Data Breach Requirements: M.G.L. c. 93H, § 1 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal information” means a resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident:
(a) Social Security number;
(b) Driver’s license number or state-issued identification card number; or
(c) Financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number, or password, that would permit access to a resident’s financial account.
Security Breach Definition
The term “breach of security” means the unauthorized acquisition or unauthorized use of unencrypted data or, encrypted electronic data and the confidential process or key that is capable of compromising the security, confidentiality, or integrity of personal information, maintained by a person or agency that creates a substantial risk of identity theft or fraud against a resident of the commonwealth.
Good Faith Exception
A good faith but unauthorized acquisition of personal information by a person or agency, or employee or agent thereof, for the lawful purposes of such person or agency, is not a breach of security unless the personal information is used in an unauthorized manner or subject to further unauthorized disclosure.
Risk of Harm Analysis
See Security Breach Definition (a substantial risk of identity theft of fraud standard).
Notification Timeline
A person or agency shall provide the breach notice as soon as practicable and without unreasonable delay, when such person or agency (1) knows or has reason to know of a breach of security or (2) when the person or agency knows or has reason to know that the personal information of such resident was acquired or used by an unauthorized person or used for an unauthorized purpose.
Security and Investigation Exceptions
A breach notice may be delayed if a law enforcement agency determines that provision of such notice may impede a criminal investigation and has notified the attorney general in writing thereof and informs the person or agency of such determination. If notice is delayed due to such determination and as soon as the law enforcement agency determines and informs the person or agency that notification no longer poses a risk of impeding an investigation, notice shall be provided, as soon as practicable and without unreasonable delay. The person or agency shall cooperate with law enforcement in its investigation of any breach of security or unauthorized acquisition or use, which shall include the sharing of information relevant to the incident, provided, however, that such disclosure shall not require the disclosure of confidential business information or trade secrets.
A breach notice shall not be delayed on grounds that the total number of residents affected is not yet ascertained. In such case, and where otherwise necessary to update or correct the information required, a person or agency shall provide additional notice as soon as practicable and without unreasonable delay upon learning such additional information.
Notification Content Requirements
The notice to be provided to the resident shall include, but shall not be limited to: (i) the resident’s right to obtain a police report; (ii) how a resident may request a security freeze and the necessary information to be provided when requesting the security freeze; (iii) that there shall be no charge for a security freeze; and (iv) mitigation services to be provided under the law, provided, however, that said notice shall not include the nature of the breach of security or unauthorized acquisition or use, or the number of residents of the commonwealth affected by said breach of security or unauthorized access or use.
If the person or agency that experienced a breach of security is owned by another person or corporation, the notice to the consumer shall include the name of the parent or affiliated corporation.
Delivery Methods
A breach notice may be provided by one of the following methods:
(i) Written notice;
(ii) Electronic notice, if notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or
(iii) Substitute notice, if the person or agency required to provide notice demonstrates that the cost of providing written notice will exceed $250,000, or that the affected class of Massachusetts residents to be notified exceeds 500,000 residents, or that the person or agency does not have sufficient contact information to provide notice.
Substitute Notice
Substitute notice shall consist of all of the following:
(i) Email notice, if the person or agency has email addresses for the members of the affected class of Massachusetts residents;
(ii) Clear and conspicuous posting of the notice on the home page of the person or agency if the person or agency maintains a website; and
(iii) Publication in or broadcast through media or medium that provides notice throughout the commonwealth.
Notice to Government Agencies
A person or agency that owns or licenses data that includes personal information about a resident of the commonwealth, shall provide the breach notice to the attorney general, and the director of the Office of Consumer Affairs and Business Regulation. The notice to be provided to the attorney general and said director, and consumer reporting agencies or state agencies if any, shall include, but not be limited to: (i) the nature of the breach of security or unauthorized acquisition or use; (ii) the number of residents of the commonwealth affected by such incident at the time of notification; (iii) the name and address of the person or agency that experienced the breach of security; (iv) name and title of the person or agency reporting the breach of security, and their relationship to the person or agency that experienced the breach of security; (v) the type of person or agency reporting the breach of security; (vi) the person responsible for the breach of security, if known; (vii) the type of personal information compromised, including, but not limited to, Social Security number, driver’s license number, financial account number, credit or debit card number, or other data; (viii) whether the person or agency maintains a written information security program; and (ix) any steps the person or agency has taken or plans to take relating to the incident, including updating the written information security program. A person who experienced a breach of security shall file a report with the attorney general and the director of the Office of Consumer Affairs and Business Regulation certifying their credit monitoring services comply with section 3A. (See Other Information). Upon receipt of this notice, the director of consumer affairs and business regulation shall identify any relevant consumer reporting agency or state agency, as deemed appropriate by said director, and forward the names of the identified consumer reporting agencies and state agencies to the notifying person or agency.
