written policies in place to address housing and the rental of housing on campus and getting utilities in your name, as well as any employee that moves in that must be on payroll deduction before they
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 24:00
can move in. Thank you. Senator Hammer, question. Thank
▶ Play Suggest a correction Report an error
Senator Kim Hammer Unverified 24:05
you, Mr. Chair. The rentals in question, were they dorms that were rented to students?
▶ Play Suggest a correction Report an error
Speaker 74 24:11
No, these were rental houses. But no students were involved in it then? I think there was a student in one of the houses, but most of the houses were rented out to employees. There may have been more than one, but
▶ Play Suggest a correction Report an error
Senator Kim Hammer Unverified 24:28
most of the houses are rented to employees. Okay. One follow-up, Mr. Chair. One follow-up. Okay. Okay, so what's been submitted to collection agencies is pertaining to people that were previous employees that are no longer there, and you're having to go to the collection agency in order to get the money from them. Am I correct in that?
▶ Play Suggest a correction Report an error
Speaker 75 24:47
Yes, which is the same procedure we use for our students. We send them to our collection. First, we
▶ Play Suggest a correction Report an error
Speaker 74 24:52
send you our 30-day note, letting you know that the debt is payable in full. Then we send you to a collection agency. Then that's a period of time being we send you off to debt set off. debts that off. You usually turn those accounts over in January. All right. Thank you. Senator Cheatham, you recognized? Thank you, Mr. Chair.
▶ Play Suggest a correction Report an error
Senator Eddie Cheatham Unverified 25:14
Senator Hammer may have already beat me to the punch, I guess, but some of these homes were actually rented to employees of the university?
▶ Play Suggest a correction Report an error
Speaker 84 25:21
That is correct. And they're not employed there any longer, correct? That is correct. Okay. So there's no way to recoup money through
▶ Play Suggest a correction Report an error
Senator Eddie Cheatham Unverified 25:29
payroll deduction from their checks the ones the ones that
▶ Play Suggest a correction Report an error
Speaker 75 25:31
we if you was the second part there was a couple of them in there that one
▶ Play Suggest a correction Report an error
Speaker 74 25:36
that were employees that still are employees were set up on payroll deduction and those bills have been closed
▶ Play Suggest a correction Report an error
Senator Eddie Cheatham Unverified 25:40
they're participating in the okay repayment okay thank you thank you mr chair any other questions
▶ Play Suggest a correction Report an error
Michael White Unverified 25:51
there's no further questions i'll entertain motion to file this report motion made and second all those in favor say aye opposed motion carried thank you uh finding number three university of arkansas at monticello state your name for the record and and if you have opening comments you'd like to share,
▶ Play Suggest a correction Report an error
Alex Becker Unverified 26:27
just continue. Yes, sir. My
▶ Play Suggest a correction Report an error
Speaker 90 26:30
name is Alex Becker. I'm the Vice Chancellor for Finance and Administration on the Monticello campus. After this incident that's been reported today, we immediately began to look at the way that we monitored changes in employee banking information. We were using a negative confirmation process, So we would notify the employee that we detected a change, and if you made the change, then disregard this email. Unfortunately, in this instance, when the email was hacked, there were rules applied to the inbox so that any email that we sent containing certain keywords was immediately deleted from the inbox. So now what we've done is not only do we send an email, but we also follow up with a phone call and get verbal confirmation for any change. And we're also doing this daily to try to stay
▶ Play Suggest a correction Report an error
Speaker 91 27:22
on top of this and protect our employees and our money.
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 27:29
Any questions of the committee? Ms. Mayberry. Thanks a lot for sharing this. When I sat on this committee back in 2015, I don't remember this many stories like this in our audit reports back then. We're seeing this more and more because we just had a school district in, I think, last month or the month before that that had a similar thing. And so, I mean, just as legislators, right now we're just kind of understanding what's happened there. But I always try, what can we learn from this? And do you have any thoughts if there's anything legislatively that can be done that can help prevent some of this fraudulent activity that we're talking about today and that has happened with
▶ Play Suggest a correction Report an error
Speaker 90 28:16
some of our school districts? Off the top of my head, I'm not sure. What we believe to have happened is the employee clicked on an email link that was fraudulent, which in turn opened the door and gave access to their username and password. so all we can do on our side is try to prevent that moving forward and so we've gotten IT involved heavily and tried to establish several barriers to identify whether or not the change was legitimate prior to and now what we do is we just take the payroll off direct deposit and cut them a check and we'd rather them be upset with us for that than losing
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 28:52
their money so I guess it's just the new age of doing things and just trying to look for solutions because more of these situations are unfortunately going to continue to happen. Yes,
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 29:03
ma'am. So, thanks. Any other questions from the committee?
▶ Play Suggest a correction Report an error
Michael White Unverified 29:12
If not, we entertain a motion to file a report. Motion is made. And second. All those in favor say aye. Opposed? Motion carried. Thank you. Finding number four, University of Arkansas Community College at Hope, Texarkana. State your name for the record, and if you'd like a statement, just continue on, please.
▶ Play Suggest a correction Report an error
Speaker 103 29:46
Good afternoon. I'm Brian Berry. I'm the Executive Vice Chancellor and CFO at UA Hope, Texarkana. Our finding is very similar to UAEM's. We had a faculty member whose email was compromised, and so the email originated from inside our system where the perpetrator completed a form and also had that faculty member's social security number to put on the form and asked that the banking direct deposit be changed. And so our payroll department received that and processed it on the day of the payroll. The faculty member contacted our payroll department, said that they had not received their direct deposit, So we checked and discovered the fraud at that point, contacted our bank, Bank Court South, and they attempted to reverse the ACH. But the perpetrator had immediately, as soon as the funds hit, withdrew the money and closed that account. It was an online banking institution, and so we were unable to recover those funds. Immediately after that, we changed our process, so we have employees have to make that request in person. In the few instances where we have an adjunct faculty who's not able to come to campus, they have to submit a notarized, and then we contact them based on information that we previously had to confirm that that is actually a change that they made. Mr. Pitch.
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 31:06
Quick question, maybe it's for the last university as well. Are they getting into your system and sending an email that appears to be obviously full of spam, but does it appear to be from within your system?
