Massachusetts

Massachusetts Privacy Law

Massachusetts has no comprehensive consumer privacy statute and has had a prescriptive data-security regulation on the books since 2010, which is close to the inverse of the usual pattern. 201 CMR 17.00 states in regulatory text what most states leave to a reasonableness standard: a written information security program with ten enumerated elements, and eight computer-security requirements including encryption of personal information travelling across public networks and of everything stored on a laptop or portable device. Chapter 93H supplies the breach duty and is one of the few state statutes that requires notice to the Attorney General before notice to consumers, while forbidding the consumer notice from describing the breach. Chapter 93A supplies the remedy, and its combination of mandatory multiple damages and fee-shifting makes Massachusetts unusual in giving private plaintiffs real leverage on facts the Attorney General also pursues.

Sector-Specific Privacy Laws in Massachusetts

Standards for the Protection of Personal Information (201 CMR 17.00)

The regulation applies to every person that owns or licenses personal information about a Massachusetts resident, where “owns or licenses” means receives, stores, maintains, processes or otherwise has access to that information in connection with providing goods or services or in connection with employment — so an employer holding payroll records is squarely within it. Personal information is a resident’s first and last name, or first initial and last name, combined with a Social Security number, a driver’s licence or state identification card number, or a financial account or card number with or without any required security code. Section 17.03(1) requires a comprehensive information security program, written in one or more readily accessible parts, scaled to the size, scope and type of business, the resources available, the amount of stored data, and the need for confidentiality of both consumer and employee information. Section 17.03(2) then enumerates its contents at (a) through (j): designating one or more employees to maintain the program; identifying and assessing foreseeable internal and external risks, with ongoing employee training, employee compliance with policies, and means for detecting and preventing security system failures; security policies for storage, access and transportation of records off the premises; disciplinary measures for violations; preventing terminated employees from accessing records; overseeing service providers by selecting capable ones and requiring safeguards by contract; reasonable restrictions on physical access with storage in locked facilities; regular monitoring; review of the scope of the measures at least annually or on a material change in business practices; and documentation of responsive actions taken on any breach with a mandatory post-incident review. Section 17.04 adds eight computer-system requirements to the extent technically feasible, including secure user-authentication protocols with blocking of access after multiple failed attempts, unique identifications and non-default passwords, encryption of all transmitted records containing personal information travelling across public networks and of all such data transmitted wirelessly, reasonable monitoring for unauthorized access, encryption of all personal information stored on laptops or other portable devices, up-to-date firewall protection and operating-system patches for internet-connected systems, up-to-date malware protection set to receive current updates, and employee education and training. The compliance deadline in § 17.05 was March 1, 2010.

Consumer Protection Act (M.G.L. c. 93A, §§ 4 and 9)

Chapter 93A is the Commonwealth’s unfair-practices statute and carries remedies that separate it from most state analogues. Section 4 governs the Attorney General’s action: the office must notify the target at least five days before commencing it unless a temporary restraining order is sought, and the court may enjoin the practice, order restoration of money or property, and impose a civil penalty of not more than $5,000 for each violation, rising to not more than $10,000 for each violation of an injunction, plus the costs of investigation and litigation including attorney’s fees. Section 9 governs the private action and is the provision that drives private litigation in Massachusetts: any person injured by an unfair or deceptive act may sue in superior court or housing court after sending a written demand for relief at least thirty days before filing; recovery is actual damages or $25, whichever is greater; and the court “shall” award up to three but not less than two times that amount where it finds the practice was a wilful or knowing violation, or where the refusal to grant relief on the demand was made in bad faith. A prevailing petitioner is awarded reasonable attorney’s fees and costs irrespective of the amount in controversy.

