Overview
McDonald Hopkins offers CyberSavvy® pre-breach services that focus on proactively managing personal, sensitive and confidential information and minimizing the risk of a data privacy incident.
The cost of a data breach, including restoration, investigation, notification and litigation fees, plus fines from regulators, can be devastating to your business. Unfortunately, it’s not a matter of if you will fall victim of a data breach, but when. You need a plan in place, knowledge of privacy regulations and effective and cost- efficient legal support.
We have conducted more than 1,000 breach response workshops and training sessions nationwide for our clients.
What we offer:
Data privacy review and legal compliance evaluation
- Data privacy risk assessment review
- Evaluate client’s current data security policies and practices
- Data privacy gap assessment
- Handbook review for data security and privacy
- Information security/cybersecurity/ privacy due diligence
- Cross-border transfers of data
- Information collection from children
- Disclosure of personal information (sale/share)
Policies and procedures
Review/revision or creation of:
- Written Information Security Program (WISP)
- Privacy Policy & Terms of Use (External)
- Privacy Policy (Internal Governance Policy)
-
Vendor Risk Management Policy and Procedures
-
Risk Management Policy and Procedures
-
Cookie Notice
-
Business Continuity and Disaster Recovery Plan
-
Privacy Impact Assessments/Data Protection Impact Assessments
- Social Media Policy
- Computer & Electronic Devices Usage Policy
- Bring Your Own Device (BYOD) Policy
- Document Retention & Destruction Policy
- Data Subject Access Request (DSAR) Policy and Procedures
- Telecommuting/Remote Access Policy
- Physical and Logical Access Security Policy
- Acceptable Use Policy
- Password Management Policy
- Vendor Management Policy
- Information Classification & Handling Policy
- Training Policy
- HIPAA Policies (Privacy Rule, Security Rule & Breach Notification Rule policies)
Incident response planning
Review/revision or creation of:
- Incident response plan and playbooks
- Incident response team (establishment of team and identification of roles/responsibilities)
Agreements
Review/revision or creation of:
- Employment (Confidentiality) Agreements
- Non-Disclosure Agreements
- Data Privacy Agreements/Addendums
- Third-Party Vendor Agreements and Amendments
- Business Associate Agreements
- Visitor Agreements
- End User License Agreements
- Payment Card Merchant Agreements
- Cloud Vendor Agreements
Employee training
Development of employee training module on client’s data privacy and security policies and best practices
regarding:
- The role of employees in protecting PII, PHI and/or PCI data
- Phishing scams
- Social engineering
- Ransomware threats
- Laptop security
- Mobile device security
- Passwords and encryption
- Internet security
- Physical site security
- Responding to individual requests to access and/or delete personal information
- Data disposal and destruction
- Reducing the risk of data breaches
- Reporting suspected privacy and security incidents
Tabletop exercise
Facilitation of a Breach Response Workshop with tabletop exercise (2-4 hour session for client’s Incident
Response Team)
- In-person or remote options available
McDonald Hopkins Data Privacy and Cybersecurity Services
Key Practice Contacts
- Member|
- Member|
Members
- Member|
- Member|
- Member|
Counsel
- Counsel|
- Counsel|
Associates
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|
- Associate|