HIPAA Compliance in Massachusetts: What Chapter 93H Adds

Practical guidance for healthcare teams and business associates

A three-dentist practice in Worcester loses a laptop. The billing coordinator kept a spreadsheet on it with patient names, dates of birth, and, for a few hundred accounts, Social Security numbers. The practice knows the federal clock: 60 days to notify patients under the HIPAA Breach Notification Rule. What it may not know is that Massachusetts expects a separate notice to the Attorney General and to the Office of Consumer Affairs and Business Regulation, that the notice cannot wait until the head count is final, and that the practice now owes those patients 18 months of credit monitoring.

OCR (the HHS Office for Civil Rights) enforces the federal rules in Massachusetts the same way it does everywhere else. The University of Massachusetts settled potential HIPAA violations with OCR following a malware infection, announced November 22, 2016. Below: how the two layers fit together, the state statutes that stack on HIPAA, the breach rules, the penalties, provider-type notes, and a checklist.

HIPAA Compliance Massachusetts: How Federal and State Rules Interact

HIPAA (Health Insurance Portability and Accountability Act) sets a national floor. The preemption rule at 45 CFR 160.203 says a federal standard "that is contrary to a provision of State law preempts the provision of State law," with exceptions. The exception that matters for privacy is 160.203(b): state law survives when it "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule.

"More stringent" is defined at 45 CFR 160.202. A state law qualifies when, among other tests, it "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted," gives the patient greater access rights, or "provides for the retention or reporting of more detailed information or for a longer duration." In plain terms: where Massachusetts is stricter about privacy, Massachusetts wins; where HIPAA is stricter, HIPAA wins; a practice has to satisfy both at the same time.

Massachusetts has no single health privacy statute the way California has the CMIA or Texas has HB 300. It has Chapter 93H, 201 CMR 17.00, Chapter 93I, and record-specific statutes for HIV tests, genetic information, hospital records, and mental health records, and none of them steps aside because a practice already follows HIPAA. The general picture is in state privacy laws vs federal HIPAA.

Who Qualifies as a Covered Entity in Massachusetts

The definition is federal and lives at 45 CFR 160.103: a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." In Massachusetts that captures hospitals and health systems, physician groups, dental practices, behavioral health providers, home health agencies, nursing homes, pharmacies, and the health plans that pay them. A cash-only practice that never bills electronically can fall outside the federal definition, though it is still bound by the state statutes below. The full test is in what is a covered entity under HIPAA.

Who Qualifies as a Business Associate in Massachusetts

Also federal, also 160.103: a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing." Billing companies, EHR and cloud vendors, IT firms with system access, answering services, shredding companies that handle records, and their subcontractors all qualify, and each one needs a signed business associate agreement.

Massachusetts adds a parallel state duty: under Chapter 93H, section 3(a), a person that "maintains or stores, but does not own or license" personal information must notify the owner "as soon as practicable and without unreasonable delay" after a breach, and cooperate with it.

Massachusetts Privacy Laws That Stack on Top of HIPAA

Chapter 93H: Security Breaches

M.G.L. c. 93H is the state's data breach statute. Section 1 defines personal information as a resident's first name or initial and last name combined with a Social Security number, a driver's license or state ID number, or a financial account or card number. Medical information is not on that list. That matters: a breach of diagnoses alone triggers HIPAA but may not trigger Chapter 93H, while a breach of a billing file with Social Security numbers triggers both.

A "breach of security" under section 1 is "the unauthorized acquisition or unauthorized use of unencrypted data or, encrypted electronic data and the confidential process or key that is capable of compromising the security, confidentiality, or integrity of personal information ... that creates a substantial risk of identity theft or fraud against a resident of the commonwealth." "Encrypted" means a 128-bit or higher algorithmic process. Full-disk encryption on every laptop and phone is the cheapest way to keep a lost device out of this statute.

201 CMR 17.00: The Written Information Security Program

Section 2 of Chapter 93H directed the Office of Consumer Affairs and Business Regulation (OCABR) to adopt regulations to "safeguard the personal information of residents of the commonwealth," taking into account "the person's size, scope and type of business, the amount of resources available to such person, the amount of stored data, and the need for security and confidentiality." The result is 201 CMR 17.00, which OCABR describes as minimum standards for the "safeguarding of personal information contained in both paper and electronic records." It is best known for requiring a written information security program, the WISP that the state's breach notice asks about by name: section 3(b) of Chapter 93H requires the notice to the Attorney General to state "whether the person or agency maintains a written information security program."

Chapter 93I: Disposal of Records

M.G.L. c. 93I, section 2 sets minimum disposal standards. Paper records containing personal information must be "redacted, burned, pulverized or shredded so that personal data cannot practicably be read or reconstructed," and electronic media must be "destroyed or erased" to the same standard. A violation carries a civil fine of up to $100 per data subject, capped at $50,000 per instance of improper disposal, recoverable by the Attorney General.

