Cybersecurity · Newton, MA — Since 1978

Massachusetts WISP Compliance & HIPAA IT Support

IT controls that support HIPAA and Massachusetts data security requirements, explained plainly and maintained by a local team.

Call 617-965-4615 Book an Assessment

Quick answer: Massachusetts regulation 201 CMR 17.00 requires businesses that hold personal information about Massachusetts residents to maintain a Written Information Security Program (WISP), and healthcare organizations also have HIPAA obligations. Systems Analysis Services in Newton, MA puts in place and maintains the IT controls that support those requirements and helps document them. Call 617-965-4615 to review where your office stands.

What is a WISP under Massachusetts law?

A WISP is a written program describing how your business protects personal information, and 201 CMR 17.00 requires one from businesses that own or license personal information about Massachusetts residents.

Personal information here generally means a resident’s name combined with a Social Security number, a driver’s license or state ID number, or a financial account or card number. The regulation turns on whose data you hold, not only where your business is located.

A WISP is expected to cover administrative, technical, and physical safeguards suited to your size, resources, and the amount of data you keep. For questions about how the regulation applies to your business, we recommend speaking with your attorney.

What IT controls support a WISP?

The regulation’s computer security requirements line up closely with everyday good IT practice.

  • Secure user authentication and unique logins, with multi-factor authentication where possible
  • Access controls that limit personal information to the people who need it
  • Encryption of personal information sent over public or wireless networks, and on laptops and portable devices
  • Reasonably current firewall protection and security patches
  • Up-to-date malware protection on every computer
  • Monitoring of systems for unauthorized access
  • Security training for employees

We set up, document, and maintain these controls so your WISP describes what is actually in place.

How does this apply to healthcare practices and HIPAA?

Healthcare providers must meet HIPAA requirements in addition to Massachusetts rules, and the IT side of the two overlaps heavily.

HIPAA calls for a security risk assessment, and practices typically need role-based access to patient records, audit logs, encrypted backups, and documented procedures for staff on-site and remote. We help medical, dental, and other healthcare offices put those controls in place and keep the documentation current.

Law firms and accounting practices have their own duties around client confidentiality and financial privacy, and the same controls do much of the work there too.

Are you a compliance auditor?

No. We are an IT provider, and our role is to put in place and maintain the technical controls and documentation that support compliance.

We do not give legal advice or certify that a business is compliant. We work alongside your attorney, compliance officer, or auditor, and we can explain in plain terms what is configured and how.

Where should a business start?

Start by finding out what personal information you hold, where it lives, and who can reach it.

That data inventory is the foundation of both a WISP and a HIPAA risk assessment, and a cybersecurity assessment covers much of the IT side: device inventory, network map, patch status, and backup verification.

For a longer explanation of the rules by industry, read our guide to IT compliance for New England law, finance, and healthcare firms.

Make sure your IT matches your WISP.

Call 617-965-4615

Frequently Asked Questions

Does my Massachusetts business need a WISP?

If your business owns or licenses personal information about Massachusetts residents, 201 CMR 17.00 generally requires a Written Information Security Program. Employee payroll records alone often include that kind of information. Your attorney can confirm how the regulation applies to you.

What counts as personal information under 201 CMR 17.00?

Generally, a Massachusetts resident’s first name or first initial and last name combined with a Social Security number, a driver’s license or state ID number, or a financial account or credit or debit card number. Check the regulation or ask your attorney for the exact definition.

Can you write our WISP for us?

We help businesses create and maintain the IT and security portions of a WISP, and we make sure the document matches the controls actually in place. Legal review of the final program should come from your attorney.

Do you help with HIPAA compliance?

Yes, on the IT side. We put in place and maintain controls such as access management, encryption, audit logging, backups, and documentation that support HIPAA requirements. We are not a compliance auditor and do not give legal advice.

What IT controls does 201 CMR 17.00 expect?

Among other things: secure authentication, access controls, encryption of personal information on laptops, portable devices, and public or wireless networks, current firewalls, patches, and malware protection, system monitoring, and employee training.

Related Services

Ready When You Are.

Systems Analysis Services · 335 Auburn Street, Newton, MA 02466
Mon–Fri 9am–5pm · Call after hours for emergencies

Scroll to Top