▶ Play Suggest a correction Report an error
Speaker 103 31:19
In our case, it was from when they had the faculty member's password to the email. RIT, working with Google, discovered that that faculty's information was available on the dark web, and so that they got, having a social security number, our payroll department didn't question it. If we get an email that originates from outside our system, it's identified in our email system, so as an external email, so they know it originated from off campus. But in this case, it was, they had the faculty member's password, and they had, like at UAM's case, had changed the rules, and so when our payroll department, you know, responded to confirm the change, it went to an e-mail that was off campus, and so the faculty member wasn't aware of the confirmation request. A follow-up? Sure. I guess, so
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 32:11
bear with me here. In effect, you're dealing with a hacker that's getting into your system and seems to be doing it at other universities, and I'm wondering if we're dealing with a system-wide, that's the new methodology of getting into this deal. And it challenges me that the DIS departments at our universities, are we aware that outsiders are coming in, getting a handhold to this, and then
▶ Play Suggest a correction Report an error
Speaker 107 32:37
getting out from there? Because that may be where the fix needs to come. We suspect
▶ Play Suggest a correction Report an error
Speaker 103 32:43
in this case that the faculty member at some point answered a phishing email and disclosed her email that they didn't gain access to our system globally. It was through this individual. And so we also have mandatory training now for all new employees when they come on board, as well as annual training, where we educate them to not, don't click on attachments, don't never answer, you know, provide your email, passwords or any system passwords. through email that we won't request those to try and address this. So we don't believe they didn't gain access globally through our system. It was through an individual who inadvertently disclosed that password at some point. Representative Fortner.
▶ Play Suggest a correction Report an error
Representative Jack Fortner Unverified 33:31
Thank you, Mr. Chairman. Did I understand you to say that this password was disclosed to the dark web?
▶ Play Suggest a correction Report an error
Speaker 111 33:39
It was. That's what Google informed our information technology that apparently, after it was disclosed,
▶ Play Suggest a correction Report an error
Representative Jack Fortner Unverified 33:46
it was available. So the employee, through the school system, went onto the
▶ Play Suggest a correction Report an error
Speaker 103 33:52
dark web? No. No. Whoever gained access to that password had put it out there for sale so that it was available to purchase for folks who wanted to commit fraud.
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 34:04
Thank you. Any further questions? I entertain a motion to
▶ Play Suggest a correction Report an error
Michael White Unverified 34:20
file the report. Motion made. Second? Need a second? Motion made and second. All those in favor say aye. Opposed? Motion carried. Thank you for your presentation.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 34:35
Item number five, University of Arkansas at Monticello. am i off
▶ Play Suggest a correction Report an error
Speaker 114 34:40
i can turn the page don't let him get away with that yeah sorry about that
▶ Play Suggest a correction Report an error
Speaker 117 34:48
if you would state your name hello i'm charlotte johnson i'm the cfo at
▶ Play Suggest a correction Report an error
Michael White Unverified 34:54
costa dot okay did you
▶ Play Suggest a correction Report an error
Speaker 118 34:59
have a comment um we had the
▶ Play Suggest a correction Report an error
Speaker 119 35:05
exact same scenario that happened. I really can't add much to it. I'm not a technical person, so I'm not sure I can tell you much about how the thievery happened, but we were able to recover our funds, and that was with our campus police contacting the recipient bank, and they actually were able to freeze the account right away, and after a couple of months, they did return the funds. That's the only difference, I think, in our scenario. Thank you.
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 35:33
Doreenny. Yeah, I got one. Mr. Pitch. And maybe I'm just not asking the right question, so I'll ask you and try again. Is your DIS department on campus? Yes.
▶ Play Suggest a correction Report an error
Speaker 118 35:45
And was the same exact thing occurred? They believe
▶ Play Suggest a correction Report an error
Speaker 119 35:48
that the employee's password was stolen because they logged in as the employee from an offsite, I would assume. But they were able to actually get into this faculty member's email. They gained access to the forms that we used off the Internet and filled it out with her Social Security number, her information,
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 36:10
and emailed it to our payroll department. I guess I hope we have every higher ed institution in the room so they're listening since we only got three of us, but it clearly
▶ Play Suggest a correction Report an error
Speaker 119 36:22
is a target, fertile ground. Be careful. And we've learned, please verify everything in person. Technology is great, but it's
▶ Play Suggest a correction Report an error
Senator Alan Clark Unverified 36:34
not all that. I'm going to ask you, it's really a question for, uh, others, uh, this doesn't seem to me to be, and again, new things come, you know, in business, we have similar things, and new scams come along all the time. That being said, this one didn't seem to be that hard to predict to me. No. So do we not have anyone that's over IT security, over our whole system of universities?
▶ Play Suggest a correction Report an error
Speaker 118 37:06
Well, each campus has their own IT, and I don't know if anybody. Could Dr. Bobbitt?
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 37:17
Do we have it? Sure. State your name for the record,
▶ Play Suggest a correction Report an error
Speaker 136 37:23
please. My name is Don Bobbitt. I'm president of the U of A system. The answer to your question, Senator Clark, is
▶ Play Suggest a correction Report an error
Speaker 139 37:29
we do have a CIO for the system. It's a new position. One of the reasons why we felt compelled to move in this direction is exactly because of what you're hearing today. I will tell you, though, that you can put every single control, state-of-the-art, in place, as Representative Pish said, and if someone makes a mistake, then the system is compromised. And in the news recently, because we have a medical campus, There is a national medical system, not an academic, but has three huge hospitals and 50,000 employees. And a phishing incident occurred in which four out of the 50,000 clicked the wrong thing. And as a consequence, all of their materials were basically hardened to being read, and they had to cancel all surgeries for over a weekend. In fact, only emergency surgeries are done. So it's very serious. But my point being, with 50,000 employees, it only takes one mistake. And these emails are originating inside the system, apparently, because you can VPN, and if you have the credentials of Don Bobbitt, you can send emails to people that look like it's coming from Don Bobbitt in the University of Arkansas system. So we're only ever as strong as our weakest link. What we have done is we're moving toward a single HR, finance, and student information system, to harden the system. We have found out with this array of different institutions that we have that we had different policies and procedures for handling almost every issue. We will have one set of policies, one set of procedures. They will be the state of the art. The other thing is that when these types of things are found out, you discovered or you've heard that our audit department notifies every institution. But what we also have, if you have six different accounting systems and five different of this and two different of that, that if there is a security patch that needs to go in, not everyone puts it in place at the same time. With a single system, the entire system will be patched, secure, and hardened at the same time. So we understand the threats that are out there, and you're absolutely right. Just as soon as we identify one, they morph into something else. But the most important thing we need to do is keep educating our
▶ Play Suggest a correction Report an error
Speaker 140 39:46
employees about what they can and
▶ Play Suggest a correction Report an error
Senator Alan Clark Unverified 39:51
