Skip to main content
Power Up Boston
Written information security program documentation for a Massachusetts business

201 CMR 17.00 & Massachusetts WISP Requirements

Since 2010, Massachusetts regulation 201 CMR 17.00 has required every business that owns or licenses personal information about a Massachusetts resident to maintain a Written Information Security Program (WISP). That covers almost any company with employees or customers in the Commonwealth. Power Up Boston writes the WISP, implements the technical controls it requires, and keeps it current for businesses across Plymouth, the South Shore, and Greater Boston.

What 201 CMR 17.00 Is and Who It Applies To

201 CMR 17.00, “Standards for the Protection of Personal Information of Residents of the Commonwealth,” was issued by the Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) under the authority of M.G.L. c. 93H, the state's data security and breach notification law. It took effect on March 1, 2010. Its purpose is stated plainly in section 17.01: to establish minimum standards for safeguarding personal information in both paper and electronic records.

The regulation applies to every person or business that owns or licenses personal information about a resident of Massachusetts. “Owns or licenses” is defined broadly in 17.02 to include receiving, storing, maintaining, processing, or otherwise having access to personal information in connection with providing goods or services or with employment. In practice, that means:

  • Any employer with Massachusetts employees (payroll and HR files contain Social Security numbers and bank account numbers).
  • Any business that takes checks, stores card numbers, runs credit checks, or holds customer financial account data.
  • Medical, dental, legal, accounting, insurance, and real estate offices that collect driver's license or SSN data.
  • Contractors, property managers, and service businesses that keep client billing records with account numbers.
  • Out-of-state companies with Massachusetts customers or employees. The rule follows the resident, not your office address.

“Personal information” under 17.02 means a resident's first and last name (or first initial and last name) combined with a Social Security number, a driver's license or state ID number, or a financial account, credit card, or debit card number. If you hold even one record like that, the regulation applies. There is no small-business exemption; instead, 17.03(1) says your safeguards must be appropriate to your size, resources, the amount of data you store, and the need for confidentiality. A five-person office and a 300-person company both need a WISP, but the programs will look different.

Not sure whether 201 CMR 17.00 applies to you?

If you have employees in Massachusetts, it almost certainly does. We'll review what data you hold and tell you exactly what your WISP needs to cover.

The WISP Checklist: What the Program Must Contain

Section 17.03(2) lists the elements every comprehensive information security program must include, “without limitation.” Use this as your checklist.

§ 17.03(2)(a)

Designated Employee

Name one or more employees responsible for maintaining the security program.

§ 17.03(2)(b)

Risk Assessment

Identify and assess reasonably foreseeable internal and external risks to records containing personal information, and evaluate whether current safeguards address them.

§ 17.03(2)(b)(1)

Employee Training

Ongoing training for employees, including temporary and contract workers, plus a means of enforcing compliance with the program.

§ 17.03(2)(c)

Off-Premises Records Policy

Written rules for storing, accessing, and transporting records containing personal information outside the office.

§ 17.03(2)(d)–(e)

Discipline & Terminations

Disciplinary measures for violations, and immediate prevention of access by terminated employees to records with personal information.

§ 17.03(2)(f)

Third-Party Vendor Oversight

Select service providers capable of protecting personal information and require them by contract to implement and maintain appropriate safeguards.

§ 17.03(2)(g)

Physical Access Restrictions

Reasonable restrictions on physical access to records, including how paper and portable media are stored.

§ 17.03(2)(h)–(i)

Monitoring & Annual Review

Regular monitoring to confirm the program is working, upgrades as needed, and a review at least annually or whenever business practices materially change.

§ 17.03(2)(j)

Incident Documentation

Document the actions taken in response to any breach of security and conduct a mandatory post-incident review.

Computer System Security Requirements

If your business stores or transmits personal information electronically, section 17.04 requires the following controls “to the extent technically feasible.” These are the items an IT provider is responsible for, and where most small businesses have gaps.

§ 17.04(1)

Secure user authentication

Controlled user IDs, a secure method of assigning and selecting passwords (or biometrics/tokens), protected password storage, access limited to active accounts, and lockout after repeated failed logins.

§ 17.04(2)

Access control

Access to personal information limited to employees who need it for their jobs; unique IDs and passwords that are not vendor-supplied defaults.

§ 17.04(3)

Encryption in transit

Encryption of all transmitted records and files containing personal information that travel across public networks, and of all such data transmitted wirelessly.

§ 17.04(4)

System monitoring

Reasonable monitoring of systems for unauthorized use of or access to personal information.

§ 17.04(5)

Encryption on portable devices

Encryption of all personal information stored on laptops or other portable devices.

§ 17.04(6)

Firewall & patching

Reasonably up-to-date firewall protection and operating system security patches for any Internet-connected system holding personal information.

§ 17.04(7)

Malware protection

Reasonably up-to-date security agent software with malware protection, patches, and current virus definitions.

§ 17.04(8)

Security training

Education and training of employees on the proper use of the computer security system and the importance of personal information security.

The two encryption requirements, 17.04(3) for data crossing public networks or wireless and 17.04(5) for laptops and portable devices, are the ones businesses most often miss. An unencrypted laptop with a payroll spreadsheet on it is a reportable breach waiting to happen. See our cybersecurity services and backup and disaster recovery pages for how we cover these controls.

Penalties and Enforcement Context

201 CMR 17.00 is enforced by the Massachusetts Attorney General. M.G.L. c. 93H § 6 provides that the Attorney General may bring an action under section 4 of Chapter 93A, the Massachusetts consumer protection statute, to remedy violations. Chapter 93A § 4 allows the court to grant injunctive relief and to impose a civil penalty of up to $5,000 for each violation, and to award the Commonwealth the costs of investigation and litigation, including reasonable attorney's fees.