Chapter 111, Section 70F: HIV Tests

No facility, physician, or health care provider may test a person for HIV without "verbal informed consent," may disclose the result to anyone other than the subject without "written informed consent," or may identify the subject of the test without the same. The consent form must state the purpose of the release and "shall be distinguished from written consent for the release of any other medical information." A general HIPAA authorization does not satisfy this. A violation is treated as a violation of Chapter 93A, section 2.

Chapter 111, Section 70G: Genetic Information

Genetic testing requires "prior written consent" on a form that "shall not be a general waiver or consent for genetic testing," and release of genetic information requires "informed written consent" on a form that, again, must be distinguished from consent for other medical records. Practices that order genetic panels or run hereditary disease programs need a separate consent document, alongside the federal HIPAA authorization.

Chapter 111, Sections 70 and 70E, and Chapter 112, Section 12CC: Records and Access

Section 70E gives every patient in a licensed facility the right "to confidentiality of all records and communications to the extent provided by law" and the right to inspect and copy the record. Section 70 caps hospital and clinic copy fees at a base charge of $15 per request, $0.50 per page for the first 100 pages, and $0.25 per page after that, and it requires the notice of privacy practices to state the facility's records termination policy. Section 12CC of Chapter 112 applies the inspection and copy right to individual providers, dentists included, and lets a psychotherapist furnish a summary when the full record would harm the patient. HIPAA's own 30-day access deadline at 45 CFR 164.524(b)(2) runs in parallel; see the right of access guide.

Chapter 123, Section 36: Mental Health Facility Records

Facilities licensed by the Department of Mental Health must keep patient records "for at least 20 years after the closing of the record due to discharge, death or last date of service," and may not destroy them without notifying the Department of Public Health. HIPAA's six-year rule at 45 CFR 164.316(b)(2)(i) covers compliance documentation, not the chart. The retention picture for other provider types is in how long to keep medical records.

Massachusetts Breach Notification Requirements

The federal rule first: 45 CFR 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," 164.408 requires HHS notice at the same time for breaches of 500 or more individuals and an annual log for smaller ones, and 164.406 requires media notice for breaches involving "more than 500 residents of a State or jurisdiction." The walkthrough is in the Breach Notification Rule guide.

The Chapter 93H Clock: As Soon as Practicable

Massachusetts does not set a day count. Section 3(b) requires a person that owns or licenses personal information to give notice "as soon as practicable and without unreasonable delay" to three parties: the Attorney General, the director of OCABR, and the affected resident. The same section adds a rule that catches practices off guard: "A notice provided pursuant to this section shall not be delayed on grounds that the total number of residents affected is not yet ascertained."

What the Attorney General and OCABR Notice Must Contain

Section 3(b) lists the contents: the nature of the breach, the number of residents affected at the time of notice, the name and address of the entity, the person reporting, the person responsible if known, the type of personal information compromised, whether the entity maintains a written information security program, and the steps taken or planned, "including updating the written information security program." A sample copy of the consumer notice goes to both offices. If the breach included Social Security numbers, section 3A requires a contract with a third party to offer each affected resident credit monitoring at no cost "for a period of not less than 18 months," and the entity must file a report with the Attorney General and OCABR confirming the offer. The resident letter, by contrast, "shall not include the nature of the breach of security or unauthorized acquisition or use, or the number of residents of the commonwealth affected," the opposite of the federal letter under 164.404(c); counsel should reconcile the two before anything is mailed.

Does a HIPAA Notice Satisfy Massachusetts?

Partly. Section 5 of Chapter 93H says a person that follows federal breach procedures "is deemed to be in compliance with this chapter if the person notifies affected Massachusetts residents in accordance with the maintained or required procedures," but only "provided further that the person also notifies the attorney general and the director of the office of consumer affairs and business regulation of the breach as soon as practicable and without unreasonable delay." The state regulator notices never go away.

ItemFederal HIPAAMassachusetts Chapter 93H
TriggerBreach of unsecured PHI (164.402), presumed unless a four-factor risk assessment shows a low probability of compromiseUnauthorized acquisition or use of personal information creating a substantial risk of identity theft or fraud
Data coveredAny P.H.I. (Protected Health Information)Name plus SSN, license or state ID number, or financial account number
Individual noticeWithout unreasonable delay, no later than 60 calendar days after discoveryAs soon as practicable and without unreasonable delay; no waiting for a final count
Regulator noticeHHS, with individual notice if 500 or more; annual log if fewerAttorney General and OCABR, every qualifying breach, any size

HIPAA Penalties in Massachusetts

Federal OCR Enforcement

Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted for inflation at 45 CFR 102.3. The amounts in force under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. The history is in the 2026 penalty amounts post.

