Massachusetts Privacy Law
Massachusetts has no comprehensive consumer privacy statute and has had a prescriptive data-security regulation on the books since 2010, which is close to the inverse of the usual pattern. 201 CMR 17.00 states in regulatory text what most states leave to a reasonableness standard: a written information security program with ten enumerated elements, and eight computer-security requirements including encryption of personal information travelling across public networks and of everything stored on a laptop or portable device. Chapter 93H supplies the breach duty and is one of the few state statutes that requires notice to the Attorney General before notice to consumers, while forbidding the consumer notice from describing the breach. Chapter 93A supplies the remedy, and its combination of mandatory multiple damages and fee-shifting makes Massachusetts unusual in giving private plaintiffs real leverage on facts the Attorney General also pursues.
Sector-Specific Privacy Laws in Massachusetts
Standards for the Protection of Personal Information (201 CMR 17.00)
The regulation applies to every person that owns or licenses personal information about a Massachusetts resident, where “owns or licenses” means receives, stores, maintains, processes or otherwise has access to that information in connection with providing goods or services or in connection with employment — so an employer holding payroll records is squarely within it. Personal information is a resident’s first and last name, or first initial and last name, combined with a Social Security number, a driver’s licence or state identification card number, or a financial account or card number with or without any required security code. Section 17.03(1) requires a comprehensive information security program, written in one or more readily accessible parts, scaled to the size, scope and type of business, the resources available, the amount of stored data, and the need for confidentiality of both consumer and employee information. Section 17.03(2) then enumerates its contents at (a) through (j): designating one or more employees to maintain the program; identifying and assessing foreseeable internal and external risks, with ongoing employee training, employee compliance with policies, and means for detecting and preventing security system failures; security policies for storage, access and transportation of records off the premises; disciplinary measures for violations; preventing terminated employees from accessing records; overseeing service providers by selecting capable ones and requiring safeguards by contract; reasonable restrictions on physical access with storage in locked facilities; regular monitoring; review of the scope of the measures at least annually or on a material change in business practices; and documentation of responsive actions taken on any breach with a mandatory post-incident review. Section 17.04 adds eight computer-system requirements to the extent technically feasible, including secure user-authentication protocols with blocking of access after multiple failed attempts, unique identifications and non-default passwords, encryption of all transmitted records containing personal information travelling across public networks and of all such data transmitted wirelessly, reasonable monitoring for unauthorized access, encryption of all personal information stored on laptops or other portable devices, up-to-date firewall protection and operating-system patches for internet-connected systems, up-to-date malware protection set to receive current updates, and employee education and training. The compliance deadline in § 17.05 was March 1, 2010.
Consumer Protection Act (M.G.L. c. 93A, §§ 4 and 9)
Chapter 93A is the Commonwealth’s unfair-practices statute and carries remedies that separate it from most state analogues. Section 4 governs the Attorney General’s action: the office must notify the target at least five days before commencing it unless a temporary restraining order is sought, and the court may enjoin the practice, order restoration of money or property, and impose a civil penalty of not more than $5,000 for each violation, rising to not more than $10,000 for each violation of an injunction, plus the costs of investigation and litigation including attorney’s fees. Section 9 governs the private action and is the provision that drives private litigation in Massachusetts: any person injured by an unfair or deceptive act may sue in superior court or housing court after sending a written demand for relief at least thirty days before filing; recovery is actual damages or $25, whichever is greater; and the court “shall” award up to three but not less than two times that amount where it finds the practice was a wilful or knowing violation, or where the refusal to grant relief on the demand was made in bad faith. A prevailing petitioner is awarded reasonable attorney’s fees and costs irrespective of the amount in controversy.
Security breaches (M.G.L. c. 93H)
Chapter 93H supplies both the security duty that 201 CMR 17.00 implements and the notification duty. Section 6 provides that the Attorney General may bring an action under § 4 of chapter 93A to remedy violations of the chapter and for other appropriate relief, which is how the regulation’s requirements reach a penalty. Section 3 requires notice to the Attorney General, the Director of Consumer Affairs and Business Regulation, the affected residents, and any consumer reporting agencies and state agencies the Director identifies, as soon as practicable and without unreasonable delay. The regulator notice must carry the nature of the breach, the number of Massachusetts residents affected, the reporting organisation’s name and address, the reporter’s name, title and relationship to the affected entity, the type of entity, the person responsible for the breach if known, the categories of compromised data, whether the organisation maintains a written information security program, and the steps taken or planned. Where credit monitoring is offered, the organisation files a report certifying that the services comply with § 3A.
