13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS OperationsSecurity Profiles. All employees have a security profile, which documents their authorized physical andlogical access to systems, data, and facilities. This authorized access is based on what is necessary foremployees to perform their job responsibilities. At a minimum, management reviews and updates thesecurity profiles annually for every position that reports to them.As part of employees’ security profiles, minimum access profiles are defined for all job code and costcenter combinations. These minimum access profiles define the minimum access an employee in a jobcode and cost center needs to perform the requirements of the job. Minimum access profiles aremaintained by the systems security unit. Any access request not contained within a minimum accessprofile for a position is treated as an exception. These exceptions are reviewed and approved bymanagement prior to granting access.All changes to security profiles, including emergency and temporary access authorization, are madethrough the Remedy system. All requests to add additional access to an employee’s security profile mustbe approved by management and the resource owner, if appropriate. The Team Noridian systems securityunit makes any changes to security profiles. All actions are logged during updates, and any unusualactivity surrounding security profiles is investigated. The centralized administration of security profilesreduces risk of unauthorized changes to security profiles and access to secured information.7.9 AccountingRFP Section 5.9, Requirements a and bOur prime contractor, Noridian, brings sound accounting practices based on years of experiencemanaging health care contracts. Our processes are consistent with the Project Management Institute’s(PMI’s) Project Management Body of Knowledge (PMBOK,) and Generally Accepted AccountingPrinciples (GAAP), and internal and external audits have confirmed our adherence to those standards.Noridian’s primary business is to provide administrative and contracted services to government clients,including state and federal agencies. Noridian, as a matter of practice, adheres to the highest standards ofpractice for all its accounting practices, including GAAP and Federal Accounting Regulations (FAR).Noridian’s current portfolio of contracts includes performance experience under Fixed Price, Time andMaterial, and Cost Plus Incentive Fee types. As such the company must be and is extremely diligent in allaccounting practices, ensuring that all records accurately reflect all aspects of our financial performance.These records are maintained at the individual contract level and then rolled up at the top level for theentire company. Noridian's cost management processes are integrated with the project budget and themanagement of the contract (including acquisitions and invoicing) and time reporting (attendance andtimesheet tracking) processes. Noridian’s accounting system, Deltek, provides the methodology for theproper identification and accumulation of costs incurred for a contract using a project-based generalledger accounting system. As such, our DCAA-accepted accounting system will ensure the propercontrols required for the reporting and compliance for the MMIS and Core MMIS Operations contract.Under Noridian’s disclosed accounting practices, costs for projects are primarily comprised of labor(including applicable fringes), subcontractor costs, and other direct costs (materials, equipment, supplies,travel). The majority of the material costs that will be incurred are costs associated with hardware andsoftware. In addition to these costs, Noridian uses various operational overhead rates and a general andadministrative (G&A) rate to allocate indirect expenses to final cost objectives. These indirect rates areapplied to the contract automatically through the Deltek Costpoint project accounting system. Allamounts are ultimately reconciled back to the accounting system and Noridian financial statements.As we have done in our current IME contract, Noridian will continue to maintain accounting and financialrecords that properly document all of the costs and expenses of the contract, separately and independentlyof other Noridian’s accounting records. All hours expended are recorded daily in Deltek Time & Expenseand validated against attendance records. Managers review and approve employee time each pay period in7 | 51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!