• Increase font size
  • Default font size
  • Decrease font size
Apogee Consulting Inc

Apogee Update

E-mail Print PDF

To our loyal readers,


As we mentioned in passing a couple of weeks ago, we have been extraordinarily busy.  That's a good thing!  Unfortunately, it also means that some things have to be moved to the back-burner.  After all, there are only so many hours in one day!  So our blog posts have dwindled in frequency and, over the past couple of weeks, have died altogether.  Rest assured, this is a short-term phenomenon. 


We've received several emails inquiring about the blog articles.  Thanks for your interest!  We promise be back with new blog articles before Thanksgiving.
Until then, we ask for your patience.


Sincerely,


Nick SandersPrincipal Consultant

Apogee Consulting, Inc.

 

SAIC Back in the News, Not in a Good Way

E-mail Print PDF
In past articles, we’ve noted that SAIC has had a few compliance challenges.  For example, in this article we wrote about allegations of bid rigging, and in this article we wrote about allegations of subcontractor kick-backs and timekeeping “irregularities” by an SAIC project manager.  In the latter article, we wondered aloud whether SAIC’s “notoriously decentralized and entrepreneurial” corporate culture may have contributed to the alleged issues caused by its rogue employees. Now comes another recent story involving yet another rogue SAIC employee.  This time it may end up costing the company millions of dollars.

When this story first came to our attention, we frankly didn’t think too much about it.  Apparently, in September 2011, an SAIC employee had his car broken-into in San Antonio, Texas.  His laptop was stolen.  The laptop contained personal information (including healthcare information) of millions of military service members enrolled in the DOD’s TRICARE program.  TRICARE itself downplayed the risk, stating—

‘The risk of harm to patients is judged to be low despite the data elements involved since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure.’

Ho hum.  Just another data theft story.  Or so we thought.But just a few weeks later, we ran across this story at NextGov.com.  It reminded us that SAIC may be facing some rather large financial repercussions related to the data theft.  The story reported—

Austin Camacho, a TRICARE Management Activity spokesman, said in a statement emailed to Nextgov that SAIC is ‘contractually bound to mitigate the harmful effects of such disclosure. …’

Readers, reportedly 4.9 million people were affected by the data theft. According to the TRICARE spokesperson, SAIC is contractually bound to mitigate the damages suffered by those 4.9 million people, including  the generation of 4.9 million individual data breach notifications and the operation of call centers to address the questions and concerns of those affected.  According to the NextGov article— 

Larry Ponemon, chairman of Ponemon Institute, a research organization that specializes in privacy and data protection, estimated mail notification could run as high $7 per person, which means SAIC could face a bill of $34.7 million to notify all 4.9 million TRICARE beneficiaries.

But that’s not all.  In addition to the $34.7 million cost of notifying the affected people, SAIC may also be liable under statute for the data breach.  The NextGov story reports—

The 2009 Health Information Technology for Economic and Clinical Health Act, enacted as part of the 2009 American Recovery and Reinvestment Act, specifies fines as high as $1.5 million for what it calls a breach of health care data.

Camacho said, ‘The Department of Health and Human Services has the discretion to investigate the conduct of both the TRICARE Management Activity and SAIC and assuming it does so will ultimately make the determination as to whether and against whom it seeks to levy any penalties.’

So this rogue employee may end up costing SAIC at least $36 million.  But that’s not all.Just a few days later, the Department of Defense was served with a $4.9 billion class action lawsuit related to the data breach.  According to NextGov (link in previous sentence)—

The suit … seeks $1,000 in damages for all 4.9 million TRICARE beneficiaries whose records were on the computer tape stolen Sept. 13 from the SAIC employee's car in San Antonio. TRICARE and Defense Secretary Leon Panetta are named as defendants. …

The suit …charges that TRICARE ‘flagrantly disregarded’ the privacy rights of TRICARE beneficiaries by failing to take the necessary precautions to protect their identity. The complaint said data on the stolen computer tape was ‘unprotected, easily copied . . . [and TRICARE] inexplicably failed to encrypt the information.’

TRICARE ‘compounded its dereliction of duty by authorizing an untrained or improperly trained individual to take the highly confidential information off of government premises and to leave unencrypted information in an unguarded car in a public location, from which it was stolen by an unknown party or parties,’ the suit alleged.

