• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

data protection

Article 10.26.2021 Dean Dorton

No one wants their data to be hacked and used for nefarious gain. Employees, customers, clients, patients, students, and vendors are depending on your organization to protect their data. You have been entrusted with it and they have a reasonable expectation you are going to take steps necessary to keep it out of the wrong hands.

We all understand there is no such thing as 100% secure, therefore “reasonable” is a much more practical goal. Ideally, every organization would prioritize investing time and resources into having an adequately mature cyber security program. However, there are myriad pressures and objectives facing every organization. Sometimes cyber security does not get the attention it needs.

Numerous regulatory bodies have established requirements with the intent of attempting to ensure organizations are adhering to common measures of cyber standards. These requirements vary based on elements such as industry, type of data and geographic location. Once an organization finds themselves falling under data protection regulations, it is common to have multiple, applicable regulatory requirements. Compliance can get complex and seemingly overwhelming quickly. Below are examples of data protections requirements:

Japan – APPI
Brazil – LGPD
Canada – PIPEDA
China – PIPL
European Union – GDPR

CMMC
GLBA
FFIEC
HIPAA
PCI
SOX

Data Break Notification Laws
Data Privacy Laws
State Grants & Contracts

For organizations that want to comply, there are two paths typically taken when faced with this complexity. The first path involves a process that looks good on paper. All the boxes are checked but no value has been provided to the organization other than dodging the penalty and fine bullet for another year. This approach has been common with credit card compliance requirements.

The second path involves a process not only addressing compliance requirements, but also recognizes there are many other objectives that can be accomplished that bring value to the organization. For example, most data regulatory standards require a risk assessment be performed. However, each standard typically narrows the scope to just the applicable processes, systems and data being regulated. If you are performing a risk assessment, why not make it enterprise-wide? The resulting information not only assists with compliance but helps identify other initiatives that are needed.

As previously mentioned, the phrase adequately mature is intended to recognize that each organization has different cyber security needs. Even though this is the case, there are fundamental steps applicable to all organizations that are beneficial to data protection. These steps will help deal with the complexities and provide a clear path forward. See the demonstration below:

https://deandorton.com/wp-content/uploads/2021/10/Cyber-Pyramid-e1635186352566.jpg

Data Inventory
Determine what data you have, where it resides, and who is interested in the data. The “who” element can include internal stakeholders, but for the purposes of compliance make sure to identify external stakeholders. I.E., regulatory bodies. Relevant information to include in your data inventory:

Application/System Name
Version #
Vendor
System Owner
Data Owner
Function/Purpose
Users of System
Primary/Secondary Locations
Sensitive Data Elements*

Alumni/Students
Applicants/Employees
CUI
DOB/SSN/Passport/Visa
Name/Address/Telephone/ID
Patients/Customers/Vendors

Based on the sensitive data elements, identify the applicable regulatory bodies governing data protection.

Cybersecurity Control Framework
Many regulatory bodies recommend or require specific control frameworks. A control framework helps create a vision of what your organizational security program should look like. It provides a path and eliminates the need to create everything from scratch due to the many resources available. Your data inventory will drive selecting the right framework.

See example of cyber security control frameworks:

https://deandorton.com/wp-content/uploads/2021/10/Screenshot-2021-10-20-151610.png

To summarize, one path does take more work and effort, but the results speak for themselves. Subscribe to Dean Dorton Insights to stay up-to-date with the latest regulatory changes.

Explore IT Audit and Compliance Services

Kevin W. Cornwell | IT Audit Associate Director
kcornwell@ddaftech.com
502.566.1011

Filed Under: Accounting and Financial Outsourcing, Healthcare, Industries, Services, Technology Tagged With: Compliance, Data, data protection, IT Audit, law, regulations

Article 03.20.2018 Dean Dorton

Did you know that most higher education institutions will be required to meet new data protection standards starting May 25, 2018?

The European Union’s General Data Protection Regulation (GDPR) will affect institutions that recruit EU students, have alumni or donors residing in the EU, or offer study abroad programs there.  It is not yet clear how the regulations will be enforced and penalties assessed against U.S. institutions, but the maximum fine can be up to 20 million Euros based on severity and other factors.

Institutions are encouraged to get out in front of this regulation before it arrives at their doorstep!  Below are some of the specific data protection requirements that may be different than what you currently have in place:

  • Must obtain consent before collecting data from someone.
  • Must notify affected persons of a data breach within 72 hours.
  • Must provide data subjects a free electronic copy of their personal data when requested.
  • Data subjects have the right to be “forgotten”, meaning erasure of their personal data and cessation of its dissemination.
  • Must allow personal data to be portable in an electronic format for the subject’s own use.
  • Data systems must be built with privacy by design using appropriate technical security measures.
  • A qualified Data Protection Officer must be appointed by organizations that process personal data and have over 250 employees.

If you would like more information on these new standards or would like assistance in assessing your readiness for GDPR, please contact Jason Whitaker at jwhitaker@ddaftech.com or Megan Crane at mcrane@deandorton.com.

Filed Under: Higher Education, Industries Tagged With: breach, Data, data protection, EU, europe, european, GDPR, general data protection regulation, Higher Education, jason, whitaker

  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved