Audit & Advisory Services Newsletter - Volume 28

Tricks, Treats & Risks Lurking in the Shadows 
Halloween may be the season for costumes, tricks and things that go bump in the night—but at UCSF, risks are no tricks. In this edition of Audit Insights, we shine a light on risks hiding in plain sight, from workplace safety and medical identity theft to fraud, emerging technology and real-world control failures. Our goal isn't to scare you, but to help you recognize warning signs, understand why controls matter and know what to do when something doesn't look right. The best way to keep risk from haunting UCSF is to shine a light on it. 
 

"Fears are educated into us, and if we wish, we can educate them out.” 
Karl Augustus Menninger

A Halloween Message from the New Interim Chief Audit Officer, Eric Groen   

It is a privilege to join UCSF as Interim Chief Audit Officer and become part of a community whose mission has such a profound impact on patients, students, researchers, faculty, staff and the communities we serve. I am excited to learn from the people who make UCSF exceptional and work alongside you in support of excellence, innovation, integrity, and public service.

Throughout my 25-plus-year career as an auditor, I have viewed internal Audit as more than an assurance function. At its best, audit is a trusted advisor that helps organizations identify opportunities, strengthen operations, manage risk and achieve strategic objectives. My goal is to build a strong foundation within Audit & Advisory Services (A&AS) through open communication, collaboration, and continuous improvement.

Over the coming months, I will meet with leaders, faculty, staff, and teams across the campus and health system to better understand your priorities, challenges, and opportunities. I believe effective auditing begins with listening, learning, and developing relationships built on trust and mutual respect.  I want A&AS to be a proactive partner that helps UCSF navigate complexity, strengthen accountability, and make informed decisions. Through assurance, advisory services, risk assessments, and consulting, our focus will remain on helping UCSF fulfill its mission while safeguarding the resources entrusted to us.

Thank you to the A&AS team and the UCSF community for the warm welcome. I look forward to meeting and working with you. In the meantime, enjoy this Halloween edition of Audit Insights. Change can sometimes be “scary”—but don’t let A&AS spook you! 

New Interim Chief Audit Executive, Eric Groen

#Back to the Top

Be Prepared, Not Scared: A Halloween Q&A with Environmental Health & Safety's Doug Dresnek 

Q: What’s the scariest safety hazard people don’t realize is dangerous?

A: Complacency. We tend to move through our day focused on where we’re going or what we’re doing next and sometimes forget to look at what’s right in front of us. Are the labels on the container correct? Am I wearing the right personal protective equipment? Is the engineering control functioning properly? Taking a couple of extra minutes to think critically about the work we do can go a long way toward preventing an adverse event.

Q: What’s an EH&S “ghost”—a risk that’s easy to overlook?

A: Risks associated with chronic or repeated exposures, like noise. Because the effects may take weeks, months or even years to appear, we may not recognize the immediate risk. We all need to be mindful of these “ghosts” when assessing our work and remember that not every hazard is something we can immediately see.

Q: What EH&S myth would you like to clear the cobwebs from?

A: There’s a tendency to think of EH&S as being just about compliance. We certainly have regulatory obligations, but our team is really here to help researchers and patient care providers do their jobs as safely as possible. We have tremendous knowledge and expertise across many disciplines, and we want to put those skills to work for our staff, students, and trainees. If we help people work safely, we’ll end up checking the compliance box anyway.

Q: If you could wave a magic wand and change one thing about our safety culture, what would it be?

A: Training. Understandably, most staff aren’t big fans of required training, but there’s a lot of useful information in those modules—especially supervisors, who need to understand the work their staff perform and the hazards involved. Required training shouldn’t be viewed as “just another regulatory box to check.” It’s an opportunity to refresh our knowledge about workplace hazards, how to prevent injuries or environmental impacts, and what to do when something doesn’t go as planned.

Q: What’s the strangest hazard that EH&S must be prepared for at a research university?

A: The nature of research means people are doing things that may not have been done before. That might involve new chemicals, biological materials, or equipment, and our team must be ready to help researchers navigate those processes safely. Fortunately, UCSF has a robust laboratory safety program with experts in chemical, biological, and radio-logical safety, so there aren’t too many things that surprise us.

Q: The title of our Q&A is Be Prepared Not Scared. What is your message about being prepared?

A: There’s a silly adage that pops up in EH&S circles, “Safety is no accident.” Despite the cringe worthy nature of a bad pun, there’s a lot of truth behind it. Taking the necessary steps to prepare before starting a new task goes a long way in preventing workplace injury. Preparation includes checking with your supervisor on the work you’ll be doing, taking the required training, reviewing the necessary SOPs, wearing the correct PPE, and ensuring equipment is functioning properly. All these controls help minimize something not going as planned. Of course, EH&S is an additional resource here to help the campus community make the necessary preparations to ensure a safe and healthy work environment.  

#Back to the Top

Medical Identity Theft: When a Disguise Is a Trick, Not a Treat 

Halloween is a time when pretending to be someone else is part of the fun—but assuming another person's identity to obtain medical care is a trick, not a treat. Medical identity theft occurs when someone uses another person's identity or insurance information to obtain medical services or make false claims. These tricks are frighteningly real: victims may receive bills for services not received or discover that someone else's emergency visits, diagnoses, medications or treatments are part of their medical record. UCSF's Identity Theft Prevention Detection and Response (TPDR) policy identifies unexplained bills, conflicting insurance information, suspicious documents and photo identification that does not match the person presenting for care as potential Red Flags. These incidents have cost UCSF thousands of dollars in lost revenue, including amounts repaid to insurers, while requiring substantial staff time to untangle the webs of billing and medical records.