can't do when people send requests to them. Mr. If I may, Mr. Chair and Dr. Bobbitt, you're, of course, absolutely correct. Before the Internet, scammers were always coming up with something new. That being said, the payroll was an obvious target, and we're way too trusting with e-mail and that type of communication, and that's why I asked about an IT security expert, because I was looking forward and seeing that the ability to change where your payments went via email, which is very convenient. It's like people, I mean, we even have locales in this country that do vote by email. And the fact that some people want to do that horrifies me because, you know, the lack of security is just that, again, I don't expect the normal rank-and-file person. because you're, but we're never going to train every person. Anything that's dependent on each individual to not click on an email or to not do this or not do that will fail. And so if it does not come back to, okay, we can't do this because of security risk, if you're going to, once you've got this initial information in here, if you're going to change it, as somebody said that they were going to do after the fact, uh, that we're going to come back now. And if you change it, You're going to have to come in person or a notarized statement. Some of these things are foreseeable because something similar has happened. And that's why I asked if we didn't have IT security experts. I'm not trying to money more than quarterback. I'm just trying for the future. Do we have people in place that can say, look, here's the things that we're doing that we shouldn't be doing. It may be convenient, but we're leaving ourselves wide open for scammers. So I'll offer you
▶ Play Suggest a correction Report an error
Speaker 136 41:57
two pieces of information to sort of show you how we're addressing that. One, our
▶ Play Suggest a correction Report an error
Speaker 139 42:03
audit department has gone outside for a firm that specializes in these type of security issues. We have an audit of the entire U of A system that's going to probe the system starting January 1. The contract's been approved. Two years? Take two years. And they're going to identify our weaknesses in places where we need to tighten things up. The second thing is we've gone to many of these transactions to multi-factor authentication so that a single point doesn't allow a substantial change to occur. All
▶ Play Suggest a correction Report an error
Speaker 136 42:36
right. Thank you. Thank you, Mr. Chair. Senator Hill,
▶ Play Suggest a correction Report an error
Speaker 146 42:43
I believe you're next. Dr. Bobbitt? Yes. I agree
▶ Play Suggest a correction Report an error
Senator Ricky Hill Unverified 42:51
with you 100% on what you're saying as far as getting these issues fixed and stuff, but I don't want you to get a false hope because we do not know what the next scam is, what the next hacker is, until it happens. Yeah. When you have that loss is when you get – the good guy is always playing defense. The bad guy is always on offense. When we get one thing stopped, there's going to be another, And I think you're on the right track as far as setting up the IT overall to go that route. But I do expect to see us back here next year discussing something, just because that's the nature of the beast we're dealing with now.
▶ Play Suggest a correction Report an error
Speaker 140 43:28
I'm going to take a year off and let Chuck Welsh
▶ Play Suggest a correction Report an error
Senator Ricky Hill Unverified 43:32
come up next. Well, hey, Chuck will be facing it too. So thank you. Just keep being proactive on it. Thank you. Okay, Ms. Mayberry.
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 43:44
Thank you, Mr. Chair. You said you hired someone new for this position. Can you tell me, again, I was trying to write down what is the title of that position, and then who is that person, and what's their background? Did they come from another state? Did they come from within? If you can share some of that.
▶ Play Suggest a correction Report an error
Speaker 136 44:01
Absolutely. Good question. First of all, the position is Chief Information and Technology
▶ Play Suggest a correction Report an error
Speaker 139 44:05
Officer for the University of Arkansas system. And as I think several of the respondents up here told you, we also have CIOs on each of our campuses, and so now we have a coordinated conversation going on amongst all of them. So what happens at one is now disseminated to all of them. The individual who holds this position is Steve Fulkerson. Steve was head of ARON in this state, which is the optical network, high-speed optical network that we have. Steve came to us from Kentucky, where he held a position of similar responsibility. He's very, very good and very good and knowledgeable about the latest technologies to kind of prevent these things. And that is one of the hope in going to a single system is what we frequently have seen is that a system would be hardened at one institution in response to an incident, and it would take some time for the others to come around, and that could be fatal, frankly, particularly at our hospital. So by having a single system, everything, everyone is patched, everyone is up to date and hardened at exactly the same time as soon as the threat becomes apparent. Thank you. Any
▶ Play Suggest a correction Report an error
Senator Eddie Cheatham Unverified 45:29
other questions of the committee? Chairman, just comment, I guess I think Dr. Bobbish pretty much explained through the other questions what I had was going to suggest or ask, but you are consolidating your systems throughout all the schools are going to be tied
▶ Play Suggest a correction Report an error
Speaker 140 45:44
together. Is that correct? Absolutely. Yep. And so whether you're in Mena, Arkansas or in Little Rock or Fayetteville or whatever, you will have exactly the same capabilities at exactly the same time. The reason I thought about
▶ Play Suggest a correction Report an error
Senator Eddie Cheatham Unverified 45:57
this is that those around this table, I'm sure if Senator Chesterfield did not get her payroll deduct, she'd be very upset. And I don't remember, I don't sit on this committee and I appreciate you letting me ask questions, but I don't remember any the other committee state agencies where this has been a problem with the state, which I'm sure is a much bigger system than what we're talking about right here. So, you know, but anyway, that's the information that's out there if we just look for it. But going to one system and hiring someone like Steve, I think, as always, you made the
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 46:37
right decision. I'll say that. Mr. Mayberry. Thank you for giving me another question. I'm sorry. I should have asked this of you. I asked of another lady who was up here, I think was that Hope or Monticello, but is there anything that we as legislators could do that could help? I mean, I don't see how we can prevent people from opening a bad email or something like that, but if there's anything legislatively that we need to do, whether that's increasing some penalties or providing some assistance, you'll let us know? or? I definitely
▶ Play Suggest a correction Report an error
Speaker 139 47:11
will let you know. I will tell you, though, that these incidents, they're not originating in Arkansas, and they're most likely not originating in the United States of America, and that's one of the reasons why it's so difficult to get the money back. Literally, at the speed of light, it has moved between multiple institutions and moved offshore, and it is effectively gone so the only way the only way that we can help the U of A system I determined is that we prevent them and that's what we're we're devoting our energies including this audit that I mentioned and the reason why we've gone external is we don't want any internal biases we want to bring in outside people state-of-the-art who theoretically do this for very large corporate entities across the United States and we want to know what we don't know, even if it
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 48:06
embarrasses us. Thank you. All right. Any other comments
▶ Play Suggest a correction Report an error
Michael White Unverified 48:13
or questions from the committee? If not, entertain a motion to file this report. Motion made. Second? Second. Motion made and second. All those in favor say aye. Opposed? Motion carried. Finding number six, Phillips Community College. Is there a
▶ Play Suggest a correction Report an error
Speaker 117 48:39
representative? Okay. If you would, recognize yourself, introduce
▶ Play Suggest a correction Report an error
Michael White Unverified 48:46
yourself. Good afternoon. I'm Keith Finchback, Chancellor of PCCUA,
▶ Play Suggest a correction Report an error
Speaker 174 48:53
and I've brought my IT man.
