Update to Massachusetts Data Security Breach Reporting Law

On January 10, 2019, the Governor signed Chapter 444 of the Acts of 2018 into law, resulting in important amendments to the state data security breach law, Massachusetts General Laws Chapter 93H (“Chapter 93H”).

Chapter 93H governs the breach reporting requirements for any “person” (defined by the statute as “a natural person, corporation, association, partnership, or other legal entity”) who maintains, stores, owns, or licenses “Personal Information” about a Massachusetts resident. Under Chapter 93H, Personal Information includes a Massachusetts resident’s first name or initial and last name, in combination with any one of the following: (a) Social Security Number; (b) driver’s license number or state-issued identification card number; or (c) financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account.

The recent changes to the law strengthen Chapter 93H’s breach reporting provisions, as follows:

A person whose breach of security or other security incident (as defined and described in Chapter 93H) includes residents’ social security numbers must offer such residents free credit monitoring services for at least eighteen months. This credit monitoring cannot be contingent on a resident’s waiver of his or her private right of action.
The breach report to the Attorney General’s Office (“AGO”) and the Office of Consumer Affairs and Business Regulation (“OCABR”) required by Chapter 93H must now include the following additional information that was not previously required:

  • The name and address of the person who experienced the breach of security;
  • The name and title of the person who is reporting the breach of security (if different than the person who experienced the breach), and such person’s relationship to the person who experienced the breach;
  • The type of person who is reporting the breach of security;
  • The person responsible for the breach of security, if known;
  • The type of Personal Information compromised;
  • Whether the person maintains a Written Information Security Program (“WISP”), as is required under Chapter 93H; and
  • A separate certification that the credit monitoring services of the person who experienced the breach comply with the new requirements (see #1 above).

The required breach notice sent to Massachusetts residents under Chapter 93H must now include the following additional information not previously required: (a) a statement that residents will not be charged anything for a security freeze; (b) a description of the mitigation services the person will provide (such as the credit monitoring described in #1 above); and (c) if applicable, the name of the parent organization of the person experiencing the breach of security. A copy of this resident notice must be provided to the AGO and OCABR.

Upon its receipt of a breach notification, OCABR is now obligated to promptly update and amend the information on its website to incorporate the breach information, and to post a copy of the breach notification letter sent to Massachusetts residents. In addition, the amendments make clear that copies of the breach notifications provided to the AGO/OCABR under Chapter 93H are subject to public records requests.
Persons governed by Chapter 93H should ensure that their WISPs and breach notification policies are complete and up-to-date, that they incorporate the amendments to Chapter 93H, and that in case of a breach of Personal Information, their reports and notices are timely and incorporate the required elements. This is especially important for health care providers whose breach notifications may need to comply with both Chapter 93H and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Up-to-date WISPs and breach notification policies are essential, as are timely response and notification in the event of a breach of security.

Please contact me at nick@bostonmit.com or our support team at support@bostonmit.com with any questions or if you need assistance with your WISP by calling our office at 617-322-5155.

Picture of Nicholas Salem

Nicholas Salem

As the CEO of BMIT, a leading managed IT services company, Nick Salem is responsible for providing strategic leadership and direction to the organization. With over 15 years of experience in the IT industry, Nick has a strong track record of driving business growth and improving operational efficiency through the use of technology. https://nicholassalem.com

Free assessment

Not sure where you stand?

Thirty minutes with a senior engineer on your security, backups, and Microsoft 365. Findings in writing.

Keep reading

Two business professionals reviewing a vendor security checklist on a laptop in an office

Third-Party Vendor Risk Is Driving Nearly Half of All Data Breaches

Third-party vendor risk, the exposure created by outside companies and software...

A Boston managed IT partner's weekly, monthly, and quarterly work laid out on a timeline

What a Boston Managed IT Partner Should Actually Be Doing for a 20–50 Person Business

Here is the conversation I have most often with a business...

IT technician checking server hardware in a data center, representing Windows Server 2022 reaching end of mainstream support

Windows Server 2022 End of Mainstream Support: What It Means for Boston Businesses

Windows Server 2022 reaches end of mainstream support on October 13,...

Free technical assessment

Thirty minutes with a senior engineer.

  • Security posture, backups, and Microsoft 365, reviewed live
  • The three fixes that matter most, ranked, with rough effort
  • Findings in writing, and an honest answer on whether you need us

Book your assessment

Next, you pick a time on our calendar. No sales deck.

Prefer the phone? (617) 322-5155