1
If your Boston business stores personal information about Massachusetts residents, a specific state law already applies to you, whether you have read it or not.
201 CMR 17.00, the Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth, requires businesses to have a written information security program in place. Not a policy on a shelf. An actual, working program.
Many small businesses in Boston assume this law only applies to large companies or specific industries. It does not. It applies to any business, of any size, anywhere, that holds personal information on Massachusetts residents.
Regulators and plaintiffs’ attorneys both look at 201 CMR 17.00 compliance immediately after a breach involving Massachusetts residents.
A business without a documented WISP at the time of a breach faces a much harder conversation with regulators, insurers, and affected customers than one that can show a working security program was already in place.
If your business collects any of this from Massachusetts residents, in any format, this law applies to you.
The written information security program (WISP). Every covered business must maintain a written, comprehensive information security program describing exactly how personal information is protected, accessed, and stored. Massachusetts’s own 201 CMR 17.00 compliance checklist walks through exactly what a WISP needs to cover.
Encryption requirements. Personal information transmitted over public networks, and personal information stored on laptops or other portable devices, must be encrypted to the extent technically feasible. That is the standard the regulation itself uses, and it covers the overwhelming majority of standard business systems.
Access and monitoring controls. Businesses must restrict access to personal information to employees who need it, and must monitor systems for unauthorized access or use.
Vendor oversight. Any third party that handles personal information on your behalf must be contractually required to maintain appropriate safeguards.
Building a compliant security program costs a fraction of what a breach costs once regulators, legal counsel, and customer notification requirements enter the picture.
Under Massachusetts’s Data Breach Notification Law, a companion statute that works alongside 201 CMR 17.00, affected Massachusetts residents must be notified, along with the Attorney General’s Office and the Office of Consumer Affairs and Business Regulation. That notification has to state whether the business has a WISP in place at all, so a business without a documented one has far less ground to stand on right at the moment it matters most.
Step 1: Assessment. Identify every place personal information is collected, stored, transmitted, or shared with vendors.
Step 2: Risk Identification. Compare current practices against 201 CMR 17.00 requirements and flag every gap.
Step 3: Implementation. Build or update the WISP, deploy encryption, and set up access controls and vendor agreements.
Step 4: Monitoring. Put ongoing monitoring in place so unauthorized access or unusual activity gets flagged quickly.
Step 5: Continuous Improvement and Compliance. Review and update the WISP at least annually, and after any significant change to systems or vendors.
Most small businesses do not have a full-time compliance officer or security team. That is exactly the gap BHD fills.
BHD has supported small and mid-sized Boston businesses since 2002, with managed cybersecurity covering threat detection, backup and recovery, phishing training, penetration testing, and vendor and access-control reviews. BHD builds and maintains the technical side of 201 CMR 17.00 compliance, the encryption, access controls, monitoring, and the documentation that backs it up, so business owners spend less time parsing state regulations. A few pieces of the WISP stay with the business itself, like naming a security coordinator and setting internal disciplinary policy for violations, and BHD can help set those up too.
Healthcare and Eldercare. Practices and care facilities holding patient and billing information face overlapping HIPAA and 201 CMR 17.00 requirements.
Legal and Professional Services. Law firms and professional service providers storing client Social Security numbers or financial records for case work are directly covered.
Nonprofits. Nonprofits holding donor or employee Social Security numbers are covered under the same standard, even with a lean IT budget.
Biotechnology. Biotech organizations handling employee and research-subject personal information carry compliance obligations alongside their research data safeguards.
Architecture and Engineering. Design firms storing client and employee personal information across large file-sharing and collaboration systems are covered as well.
Hospitality. Hotels and hospitality businesses storing guest payment and identification information carry some of the highest exposure under this law.
Yes. There is no company size exemption. Any business holding personal information on Massachusetts residents is covered, regardless of where the business itself is located.
A written information security program, a documented plan describing how a business protects personal information, including administrative, technical, and physical safeguards.
A resident’s name combined with a Social Security number, driver’s license number, or financial account number.
In most cases, yes. The regulation requires encryption of personal information sent over public networks and stored on portable devices to the extent technically feasible, a standard that covers the overwhelming majority of standard business systems.
You face notification obligations to affected residents, the Attorney General’s Office, and the Office of Consumer Affairs and Business Regulation, plus significantly higher legal and regulatory exposure without a documented program in place.
201 CMR 17.00 compliance is not a project to start after a breach. It is a program that needs to already be working when something goes wrong.
BHD has helped Boston small businesses build a WISP, deploy the right safeguards, and keep both up to date year over year since 2002.
Schedule your free IT assessment from BHD and find out exactly where your business stands.
Want the bigger picture first? Explore compliance solutions designed around Massachusetts requirements.
Call BHD Sales at (617) 850-9499, or reach Client Support anytime at (617) 848-9393.