▶ Play Suggest a correction Report an error
Speaker 177 48:59
I'm Jason Jaco, I'm the IT Director for Philips Community College, University of Arkansas. Stan
▶ Play Suggest a correction Report an error
Speaker 178 49:06
Sullivan, Vice Chancellor for Finance and Administration. All right, do
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 49:10
you have any comments you'd like to start with? Yes,
▶ Play Suggest a correction Report an error
Speaker 179 49:13
it's almost identical, sir, except I will say that because of the new procedures we put in, we were able to catch two attempts. Also, let me remark for Jason that he did track the IP address to an address in San Jose, California. So if you have any questions of us, I will most likely point over to Jason.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 49:36
Okay, is there any questions from the committee?
▶ Play Suggest a correction Report an error
Speaker 61 49:40
Comment. Comment. Comment, Mr. Spitz.
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 49:43
Just a comment, Mr. Chairman. It was just whispered in my ear that we have three audit committees going on at the same time, and right now they're doing the exact same thing, dealing with identity theft. It is a real situation, and we just asked, you know, we have Dr. Welch and Dr. Bobbitt. We've just got to be somehow, and it's a changing field that we don't exist in, and it's real, and it's taxpayer money now that's being spent, whether that's identity theft on a pay, and quite frankly, I just mentioned to the person that told me that, we're really lucky we only have four institutions of higher learning here. What do we have, 21 or something like that? Yes. Because that's a fruitful ground. And quite frankly, you have lots bigger financial transactions going on than payroll. And at some level, we're just thankful they're not getting into that pot.
▶ Play Suggest a correction Report an error
Speaker 179 50:40
And you are correct. And this policy was started for efficiency. But with technology and efficiency, sometimes it doesn't mix completely. And that's what we have found, that we still need to see a human being for this change. Okay,
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 50:55
we have Senator Chesterfield and then Senator Clark. Thank you, Mr. Chair, and
▶ Play Suggest a correction Report an error
Senator Linda Chesterfield Unverified 51:00
thank you for allowing me to ask a question. One of the things that I noticed recently on television are the smart TV things that are creating difficulty now, like, for instance, the guy that took over the smart TV and was talking to the little girl and luring her away from home. Are we having to deal with that? Because I know we're using up-to-date equipment, not just in our finances, but in other areas as well. Are we being hacked in that way as well, or have we even thought about it? Because I know many of our classrooms are equipped with smart TVs and that sort of thing. And people are taking over the cameras, and they're doing, yeah, I mean, it's here. So I'm wondering, are we looking at that as well? and perhaps I should have asked Dr. Bobbitt across the system, are we looking at that as we upgrade equipment, are we making sure then that the smart TVs and the smart this and that are not also becoming our
▶ Play Suggest a correction Report an error
Speaker 188 52:01
enemies? I'm sure, and I can't speak for all of my counterparts at the UA System Schools, we do have that type of equipment out there broadly at all of our campuses. We each monitor traffic as best we can to see if there's anything outside of the norm going on. But, yes, ma'am, that is absolutely an area that we have to take a look at.
▶ Play Suggest a correction Report an error
Senator Alan Clark Unverified 52:24
Thank you, Mr. Chair. Thank you. Senator Clark. Yes. If it's relevant, what did you all do that enabled you to catch a couple of tries and to track it down? The
▶ Play Suggest a correction Report an error
Speaker 188 52:42
way that they, we detected a couple more attempts. What we noticed, and I think it's the same case with each of the campuses, they would go to our faculty, staff, student portal, log in with the credentials that they had received, that they had gotten from the email. They would log in from whatever location they wanted to. We use Microsoft Office 365. They have some tools where you can go and track down where that system, Where the email system was accessed from and it was from a virtual private network The last point out was in San Jose, California that by no means means that that's where that person was Very likely as dr. Bobbitt said they're probably outside the country. That was just their point of entry
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 53:31
Thank you, mr. Chair Representative flowers As we've been hearing about this finding after finding around the same issue or the same problem, sorry, I just started looking up some things on my phone, which I'm scared to do now. And I just started thinking about how, especially with universities, it used to be that paper was located on campus, right? You got paper checks, and then you take them to the bank. And one of the things that struck me about one of the articles that I was just reading is, number one, obviously this is an issue that's affecting campuses all over the country, right? And that I got whispered in my ear of my colleague who works at a bank about how oftentimes these fraudulent transactions are taking place in another country. And China is what kept popping up in this particular article. So when we think about AI, when we think about the technology with our phones, when we think about what's happening with these fraudulent activities as it relates to employees that we've heard, students. What is happening maybe globally and maybe what's happening with our federal law enforcement to deal with this as a law enforcement issue, but also is there anything, conversations, conferences, technology, as it relates to what's happening globally? Because this is clearly a global
▶ Play Suggest a correction Report an error
Speaker 188 55:25
issue. That's a hot-button topic for any conference that I've attended. Security is always just on the forefront of the discussions. The FBI, just from my Google feed, I know that the FBI has had some pretty high-profile arrests as far as identity theft and these type of incidents. It just has to be hit from so many different angles, And it's hard to get a comprehensive strategy that the federal government's involved down to the individual institution or business. There are just so many different openings to get in. So this is sort
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 56:06
of a joke, but not really. Maybe we ought to go back to
▶ Play Suggest a correction Report an error
Speaker 179 56:12
landlines and paper. Well, you mentioned artificial intelligence. We could talk a whole day about that, but we don't too. But Stan and I recently, I guess, went last year to a fraud conference, and there was a whole set of meetings specifically on this topic, and it was from the federal level. So it's out there. But as mentioned, each time we change our
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 56:36
protocols, the hackers get smarter. Well, and one other thing. I was listening to something just on the radio like two days ago, and there was a Chinese company that is looking at, and I think it was an AI company and providing some sort of service to data collection and technology firms that manage our data on a large scale, and then the guy who was being interviewed was talking about how dangerous it was because they're doing it at such a cheaper rate, and then some of our U.S. companies are taking advantage of that. Some of them aren't in heeding the warning. But we're sitting here, you know, using our phones and mining our business, and who knows what's happening with our medical data, our financial data, our personal data, our social media data. It just scares the bejesus out of me right now, and I don't even know. Like, there is no legislative fix for this, and we keep on going down this rabbit hole with everything we do. I mean, I'm serious. Maybe the legislative fix is we go back to paper. Okay. Are there any other comments?
▶ Play Suggest a correction Report an error
Speaker 146 57:57
Mr. Smith, we need to run along
▶ Play Suggest a correction Report an error
Representative Stu Smith Unverified 58:01
here pretty quick. Thank you, Mr. Chair. Just broadly, have any of our institutions of higher learning had any problem with ransomware hacks, where your system is all locked down, and what did you do to remedy that? Because a lot of times it's cheaper to pay than it is to go after the hackers. So anyone can respond to that.