Massachusetts Wiretap Act as applied to websites (M.G.L. c. 272, § 99)
Section 99 is a criminal statute that also supplies a civil remedy — actual damages but not less than liquidated damages computed at $100 per day of violation or $1,000, whichever is higher, plus punitive damages and attorney’s fees — and it became the vehicle for a wave of website-tracking litigation against Massachusetts businesses. The Supreme Judicial Court resolved the question in Kathleen Vita v. New England Baptist Hospital, SJC-13542, decided October 24, 2024. The plaintiff alleged that two hospitals had used tracking software to collect and transmit her browsing of their public websites to third parties for advertising. She did not allege interception of patient records or of messages to providers. The majority held that interactions with a public website are not “communications” the wiretap act protects, reasoning that “browsing and accessing the information published on a website is significantly different from having a conversation or sending a message to another person”, and applied the rule of lenity to the resulting ambiguity because the statute carries criminal penalties. A justice dissented on the ground that the statutory language was unambiguous.
Data Breach Notification in Massachusetts
Chapter 93H, § 3 inverts the sequence most states use. Notice runs first to the Attorney General and the Director of Consumer Affairs and Business Regulation and only then to the affected residents, and the statute forbids the resident notice from including the nature of the breach or the number of Massachusetts residents affected — the two facts the regulator notice must contain. What the resident notice must carry instead is the categories of personal information compromised, the organisation’s contact details, the toll-free numbers and addresses of the major credit reporting agencies, and the Federal Trade Commission and Attorney General contact details with a statement about identity-theft prevention resources. The definition of “breach of security” at 201 CMR 17.02 turns on substantial risk: it is the unauthorized acquisition or unauthorized use of unencrypted data, or of encrypted data together with the confidential process or key, that is capable of compromising the security, confidentiality or integrity of personal information and that creates a substantial risk of identity theft or fraud against a Massachusetts resident. Good-faith but unauthorized acquisition by an employee or agent for the entity’s lawful purposes is not a breach unless the information is then used or further disclosed without authorisation. Section 6 routes enforcement into chapter 93A, § 4, so a notification failure and a security failure carry the same $5,000-per-violation exposure.
Residents must be notified as soon as practicable and without unreasonable delay. Notice to the Attorney General and the Director of Consumer Affairs and Business Regulation is required before notice to residents, for any breach, with no numeric threshold. Complaints are taken by the Massachusetts Attorney General, which enforces the statute.
How Massachusetts Enforces Its Privacy Laws
Chapter 93H violations are prosecuted under chapter 93A. Chapter 93H, § 6 does not set its own penalty. It provides that the Attorney General may bring an action under § 4 of chapter 93A against a person to remedy violations of the chapter and for other appropriate relief. That routes both a late notification and an inadequate security program into the same civil-penalty schedule: not more than $5,000 for each violation, not more than $10,000 for each violation of an injunction, restoration of money or property, and the costs of investigation and litigation including attorney’s fees. Section 4 also requires the office to give at least five days’ notice of the intended action unless it is seeking a temporary restraining order.
Settlements are entered as consent judgments in Suffolk Superior Court. The office’s data-security matters are resolved by consent judgment filed in Suffolk Superior Court rather than by administrative order, which puts the injunctive terms under a court’s continuing jurisdiction. The recurring terms across recent matters are consistent enough to be read as the office’s standard package: phishing protection software, a vulnerability management program, multi-factor authentication, an asset inventory, an intrusion detection and prevention system, a security incident and event management platform, endpoint protection software, and annual security assessments reported to the Attorney General for three years.
Recent Enforcement in Massachusetts
Comstar, LLC — $515,000 over an ambulance billing vendor’s missing security program. On January 28, 2026 the Attorney General announced a consent judgment filed in Suffolk Superior Court against Comstar, LLC, a Rowley-based ambulance billing vendor, resolving allegations arising from a breach affecting approximately 326,426 Massachusetts residents. The total was $515,000, of which $415,000 is a payment to Massachusetts, with the balance to Connecticut, whose Attorney General joined the matter. The office alleged that Comstar violated the Massachusetts data security regulations and HIPAA by failing to maintain an adequate written information security program to prevent the initial attack, including a lack of employee training and compliance measures. The judgment requires phishing protection software, a vulnerability management program, multi-factor authentication, an asset inventory, an intrusion detection and prevention system, a security incident and event management platform, and endpoint protection software, together with annual security assessments for three years reported to both attorneys general.
