Question: Answer the below questions in paragraph format and number your answer for each question. Do not forget to number your answers for each question! Scenario:
Answer the below questions in paragraph format and number your answer for each question. Do not forget to number your answers for each question!
Scenario: The Data Breach Class Action
Your firm is defending a large healthcare provider in a data breach class action involving thousands of patients' records being accessed without authorization. The case involves HIPAA compliance, and multiple departments and custodians hold relevant data.
Questions:
Custodian Interviews: Interviews are planned with custodians from IT security, compliance, legal, and patient records management.
- How do you prioritize which custodians to interview first, and what special considerations are needed given the sensitivity of the data involved?
- How would you document potential data locations and systems mentioned during the interviews? Collection Best Practices: One of the systems mentioned during interviews is a legacy database without clear export tools. The IT department suggests screenshots or printed logs.
- What risks are involved with this method of data collection?
- What alternative approaches could you recommend to ensure integrity and searchability? ESI Protocols: Plaintiffs propose a broad keyword search list including patient names and internal terms like "flagged account," which may return thousands of irrelevant results.
- What negotiation strategies would you suggest to refine or challenge this search criteria?
- What ESI protocol provisions should be proposed to address data volume, relevance, and privacy concerns?
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