▶ Play Suggest a correction Report an error
Speaker 188 58:31
Thank you, Mr. Chair. We have not had any issue with that, and I know that as far as the University of Arkansas System Schools, each one of us has not the same software, but a software package in place that one of the things that it detects upon entry is ransomware as well as other types of malware. Again, it's hard to stop. They change as quickly as one protocol is figured out, they move to another one, but But we do have things in place to help minimize that
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 59:10
risk. Anyone else? Okay, I have a motion at the
▶ Play Suggest a correction Report an error
Michael White Unverified 59:17
proper time to file this report. Second. Let me just say that there's a lot of good discussion. All these problems are pretty relative to one school or one organization. the other and i think it's important that we talk about it and it's been a good discussion all those in favor of the motion to file this report say aye opposed motion carried thank you
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 59:48
thank you thank you we have one more finding number seven these are we have four or two findings, okay.
▶ Play Suggest a correction Report an error
Michael White Unverified 1:00:05
Does anybody, do the members have any questions on these? And Mr. Pitch? Well, at the risk of having my colleague come
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:00:12
back to the end of the table, because it may not be his question, but Senator Hammer asked me to ask a question in general of the higher ed folks, because these two findings both deal with people who didn't make it to the 11th day. And he wanted to remind that we passed the legislation that if you don't make it to the end of the 11th day, there should be every effort to recoup the Arkansas scholarship money that was given to said student. And he wanted to ask if there was anybody that could weigh in on how that process was working since we've got to a point where fraud and abuse is dominating. So I don't know if anybody wants to comment for him, but he wanted that question put in front of the higher ed folks in the room.
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 1:00:58
Sir, do you have a comment that you'd like to make? You started to the end of the table. Not
▶ Play Suggest a correction Report an error
Michael White Unverified 1:01:06
put you on the spot or anything, but you were ready to go, I believe.
▶ Play Suggest a correction Report an error
Speaker 218 1:01:11
I was ready to go. I'm Robert Carr. I'm the provost and vice chancellor of academic affairs at the University of Arkansas at Pine Bluff. I'm going to chalk that up to a rookie mistake. But I just wanted to say, in our case, what we found was that it was an isolated instance and that the faculty members actually misreported what they thought they were putting into the system. We take those types of instances and occurrences very seriously, and it has caused us to review our policies and make some new policies to make sure that that instance doesn't happen again. Were
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:01:50
you able to follow up? In those cases, were you able to recoup any of the Arkansas back to Senator Hammer's question? Were you aware of
▶ Play Suggest a correction Report an error
Speaker 222 1:01:58
that process? We have our controller, Mr. Childs, here, and he would be able to talk about it. I think
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:02:05
it's interesting, and I don't know whether the UA system would like to weigh in or the ASU system, but it is an intriguing deal, folks not getting to the 11th day and having scholarship money dispersed.
▶ Play Suggest a correction Report an error
Speaker 224 1:02:17
introduce yourself if you
▶ Play Suggest a correction Report an error
Speaker 225 1:02:21
would and continue all
▶ Play Suggest a correction Report an error
Speaker 226 1:02:24
right yes sir agent childs controller and um interim um cfo in this instance it involved a um deployed military student and in our instance you know we apply aid rather lately so no aid from arkansas was applied to him
▶ Play Suggest a correction Report an error
Speaker 165 1:02:47
Any questions from the committee?
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 1:02:56
Ms. Flowers. What happens in the instance with this new rule, and I know this is something that other universities probably could answer too, but since you're here. Yes, ma'am. What happens in the case of a class where there's a midterm and a final? Or how does that work where you have to have some sort of assignment logged? Do they just add some kind of extra credit homework? How does that work?
▶ Play Suggest a correction Report an error
Speaker 218 1:03:29
When you mean in terms of midterm and final? To report, to be able to report that a student is attending. Yes. So what our new policy is going to be is that before the 11th day, we're requiring each faculty member, both our regular faculty and adjunct faculty members, to have students submit some assignment to them in writing, or if it's on Blackboard, through the internet, through online means, that verifies that they're actually in
▶ Play Suggest a correction Report an error
Speaker 220 1:03:58
the course. Because you should have something to verify that you've attended. And one
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 1:04:05
other question. So what happens if that student is still in the process of being enrolled, because sometimes you have stragglers, sometimes you have someone who might be coming back from serving or whatever. What happens if that person is not enrolled until after that? After the 11th day?
▶ Play Suggest a correction Report an error
Speaker 223 1:04:25
Yeah. We're going to hope that doesn't happen.
▶ Play Suggest a correction Report an error
Speaker 231 1:04:30
Okay. We're going to hope that doesn't happen. Well, if it does, you know
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:04:34
they're going to call me, and then I'll call you. Absolutely. Thank you. Mr. Pitch. I just had a visit with Mr. Broadway, And he's going to step out and make one quick phone call to verify. But I think he's got clarification on where that is. So I don't want to derail the discussion about your individual findings with 11th day scenarios. But
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 1:04:57
I think he's got the answer for us. Okay. Okay. So we can go ahead and move on. Do you have any further comments you'd like to make? I don't. Okay. Ms. Flowers.
▶ Play Suggest a correction Report an error
Speaker 235 1:05:16
Oh, Mo... There's a... Is he going... It's
▶ Play Suggest a correction Report an error
Michael White Unverified 1:05:20
okay to motion. Okay. Instead of waiting on Mr. Broadway, let's go ahead and... Do I have a motion to... Okay, second. Do I have a second? Okay, I've got seconds everywhere. All those in favor say aye.
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 1:05:37
Aye. Opposed? motion carried thank you thank you we'll uh
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:05:46
on uh findings number seven there are does anybody have any other comments that the the committee have any other comments on any of these colleges If not, the University Let's see. These are all. That's the responses to the findings. So we have
▶ Play Suggest a correction Report an error
Speaker 241 1:06:30
those others with follow-up. Correct me if I'm wrong. Okay. So
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:06:38
we need to move on to, if Mr. Broadway's not in it. We can do that. Mr. New.
