201 CMR 17.00 is the Massachusetts regulation that made the written information security plan a legal requirement for almost every business in the United States that holds a Massachusetts resident’s data — years before the FTC Safeguards Rule required one of financial institutions.
Issued by the Office of Consumer Affairs and Business Regulation under M.G.L. c. 93H and in force since 1 March 2010, it applies to all persons that own or license personal information about a resident of the Commonwealth, wherever the business is located, and requires them to develop, implement and maintain a comprehensive information security program that is written, contains administrative, technical and physical safeguards, and includes ten specified elements in section 17.03 — from designating an employee to run it, through risk assessment, employee policies, discipline, terminated-employee access, service-provider contracts, physical access, monitoring and annual review, to documenting incident response.
For electronic records it adds the eight computer system security requirements of section 17.04, including encryption of personal information transmitted over public networks or wirelessly and stored on laptops and portable devices. This guide sets out who 201 CMR 17.00 binds and what “personal information” means, the ten WISP elements of 17.03, the eight technical requirements of 17.04, how the regulation lines up with the FTC Safeguards Rule so that one plan satisfies both, and how it is enforced.

Who 201 CMR 17.00 applies to
| Term (17.02) | Definition | Consequence |
|---|---|---|
| Person | A natural person, corporation, association, partnership or other legal entity, other than a Commonwealth agency or political subdivision | Every private business, non-profit and professional practice, in any state |
| Owns or licenses | Receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment | Employers with Massachusetts employees are covered; so are service providers |
| Personal information | A Massachusetts resident’s first name and last name, or first initial and last name, in combination with a Social Security number, a driver’s licence or state-issued ID number, or a financial account number or credit or debit card number (with or without codes) that would permit access to the account — excluding information lawfully obtained from public records | Payroll, HR files, customer payment records and tax data all qualify |
| Service provider | Any person that receives, stores, maintains, processes or is otherwise permitted access to personal information through its provision of services directly to a covered person | Vendors are pulled in by contract under 17.03(2)(f) |
| Breach of security | Unauthorised acquisition or use of unencrypted data, or of encrypted data together with the key, that creates a substantial risk of identity theft or fraud; good-faith acquisition for a lawful purpose is excluded unless the information is misused | The definition the incident-response element of 17.03 is written for |
Section 17.03(1) scales the program to the size, scope and type of business, the resources available, the amount of stored data and the need for security of consumer and employee information — but it does not exempt anyone. A sole practitioner with one Massachusetts client is covered. Our guide to the written information security plan covers the federal ten elements the Massachusetts ten are so often confused with.
The ten WISP elements of 201 CMR 17.03
| Element | 17.03(2) requirement | What it looks like |
|---|---|---|
| (a) | Designating one or more employees to maintain the comprehensive information security program | A named data security coordinator — the Massachusetts counterpart of the federal Qualified Individual |
| (b) | Identifying and assessing reasonably foreseeable internal and external risks to the security, confidentiality and/or integrity of records containing personal information, and evaluating and improving safeguards, including ongoing employee training, employee compliance and means for detecting and preventing security system failures | A written risk assessment reviewed with training and compliance records |
| (c) | Security policies for employees on the storage, access and transportation of records containing personal information outside business premises | Remote work, laptop and paper-file rules |
| (d) | Disciplinary measures for violations of the program rules | A sanctions clause in the policy and the employee handbook |
| (e) | Preventing terminated employees from accessing records containing personal information | Same-day deprovisioning and physical access removal |
| (f) | Overseeing service providers: reasonable steps to select and retain providers capable of maintaining appropriate security measures, and requiring them by contract to implement and maintain such measures | Vendor due diligence and a contractual security clause |
| (g) | Reasonable restrictions on physical access to records, and storage in locked facilities, storage areas or containers | Locked cabinets, restricted rooms, clean desk |
| (h) | Regular monitoring to ensure the program operates as intended, and upgrading safeguards as necessary to limit risks | Log review, spot checks, a monitoring record |
| (i) | Reviewing the scope of the security measures at least annually or whenever there is a material change in business practices that may implicate the security or integrity of records | A dated annual review |
| (j) | Documenting responsive actions taken in connection with any incident involving a breach of security, and mandatory post-incident review of events and actions taken to make changes in business practices | An incident log and a lessons-learned record |
The eight computer system security requirements of 201 CMR 17.04
| Requirement | 17.04 text (condensed) | Practical control |
|---|---|---|
| (1) Secure user authentication | Control of user IDs; a reasonably secure method of assigning and selecting passwords or unique identifier technologies such as biometrics or tokens; secure storage of passwords; access restricted to active users and accounts; lockout after multiple failed attempts | Password policy, MFA, account lockout, no shared or dormant accounts |
| (2) Secure access control | Access to personal information restricted to those who need it for their job duties; unique IDs plus passwords that are not vendor-supplied defaults | Role-based access; default credentials changed |
| (3) Encryption in transit | Encryption of all transmitted records and files containing personal information that travel across public networks, and of all such data transmitted wirelessly | TLS, encrypted email or portals, WPA-secured wireless |
| (4) Monitoring | Reasonable monitoring of systems for unauthorised use of or access to personal information | Logging and review |
| (5) Encryption on portable devices | Encryption of all personal information stored on laptops or other portable devices | Full-disk encryption on laptops, phones, USB media |
| (6) Firewall and patches | Reasonably up-to-date firewall protection and operating system security patches for systems connected to the Internet | Managed firewall; patch cycle |
| (7) Malware protection | Reasonably up-to-date system security agent software with malware protection and current patches and virus definitions, set to receive updates regularly | Endpoint protection with automatic updates |
| (8) Training | Education and training of employees on the proper use of the computer security system and the importance of personal information security | Onboarding and annual training records |
All eight apply “to the extent technically feasible” — a qualification that excuses genuinely infeasible measures, not inconvenient ones, and that the Attorney General reads narrowly for encryption.
