There is a Massachusetts regulation that applies to almost every business in the state, that most small businesses have never heard of, and that has been in force since 2010.

201 CMR 17.00 requires any person or business that owns or licenses personal information about a Massachusetts resident to develop, implement and maintain a written information security program — a WISP. There is no employee-count minimum. There is no revenue threshold. Sole proprietors are covered (Mass.gov).

We raise it with nearly every new client in Greater Boston, and the reaction is nearly always the same: nobody has ever mentioned this to us.

The scope is wider than people assume

The common assumption is that this is a rule about customer data, so a business without Massachusetts customers is fine.

The rule follows the resident, not the customer. Personal information means a Massachusetts resident’s first name or initial and last name combined with a Social Security number, a driver’s licence or state ID number, or a financial account or card number.

Read that against your own payroll. If you employ one person who lives in Massachusetts, you hold their name alongside a Social Security number and a bank account for direct deposit. You are in scope, on the strength of your own staff records, regardless of where your customers are.

This is why the accounting firms, dental practices, law offices and design studios we work with are all covered, and why so few of them knew it.

What the program has to contain

The regulation is prescriptive in a way that is actually helpful — it tells you what to write down.

A designated coordinator. One named person responsible for maintaining and enforcing the program. In a small business this is usually the owner. It does not require a title, it requires a name.

A risk assessment. Identify where personal information lives in your business, and evaluate the internal and external risks to it. Ongoing, not a one-time exercise. In practice this is the step that produces the surprises — the spreadsheet on a shared drive, the old laptop in a closet, the third-party portal nobody uses anymore but everyone still has access to.

Employee training. Everyone with access to personal information must be trained on your policies and procedures. Written down, with a record of who attended.

Encryption. Personal information transmitted across public networks — email included — and stored on portable devices such as laptops and USB drives must be encrypted. For most modern offices this is a setting to verify rather than a product to purchase, but “we assume it is on” is not the same as having checked.

Vendor oversight. Every vendor that touches personal information about Massachusetts residents has to be selected with reasonable diligence and bound by contract to maintain appropriate safeguards. That list is longer than people expect: payroll provider, cloud platforms, document shredding service — and your IT support company.

That last item is worth sitting with. If you outsource IT, your provider is a vendor in scope of your WISP, and you are supposed to have documented that they maintain appropriate safeguards. Most small businesses have never asked. Most providers have never been asked.

Why it is worth doing before you are asked

The obligation is real, but it is rarely enforcement that brings it up. What brings it up is one of four moments:

  • A breach. Massachusetts requires notice as soon as practicable and without unreasonable delay — not a fixed number of days, which in practice means quickly (Mass.gov). Building a security program while notifying people is the worst possible time to build one.
  • A client’s vendor review. Larger customers increasingly send security questionnaires down their supply chain. The questions map closely to what a WISP already documents.
  • Insurance renewal. Cyber liability applications now ask about written policies, encryption and multi-factor authentication. Wrong answers change the premium or the coverage.
  • A sale or investment. Diligence asks about access control, backups and documented policy. Absence is a finding.

In every one of those, the work is the same. The only variable is whether you did it calmly or under pressure.

What it looks like in practice for a small office

For a business with fewer than about thirty people and no on-premises server, this is usually a few days of work spread over a few weeks, not a project with a budget line.

Find out where personal information actually is — which is mostly Microsoft 365 or Google Workspace, the accounting platform, and whatever industry software you run. Confirm encryption is on for laptops and phones rather than assumed. Turn on multi-factor authentication and enforce it rather than offering it. Remove access for people who left. Write the assessment and the safeguards down in plain language. Train the staff, and record that you did.

The document that comes out of it is not long. Ten to fifteen pages is normal for a small office, and most of the value is in the assessment that produced it rather than the prose.

Where we fit

We are an IT provider, not a law firm, and a WISP has a legal dimension we do not advise on. What we do is the technical half: finding where the data actually lives, closing the gaps the assessment exposes, getting encryption and multi-factor authentication genuinely enforced, and documenting the controls in language your lawyer or insurer can use.

For accounting and tax firms there is a second layer — the IRS requires a written security plan too, and the FTC Safeguards Rule treats tax preparers as financial institutions.

If you hold client or employee data in Massachusetts and have never written any of this down, text us and say what industry you are in. The honest answer is sometimes that you are closer than you think.

Sources

Frequently asked questions

We have four employees. Does this really apply to us?
Yes. The regulation applies to any person or business that owns or licenses personal information about a Massachusetts resident. There is no employee minimum and no revenue floor — sole proprietors are covered. What scales with size is what counts as reasonable, not whether the obligation exists.
We do not have customers in Massachusetts. Are we out of scope?
Probably not, and this is the detail that catches people. The rule follows the resident, not your customer list. If you employ someone who lives in Massachusetts, you hold their name together with a Social Security or account number for payroll — that is personal information about a Massachusetts resident, and it puts you in scope on its own.
Is a downloaded template enough?
A template is a reasonable starting structure and a poor finished document. The rule requires you to identify where personal information actually lives in your business, assess your specific risks, and record the safeguards you chose. A template that names systems you do not use and omits the ones you do is evidence that you did not do the assessment.
What happens if we do not have one?
Nothing, until something else happens. The absence rarely gets discovered on its own — it surfaces after a breach, during a client’s vendor review, when an insurer asks at renewal, or when a larger customer sends a security questionnaire. At that point you are solving two problems instead of one, under time pressure.