▶ Play Suggest a correction Report an error
Speaker 8 1:06:52
We're going to move on to the next report. Now, probably
▶ Play Suggest a correction Report an error
Speaker 25 1:06:55
Batesville's feeling left out, I bet. We talk to everybody except Batesville. Now, if you really want to come
▶ Play Suggest a correction Report an error
Speaker 8 1:07:11
up here, you can. But we'll move on. The next report that we have is actually a special report, and it's in that order because there was a finding that was referred to the prosecutor. I'm not going to go over the whole summary of that. It's there for you. I'll go over the findings for each individual school district. Basically, we looked at six school districts that received private audits that were scheduled for a private audit in 2019. This is our fourth year to do that. The Blyville, Conway, Harmony Grove of Saline County North Little Rock, school districts had no reportable findings. But Fordyce School District had one finding and Pottsville had one finding. For Fordyce School District, and it was the finding referred to the prosecutor due to an ethics violation, the district paid an employee $4,700 for personalizing apparel and supplies during the period July 1st, 2018 through April 30th, 2019, without a board authorizing resolution as required by the ethics law. And then Pottsville, I'm not going to read all the individual items there, but they had several internal control weaknesses in their cash receding process, and it was in the activity funds. This did not involve the district funds, but the activity funds, so they had some weaknesses there. And that concludes the summary of that report. Okay, let's go ahead
▶ Play Suggest a correction Report an error
Speaker 12 1:08:55
and... You want to go ahead and review this
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:09:03
report? Yeah, I think if there are questions, review that, and we'll go back. Well, let's go ahead, before we go with Mr. Broadway, let's go ahead and
▶ Play Suggest a correction Report an error
Speaker 253 1:09:09
I entertain We need a motion to, if there's any questions, or we can have a motion to file the report.
▶ Play Suggest a correction Report an error
Speaker 254 1:09:18
I think I would ask for a motion
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:09:21
to review. Go ahead and introduce Mr. Broadway, is what you would like to ask
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:09:26
for a review. I think since we kind of got off the rail with Senator Hammer's question, I think I got an answer whispered in my ear. Shane Broadway, would you identify yourself and then we'll ask the question
▶ Play Suggest a correction Report an error
Speaker 258 1:09:39
and you can answer what you found. Shane Broadway, ASU
▶ Play Suggest a correction Report an error
Speaker 222 1:09:43
system, more importantly probably for this question, former director of the Department of
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:09:48
Higher Education. Senator Hammer had a question about his recently passed legislation and what was defined to me was the Arkansas scholarship money being recouped and he applied it to the 11th day but I think you
▶ Play Suggest a correction Report an error
Speaker 222 1:10:00
found some other information for the committee so please answer. Thank you Mr.
▶ Play Suggest a correction Report an error
Speaker 258 1:10:05
Chairman and members of the committee for a chance to help clarify. Senator Hammer's bill applies to the Arkansas Scholarship Lottery or any scholarship that the Department of Higher Ed administers. The department does not pay on the 11th class day. What happens is once you reach the 11th class day, anyone who's applied for a scholarship through ADHE is on what we call the roster. And we had a roster of that student's name and what institution they were at. And once you got to the 11th class day, we would send that roster out to the Department of Higher Education, to the institution that they had identified that they were enrolled in. That institution would then verify that that student is in fact at that institution and enrolled in the minimum number of required hours, which in the freshman year it's at least 12 in the first fall semester. They would then send that notice back to the department and then we would begin the process of disbursing. So no student receives money before the school year starts. Nobody receives any money until after they've been verified. What Senator Hammer's legislation focused on was there were some students, and we can get with the department and try to get this number, his concern was that there were some students who would get money and they would go through the whole fall semester and never earn an hour. They wouldn't complete any courses. They'd end up with zero. When the Arkansas Lottery Scholarship first started, we did not have the ability, I was at the department the second year of the awardees, we didn't have, the technology wasn't in a way where we could check every semester if a student had any hours or not. And so you had some students who enrolled in the fall, didn't complete any hours, but that they re-enrolled in the spring for enough hours, even though I'd completed zero in the previous semester, if they'd enrolled and were at that university, we were paying it out. So they could go a whole year and not complete any hours. And at that time, it was $5,000. Now it's $1,000. So they could get that money and never complete a course. And so what Senator Hammer's bill did was back that up. And we finally were able, working with all the financial aid folks around at all the institutions was every semester those rosters are verified that a student completed hours. So if you got a student who went through the fall semester and received their $500, because it's half and half, if they got their $500 and completed zero hours in that fall semester, they would not be permitted to receive money for the spring. There was no provision or really a way, because it's, we're talking about state money, not institution monies. This is just state dollars that would disperse this way. There's really not a way for ADHE to recoup that except to go through some kind of recovery process, you know, lien process or anything like that. We may get some more information from the department about how they've done that if there's a way to recoup it. But at at least what it does is stop them getting money for the next semester to complete
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 1:13:33
nothing. Does that help? Mr. Mayberry. Thank you. Hello? I may have to turn this one off. Hello? Okay, I'll just talk about it. So you're referring to the first year student, so it's really only $500?
▶ Play Suggest a correction Report an error
Speaker 260 1:13:44
Right. that maybe would be out but then it would be every year so it would be every year good question they do get more money right and it does still apply
▶ Play Suggest a correction Report an error
Speaker 259 1:13:53
to those it does yes that's an excellent question it does it applies every year i was just referencing the first year but you
▶ Play Suggest a correction Report an error
Speaker 258 1:13:59
get to a senior year where it's five thousand dollars and they get the first twenty five hundred and don't complete any hours then it would be uh then they wouldn't no way to get no way to get it back to my knowledge And that's where we may, Representative Klemmer had already left from another meeting we'd had.
▶ Play Suggest a correction Report an error
Speaker 259 1:14:17
So we can probably get the department maybe to help. I think we're good. I mean,
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:14:22
I don't want to, we're already off the rails from our agenda. It was a question. Senator Hammerhead that thought applied to the 11th hour or 11th day. Yeah, it doesn't apply to 11th day. So I just, I think we've closed it with your description here. I think our chair is ready to go back to, did you need something, Senator Clark? Mark, I'm going
▶ Play Suggest a correction Report an error
Senator Alan Clark Unverified 1:14:43
to step in here. Point of order. Normally, the reason that a mic doesn't work is because too many others have been left on.
▶ Play Suggest a correction Report an error
Speaker 267 1:14:49
Yes. You might check your mics,
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:14:51
make sure they're not on. Only the two chairs should really be the only one left on. Yeah, they're
▶ Play Suggest a correction Report an error
Speaker 269 1:14:59
working now. Okay. Thank you, Mr. Chairman.
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 1:15:10
Thank you, Mr. Broadway. Anytime, Mr. Chairman.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:15:13
Okay. Okay. I think we're going to get back on track here. Need a file motion to file for six Arkansas school districts. The review is selected in policies and procedures transactions, and I'll entertain a motion for that. Motion made. Any second? Second. All those in
▶ Play Suggest a correction Report an error
Don Bobbitt Unverified 1:15:41
favor say aye. Aye. Opposed? Motion carried.
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:15:49
Okay. The next report, findings of Pine Bluff School District of Jefferson County.
