Joan Goodchild
Contributor

Massachusetts makes changes to ID theft regulations

News
Aug 18, 20092 mins

State regulators in Massachusetts have made changes to a set of identity theft regulations.

Worst moments in network security history.

The changes, according to a release from the state’s Office of Consumer Affairs and Business Regulation, maintain protections and also reinforce flexibility in compliance by small businesses and were made in response to concerns among small businesses who were concerned the proposed regulations would be too costly to put in place. The updated regulations will take effect March 1, 2010.

“The regulations make clear that their approach to data security is a risk-based approach that is especially important to small businesses that may not handle a lot of personal information about customers,” state officials said in a statement. “Under a risk-based approach, a business, in developing a written security program, should take into account its size, nature of its business, the kinds of records it maintains, and the risk of identity theft posed by its operations.”

Officials said the new changes recognize that the size of a business and the amount of personal information it handles plays a role in the data security plan the business creates. The new language requires safeguards that are appropriate to the size, scope and type of business handling the information; the amount of resources available to the business; the amount of stored data; and the need for security and confidentiality of both consumer and employee information.

The changes, according to Massachusetts Undersecretary of the Office of Consumer Affairs and Business Regulation Barbara Anthony, make clear the regulations are risk-based in implementation, not just in enforcement as had been the case in earlier versions of the regulations. In addition, the regulations are technology neutral and acknowledge that technical feasibility plays a role in what many businesses, especially small businesses can do to protect data. The overall approach is more consistent with federal law, she said.

Whether it’s a small amount of employee paperwork, or a large amount of consumer information kept on an electronic database, each requires its own appropriate level of security and protection, Anthony said. The changes we are making reflect that reality without exposing companies or consumers to a heightened risk of theft.

The regulations are a product of the identity theft prevention law signed by Gov. Deval Patrick. Gov. Patrick signed an executive order last September requiring all state agencies to implement security measures consistent with the requirements in the regulations.

Joan Goodchild

Joan Goodchild is a veteran writer and editor with more than 20 years of experience covering cybersecurity, technology, and business strategy. She is the former editor-in-chief of CSO and has contributed to leading publications including CIO, Dark Reading, and SC Media. Joan has partnered with global security companies to produce thought leadership content, executive communications, and industry research. She is also the creator of CyberSavvy Mom, a consumer-focused brand that helps families be smart, secure, and civil online.

More from this author