You're legally required to have a WISP. Do you?
Massachusetts law (201 CMR 17.00) requires every home health and hospice agency handling patient data to maintain a written security program - and to notify the Attorney General if a breach happens. Most agencies in the state aren't fully covered.
Get My Free Risk Check →No cost. No commitment. About 10 minutes. Boston-based team.
WISP Required
Two Massachusetts rules most agencies overlook
The WISP Requirement
Any business that holds personal information about a Massachusetts resident must maintain a written, documented security program - a WISP. There's no size exemption. A five-person agency is held to the same standard as a hospital system.
Breach Notification
If patient data is exposed, you must notify the Massachusetts Attorney General's office and the Office of Consumer Affairs - without unreasonable delay. There's no grace period to get your paperwork in order after the fact.
Non-compliance isn't hypothetical
Civil penalty exposure per violation under Massachusetts law
Grace period - notification is required "as soon as practicable"
Licensed home health and hospice agencies in Massachusetts, all held to the same standard
Find your compliance gaps before the state does.
Free, confidential 10-minute assessment. No systems access required - just a few questions about your current setup.
Get My Free Risk Check →