The ‘intentional, willful and reckless disregard of plaintiffs' privacy rights caused one of the largest unauthorized disclosures of Social Security numbers, medical records and other private information in recent history,’ the complaint charged.

But that’s not all.  Just a few days later, SAIC was itself served with a similar lawsuit, also seeking $4.9 billion in damages plus free credit monitoring.

But that’s not all.  On November 7, 2011, NextGov reported that—

The TRICARE Management Activity on Friday directed Science Applications International Corp. to provide credit monitoring services for up to 4.9 million beneficiaries whose health information was stored on backup computer tapes stolen from an SAIC employee's car in San Antonio. …  [TRICARE] directed SAIC provide one year of credit monitoring to patients who want it. SAIC will also analyze all available data to help TMA determine if identity theft occurs due to the data breach …

Providing credit monitoring services is not cheap.  According to NextGov—

This could hit SAIC with a hefty bill if all 4.9 million beneficiaries whose data was on the stolen tapes ask for credit monitoring. When the Veterans Affairs Department experiences a loss, theft or exposure of this kind, it routinely offers credit monitoring services and up to $1 million annually in identity theft protection at a cost per veteran of $29.95 a year. If SAIC provided such monitoring and protection at the same rate, it would cost $146.8 million to cover 4.9 million people.

So, let’s see now.  We were at about $36 million or so.  Plus $4.9 billion in potential legal damages.  Plus $147 million in credit monitoring services. Hey SAIC, might want to rein in those rogue employees of yours.  You know, the ones who can’t be bothered to encrypt their laptop hard drives?  
 

Boeing’s Innovative Plan to Reduce Medical Plan Costs Shot-Down by FBI

E-mail Print PDF
Drug_Bust

On September 28, 2011, the FBI stopped Boeing’s unique and innovative attempt to reduce out-of-control medical plan costs. See the news story here.

According to the story, FBI agents raided Boeing’s Ridley Park, Pennsylvania facility and arrested “approximately three dozen people” on charges of running a “prescription drug ring” at the facility. The story reported that, “the accused are a variety of workers, from line workers at the plant to office personnel, along with former employees and outside folks.” Another story, on Reuters, reported that, “23 people were charged with selling the prescription painkiller Oxycontin and other illegal drugs and 14 were charged with attempted possession of various drugs for trying to buy them.”

Boeing produces helicopters at the plant, including both the Chinook and parts of the V-22 Osprey. Roughly 6,000 are employed at the facility. There is no indication that any military hardware was compromised by the druggies at the site.

Boeing, of course, is now going to face some difficult questions, including:

  • How effective is its plant security at the facility?
  • How does the facility ensure compliance with the Drug-Free Workplace Act of 1988, which requires (among other things) that the company make a “good-faith effort to maintain a drug-free workplace”?
  • Where did the employees charge their time when engaging in the (alleged) illegal activities?

The bottom-line is that the company is going to have to divert resources from other activities to address the foregoing questions. This is going to be a problem for some time to come.

  

 

DCMA Issues Guidance on Disapproving Contractor Business Systems

E-mail Print PDF

On September 21, 2011, DCMA issued policy guidance to Contracting Officers addressing the process for making final determinations regarding Contractor Business Systems.  As readers should be aware, in May 2011 the DAR Council published an interim rule on Contractor Business Systems, defining six (6) Business Systems and establishing a process for those systems to be reviewed, for “significant deficiencies” to be reported to a DCMA Contracting Officer, and for that Contracting Officer to make a determination that the Business System in question is either “adequate” or “inadequate”.  If the Business System is determined to be inadequate, then the new rule requires a mandatory payment withhold on covered contracts (ranging from five to ten percent of total contract costs).

Industry bitterly fought the proposed rule but, ultimately, lost the battle and the new oversight/enforcement regime was established.  (Even Apogee Consulting, Inc. submitted comments to the DAR Council.)  One of the biggest concerns expressed by those opposed to the rule was in regard to the process, which seemed ill-defined and prone to subjectivity and inconsistency.  The DCMA policy established by the memo goes a long way to address those concerns.

