Massachusetts 201 CMR 17.00: The Complete Compliance Guide for Small Business Owners
Every business that holds personal information about Massachusetts residents must comply with 201 CMR 17.00. Most business owners only learn about this regulation after it becomes a problem. This guide explains who the law covers, exactly what it requires for document disposal, the penalties for non-compliance, and the one document that proves you followed the rules.
You Are Probably Already Subject to This Law
Picture this: You run a small landscaping company in Andover. You have three employees. You keep a filing cabinet with their names, addresses, Social Security numbers, and direct deposit information. You also have a folder of background check results from the staffing agency you used last spring. At the end of the year, you toss some old hiring files in the paper recycling.
That recycling step just violated Massachusetts law.
Massachusetts 201 CMR 17.00 is the state’s data security regulation, administered by the Office of Consumer Affairs and Business Regulation. It has been in effect since 2010. It applies to every business — regardless of size, industry, or revenue — that owns, licenses, stores, or maintains personal information about any Massachusetts resident. There is no minimum employee count. There is no revenue threshold. A sole proprietor with a single client file is legally subject to the same standard as a regional hospital system.
Most Massachusetts business owners discover this regulation when a compliance auditor, an angry customer, or the Attorney General’s office asks them about it. This guide gives you the information before it becomes a problem.
What the Regulation Defines as “Personal Information”
The regulation defines personal information as a Massachusetts resident’s first name (or first initial) and last name combined with any one of the following:
Social Security number · Driver’s license number or state-issued ID number · Financial account number (bank account, investment account) combined with any required access or security code or password · Credit card or debit card number combined with any required access or security code, PIN, or password.
That list covers almost every business relationship you have. Employee onboarding creates records with Social Security numbers. Customer transactions create records with credit card numbers. Tenant applications create records with driver’s license numbers. Vendor contracts may include financial account numbers if you pay by ACH. Every one of those documents, once it is no longer needed, must be destroyed under a specific legal standard — not simply discarded.
Healthcare providers have an additional layer of obligation under HIPAA for protected health information, but 201 CMR 17.00 applies to healthcare providers independently of HIPAA. A dental practice in Burlington, MA, must satisfy both regulations simultaneously. The medical records standard is separate and additional — it does not replace the state requirement.
What 201 CMR 17.00 Actually Requires for Document Disposal
Section 17.03 establishes the foundational duty: every covered entity must implement and maintain a comprehensive information security program that includes reasonable measures to protect personal information in all forms — including physical records.
Section 17.05(2)(f) gets specific about disposal. It requires “secure disposal, in any manner that shall ensure the security of the personal information, of records and documents containing personal information no longer to be retained.” The statute lists specific acceptable methods: burning, pulverizing, or shredding papers containing personal information.
Recycling does not comply with 201 CMR 17.05(2)(f). Documents placed in a paper recycling bin remain intact and readable. They can be retrieved from a recycling truck, a recycling center, or a bin left on the curb. Massachusetts law requires destruction — not disposal — of records containing personal information. The distinction matters and the penalty exposure is real.
The regulation also requires that covered businesses create and maintain a Written Information Security Plan (WISP) — a formal written document that describes how the organization identifies risks to personal information and how it addresses those risks, including through its document destruction procedures. Massachusetts is one of the few states in the country that mandates a written security policy at this level of specificity for all businesses, regardless of size.
Which Industries Are Most Affected — and Why
The common assumption is that 201 CMR 17.00 primarily concerns healthcare and financial services. In practice, it reaches far deeper into the Massachusetts business community. Here are the industries most frequently caught off guard:
If your organization does not appear in that list, ask yourself one question: does any record you hold contain a Massachusetts resident’s name paired with a Social Security number, financial account number, driver’s license number, or credit card number? If the answer is yes, you are covered.
The Penalties for Non-Compliance
Enforcement of 201 CMR 17.00 runs through Massachusetts General Laws Chapter 93H (the breach notification law) and Chapter 93I (the improper disposal law). When a covered business improperly disposes of records containing personal information, it triggers obligations and penalties under both statutes.
The math matters here. A business that discards one box of old client files — say, 40 folders each containing a different individual’s personal information — has potentially created 40 separate violations at up to $5,000 each. That is $200,000 in maximum exposure before any civil claims from affected individuals. The Massachusetts Attorney General’s office actively investigates and prosecutes data disposal violations.
Chapter 93H also triggers mandatory breach notification. If improperly discarded records expose or risk exposing personal information, you must notify every affected Massachusetts resident and file a report with the Attorney General. The notification process has its own costs, timelines, and legal obligations — separate from and in addition to the underlying disposal violation.
A Certificate of Destruction for one shredding job costs $14.95. The minimum fine for one violation under 93H is measured in the thousands. The documentation that protects you costs less than a business lunch.
Your Business Needs a Documented Destruction Process
We help Massachusetts businesses stay compliant with 201 CMR 17.00. Every job includes a signed Certificate of Destruction. Most customers schedule within 2 to 3 business days.
