Skip to content
Surf Wiki
Save to docs
law

From Surf Wiki (app.surf) — the open knowledge base

201 CMR 17.00

Massachusetts General Law


Massachusetts General Law

The Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00 require that any companies or persons who store or use personal information (PI) about a Massachusetts resident develop a written, regularly audited plan to protect personal information. Both electronic and paper records will need to comply with the new law. The regulations went into effect on March 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010, and then to March 1, 2010, due to the state of the economy and confusion about the law.

Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00. For example, if a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoid security breach and fines.

According to the regulations, companies will need a written security plan to safeguard their contacts' or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan will need to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

References

References

  1. [http://www.mass.gov/ocabr/government/oca-agencies/dpl-lp/re-compliance-with-201-cmr-1700-standards.html "RE: Compliance with 201 CMR 19:00: Standards for the Protection of Personal Information of Residents of the Commonwealth"] by George K. Weber, Director of the Massachusetts Division of Professional Licensure, on mass.gov, February 2, 2010
  2. [http://www.csoonline.com/article/465629/Why_Mass._CMR_Deadline_Was_Extended Why Mass. 201 CMR 17 Deadline Was Extended] on CSO Online
Info: Wikipedia Source

This article was imported from Wikipedia and is available under the Creative Commons Attribution-ShareAlike 4.0 License. Content has been adapted to SurfDoc format. Original contributors can be found on the article history page.

Want to explore this topic further?

Ask Mako anything about 201 CMR 17.00 — get instant answers, deeper analysis, and related topics.

Research with Mako

Free with your Surf account

Content sourced from Wikipedia, available under CC BY-SA 4.0.

This content may have been generated or modified by AI. CloudSurf Software LLC is not responsible for the accuracy, completeness, or reliability of AI-generated content. Always verify important information from primary sources.

Report