ShieldForce Colored Variance Logo
For Massachusetts Agencies

You're legally required to have a WISP. Do you?

Massachusetts law (201 CMR 17.00) requires every home health and hospice agency handling patient data to maintain a written security program - and to notify the Attorney General if a breach happens. Most agencies in the state aren't fully covered.

Get My Free Risk Check →

No cost. No commitment. About 10 minutes. Boston-based team.

Compliance Notice
201 CMR 17.00
WISP Required
M.G.L. c. 93H · MA
The Law, In Plain English

Two Massachusetts rules most agencies overlook

201 CMR 17.00

The WISP Requirement

Any business that holds personal information about a Massachusetts resident must maintain a written, documented security program - a WISP. There's no size exemption. A five-person agency is held to the same standard as a hospital system.

M.G.L. c. 93H

Breach Notification

If patient data is exposed, you must notify the Massachusetts Attorney General's office and the Office of Consumer Affairs - without unreasonable delay. There's no grace period to get your paperwork in order after the fact.

What's At Stake

Non-compliance isn't hypothetical

$5,000

Civil penalty exposure per violation under Massachusetts law

0 days

Grace period - notification is required "as soon as practicable"

700+

Licensed home health and hospice agencies in Massachusetts, all held to the same standard

Boston-based team
24/7 security monitoring
HIPAA-ready
Starting at $35/user/month

Find your compliance gaps before the state does.

Free, confidential 10-minute assessment. No systems access required - just a few questions about your current setup.

Get My Free Risk Check →