Massachusetts Identity Theft and Data Breach Statistics: 2025 Report
Massachusetts is among the most breach-active states in the country — not because it has weaker protections, but because it requires businesses to report more than almost any other state. This report compiles the latest verified data from the Massachusetts Attorney General, the Identity Theft Resource Center, and IBM on breach frequency, affected residents, industry targets, costs, and what businesses and residents can do to reduce their exposure.
By Erica McKowski, Founder — MyPaperShredding·Updated May 2026·14 min read📊 Data & Statistics📍 Massachusetts
~7M
Massachusetts residents impacted in peak breach year
Source: MA Attorney General / NBC Boston
2,400+
Breaches reported to MA Attorney General in a single year
Source: MA AG Office
$10.22M
Average US data breach cost — highest of any global region
Source: IBM Cost of a Data Breach 2025
$5,000
Maximum fine per violation under MA General Laws c. 93H
Source: MGL c. 93H
Sources Used in This Report
Massachusetts
MA Attorney General’s office breach reports · NBC Boston investigative data · MGL Chapter 93H enforcement records
National
Identity Theft Resource Center 2024 Annual Data Breach Report · IBM Cost of a Data Breach Report 2025 · FTC Consumer Sentinel Network
The Massachusetts Data Breach Landscape
Massachusetts holds a paradoxical position in national data breach statistics. The state consistently appears near the top of reported breach counts not because its businesses are less secure, but because MGL Chapter 93H — the Massachusetts data breach notification law — requires every business that experiences a qualifying breach to notify both affected individuals and the Attorney General. States with weaker notification requirements simply report fewer breaches. Massachusetts reports nearly all of them.
The practical result: Massachusetts businesses and residents have access to more accurate data about the actual scope of the breach problem than residents of most states. That transparency is valuable. But the underlying numbers are genuinely alarming.
According to NBC Boston’s investigation into Massachusetts breach data, over 2,400 breaches were reported to the Massachusetts Attorney General in a recent annual reporting period. In the highest-impact year tracked, nearly 7 million Massachusetts residents had personal information exposed — a number that exceeds the state’s total adult population and reflects the reality that many individuals are caught in multiple breach events. Nearly 2 million residents had their information compromised in 2024 alone.
NBC Boston investigation into Massachusetts data breach statistics, October 2024. Massachusetts AG Office annual data breach reporting database.
National Context: Where Massachusetts Fits
Understanding Massachusetts breach statistics requires national context. The Identity Theft Resource Center tracked 3,158 US data compromises in 2024 — one event short of tying the all-time record set the prior year. The number of victim notices issued in 2024 reached 1.35 billion, a 211% increase from 2023, driven primarily by five mega-breaches that each generated over 100 million notices.
3,158
US data compromises reported in 2024 — near-record high
ITRC 2024 Annual Report
1.35B
Victim breach notices issued in 2024 — up 211% from 2023
ITRC 2024 Annual Report
1,732
Data compromises in H1 2025 — already 55% of full-year 2024 total
ITRC H1 2025 Report
Identity Theft Resource Center 2024 Annual Data Breach Report, released January 28, 2025. ITRC H1 2025 Data Breach Report, released July 16, 2025.
The US average breach cost of $10.22 million in 2025 is not just a national figure — it is a figure Massachusetts businesses face specifically. The concentration of healthcare systems, financial institutions, law firms, and technology companies in the Greater Boston area means the state’s businesses are heavily represented in the industry categories that carry the highest breach costs.
One trend that is particularly relevant for Massachusetts businesses: physical attacks on data storage increased in 2025. The Identity Theft Resource Center tracked more physical attacks on data infrastructure in the first half of 2025 than in all of 2024. While cyberattacks remain the dominant breach vector, the physical dimension — including improperly discarded paper records — is measurably growing.
Industries Most Targeted in Massachusetts
Two industries dominate Massachusetts breach data by volume: healthcare and financial services. Both are core pillars of the Massachusetts economy. The Greater Boston healthcare cluster — one of the largest in the country — and the financial services concentration along the Route 128 and Boston corridors create concentrated targets for both cyberattacks and physical data exposure.
