HIPAA Compliance in Massachusetts: 201 CMR 17.00 & State Laws
Massachusetts imposes some of the strictest data security and healthcare privacy requirements in the nation. This guide covers 201 CMR 17.00 (data security regulations), medical records laws, consumer protection statutes, and other Massachusetts requirements that exceed HIPAA standards.
Massachusetts imposes healthcare privacy through three main frameworks: HIPAA (federal), 201 CMR 17.00 (state data security law), and medical records statutes (Mass. Gen. Laws c. 111, §70). The 201 CMR 17.00 regulation is notably stringent: it specifies detailed security requirements (authentication, encryption, access controls) that exceed HIPAA's risk-based approach. Massachusetts also requires prompt breach notification, grants patients broad rights to medical records, and allows enforcement by both the Massachusetts Attorney General and private lawsuits. Healthcare organizations must meet the highest standard across all three frameworks—201 CMR 17.00 compliance is often more demanding than HIPAA compliance alone.
How Massachusetts Law Extends Beyond HIPAA
Massachusetts law creates overlapping privacy and security requirements that frequently exceed HIPAA standards:
1. 201 CMR 17.00 (Standards for Safeguarding Personal Information)
Massachusetts's data security regulation applies to all entities handling personal information of Massachusetts residents:
- Scope: Applies to healthcare providers, insurers, vendors, and any entity processing Massachusetts resident data
- Specificity: Unlike HIPAA's risk-based approach, 201 CMR 17.00 prescribes detailed security requirements including multi-factor authentication, encryption standards, access controls, and incident response
- Standards include: Written security policies, role-based access, encryption at rest and in transit, secure disposal, intrusion detection, vendor management, workforce training, and audit logs
- Stringency: Massachusetts interprets 201 CMR 17.00 strictly; compliance requires demonstrable implementation of specified safeguards, not just risk analysis
- Enforcement: Massachusetts Attorney General has cited healthcare organizations for non-compliance; penalties and requirement for ongoing audits
2. Massachusetts Medical Records Access Law (Mass. Gen. Laws c. 111, §70)
Establishes patient rights to medical records:
- Access timeline: Patients have right to access records promptly; detailed regulatory requirements for response
- Copy costs: Reasonable copying and mailing costs permitted; costs must be transparent and not punitive
- Format: Records must be provided in format requested when feasible; electronic copies must be provided at reasonable cost
- Amendment rights: Patients can request amendments; providers must address requests within specified timeframe
3. Massachusetts Data Breach Notification Law (Mass. Gen. Laws c. 149, §24G)
Requires notification of breaches of personal information:
- Timeline: Without unreasonable delay; interpreted by Massachusetts AG as requiring immediate notification
- Scope: Applies to any breach of personal information, including health data
- Content: Notice must describe breach, affected information types, company response, and available resources
- Law enforcement notification: May be required depending on breach circumstances
4. Massachusetts Consumer Protection Act (Mass. Gen. Laws c. 93A)
Provides broad private right of action for unfair/deceptive practices:
- Healthcare privacy violations: Can be pursued as violations of consumer protection law
- Private right of action: Patients can sue for damages plus attorney fees
- Enhanced remedies: If healthcare provider is found to have violated consumer protection law knowingly, damages can be trebled
5. Massachusetts Mental Health Record Confidentiality
Additional protections for mental health and substance abuse information:
- Specific consent requirement: Written authorization required for disclosure of mental health treatment
- Substance abuse treatment: Federal 42 CFR Part 2 plus Massachusetts law
Key Massachusetts State Statutes & References
Massachusetts Attorney General Enforcement
Massachusetts Attorney General aggressively enforces healthcare privacy and data security laws:
- 201 CMR 17.00 enforcement: AG has explicitly stated it enforces the regulation against healthcare organizations; violations result in enforcement actions and required security improvements
- HIPAA enforcement: Massachusetts AG enforces HIPAA violations in Massachusetts
- Chapter 93A enforcement: AG pursues unfair healthcare privacy practices with authority to impose penalties
- Data breach enforcement: Investigates breaches and enforces breach notification requirements
Notable enforcement: Massachusetts AG has pursued healthcare providers and health insurers for data breaches, non-compliance with 201 CMR 17.00, and inadequate security measures. Settlements have included penalties, patient notification, credit monitoring, and ongoing third-party security audits.
