Press Releases

Audit Report TI-22-13, Cardiovascular Center of Puerto Rico and the Caribbean Corporation – Information Technology Systems

June 28, 2022

The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information Technology Systems area of the Cardiovascular Center of Puerto Rico and the Caribbean. A qualified opinion is issued when the noncompliances, individually or together, are significant but not pervasive.

The Report reveals that the risk vulnerability analysis contracted for $14,950 in 2017 did not include an inventory of the information system assets – equipment, program, and data –, or the classification of these assets according to the level of importance for the continuity of operations. This situation prevented the Cardiovascular Center from estimating the impact that the risk elements would have on the critical data, equipment, and systems, in order to protect them and reduce the risks of damage.

The five-finding audit notes that the Contingency Plan revised as of May 26, 2021, did not include necessary information such as: the technological conditions of the Cardiovascular Center, the name of the person in charge of activating the Plan, or a restoration schedule, among others. In addition, it did not have an alternate center to restore its critical computerized operations in case of emergency.

The auditors identified that the safe box rented off the premises of the Cardiovascular Center did not have the tapes of nine monthly backups of the Optimum system for the year ended June 30, 2021. The annual backups for 2019 and 2020 were also not located in the box. These situations can cause the loss of information of the patient's electronic medical record without the possibility of being able to recover it.

Contrary to the regulations and procedures in force, the Center did not have defined the policies related to the password of the access accounts (password policy) or the account control policies (account lockout policy). In addition, the information technology supervisor did not periodically review the activity logs of security events to detect possible security violations and take corrective measures.

The audit recommends compliance with the guidelines related to the cancellation of access accounts assigned to former employees and having the documentation of the remote access authorizations. As of June 3, 2021, five accounts of four former employees and of a former member of the medical faculty remained active after their cessation of functions. In addition, 52% of the remote accesses did not have the supporting documents and 25% of the examined forms did not establish the expiration date of the remote access.

This report covers the period from February 26 to September 30, 2021.

See Audit Report TI-22-13.

To see other published reports, visit our section of Audit Reports.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®