▶ Play Suggest a correction Report an error
Speaker 12 1:15:55
Mr. Newt. Thank you, Mr. Chair. We've got a lot of exiting folks now. I'll bring up, I don't know if Dr. Owa
▶ Play Suggest a correction Report an error
Speaker 8 1:16:11
is here yet. Okay. um since pine bluff was a physical distress repeat school district had a repeat finding um they the superintendent is invited um to the committee um but he also was scheduled to be in attendance at the state board of education meeting which is going on now and he said he would try to get here, but he has not yet. But he has his chief operating officer and also a representative from ADE is here as well. If you want to go ahead and review the report, it's up to the committee whether they want to go ahead and defer the report without review or go ahead and review the report and listening uh if you have any questions you can um inquire of these these folks
▶ Play Suggest a correction Report an error
Michael White Unverified 1:17:00
uh committee does everyone understand we can correct we can defer it to uh next month or we can uh listen to the testimony of okay
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:17:18
i have a motion to defer it uh for next month and second Oh, I'm sorry. Does
▶ Play Suggest a correction Report an error
Senator Linda Chesterfield Unverified 1:17:27
the state board meet again the same time next month? That's the problem when we have schools that are under state control, is that the state board of education meets at the very same time that this committee meets. Right. Our meeting is off in January because we
▶ Play Suggest a correction Report an error
Speaker 8 1:17:45
rescheduled it to January 23rd. So that will make a difference. I don't know what this, do you, that's okay, it seems like. I can't hear. She's saying they're going to financial reports, they will be available. That's the only reason I wanted to ask that question. It appears that they
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:18:15
would be available January 23rd. The superintendent should be.
▶ Play Suggest a correction Report an error
Michael White Unverified 1:18:21
Senator Flowers, did you have a question? We should thank fiscal officers. Okay, we have a motion on the floor to defer this issue to next month and a second. All those, is there any discussion on the motion?
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 1:18:39
Yes, ma'am. I just started reading this, but since the CFO is here and someone from the State Department, I'm wondering if we can hear and ask questions, and then if the information is not, if we still have more questions, and I'm wondering if we can defer at that time or consider that. And I'm just proposing that to my colleague who's made the motion.
▶ Play Suggest a correction Report an error
Speaker 281 1:19:11
Since they're here. Since they're here. I'm sorry. Oh, he
▶ Play Suggest a correction Report an error
Representative Vivian Flowers Unverified 1:19:18
requested that? We have
▶ Play Suggest a correction Report an error
Speaker 282 1:19:20
a motion on the floor.
▶ Play Suggest a correction Report an error
Michael White Unverified 1:19:42
to. We have motion on the floor and second to defer it to next month. Do you want more discussion? Excuse me?
▶ Play Suggest a correction Report an error
Senator Mathew Pitsch Unverified 1:19:51
Do you want more discussion? Because I'd like to comment. Yeah, go ahead. I do think a superintendent, when you're in fiscal distress and you've made arrangements to try your best to get here and you didn't get here, we probably owe them the right to defer and let him come have his ability to answer questions my opinion we're not in a hurry to get to a review of a finding and I guess I tend to agree with it I feel sorry for our financial officer who's here but he'll probably
▶ Play Suggest a correction Report an error
Speaker 287 1:20:25
be here next month with his superintendent
▶ Play Suggest a correction Report an error
Michael White Unverified 1:20:28
I imagine I agree with you Mr. Pitch I'm going to go ahead and call a vote all those in favor of the motion to defer to next month, say aye. Aye. Opposed?
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:20:44
Motion carried. All right, thank you. So we'll review that next week, or next month, excuse me.
▶ Play Suggest a correction Report an error
Speaker 8 1:20:50
Mr. Newt, comment. There is one more report with findings. It's the Arkansas State University system. They had one finding. The university had uninsured and uncollateralized deposits totaling $328,000 at June 30, 2019 in noncompliance with Arkansas Code. Identify yourself, please,
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:21:11
and make your comments. Chuck Welch, I'm the
▶ Play Suggest a correction Report an error
Speaker 294 1:21:16
president of the Arkansas State University System. This was a situation where we had an investment that matured two days prior to the end of the fiscal year, was temporarily converted to cash and failed to get collateralized. That was fixed as soon as it was noticed. I believe, correct me if I'm wrong, but anything over $250,000 is registered as a finding. Is that right, that amount? Anything over
▶ Play Suggest a correction Report an error
Speaker 250 1:21:42
$250,000 has to be collateralized. Right, right, right. So, but that's been
▶ Play Suggest a correction Report an error
Speaker 294 1:21:47
addressed. We've also put policies and procedures in place to ensure that this doesn't happen again. Questions by the committee? Anything else? You know, just real quickly on the comments that were made about the cybersecurity, very similar to what's happening in the University of Arkansas system, we also have efforts going on within hours. Our CIOs working together to identify those. We have a dual authentication system now that's in place that it's a pain, but it's one of those necessary pains that before I can do certain things in our system, I have to respond to a text or an email, however, that dual authentication is set up to verify that it is indeed me. And then we have a lot of other different kinds of processes that we're working on. Ransomware question was asked. We've had attempts that have not been successful. We actually, our CIOs attack our own systems in an effort to try to identify. I know Audit does some of those, and we hire third-party vendors to do it. It's just one of those that you have to constantly stay on top of it and look at it, and it's a difficult scenario. The biggest challenge we've probably had of late is that individuals sending emails from outside of our system that has my name and says, please call me immediately. Now, one of them that's been most frequently used is, I can't talk right now because I'm about to round off this meeting. And I've told people, if I ever say round off a meeting, then I want you to do something else to me. But, you know, that's one of those things that's just difficult as well. and we try to do as much employee education as possible. But, you know, as you said earlier, it's just that weakest link is a challenge. But I can assure you that it's something we look at. I texted our CIO here, and I said, tell me again for the Jonesboro campus how many unique devices we have touching our system daily. And he said it's about 35,000 every day unique. And so that obviously brings with it a whole different set of challenges as well that we have to stay on top of. uh
▶ Play Suggest a correction Report an error
Senator Linda Chesterfield Unverified 1:24:00
senator chesterfield you could have gotten out of here you know we i know i could have senator but you know don's over here volunteering me for stuff so uh all of the campuses on the
▶ Play Suggest a correction Report an error
Speaker 294 1:24:11
on a singular system we are moving to that just as the u of a system is yes we actually had a meeting this morning so for for that's one of the primary reasons as well all right how far long are you are you already hired someone is done oh yes we're already uh we're six months into it for uh phase one and then we'll go into that phase two starting in the in the new year but we're definitely well into working on
▶ Play Suggest a correction Report an error
Speaker 297 1:24:32
it so thank you thank you mr chair miss
▶ Play Suggest a correction Report an error
Representative Julie Mayberry Unverified 1:24:41
mayberry thank you mr chair um on this report and this is kind of for audit two henderson is not listed here and so i'm just trying to find out where we are in finding out the most latest audit report i I know that we were really behind, so I don't know who wants to address
▶ Play Suggest a correction Report an error
Speaker 250 1:24:57
that and how. Well, I can go ahead and address it because the Henderson State 2018 report
▶ Play Suggest a correction Report an error
Speaker 8 1:25:04
was early released today. It's on our website. You have an email. It was decided to be presented at the January full committee along with the 2019 audit because we're wrapping up that audit as well. So we thought it would be more efficient to combine those two and report it in the full committee. Correct. January 24th, full committee. Yes. And,
▶ Play Suggest a correction Report an error
Speaker 294 1:25:31
Representative Mayberry, we've done the exit for the 2018. If you'd like to visit, we can visit about some of the findings in there after
▶ Play Suggest a correction Report an error
Speaker 86 1:25:42
you review it. Just let me know. Anyone else on the committee? We need to move along.
