safeguardsmonitor.com/massachusetts-201-cmr-17· printed from the live page · figures carry their own as-of dates
Massachusetts 201 CMR 17.00: The State WISP Law That Reaches Any Firm with Massachusetts Clients
Checked against the primary record: July 19, 2026 · Compliance date: March 1, 2010 (201 CMR 17.05)
The short answer
One Massachusetts client is enough. Under 201 CMR 17.00, a firm that holds personal information about a Massachusetts resident must develop, implement, and maintain a written information security program, wherever the firm sits. The rule has applied since March 1, 2010, it enumerates its required elements, and it reaches a tax practice through its client list, not its office address.
This page explains a Massachusetts regulation as it applies to tax and accounting practices. It's general information, not legal advice for your specific situation. For that, consult a qualified professional.
What does 201 CMR 17.00 require?
201 CMR 17.00 is a binding Massachusetts regulation, issued by the state's Office of Consumer Affairs and Business Regulation under the data security statute, chapter 93H. Its title states the subject plainly: Standards for the Protection of Personal Information of Residents of the Commonwealth (the official text). At its center sits one sentence, worth reading whole:
Primary record
Every person that owns or licenses personal information about a resident of the Commonwealth shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to: (a) the size, scope and type of business of the person obligated to safeguard the personal information under such comprehensive information security program; (b) the amount of resources available to such person; (c) the amount of stored data; and (d) the need for security and confidentiality of both consumer and employee information.
Compliance date March 1, 2010 (201 CMR 17.05) · Verified July 19, 2026
Two phrases in that sentence do the work. "Written in one or more readily accessible parts" means the program is a document you can produce, not a posture. And the appropriateness factors scale it to the firm: a solo practice is not being asked to run an enterprise security office. The regulation then points outward too. The sentence that follows says the safeguards "must be consistent with the safeguards for protection of personal information and information of a similar character set forth in any state or federal regulations by which the person who owns or licenses such information may be regulated." For a tax practice, that federal regulation exists: the federal program's nine elements under the FTC Safeguards Rule. Massachusetts expects the two programs to agree.
Section 17.03(2) then lists what the written program must include. In condensed form (the full text is one click away above):
- (a) One or more employees designated to maintain the program.
- (b) Identify and assess reasonably foreseeable internal and external risks, and evaluate the safeguards against them, including ongoing employee training (temporary and contract employees included), employee compliance, and means for detecting and preventing security system failures.
- (c) Security policies for employees on the storage, access, and transportation of records containing personal information outside business premises.
- (d) Disciplinary measures for violations of the program's rules.
- (e) Prevent terminated employees from accessing records containing personal information.
- (f) Oversee service providers: reasonable steps to select and retain providers capable of maintaining appropriate safeguards, and a contract requiring them to maintain such safeguards.
- (g) Reasonable restrictions upon physical access to records containing personal information, including storage in locked facilities or containers.
- (h) Regular monitoring to ensure the program is operating as intended.
- (i) Review the scope of the security measures at least annually, or whenever a material change in business practices calls for it.
- (j) Document responsive actions taken in connection with any incident involving a breach of security, with a post-incident review.
Count the letters and you get ten requirements, (a) through (j), two of which carry numbered sub-parts: training, compliance, and failure detection under (b), and provider selection plus provider contracts under (f). A count of "12 elements" circulates in the field; the regulation's own lettering is the safer count. OCABR's official compliance checklist doesn't count elements at all. It asks 21 questions about the program and 9 more about computer systems, and it opens with a line worth keeping: "This Checklist is not a substitute for compliance with 201 CMR 17.00."
Is Massachusetts unusual here? In our reading, yes. Several state statutes enumerate example safeguards, New York's SHIELD Act and Oregon's among them. We know of no other state that does what Massachusetts does in a binding regulation: require the program in writing and enumerate both its minimum elements and specific computer-system controls, down to encryption on portable devices. The American Bar Association's survey of state data security laws puts the Massachusetts requirements among "the most stringent information security program requirements" (ABA GPSolo eReport, August 2023). The depth behind our own claim: we checked NCSL's state data security laws survey (updated February 14, 2025) and the ABA overview on July 19, 2026, and found no counter-example at this depth.
