Massachusetts data security regulation
201 CMR 17.00, under M.G.L. Chapter 93H
- Applies to
- Every business that owns or licenses personal information about a Massachusetts resident, wherever the business is.
- What it asks
- A written information security program (WISP), access limited to people who need it, secure user authentication, encryption of personal information sent over public networks or stored on laptops and portable devices, and monitoring.
- What the software does
- Permissions by document type and field, multi-factor sign-in, an audit trail, password-protected encrypted ZIP files for email, and reading on your own PC so documents do not travel to be read.