▶ Play Suggest a correction Report an error
Michael White Unverified 1:25:48
Sounds good. Thank you. All right. you're taking a motion to file motion made and second all those in favor say aye opposed motion carried
▶ Play Suggest a correction Report an error
Speaker 300 1:26:07
okay mr newt the remaining
▶ Play Suggest a correction Report an error
Speaker 8 1:26:10
reports had no findings and that's arkansas tech university the UAMS, Dollar Way School District, the Excel Center, which is an open enrollment charter school, and the Wynn School District. The only thing concerning those is the Dollar Way School District. It is the guidelines to invite the superintendent for physical distress districts. And I'm sorry. Okay. Miss Barbara Warren, she called me earlier and she too is at the State Board of Education meeting. But the chief financial officer is here. Again, they do not have any findings. It would just be up to the committee whether to go ahead and file this report or defer it, unless you have any questions for the chief physical officer. This committee,
▶ Play Suggest a correction Report an error
Michael White Unverified 1:27:09
what's the committee's? Motion. All right. I have a motion to file and second. All those in favor say aye. Aye. Opposed? Motion carried. And One more
▶ Play Suggest a correction Report an error
Speaker 302 1:27:27
item. That's all the reports, new business.
▶ Play Suggest a correction Report an error
Speaker 8 1:27:30
Okay. Mr. Newt. We just have one item for the new business. Arkansas Code requires school districts classified as being in fiscal distress at June 30th of any year that the respective audit report be completed and filed with the committee within six months, which is December 31st. We had five fiscal distress districts at June 30th. Dollar Way and Pine Bluff, Pine Bluff was deferred, but we presented them here today. Lee County, Earl, and Marvel are also on that distress list, and staff requests that, which is allowed by law, for the committee to extend that to additional 90 days to file those audit reports it was just additional time was required to complete those reports so staff just request an extension for those audit reports okay any other comments from the committee pardon me um miss
▶ Play Suggest a correction Report an error
Michael White Unverified 1:28:28
mayberry you're recognized yes we need a motion
▶ Play Suggest a correction Report an error
Speaker 303 1:28:43
to approve a motion motion oh okay
▶ Play Suggest a correction Report an error
Speaker 304 1:28:48
it's getting a little bit late
▶ Play Suggest a correction Report an error
Michael White Unverified 1:28:52
in here uh motion to approve the second all those in favor say aye motion carried I didn't finish that
▶ Play Suggest a correction Report an error
Representative Stan Berry Chair Unverified 1:29:09
all those yeah I did okay any further comments if not
▶ Play Suggest a correction Report an error
Speaker 253 1:29:15
I think all those identity thefts drained us so
▶ Play Suggest a correction Report an error
Michael White Unverified 1:29:18
we're ready if no other comments from the committee this meeting is adjourned Thank you.
▶ Play Suggest a correction Report an error

Agenda

A. Call to order by Co-Chairman.

-9:04

B. Adoption of Minutes of the November 7, 2019 meeting.

C. Review of Reports. Refer to the Synopsis

D. New Business.

E. Adjournment.

1:29:43

Speakers

Representative Stan Berry Chair Unverified
32 segments
Senator Mathew Pitsch Unverified
30 segments
Michael White Unverified
32 segments
Speaker 8
35 segments
Speaker 24
19 segments
Speaker 26
1 segment
Representative Stu Smith Unverified
5 segments
Senator Kim Hammer Unverified
7 segments
Speaker 53
1 segment
Laura Cheek Unverified
1 segment
Speaker 60
1 segment
Speaker 74
7 segments
Speaker 75
3 segments
Senator Eddie Cheatham Unverified
6 segments
Speaker 84
1 segment
Alex Becker Unverified
1 segment
Speaker 90
4 segments
Speaker 91
1 segment
Representative Julie Mayberry Unverified
9 segments
Speaker 103
8 segments
Speaker 107
1 segment
Representative Jack Fortner Unverified
2 segments
Speaker 111
1 segment
Don Bobbitt Unverified
8 segments
Speaker 114
1 segment
Speaker 117
2 segments
Speaker 118
3 segments
Speaker 119
3 segments
Senator Alan Clark Unverified
12 segments
Speaker 136
4 segments
Speaker 139
13 segments
Speaker 140
3 segments
Speaker 146
2 segments
Senator Ricky Hill Unverified
3 segments
Speaker 174
1 segment
Speaker 177
1 segment
Speaker 178
1 segment
Speaker 179
5 segments
Speaker 61
1 segment
Senator Linda Chesterfield Unverified
7 segments
Speaker 188
7 segments
Representative Vivian Flowers Unverified
19 segments
Speaker 218
4 segments
Speaker 222
3 segments
Speaker 224
1 segment
Speaker 225
1 segment
Speaker 226
1 segment
Speaker 165
1 segment
Speaker 220
1 segment
Speaker 223
1 segment
Speaker 231
1 segment
Speaker 235
1 segment
Speaker 241
1 segment
Speaker 25
1 segment
Speaker 12
2 segments
Speaker 253
2 segments
Speaker 254
1 segment
Speaker 258
9 segments
Speaker 260
1 segment
Speaker 259
2 segments
Speaker 267
1 segment
Speaker 269
1 segment
Speaker 281
1 segment
Speaker 282
1 segment
Speaker 287
1 segment
Speaker 294
9 segments
Speaker 250
2 segments
Speaker 297
1 segment
Speaker 86
1 segment
Speaker 300
1 segment
Speaker 302
1 segment
Speaker 303
1 segment
Speaker 304
1 segment