There is certain information that is not supposed to be accessible to everyone per Department of Education regulations. The way things are set up now, you either have the ability to see financial data or not. There needs to be a way to divide out the financial aid information that should not be visible to other offices. Including financial services.
5 comments
-
Evan Donovan Hi Jennifer, could you clarify which specific data you are referring to? Does the distinction between Financial Admin and Financial Aid help?
I'm not aware of this issue myself, but since we may be reviewed by USDE for compliance again soon, I want to make sure that we are compliant.
The main regulation I am aware of that seems related is 34 CFR 668.16(c), but to the best of my knowledge, that is about the people who handle different administrative functions, not whether the data was viewable at all. I think that the main issue is that financial and financial aid staff are not supposed to be able to edit the data pertaining to the other role. -
Jennifer Settergren One of the key things I have notices is the accessibility of the EFC and the FAFSA info. Only financial aid staff should be able to view that data. Any verification materials should also be protected
-
Evan Donovan Yes, I would agree that those things should be limited to the Financial Aid role as per USDE regs.
I believe there are some legitimate use cases where schools could have people in multiple functional roles where they would need to see that info even though their primary role was not as a Financial Aid Administration - but in that case, they could just have multiple roles assigned in Populi.
The main thing, regulatorily, I think is that those bits of information are not to be used by the admissions department.
As to verification materials, Jennifer Settergren, is there a place to store those in Populi (other than Custom Fields)? I am not aware of one.
I think there may already be a separate feature request on here for more access control for Custom Fields. Is there a way to limit that now? -
Jennifer Settergren Agreed.
The admissions office should be able to see pending awards, but that would be the extent of what they would need.
The Show COD link should also be limited to FA staff.
Verification materials (tax returns, Proof of citizenship, and other materials are uploaded to the system's Activity Feed. If they are marked private, only the person who made the note can see them. If there are more people in the office and they are marked for the FA role, then anyone with the FA role can see them. This would be helpful for other activity notes as well.
The aid application itself also shows EFC and Income information.
Hope this helps.
-
Evan Donovan Thanks for the clarifications. I think these will be helpful for the Populi staff.
I don't think all schools upload verification docs to Populi. At our school we don't, because of confidentiality reasons.
if you do upload verification docs to the Activity Feed, though, it looks like you could probably be compliant simply by changing the visibility rules, and thus you would not need modifications to Populi for that part.
It seems like the edits might be needed especially on what can be seen by people in Admissions related to awards or aid applications.
I don't know exactly which roles can see these different things though - that would be for Populi to say.