← Back to Library
201 CMR 17

201 CMR 17.00 (v1.0)

Full Name:
Commonwealth of Massachusetts (201 CMR 17)
Acronym:
201 CMR 17
Type:
US State Standard
Organization:
Commonwealth of Massachusetts
Version:
1
Year Published:
2017
Popularity:
Low

Overview of 201 CMR 17

Massachusetts 201 CMR 17.00, one of the most comprehensive state-level data protection regulations in the United States, mandates that organizations owning, licensing, or maintaining personal information about Massachusetts residents implement comprehensive information security programs. Originally effective in 2010 with updates in 2017, the regulation established security requirements that anticipated many concepts later incorporated into broader privacy laws like GDPR and CCPA. The regulation applies to any organization—regardless of location—that handles personal information of Massachusetts residents, creating nationwide (and international) compliance obligations.

Personal information under 201 CMR 17 includes first name and last name (or first initial and last name) in combination with Social Security numbers, driver's license numbers, financial account numbers, credit/debit card numbers with access codes, or other sensitive identifiers. The regulation requires comprehensive security programs including written information security policies, designated security coordinators, risk assessments, access controls, encryption, monitoring, vendor management, incident response, and employee training. Massachusetts can enforce the regulation through civil penalties, consent decrees, and injunctions for non-compliance.

Core Security Requirements

201 CMR 17 mandates specific technical, administrative, and physical safeguards that organizations must implement to protect personal information.

Written Information Security Program (WISP)

Organizations must develop, implement, and maintain comprehensive written information security programs appropriate to their size, scope, resources, data volume, and identified risks. The WISP must designate employees responsible for security program implementation, identify reasonably foreseeable internal and external risks, assess current safeguards' adequacy, design and implement safeguarding measures, regularly monitor and test safeguards, and update the program as needed to address changes in risks or circumstances. The WISP represents the foundational document demonstrating compliance commitment and approach.

Encryption Requirements

The regulation mandates encryption of personal information stored on laptops and portable devices, transmitted wirelessly, and transmitted across public networks. Organizations must encrypt data both in transit and at rest on mobile devices using industry-standard encryption algorithms (AES-256 recommended). This requirement predated many organizations' encryption practices, forcing widespread adoption of full disk encryption and encrypted communications. Cloud storage of personal information requires encryption, with organizations maintaining encryption key control.

Access Controls and Authentication

Organizations must restrict access to personal information to those with legitimate business need and implement authentication measures including unique user IDs, reasonably complex passwords, password protections preventing unauthorized access, and termination of user access immediately upon employment separation. The regulation requires secure authentication mechanisms appropriate to the risk—systems processing large volumes of personal information warrant multi-factor authentication even though not explicitly mandated. Role-based access control (RBAC) helps organizations enforce need-to-know principles systematically.

Security Monitoring and Intrusion Detection

Organizations must implement up-to-date firewall protection and operating system security patches, monitor systems for unauthorized access to or use of personal information, and implement security system up-to-date patches and virus/malware protection. These requirements necessitate vulnerability management programs, security information and event management (SIEM) for log monitoring, endpoint protection platforms, and network intrusion detection systems. Organizations should establish security operations procedures reviewing alerts and investigating suspicious activities.

Third-Party Service Provider Management

Organizations utilizing third parties to maintain or process personal information must require through contracts that providers implement and maintain appropriate security measures. Contracts should include security requirements at least as protective as the organization's own standards, provisions for security audits and assessments, and requirements for breach notification. Organizations remain responsible for third-party security failures, making vendor due diligence and ongoing monitoring critical compliance components.

Compliance and Enforcement

The Massachusetts Attorney General's Office enforces 201 CMR 17 through investigations, consent decrees, civil penalties, and injunctive relief. Violations can result in penalties up to $5,000 per violation—with each compromised record potentially constituting a separate violation in serious breaches. Beyond regulatory penalties, organizations face civil litigation risk under Massachusetts consumer protection laws when data breaches result from non-compliance.

Organizations should conduct annual compliance assessments evaluating WISP implementation, testing security controls, reviewing vendor contracts and security practices, and validating that safeguards remain appropriate to current risks. Documentation of compliance efforts including policies, risk assessments, vendor agreements, security testing results, and training records provides evidence of good-faith compliance efforts valuable in enforcement proceedings.

Relationship to Other Privacy Laws

201 CMR 17 pioneered comprehensive state-level data protection requirements, influencing subsequent privacy laws including CCPA, GDPR, and other state privacy statutes. Organizations compliant with 201 CMR 17 satisfy many requirements of these broader privacy laws, though specific provisions differ. The regulation's encryption, access control, vendor management, and incident response requirements align with NIST Privacy Framework, ISO 27001, and NIST SP 800-53 privacy and security controls.

Healthcare organizations subject to HIPAA will find significant overlap, as both regulations require comprehensive security programs, encryption, access controls, and vendor management. Financial institutions under GLBA similarly implement comparable controls. Organizations can leverage integrated compliance programs addressing multiple regulations through unified control implementations.

Frequently Asked Questions

Who must comply with 201 CMR 17?

Any organization that owns, licenses, or maintains personal information about Massachusetts residents must comply, regardless of the organization's location. This includes businesses, non-profits, government agencies, and individuals handling personal information in the course of business. Organizations with even one Massachusetts resident's personal information fall under the regulation. Cloud service providers, managed service providers, and contractors processing personal information on behalf of others must also comply or contractually commit to equivalent protections.

What constitutes personal information under 201 CMR 17?

Personal information is a Massachusetts resident's first name and last name (or first initial and last name) combined with: Social Security number, driver's license number, state ID card number, financial account number, credit/debit card number with security code/access code/password allowing account access. The definition is narrower than many privacy laws—it excludes standalone email addresses, phone numbers, or addresses. However, organizations should apply protective measures to broader personal data categories as privacy law trends expand definitions.

Does 201 CMR 17 require data breach notifications?

No, data breach notification is governed by separate Massachusetts law (M.G.L. c. 93H), not 201 CMR 17. However, organizations must maintain incident response capabilities as part of their information security programs. Massachusetts breach notification law requires notification to affected residents, the Attorney General, and in some cases the Director of Consumer Affairs and Business Regulation when breaches involve Massachusetts residents' personal information. Organizations should implement integrated programs addressing both 201 CMR 17 security requirements and breach notification law obligations.

How often should organizations update their WISP?

Organizations must review and update their Written Information Security Programs at least annually or whenever material changes occur to risks, business operations, or technology environments. Best practice involves continuous WISP updates as security enhancements are implemented rather than annual wholesale revisions. Organizations should document WISP review dates, changes made, and rationale for updates. Regular reviews ensure WISPs remain accurate representations of actual security practices rather than outdated documents disconnected from operational reality.

Can organizations use cloud services under 201 CMR 17?

Yes, organizations can use cloud services for personal information storage and processing provided cloud providers implement appropriate safeguards. Organizations must ensure contracts with cloud providers require security measures meeting 201 CMR 17 standards including encryption, access controls, monitoring, and incident notification. Organizations should conduct vendor security assessments, review SOC 2 reports or equivalent attestations, and validate that cloud configurations meet regulatory requirements. Organizations remain liable for vendor security failures, making thorough due diligence essential.