Security breaches (M.G.L. c. 93H)

Chapter 93H supplies both the security duty that 201 CMR 17.00 implements and the notification duty. Section 6 provides that the Attorney General may bring an action under § 4 of chapter 93A to remedy violations of the chapter and for other appropriate relief, which is how the regulation’s requirements reach a penalty. Section 3 requires notice to the Attorney General, the Director of Consumer Affairs and Business Regulation, the affected residents, and any consumer reporting agencies and state agencies the Director identifies, as soon as practicable and without unreasonable delay. The regulator notice must carry the nature of the breach, the number of Massachusetts residents affected, the reporting organisation’s name and address, the reporter’s name, title and relationship to the affected entity, the type of entity, the person responsible for the breach if known, the categories of compromised data, whether the organisation maintains a written information security program, and the steps taken or planned. Where credit monitoring is offered, the organisation files a report certifying that the services comply with § 3A.

Massachusetts Wiretap Act as applied to websites (M.G.L. c. 272, § 99)

Section 99 is a criminal statute that also supplies a civil remedy — actual damages but not less than liquidated damages computed at $100 per day of violation or $1,000, whichever is higher, plus punitive damages and attorney’s fees — and it became the vehicle for a wave of website-tracking litigation against Massachusetts businesses. The Supreme Judicial Court resolved the question in Kathleen Vita v. New England Baptist Hospital, SJC-13542, decided October 24, 2024. The plaintiff alleged that two hospitals had used tracking software to collect and transmit her browsing of their public websites to third parties for advertising. She did not allege interception of patient records or of messages to providers. The majority held that interactions with a public website are not “communications” the wiretap act protects, reasoning that “browsing and accessing the information published on a website is significantly different from having a conversation or sending a message to another person”, and applied the rule of lenity to the resulting ambiguity because the statute carries criminal penalties. A justice dissented on the ground that the statutory language was unambiguous.

Data Breach Notification in Massachusetts

Chapter 93H, § 3 inverts the sequence most states use. Notice runs first to the Attorney General and the Director of Consumer Affairs and Business Regulation and only then to the affected residents, and the statute forbids the resident notice from including the nature of the breach or the number of Massachusetts residents affected — the two facts the regulator notice must contain. What the resident notice must carry instead is the categories of personal information compromised, the organisation’s contact details, the toll-free numbers and addresses of the major credit reporting agencies, and the Federal Trade Commission and Attorney General contact details with a statement about identity-theft prevention resources. The definition of “breach of security” at 201 CMR 17.02 turns on substantial risk: it is the unauthorized acquisition or unauthorized use of unencrypted data, or of encrypted data together with the confidential process or key, that is capable of compromising the security, confidentiality or integrity of personal information and that creates a substantial risk of identity theft or fraud against a Massachusetts resident. Good-faith but unauthorized acquisition by an employee or agent for the entity’s lawful purposes is not a breach unless the information is then used or further disclosed without authorisation. Section 6 routes enforcement into chapter 93A, § 4, so a notification failure and a security failure carry the same $5,000-per-violation exposure.

Residents must be notified as soon as practicable and without unreasonable delay. Notice to the Attorney General and the Director of Consumer Affairs and Business Regulation is required before notice to residents, for any breach, with no numeric threshold. Complaints are taken by the Massachusetts Attorney General, which enforces the statute.

How Massachusetts Enforces Its Privacy Laws

Chapter 93H violations are prosecuted under chapter 93A. Chapter 93H, § 6 does not set its own penalty. It provides that the Attorney General may bring an action under § 4 of chapter 93A against a person to remedy violations of the chapter and for other appropriate relief. That routes both a late notification and an inadequate security program into the same civil-penalty schedule: not more than $5,000 for each violation, not more than $10,000 for each violation of an injunction, restoration of money or property, and the costs of investigation and litigation including attorney’s fees. Section 4 also requires the office to give at least five days’ notice of the intended action unless it is seeking a temporary restraining order.

Settlements are entered as consent judgments in Suffolk Superior Court. The office’s data-security matters are resolved by consent judgment filed in Suffolk Superior Court rather than by administrative order, which puts the injunctive terms under a court’s continuing jurisdiction. The recurring terms across recent matters are consistent enough to be read as the office’s standard package: phishing protection software, a vulnerability management program, multi-factor authentication, an asset inventory, an intrusion detection and prevention system, a security incident and event management platform, endpoint protection software, and annual security assessments reported to the Attorney General for three years.

