HomeInsights › Compliance

Guide · Massachusetts compliance

Massachusetts WISP Requirements: What 201 CMR 17.00 Asks Of You

Short answer: if your business holds a Massachusetts resident’s name together with their Social Security number, driver’s license number, or financial account number , whether they are a customer, a patient, or one of your own employees, Massachusetts regulation 201 CMR 17.00 requires you to maintain a written, comprehensive information security program. It applies regardless of your size, and regardless of whether you are based in Massachusetts.

What the regulation actually is

201 CMR 17.00 is titled Standards for the Protection of Personal Information of Residents of the Commonwealth. It sits under Massachusetts General Laws chapter 93H and has been in force since March 2010. Despite being fifteen years old it remains one of the more demanding state data-security regulations in the country, and a great many small businesses subject to it have never heard of it.

It is not an industry rule. It does not care whether you are a law firm, a landscaping company or a dental practice. The trigger is the data, not the sector.

Who it applies to

Any person or business that owns or licenses personal information about a Massachusetts resident. The regulation defines that narrowly and usefully: a resident’s first name or first initial and last name, combined with any one of the following:

  • Social Security number
  • Driver’s license number or state-issued ID number
  • Financial account number, or credit or debit card number

Two things follow from that definition that surprise people. The first is that your own payroll records qualify. If you have Massachusetts employees, you hold names alongside Social Security numbers and bank details, which puts you in scope even if every customer you have is out of state. The second is that being headquartered elsewhere does not exempt you. The regulation follows the resident, not the business.

What has to be in the program

The word that matters is written. A business with excellent security and nothing on paper does not satisfy this regulation. The program has to be documented, and it has to address a specific set of things:

  • A designated person responsible for maintaining the program.
  • A risk assessment identifying reasonably foreseeable internal and external risks, and an evaluation of how well current safeguards address them.
  • Employee training and disciplinary measures for violations.
  • Access controls limiting personal information to those who genuinely need it, including prompt removal of access for departing staff.
  • Physical safeguards restricting access to records and storage areas.
  • Third-party oversight. You must take reasonable steps to select service providers capable of protecting the data, and contractually require them to do so. Your IT provider, your payroll company and your cloud vendors all fall here.
  • Monitoring to verify the program is working.
  • Annual review, and review whenever your business changes materially.
  • Documented incident response. Post-incident review of any breach, recorded.

The technical controls it depends on

Section 17.04 sets out computer system requirements, to the extent technically feasible. This is the part your IT provider either has already handled or has not:

  • Secure user authentication. Controls on user IDs, passwords, and blocking access after repeated failed attempts.
  • Secure access control. Unique credentials per person, access limited to what each role needs.
  • Encryption of personal information transmitted across public networks or wirelessly.
  • Encryption of personal information stored on laptops and other portable devices. This one is explicit, and it is the requirement most often missed. A single unencrypted laptop in a car is the classic Massachusetts breach.
  • Reasonable monitoring for unauthorized use of or access to personal information.
  • Up-to-date firewall protection for systems connected to the internet.
  • Up-to-date malware protection and security patches, set to receive updates on a reasonably prompt basis.
  • Employee training on the proper use of the computer security system.

Read that list again with your own environment in mind. Full-disk encryption on every laptop, multi-factor authentication, a managed firewall, patching on a schedule, and unique logins per person are not exotic. They are the baseline, and most of them cost nothing beyond the effort of turning them on properly.

What happens if you have a breach without one

Massachusetts breach notification rules under chapter 93H require notifying the Attorney General, the Office of Consumer Affairs and Business Regulation, and the affected residents. The notification to regulators asks what security program you had in place. Answering that question honestly, after the fact, without a WISP, is a considerably worse position than answering it with one — both in terms of enforcement exposure and in terms of what your clients conclude about you.

The practical reality is that the WISP rarely matters until the day it matters enormously.

How to actually get one

There are two halves, and they need different people.

The document is a policy and legal exercise. Templates exist, and a template you have genuinely read, filled in accurately and adopted is far better than nothing. For a practice holding significant volumes of sensitive data, having an attorney review it is money well spent. We do not draft legal documents and would not pretend otherwise.

The controls underneath it are ours. Encryption on every portable device, MFA across email and remote access, unique accounts with least-privilege access, managed firewalls, patch management, monitoring and logging, tested backups, and a documented offboarding process so departing employees actually lose access. We implement those, and we document what protects what, so that when someone asks you to evidence your program you have something real to hand them.

The mismatch we see most often is a business with a WISP document in a drawer and none of the controls it describes. That is arguably worse than having neither, because you have now written down a standard you are demonstrably not meeting.

A short honest disclaimer

We are an IT and security company, not a law firm. Everything above is a plain-language summary of a public regulation, offered so you can tell whether it applies to you. It is not legal advice, and for anything turning on interpretation you want an attorney. What we can do is build and document the technical safeguards the regulation rests on — and tell you honestly which ones you are currently missing.

Ask us for an honest look at where you stand, or read about small business cybersecurity more generally.

Common questions

Yes. There is no employee-count exemption. If you hold a Massachusetts resident’s name together with a Social Security number, driver’s license number or financial account number, you are in scope. Your own payroll records alone are usually enough to put a small business there.

No. The regulation protects Massachusetts residents regardless of where the business holding their data is located. If you have Massachusetts customers or employees whose personal information you hold, it applies to you.

A template you have genuinely read, filled in accurately, and actually implemented is far better than nothing. A template downloaded, left generic and filed away is close to worthless, and arguably harmful, since it documents a standard you are not meeting. For businesses holding significant sensitive data, attorney review is worth the cost.

Encryption of personal information stored on laptops and portable devices. It is stated explicitly in the regulation, it is free to enable on modern Windows and Mac hardware, and we routinely find it switched off across entire fleets.

Yes. The regulation requires you to take reasonable steps to select service providers capable of protecting personal information, and to contractually require them to do so. That includes your IT provider, payroll company and relevant cloud vendors.

We build and document the technical controls a WISP depends on, and we will tell you plainly which ones you are missing. We do not draft the legal document itself — that is properly an attorney’s work, and we would rather say so than sell you something outside our lane.

Related: IT for accounting firms · Small business cybersecurity · Managed IT & support. See all guides and insights.

Questions? Just ask.

Prefer to pick a time? Book an appointment →

Or call (978) 885-1819 — if we’re on a job, leave a message and you’ll hear back the same business day.