🏥
Healthcare
Consistently the highest-cost breach category. Healthcare breach frequency increased in H1 2025. Massachusetts is home to some of the largest academic medical systems in the US. PHI breaches trigger both HIPAA and 201 CMR 17.00 obligations simultaneously. Our HIPAA medical shredding service addresses both compliance layers.
🏦
Financial Services
The most numerous breach events nationally. Banks, mortgage brokers, investment advisors, and insurance companies generate high volumes of records containing financial account numbers, SSNs, and credit information — all covered under both GLBA and Massachusetts 201 CMR 17.00.
⚖️
Legal & Professional Services
Law firms, accounting firms, and HR consulting companies maintain files dense with personal identifiers. Massachusetts has a high concentration of professional services firms per capita. Client matter files, employment records, and tax documentation all carry significant breach exposure.
🎓
Education & Research
Massachusetts universities and research institutions — among the most concentrated in the world — hold student records, research data, financial aid files, and employment records. Higher education breach frequency has risen nationally as institutions digitize historical records.
🏢
Small Business
Often overlooked in breach statistics because small business incidents receive less media coverage. But small businesses generate the same categories of covered records — employee files, customer transaction records, contractor agreements — without enterprise-level security resources. Massachusetts 201 CMR 17.00 treats every business identically regardless of size.
🏥
Dental & Medical Specialty Practices
Individual dental practices and specialty medical offices generate X-rays, patient intake forms, insurance records, and billing data. HIPAA applies in full, and Massachusetts adds 201 CMR 17.00 for the non-PHI personal information in the same files. Disposal compliance is a documented gap for practices without formal records management programs.
Our industrial shredders process up to 8,000 lbs per hour. Every job produces a Certificate of Destruction — documented proof of proper disposal for 201 CMR 17.00, HIPAA, GLBA, and FACTA compliance.
Physical Document Disposal as a Data Breach Vector
The public conversation about data breaches focuses overwhelmingly on cyber threats — phishing emails, ransomware, credential theft, and system intrusions. These are real and serious. But a significant and consistently underreported category of breach events begins with physical records: a box of personnel files in a recycling dumpster, a year’s worth of bank statements in an unlocked trash bin, a filing cabinet donated to a thrift store with documents still inside.
Massachusetts General Laws Chapter 93I — the state’s improper disposal of personal information law — exists specifically because the legislature recognized this category of risk. Chapter 93I defines improper disposal as placing records containing personal information in a trash or recycling container without first rendering the information unreadable. It applies to any paper record with a Massachusetts resident’s personal information. A single improperly discarded file triggers breach notification obligations under Chapter 93H.
Recycling paper records is not compliant disposal under Massachusetts law. MGL Chapter 93I requires that records containing personal information be rendered unreadable before disposal. Documents in a recycling bin remain intact, readable, and accessible. The Massachusetts Attorney General has brought enforcement actions against businesses for exactly this category of improper disposal.
The FTC’s enforcement of the federal FACTA Disposal Rule parallels the Massachusetts statute at the national level. FACTA applies to any business that uses consumer reports — including credit checks for tenants, background checks for employees, and credit decisions for customers. Violations of the Disposal Rule have resulted in multi-million dollar FTC settlements with businesses across the country for exactly this kind of physical records mishandling.
📌 The math for Massachusetts businesses
A Massachusetts business that discards one box of client files — 40 folders, each containing a name and Social Security number — has created up to 40 separate violations at a maximum fine of $5,000 each under MGL c. 93H. That is $200,000 in maximum penalty exposure from one improperly discarded box. The cost of having that box professionally shredded: approximately $60.