The person or agency that experienced the breach of security shall provide a sample copy of the notice it sent to consumers to the attorney general and the Office of Consumer Affairs and Business Regulation.
As practicable and as not to impede active investigation by the attorney general or other law enforcement agency, the Office of Consumer Affairs and Business Regulation shall: (i) make available electronic copies of the sample notice sent to consumers on its website and post such notice within 1 business day upon receipt from the person that experienced a breach of security; (ii) update the breach of security notification report on its website as soon as practically possible after the information has been verified by said office but not more than 10 business days after receipt unless the information provided is not verifiable; provided, however, that the office shall post said notice as soon as verified; (iii) amend, on a recurring basis, the breach of security notification report to include new information discovered through the investigation process or new subsequent findings from a previously reported breach of security; and (iv) instruct consumers on how they may file a public records request to obtain a copy of the notice provided to the attorney general and said director from the person who experienced a breach of security.
Consumer Reporting Agencies
Such person or agency shall, as soon as practicable and without unreasonable delay, also provide the breach notice to the consumer reporting agencies and state agencies identified by the director of the Office of Consumer Affairs and Business Regulation.
Preemption and Compliance
This law does not relieve a person or agency from the duty to comply with requirements of any applicable general or special law or federal law regarding the protection and privacy of personal information provided, however, a person who maintains procedures for responding to a breach of security pursuant to federal laws, rules, regulations, guidance, or guidelines, is deemed to be in compliance with this chapter. A person is deemed to be in compliance if he or she notifies affected Massachusetts residents in accordance with the maintained or required procedures when a breach occurs and also notifies the attorney general and the director of the Office of Consumer Affairs and Business Regulation of the breach as soon as practicable and without unreasonable delay following the breach. The notice to be provided to the attorney general and the director of the Office of Consumer Affairs and Business Regulation shall consist of, but not be limited to, any steps the person or agency has taken or plans to take relating to the breach pursuant to the applicable federal law, rule, regulation, guidance, or guidelines. If said person or agency does not comply with applicable federal laws, rules, regulations, guidance or guidelines, then he or she shall be subject to the provisions of this chapter.
Data Processor Obligations
A person or agency that maintains or stores, but does not own or license data that includes personal information about a resident of the commonwealth, shall provide notice, as soon as practicable and without unreasonable delay, when such person or agency (1) knows or has reason to know of a breach of security or (2) when the person or agency knows or has reason to know that the personal information of such resident was acquired or used by an unauthorized person or used for an unauthorized purpose, to the owner or licensor in accordance with this chapter. In addition to providing notice as provided herein, such person or agency shall cooperate with the owner or licensor of such information. Such cooperation shall include, but not be limited to, informing the owner or licensor of the breach of security or unauthorized acquisition or use, the date or approximate date of such incident, and the nature thereof, and any steps the person or agency has taken or plans to take relating to the incident, except that such cooperation shall not be deemed to require the disclosure of confidential business information or trade secrets, or to provide notice to a resident who may have been affected by the breach of security or unauthorized acquisition or use.
Other Information
§ 3A. Breaches of security including Social Security numbers; offer of credit monitoring services required:
(a) If a person knows or has reason to know that said person experienced an incident that requires breach notice and such breach of security includes a Social Security number, the person shall contract with a third party to offer to each resident whose Social Security number was disclosed in the breach of security or is reasonably believed to have been disclosed in the breach of security, credit monitoring services at no cost to said resident for a period of not less than 18 months. However, if the person who has experienced a breach of security is a consumer reporting agency, then said agency shall contract with a third party to offer each resident whose Social Security number was disclosed in the breach of security or is reasonably believed to have been disclosed in the breach of security, credit monitoring services at no cost to such resident for a period of not less than 42 months. Said contracts shall not include reciprocal agreements for services in lieu of payment or fees. The person or agency shall provide all information necessary for the resident to enroll in credit monitoring services and shall include information on how the resident may place a security freeze on the resident’s consumer credit report.
(b) A person that experienced a breach of security shall not require a resident to waive the resident’s right to a private right of action as a condition of the offer of credit monitoring services.
Data Disposal and Security: M.G.L. ch. 93I, §§ 1-2; ch. 93H, § 2; 201 Mass. Code Regs. 17.01-05.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal information” means a resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to the resident:-
(a) Social Security number;
(b) Driver’s license number or Massachusetts identification card number;
(c) Financial account, credit, or debit card number, with or without any required security code, access code, personal identification number, or password that would permit access to a resident’s financial account; or
(d) A biometric indicator.
Written Policies
See Data Disposal (third party’s shall implement and monitor compliance with policies and procedures).
Data Disposal
When disposing of records, each agency or person shall meet the following minimum standards for proper disposal of records containing personal information:
(a) Paper documents containing personal information shall be either redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed;
(b) Electronic media and other non-paper media containing personal information shall be destroyed or erased so that personal information cannot practicably be read or reconstructed.
