If you operate a business in Massachusetts, please read the following as it may affect you.
In keeping with the Patrick Administration's commitment to protecting consumers, the Office of Consumer Affairs and Business Regulation (OCABR) issued in October 2008 a comprehensive set of final regulations establishing standards for how businesses protect and store consumers' personal information.
201 CMR 17.00: Standards for The Protection of Personal Information of Residents of the Commonwealth
The regulations are set to take effect on January 1, 2009 (Read the latest update, this has now been extended to January 1st, 2010!)
All companies who have employees, customers, members, contactors maintain some sort of information about these people are now required to take more serious security measures to maintain their confidentiality.
After reading through these regulations, a lot of these directives made good sense to me but then, I began to wonder on how do you explain to some people that security really matters? I know of some companies that already maintain good security practices while many others just don't care, don't know how bad their internal security is or in some cases, choose to ignore it altogether. In 99% of cases that I have encountered, most basic security practices can be implemented at very little cost and mostly require basic common sense and good internal procedures.
One my biggest concern is how data is stored on laptops, USB drives and other portable devices. Having worked on a few of the devices through the years, I discovered that in many cases an incredible amount of personal and confidential data was stored on these devices. Key staff members and sales people routinely copy entire company databases into their laptops or home computers (convenience, they would argue!) and most business owners at totally oblivious of it because they don't have procedures in place that restrict these practices. Over 90% of this data is not encrypted and not even protected by a basic password so if it is lost or stolen, anyone has access to it.
if you are interested and want to know if these regulations apply to your business download the following document (Click on the link)
- TSI paper reviewing the Mass. Privacy Law - DOWNLOAD
- IT Audit process conducted by TSI - DOWNLOAD
- Quick Notes reviewing these requirements - DOWNLOAD
- Executive Order 504 - DOWNLOAD
Do these regulations apply to my business? (Download)