Don't let a disguise fool you—careful patient identification (ID) is our best control. TPDR directs staff to ask for ID each time a patient presents (before services are rendered) unless medical necessity dictates otherwise. Two forms of ID are recommended, including photo ID. Controls continue after registration: The Patient ID policy requires verification of two patient IDs before clinical encounters, medications, specimens, treatments, surgery or procedures.  

Watch for Red Flags hiding in plain sight: a photo that does not resemble the patient, inconsistent names or dates of birth, altered documents, conflicting insurance information or information inconsistent with prior visits. Staff who suspect medical identity theft should notify their manager. When further investigation is necessary, the appropriate provider and UCPD may need to be involved; staff should not attempt to restrain the individual. A discrepancy should not automatically be labeled identity theft—TPDR first calls for determining whether mistaken billing or mislabeled medical records caused the problem. Confirmed identity theft may require several departments to repair affected records and billing. Most importantly, patient care comes first: when emergent or urgent care is needed, provide necessary care and address identity concerns later. 

#Back to the Top

Don’t Let Fraud Hide in the Shadows: Why Our Controls Matter

Fraud can hide in unexpected places, and the latest Association of Certified Fraud Examiners Report to the Nations provides several reasons to keep the lights on:

  • Corruption and Collusion (schemes involving multiple employees or employees and vendors) are on the rise.  
  • Fraudsters have moved up the organizational chart and have longer tenure resulting in increased losses to institutions. 

The lesson is that trust, tenure, and title should never be a magic wand that makes controls disappear. Controls aren't bureaucratic cobwebs—they exist for a reason. Two factors contributing to fraud are the overriding existing controls and inadequate management review. That's why employees need to follow established approval, reconciliation, purchasing and inventory controls—and why managers need to actually review control reports rather than simply “check a box.” The antidote works: management review was associated with 55% lower median losses and 44% faster detection. Proactive data monitoring was associated with 53% lower losses and 44% faster detection. Often fraudsters collude to get around controls designed to stop a lone werewolf.  This makes meaningful supervisory reviews especially important.

Tips remain the most common way fraud comes out of the shadows. Organizations with formal reporting experienced lower losses and faster detection and trained employees were more than twice as likely to submit a tip. So, when a control asks you to verify something, verify it. When a report identifies an exception, review it. When something doesn't look right, speak up. Controls aren't there because UCSF assumes people are dishonest; they're there because fraud thrives when controls are ignored, overridden or left in the dark. 

#Back to the Top

Seeing Ghosts, or Just Hallucinating

Halloween is the one time of year when people intentionally deceive you with elaborate costumes, leaving you to question what's real and what's just an impressive disguise. AI, on the other hand, has been tricking people all year long. “Hallucination” describes when generative AI produces information that is entirely made up but presents it confidently as though it were true. That leaves us with an important question: How do we separate fact from fiction and spot incorrect answers wearing convincing costumes? It's a risk that's easy to miss.

The legal profession is one of the industry's most visibly haunted by this phenomenon. In Fletcher v. Experian, a Fifth Circuit Court sanctioned an attorney after an AI-assisted brief contained fabricated quotations. The tools weren't general chatbots—they were professional AI platforms designed specifically for legal work. Yet hallucinations still slipped through. The control gap was the absence of sufficient independent review before the work went out. Specialized AI tools may reduce hallucination risk, but they don't eliminate the need for verification. They're just better at wearing masks!

This matters as AI-generated work carries a control gap until a human verifies it. As we incorporate AI into everyday work, more AI-generated content will flow through our processes, creating more opportunities for an unverified error to slip through. Depending on where it lands, a hallucinated statistic, fabricated source or incorrect assumption could have significant consequences. AI tools, including ChatGPT Enterprise, can dramatically improve productivity—but speed doesn't replace due diligence. The more we use AI, the more important it becomes to verify its output before relying on it or passing it along. 

#Back to the Top

Fraud in the News: Four Frightening Fraud Schemes 

1. Draining of Funds: A former Colorado University (CU) Assoc Athletics Director was arrested after an audit uncovered alleged theft of funds. For four years, the scheme drained money from the university's Nike Elite program for personal benefit. Following his disappearance, CU implemented stronger oversight and reporting over its equipment program.

Ghoulish Warning: Restricted and vendor-supported programs require independent monitoring and reconciliation. No single individual should control purchasing, and itemized receipts should be reviewed against independent inventory records.

2. A Grim Lesson in Non-Cash Assets: Harvard agreed to a $53 million settlement of class-action lawsuits following criminal conduct involving its Anatomical Gift Program. Its former manager spent years stealing and selling human remains from donated cadavers. An independent review identified serious failures in operational oversight.

Ghoulish Warning: Not every asset has a price tag. Departments should evaluate physical security and chain-of-custody controls over unique or sensitive assets, restrict access, and maintain records that identify who accessed them.

3. Phantom Invoices: A supervisor at Claremont College was sent to a federal dungeon after a six-year embezzlement scheme involving 1,343 in unauthorized transactions. He connected a university P-Card to a personal PayPal account and used fictitious invoices in their Workday ERP system to disguise purchases as ordinary supply transactions.

Ghoulish Warning: Don't let an intermediary make the ultimate recipient disappear. Controls should identify the actual beneficiary of payments, maintain segregation of duties and independently verify purchases and physical inventory.

4. The Ghost Business: A University of Iowa (UI) machine-shop supervisor pleaded guilty after using UI equipment, materials and employees to perform work for his private business, bleeding $1million in resources.

Ghoulish Warning: Controls must extend beyond the ledger. Periodically compare equipment use and material consumption with official billing records and maintain appropriate conflict-of-interest disclosures. 

#Back to the Top