What a Data Breach Actually Costs a Massachusetts Business
The $10.22 million US average breach cost cited in IBM’s 2025 report is a mean figure heavily influenced by large enterprise breaches. For small and mid-sized Massachusetts businesses, the relevant number is the cost of a breach relative to company scale. Even a small breach — one improperly discarded file cabinet of customer records — triggers specific, documented costs:
$5,000
Max fine per violation under MGL c. 93H — multiplied by number of individuals affected
Legal
Attorney fees for breach notification response, AG communication, and civil defense
Notify
Mandatory written notification to every affected MA resident plus AG filing — postage, printing, and staff time
IBM Cost of a Data Breach Report 2025. Massachusetts General Laws Chapter 93H (breach notification requirements and penalty structure).
Beyond direct costs, breach events in Massachusetts trigger reputational consequences that are disproportionately damaging for locally owned businesses. A Google news search for a business name plus “data breach” is permanent. The Attorney General’s breach database is publicly accessible. Clients and patients searching for a vendor will find the breach record. Trust, once lost through a preventable disposal incident, is expensive to rebuild.
The total economic argument is straightforward: professional shredding with a Certificate of Destruction costs between $60 and $450 per job depending on volume. The documented cost of a breach from one improperly discarded box starts in the thousands. The break-even is not close.
Breach Trend Data: Where Things Are Heading
The trajectory of US breach data through 2024 and into 2025 points consistently in one direction. Breach counts are near record levels. Victim notices grew 211% year-over-year in 2024. The first half of 2025 was already running 5% ahead of 2024’s pace with 1,732 reported compromises tracked by mid-year.
US Data Compromises — Annual Trend (ITRC)
2021
1,862 compromises
2022
1,802 compromises
2023
3,202 compromises (record)
2024
3,158 compromises (near-record)
2025
1,732 in H1 (on pace for record)
Identity Theft Resource Center Annual Data Breach Reports 2021–2024. ITRC H1 2025 Data Breach Report. 2025 bar represents H1 only, shaded to indicate partial year.
One specific trend worth noting for Massachusetts businesses: the shift in healthcare breach frequency. After a slight decrease in financial services breach counts in early 2025, healthcare saw a concurrent increase — making it the sector with both the highest costs per breach and the growing frequency. For the thousands of healthcare providers operating in Metro Boston, this trend directly increases their breach risk profile and their 201 CMR 17.00 and HIPAA exposure simultaneously.
Every shredding job we complete closes a potential breach vector. Physical records that contain personal information leave our facility as recycled pulp — nothing is recoverable.
What Massachusetts Businesses and Residents Can Do Right Now
Statistics without action steps are just anxiety. Here is what the data specifically indicates for different audiences:
For businesses
Audit your document disposal process today
Walk your office and identify every location where records with personal information accumulate — filing cabinets, desks, copy room recycle bins, storage closets. If any of those end up in a recycling bin without destruction, you have a compliance gap. Locked shredding consoles at your office eliminate this risk at the collection point.
For businesses
Create or update your Written Information Security Plan
Massachusetts 201 CMR 17.00 requires a documented WISP for every business. The destruction process must be described in writing. Our 201 CMR 17.00 compliance guide walks through every WISP requirement specifically for Massachusetts businesses.
For healthcare providers
Verify your shredding vendor’s BAA status
Your shredding company is a business associate under HIPAA. If they do not have a signed Business Associate Agreement with your practice, every pickup is a potential HIPAA violation. We sign a BAA before the first pickup for all medical and HIPAA clients at no additional charge.
For residents
Schedule a home shredding appointment annually
Tax returns, bank statements, old Medicare cards, and utility bills with your name and address accumulate every year. An annual shredding appointment handles the prior year’s documents and keeps your exposure window closed. Residential shredding costs under $100 for most typical household volumes.
Close Your Biggest Physical Breach Vector This Week
We serve 16 Metro Boston cities. Every job includes a Certificate of Destruction. Most customers schedule within 2 to 3 business days.
Frequently Asked Questions About Massachusetts Data Breach Statistics
Questions about this data or how it applies to your business? Call (978) 636-0301 and we will talk through it directly.
