Massachusetts Chapter 93H, the state’s data breach notification law, requires any business holding personal information on a Massachusetts resident to notify that resident, the Attorney General, and the Office of Consumer Affairs and Business Regulation (OCABR) as soon as practicable after discovering a breach. There is no employee count or revenue threshold. If you have one employee’s Social Security number or one customer’s credit card number on a server in Woburn or a laptop in Southie, the law applies to you.
- Chapter 93H covers any business, nonprofit, or vendor that owns or licenses a Massachusetts resident’s personal information, regardless of size.
- Notification to the resident, the Attorney General, and OCABR must happen “as soon as practicable and without unreasonable delay” – there’s no fixed day count, but regulators expect days, not months.
- Breaches involving a Social Security number trigger free credit monitoring for the resident for at least 18 months, or 42 months if you’re a consumer reporting agency, under Section 3A.
- Your notice to regulators must describe the breach, the number of residents affected, and whether you had a written information security program in place at the time.
- The global average cost of a data breach hit a record $4.99 million in 2026 according to IBM’s Cost of a Data Breach Report, and small businesses rarely have the cash reserves to absorb legal fees, notification costs, and lost customers on top of that.
Who has to notify under Massachusetts law?
Any “person or agency that owns or licenses” personal information belonging to a Massachusetts resident, which covers most local businesses, nonprofits, medical practices, and law firms, plus any out-of-state vendor holding data on your Massachusetts customers or employees. Personal information under the statute means a resident’s name combined with a Social Security number, driver’s license or state ID number, or a financial account, credit, or debit card number. Losing a spreadsheet of names and emails alone doesn’t trigger the law; losing that spreadsheet with Social Security numbers attached does.
How fast do you actually have to notify people?
Chapter 93H doesn’t give you a countdown clock the way some newer state laws do. The statute’s language is “as soon as practicable and without unreasonable delay,” which sounds vague until you’re the business explaining a six-week gap to the Attorney General’s office. In practice, that phrase gets interpreted as days to a couple of weeks once you’ve confirmed what happened, unless a law enforcement agency asks you to delay notice during an active criminal investigation. Waiting to see if anyone notices is not a strategy regulators accept.
What has to be in the notice?
You’ll actually send two different notices. The one to the Attorney General and OCABR has to include the nature of the breach, the number of Massachusetts residents affected, your business’s name and address, who’s reporting it, the type of data involved, and whether you had a written information security program (WISP) at the time. That last question is not rhetorical. If you don’t already have a written information security program under 201 CMR 17.00, you’ll be putting that gap in writing to the state while you’re trying to limit liability. The notice to the affected resident is different: it explains how to request a police report and a security freeze, but it cannot describe the nature of the breach or the number of people affected, so residents don’t get a roadmap for exploiting the incident further.
What does it cost to get this wrong?
Under Section 6 of the statute, the Attorney General can bring an enforcement action, and Chapter 93A (the state’s consumer protection law) allows affected residents to sue, including for treble damages and attorney’s fees in willful cases, after a required 30-day demand letter. Add in notification costs, forensic investigation, and credit monitoring for every resident whose SSN was exposed, and a breach that started as one phished email account can become a five- or six-figure event for a company with a dozen employees.
What should a Boston small business do before a breach happens?
Write the WISP if you don’t have one; it’s the document the state literally asks about in your breach notice. Know in advance which vendor or attorney you’ll call first, because you’ll have days, not weeks, to assess scope once something looks wrong. Keep an inventory of where Social Security numbers, driver’s license numbers, and payment data actually live, since you can’t assess a breach’s scope if you don’t know what you’re protecting in the first place. And build the response into your business continuity plan rather than improvising it during the incident itself, when adrenaline is a bad substitute for a checklist.
Frequently asked questions
Does Chapter 93H apply to a five-person business?
Yes. Massachusetts law sets no minimum size or revenue for the notification duty. If your business owns or licenses personal information on a Massachusetts resident, the requirement applies whether you have five employees or five hundred.
Do we have to report a breach if no Social Security numbers were involved?
You still have to report a breach involving driver’s license numbers, state ID numbers, or financial account and card numbers combined with a name. Losing names and email addresses alone, without one of those data elements, generally does not trigger the statute, though it may still be worth disclosing for trust reasons.
Can we wait until we fully understand the breach before notifying anyone?
You can take reasonable time to determine scope, but the standard is “as soon as practicable and without unreasonable delay,” not “once we’re completely certain.” Regulators expect notification to move in parallel with your investigation, not after it wraps up.
Does a WISP protect us from having to notify people after a breach?
No. A written information security program reduces your risk of a breach happening and is one of the facts you have to disclose to regulators, but it doesn’t exempt you from notification if a breach occurs anyway.
A ransomware note, a phished admin account, or a stolen laptop can turn into a Massachusetts Chapter 93H notification obligation before lunch. Boston Managed IT offers a free 15-minute Microsoft 365 and security review to check whether your business has a written information security program, where your regulated data actually lives, and whether your account protections would hold up against the kind of breach that starts this clock. Call (617) 322-5155 or visit bostonmit.com/contact to set it up.
— Boston Managed IT