201 CMR 17.00 in plain English

The Massachusetts data-security rule, translated: who it covers, what a WISP actually is, and what a small office has to put in place. Plain-language guide, not legal advice.

What 201 CMR 17.00 actually is

201 CMR 17.00 is the Massachusetts data-security regulation. It has been in force since 2010, and it applies to any business — of any size, based anywhere — that holds personal information about a Massachusetts resident. There is no small-business exemption: a two-person office in Hyannis that keeps client Social Security numbers on file is covered the same way a Boston firm is.

The purpose is plainer than the citation suggests: if you hold information that could be used to steal a person’s identity or money, the Commonwealth expects you to have a written plan for protecting it and a set of technical basics genuinely in place.

What counts as “personal information”

The definition is narrower than most owners fear. Personal information means a resident’s name combined with at least one of: a Social Security number, a driver’s license or state ID number, or a financial account number — a bank account or payment-card number that would give access to money.

A customer list of names and email addresses is not, by itself, covered by this rule. Payroll records are: every employer with W-2 staff holds Social Security numbers. That is why almost every Massachusetts business with employees is in scope, whether or not it thinks of itself as a company that “holds data.”

The WISP: a document, not a product

The centerpiece requirement is a WISP — a written information security program. Despite the acronym, it is not software and it cannot be bought preinstalled. It is a document, and it has to say, in writing:

  • who at your business is responsible for information security — one named person,
  • what personal information you hold and where it actually lives,
  • what could go wrong, and what you do to reduce those risks,
  • the rules your people follow — passwords, access, what may leave the office,
  • what happens when an employee leaves or a laptop goes missing.

The technical basics the rule expects

Alongside the document, the regulation lists requirements for the computers and network that touch personal information. In plain terms:

  • Passwords and access control — unique logins for each person, no shared accounts around sensitive records, and access limited to the people whose jobs need it.
  • Encryption — on laptops and portable drives that hold personal information, and whenever that information travels across public networks or wireless.
  • Current systems — security updates applied to computers and servers, with reasonably up-to-date protection against malicious software.
  • Firewall protection — a real firewall between the internet and any system holding personal information.
  • Watching for trouble — reasonable monitoring, so a break-in can actually be noticed rather than discovered months later.

What a small office actually does Monday morning

Regulators expect the program to match your size — a five-person office’s WISP can be a few honest pages. What it cannot be is nothing. A realistic first pass looks like this:

  • Name the responsible person and start the WISP document — a page of true answers beats a binder of boilerplate.
  • List where personal information really lives: payroll, client files, the scans folder, the old laptop in the closet.
  • Turn on disk encryption for every laptop that could hold that information, and retire the machines that cannot support it.
  • Check the basics: unique logins, a properly configured firewall behind the internet connection, and security updates switched on everywhere.
  • Decide, in writing, how you would notice a break-in — and who gets the call when something looks wrong.

Where we fit — and where we don’t

We are an IT company, not a law firm. The WISP itself is a business and legal document: deciding what you hold, who is responsible, and what your policies say is your work, ideally with your attorney. Plain-language guide, not legal advice.

The technical side is ours. Encryption on laptops, firewalls configured properly, passwords and access brought to order, updates kept current, and systems watched so unauthorized access stands a chance of being noticed — that is what we set up and maintain for Cape Cod offices, quoted in writing before any work starts.

Find out where you stand.

A free IT assessment for your business — plain answers, in plain English.

Book a Free Assessment

30 minutes · No obligation · Response within one business day