Over 2,400 data breaches were reported to the Massachusetts Attorney General’s office in a recent annual reporting period, affecting the personal information of millions of state residents. In the highest-impact year tracked, the number of affected residents approached 7 million — reflecting many individuals being caught in multiple breach events. Nearly 2 million Massachusetts residents had their information compromised in 2024. Massachusetts’s strong breach notification law under MGL Chapter 93H means these numbers are more complete than in most states.
According to IBM’s 2025 Cost of a Data Breach Report, the average cost of a data breach in the United States reached $10.22 million — the highest of any global region, representing a 9% increase from 2024. The global average was $4.44 million. Healthcare remained the most expensive industry for breach costs by a wide margin, averaging significantly above other sectors. These figures include direct costs (notification, legal, forensics) and indirect costs (reputational damage, customer loss, regulatory fines).
Massachusetts consistently appears among the highest states in reported data breach volume, in part because MGL Chapter 93H requires businesses to report breaches that go unreported in states with weaker notification laws. The state’s concentration of healthcare, financial services, and technology industries also elevates its breach exposure relative to states with different economic compositions. Massachusetts residents should assume their personal information has been involved in at least one breach event.
Healthcare and financial services lead all sectors in data compromise frequency, both nationally and in Massachusetts. The ITRC reported that these two industries accounted for the largest share of H1 2025 compromises. Healthcare breach frequency increased year-over-year in early 2025. Massachusetts’s high concentration of academic medical centers, community hospitals, insurance companies, and investment firms makes the state particularly exposed in both categories.
Yes. MGL Chapter 93I specifically addresses improper physical disposal of personal information — placing readable records containing personal data in recycling or trash bins rather than destroying them first. This constitutes a violation of Massachusetts law and triggers breach notification obligations under Chapter 93H. The Massachusetts Attorney General enforces both statutes. A Certificate of Destruction from a professional shredding service documents compliance with the disposal requirement.
Under MGL Chapter 93H, any business that experiences a breach of security involving Massachusetts residents’ personal information must notify every affected individual in writing and file a written report with the Massachusetts Attorney General’s office. Notification must occur as soon as reasonably possible after discovering the breach. The business must describe the nature of the breach, the categories of information involved, and the remediation steps taken. Failures to notify within a reasonable timeframe create additional legal exposure.
Shredding documents with personal information eliminates the physical records that identity thieves recover from improperly discarded files. It also satisfies the destruction standard under Massachusetts 201 CMR 17.00, which requires businesses to destroy records containing personal information so the data cannot be read or reconstructed. A Certificate of Destruction documents compliance, protecting businesses from enforcement actions and civil liability if a breach question later arises.
The Massachusetts Attorney General’s office publishes annual data breach reports and maintains a searchable database of reported breaches at mass.gov. The Identity Theft Resource Center (idtheftcenter.org) publishes quarterly and annual reports on national breach trends with industry breakdowns. IBM publishes its annual Cost of a Data Breach Report each summer. NBC Boston has published several in-depth investigations into Massachusetts-specific breach data with original analysis of AG office records.
Eliminate Your Physical Breach Exposure
The statistics are real. The legal exposure is documented. The solution for physical records is straightforward. We serve Metro Boston businesses and residents with compliant, certified document destruction from 99¢ per pound. Every job includes a Certificate of Destruction. Call or request a quote and we will confirm pricing before you commit to anything.
✓ Certificate of Destruction Every Job✓ 201 CMR 17.00 + HIPAA Compliant✓ BBB A+ Rated✓ Locally Owned Since 2007
EM
Erica McKowski
Founder & CEO, MyPaperShredding
Erica McKowski founded Neighborhood Parcel, dba MyPaperShredding, in 2007 to help Metro Boston businesses and residents manage document security with transparency and documented compliance. She compiles this statistics report annually from primary sources including the Massachusetts Attorney General’s office, the Identity Theft Resource Center, and IBM’s Cost of a Data Breach research. MyPaperShredding is BBB A+ rated and serves 16 cities across the Merrimack Valley and Greater Boston. Learn more →