Any agency or person disposing of personal information may contract with a third party to dispose of personal information in accordance with this chapter. Any third party hired to dispose of material containing personal information shall implement and monitor compliance with policies and procedures that prohibit unauthorized access to or acquisition or use of personal information during the collection, transportation, and disposal of personal information.
Key Terms
The term “personal information” means a Massachusetts resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident:
(a) Social Security number;
(b) Driver’s license number or state-issued identification card number; or
(c) Financial account, credit, or debit card number, with or without any required security code, access code, personal identification number, or password, that would permit access to a resident’s financial account.
Security Requirements
Every person that owns or licenses personal information about a resident of the commonwealth shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to:
(a) The size, scope, and type of business of the person obligated to safeguard the personal information under such comprehensive information security program;
(b) The amount of resources available to such person;
(c) The amount of stored data; and
(d) The need for security and confidentiality of both consumer and employee information.
The safeguards contained in such a program must be consistent with the safeguards for protection of personal information and information of a similar character set forth in any state or federal regulations by which the person who owns or licenses such information may be regulated.
Written Policies
Every comprehensive information security program shall include:
(a) Designating one or more employees to maintain the comprehensive information security program;
(b) Identifying and assessing reasonably foreseeable internal and external risks to the security, confidentiality, and/or integrity of any electronic, paper or other records containing personal information, and evaluating and improving, where necessary, the effectiveness of the current safeguards for limiting such risks, including but not limited to: 1. ongoing employee (including temporary and contract employee) training; 2. employee compliance with policies and procedures; and 3. means for detecting and preventing security system failures.
(c) Developing security policies for employees relating to the storage, access, and transportation of records containing personal information outside of business premises.
(d) Imposing disciplinary measures for violations of the comprehensive information security program rules.
(e) Preventing terminated employees from accessing records containing personal information.
(f) Oversee service providers, by: 1. Taking reasonable steps to select and retain third-party service providers that are capable of maintaining appropriate security measures to protect such personal information consistent with 201 CMR 17.00 and any applicable federal regulations; and 2. Requiring such third-party service providers by contract to implement and maintain such appropriate security measures for personal information; provided, however, that until March 1, 2012, a contract a person has entered into with a third-party service provider to perform services for said person or functions on said person’s behalf satisfies the provisions of 201 CMR 17.03(2)(f)2, even if the contract does not include a requirement that the third-party service provider maintain such appropriate safeguards, as long as said person entered into the contract no later than March 1, 2010.
(g) Reasonable restrictions upon physical access to records containing personal information, and storage of such records and data in locked facilities, storage areas or containers.
(h) Regular monitoring to ensure that the comprehensive information security program is operating in a manner reasonably calculated to prevent unauthorized access to or unauthorized use of personal information; and upgrading information safeguards as necessary to limit risks.
(i) Reviewing the scope of the security measures at least annually or whenever there is a material change in business practices that may reasonably implicate the security or integrity of records containing personal information.
(j) Documenting responsive actions taken in connection with any incident involving a breach of security, and mandatory post-incident review of events and actions taken, if any, to make changes in business practices relating to protection of personal information.
Computer System Requirements
Every person that owns or licenses personal information about a resident of the commonwealth and electronically stores or transmits such information shall include in its written, comprehensive information security program the establishment and maintenance of a security system covering its computers, including any wireless system, that, at a minimum, and to the extent technically feasible, shall have the following elements:
(1) Secure user authentication protocols including: (a) control of user IDs and other identifiers; (b) a reasonably secure method of assigning and selecting passwords, or use of unique identifier technologies, such as biometrics or token devices; (c) control of data security passwords to ensure that such passwords are kept in a location and/or format that does not compromise the security of the data they protect; (d) restricting access to active users and active user accounts only; and (e) blocking access to user identification after multiple unsuccessful attempts to gain access or the limitation placed on access for the particular system;
(2) Secure access control measures that: (a) restrict access to records and files containing personal information to those who need such information to perform their job duties; and (b) assign unique identifications plus passwords, which are not vendor supplied default passwords, to each person with computer access, that are reasonably designed to maintain the integrity of the security of the access controls;
(3) Encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information to be transmitted wirelessly;
(4) Reasonable monitoring of systems for unauthorized use of or access to personal information;
(5) Encryption of all personal information stored on laptops or other portable devices;
(6) For files containing personal information on a system that is connected to the internet, there must be reasonably up-to-date firewall protection and operating system security patches, reasonably designed to maintain the integrity of the personal information;
(7) Reasonably up-to-date versions of system security agent software which must include malware protection and reasonably up-to-date patches and virus definitions, or a version of such software that can still be supported with up-to-date patches and virus definitions, and is set to receive the most current security updates on a regular basis; and
(8) Education and training of employees on the proper use of the computer security system and the importance of personal information security.
Other Information
Every person who owns or licenses personal information about a resident of the commonwealth shall be in full compliance with these requirements on or before March 1, 2010.