Systems and methods for managing multifaceted data incidents
First Claim
1. A method for managing a data incident, comprising:
- receiving, via a risk assessment server, in response to an occurrence of a multifaceted data incident, data incident data that comprises information corresponding to the multifaceted data incident, the multifaceted data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment, wherein the multifaceted data incident has a plurality of facets with each facet comprising any of unique and overlapping set of privacy data, and media type, and associated risk factors requiring facet specific incident risk assessment;
automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the facet is reportable from a comparison of each of a plurality of privacy rules;
wherein the privacy rules define requirements associated with data incident notification obligations or a privacy related contractual obligation that comprise any of notification and mitigation obligations; and
providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server;
wherein;
the risk assessment comprises a determination as to whether a number of unique or non-unique but overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction;
one or more of the plurality of facets comprises a single or multiple regulatory regions associated with one or more of the privacy rules;
one or more of the plurality of facets is associated with a collection of privacy data determined by a regulatory agency in one or more regulatory regions;
receiving data incident data comprises;
providing one or more data incident risk factor questions to the display device that elicit information corresponding to each facet of the data incident;
receiving responses to the one or more data incident risk factor questions; and
providing the responses to the display device; and
receiving confirmation of at least a portion of the responses; and
further comprising providing an alert to the display device when the comparison indicates that one or more of the plurality of facets of the data incident violates and triggers a notification obligation according to the privacy rules, further wherein a notification schedule comprises notification dates that are based upon a violated one of the privacy rules, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.
5 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods for managing a multifaceted data incident are provided herein. Example methods include receiving, via a risk assessment server, in response to an occurrence of the data incident, data incident data that including information corresponding to the data incident, wherein the data incident has a plurality of facets with each facet having any of unique and overlapping set of privacy data and media type and associated risk factors requiring facet specific incident risk assessment, automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the facet is reportable, from a comparison of the facet to privacy rules, the privacy rules define requirements associated with data incident notification obligations, and providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server.
171 Citations
16 Claims
-
1. A method for managing a data incident, comprising:
-
receiving, via a risk assessment server, in response to an occurrence of a multifaceted data incident, data incident data that comprises information corresponding to the multifaceted data incident, the multifaceted data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment, wherein the multifaceted data incident has a plurality of facets with each facet comprising any of unique and overlapping set of privacy data, and media type, and associated risk factors requiring facet specific incident risk assessment; automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the facet is reportable from a comparison of each of a plurality of privacy rules; wherein the privacy rules define requirements associated with data incident notification obligations or a privacy related contractual obligation that comprise any of notification and mitigation obligations; and providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server; wherein; the risk assessment comprises a determination as to whether a number of unique or non-unique but overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction; one or more of the plurality of facets comprises a single or multiple regulatory regions associated with one or more of the privacy rules; one or more of the plurality of facets is associated with a collection of privacy data determined by a regulatory agency in one or more regulatory regions; receiving data incident data comprises; providing one or more data incident risk factor questions to the display device that elicit information corresponding to each facet of the data incident; receiving responses to the one or more data incident risk factor questions; and providing the responses to the display device; and receiving confirmation of at least a portion of the responses; and
further comprising providing an alert to the display device when the comparison indicates that one or more of the plurality of facets of the data incident violates and triggers a notification obligation according to the privacy rules, further wherein a notification schedule comprises notification dates that are based upon a violated one of the privacy rules, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A risk assessment server for managing a multifaceted data incident, the server comprising:
-
a memory for storing executable instructions; a processor for executing the instructions; an input module stored in memory and executable by the processor to; receive in response to an occurrence of the multifaceted data incident, data incident data, the data incident data comprising information corresponding to the multifaceted data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data, personally identifiable information, or protected health information to an untrusted or unauthorized environment, wherein the multifaceted data incident has a plurality of facets with each facet comprising any of unique set of privacy data, media type, and associated risk factors requiring facet specific incident risk assessment; a risk assessment generator stored in memory and executable by the processor to generate a risk assessment for each of the facets from a comparison of the data incident data to privacy rules; wherein the privacy rules define requirements associated with data incident notification laws or a privacy related contractual obligation that comprise any of notification and mitigation obligations; and a user interface module stored in memory and executable by the processor to provide the risk assessment to a display device that selectively couples with the risk assessment server; wherein; the risk assessment comprises a determination as to whether a number of unique or non-unique but overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction; one or more of the plurality of facets comprises a single or multiple regulatory regions associated with one or more of the privacy rules; one or more of the plurality of facets is associated with a collection of privacy data determined by a regulatory agency in one or more regulatory regions; receiving data incident data comprises; providing one or more data incident risk factor questions to the display device that elicit information corresponding to each facet of the data incident; receiving responses to the one or more data incident risk factor questions; and providing the responses to the display device; and receiving confirmation of at least a portion of the responses; and
further comprising providing an alert to the display device when the comparison indicates that one or more of the plurality of facets of the data incident violates and triggers a notification obligation according to the privacy rules, further wherein a notification schedule comprises notification dates that are based upon a violated one of the privacy rules, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident. - View Dependent Claims (15, 16)
-
Specification