Does it apply to firms outside Massachusetts?
The applicability sentence carries no geography test for the firm: "201 CMR 17.00 applies to all persons that own or license personal information about a resident of the Commonwealth" (17.01(2)). The definitions widen the reach further. "Owns or licenses" means "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment" (17.02). Preparing a return for a Massachusetts resident is providing a service while holding exactly that information, so in our reading a practice in Ohio with one Boston client sits inside the definition from the day the client's organizer arrives. Whether the federal rule reaches you is a different question with its own answer: the coverage map, profession by profession. Massachusetts runs on where the data subject lives.
"Personal information" is a defined term, and for a tax practice it is everywhere: a resident's name combined with a Social Security number, a driver's license or state ID number, or a financial account or card number that would permit access to the resident's financial account (17.02). Nearly every Form 1040 pairs a name with a Social Security number on page one. Massachusetts has required this written program since March 1, 2010, and the duty runs on the state's own clock: it stands whether or not the FTC ever calls. A federal WISP is the backbone; the Massachusetts layer is the part firms miss.
The in-scope conclusion above is this page's most consequential legal read, and scope questions are fact-specific: whose information you hold, in what form, under which definitions. Before you rely on an in-scope or out-of-scope answer for your own firm, put the question to a qualified professional.
Does your federal WISP satisfy Massachusetts?
Mostly, and measurably, and the regulation itself invites the comparison: as quoted above, 17.03(1) requires consistency with the federal safeguards that already regulate the firm. So the honest answer is a mapping, not a verdict. The table reads each Massachusetts duty against a federal Safeguards Rule program (16 CFR 314.4) and names what Massachusetts adds. It's a working comparison for a tax practice, not a compliance ruling on any particular plan.
| Massachusetts duty | A federal 314.4 program covers it? | What Massachusetts adds |
|---|---|---|
| Written program, 17.03(1) | Yes at the core: 314.3(a) requires a written program for customer information | Scope: the Massachusetts program covers consumer and employee information alike, paper records included, and turns on residents' data, not on customers |
| Designated employee, 17.03(2)(a) | Yes: the Qualified Individual, 314.4(a) | One or more employees named to maintain the program; the same person can hold both roles, stated in the document |
| Risk assessment, training, failure detection, 17.03(2)(b) | Yes: the written risk assessment, 314.4(b), and training, 314.4(e) | Training expressly includes temporary and contract employees, and the risk work must cover the wider Massachusetts scope |
| Discipline, terminated access, physical restrictions, 17.03(2)(d), (e), (g) | Partly: federal access controls, 314.4(c)(1), include technical and, as appropriate, physical controls | Massachusetts names what the federal text leaves general: disciplinary measures stated in the program, blocking of terminated employees, and locked storage for paper records |
| Service providers, 17.03(2)(f) | Yes: provider selection and contractual commitments, 314.4(f) | The contract clause is explicit: providers must be bound by contract to maintain appropriate safeguards for the personal information |
| Monitoring, review, incident documentation, 17.03(2)(h), (i), (j) | Yes: testing and monitoring, 314.4(d), and program evaluation, 314.4(g) | An explicit floor of a review at least annually, plus documented responsive actions after any incident |
| Computer system requirements, 17.04(1) through (8) | Largely: the 314.4(c) safeguards cover access, authentication, encryption, and monitoring | Named specifics: no vendor-default passwords, account lockout after repeated failed attempts, current patches and malware protection, and the encryption items below |
The encryption rows deserve their own paragraph, because the two regimes cut differently. Massachusetts requires, "to the extent technically feasible," "encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information to be transmitted wirelessly" (17.04(3)), plus "encryption of all personal information stored on laptops or other portable devices" (17.04(5)). The federal element, 314.4(c)(3), is broader on paper, reaching customer information at rest generally, but it carries an alternative-controls valve a Qualified Individual can review and approve. Massachusetts names the laptop in so many words. If a preparer's machine leaves the office unencrypted with client files on it, the Massachusetts text is the one that says so directly.
What has actually happened to tax firms in Massachusetts?