Recent Enforcement in Massachusetts

Comstar, LLC — $515,000 over an ambulance billing vendor’s missing security program. On January 28, 2026 the Attorney General announced a consent judgment filed in Suffolk Superior Court against Comstar, LLC, a Rowley-based ambulance billing vendor, resolving allegations arising from a breach affecting approximately 326,426 Massachusetts residents. The total was $515,000, of which $415,000 is a payment to Massachusetts, with the balance to Connecticut, whose Attorney General joined the matter. The office alleged that Comstar violated the Massachusetts data security regulations and HIPAA by failing to maintain an adequate written information security program to prevent the initial attack, including a lack of employee training and compliance measures. The judgment requires phishing protection software, a vulnerability management program, multi-factor authentication, an asset inventory, an intrusion detection and prevention system, a security incident and event management platform, and endpoint protection software, together with annual security assessments for three years reported to both attorneys general.

Peabody Properties — $795,000 over five breaches and a seven-month notification gap. On August 19, 2025 the Attorney General announced a $795,000 settlement, subject to court approval, with Peabody Properties, Inc., a Braintree property management company. Five separate incidents between November 2019 and September 2021, all beginning with phishing e-mails, exposed Social Security numbers, driver’s licence numbers and bank account information; roughly 14,000 Massachusetts consumers received breach notices. The office alleged violations of the Consumer Protection Act at c. 93A, the data security law at c. 93H, and the data security regulations at 201 CMR 17.00 — specifically that the company delayed notifying the Attorney General’s office and residents, leaving the first two breaches unreported for nearly seven months, and that its cybersecurity protections were insufficient to prevent the unauthorized access. The settlement requires the same package of security measures and three years of annual assessments.

23andMe genetic data — multistate settlement, $387,218 to Massachusetts. The Attorney General joined the multistate settlement with the bankruptcy trustee of 23andMe announced on July 14, 2026 over the October 2023 breach affecting 6.9 million consumers worldwide, including at least 136,761 Massachusetts residents. Massachusetts’s share of the $18 million recovered from available bankruptcy funds is $387,218; a separate class-action settlement accounts for $46.75 million. The multistate investigation identified unreasonable security practices including the absence of safeguards against credential-stuffing attacks such as comparing passwords against lists of known breached passwords or requiring multifactor authentication, inadequate restrictions on login attempts over time, missing logging, monitoring and breach-detection tools, and a failure to investigate unusual login patterns and traffic spikes.

Pending Privacy Legislation

The Massachusetts Data Privacy Act has passed both chambers in different forms and is the furthest-advanced comprehensive privacy bill in any state without one. The Senate passed S.2608 unanimously, 40-0, on September 25, 2025; the bill began as S.2516, was reported favourably from the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity on May 12, 2025, went to Senate Ways and Means, and was substituted as a new draft on the day of passage. The House passed its version 146-0 on June 4, 2026 and returned it to the Senate. The Senate-passed text folds in the core of the Location Shield Act, barring the sale of geolocation data for anyone visiting Massachusetts including those seeking health care, and pairs it with a flat prohibition on selling sensitive data and on selling any minor’s personal data. Enforcement would run through the Attorney General’s office with broad regulatory authority.

Federal Privacy Laws That Apply in Massachusetts

Federal privacy law applies in Massachusetts by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Consumer Protection Act (M.G.L. c. 93A, §§ 4 and 9), which the Massachusetts Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Massachusetts Businesses

With no comprehensive state statute, most privacy obligations on a Massachusetts business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Massachusetts businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Massachusetts itself has none, and any business holding personal information about Massachusetts residents is subject to the state’s breach-notification statute described above.

