1 201 CMR 17.00 Compliance Guide for Boston Small Businesses

If your Boston business stores personal information about Massachusetts residents, a specific state law already applies to you, whether you have read it or not.

201 CMR 17.00, the Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth, requires businesses to have a written information security program in place. Not a policy on a shelf. An actual, working program.

Many small businesses in Boston assume this law only applies to large companies or specific industries. It does not. It applies to any business, of any size, anywhere, that holds personal information on Massachusetts residents.

Quick Answer

  • 201 CMR 17.00 applies to any business holding personal information on Massachusetts residents.
  • It requires a written information security program, known as a WISP.
  • Personal information sent over public networks or stored on portable devices must be encrypted, to the extent technically feasible.
  • Employee training and vendor oversight are required, not optional.
  • There is no minimum company size exemption.
  • A companion law, the state’s Data Breach Notification Law, adds separate reporting duties on top of the WISP requirement if a breach happens.

Why This Matters in 2026

Regulators and plaintiffs’ attorneys both look at 201 CMR 17.00 compliance immediately after a breach involving Massachusetts residents.

A business without a documented WISP at the time of a breach faces a much harder conversation with regulators, insurers, and affected customers than one that can show a working security program was already in place.

What Counts as Personal Information Under This Law

  • A resident’s first and last name combined with a Social Security number
  • A driver’s license or state ID number
  • A financial account, credit, or debit card number

If your business collects any of this from Massachusetts residents, in any format, this law applies to you.

Risks, Requirements, and Compliance Gaps

The written information security program (WISP). Every covered business must maintain a written, comprehensive information security program describing exactly how personal information is protected, accessed, and stored. Massachusetts’s own 201 CMR 17.00 compliance checklist walks through exactly what a WISP needs to cover.

Encryption requirements. Personal information transmitted over public networks, and personal information stored on laptops or other portable devices, must be encrypted to the extent technically feasible. That is the standard the regulation itself uses, and it covers the overwhelming majority of standard business systems.

Access and monitoring controls. Businesses must restrict access to personal information to employees who need it, and must monitor systems for unauthorized access or use.

Vendor oversight. Any third party that handles personal information on your behalf must be contractually required to maintain appropriate safeguards.

How BHD Closes These Gaps

  • Build or update a WISP that reflects how your business actually operates
  • Deploy encryption for data in transit and on portable devices
  • Set up access controls so only the right people reach sensitive data
  • Establish monitoring so unauthorized access gets caught, not discovered months later
  • Review vendor contracts and data-sharing arrangements for gaps
  • Run employee training so the human side of compliance is not the weak point

Tools, Frameworks, and Best Practices

  • Full-disk encryption on every laptop and portable device
  • Encrypted email and file transfer for anything containing personal information
  • Role-based access controls tied to job function
  • Centralized logging and monitoring across systems
  • Documented incident response plan
  • Annual WISP review and update cycle

The Cost of Ignoring 201 CMR 17.00

Building a compliant security program costs a fraction of what a breach costs once regulators, legal counsel, and customer notification requirements enter the picture.

Under Massachusetts’s Data Breach Notification Law, a companion statute that works alongside 201 CMR 17.00, affected Massachusetts residents must be notified, along with the Attorney General’s Office and the Office of Consumer Affairs and Business Regulation. That notification has to state whether the business has a WISP in place at all, so a business without a documented one has far less ground to stand on right at the moment it matters most.

Step-by-Step Compliance Framework

Step 1: Assessment. Identify every place personal information is collected, stored, transmitted, or shared with vendors.

Step 2: Risk Identification. Compare current practices against 201 CMR 17.00 requirements and flag every gap.

Step 3: Implementation. Build or update the WISP, deploy encryption, and set up access controls and vendor agreements.

Step 4: Monitoring. Put ongoing monitoring in place so unauthorized access or unusual activity gets flagged quickly.

Step 5: Continuous Improvement and Compliance. Review and update the WISP at least annually, and after any significant change to systems or vendors.

Why BHD Makes This Manageable

Most small businesses do not have a full-time compliance officer or security team. That is exactly the gap BHD fills.

BHD has supported small and mid-sized Boston businesses since 2002, with managed cybersecurity covering threat detection, backup and recovery, phishing training, penetration testing, and vendor and access-control reviews. BHD builds and maintains the technical side of 201 CMR 17.00 compliance, the encryption, access controls, monitoring, and the documentation that backs it up, so business owners spend less time parsing state regulations. A few pieces of the WISP stay with the business itself, like naming a security coordinator and setting internal disciplinary policy for violations, and BHD can help set those up too.

Real-World Impact Across Industries

Healthcare and Eldercare. Practices and care facilities holding patient and billing information face overlapping HIPAA and 201 CMR 17.00 requirements.

Legal and Professional Services. Law firms and professional service providers storing client Social Security numbers or financial records for case work are directly covered.

Nonprofits. Nonprofits holding donor or employee Social Security numbers are covered under the same standard, even with a lean IT budget.

Biotechnology. Biotech organizations handling employee and research-subject personal information carry compliance obligations alongside their research data safeguards.

Architecture and Engineering. Design firms storing client and employee personal information across large file-sharing and collaboration systems are covered as well.

Hospitality. Hotels and hospitality businesses storing guest payment and identification information carry some of the highest exposure under this law.

FAQs

Yes. There is no company size exemption. Any business holding personal information on Massachusetts residents is covered, regardless of where the business itself is located.

A written information security program, a documented plan describing how a business protects personal information, including administrative, technical, and physical safeguards.

A resident’s name combined with a Social Security number, driver’s license number, or financial account number.

In most cases, yes. The regulation requires encryption of personal information sent over public networks and stored on portable devices to the extent technically feasible, a standard that covers the overwhelming majority of standard business systems.

You face notification obligations to affected residents, the Attorney General’s Office, and the Office of Consumer Affairs and Business Regulation, plus significantly higher legal and regulatory exposure without a documented program in place.

Get Your WISP in Place Before You Need It

201 CMR 17.00 compliance is not a project to start after a breach. It is a program that needs to already be working when something goes wrong.

BHD has helped Boston small businesses build a WISP, deploy the right safeguards, and keep both up to date year over year since 2002.

Schedule your free IT assessment from BHD and find out exactly where your business stands.

Want the bigger picture first? Explore compliance solutions designed around Massachusetts requirements.

Call BHD Sales at (617) 850-9499, or reach Client Support anytime at (617) 848-9393.

Albert Najimy

Albert Najimy

When it comes to technology services and solutions, it's vital to have a knowledgeable and enthusiastic partner who can help clients achieve long-lasting growth using proven IT solutions. Our CEO, Albert, is fully dedicated to assisting clients in improving their technology to gain a competitive edge in their industries. At Boston Helpdesk, Albert Najimy leads a team of dedicated professionals who are focused on delivering exceptional IT services and solutions. With his extensive expertise and practical experience, Albert ensures that clients receive top-quality support and guidance for their IT projects. You can count on Boston Helpdesk to enhance your business systems and stay ahead in today's fiercely competitive business environment.