System and method for automated data breach compliance
Abstract
Computer-implemented methods and systems for data breach compliance are disclosed. Organization related information may be received. Breach information relating to a data breach event of the organization may be received. The breach information may include, for example, breach event description information, compromised personally identifiable information, and remediation action information. A breach report may be generated based on the breach information, the organization related information, and one or more rules related to data breach. At least one reporting entity may be determined based on the organization related information, the breach information, and the one or more rules. The breach report may be output.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 - 19 . (canceled)
20 . A computer-implemented system for data breach compliance comprising:
a processor; and a memory in communication with the processor; said system configured to:
receive information related to an organization;
receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information;
generate a breach report based on the breach information, the organization related information, and one or more rules related to data breach;
select one or more reporting entities based on one or more types of breached data, where the one or more types of breached data are determined based on the compromised PII, wherein the system is configured to:
select, if the breached data includes health care related information, at least one reporting entity associated with health care,
select, if the breached data includes credit card related information, at least one credit card related entity, and
select a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; and
output the breach report to the one or more reporting entities.
21 . The computer implemented system of claim 20 , wherein the system is further configured to output, if the breach information indicates the breach is related to the United States, the breach report to a United States agency.
22 . The computer implemented system of claim 20 , wherein the system is further configured to output the breach report to a reviewing entity.Join the waitlist — get patent alerts
Track US2016300241A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.