US2016300241A1PendingUtilityA1

System and method for automated data breach compliance

Assignee: CSR PROFESSIONAL SERVICES INCPriority: Mar 30, 2012Filed: Jun 20, 2016Published: Oct 13, 2016
Est. expiryMar 30, 2032(~5.7 yrs left)· nominal 20-yr term from priority
G06Q 90/00G06F 21/6245G06Q 30/018G06F 21/55G06Q 50/26G06F 21/554G06F 2221/034
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computer-implemented methods and systems for data breach compliance are disclosed. Organization related information may be received. Breach information relating to a data breach event of the organization may be received. The breach information may include, for example, breach event description information, compromised personally identifiable information, and remediation action information. A breach report may be generated based on the breach information, the organization related information, and one or more rules related to data breach. At least one reporting entity may be determined based on the organization related information, the breach information, and the one or more rules. The breach report may be output.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 - 19 . (canceled) 
     
     
         20 . A computer-implemented system for data breach compliance comprising:
 a processor; and   a memory in communication with the processor;   said system configured to:
 receive information related to an organization; 
 receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information; 
 generate a breach report based on the breach information, the organization related information, and one or more rules related to data breach; 
 select one or more reporting entities based on one or more types of breached data, where the one or more types of breached data are determined based on the compromised PII, wherein the system is configured to:
 select, if the breached data includes health care related information, at least one reporting entity associated with health care, 
 select, if the breached data includes credit card related information, at least one credit card related entity, and 
 
 select a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; and 
 output the breach report to the one or more reporting entities. 
   
     
     
         21 . The computer implemented system of  claim 20 , wherein the system is further configured to output, if the breach information indicates the breach is related to the United States, the breach report to a United States agency. 
     
     
         22 . The computer implemented system of  claim 20 , wherein the system is further configured to output the breach report to a reviewing entity.

Join the waitlist — get patent alerts

Track US2016300241A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.