Massachusetts publishes an annual Data Breach Notification Report: a table of every breach notice the state received, with the organization's name, the date, the count of residents affected, and which data classes were exposed (the report archive). We read the two files behind this section in full on July 19, 2026: the 2023 report runs 2,429 numbered rows, and the 2026 file, current through July 17, 2026, runs 1,163. Tax practices appear in both. Here are two rows, read exactly as the record carries them.
At a glance
OCABR Data Breach Report 2023, row 29244: a tax practice under a national brand
- Entity
- Ariana Murrell d/b/a Liberty Tax Service, as the report names it
- Reported
- March 20, 2023 (breach number 29244)
- Breach type
- Both, the report's category for electronic and paper together
- Massachusetts residents affected
- 4,000
- Data classes marked breached
- Social Security numbers, account numbers, driver's licenses, and credit or debit card numbers: every class the 2023 report tracks, marked Yes
What the record teaches: one tax practice can hold four thousand residents' identities across every sensitive class the state tracks, on paper as well as on disk. The firm behind this row is a crime victim, and the row exists because it reported, as the law requires. The lesson is the shape of the exposure, not the name on it.
At a glance
OCABR Data Breach Report 2026, row 2026-261: a tax firm, one data class
- Entity
- H&N Tax, Inc., filed under the report's Financial Services Company category
- Reported
- February 21, 2026 (breach number 2026-261)
- Massachusetts residents affected
- 2,892
- Data classes marked breached
- Social Security numbers. The other tracked classes (medical, financial account, driver's license, credit and debit) are marked No
What the record teaches: one firm, one incident, 2,892 Social Security numbers. For a tax practice the SSN column is the business itself; it sits on nearly every document a preparer touches. And the notice behind this row had to answer a question the statute writes into every Massachusetts breach filing, which is the next point.
Massachusetts wired the WISP question into its breach law. A notice a breached firm sends the attorney general and the director of consumer affairs and business regulation must state, in the statute's words, "whether the person or agency maintains a written information security program" (G.L. c. 93H, section 3(b), clause (viii)). The published annual reports, the ones the two rows above come from, don't carry that field: the 2023 report's columns run from breach number and date through the four data classes, the 2026 file swaps the breach-type column for an organization-type column and adds a medical one, and a WISP column appears in neither. We checked both files in full on July 19, 2026. So every notice behind the rows in these reports had to answer the WISP question, and the public table doesn't show the answers. What stays visible is the duty itself, and one practical truth: the day a firm writes that notice is the worst possible day to be drafting a written information security program for the first time.
How do you extend a federal WISP for Massachusetts?
If your firm already holds a real federal WISP, the Massachusetts layer is an extension pass, not a second program. The regulation's own consistency sentence makes that the intended shape. None of these steps is exotic, and each one closes a named gap from the table above.
- Search your files for Massachusetts, current and former clients alike. The regulation reaches any person that owns or licenses a resident's personal information, defined as "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment" (17.02). A prior-year return prepared for a Massachusetts resident keeps you inside that definition; addresses are the practical search key, residency is what the rule turns on.
- Write Massachusetts into the plan's scope. State that the program covers records containing Massachusetts residents' personal information in any form, paper included, and name the responsible employee under 17.03(2)(a). Your federal Qualified Individual can hold both roles; say so in the document.
- Extend the data inventory to employees. The Massachusetts program protects consumer and employee information alike (17.03(1)), so if you employ a Massachusetts resident, payroll and HR records join the inventory.
- Walk the eight computer-system requirements of 17.04. Most fall out of a real federal program already. The named specifics to confirm: vendor-default passwords replaced, account lockout after repeated failed login attempts, current operating system patches, and up-to-date malware protection.
- Confirm the encryption items and document feasibility. Public-network and wireless transmission (17.04(3)), laptops and portable devices (17.04(5)). The standard is "to the extent technically feasible"; wherever you rely on that phrase, write down why.
- Put the provider clause in the contracts. 17.03(2)(f) requires reasonable selection of service providers and a contract obligating them to maintain appropriate safeguards. Your tax software and cloud storage vendors are the obvious rows in that part of the plan.