Massachusetts Privacy Law FAQ

What must a Massachusetts written information security program contain?
201 CMR 17.03(2) lists ten elements at (a) through (j): designating one or more employees to maintain the program; identifying and assessing foreseeable internal and external risks with ongoing employee training, policy compliance and means for detecting and preventing security system failures; security policies for storage, access and transportation of records off the premises; disciplinary measures for violations; preventing terminated employees from accessing records; overseeing service providers by selecting capable ones and requiring safeguards by contract; reasonable restrictions on physical access with storage in locked facilities, areas or containers; regular monitoring; review of the scope of the measures at least annually or on a material change in business practices; and documenting responsive actions on any breach together with a mandatory post-incident review.
When does Massachusetts require encryption?
In two situations named in 201 CMR 17.04, both qualified by technical feasibility. Subsection (3) requires encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information transmitted wirelessly. Subsection (5) requires encryption of all personal information stored on laptops or other portable devices. The regulation defines “encrypted” at 17.02 as the transformation of data into a form in which meaning cannot be assigned without the use of a confidential process or key.
Does Massachusetts notify the Attorney General before or after notifying consumers?
Before. Chapter 93H, § 3 requires notice to the Attorney General and the Director of Consumer Affairs and Business Regulation prior to notifying residents, which is the reverse of the sequence in most state statutes. The regulator notice carries the nature of the breach and the number of Massachusetts residents affected; the resident notice is forbidden from containing either of those two facts.
What are the damages under chapter 93A, and are they discretionary?
Partly not. Section 9 sets recovery at actual damages or $25, whichever is greater, and provides that the court may award up to three but not less than two times that amount where it finds a wilful or knowing violation, or where relief was refused in bad faith — so the multiplier has a floor of double damages once the predicate finding is made. A prevailing petitioner is awarded reasonable attorney’s fees and costs irrespective of the amount in controversy. Section 4, which governs the Attorney General’s action, is separate and sets a civil penalty of not more than $5,000 for each violation and not more than $10,000 for each violation of an injunction.
Did the Massachusetts wiretap act reach website tracking pixels?
No. In Kathleen Vita v. New England Baptist Hospital, SJC-13542, decided October 24, 2024, the Supreme Judicial Court held that a plaintiff’s interactions with hospitals’ public websites were not “communications” capable of interception under G. L. c. 272, § 99. The majority reasoned that “browsing and accessing the information published on a website is significantly different from having a conversation or sending a message to another person”, and applied the rule of lenity because the statute is criminal. A justice dissented, arguing the statutory text was unambiguous. The claims at issue did not involve patient records or messages to providers.
Does the Massachusetts regulation reach employee data as well as customer data?
Yes. 201 CMR 17.02 defines “owns or licenses” to include receiving, storing, maintaining, processing or otherwise having access to personal information “in connection with the provision of goods or services or in connection with employment”, and 17.03(1)(d) directs that the program be appropriate to the need for security and confidentiality of “both consumer and employee information”. The regulation also applies to personal information in paper records, not only electronic ones; § 17.01(1) states that it establishes minimum standards for information “contained in both paper and electronic records”, while the eight computer-security requirements of 17.04 apply to those who electronically store or transmit.
Has a comprehensive Massachusetts privacy law passed?
Not yet, but it is closer than in most non-comprehensive states. The Senate passed the Massachusetts Data Privacy Act as S.2608 on September 25, 2025 by a vote of 40-0; the bill originated as S.2516, reported favourably on May 12, 2025 and substituted as a new draft on September 25. The House passed comprehensive legislation 146-0 on June 4, 2026, returning it to the Senate. As passed by the Senate the bill would create rights to know, access, learn who data was shared with, correct, delete, and opt out of targeted advertising and sale; bar the sale of sensitive data including health information, biometrics, precise geolocation, immigration status, sexual orientation, gender identity, race, ethnicity, religion and children’s information; bar the sale of geolocation data for anyone visiting Massachusetts; bar all sale of minors’ personal data and targeted advertising to children; and limit collection to what is reasonably necessary, or strictly necessary for sensitive data. Enforcement would rest with the Attorney General.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.