Data Protection

Massachusetts 201 CMR 17.00: Data Security Requirements

A plain-language overview of the Massachusetts data security regulation and the written information security program it requires.

Reviewed October 10, 2026 3 minute read Reviewed by Meta IT Pro
Part of the Data Protection & Recovery Learning Center

201 CMR 17.00 requires businesses that own or license personal information about Massachusetts residents to maintain a written information security program with administrative, technical, and physical safeguards.

Key takeaways

What to know before you act

  • 201 CMR 17.00 applies to persons that own or license personal information about Massachusetts residents, wherever the business is located.
  • It requires a written information security program (WISP) plus specific computer security controls.
  • This overview is not legal advice; confirm obligations with qualified counsel and the official regulation.

Why it matters

What business leaders should understand

The regulation applies to many businesses outside Massachusetts as well as inside it, wherever they hold qualifying resident information. Its requirements also overlap with what insurers and clients expect.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

What information is covered

The regulation defines personal information as a Massachusetts resident's first name or first initial and last name combined with a Social Security number; a driver's license or state-issued ID number; or a financial account or credit or debit card number, with or without any required security code or password that would permit access to the account. Many employers, retailers, professional firms, and healthcare-adjacent businesses hold this information about employees or customers.

Written information security program requirements

The WISP must contain administrative, technical, and physical safeguards appropriate to the business's size, resources, the amount of data stored, and the need for security. Key elements include:

  • Designating one or more employees to maintain the program.
  • Identifying and assessing reasonably foreseeable internal and external risks.
  • Employee training and disciplinary measures for violations.
  • Preventing terminated employees from accessing records.
  • Overseeing third-party service providers, including contractual requirements to protect information.
  • Reasonable restrictions on physical access to records.
  • Regular monitoring and at least annual review of the program.
  • Documenting responsive actions taken after incidents.

Computer system security requirements

To the extent technically feasible, the regulation also specifies technical controls for systems that store or transmit personal information.

  • Secure user authentication and access controls.
  • Encryption of personal information transmitted across public networks or wirelessly.
  • Encryption of personal information stored on laptops and other portable devices.
  • Monitoring of systems for unauthorized use or access.
  • Up-to-date firewall protection and operating-system security patches.
  • Current malware protection with regular updates.
  • Employee education on computer security and the importance of personal information security.

Practical action plan

Steps your business can take

01

Identify where you store Massachusetts residents' personal information.

02

Designate an employee to maintain a written information security program.

03

Implement the required computer security controls, including encryption where specified.

04

Review the program at least annually and after material changes.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • No written information security program exists
  • Laptops holding personal information are not encrypted
  • Vendors with access to personal information have no security terms in their contracts

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.