Mass. data security law is nation's toughest.

PositionLEGISLATION

The toughest law regulating the use of personally identifiable information in the United States went into effect March 1, 2010, in Massachusetts.

The Massachusetts Data Breach Law, passed in 2007. requires personal information in networked systems to be protected by strong encryption, firewalls, antivirus. access controls, and a formal security plan.

The law is a response to the TJX Companies data breach in 2007 in which more than 45 million credit card accounts were breached by a hacker.

The regulation defines "personal information" as name plus a Social Security number, driver's license or other government-issued number, or bank or credit card account number, The National Law Journal reported.

According to Government Computer News (GCN), the law is designed to ensure "the security and confidentiality of customer information," based on current industry standards, focusing on threats that can or should be anticipated. The regulations consider the size of a business, the amount of resources available to it, the amount of personal data held, and the sensitivity of that data. It requires that paper and electronic records be protected by physical and IT security.

[ILLUSTRATION OMITTED]

GCN reported that...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT