HomeInsights › Compliance

Guide · Massachusetts compliance

Massachusetts WISP Requirements: What 201 CMR 17.00 Asks Of You

Short answer: do you keep a Massachusetts resident’s name next to their Social Security number, driver’s license number, or a bank or card number? Then Massachusetts regulation 201 CMR 17.00 applies to you, and you need a written information security program — a WISP. It makes no difference whether that person is a customer, a patient, or someone on your own payroll. It makes no difference how small you are, or whether your business is even based in Massachusetts.

What the regulation actually is

201 CMR 17.00 is titled Standards for the Protection of Personal Information of Residents of the Commonwealth. It sits under Massachusetts General Laws chapter 93H and has been in force since March 2010. It is fifteen years old and still one of the strictest state data-security rules in the country. Most of the small businesses it covers have never heard of it.

It is not an industry rule. It does not care whether you are a law firm, a landscaping company or a dental practice. The trigger is the data, not the sector.

Who it applies to

Any person or business that owns or licenses personal information about a Massachusetts resident. The regulation defines that narrowly and usefully: a resident’s first name or first initial and last name, combined with any one of the following:

  • Social Security number
  • Driver’s license number or state-issued ID number
  • Financial account number, or credit or debit card number

Two things follow from that definition that surprise people. The first is that your own payroll records qualify. If you have Massachusetts employees, you hold names alongside Social Security numbers and bank details, which puts you in scope even if every customer you have is out of state. The second is that being headquartered elsewhere does not exempt you. The regulation follows the resident, not the business.

What has to be in the program

The word that matters is written. A business with excellent security and nothing on paper does not satisfy this regulation. The program has to be documented, and it has to address a specific set of things:

  • A designated person responsible for maintaining the program.
  • A risk assessment. Write down what could realistically go wrong, inside the business and outside it, and how well what you have today handles each one.
  • Employee training, plus real consequences when somebody ignores the rules.
  • Access controls. Personal information reaches only the people who genuinely need it. When somebody leaves, their access goes the same day.
  • Physical safeguards restricting access to records and storage areas.
  • Third-party oversight. You have to check that your vendors can actually protect the data, and put that duty in their contract. This covers your IT provider, your payroll company and every cloud service you use.
  • Monitoring to verify the program is working.
  • Annual review, and review whenever your business changes materially.
  • Documented incident response. Post-incident review of any breach, recorded.

The technical controls it depends on

Section 17.04 sets out computer system requirements, to the extent technically feasible. This is the part your IT provider either has already handled or has not:

  • Secure user authentication. Real controls on usernames and passwords, and a lockout after too many failed attempts.
  • Secure access control. Unique credentials per person, access limited to what each role needs.
  • Encryption in transit. Personal information has to be scrambled whenever it crosses the open internet or travels over Wi-Fi, so that anyone intercepting it gets nothing readable.
  • Encryption of personal information stored on laptops and other portable devices. This one is explicit, and it is the requirement most often missed. A single unencrypted laptop in a car is the classic Massachusetts breach.
  • Monitoring. Something has to be watching for people using or opening personal information when they should not be.
  • Up-to-date firewall protection for systems connected to the internet.
  • Up-to-date malware protection and security patches, set to receive updates on a reasonably prompt basis.
  • Employee training on the proper use of the computer security system.

Read that list again, thinking about your own office. None of it is exotic. Full-disk encryption on every laptop. Multi-factor authentication. A managed firewall. Patching on a schedule. One login per person, never shared. This is the floor, not the ceiling — and most of it costs nothing beyond the work of setting it up properly.

What happens if you have a breach without one

Under chapter 93H a breach has to be reported to three places. The Attorney General. The Office of Consumer Affairs and Business Regulation. And every resident whose information was exposed. That report asks what security program you had. It is a bad moment to have nothing to show. A WISP does not undo a breach, but it changes what regulators do next — and it changes what your clients decide about you.

The practical reality is that the WISP rarely matters until the day it matters enormously.

How to actually get one

There are two halves, and they need different people.

The document is a policy and legal job. Templates exist, and a template you have actually read, filled in honestly and adopted beats having nothing at all. If you hold a lot of sensitive data, paying an attorney to review it is money well spent. We do not draft legal documents, and we are not going to pretend we do.

The controls underneath it are ours. Encryption on every portable device. MFA across email and remote access. One account per person, holding only the access that person needs, which is what least privilege means. Managed firewalls. Patch management. Monitoring and logging. Backups that get tested. And a written offboarding process, so people who leave actually lose access. We implement those, and we document what protects what, so that when someone asks you to evidence your program you have something real to hand them.

The mismatch we see most often is a business with a WISP document in a drawer and none of the controls it describes. That is arguably worse than having neither, because you have now written down a standard you are demonstrably not meeting.

A short honest disclaimer

We are an IT and security company, not a law firm. Everything above is a plain-language summary of a public regulation, offered so you can tell whether it applies to you. It is not legal advice, and for anything turning on interpretation you want an attorney. What we can do is build and document the technical safeguards the regulation rests on — and tell you honestly which ones you are currently missing.

Ask us for an honest look at where you stand, or read about small business cybersecurity more generally.

Common questions

Yes. There is no employee-count exemption. If you hold a Massachusetts resident’s name together with a Social Security number, driver’s license number or financial account number, you are in scope. Your own payroll records alone are usually enough to put a small business there.

No. The regulation protects Massachusetts residents regardless of where the business holding their data is located. If you have Massachusetts customers or employees whose personal information you hold, it applies to you.

A template you have genuinely read, filled in accurately, and actually implemented is far better than nothing. A template downloaded, left generic and filed away is close to worthless, and arguably harmful, since it documents a standard you are not meeting. For businesses holding significant sensitive data, attorney review is worth the cost.

Encryption of personal information stored on laptops and portable devices. It is stated explicitly in the regulation, it is free to enable on modern Windows and Mac hardware, and we routinely find it switched off across entire fleets.

Yes. The regulation says you have to take reasonable steps to pick vendors who can protect personal information. It also says you have to write that duty into their contract. That includes your IT provider, payroll company and relevant cloud vendors.

We build and document the technical controls a WISP depends on, and we will tell you plainly which ones you are missing. We do not draft the legal document itself — that is properly an attorney’s work, and we would rather say so than sell you something outside our lane.

Related: IT for accounting firms · Small business cybersecurity · Managed IT & support. See all guides and insights.

Questions? Just ask.

Prefer to pick a time? Book an appointment →

Or call (978) 885-1819 — if we’re on a job, leave a message and you’ll hear back the same business day.