- Calendar the annual review and wire in the breach path. Review the security measures at least annually, and on material changes in business practices (17.03(2)(i)); document responsive actions after any incident (17.03(2)(j)). Then put the Massachusetts notice duty inside the plan's incident section: the attorney general, the director of consumer affairs and business regulation, and affected residents, notified "as soon as practicable and without unreasonable delay" (c. 93H, section 3(b)). More than one clock starts that day; the full post-breach sequence is its own page.
Who enforces it, and how?
Enforcement lives in the statute, and it is one sentence: "The attorney general may bring an action pursuant to section 4 of chapter 93A against a person or otherwise to remedy violations of this chapter and for other relief that may be appropriate" (G.L. c. 93H, section 6). Chapter 93A is the state's consumer protection act, so the lever is an attorney general enforcement action.
Two precision notes on that. First, you will meet compliance marketing built around the idea that Massachusetts audits WISPs. We can find no audit program in chapter 93H's notice and enforcement sections, in the regulation's full text, or in OCABR's posted compliance materials; that absence claim was checked against those texts and pages on July 19, 2026. The audit the regulation does mandate is internal: regular monitoring under 17.03(2)(h) and a review of the security measures at least annually under 17.03(2)(i). Second, the state offices a breached firm actually meets are the attorney general and OCABR, on the day its notice arrives, and the two records above are that pipeline's public face.
FAQ
Do you file your WISP with Massachusetts?
No. Nothing in 201 CMR 17.00 requires filing or registering the program with any agency. The duty is to hold the program and keep it current. It surfaces after a breach: a notice under c. 93H, section 3(b) must state "whether the person or agency maintains a written information security program." The first time a regulator reads about your WISP is usually the day you report losing data, which is a strong argument for the answer in that notice being yes.
Is encryption actually mandatory in Massachusetts?
For the named cases, yes, under the regulation's own standard. The computer-system section applies "to the extent technically feasible," and within that standard it requires encryption for records that travel across public networks or wirelessly (17.04(3)) and for personal information stored on laptops or other portable devices (17.04(5)). The definition is technology-neutral: encrypted means "the transformation of data into a form in which meaning cannot be assigned without the use of a confidential process or key" (17.02). Full-disk encryption on a modern laptop meets that plainly, and mainstream operating systems include it.
What if your only Massachusetts data is a former client's?
The definition has no expiration date. A firm "receives, stores, maintains, processes, or otherwise has access to" the information for as long as the records sit in its files, so a former client's data keeps you in scope while you retain it. The regulation sets no retention clock of its own; how long you keep old returns is governed by other obligations. The practical lever is the inventory: know which records you still hold and why, and securely dispose of what nothing requires you to keep. Where that line sits for a specific archive depends on those other obligations, not on this regulation.
Does Massachusetts have penalties for violating 201 CMR 17.00?
Exposure exists through the attorney general path above. By site policy, every penalty figure on this site lives on the one page that carries penalty figures, each with its source and as-of date; this page deliberately carries none.
Where are the official text and the state's checklist?
Three primary stops. The regulation itself is a short read of five sections. OCABR's compliance checklist asks 21 program questions plus 9 computer-system questions. And the annual Data Breach Notification Reports are where this page's records come from. If you read one, read the regulation; the checklist itself opens by saying it "is not a substitute for compliance with 201 CMR 17.00."
The bottom line
Massachusetts wrote the demanding version of the WISP duty: written, enumerated, in force since 2010, and attached to its residents' data wherever that data sits. For a tax practice the arithmetic is simple. If a Massachusetts resident's name and Social Security number are anywhere in your files, this regulation is already yours, and the right response is not a second compliance project. It is one document, built on the federal backbone and extended by the pass above, that can answer every list on this page, including the question every Massachusetts breach notice has to answer.
Next in this guide
NY SHIELD Act for Tax Preparers
The NY SHIELD Act for tax preparers: what GBS 899-bb requires, the small-business test read correctly, and the GLBA deemed-compliance shortcut, from the statute.
Related
- How we verify
The method behind every figure on this site: primary sources, as-of dates, and dated corrections.