News

Why Mass. 201 CMR 17 Deadline Was Extended

Companies that live or do business in Massachusetts have a few extra months to meet compliance deadlines for the state's tough 201 CMR 17 data protection law. The simple reason: Too few understand the law to meet the original January deadline (Part 1 in a series)

By Bill Brenner, Senior Editor

Page 2

Daniel, who ultimately believes the law is "legislating common sense," noted that it's probably going to be well beyond May 1 before implementers get all their compliance work done.

"I'll be startled if this doesn't change again at least a little bit in the next six months do to financial pressures. Spending on additional security isn't a popular thing right now."

Though companies may be grateful that the state is allowing more leeway in light of the current economic crisis, security pros at the NAISG meeting suggested compliance is going to take more time simply because the details are still too new and undigested.

One attendee whose clients include a healthcare organization worried aloud that it's going to be exceedingly difficult for operations like his to prove that every third-party "average Joe" has the necessary encryption in place when trading electronic communications. Daniel noted this is particularly challenging in schools and small doctors offices, where IT controls are far more scattered than larger enterprise networks.

Ed Ziots, a Rhode Island-based network engineer, questioned the ability of Massachusetts to enforce the law outside its borders.

"If my company is in Rhode Island and someone from Massachusetts comes in and buys something, how can Massachusetts enforce the law on us?" he asked. A Massachusetts law is not enforceable in Rhode Island."

To that, Daniel said it might be possible for an out-of-state company to get away with some isolation, but that it "probably wouldn't be wise to mount a challenge."

Part 2 of this series will focus on whether 201 CMR 17's requirements are overdue, or if they go too far.

Other stories by Bill Brenner

201 CMR 17

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors