IP Library Granted Patent US 10,331,904
Granted Patent B2
US 10,331,904 · App. 15/786,538 · Granted Jun 25, 2019

Systems and methods for managing multifaceted data incidents

Inventors: Mahmood Sher-Jan (Lake Oswego, OR); Andrew Migliore (Portland, OR); Nicholas J. Church (Milwaukie, OR); David John DeAngelis (Portland, OR); Reno Brown (Portland, OR)
Assignee: RADAR, LLC
G06F21/6245G06F19/00G06F21/554G06F21/577G16H10/60H04L63/0227H04L63/1416H04L63/1433H04L63/0407
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,331,904
App. No.
15/786,538
Granted
Jun 25, 2019
Kind
B2
Abstract

Systems and methods for managing a multifaceted data incident are provided herein. Example methods include receiving, via a risk assessment server, in response to an occurrence of the data incident, data incident data that including information corresponding to the data incident, wherein the data incident has a plurality of facets with each facet having any of unique and overlapping set of privacy data and media type and associated risk factors requiring facet specific incident risk assessment, automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the facet is reportable, from a comparison of the facet to privacy rules, the privacy rules define requirements associated with data incident notification obligations, and providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server.

Claims (49)

1. A method for managing a data incident, comprising:

receiving, via a risk assessment server, in response to an occurrence of a multifaceted data incident, data incident data that comprises information corresponding to the multifaceted data incident, the multifaceted data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment, wherein the multifaceted data incident has a plurality of facets with each facet comprising any of unique and overlapping set of privacy data, and media type, and associated risk factors requiring facet specific incident risk assessment;

automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the facet is reportable from a comparison of each of a plurality of privacy rules;

wherein the privacy rules define requirements associated with data incident notification obligations or a privacy related contractual obligation that comprise any of notification and mitigation obligations; and

providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server;

wherein:

the risk assessment comprises a determination as to whether a number of unique or non-unique but overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction;

one or more of the plurality of facets comprises a single or multiple regulatory regions associated with one or more of the privacy rules;

one or more of the plurality of facets is associated with a collection of privacy data determined by a regulatory agency in one or more regulatory regions;

receiving data incident data comprises:

providing one or more data incident risk factor questions to the display device that elicit information corresponding to each facet of the data incident;

receiving responses to the one or more data incident risk factor questions; and

providing the responses to the display device; and

receiving confirmation of at least a portion of the responses; and further comprising providing an alert to the display device when the comparison indicates that one or more of the plurality of facets of the data incident violates and triggers a notification obligation according to the privacy rules, further wherein a notification schedule comprises notification dates that are based upon a violated one of the privacy rules, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.

2. The method according to claim 1 , further wherein each data incident comprises any of risk factors, the data incident data, and at least one jurisdiction.

3. The method according to claim 1 , wherein one or more of the plurality of facets is capable of being assessed independently of other ones of the plurality of facets.

4. The method according to claim 3 , wherein each of the plurality of facets comprises a complete set of privacy data.

5. The method according to claim 1 , wherein the privacy rules comprise at least one European General Data Privacy Regulation (GDPR) rule that governs privacy breaches relative to at least one of personal data, special categories of personal data, or combinations thereof.

6. The method according to claim 1 , wherein the risk assessment comprises a risk level that indicates a severity of the data incident relative to the privacy rules, and further wherein the risk level is associated with a color, wherein a hue of the color is associated with the severity of the data incident and a sensitivity of the data incident data as determined by the comparison.

7. The method according to claim 1 , wherein the privacy rules comprise a privacy related contractual obligations between two or more parties.

8. The method according to claim 1 , wherein the risk assessment defines one or more exceptions that apply to at least a portion of the data incident data based upon the comparison.

9. The method according to claim 1 , wherein the risk assessment comprises at least a portion of at least one European General Data Privacy Regulation (GDPR) rule.

10. The method according to claim 1 , further comprising generating a notification schedule when the comparison indicates that the data incident violates and triggers a notification obligation according to at least one European General Data Privacy Regulation (GDPR) rule.

11. The method according to claim 1 , further comprising receiving the information that is to be provided to a regulatory agency and storing the same in a content repository associated with the risk assessment server.

