201 CMR 17.00 is a Massachusetts regulation. It sits under the state's data-security law, M.G.L. c. 93H, and it sets standards for safeguarding personal information about Massachusetts residents. The number — “17.00” — refers to the section of the Massachusetts Code of Regulations where the rules live. If you've been handed a request from your insurer, your bank, or your attorney, you've probably seen reference to it. The regulation describes its scope by reference to who owns or licenses the covered information; whether it applies to your records depends on your business facts and the information you hold.
If the phrase “Written Information Security Program” is new to you, the regulation is the reason it exists. It wrote the rule that produced the document.
It reaches further than Massachusetts
Here's the part that surprises a lot of business owners. 201 CMR 17.00 can reach a business outside Massachusetts when it owns or licenses personal information about a Massachusetts resident. The location of the business alone does not answer whether the regulation applies.
A business may need to look more closely if it keeps records about Massachusetts residents, including customer or employee records. The details of the records, how they are held, and the business's other obligations matter, so counsel should assess the specific situation.
Small service businesses — accountants, bookkeepers, real estate brokerages, insurance agents, and dental offices — may find this regulation relevant when their records meet the definition. That is a fact-specific question, not a conclusion Shieldwise can make for you.
What counts as “personal information”
The regulation defines “personal information” narrowly, and the definition matters because it's what determines whether the rule applies to a given record.
Under 201 CMR 17.00, personal information is a Massachusetts resident's first name (or first initial) plus last name paired with any one of the following:
- a Social Security number
- a driver's license or state identification card number
- a financial account number, together with the security or access code that would let someone use it
- a credit or debit card number, together with the security or access code that would let someone use it
A name by itself isn't covered. A name plus an address isn't covered. The trigger is usually the Social Security number, and that combination — full name plus SSN — is the one most small businesses hold without realizing they're inside the scope.
The official definition is published by the Office of the Massachusetts Attorney General. We keep the citation alongside the regulation text on the sources page; the full text is maintained at mass.gov.
Administrative safeguards — the program around the data
Section 17.03 calls for a Written Information Security Program — the WISP most small businesses have started hearing about. The piece that surprises people is that the regulation lists the things the program has to contain, not a specific format you have to use.
A working program can name a person who is responsible for keeping it current. It can include a risk assessment — a working list of where personal information lives, who can touch it, and what would happen if it walked out the door. It can cover how you oversee vendors and contractors that touch the data, schedule training, and set the cadence at which the program itself is reviewed.
None of these pieces require an IT department. They require a documented program, written in language your team can read.
Technical safeguards — the controls on the systems
Section 17.04 is the part most people think of when they hear “cybersecurity.” The regulation requires reasonable technical controls: unique user accounts for each person who touches the data, strong authentication (which today usually means multi-factor), encryption of personal information both as it sits in storage and as it moves over a network, monitoring that flags unusual activity, and a patch cadence that keeps software current.
For a five-person shop, this doesn't mean buying enterprise tooling. It usually means turning on the controls that come with the software you already pay for — multi-factor on your email, full-disk encryption on the laptops, an offboarding checklist that revokes access the day someone leaves, and a written reminder to install updates.
Physical safeguards — the actual doors and papers
The third family is the easiest to underestimate. The regulation covers the physical world too. Locked offices. Locked filing cabinets. Clean-desk habits. A shredder, or a shredding service. Controls on who walks in the back office as a visitor. And procedures for destroying media — hard drives, photocopier hard disks, old backup tapes — before a device leaves the building.
Paper records are still records. A stack of W-2s on the corner of the desk overnight is the same kind of exposure as an unencrypted laptop — the regulator will look at it the same way.
What “reasonable” actually means
The rule that ties all three families together is “reasonable.” The size of those safeguards has to scale to your business: the scope of what you do, the sensitivity of what you hold, and the resources you actually have. A two-person design studio that holds a single contractor's 1099 information isn't being measured against the same yardstick as a hospital.
What the regulation asks for is a documented, working program — written so an outsider can read it, sized so a small team can actually maintain it.
Where Shieldwise fits in
This is the regulation Shieldwise is built against. If you hold personal information about Massachusetts residents and want a working starting point organized around this source, the intake takes about twenty minutes.
Shieldwise provides document-preparation and workflow tools, not legal advice or attorney representation. This article and the generated working document do not determine whether the regulation applies to your business or whether your program meets a legal obligation; review the result with counsel.
See what it would look like for your business →
When you're ready, see plan options →. The document is built against the published text of 201 CMR 17.00; for your specific facts, contracts, and any material amendments, review with a licensed attorney in your state.