Massachusetts Compliance

Massachusetts 201 CMR 17.00: The Complete Compliance Guide for Small Business Owners

Every business that holds personal information about Massachusetts residents must comply with 201 CMR 17.00. Most business owners only learn about this regulation after it becomes a problem. This guide explains who the law covers, exactly what it requires for document disposal, the penalties for non-compliance, and the one document that proves you followed the rules.

By Erica McKowski, Founder — MyPaperShredding Updated May 2026 12 min read 🔒 HIPAA + MA 201 CMR 17.00 📍 Metro Boston, MA
The 30-Second Version
What it is
Massachusetts data security regulation — effective March 1, 2010
Who it covers
Every business, nonprofit, and individual holding personal information about MA residents — no size or revenue minimum
Disposal requirement
Records must be destroyed so information cannot be read or reconstructed — shredding, pulverizing, or burning
Penalty exposure
Up to $5,000 per violation under MGL c. 93H, plus civil liability to affected individuals

You Are Probably Already Subject to This Law

Picture this: You run a small landscaping company in Andover. You have three employees. You keep a filing cabinet with their names, addresses, Social Security numbers, and direct deposit information. You also have a folder of background check results from the staffing agency you used last spring. At the end of the year, you toss some old hiring files in the paper recycling.

That recycling step just violated Massachusetts law.

Massachusetts 201 CMR 17.00 is the state’s data security regulation, administered by the Office of Consumer Affairs and Business Regulation. It has been in effect since 2010. It applies to every business — regardless of size, industry, or revenue — that owns, licenses, stores, or maintains personal information about any Massachusetts resident. There is no minimum employee count. There is no revenue threshold. A sole proprietor with a single client file is legally subject to the same standard as a regional hospital system.

Most Massachusetts business owners discover this regulation when a compliance auditor, an angry customer, or the Attorney General’s office asks them about it. This guide gives you the information before it becomes a problem.

What the Regulation Defines as “Personal Information”

The regulation defines personal information as a Massachusetts resident’s first name (or first initial) and last name combined with any one of the following:

Statutory Definition — 201 CMR 17.02

Social Security number  ·  Driver’s license number or state-issued ID number  ·  Financial account number (bank account, investment account) combined with any required access or security code or password  ·  Credit card or debit card number combined with any required access or security code, PIN, or password.

That list covers almost every business relationship you have. Employee onboarding creates records with Social Security numbers. Customer transactions create records with credit card numbers. Tenant applications create records with driver’s license numbers. Vendor contracts may include financial account numbers if you pay by ACH. Every one of those documents, once it is no longer needed, must be destroyed under a specific legal standard — not simply discarded.

Healthcare providers have an additional layer of obligation under HIPAA for protected health information, but 201 CMR 17.00 applies to healthcare providers independently of HIPAA. A dental practice in Burlington, MA, must satisfy both regulations simultaneously. The medical records standard is separate and additional — it does not replace the state requirement.

What 201 CMR 17.00 Actually Requires for Document Disposal

Section 17.03 establishes the foundational duty: every covered entity must implement and maintain a comprehensive information security program that includes reasonable measures to protect personal information in all forms — including physical records.

Section 17.05(2)(f) gets specific about disposal. It requires “secure disposal, in any manner that shall ensure the security of the personal information, of records and documents containing personal information no longer to be retained.” The statute lists specific acceptable methods: burning, pulverizing, or shredding papers containing personal information.

The regulation also requires that covered businesses create and maintain a Written Information Security Plan (WISP) — a formal written document that describes how the organization identifies risks to personal information and how it addresses those risks, including through its document destruction procedures. Massachusetts is one of the few states in the country that mandates a written security policy at this level of specificity for all businesses, regardless of size.

Which Industries Are Most Affected — and Why

The common assumption is that 201 CMR 17.00 primarily concerns healthcare and financial services. In practice, it reaches far deeper into the Massachusetts business community. Here are the industries most frequently caught off guard:

Healthcare & Dental
Patient intake forms, billing records, insurance EOBs, and PHI all qualify. Covered by both HIPAA and 201 CMR 17.00. A HIPAA-compliant shredding service with a Business Associate Agreement satisfies both standards.
Legal & Accounting
Client matter files, retainer agreements, tax returns, and engagement letters contain SSNs, financial account numbers, and other covered identifiers. Attorneys and CPAs have independent ethical obligations on top of the statutory requirement.
Employers (All Industries)
Every Massachusetts employer generates employee records with Social Security numbers, direct deposit account numbers, and state ID information. HR files are among the most common sources of improper disposal violations.
Real Estate & Landlords
Rental applications routinely include Social Security numbers, driver’s license numbers, and financial account information for credit checks. Landlords who discard these applications in the trash or recycling are in direct violation.
Financial Services
Banks, mortgage brokers, insurance agents, and financial advisors are covered by GLBA (federal) and 201 CMR 17.00 (state). Both require proper disposal with documented chain of custody. Scheduled shredding service satisfies both standards simultaneously.
Non-Profits & Schools
Donor records, grant applications, employee files, and student records frequently contain covered personal information. Non-profit status provides no exemption from 201 CMR 17.00.

