The Massachusetts Data Security Law (201 CMR 17.00): A Compliance Checklist for Small Businesses

Massachusetts data security law 201 CMR 17.00 compliance checklist - Boston Networks

If your business stores the personal information of even one Massachusetts resident — an employee’s Social Security number, a customer’s driver’s license or financial account number — you are subject to 201 CMR 17.00, the Massachusetts data security regulation. It has been on the books since 2010, yet many small businesses have never written the security program the law requires. Here’s a plain-English checklist.

Who the Law Applies To

Every person or company, anywhere, that owns or licenses personal information about a Massachusetts resident. There’s no employee-count minimum and no revenue threshold. If you have W-2 employees in Massachusetts, this means you.

The Core Requirement: A Written Information Security Program (WISP)

The regulation’s centerpiece is a written, regularly audited security program. Your WISP must designate someone responsible for it, identify where personal information lives, assess foreseeable risks, and document the safeguards you’ve chosen. If a breach happens and the Attorney General comes asking, the WISP is the first thing they request.

The Technical Safeguards Checklist

  • Encryption of personal information on laptops, portable devices, and in transit over public networks
  • Up-to-date firewall protection and security patches on systems containing personal information
  • Current anti-malware with regular updates
  • Secure user authentication — unique IDs, strong password controls, and locking accounts after failed attempts
  • Access controls that limit personal information to employees who need it
  • Monitoring for unauthorized use of or access to personal information
  • Employee training on the program, plus disciplinary measures for violations
  • Vendor oversight — verifying that third parties handling your data can protect it, and putting it in the contract

Where Small Businesses Fall Short

In our experience helping companies with regulatory compliance, the most common gaps are missing WISPs, unencrypted laptops, shared logins, and no record of employee training. None of these is expensive to fix — but all of them are expensive to explain after a breach, when fines and mandatory consumer notifications kick in.

How an MSP Makes This Manageable

A good IT partner implements the technical safeguards — managed firewalls, encryption, monitoring, access control — as part of everyday service, documents everything, and runs the security awareness training your WISP promises. Compliance stops being a project and becomes a byproduct of well-run IT.

Get a Compliance Gap Review

Boston Networks helps Massachusetts businesses build and maintain WISPs and the controls behind them. Request a consultation for a practical review of where you stand.

This article is general information, not legal advice — consult your attorney for guidance on your specific obligations.

Get Your Free Guide To Choosing a Managed Services Provider