Get Security Assessment

HIPAA Compliance in Massachusetts: 201 CMR 17.00 & State Laws

Massachusetts imposes some of the strictest data security and healthcare privacy requirements in the nation. This guide covers 201 CMR 17.00 (data security regulations), medical records laws, consumer protection statutes, and other Massachusetts requirements that exceed HIPAA standards.

Quick Answer

Massachusetts imposes healthcare privacy through three main frameworks: HIPAA (federal), 201 CMR 17.00 (state data security law), and medical records statutes (Mass. Gen. Laws c. 111, §70). The 201 CMR 17.00 regulation is notably stringent: it specifies detailed security requirements (authentication, encryption, access controls) that exceed HIPAA's risk-based approach. Massachusetts also requires prompt breach notification, grants patients broad rights to medical records, and allows enforcement by both the Massachusetts Attorney General and private lawsuits. Healthcare organizations must meet the highest standard across all three frameworks—201 CMR 17.00 compliance is often more demanding than HIPAA compliance alone.

How Massachusetts Law Extends Beyond HIPAA

Massachusetts law creates overlapping privacy and security requirements that frequently exceed HIPAA standards:

1. 201 CMR 17.00 (Standards for Safeguarding Personal Information)

Massachusetts's data security regulation applies to all entities handling personal information of Massachusetts residents:

2. Massachusetts Medical Records Access Law (Mass. Gen. Laws c. 111, §70)

Establishes patient rights to medical records:

3. Massachusetts Data Breach Notification Law (Mass. Gen. Laws c. 149, §24G)

Requires notification of breaches of personal information:

4. Massachusetts Consumer Protection Act (Mass. Gen. Laws c. 93A)

Provides broad private right of action for unfair/deceptive practices:

5. Massachusetts Mental Health Record Confidentiality

Additional protections for mental health and substance abuse information:

Key Massachusetts State Statutes & References

201 CMR 17.00 (Standards for Safeguarding Personal Information)
Prescriptive data security regulation requiring specific controls: multi-factor authentication, encryption, access controls, vendor management, training, incident response. More detailed than HIPAA's risk-based approach.
Massachusetts General Laws c. 111, §70 (Patient Access to Medical Records)
Grants patients right to access medical records promptly. Requires reasonable copying fees, format flexibility, and amendment procedures. Applies to all healthcare providers.
Massachusetts General Laws c. 149, §24G (Data Breach Notification)
Requires notification of breaches of personal information without unreasonable delay. Applies to entities handling Massachusetts resident data.
Massachusetts General Laws c. 93A (Consumer Protection Act)
Prohibits unfair and deceptive practices. Healthcare privacy violations can be pursued as consumer protection violations. Private right of action with potential treble damages.
Massachusetts General Laws c. 123, §§12H-12P (Mental Health Record Confidentiality)
Protects confidentiality of mental health treatment records. Requires written authorization for disclosure. More stringent than HIPAA for mental health data.
Massachusetts General Laws c. 94, §305-328 (Identity Theft and Privacy Protection)
Protects against identity theft using personal information from healthcare records. Requires reasonable security and breach notification.

Massachusetts Attorney General Enforcement

Massachusetts Attorney General aggressively enforces healthcare privacy and data security laws:

Notable enforcement: Massachusetts AG has pursued healthcare providers and health insurers for data breaches, non-compliance with 201 CMR 17.00, and inadequate security measures. Settlements have included penalties, patient notification, credit monitoring, and ongoing third-party security audits.

Comparison: HIPAA vs. Massachusetts State Requirements

Area HIPAA Massachusetts Law More Stringent
Security Standards Risk-based reasonable safeguards 201 CMR 17.00: Prescriptive requirements (MFA, encryption, access controls, etc.) Massachusetts
Multi-Factor Authentication Recommended but not required 201 CMR 17.00: Required for remote access Massachusetts
Encryption in Transit Encryption recommended 201 CMR 17.00: Encryption required by standard Massachusetts
Encryption at Rest Encryption recommended 201 CMR 17.00: Encryption required Massachusetts
Vendor Management BA agreements and oversight 201 CMR 17.00: Detailed vendor requirements, due diligence, monitoring Massachusetts
Breach Notification 60 days of discovery Without unreasonable delay (immediate) Massachusetts
Private Right of Action No private HIPAA right for patients Chapter 93A allows consumer lawsuits; potential treble damages Massachusetts
Workforce Training Required but flexible 201 CMR 17.00: Documented training required Massachusetts

Massachusetts-Specific Security & Breach Requirements

201 CMR 17.00 Safeguarding Requirements

Breach Notification Timeline & Requirements

Chapter 93A Private Right of Action

Frequently Asked Questions

Does 201 CMR 17.00 apply to out-of-state healthcare providers? +

Yes. 201 CMR 17.00 applies to any entity handling personal information of Massachusetts residents, regardless of where the entity is located. If you're an out-of-state healthcare provider serving Massachusetts residents (including telemedicine), you must comply with 201 CMR 17.00. This includes implementing multi-factor authentication, encryption standards, vendor management procedures, and documented security policies. Many out-of-state organizations were surprised to discover they must comply with Massachusetts's more stringent security standards even though they're not based in Massachusetts.

What's the difference between HIPAA's security requirements and 201 CMR 17.00? +

HIPAA requires a risk-based approach: analyze risks to PHI and implement reasonable safeguards based on that analysis. 201 CMR 17.00 is prescriptive: it specifies certain controls that must be implemented (multi-factor authentication, encryption, access controls, etc.) regardless of risk analysis. For example, HIPAA allows encryption to be optional if your risk analysis concludes it's not necessary; 201 CMR 17.00 requires encryption for data at rest and in transit. 201 CMR 17.00 also requires documented third-party audits for larger entities and detailed vendor management. In practice, compliance with 201 CMR 17.00 typically requires more robust security than HIPAA alone.

Can Massachusetts patients sue me for healthcare privacy violations under Chapter 93A? +

Yes. Under Massachusetts General Laws c. 93A, if your healthcare organization's privacy practices are unfair or deceptive, affected patients can sue directly for damages. Chapter 93A allows actual damages plus statutory damages. If the violation is "knowing" (intentional or reckless), the court can award treble damages (three times actual damages) plus attorney fees. This is a significant exposure—a data breach involving negligent security could be characterized as a Chapter 93A violation. Unlike HIPAA, which only allows enforcement by the federal government and Massachusetts AG, Chapter 93A private lawsuits can be initiated by affected patients directly, creating class action risk.

What documentation must we maintain for 201 CMR 17.00 compliance? +

201 CMR 17.00 requires comprehensive documentation: (1) Written security program with policies and procedures; (2) Risk assessments documenting threats and safeguards; (3) Vendor contracts and assessment results; (4) Audit logs and access reviews; (5) Training records documenting employee security training; (6) Incident response plans and breach records; (7) Encryption standards and key management procedures; (8) Multi-factor authentication implementation details. The regulation requires this documentation be available for Massachusetts AG review. Best practice is to maintain a security compliance binder with all documentation and periodic security assessments. Many healthcare organizations underestimate the documentation burden of 201 CMR 17.00 compliance.

Ensure Your Organization Meets Massachusetts's Strict Requirements

Massachusetts's 201 CMR 17.00 imposes stricter security standards than HIPAA. Get a professional security assessment to ensure compliance with 201 CMR 17.00, HIPAA, and Massachusetts privacy laws.

Get Your Security Assessment