Claims
- 1. A method of facilitating compliance to one or more information sharing regulations comprising the steps of:
identifying at least one primary party for sharing data and at least one secondary party for receiving shared data; classifying said primary party as belonging to a first party type; classifying said secondary party as belonging to a second party type; utilizing said first party type and said second party type, defining a sharing relationship between said primary party and said secondary party; defining said data as belonging to a data type; utilizing said relationship and said data type, defining a data sharing arrangement between said primary party and said secondary party; and retrieving data sharing guidelines relating to said sharing arrangement, said guidelines providing guidance to facilitate compliance of said information sharing regulations applicable to said data sharing arrangement.
- 2. The method of claim 1, wherein said sharing relationship comprises an affiliate relationship.
- 3. The method of claim 1, wherein said sharing relationship comprises a non-affiliate relationship.
- 4. The method of claim 1, further comprising the additional step of providing one or more contact persons associated with said data sharing arrangement.
- 5. The method of claim 1, wherein said data sharing guidelines further comprise one or more exemptions.
- 6. The method of claim 1, wherein said data sharing arrangement further comprises one or more reasons for sharing said data between said parties.
- 7. The method of claim 1 or 6, further comprising the additional step of compiling one or more reports illustrating said data sharing guidelines and said related data sharing arrangements in combination.
- 8. The method of claim 1, further comprising the additional step of assessing one or more security risks associated with said data sharing arrangement.
- 9. The method of claim 8, further comprising the additional step of determining whether one or more security measures are in place to protect said data from unauthorized access.
- 10. The method of claim 9, further comprising the additional step of instituting supplementary security measures to protect said data from unauthorized access.
- 11. The method of claim 1, wherein said data type comprises non-public personally identifiable data.
- 12. The method of claim 11, wherein said non-public personally identifiable data comprises health related data or credit related data.
- 13. The method of claim 1, further comprising the additional steps of:
determining one or more consumers associated with said shared data; preparing one or more notices according to said data sharing guidelines; and transmitting said notice to said consumers.
- 14. The method of claim 13, wherein said notice further comprises an opt-out provision for providing said consumer with an opportunity to decline said data sharing arrangement.
- 15. The method of claim 13, wherein said notice further comprises an opt-in provision for providing said consumer with an opportunity to provide express written consent to said data sharing arrangement.
- 16. The method of claim 13, wherein said notice further comprises a revocation provision for providing said consumer with an opportunity to revoke consent to said data sharing arrangement.
- 17. The method of claim 13, wherein said notice further comprises one or more data sharing conditions.
- 18. A computer system for facilitating compliance with one or more information sharing regulations comprising:
an input device; a processing unit coupled to said input device for: receiving identifying information relating to at least one primary data sharing party and at least one secondary data receiving party; classifying said primary party as belonging to a first party type; classifying said secondary party as belonging to a second party type; utilizing said first party type and said second party type, defining a sharing relationship between said primary party and said secondary party; defining said data as belonging to a data type; utilizing said relationship and said data type, defining a data sharing arrangement between said primary party and said secondary party; and, retrieving data sharing guidelines relating to said sharing arrangement, said guidelines providing guidance to facilitate compliance with said information sharing regulations applicable to said data sharing arrangement.
- 19. The computer system of claim 18, wherein said sharing relationship comprises an affiliate relationship.
- 20. The computer system of claim 18, wherein said sharing relationship comprises a non-affiliate relationship.
- 21. The computer system of claim 18, further comprising a storage device capable of storing electronic data, said storage device being coupled to said processing unit such that electronic data may pass therebetween.
- 22. The computer system of claim 18, wherein said processing unit is for:
determining one or more consumers associated with said shared data; preparing one or more notices according to said data sharing guidelines; and, transmitting said notice to said consumers.
- 23. The computer system of claim 22, wherein said notice is transmitted to said consumer via a computer network.
- 24. The computer system of claim 22, wherein said notice further comprises an opt-out provision for providing said consumer with an opportunity to decline said data sharing arrangement.
- 25. The computer system of claim 22, wherein said notice further comprises an opt-in provision for providing said consumer with an opportunity to provide express written consent to said data sharing arrangement.
- 26. The computer system of claim 22, wherein said notice further comprises a revocation provision for providing said consumer with an opportunity to revoke consent to said data sharing arrangement.
Parent Case Info
[0001] This patent application claims priority upon a provisional patent application entitled “Privacy Compliance,” Serial No. 60/344,162, having a filing date of Dec. 26, 2001.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60344162 |
Dec 2001 |
US |