Most Massachusetts business owners learn about the state's data breach notification law the same way: a laptop goes missing, an employee's email account gets phished, or a vendor calls to say their system was compromised, and someone asks, "Do we have to report this?" Usually the answer is yes, and the clock starts immediately.
This guide explains Massachusetts General Laws chapter 93H, "Security Breaches," in plain language for small businesses: what counts as a breach, who has to be notified, what the notices must contain, how the law connects to the state's 201 CMR 17.00 data security regulation, and what a workable incident response plan looks like for a company with five to fifty employees. It is general information, not legal advice. When you have an actual incident, call your attorney and your IT provider on the same day.
Who the Law Applies To
M.G.L. c. 93H applies to any person, business, or agency that owns or licenses data containing personal information about a Massachusetts resident, and separately to anyone who maintains or stores such data on someone else's behalf. Like 201 CMR 17.00, the law follows the resident, not the business: an out-of-state company with Massachusetts customers or employees is covered.
"Personal information" under c. 93H § 1 is a Massachusetts resident's first name and last name (or first initial and last name) in combination with any one or more of:
- Social Security number;
- driver's license number or state-issued identification card number; or
- financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number, or password that would permit access to the resident's financial account.
Information lawfully obtained from publicly available sources or from government records that are lawfully made available to the public is excluded. Note what is not on the list: a name plus an email address, or a name plus a phone number, is not "personal information" under this statute, although it may trigger obligations under other laws or your contracts.
What Counts as a "Breach of Security"
The statute defines a breach of security as the unauthorized acquisition or unauthorized use of unencrypted data, or of encrypted electronic data together with the confidential process or key, that is capable of compromising the security, confidentiality, or integrity of personal information and that creates a substantial risk of identity theft or fraud against a resident.
Three points matter for small businesses:
- Encryption is a real defense. If a lost laptop was fully encrypted and the key was not compromised, the incident generally does not meet the definition. This is why 201 CMR 17.04(5) requires encryption on laptops and portable devices in the first place.
- Good-faith employee access is not a breach as long as the information is not used in an unauthorized manner or subject to further unauthorized disclosure. An employee who opens the wrong file by mistake and closes it is not a reportable event; an employee who copies the customer database to a personal drive is.
- The trigger is broader than "hacked." Notification is required when you know or have reason to know of a breach of security, or when you know or have reason to know that personal information was acquired or used by an unauthorized person or for an unauthorized purpose. A misdirected email with a payroll spreadsheet attached can qualify.
Who You Must Notify
Under c. 93H § 3(b), a business that owns or licenses the data must provide notice, as soon as practicable and without unreasonable delay, to three parties:
- The Massachusetts Attorney General.
- The Director of the Office of Consumer Affairs and Business Regulation (OCABR).
- Each affected Massachusetts resident.
There is no fixed number of days in the statute. "As soon as practicable and without unreasonable delay" is the standard, and the law specifically says notice may not be delayed on the grounds that the total number of affected residents has not yet been determined. If you learn more later, you provide additional notice as soon as practicable.
A business that only maintains or stores the data for someone else (for example, a payroll processor, an IT provider, or a cloud host) must notify the owner or licensor of the data as soon as practicable and without unreasonable delay, and cooperate with them. The owner then handles the notices above.
Law enforcement delay. Under § 4, notice may be delayed if a law enforcement agency determines that it would impede a criminal investigation and has notified the Attorney General in writing. The notice is then made as soon as the agency says it will no longer impede the investigation.
OCABR also notifies the consumer reporting agencies and any other state agencies it deems appropriate, and it publishes a running list of reported breaches. Both the Attorney General's office and OCABR provide a data breach notification form on mass.gov; most small businesses file through those forms.
What the Notice to the State Must Contain
The notice to the Attorney General and OCABR must include, at a minimum:
- the nature of the breach of security or unauthorized acquisition or use;
- the number of Massachusetts residents affected at the time of notification;
- the name and address of the business that experienced the breach;
- the name and title of the person reporting it, and their relationship to the business;
- the type of business (for example, retailer, health care provider, contractor);
- the person responsible for the breach, if known;
- the type of personal information compromised (Social Security number, driver's license number, financial account number, credit or debit card number, or other);
- whether the business maintains a written information security program; and
- the steps the business has taken or plans to take relating to the incident, including updating the written information security program.
That second-to-last item is the direct link to 201 CMR 17.00. The state asks, on the breach form, whether you have a WISP. If the answer is no, you have just documented a separate regulatory violation in the same filing.
If the business that experienced the breach is owned by another company, the notice must also identify the parent or affiliate.
What the Notice to Residents Must Contain
The notice to affected residents is different, and Massachusetts is unusual here. Under § 3(b), the resident notice must include:
- the resident's right to obtain a police report;
- how the resident can request a security freeze on their consumer credit report, what information they must provide, and the fact that there is no charge for a security freeze; and
- any mitigation services the business is providing.
The resident notice must not include the nature of the breach or the number of Massachusetts residents affected. Many businesses copy a template from another state that leads with "on March 3, an attacker gained access to our server, affecting 1,200 customers." In Massachusetts, that language belongs in the notice to the state, not the notice to residents.
