Risk Assessment Server for Data Incident Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack an efficient method for managing data incidents, particularly in handling the exposure of personally identifiable information (PII) and protected health information (PHI), as they fail to provide comprehensive risk assessments and notification schedules that align with federal, state, and contractual obligations.

Innovation Solution

A risk assessment server system that receives data incident data, compares it to federal, state, and contractual privacy rules, and generates a risk assessment and notification schedule, providing a visual representation of the risk level and obligations, including notification to regulatory agencies and affected individuals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive risk assessment and notification schedule generation is implemented, then compliance accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex compliance assessment into distinct modules: data incident data reception module, risk assessment generation module comparing against federal rules, state rules, and contractual obligations, and notification schedule generation module. This segmentation allows comprehensive compliance checking while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The risk assessment server is designed as a universal system that handles multiple types of privacy rules (federal, state, contractual) and generates both risk assessments and notification schedules through a single integrated platform, reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If automated risk assessment and notification scheduling is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveincident response efficiencyVSAvoidserver system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing the framework for comparing data incident data against multiple privacy rules and pre-generating notification schedules based on risk assessment outcomes. This automation eliminates manual assessment steps and improves incident response efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The risk assessment server autonomously compares received data incident data against stored privacy rules, automatically generates risk assessments, and creates notification schedules without requiring manual intervention, thereby improving productivity through self-service automation.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive privacy rule comparison is performed, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system maintains continuous readiness by pre-loading and organizing multiple privacy rules (federal, state, contractual) in the risk assessment server, enabling continuous automated comparison operations that achieve high measurement precision without manual intervention delays.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9781147B2Systems and methods for managing data incidents
Publication Date: 2017.10.03 RADAR LLC
  • US9781147B2 patent drawing
  • US9781147B2 patent drawing
  • US9781147B2 patent drawing

AI summary

Systems and methods for managing a data incident are provided herein. Exemplary methods may include providing an external entity interface that receives external entity information including a contract between a first party and at least one additional party, notification obligations that specify when the first party or the at least one additional party notifies entities that a data incident has occurred, and properties that trigger an assessment of the notification obligations. When an incident occurs, an assessment is completed and the results thereof are displayed on a risk assessment guidance interface.