US2017076093A1PendingUtilityA1

System and method for automated data breach compliance

Assignee: CSR PROFESSIONAL SERVICES INCPriority: Mar 30, 2012Filed: Nov 28, 2016Published: Mar 16, 2017
Est. expiryMar 30, 2032(~5.7 yrs left)· nominal 20-yr term from priority
G06Q 90/00G06Q 50/26G06F 21/6245G06F 2221/034G06Q 30/018G06F 21/554G06F 21/55
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computer-implemented methods and systems for data breach compliance are disclosed. Organization related information may be received. Breach information relating to a data breach event of the organization may be received. The breach information may include, for example, breach event description information, compromised personally identifiable information, and remediation action information. A breach report may be generated based on the breach information, the organization related information, and one or more rules related to data breach. At least one reporting entity may be determined based on the organization related information, the breach information, and the one or more rules. The breach report may be output.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for data breach compliance, comprising:
 receiving information related to an organization;   receiving breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information;   generating a breach report based on the breach information, the organization related information, and one or more rules related to data breach;   determining, based on a comparison of the organization related information, the breach information, and one or more of the following: state rules, federal rules, international rules, industry standards, and rules applicable to the breach event, whether the breach report is in the proper format;   modifying the breach report, if it is determined that the proper format is an entity specific format, to include predetermined data entry fields;   selecting one or more reporting entities based on one or more geographic locations associated with the data breach event, where the one or more geographical locations are determined based on the organization related information, the breach information, and the one or more rules, the selecting comprising the steps of:
 determining, if the one or more geographic locations are in the United States, any applicable attorney general reporting rules and applicable long reach rules associated with the one or more geographical locations, 
 selecting one or more reporting entities based on the applicable attorney general reporting rules and the applicable long reach rules, and 
 selecting, if the breach information indicates the breach is related to an international jurisdiction, one or more reporting entities based on rules associated with the international jurisdiction; 
   selecting one or more reporting entities based on one or more types of breached data, where the one or more types of breached data are determined based on the compromised PII, the selecting comprising the steps of:
 selecting, if the breached data includes health care related information, at least one reporting entity associated with health care, 
 selecting, if the breached data includes credit card related information, at least one credit card related entity, and 
 selecting a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; 
   outputting, if the breach information indicates the breach is related to the United States, the breach report to a United States agency; and   outputting the breach report to the one or more reporting entities.   
     
     
         2 . The method of  claim 1 , comprising, after the modifying the breach report step:
 receiving modified organization related information and modified breach information; and   updating the breach report based on the modified organization related information and modified breach information.   
     
     
         3 . The method of  claim 1 , wherein the receiving breach information step comprises:
 receiving audio representative of breach report information;   converting the audio to text using a speech-to-text conversion process; and   organizing the text into breach event description information, compromised PII, and remediation action information.   
     
     
         4 . The method of  claim 1 , wherein the U.S. agency is one or more of Federal Bureau of Investigation and a federal government agency. 
     
     
         5 . The method of  claim 1 , wherein the at least one reporting entity associated with health care is one or more of Office of Civil Rights, Office of Health and Human Services, and a Secret Service regional office. 
     
     
         6 . The method of  claim 1 , wherein receiving breach information includes:
 generating one or more data entry fields including one or more of a breach event description information, compromised PII, and remediation action information data entry field; and   receiving breach information in the one or more data entry fields.   
     
     
         7 . The method of  claim 6 , wherein the one or more data entry fields are pre-populated based on one or more of previously received data breach event description information, compromised PII, and remediation action information related to a previous breach event associated with the organization. 
     
     
         8 . The method of  claim 1 , wherein receiving breach information includes:
 generating one or more data entry fields based on previously received breach event Information from the organization; and   receiving breach information in the one or more data entry fields.   
     
     
         9 . The method of  claim 1 , wherein receiving breach information includes receiving the breach information through an application programming interface (API). 
     
     
         10 . The method of  claim 1 , further comprising outputting, if the breach information indicates the breach is related to an international jurisdiction, the breach report to an entity associated with the international jurisdiction. 
     
     
         11 . The method of  claim 1 , wherein the international jurisdiction includes one or more of European Union, a government of a foreign country, and a state government in a foreign country. 
     
     
         12 . The method of  claim 1 , wherein the one or more of rules, regulations, and laws associated with the PII include European Union rules related to PII. 
     
