
If a Massachusetts business loses control of personal data, whether it’s a laptop with customer records, a compromised email account, or a full blown ransomware incident, the clock starts immediately. State law doesn’t give a fixed number of days the way some other states do. It requires notification “as soon as practicable and without unreasonable delay,” which sounds simple until you’re the one deciding what “reasonable” means in the middle of an actual incident.
Who This Actually Applies To
Massachusetts General Law Chapter 93H applies to any business, of any size, that owns or licenses personal information belonging to Massachusetts residents. That’s not just companies headquartered here. A business in another state with even a handful of Massachusetts customers or employees falls under it too, there’s no small business exemption.
Once a breach is discovered, the business has to notify both the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation, with specifics: what happened, how many residents were affected, what’s already been done, and whether the business has a Written Information Security Program, a WISP, in place. That last question matters more than most business owners realize. Not having one doesn’t just look bad, it’s itself a compliance gap regulators can act on separately from the breach.
The Part Everyone Underestimates
If Social Security numbers are involved, the business must offer affected residents 18 months of free credit monitoring through a third-party vendor. For a breach touching a few thousand records, that’s a real, unplanned expense arriving on top of the incident response bill, the legal review, and the reputational hit, all inside a window measured in days, not months.
This is where a lot of SMBs discover, mid-crisis, that they never actually built the WISP the law assumes they have. A written security program isn’t a formality for a binder nobody reads. It’s supposed to reflect real, current practices: how data is classified, who has access, how incidents get escalated, and how quickly the business can actually answer the state’s questions when it matters.
Getting Ahead of It Instead of Reacting to It
The businesses that handle this well aren’t scrambling to write a WISP after an incident. They built one, and updated it, before they needed it. A few things worth having in place now:
- A current, honest WISP that matches how the business actually operates today, not three reorganizations ago
- A documented incident response plan naming who does what in the first 24 hours
- Clear visibility into where personal information actually lives across systems and vendors
- A relationship with legal and IT partners who can move fast, not one built during the emergency itself
This is squarely where strategic IT planning earns its keep. Compliance readiness isn’t a project you finish once, it’s a standing part of how the business operates. Working with a partner who brings both technical depth and specialized compliance expertise means the WISP reflects reality, and the business actually knows what to do the day something goes wrong.
The Bottom Line
“Without unreasonable delay” is not a deadline you get to define favorably to yourself after the fact. It’s a standard regulators apply in hindsight, and it’s a lot easier to meet when the plan already exists. If your business hasn’t looked at its WISP in a while, or isn’t sure it has one that reflects reality, now’s the time, not during an actual incident.
Schedule a free security assessment with Cloud9 and find out where your compliance readiness actually stands.
