QuestionQ241

Privacy Operational Lifecycle: Respond

An organization’s privacy officer has just been informed by the benefits manager that she inadvertently sent the retirement enrollment report for all employees to the wrong vendor.

Which of the following should the privacy officer do first?

  • A Perform a risk of harm analysis.
  • B Report the incident to law enforcement.
  • C Contact the recipient to delete the email.
  • D Send firm-wide email notification to employees.
Explanation

Privacy-incident response begins with containment and mitigation. Promptly contacting the unintended recipient to delete the misdirected report limits further disclosure and helps establish whether the information was accessed or retained; those facts support any subsequent risk-of-harm assessment and notification decision. HHS breach guidance includes the extent to which risk was mitigated as a factor in assessing compromise.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!