Comparison: HIPAA vs. Massachusetts State Requirements
| Area | HIPAA | Massachusetts Law | More Stringent |
|---|---|---|---|
| Security Standards | Risk-based reasonable safeguards | 201 CMR 17.00: Prescriptive requirements (MFA, encryption, access controls, etc.) | Massachusetts |
| Multi-Factor Authentication | Recommended but not required | 201 CMR 17.00: Required for remote access | Massachusetts |
| Encryption in Transit | Encryption recommended | 201 CMR 17.00: Encryption required by standard | Massachusetts |
| Encryption at Rest | Encryption recommended | 201 CMR 17.00: Encryption required | Massachusetts |
| Vendor Management | BA agreements and oversight | 201 CMR 17.00: Detailed vendor requirements, due diligence, monitoring | Massachusetts |
| Breach Notification | 60 days of discovery | Without unreasonable delay (immediate) | Massachusetts |
| Private Right of Action | No private HIPAA right for patients | Chapter 93A allows consumer lawsuits; potential treble damages | Massachusetts |
| Workforce Training | Required but flexible | 201 CMR 17.00: Documented training required | Massachusetts |
Massachusetts-Specific Security & Breach Requirements
201 CMR 17.00 Safeguarding Requirements
- Written security program: Detailed written policies and procedures required; must be updated regularly
- Multi-factor authentication: Required for remote access to systems containing personal information
- Encryption: Data at rest must be encrypted; data in transit must use encryption by standard (SSL/TLS)
- Access controls: Role-based access, audit logs, regular access reviews
- Secure disposal: Documented procedures for destroying personal information when no longer needed
- Third-party oversight: Vendor assessment, contracts, and ongoing monitoring required
- Incident response: Written plan for responding to security breaches
- Third-party audits: Annual independent security testing required for larger entities
Breach Notification Timeline & Requirements
- HIPAA requirement: Within 60 days of discovery
- Massachusetts requirement: Without unreasonable delay; AG interprets as immediate when feasible
- Content: Description of breach, types of information involved, actions being taken, available resources
- Method: Written notice by mail, email, or telephone
Chapter 93A Private Right of Action
- Damages: Actual damages plus statutory damages; if deceptive practice is knowing, damages can be trebled
- Attorney fees: Prevailing parties can recover attorney fees and court costs
- Scope: Any healthcare privacy violation can potentially be characterized as unfair/deceptive practice
Frequently Asked Questions
Yes. 201 CMR 17.00 applies to any entity handling personal information of Massachusetts residents, regardless of where the entity is located. If you're an out-of-state healthcare provider serving Massachusetts residents (including telemedicine), you must comply with 201 CMR 17.00. This includes implementing multi-factor authentication, encryption standards, vendor management procedures, and documented security policies. Many out-of-state organizations were surprised to discover they must comply with Massachusetts's more stringent security standards even though they're not based in Massachusetts.
HIPAA requires a risk-based approach: analyze risks to PHI and implement reasonable safeguards based on that analysis. 201 CMR 17.00 is prescriptive: it specifies certain controls that must be implemented (multi-factor authentication, encryption, access controls, etc.) regardless of risk analysis. For example, HIPAA allows encryption to be optional if your risk analysis concludes it's not necessary; 201 CMR 17.00 requires encryption for data at rest and in transit. 201 CMR 17.00 also requires documented third-party audits for larger entities and detailed vendor management. In practice, compliance with 201 CMR 17.00 typically requires more robust security than HIPAA alone.
Yes. Under Massachusetts General Laws c. 93A, if your healthcare organization's privacy practices are unfair or deceptive, affected patients can sue directly for damages. Chapter 93A allows actual damages plus statutory damages. If the violation is "knowing" (intentional or reckless), the court can award treble damages (three times actual damages) plus attorney fees. This is a significant exposure—a data breach involving negligent security could be characterized as a Chapter 93A violation. Unlike HIPAA, which only allows enforcement by the federal government and Massachusetts AG, Chapter 93A private lawsuits can be initiated by affected patients directly, creating class action risk.
201 CMR 17.00 requires comprehensive documentation: (1) Written security program with policies and procedures; (2) Risk assessments documenting threats and safeguards; (3) Vendor contracts and assessment results; (4) Audit logs and access reviews; (5) Training records documenting employee security training; (6) Incident response plans and breach records; (7) Encryption standards and key management procedures; (8) Multi-factor authentication implementation details. The regulation requires this documentation be available for Massachusetts AG review. Best practice is to maintain a security compliance binder with all documentation and periodic security assessments. Many healthcare organizations underestimate the documentation burden of 201 CMR 17.00 compliance.
Ensure Your Organization Meets Massachusetts's Strict Requirements
Massachusetts's 201 CMR 17.00 imposes stricter security standards than HIPAA. Get a professional security assessment to ensure compliance with 201 CMR 17.00, HIPAA, and Massachusetts privacy laws.
Get Your Security Assessment