The regulation also connects directly to the state's breach notification law. When a business reports a breach to the Attorney General and OCABR under c. 93H § 3, the required notice must state whether the business maintains a written information security program and what steps it has taken or plans to take, including updating that program. In other words, the first question the state asks after a breach is whether you had a WISP. Our guide to the Massachusetts data breach notification law walks through that process.

A related statute, M.G.L. c. 93I, governs disposal: paper and electronic records containing personal information must be destroyed so that the data cannot practicably be read or reconstructed. A good WISP covers disposal of old hard drives, copiers, and file boxes as well.

This page summarizes public regulations for general information and is not legal advice. Have your attorney review your WISP and any breach response.

How a WISP Fits With Other Compliance

A WISP is the Massachusetts baseline. If you are also subject to a federal or industry framework, the controls overlap heavily and we build them once:

  • HIPAA for medical, dental, and other covered entities and their business associates: the HIPAA Security Rule risk analysis and the 17.03 risk assessment can share one workpaper.
  • PCI DSS for any business that accepts cards: card data is also “personal information” under 17.02 when tied to a name.
  • CMMC for defense contractors: the Level 1 safeguarding requirements (access control, authentication, malware protection, patching) satisfy most of 17.04.

Because a WISP is required of nearly every Massachusetts employer, it is usually the first compliance document we put in place for a new client, and the other frameworks are layered on top of it.

From Assessment to Annual Review

A WISP is only as good as the controls behind it. We handle both the document and the technology, so what you sign matches what is actually running on your network.

1

Risk Assessment

We map where personal information enters, lives, and leaves your business: payroll, HR files, customer records, payment data, email, laptops, and vendors. The output is the risk assessment 201 CMR 17.03 requires.

2

WISP Document

We draft a WISP that matches how your business actually operates, names your designated employee, and covers every element in 17.03 and 17.04. No boilerplate you can't defend in an audit.

3

Technical Controls

We implement what the document promises: full-disk encryption on laptops, multi-factor authentication, endpoint protection, firewall and patch management, monitoring, and tested backups.

4

Employee Training

Short, practical training on phishing, password hygiene, handling records off-site, and what to do when something looks wrong, with records kept for your file.

5

Annual Review

Each year, or when your business changes, we refresh the risk assessment, update the WISP, re-check vendors, and re-run training so the program stays current.

201 CMR 17.00 and WISP FAQ

What is 201 CMR 17.00?

201 CMR 17.00 is the Massachusetts regulation titled "Standards for the Protection of Personal Information of Residents of the Commonwealth." It was issued by the Office of Consumer Affairs and Business Regulation under M.G.L. c. 93H and has been in effect since March 1, 2010. It requires every person or business that owns or licenses personal information about a Massachusetts resident to develop, implement, and maintain a comprehensive written information security program (WISP).

What is a Massachusetts WISP?

A WISP (Written Information Security Program) is the written set of administrative, technical, and physical safeguards your business uses to protect personal information. Under 201 CMR 17.03 it must be appropriate to the size, scope, and type of your business, the resources available to you, the amount of data you store, and the need to keep both customer and employee information secure. It is a working document, not a one-time form.

Does my business need a WISP if I'm not located in Massachusetts?

Yes, if you own or license personal information about Massachusetts residents. The regulation is keyed to the residence of the person whose data you hold, not to where your business is located. Out-of-state companies with Massachusetts customers or employees are covered.

What counts as "personal information" under 201 CMR 17.00?

A Massachusetts resident's first name and last name (or first initial and last name) in combination with any one or more of: a Social Security number; a driver's license or state-issued ID card number; or a financial account number, credit card number, or debit card number, with or without any required security code or password that would permit access to the account. Information lawfully obtained from publicly available sources or public government records is excluded.

What must a WISP include?

At minimum, 201 CMR 17.03 requires you to designate one or more employees to maintain the program; identify and assess reasonably foreseeable internal and external risks; train employees and enforce compliance; set policies for records taken off-site; discipline violations; cut off access for terminated employees; oversee third-party service providers (including by contract); restrict physical access to records; monitor the program regularly; review it at least annually or whenever business practices change; and document your response to any security incident. Section 17.04 adds the computer-system controls: secure authentication, access control, encryption of personal information sent across public networks or wirelessly and stored on laptops and portable devices, system monitoring, firewalls and patching, up-to-date malware protection, and employee security training.

What are the penalties for not complying with 201 CMR 17.00?

M.G.L. c. 93H § 6 lets the Massachusetts Attorney General enforce the law through Chapter 93A, the state consumer protection statute. That allows the Attorney General to seek injunctive relief, civil penalties of up to $5,000 per violation, and the costs of investigation and litigation, including attorney's fees. If a breach occurs, the lack of a WISP is also a specific question on the breach notification you must file with the state.

How often does a WISP need to be reviewed?

201 CMR 17.03(2)(i) requires reviewing the scope of your security measures at least annually, or whenever there is a material change in business practices that may affect the security of personal information. Most of our clients handle this as a scheduled annual review that also refreshes the risk assessment and training records.

Can Power Up Boston write and implement our WISP?

Yes. We start with a risk assessment of how personal information actually moves through your business, write a WISP that reflects your real operations, and then implement the technical controls the document commits you to: encryption, multi-factor authentication, endpoint protection, monitoring, backups, and access control. We also run the employee training and schedule the annual review. This page is general information, not legal advice; we recommend having your attorney review the final document.

Need a 201 CMR 17.00 Compliant WISP?

We write the program, implement the controls, train your team, and handle the annual review. Free assessment for Massachusetts businesses.

Trusted since 2009 · 5-star rated on Google · On-site support across Plymouth, South Shore, Cape Cod & Greater Boston