201 CMR 17.00 requires businesses that own or license personal information about Massachusetts residents to maintain a written information security program with administrative, technical, and physical safeguards.
Key takeaways
What to know before you act
- 201 CMR 17.00 applies to persons that own or license personal information about Massachusetts residents, wherever the business is located.
- It requires a written information security program (WISP) plus specific computer security controls.
- This overview is not legal advice; confirm obligations with qualified counsel and the official regulation.
Why it matters
What business leaders should understand
The regulation applies to many businesses outside Massachusetts as well as inside it, wherever they hold qualifying resident information. Its requirements also overlap with what insurers and clients expect.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with compliance it services, backup and disaster recovery, and business continuity planning.
Related reading: What is data security? and Vendor risk management for small businesses.
What information is covered
The regulation defines personal information as a Massachusetts resident's first name or first initial and last name combined with a Social Security number; a driver's license or state-issued ID number; or a financial account or credit or debit card number, with or without any required security code or password that would permit access to the account. Many employers, retailers, professional firms, and healthcare-adjacent businesses hold this information about employees or customers.
Written information security program requirements
The WISP must contain administrative, technical, and physical safeguards appropriate to the business's size, resources, the amount of data stored, and the need for security. Key elements include:
- Designating one or more employees to maintain the program.
- Identifying and assessing reasonably foreseeable internal and external risks.
- Employee training and disciplinary measures for violations.
- Preventing terminated employees from accessing records.
- Overseeing third-party service providers, including contractual requirements to protect information.
- Reasonable restrictions on physical access to records.
- Regular monitoring and at least annual review of the program.
- Documenting responsive actions taken after incidents.
Computer system security requirements
To the extent technically feasible, the regulation also specifies technical controls for systems that store or transmit personal information.
- Secure user authentication and access controls.
- Encryption of personal information transmitted across public networks or wirelessly.
- Encryption of personal information stored on laptops and other portable devices.
- Monitoring of systems for unauthorized use or access.
- Up-to-date firewall protection and operating-system security patches.
- Current malware protection with regular updates.
- Employee education on computer security and the importance of personal information security.
Practical action plan
Steps your business can take
Identify where you store Massachusetts residents' personal information.
Designate an employee to maintain a written information security program.
Implement the required computer security controls, including encryption where specified.
Review the program at least annually and after material changes.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is data security?
Apply access control, encryption, and monitoring to personal information.
Explore nextRelated guide
Vendor risk management for small businesses
Oversee service providers that handle resident data.
Explore nextCompliance resource
FTC Safeguards Rule IT compliance
Compare with federal safeguards for covered financial businesses.
Explore nextService
Cybersecurity services
Implement the technical safeguards your WISP describes.
Explore nextWarning signs
Do not ignore these indicators
- No written information security program exists
- Laptops holding personal information are not encrypted
- Vendors with access to personal information have no security terms in their contracts
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Massachusetts Office of Consumer Affairs and Business Regulation
201 CMR 17.00: Standards for the Protection of Personal Information of Residents of the Commonwealth
The official text of the Massachusetts data security regulation.
Federal Trade Commission
Protecting Personal Information: A Guide for Business
Five principles for taking stock of, reducing, locking down, disposing of, and planning around personal information.
Federal Trade Commission
Data Breach Response: A Guide for Business
Steps for securing operations, fixing vulnerabilities, and notifying appropriate parties after a breach.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
