De La Rosa questions data breach reporting failures
De La Rosa cites the comptroller's finding that DOE reported 67 of 141 breaches late, nearly half. Doyle explains difficulties with vendor reporting timeliness, staff awareness, and forensic investigation delays. De La Rosa asks what steps beyond training have been taken to fix lapses in notifying families within the required 60-day timeframe.
I want to end with just more about the state controller's report.
About data breaches.
I think very concerning to all of us, correct?
Yes, absolutely.
Good answer.
Oh, we're nodding again.
Okay, yeah.
That's called saying yes out loud.
It's called implementing feedback.
We love to see that.
And, of course, the DOE thinks it's important to report data breaches in a timely manner when they occur.
Reporting the breaches is required by Part 121 of the State Education Department's regulations.
It requires the DOE to notify the State Education Department's Chief Privacy Officer within 10 calendar days of discovering a breach.
The Comptroller's audit reviewed 141 breaches and found that the DOE reported 67 of those breaches, which is almost half of them, late.
Explain why the DOE failed to comply with the law in almost half of the instances that the Comptroller examined.
Yeah, thank you for the question.
I think as far as reporting to the state goes, when we have a breach,
I alluded to this before in another answer, but part of our difficulty is that we rely on either our vendors to come to us and report this information to us in a timely fashion, which unfortunately does not always happen, or
we rely on our staff to come to us and report the breach or unauthorized disclosure to us as soon as possible.
And I think one of the ways that we've improved on that front, and I think the figures in the controller's audit show that at least we're trending in the right direction, is by improving our awareness campaigns, improving our training.
I understand that we are not at 100% completion for the training, but even that number is improving.
We're finding that we're getting more.
More staff that are aware of their privacy obligations.
They're in contact with our office more and reporting more to us.
So I think we're improving on that front.
And it's a tight timeline, I think 10 days to report to the state.
So those are some of the factors that go into it.
But, yeah, we're moving in the right direction on that front.
So you've spoken about how you ensure or are attempting to ensure that professionals get the training so that they report.
But what about the vendors?
Our vendors are required under our data processing agreements to notify us as soon as they have confirmed an unauthorized.
authorized disclosure or a data breach.
There are sometimes difficulties with getting that information from vendors in a timely fashion, notwithstanding what they're required to do under the DPA.
Sometimes vendors don't contact us at the right point of contact.
They will, for example, contact a school and not contact the student privacy office so we can affect the notification right away.
But that's not, I'm sorry, but that's not in their contract that in the instance of a data breach, contact.
It is.
It is, but we still have difficulty with vendors, you know, complying with that part of the contract, and we're looking into, you know.
Different ways that we can strengthen our DPAs to make sure that vendors are going to be held accountable to this to make sure that they're reporting it in a timely fashion.
So you drop them as a vendor?
Say that again?
You drop them as a vendor if they don't comply?
I didn't, no, I didn't say that.
I know, I'm asking.
Would we?
I mean, we have...
No, have you?