The policy memo establishes a Contractor Business Systems Review Panel for the purpose of performing “a higher-level review of the COs final determination to disapprove a Contractor’s Business System, prior to notifying the Contractor in writing that the system is disapproved.”  The memo states that the Panel will “fully evaluate and discuss” all significant deficiencies identified by DCAA, and will ensure “consistent application of the Business System criteria and policy requirements.”

According to the policy memo, the process is as follows—
  1.  When a CACO/DACO/ACO network exists, the CO responsible for making the final determination must obtain concurrence from all network COs prior to notifying the Contractor of the final (negative) determination.
  2.  All final determinations must be approved by the CMO Contracts Director or the Director of the Pricing Center prior to issuance to the Contractor.
  3.  Prior to notifying the Contractor, the cognizant CO must submit a review package to the Business System Review Panel.  The package must include (a) a copy of the audit report, (b) the Contractor’s response to that audit report, and (c) a proposed final determination written notice.
  4. The intent is to convene the Panel within three days to review the CO’s determination.
Importantly, the Panel’s recommendations and opinions “are advisory” (“for most cases”) but “shall be considered” by the CO prior to disapproving a Contractor’s Business System.

We have gone on record as disapproving—quite stridently—of the DCMA’s recent predilection for convening Review Boards.  We think that such Boards undercut the FAR-mandated discretion of Contracting Officers, intimidate personnel and stop them from disagreeing with DCAA audit findings, and (in general) unreasonably slow down the procurement system.  That being said, we think this particular Review Board is a good interim step to ensuring an equitable application of an inequitable rule.

In the long run, however, we think the better approach is to properly train Contracting Officers, reinforce their discretion and authority, and then hold them accountable for their decisions.
 

Little Things Lead to Big Changes for DCAA

E-mail Print PDF

In chaos theory, it’s known as sensitive dependence on initial conditions, or, more popularly, as “the butterfly effect.” Basically, it stands for the theory that a hurricane can be caused by the flapping of a butterfly’s wings a thousand miles away, several weeks before. Looking at a recent DOD Inspector General audit report on the investigation of a hotline report made by a DCAA auditor, we might be able to discern that same effect in action.

We’re talking about DOD IG audit report number D-2011-6-011, entitled, “Report on Hotline Allegation Regarding Lack of Agency Guidance on the Currency of Audit Testing at the Defense Contract Audit Agency,” dated September 21, 2011. You can find a copy of the DOD IG’s report here.

An unnamed DCAA auditor in the Eastern Region began evaluating Northrop Grumman Navel Shipyard’s Earned Value Management System (EVMS) in December, 2008. The auditor’s 90-page audit report had 17 findings. To support his conclusions, the auditor reviewed Contract Performance Reports (CPRs) dated September 21, 2008 “that were available at the time the audit started,” according to the DOD IG report. The audit was completed in August, 2009, and the report was then submitted for supervisory review, which was completed in November, 2009. The report was then forwarded to the Easter Region’s Technical Programs Division, for review by a Technical Specialist.

And that’s when the trouble started.

According to the DOD IG report—

On November 9, 2009, the Eastern Regional Technical Programs Specialist telephoned the supervisory auditor and told him that she would like the auditor to perform ‘current’” testing on more recent Contract Performance Reports. The auditor stated that he selected the most current Contract Performance Reports available at the start of the audit. At that time, no written guidance or policy related to a 6-, 9-, or 12-month testing policy existed. However, the data tested was no longer current by the time the audit was completed. To be sufficient and current, evidence supporting the audit opinion should be reasonably current as of the date of the audit report.

The Eastern Regional Technical Programs Specialist was concerned with the ‘age’ of the Contract Performance Reports and related transaction testing performed by the auditor. [Which, by the time of the review, were more than a year old.] … the specialist stated that it is the Eastern Regional Director’s position based upon discussions held in DCAA Executive Steering Committee meetings that the data tested should be within a six- to nine-month period prior to the issuance of the audit report.

On November 17, 2009, a Program Manager from Headquarters … said that the testing should be updated if it is more than 12 months old. On November 18, 2009, the Eastern Regional Director decided that the testing should be updated for transactions that were tested and are older than nine months. … the Eastern Regional Director directed the auditor to perform additional testing and determine if the original deficiencies were still at issue. Subsequently the Regional Audit Manager advised the Resident Auditor that the opinion stated in the audit report cannot be based on testing performed on contractor Contract Performance Report data from September 2008.

