System and method for automated data breach compliance
Abstract
Computer-implemented methods and systems for data breach compliance are disclosed. Organization related information may be received. Breach information relating to a data breach event of the organization may be received. The breach information may include, for example, breach event description information, compromised personally identifiable information, and remediation action information. A breach report may be generated based on the breach information, the organization related information, and one or more rules related to data breach. At least one reporting entity may be determined based on the organization related information, the breach information, and the one or more rules. The breach report may be output.
Claims
exact text as granted — not AI-modified1 - 19 . (canceled)
20 . A computer-implemented system for data breach compliance comprising:
a processor; and a memory in communication with the processor; said system configured to:
receive information related to an organization;
receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information;
generate a breach report based on the breach information, the organization related information, and one or more rules related to data breach;
determine, based on a comparison of the organization related information, the breach information, and one or more of the following: state rules, federal rules, international rules, industry standards, and rules applicable to the breach event, whether the breach report is in the proper format; and
select a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; and
output the breach report to the one or more reporting entities.
21 . The computer implemented system of claim 20 , wherein the system is further configured to modify the breach report, if it is determined that the proper format is an entity specific format, to include predetermined data entry fields.
22 . The computer implemented system of claim 20 , wherein the system is further configured to output, if the breach information indicates the breach is related to the United States, the breach report to a United States agency.
23 . The computer implemented system of claim 20 , wherein the system is further configured to output the breach report to a reviewing entity.
24 . A computer-implemented system for data breach compliance by an organization comprising:
a memory; and said the system operable to: receive organization related information relating to the organization; receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personal identification information, and remediation action information; generate a breach report based on the breach information, the organization related information, and one or more compliance rules related to data breach; determine at least one report receiving entity based on the organization related information, the breach information, and the one or more compliance rules; and output the breach report to the report receiving entity.
25 . A computer-implemented system of claim 24 , wherein to determine at least one report receiving entity the system is to:
determine at least one geographic location associated with the data breach event based on the organization related information, the breach information, and the one or more compliance rules; and select the at least one report receiving entity based on the one or more geographic locations.
26 . A computer-implemented system of claim 24 , wherein to determine at least one report receiving entity the system is to:
determine one or more types of breached data based on the compromised personal identification information; and select the at least one report receiving entity based on the one or more types of breached data.
27 . A computer-implemented system of claim 24 , wherein to generate a breach report the system is to:
generate the breach report based on the breach information, the organization related information, and the one or more compliance rules; output the breach report; receive modified organization related information and modified breach information; and update the breach report based on the modified organization related information and modified breach information.
28 . A computer-implemented system of claim 24 , wherein to generate a breach report the system is to:
determine at least one geographic location associated with the data breach event based on the organization related information, the breach information, and the one or more compliance rules; and generate the breach report based on the at least one geographic location, the organization related information, the breach information, and the one or more compliance rules.
29 . A computer-implemented system of claim 24 , further operable to update a database to include the organization related information, the breach information, and the breach report.
30 . A method for data breach compliance by an organization, implemented using at least one computing device, comprising:
receiving, at the at least one computing device organization related information relating to the organization; receiving, at the at least one computing device, breach information relating to a data breach event of the organization at the at least one computing device, the breach information including breach event description information, compromised personal identification information, and remediation action information; determining, using the at least one computing device, based on the breach information, the organization related information, and one or more compliance rules related to data breach, whether to generate a breach report; if the breach report is to be generated according to the determining step, generating the breach report having contents, the contents determined by the at least one computing device based on the breach information, the organization related information, and the one or more compliance rules; determining, using the at least one computing device, at least one report receiving entity based on the organization related information, the breach information, and the one or more compliance rules; and outputting the breach report.Join the waitlist — get patent alerts
Track US2016300058A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.