12. The method according to claim 1 , wherein the comparison includes modeling of the data incident data to the privacy rules to determine a severity and a data sensitivity of the data incident.

13. The method according to claim 1 , wherein the comparison comprises:

modeling the data incident data to determine severity and data sensitivity of the data incident by evaluating the data incident data relative to the privacy rules; and generating a risk assessment from the modeling.

14. A risk assessment server for managing a multifaceted data incident, the server comprising:

a memory for storing executable instructions;

a processor for executing the instructions;

an input module stored in memory and executable by the processor to:

receive in response to an occurrence of the multifaceted data incident, data incident data, the data incident data comprising information corresponding to the multifaceted data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data, personally identifiable information, or protected health information to an untrusted or unauthorized environment, wherein the multifaceted data incident has a plurality of facets with each facet comprising any of unique set of privacy data, media type, and associated risk factors requiring facet specific incident risk assessment;

a risk assessment generator stored in memory and executable by the processor to generate a risk assessment for each of the facets from a comparison of the data incident data to privacy rules;

wherein the privacy rules define requirements associated with data incident notification laws or a privacy related contractual obligation that comprise any of notification and mitigation obligations; and

a user interface module stored in memory and executable by the processor

to provide the risk assessment to a display device that selectively couples with the risk assessment server;

wherein:

the risk assessment comprises a determination as to whether a number of unique or non-unique but overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction;

one or more of the plurality of facets comprises a single or multiple regulatory regions associated with one or more of the privacy rules;

one or more of the plurality of facets is associated with a collection of privacy data determined by a regulatory agency in one or more regulatory regions;

receiving data incident data comprises:

providing one or more data incident risk factor questions to the display device that elicit information corresponding to each facet of the data incident;

receiving responses to the one or more data incident risk factor questions; and

providing the responses to the display device; and

receiving confirmation of at least a portion of the responses; and further comprising providing an alert to the display device when the comparison indicates that one or more of the plurality of facets of the data incident violates and triggers a notification obligation according to the privacy rules, further wherein a notification schedule comprises notification dates that are based upon a violated one of the privacy rules, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.

15. The server according to claim 14 , wherein the processor further executes the instructions to determine whether a number of unique or overlapping individuals across the plurality of facets meet notification thresholds based on jurisdiction.

16. The server according to claim 14 , wherein the risk assessment generator, for each of the plurality of facets further:

generates a risk assessment that comprises a risk level that indicates a severity of the data incident relative to at least one of at least one federal rule, at least one state rule, or at least one European General Data Privacy Regulation (GDPR) rule, and a privacy related contractual obligation, and any combinations thereof; and

creates a notification that one or more exceptions apply to at least a portion of the data incident data based upon modeling.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Apr 7, 2022
From: RADAR, LLC
To: BANK OF MONTREAL, AS COLLATERAL AGENT
Reel/Frame 059623/0572 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2019
From: RADAR, INC.
To: RADAR, LLC
Reel/Frame 048885/0133 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2019
From: MIGLIORE, ANDREW; CHURCH, NICHOLAS J.; BROWN, RENO
To: RADAR, INC.
Reel/Frame 048875/0941 →
CONFIDENTIAL INFORMATION, INVENTION ASSIGNMENT, NONCOMPETE AND NONSOLICITATION AGREEMENT Recorded Apr 12, 2019
From: DEANGELIS, DAVID JOHN
To: RADAR, INC.
Reel/Frame 048878/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2017
From: SHER-JAN, MAHMOOD
To: RADAR, INC.
Reel/Frame 044165/0109 →
Continuity (7)
Continuation In Part 15339786 · Oct 31, 2016
Continuation In Part 14868311 · Sep 28, 2015
Continuation In Part 14588159 · Dec 31, 2014
Continuation In Part 14311253 · Jun 21, 2014
Continuation 13691661 · Nov 30, 2012
Continuation 13396558 · Feb 14, 2012
Related Publication 20180039794A1 · Feb 8, 2018
Cited By (18)
US 12,190,330 US 12,204,564 US 12,216,794 US 12,259,882 US 12,265,896 US 12,277,232 US 12,288,233 US 12,299,065 US 12,353,405 US 12,381,915 US 12,412,140 US 12,536,329 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044 US 12,718,167