So, in essence, the fact that the audit took more than nine months to complete meant that the evidence used to support the auditor’s conclusions was too dated and no longer acceptable. The auditor was told to get back into the field and continue testing. Those of us who have experienced audits lasting two or more years might look at this direction and think, “Isn’t this just creating a perpetual audit environment where audits never end because the supporting data becomes stale before management signs-off?”

Yes. Yes, it is.

And that’s what the DCAA auditor alleged when he called the DOD IG hotline and reported his management. As the GAO audit report stated—

The complainant alleged that DCAA lacks any written guidance or agency-wide policy regarding the ‘currency’ of audit testing which is causing audit reports on contractor business system reviews to be delayed as a result of retesting.

The DOD IG substantiated the auditor’s allegation that DCAA lacked agency-wide guidance, which contributed to auditor uncertainty regarding when evidentiary data was too old   The IG recommended that DCAA develop such guidance. However, the IG also agreed that, in this instance, the data was too old and that the auditor was properly directed to perform additional testing.

As the IG stated in its report—

The auditor should have tested a representative selection of transactions across the year and not just transactions from reports issued on just one day. We observed that for very large projects such as this, the data tested will never be current unless such audits are scoped and resourced adequately. This particular audit only had two auditors assigned. Cost Performance Reports are submitted monthly for the nuclear aircraft carrier and are submitted quarterly for the nuclear submarine. The data tested by the auditor was not current and did not consist of sufficient appropriate evidence to provide a reasonable basis for the audit conclusion.

The IG stated that the rule that should have been applied to the situation to be as follows—

GAGAS 6.04b requires the auditor to obtain sufficient and appropriate evidence to provide a reasonable basis for the conclusion that is expressed in the report. The evidence provided in the report is more helpful if it is current.

The IG noted that prior GAO reports had criticized DCAA for GAGAS violations. The IG recommended that DCAA implement policy guidance to address the gap and ensure GAGAS compliance. The IG audit report included the following statement—

We recommend that DCAA Headquarters develop written agency-wide policy and guidance on the need to test current data to support opinions on the contractor’s internal controls and business systems. The policy and guidance should include criteria when the auditor should expand testing and perform additional work.

On behalf of DCAA, Patrick Fitzgerald concurred with the IG’s recommendation. The DOD IG report stated that DCAA committed to undertake the following steps—

By November 2011, DCAA will issue guidance, which will include the requirement for auditors to (i) perform sufficient testing of data that is relevant to the audit objectives, including the period or point in time covered by the report, (ii) perform testing of data generated by the system throughout the period under audit, and (iii) issue timely audit reports. For audits of contractor business systems, DCAA will perform compliance attestation engagements and report on the contractor’s compliance during a period of time or as of a point in time, consistent with the applicable attestation reporting standards (AT 601.55b) in AICPA’s Statements on Standards for Attestation Engagements. Circumstances where auditors would need to expand testing to obtain sufficient evidence for the conclusions expressed in the report should be limited since the transactions being evaluated in the audit will coincide with the defined period covered by the audit. DCAA agrees with the guidance in GAGAS A8.02g, that the evidence provided in the report is more helpful if it is current and, therefore, timely issuance of the report is an important reporting goal for auditors.

Importantly, the above paragraph states that DCAA plans to issue guidance in the very near future that will provide a policy statement regarding the issuance of timely audit reports. Obviously, that’s the first step to addressing the concern about “perpetual audits”. For our part, we applaud any actions taken by DCAA to get audit reports out quicker than the current system permits.

So to our readers, keep an eye out for the promised November 2011 Memorandum for Regional Directors (MRD) implementing the promised policy guidance. We think it will be quite important.

And also notice how a single phone call to the DOD IG hotline by a concerned auditor led to potentially big changes at the DCAA. That’s the butterfly effect in action.

 


Page 197 of 278

Newsflash

Effective January 1, 2019, Nick Sanders has been named as Editor of two reference books published by LexisNexis. The first book is Matthew Bender’s Accounting for Government Contracts: The Federal Acquisition Regulation. The second book is Matthew Bender’s Accounting for Government Contracts: The Cost Accounting Standards. Nick replaces Darrell Oyer, who has edited those books for many years.