Plenty of Boston businesses find gaps in their 201 CMR 17.00 compliance only after a breach forces the issue. The Massachusetts data security law applies to any organization holding personal information about a Massachusetts resident, which sweeps in most law firms, schools, nonprofits, and SMBs in the city. In August 2025, Attorney General Andrea Campbell secured a $795,000 settlement with a Braintree-based property management company over data security failures and delayed breach notifications.
Cyber insurance carriers now factor compliance into both pricing and renewal decisions, and a public breach notification leaves a footprint that stays on the public record for years. The piece below walks through what the regulation requires and the practical steps to meet it.
What the Massachusetts data security law requires
201 CMR 17.00 sits under M.G.L. Chapter 93H and applies to anyone who owns, licenses, stores, or maintains personal information about a Massachusetts resident. Personal information means a first name (or initial) and last name combined with a Social Security number, driver’s license or state ID number, or financial account or payment card number. The reach extends well beyond Massachusetts borders, so a vendor in California processing payroll for a Boston employer falls under it.
The regulation requires what is known as a Written Information Security Program, or WISP. The program must include administrative, technical, and physical safeguards proportionate to the size and resources of the organization, the volume of personal data handled, and the sensitivity of that data. Enforcement runs through the Attorney General under Chapter 93A, which carries civil penalties of up to $5,000 per violation, plus investigation costs and exposure to consumer lawsuits.
201 CMR 17.00 compliance Boston businesses cannot skip
The list below maps the core obligations under 201 CMR 17.00 to practical steps. None of these are optional, and most can be reviewed and updated without major disruption.
A written information security program (WISP)
Every covered organization needs a WISP in writing, sized appropriately to the business. The Massachusetts WISP documents the administrative, technical, and physical safeguards used to protect personal information, identifies the people and processes involved, and serves as the master reference auditors and the AG’s office ask about first. Generic templates downloaded off the internet rarely hold up under scrutiny.
A designated security coordinator
The regulation obliges you to name one or more employees responsible for maintaining the WISP. For most Boston SMBs, that is an office manager, operations lead, or vCISO partner with both the authority and the time to do the work properly. The coordinator owns updates to the program, oversees training, and is the named point of contact when something goes wrong.
Risk assessment and ongoing monitoring
Identify the foreseeable internal and external risks to personal information across paper records, laptops, cloud systems, and shared drives. Document the controls used to mitigate each risk and the gaps you are working to close. Monitoring cannot stop at the assessment, since new risks appear with every employee change, vendor switch, or system update.
Employee training
Phishing was the primary attack vector in the Peabody Properties case, and similar attacks drive most breaches affecting Boston businesses. Training should cover phishing recognition, password practices, secure handling of personal information, and the disciplinary measures for non-compliance. Annual sessions with periodic refreshers are reasonable for most organizations, with documentation kept for each employee.
Access controls and authentication
Limit access to personal information to employees who need it for their work. Multi-factor authentication is now expected on email, remote access, and any system holding personal data. When someone leaves the organization, accounts must be deactivated promptly to prevent former employees from accessing records they no longer have a right to see.
Encryption of personal data in transit and at rest
Personal information must be encrypted when transmitted across public networks and when stored on laptops or other portable devices. Encryption is also the law’s strongest safe harbor. If properly encrypted data is lost or stolen and the encryption key is not also exposed, the incident may not meet the statutory definition of a breach.
Third-party vendor oversight
Every vendor that touches personal information about Massachusetts residents needs to be selected with reasonable diligence and bound by contract to maintain appropriate safeguards. The list typically includes payroll providers, cloud platforms, IT support firms, and document shredding services. Many compliance failures begin with a vendor breach that no one mapped before signing the contract.
Incident response, secure disposal, and annual review
Document responsive actions for every security incident and run a post-incident review to update business practices. Personal information on retired hardware and paper records must be destroyed so it cannot be reconstructed. Review the WISP at least annually or whenever the business changes in ways that affect security, and keep records of each review on file.
From compliance to stronger Boston IT support
Compliance with 201 CMR 17.00 is a starting point. The same controls that satisfy the regulation also anchor a broader cybersecurity posture, reducing exposure to ransomware, business email compromise, and the operational downtime that follows a breach. Cyber insurance applications now ask about most of the items above by name, and a clean WISP often translates into better terms at renewal.
The regulation also pairs well with the broader Boston IT support decisions a growing organization must make. For teams with internal IT staff, Boston compliance IT support through a co-managed IT partnership often fills the gaps where documentation and ongoing monitoring tend to slip. Documenting safeguards, training employees, and monitoring vendors all need ongoing attention to stay current.
Most 201 CMR 17.00 problems trace back to the same issue. The WISP exists, but training lapsed, vendor contracts were never updated, or the annual review never happened. SecureWon’s team has helped law firms, schools, and nonprofits across the region map their obligations and close the practical gaps. Book a consultation with Craig to review your 201 CMR 17.00 readiness.