How a Certificate of Destruction Satisfies the Legal Requirement
Complying with 201 CMR 17.00 is not just about the physical act of shredding. The regulation’s WISP requirement means you need to be able to demonstrate that your information security program includes a documented disposal process. A Certificate of Destruction is that documentation.
A properly issued Certificate of Destruction records the date of destruction, the volume of material destroyed, the method used, the name of the vendor who performed the destruction, and the chain of custody from the point of collection to the point of final destruction. It is a contemporaneous record — created at the time of the destruction event — that gives you auditable proof of compliance.
If your business is ever subject to an Attorney General investigation, a civil claim by an affected individual, or a compliance audit, the Certificate of Destruction is what you produce as evidence. Without it, you have no proof that any records were ever destroyed, regardless of what you did physically. Document destruction without documentation is compliance theater.
Massachusetts courts and regulators have made clear that “reasonable steps” under 201 CMR 17.00 means documented steps. A Written Information Security Plan that describes a shredding process, combined with Certificates of Destruction that verify it was followed, gives your business the strongest available defense against a compliance action.
If you want to understand exactly what a Certificate of Destruction documents and why it matters for different compliance frameworks, our Certificate of Destruction guide walks through it in detail.
5 Steps to Get Your Business Compliant with 201 CMR 17.00
Compliance does not require a law degree or an expensive outside counsel engagement. It requires a documented process and a reliable vendor. Here is the practical sequence:
-
Map every record that contains personal informationWalk through every department, filing cabinet, storage room, and archive. Identify every category of record that contains a Massachusetts resident’s name paired with an SSN, financial account number, driver’s license number, or credit or debit card number. You cannot protect what you have not identified.
-
Write a document retention and destruction policyYour WISP must include documented retention periods for every category of record and a defined destruction trigger. For most employee records, federal guidance suggests seven years. For customer financial transaction records, retention periods vary by industry. Define the timeline and write it down.
-
Implement secure collection and access controlsRecords awaiting destruction should not be accessible to unauthorized employees or visitors. Locked shredding consoles at your office provide controlled collection and eliminate the risk of records being accessed or removed before destruction. We place these at your location at no extra charge as part of a scheduled service contract.
-
Engage a vendor with documented chain of custodyYour destruction vendor must provide a documented chain of custody from the point of collection to the point of final destruction. “We shred everything” is not documentation. A receipt at collection, a signed Certificate of Destruction at completion, and a verifiable chain of custody are the minimum. Ask your vendor for these before you sign anything. Our business shredding service provides all three as standard.
-
Retain Certificates of Destruction with your WISPFile every Certificate of Destruction you receive. Keep them with your Written Information Security Plan. If you are ever asked to demonstrate compliance, you produce your WISP showing your documented policy and your Certificates of Destruction showing it was executed. That combination is your legal shield. Most compliance advisors recommend retaining destruction records for a minimum of seven years.
How to Choose a Shredding Vendor That Satisfies 201 CMR 17.00
Not all shredding services provide the documentation that 201 CMR 17.00 requires. A big-box store drop-off (Staples, UPS Store) typically gives you a receipt at the counter, not a Certificate of Destruction with chain of custody documentation. National brokers like Shred-it or Iron Mountain often subcontract jobs to regional providers, and the documentation trail can be inconsistent. For Massachusetts compliance purposes, you need a vendor who provides three things:
A documented chain of custody from collection to destruction
This means the vendor tracks your material from the moment it leaves your hands to the moment it is destroyed. Locked collection bins, signed collection receipts, and secure transport are the standard components. Any gap in that chain is a compliance gap.
A signed Certificate of Destruction per job
The Certificate must include the date, volume, method of destruction, and the vendor’s signature. This is the document you retain in your WISP file. Some vendors issue these automatically. Others charge extra or do not issue them at all. Know before you commit.
Verifiable security practices
Background-checked staff, industrial shredding equipment, and a verifiable recycling chain are the baseline. For higher-sensitivity materials or regulated industries, witnessed shredding — where you or a designated employee observes the destruction in real time — provides the highest level of documented assurance.
We have served Massachusetts businesses and medical offices since 2007. Every job we complete includes a signed Certificate of Destruction, a documented chain of custody, and 100% recycling of all shredded material. Our pricing is posted publicly because we believe in the same transparency we help our clients achieve through compliant document disposal.
Frequently Asked Questions About 201 CMR 17.00
These are the questions Massachusetts business owners ask us most often about this regulation. If yours is not here, call us at (978) 636-0301 and we will give you a straight answer.
Get Your Business Compliant This Week
We have helped Massachusetts businesses, medical offices, and law firms maintain 201 CMR 17.00 compliance since 2007. Every job we complete includes a signed Certificate of Destruction and a documented chain of custody. Most customers schedule within 2 to 3 business days. Call us or request a quote and we will confirm your pricing before you commit to anything.