IP Library Granted Patent US 10,325,113
Granted Patent B2
US 10,325,113 · App. 15/464,843 · Granted Jun 18, 2019

Limiting exposure to compliance and risk in a cloud environment

Inventors: Corville O. Allen (Morrisville, NC); Arthur R. Francis (Raleigh, NC); Eduardo A. Patrocinio (Apex, NC)
Assignee: International Business Machines Corporation
G06F21/6245H04L63/10H04L63/20H04L67/1097G06F21/6227H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,325,113
App. No.
15/464,843
Granted
Jun 18, 2019
Kind
B2
Abstract

Minimizing data security risks may be provided. A number and type of confidential data in a computing environment may be determined to generate a metric for the type of confidential data in the computing environment. The metric of the type of confidential data may be compared to a predetermined metric for the type. Responsive to determining the metric for the type of confidential data exceeding a predetermined metric for the type, an action may be performed to prevent more entries of the type of confidential data in the computing environment.

Claims (35)

1. A method of minimizing data security risks in a computing environment wherein a plurality of types of protected health information are stored, the method comprising:

measuring an amount of data stored for each type of protected health information;

comparing each amount to a predetermined threshold for a corresponding type;

determining that a first amount of data for a first type of protected health information exceeds a first predetermined threshold corresponding to the first type of protected health information;

responsive to determining the first predetermined threshold is exceeded, preventing more entries of the first type of protected health information into the computing environment by closing an access port in the computing environment to requests associated with new data of the first type of protected health information.

2. The method of claim 1 , further comprising:

responsive to determining the first predetermined threshold is exceeded, scheduling work associated with the first type of protected health information into a different computing environment.

3. The method of claim 1 , wherein the computing environment comprises one or more of a virtual environment, a virtual machine (VM), a logical partition (LPAR), a workload partition (WPAR), a machine, a node, or public cloud, or combinations thereof.

4. The method of claim 1 , wherein the first type of protected health information comprises patient identifying information.

5. The method of claim 1 , wherein the first type of protected health information comprises patient address information.

6. The method of claim 1 , wherein the first type of protected health information comprises patient financial information.

7. A computer readable storage device storing a program of instructions executable by a machine to perform a method of minimizing data security risks in a computing environment wherein a plurality of types of protected health information are stored, the method comprising:

measuring an amount of data stored for each type of protected health information;

comparing each amount to a predetermined threshold for a corresponding type;

determining that a first amount of data for a first type of protected health information exceeds a first predetermined threshold corresponding to the first type of protected health information;

responsive to determining the first predetermined threshold is exceeded, preventing more entries of the first type of protected health information into the computing environment by closing an access port in the computing environment to requests associated with new data of the first type of protected health information.

8. The computer readable storage device of claim 7 , further comprising:

responsive to determining the first predetermined threshold is exceeded, scheduling work associated with the first type of protected health information into a different computing environment.

9. The computer readable storage device of claim 7 , wherein the computing environment comprises one or more of a virtual environment, a virtual machine (VM), a logical partition (LPAR), a workload partition (WPAR), a machine, a node, or public cloud, or combinations thereof.

10. The computer readable storage device of claim 7 , wherein the first type of protected health information comprises patient identifying information.

11. The computer readable storage device of claim 7 , wherein the first type of protected health information comprises patient address information.

12. The computer readable storage device of claim 7 , wherein the first type of protected health information comprises patient financial information.

13. A system of minimizing data security risks in a computing environment, comprising:

a processor executing in the computing environment; and

a storage device couple to the processor in the computing environment, the storage device storing a plurality of types of protected health information;

the processor operable to measure an amount of data stored for each type of protected health information,

the processor further operable to compare each amount to a predetermined threshold for a corresponding type;

the processor further operable to determine that a first amount of data for a first type of protected health information exceeds a first predetermined threshold corresponding to the first type of protected health information;

responsive to determining the first predetermined threshold is exceeded, the processor further operable to prevent more entries of the first type of protected health information into the computing environment by closing an access port in the computing environment to requests associated with new data of the first type of protected health information.

14. The system of claim 13 , further comprising:

responsive to determining the first predetermined threshold is exceeded, the processor further operable to schedule work associated with the first type of protected health information into a different computing environment.

15. The system of claim 13 , wherein the computing environment comprises one or more of a virtual environment, a virtual machine (VM), a logical partition (LPAR), a workload partition (WPAR), a machine, a node, or public cloud, or combinations thereof.

16. The system of claim 13 , wherein the first type of protected health information comprises patient identifying information.

17. The system of claim 13 , wherein the first type of protected health information comprises patient address information.

18. The system of claim 13 , wherein the first type of protected health information comprises patient financial information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2017
From: ALLEN, CORVILLE O.; FRANCIS, ARTHUR R.; PATROCINIO, EDUARDO A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041664/0659 →
Continuity (3)
Continuation 14833819 · Aug 24, 2015
Continuation 14591578 · Jan 7, 2015
Related Publication 20170193248A1 · Jul 6, 2017