Credit monitoring. If the breach involved Social Security numbers, the business must contract with a third party to provide credit monitoring services to affected residents at no cost for at least 18 months (42 months if the business is a consumer reporting agency), and must certify to the Attorney General and OCABR that the services comply with the law.
Form of notice. Notice to residents may be written (mailed) or electronic if it meets federal E-SIGN requirements. Substitute notice, consisting of email where you have an address, a clear and conspicuous posting on your website, and notification to major statewide media, is permitted only if the cost of written notice would exceed $250,000, more than 500,000 residents are affected, or you do not have sufficient contact information.
How the Breach Law and 201 CMR 17.00 Fit Together
Chapter 93H does two things. Section 3 is the breach notification law described above. Section 2 directed OCABR to adopt regulations setting minimum data security standards, and the result was 201 CMR 17.00, the regulation that requires every business holding personal information about Massachusetts residents to maintain a comprehensive written information security program (WISP). Our 201 CMR 17.00 and Massachusetts WISP page covers those requirements in detail.
The two work as a pair:
| Before an incident (201 CMR 17.00) | After an incident (c. 93H § 3) |
|---|---|
| Designate a responsible employee (17.03(2)(a)) | That person leads the response and signs the state notice |
| Encrypt laptops, portable devices, and data in transit (17.04(3), (5)) | Encrypted data with an uncompromised key is generally not a "breach" |
| Monitor systems for unauthorized access (17.04(4)) | Monitoring is how you "know or have reason to know" quickly |
| Document incident response and post-incident review (17.03(2)(j)) | The state notice asks what steps you took and whether you updated the WISP |
| Oversee vendors by contract (17.03(2)(f)) | Vendors who "maintain or store" your data must notify you promptly |
Enforcement for both runs through the Attorney General. Under c. 93H § 6, the Attorney General may bring an action under chapter 93A § 4, which allows injunctive relief, civil penalties of up to $5,000 per violation, and recovery of the costs of investigation and litigation. A related statute, M.G.L. c. 93I, separately requires that paper and electronic records containing personal information be disposed of so the information cannot practicably be read or reconstructed.
Incident Response Basics for a Small Business
You do not need a 40-page plan. You need a one-page procedure that everyone can find, and a few decisions made in advance. Here is the structure we put in place for clients as part of their WISP.
1. Name the people. The designated WISP employee, the owner or manager who can authorize spending, your IT provider's emergency number, your attorney, and your cyber insurance carrier's claims line. Put all five on one card.
2. Contain first, investigate second. Disconnect the affected machine from the network but do not wipe it. Reset the compromised account's password and revoke its sessions. If email is involved, check for forwarding rules and mailbox delegations the attacker may have added. Preserve logs.
3. Determine what data was involved. This is the question that decides whether c. 93H applies. Was there personal information as defined above? Was it encrypted? Whose residents? Your IT provider should be able to tell you what was on the device or in the account and whether encryption was in force. Write down how you reached each conclusion.
4. Decide on notification with counsel. If the definition is met, the notices to the Attorney General, OCABR, and residents go out as soon as practicable. Draft the two notices separately, because their required contents differ. Arrange credit monitoring if Social Security numbers were involved.
5. Notify your insurer. Most cyber policies require prompt notice and may cover forensics, notification costs, and credit monitoring. Late notice can void coverage.
6. Fix the cause and document it. 201 CMR 17.03(2)(j) requires a post-incident review. Record what happened, what was changed (MFA turned on, encryption deployed, vendor replaced, training repeated), and update the WISP. That record is also what you summarize in the "steps taken" section of the state notice.
7. Reduce the odds of a repeat. The controls that prevent most small-business breaches are not exotic: multi-factor authentication on email, full-disk encryption on every laptop, patching, endpoint protection, tested backups, and short, regular staff training on phishing. Every one of these is already required by 201 CMR 17.04.
Common Questions
We only have a few Massachusetts customers. Does this apply? Yes. The law applies to personal information about any Massachusetts resident, with no minimum count.
A vendor lost our data. Who notifies? The vendor, as the party that maintains or stores the data, must notify you promptly. As the owner or licensor, you are responsible for the notices to the state and to residents. Your vendor contract should say who pays.
Do we have to notify if the data was encrypted? Generally not, if the encryption key was not also compromised. Document the encryption status carefully; it is the first thing counsel will ask.
Is there a deadline in days? No. The standard is "as soon as practicable and without unreasonable delay." Waiting to count every affected record is specifically not a valid reason to delay.
What if we don't have a WISP? File the notice anyway, answer the WISP question truthfully, and put a program in place immediately. The absence of a WISP is a separate violation of 201 CMR 17.00, and the state notice asks about it directly.
Where to Go From Here
If you have not had an incident, the best time to prepare is now: confirm you have a WISP that meets 201 CMR 17.00, encrypt every laptop, turn on multi-factor authentication, and write the one-page incident procedure above. If you are dealing with an incident today, contain it, preserve evidence, and get your attorney and your IT provider on the phone.
Power Up Boston has supported businesses across Plymouth, the South Shore, and Greater Boston for 17+ years, and we build these controls into every managed IT relationship. Contact us for a free assessment, or read about our cybersecurity and managed IT services.