201 CMR 17.00 and the FTC Safeguards Rule: one plan for both
| Topic | 201 CMR 17.00 | 16 CFR Part 314 (FTC Safeguards Rule) | One plan covers both by |
|---|---|---|---|
| Who | Anyone holding a Massachusetts resident’s personal information | Financial institutions under FTC jurisdiction, including tax preparers, mortgage brokers, dealers, collection agencies | A financial institution with Massachusetts clients or employees needs both; a non-financial business needs only the state rule |
| Coordinator | One or more designated employees (17.03(2)(a)) | A Qualified Individual, who may be a service provider (314.4(a)) | Naming the Qualified Individual as the 17.03 designee |
| Risk assessment | Required, with training and compliance evaluation (17.03(2)(b)) | Written risk assessment with specified criteria (314.4(b)); writing exempt below 5,000 consumers | One written assessment covering both |
| Technical safeguards | Eight specified in 17.04, including encryption in transit and on portable devices | Access controls, inventory, encryption at rest and in transit, MFA, secure development, disposal, change management, monitoring (314.4(c)) | The federal list is broader; the state list is more specific on portable-device encryption |
| Service providers | Select and retain capable providers; contract for safeguards (17.03(2)(f)) | Select, contract and periodically assess (314.4(f)) | One vendor procedure with periodic assessment |
| Testing | Regular monitoring (17.03(2)(h)) | Continuous monitoring or annual penetration testing and six-monthly vulnerability assessments (314.4(d)) | The federal testing regime satisfies the state monitoring requirement |
| Incident response | Document responsive actions and post-incident review (17.03(2)(j)); breach notice under c. 93H §3 | Written incident response plan (314.4(h)); FTC notice at 500 consumers within 30 days (314.4(j)) | One plan with both notice paths |
| Review | At least annually or on material change (17.03(2)(i)) | Evaluate and adjust in light of testing and changes (314.4(g)); annual report to the board (314.4(i)) | One annual review producing the federal report |
Our guides to the Qualified Individual and to FTC Safeguards Rule breach notification cover the two federal elements with the closest state counterparts.
How 201 CMR 17.00 is enforced
The regulation is issued under M.G.L. c. 93H, and the Attorney General enforces it under c. 93H §6 through the Massachusetts consumer protection statute, c. 93A, which allows civil penalties, injunctions and costs; the breach notification duty in c. 93H §3 — notice to the Attorney General, the Office of Consumer Affairs and Business Regulation and affected residents — is where most enforcement begins, because a breach notice invites the question whether the WISP existed. The Attorney General’s settlements have routinely required the written program, encryption, training and audits that the regulation already demanded. Our guide to FTC Safeguards Rule penalties covers the federal enforcement path that runs alongside for financial institutions.
Frequently asked questions
What is 201 CMR 17.00?
The Massachusetts regulation, in force since 1 March 2010 under M.G.L. c. 93H, requiring every person that owns or licenses personal information about a Massachusetts resident to maintain a written comprehensive information security program with ten specified elements (17.03) and, for electronic records, eight computer system security requirements (17.04).
Does it apply to businesses outside Massachusetts?
Yes. The test is whether the person owns or licenses personal information about a Massachusetts resident — a customer, patient or employee — not where the business is located.
What counts as personal information?
A Massachusetts resident’s first name or initial and last name combined with a Social Security number, a driver’s licence or state ID number, or a financial account or credit or debit card number that would permit access to the account — excluding information lawfully obtained from public records.
Is encryption mandatory?
Section 17.04 requires, to the extent technically feasible, encryption of personal information transmitted across public networks or wirelessly and of all personal information stored on laptops or other portable devices.
Is a 201 CMR 17.00 WISP the same as an FTC Safeguards Rule WISP?
They overlap heavily and one document can satisfy both, but the scopes differ: the state rule covers any business with Massachusetts residents’ data, the federal rule covers financial institutions; the federal rule adds a Qualified Individual, specified testing, a written incident response plan and FTC breach notification at 500 consumers.
Where this leaves you
Treat 201 CMR 17.00 as the floor for any business that touches a Massachusetts resident’s name with a Social Security, licence or account number: a written program with the ten 17.03 elements, the eight 17.04 technical requirements with encryption in transit and on every portable device, a named coordinator, an annual review and a documented incident process — and, for a financial institution, fold the FTC Safeguards Rule’s Qualified Individual, testing, incident response plan and 500-consumer notice into the same document, because the Attorney General and the FTC will each ask to see it.
References
- Mass.gov — 201 CMR 17.00: Standards for the protection of personal information of residents of the Commonwealth — The regulation text, sections 17.01–17.05.
- 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR) — The FTC Safeguards Rule, for the comparison.
More on WISP and the Safeguards Rule
- 201 CMR 17.00 — you are here
- The written information security plan: 10 elements
- Who the FTC Safeguards Rule applies to
- The Qualified Individual
- FTC Safeguards Rule penalties
- WISP for sole practitioners
The written information security plan covering both the 201 CMR 17.03 elements and the 16 CFR 314.4 elements, the 17.04 technical requirements checklist, the risk assessment, the vendor contract clause and the incident and breach-notice procedures are in the WISP Toolkit, or start with the free templates.