     
         13 . A computer-implemented system for data breach compliance comprising:
 a memory; and   said system configured to:
 receive information related to an organization; 
 receive breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information; 
 generate a breach report based on the breach information, the organization related information, and one or more rules related to data breach; 
 determine, based on a comparison of the organization related Information, the breach information, and one or more of the following: state rules, federal rules, international rules, industry standards, and rules applicable to the breach event, whether the breach report is in the proper format; 
 modify the breach report, if it is determined that the proper format is an entity specific format, to include predetermined data entry fields; 
 select one or more reporting entities based on one or more geographic locations associated with the data breach event, where the one or more geographical locations are determined based on the organization related information, the breach information, and the one or more rules, wherein the system is configured to:
 determine, if the one or more geographic locations are in the United States, any applicable attorney general reporting rules and applicable long reach rules associated with the one or more geographical locations, 
 select one or more reporting entities based on the applicable attorney general reporting rules and the applicable long reach rules, and 
 select, if the breach information indicates the breach is related to an international jurisdiction, one or more reporting entities based on rules associated with the international jurisdiction; 
 
 select one or more reporting entities based on one or more types of breached data, where the one or more types of breached data are determined based on the compromised PII, wherein the system is configured to:
 select, if the breached data includes health care related information, at least one reporting entity associated with health care, 
 select, if the breached data includes credit card related information, at least one credit card related entity, and 
 select a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; 
 
 output, if the breach information indicates the breach is related to the United States, the breach report to a United States agency; and 
 output the breach report to the one or more reporting entities. 
   
     
     
         14 . A computer-implemented system of  claim 13 , wherein the system is to:
 output the breach report to a reviewing entity;   receive, from the reviewing entity, modified organization related information and modified breach information; and   update the breach report based on the modified organization related information and modified breach information.   
     
     
         15 . A computer-implemented system of  claim 13 , wherein the one or more of rules, regulations, and laws associated with the PII include European Union rules related to PII. 
     
     
         16 . A computer-implemented system of  claim 13 , wherein to receive breach information the system is to:
 receive audio representative of breach report information;   convert the audio to text using a speech-to-text conversion process; and   organize the text into breach event description information, compromised PII, and remediation action information.   
     
     
         17 . A computer storage medium having computer executable instructions which when executed by a computer cause the computer to perform operations comprising:
 receiving information related to an organization;   receiving breach information relating to a data breach event of the organization, the breach information including breach event description information, compromised personally identifiable information (PII), and remediation action information;   generating a breach report based on the breach information, the organization related information, and one or more rules related to data breach;   determining, based on a comparison of the organization related information, the breach information, and one or more of the following: state rules, federal rules, international rules, industry standards, and rules applicable to the breach event, whether the breach report is in the proper format;   modifying the breach report, if it is determined that the proper format is an entity specific format, to include predetermined data entry fields;   selecting one or more reporting entities based on one or more geographic locations associated with the data breach event, where the one or more geographical locations are determined based on the organization related information, the breach information, and the one or more rules, the selecting comprising the steps of:
 determining, if the one or more geographic locations are in the United States, any applicable attorney general reporting rules and applicable long reach rules associated with the one or more geographical locations, 
 selecting one or more reporting entities based on the applicable attorney general reporting rules and the applicable long reach rules, and 
 selecting, if the breach information indicates the breach is related to an international jurisdiction, one or more reporting entities based on rules associated with the international jurisdiction; 
   selecting one or more reporting entities based on one or more types of breached data, where the one or more types of breached data are determined based on the compromised PII, the selecting comprising the steps of:
 selecting, if the breached data includes health care related information, at least one reporting entity associated with health care, 
 selecting, if the breached data includes credit card related information, at least one credit card related entity, and 
 selecting a reporting entity based on one or more of rules, regulations, and laws associated with the compromised PII; 
   outputting, if the breach information indicates the breach is related to the United States, the breach report to a United States agency; and   outputting the breach report to the one or more reporting entities.   
     
     
         18 . The computer storage medium of  claim 17 , further comprising the operation of outputting, if the breach information indicates the breach is related to an international jurisdiction, the breach report to a entity associated with the international jurisdiction. 
     
     
         19 . The computer storage medium of  claim 17 , wherein the receiving breach information operation comprises:
 receiving audio representative of breach report information;   converting the audio to text using a speech to text conversion process; and   organizing the text into breach event description information, compromised PII, and remediation action information.   
     
     
         20 . The computer storage medium of  claim 17 , comprising, alter modifying the breach report, the operation of:
 receiving modified organization related information and modified breach information; and   updating the breach report based on the modified organization related information and modified breach information.

Join the waitlist — get patent alerts

Track US2017076093A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.