If your organization does not appear in that list, ask yourself one question: does any record you hold contain a Massachusetts resident’s name paired with a Social Security number, financial account number, driver’s license number, or credit card number? If the answer is yes, you are covered.

The Penalties for Non-Compliance

Enforcement of 201 CMR 17.00 runs through Massachusetts General Laws Chapter 93H (the breach notification law) and Chapter 93I (the improper disposal law). When a covered business improperly disposes of records containing personal information, it triggers obligations and penalties under both statutes.

$5,000
Maximum fine per violation under MGL c. 93H
Per Record
Each exposed individual may represent a separate violation
+Civil
Affected individuals may sue for actual and statutory damages

The math matters here. A business that discards one box of old client files — say, 40 folders each containing a different individual’s personal information — has potentially created 40 separate violations at up to $5,000 each. That is $200,000 in maximum exposure before any civil claims from affected individuals. The Massachusetts Attorney General’s office actively investigates and prosecutes data disposal violations.

Chapter 93H also triggers mandatory breach notification. If improperly discarded records expose or risk exposing personal information, you must notify every affected Massachusetts resident and file a report with the Attorney General. The notification process has its own costs, timelines, and legal obligations — separate from and in addition to the underlying disposal violation.

The cost comparison

A Certificate of Destruction for one shredding job costs $14.95. The minimum fine for one violation under 93H is measured in the thousands. The documentation that protects you costs less than a business lunch.

How a Certificate of Destruction Satisfies the Legal Requirement

Complying with 201 CMR 17.00 is not just about the physical act of shredding. The regulation’s WISP requirement means you need to be able to demonstrate that your information security program includes a documented disposal process. A Certificate of Destruction is that documentation.

A properly issued Certificate of Destruction records the date of destruction, the volume of material destroyed, the method used, the name of the vendor who performed the destruction, and the chain of custody from the point of collection to the point of final destruction. It is a contemporaneous record — created at the time of the destruction event — that gives you auditable proof of compliance.

If your business is ever subject to an Attorney General investigation, a civil claim by an affected individual, or a compliance audit, the Certificate of Destruction is what you produce as evidence. Without it, you have no proof that any records were ever destroyed, regardless of what you did physically. Document destruction without documentation is compliance theater.

Massachusetts courts and regulators have made clear that “reasonable steps” under 201 CMR 17.00 means documented steps. A Written Information Security Plan that describes a shredding process, combined with Certificates of Destruction that verify it was followed, gives your business the strongest available defense against a compliance action.

If you want to understand exactly what a Certificate of Destruction documents and why it matters for different compliance frameworks, our Certificate of Destruction guide walks through it in detail.

5 Steps to Get Your Business Compliant with 201 CMR 17.00

Compliance does not require a law degree or an expensive outside counsel engagement. It requires a documented process and a reliable vendor. Here is the practical sequence:

✓ 201 CMR 17.00 Compliance Checklist
  1. Map every record that contains personal information
    Walk through every department, filing cabinet, storage room, and archive. Identify every category of record that contains a Massachusetts resident’s name paired with an SSN, financial account number, driver’s license number, or credit or debit card number. You cannot protect what you have not identified.
  2. Write a document retention and destruction policy
    Your WISP must include documented retention periods for every category of record and a defined destruction trigger. For most employee records, federal guidance suggests seven years. For customer financial transaction records, retention periods vary by industry. Define the timeline and write it down.
  3. Implement secure collection and access controls
    Records awaiting destruction should not be accessible to unauthorized employees or visitors. Locked shredding consoles at your office provide controlled collection and eliminate the risk of records being accessed or removed before destruction. We place these at your location at no extra charge as part of a scheduled service contract.
  4. Engage a vendor with documented chain of custody
    Your destruction vendor must provide a documented chain of custody from the point of collection to the point of final destruction. “We shred everything” is not documentation. A receipt at collection, a signed Certificate of Destruction at completion, and a verifiable chain of custody are the minimum. Ask your vendor for these before you sign anything. Our business shredding service provides all three as standard.
  5. Retain Certificates of Destruction with your WISP
    File every Certificate of Destruction you receive. Keep them with your Written Information Security Plan. If you are ever asked to demonstrate compliance, you produce your WISP showing your documented policy and your Certificates of Destruction showing it was executed. That combination is your legal shield. Most compliance advisors recommend retaining destruction records for a minimum of seven years.