Peabody Properties — $795,000 over five breaches and a seven-month notification gap. On August 19, 2025 the Attorney General announced a $795,000 settlement, subject to court approval, with Peabody Properties, Inc., a Braintree property management company. Five separate incidents between November 2019 and September 2021, all beginning with phishing e-mails, exposed Social Security numbers, driver’s licence numbers and bank account information; roughly 14,000 Massachusetts consumers received breach notices. The office alleged violations of the Consumer Protection Act at c. 93A, the data security law at c. 93H, and the data security regulations at 201 CMR 17.00 — specifically that the company delayed notifying the Attorney General’s office and residents, leaving the first two breaches unreported for nearly seven months, and that its cybersecurity protections were insufficient to prevent the unauthorized access. The settlement requires the same package of security measures and three years of annual assessments.
23andMe genetic data — multistate settlement, $387,218 to Massachusetts. The Attorney General joined the multistate settlement with the bankruptcy trustee of 23andMe announced on July 14, 2026 over the October 2023 breach affecting 6.9 million consumers worldwide, including at least 136,761 Massachusetts residents. Massachusetts’s share of the $18 million recovered from available bankruptcy funds is $387,218; a separate class-action settlement accounts for $46.75 million. The multistate investigation identified unreasonable security practices including the absence of safeguards against credential-stuffing attacks such as comparing passwords against lists of known breached passwords or requiring multifactor authentication, inadequate restrictions on login attempts over time, missing logging, monitoring and breach-detection tools, and a failure to investigate unusual login patterns and traffic spikes.
Pending Privacy Legislation
The Massachusetts Data Privacy Act has passed both chambers in different forms and is the furthest-advanced comprehensive privacy bill in any state without one. The Senate passed S.2608 unanimously, 40-0, on September 25, 2025; the bill began as S.2516, was reported favourably from the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity on May 12, 2025, went to Senate Ways and Means, and was substituted as a new draft on the day of passage. The House passed its version 146-0 on June 4, 2026 and returned it to the Senate. The Senate-passed text folds in the core of the Location Shield Act, barring the sale of geolocation data for anyone visiting Massachusetts including those seeking health care, and pairs it with a flat prohibition on selling sensitive data and on selling any minor’s personal data. Enforcement would run through the Attorney General’s office with broad regulatory authority.
Federal Privacy Laws That Apply in Massachusetts
Federal privacy law applies in Massachusetts by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Consumer Protection Act (M.G.L. c. 93A, §§ 4 and 9), which the Massachusetts Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Massachusetts Businesses
With no comprehensive state statute, most privacy obligations on a Massachusetts business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Massachusetts businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Massachusetts itself has none, and any business holding personal information about Massachusetts residents is subject to the state’s breach-notification statute described above.
Massachusetts Privacy Law FAQ
What must a Massachusetts written information security program contain?
When does Massachusetts require encryption?
Does Massachusetts notify the Attorney General before or after notifying consumers?
What are the damages under chapter 93A, and are they discretionary?
Did the Massachusetts wiretap act reach website tracking pixels?
Does the Massachusetts regulation reach employee data as well as customer data?
Has a comprehensive Massachusetts privacy law passed?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- 201 CMR 17.00 — Standards for the Protection of Personal Information of Residents of the Commonwealth regulation
- M.G.L. c. 93H, § 3 — Duty to report known security breach statute
- M.G.L. c. 93H, § 6 — Enforcement statute
- M.G.L. c. 93A, § 4 — Action by attorney general statute
- M.G.L. c. 93A, § 9 — Civil actions and remedies statute
- Kathleen Vita v. New England Baptist Hospital, SJC-13542 (Mass. Oct. 24, 2024) case
- Massachusetts Senate Bill S.2516 — Massachusetts Data Privacy Act legislation
- Massachusetts Senate — Senate passes the Massachusetts Data Privacy Act (S.2608, 40-0) legislation
- Massachusetts Attorney General — $515,000 settlement with ambulance billing vendor Comstar agency
- Massachusetts Attorney General — $795,000 settlement with Peabody Properties agency
- Massachusetts Attorney General — multistate settlement with 23andMe over genetic data breach agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.