US2016300058A1PendingUtilityA1

System and method for automated data breach compliance

Assignee: CSR PROFESSIONAL SERVICES INCPriority: Mar 30, 2012Filed: Jun 21, 2016Published: Oct 13, 2016
Est. expiryMar 30, 2032(~5.7 yrs left)· nominal 20-yr term from priority
G06Q 90/00G06F 21/55G06F 2221/034G06Q 50/26G06Q 30/018G06F 21/554G06F 21/6245
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computer-implemented methods and systems for data breach compliance are disclosed. Organization related information may be received. Breach information relating to a data breach event of the organization may be received. The breach information may include, for example, breach event description information, compromised personally identifiable information, and remediation action information. A breach report may be generated based on the breach information, the organization related information, and one or more rules related to data breach. At least one reporting entity may be determined based on the organization related information, the breach information, and the one or more rules. The breach report may be output.

Claims

exact text as granted — not AI-modified
1 - 19 . (canceled) 
     
     
         20 . A computer-implemented system for data breach compliance comprising:
 a processor; and   a memory in communication with the processor;   said system configured to:
 receive information related to an organization; 
 receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information; 
 generate a breach report based on the breach information, the organization related information, and one or more rules related to data breach; 
 determine, based on a comparison of the organization related information, the breach information, and one or more of the following: state rules, federal rules, international rules, industry standards, and rules applicable to the breach event, whether the breach report is in the proper format; and 
 select a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; and 
 output the breach report to the one or more reporting entities. 
   
     
     
         21 . The computer implemented system of  claim 20 , wherein the system is further configured to modify the breach report, if it is determined that the proper format is an entity specific format, to include predetermined data entry fields. 
     
     
         22 . The computer implemented system of  claim 20 , wherein the system is further configured to output, if the breach information indicates the breach is related to the United States, the breach report to a United States agency. 
     
     
         23 . The computer implemented system of  claim 20 , wherein the system is further configured to output the breach report to a reviewing entity. 
     
     
         24 . A computer-implemented system for data breach compliance by an organization comprising:
 a memory; and   said the system operable to:   receive organization related information relating to the organization;   receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personal identification information, and remediation action information;   generate a breach report based on the breach information, the organization related information, and one or more compliance rules related to data breach;   determine at least one report receiving entity based on the organization related information, the breach information, and the one or more compliance rules; and   output the breach report to the report receiving entity.   
     
     
         25 . A computer-implemented system of  claim 24 , wherein to determine at least one report receiving entity the system is to:
 determine at least one geographic location associated with the data breach event based on the organization related information, the breach information, and the one or more compliance rules; and   select the at least one report receiving entity based on the one or more geographic locations.   
     
     
         26 . A computer-implemented system of  claim 24 , wherein to determine at least one report receiving entity the system is to:
 determine one or more types of breached data based on the compromised personal identification information; and   select the at least one report receiving entity based on the one or more types of breached data.   
     
     
         27 . A computer-implemented system of  claim 24 , wherein to generate a breach report the system is to:
 generate the breach report based on the breach information, the organization related information, and the one or more compliance rules;   output the breach report;   receive modified organization related information and modified breach information; and   update the breach report based on the modified organization related information and modified breach information.   
     
     
         28 . A computer-implemented system of  claim 24 , wherein to generate a breach report the system is to:
 determine at least one geographic location associated with the data breach event based on the organization related information, the breach information, and the one or more compliance rules; and   generate the breach report based on the at least one geographic location, the organization related information, the breach information, and the one or more compliance rules.   
     
     
         29 . A computer-implemented system of  claim 24 , further operable to update a database to include the organization related information, the breach information, and the breach report. 
     
     
         30 . A method for data breach compliance by an organization, implemented using at least one computing device, comprising:
 receiving, at the at least one computing device organization related information relating to the organization;   receiving, at the at least one computing device, breach information relating to a data breach event of the organization at the at least one computing device, the breach information including breach event description information, compromised personal identification information, and remediation action information;   determining, using the at least one computing device, based on the breach information, the organization related information, and one or more compliance rules related to data breach, whether to generate a breach report;   if the breach report is to be generated according to the determining step, generating the breach report having contents, the contents determined by the at least one computing device based on the breach information, the organization related information, and the one or more compliance rules;   determining, using the at least one computing device, at least one report receiving entity based on the organization related information, the breach information, and the one or more compliance rules; and   outputting the breach report.

Join the waitlist — get patent alerts

Track US2016300058A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.