Most organizations understand their regulatory compliance obligations with regard to data security and privacy. Or do they?
Two key trends are complicating compliance: laws and regulations are becoming more numerous and complex, and organizations are storing more data than ever. For example, organizations that have COVID-19 vaccination requirements are storing information on their employees’ vaccine status. In other words, organizations outside the healthcare industry are storing personal health data that must be kept private and secure. The HR department is often a treasure trove of information, including Social Security Numbers, insurance coverage, 401(k) and retirement funds, and more. The payroll department has salary, bank account and tax information. A data breach affecting any of these data stores would be devastating. A data breach that exposed data across the enterprise would be cataclysmic. In addition to the cost and business disruption of the breach and the impact on productivity and morale, the organization could be facing stiff fines and other penalties due to regulatory compliance violations.