How to Choose a Shredding Vendor That Satisfies 201 CMR 17.00

Not all shredding services provide the documentation that 201 CMR 17.00 requires. A big-box store drop-off (Staples, UPS Store) typically gives you a receipt at the counter, not a Certificate of Destruction with chain of custody documentation. National brokers like Shred-it or Iron Mountain often subcontract jobs to regional providers, and the documentation trail can be inconsistent. For Massachusetts compliance purposes, you need a vendor who provides three things:

A documented chain of custody from collection to destruction

This means the vendor tracks your material from the moment it leaves your hands to the moment it is destroyed. Locked collection bins, signed collection receipts, and secure transport are the standard components. Any gap in that chain is a compliance gap.

A signed Certificate of Destruction per job

The Certificate must include the date, volume, method of destruction, and the vendor’s signature. This is the document you retain in your WISP file. Some vendors issue these automatically. Others charge extra or do not issue them at all. Know before you commit.

Verifiable security practices

Background-checked staff, industrial shredding equipment, and a verifiable recycling chain are the baseline. For higher-sensitivity materials or regulated industries, witnessed shredding — where you or a designated employee observes the destruction in real time — provides the highest level of documented assurance.

We have served Massachusetts businesses and medical offices since 2007. Every job we complete includes a signed Certificate of Destruction, a documented chain of custody, and 100% recycling of all shredded material. Our pricing is posted publicly because we believe in the same transparency we help our clients achieve through compliant document disposal.

Frequently Asked Questions About 201 CMR 17.00

These are the questions Massachusetts business owners ask us most often about this regulation. If yours is not here, call us at (978) 636-0301 and we will give you a straight answer.

Yes. If your business collects or stores any personal information about Massachusetts residents, 201 CMR 17.00 applies — regardless of your company size, industry, or revenue. There is no minimum employee count. A sole proprietor with one client file is subject to the same standard as a large corporation.
Any record containing a Massachusetts resident’s first and last name combined with a Social Security number, driver’s license or state ID number, financial account number, or credit or debit card number must be destroyed before disposal. Under 201 CMR 17.05(2)(f), destruction must render the information unreadable and unrecoverable — typically through shredding, pulverizing, or burning.
Penalties are assessed under Massachusetts General Laws Chapter 93H and 93I. Fines reach up to $5,000 per violation. If improperly discarded records expose multiple individuals, each person affected may represent a separate violation. Businesses also face civil liability to individuals whose information was exposed, plus mandatory breach notification costs.
HIPAA is a federal law that applies specifically to healthcare providers, health plans, and their business associates. 201 CMR 17.00 is a Massachusetts state regulation that applies to every business handling personal information about Massachusetts residents, regardless of industry. A healthcare provider in Massachusetts must comply with both. A retail business, landlord, or accounting firm has no HIPAA obligation but is fully subject to 201 CMR 17.00.
No. Recycling does not meet the destruction standard under 201 CMR 17.05(2)(f). The regulation requires that personal information be rendered unreadable and unable to be reconstructed. Documents placed in a recycling bin remain intact and accessible. Only shredding, pulverizing, or burning satisfies the legal standard.
Yes. Section 17.05(1) requires every covered business to create and maintain a Written Information Security Plan (WISP). The WISP must describe how the business identifies, assesses, and addresses risks to personal information, including the disposal process. Massachusetts is one of the few states that mandates a written policy at this level of specificity for all businesses, regardless of size.
A Certificate of Destruction documents the date, volume, method of destruction, and chain of custody for records that were destroyed. If a regulator, auditor, or plaintiff asks whether personal information was properly disposed of, a signed Certificate of Destruction is your documented proof. Without it, you have no evidence that the records were ever destroyed — regardless of what was actually done.
201 CMR 17.00 sets the standards for protecting personal information, including the disposal requirements. MGL Chapter 93H is the breach notification law that determines what happens after a violation occurs — including mandatory notification to affected residents and the Attorney General. The two laws work together: violating 201 CMR 17.00 by improperly discarding records triggers the breach notification obligations under 93H.