Massachusetts Attorney General Enforcement

Section 6 of Chapter 93H authorizes the Attorney General to "bring an action pursuant to section 4 of chapter 93A." Under 93A, section 4, a court may impose a civil penalty of "not more than five thousand dollars for each such violation" when the person "knew or should have known" the conduct was unlawful, plus the reasonable costs of investigation and litigation, including attorneys' fees. Violations of the HIV statute are 93A violations by definition.

HIPAA Compliance for Massachusetts Healthcare Providers

Massachusetts Hospitals and Health Systems

Hospitals carry the heaviest state layer: the section 70 fee caps and records termination policy in the notice of privacy practices, the section 70E rights notice at admission, section 70F HIV consent, section 70G genetic consent, and Chapter 123, section 36 for any DMH-licensed unit. Review the BAA list at least annually.

Massachusetts Dental Practices

A dental office becomes a covered entity with its first electronic claim. Chapter 112, section 12CC governs record inspection and copies. The biggest state exposure is Chapter 93H, because billing files carry Social Security numbers: encrypt every device, write the WISP, and keep an Attorney General notice template ready.

Massachusetts Behavioral Health Providers

Psychotherapists may furnish a summary under section 12CC when the full record would harm the patient, DMH-licensed facilities keep records 20 years under Chapter 123, section 36, and any program holding substance use disorder records also answers to 42 CFR Part 2.

Massachusetts Home Health and Long-Term Care

Nursing homes and rest homes are "facilities" under section 70E, so the rights notice applies at admission. Home health runs on phones and laptops in the field, which is what Chapter 93H's encryption definition was written for, and every field vendor that touches PHI needs a BAA.

Massachusetts HIPAA Compliance Checklist

RequirementFederal or StateDeadline or FrequencyDocumentation
Security risk analysis and risk managementFederal, 164.308(a)(1)Ongoing; review at least annuallySigned risk analysis, remediation plan
Written information security program (WISP)State, c. 93H s. 2 and 201 CMR 17.00In place before a breach; keep currentWISP document, review dates
BAA with every PHI vendorFederal, 164.308(b) and 164.504(e)Before access; review annuallySigned BAA per vendor
Breach notice to individualsFederal and state60 days federal; as soon as practicable stateLetters, mailing proof
Breach notice to Attorney General and OCABRState, c. 93H s. 3(b)As soon as practicable, any sizeFiled notices, sample consumer letter, s. 3A report
Credit monitoring offerState, c. 93H s. 3AWhen SSNs are involved; 18 months minimumVendor contract, enrollment instructions
HIV and genetic consent formsState, c. 111 ss. 70F and 70GBefore testing and before any releaseSigned separate consents
Records disposalState, c. 93I s. 2Every disposalShredding vendor receipts, media destruction log

A Note on the Proposed Security Rule Update

The January 2025 proposed Security Rule update (explicit encryption, multifactor authentication, asset inventories) is proposed, not final, and OCR is not enforcing it. Massachusetts practices already have a state reason to encrypt: under Chapter 93H, encrypted data with the key intact is not a breach of security. This article is educational information, not legal advice; a practice facing a real incident should involve counsel early.

---

FAQ

Does Massachusetts have its own HIPAA law?

Not a single one. Massachusetts layers a general data breach and security statute (M.G.L. c. 93H), the 201 CMR 17.00 data security regulation, a records disposal law (c. 93I), and record-specific statutes for HIV tests, genetic information, hospital records, and mental health records on top of federal HIPAA. HIPAA still applies in full.

How quickly must a Massachusetts practice report a data breach?

Federal HIPAA requires individual notice without unreasonable delay and no later than 60 calendar days after discovery. Chapter 93H requires notice to the Attorney General, the Office of Consumer Affairs and Business Regulation, and affected residents as soon as practicable and without unreasonable delay, and the notice may not be held back until the number of residents affected is known.

Does a HIPAA breach letter satisfy Chapter 93H?

Only partly. Section 5 of Chapter 93H deems an entity that follows federal breach procedures compliant for the resident notice, but only if it also notifies the Attorney General and OCABR as soon as practicable. The state letter also has content rules of its own, including a ban on describing the nature of the breach and the number affected.

What is a WISP and does a medical practice need one?

A written information security program, required by 201 CMR 17.00, the regulation OCABR issued under Chapter 93H. Any person that owns or licenses personal information about Massachusetts residents is covered. A practice with a documented HIPAA Security Rule program has most of the content already; the state breach notice asks whether a WISP exists.

Who enforces health privacy law in Massachusetts?

OCR enforces federal HIPAA. The Massachusetts Attorney General enforces Chapter 93H and Chapter 93I through Chapter 93A actions, with civil penalties of up to $5,000 per violation under 93A. Licensing boards and the Department of Public Health handle the record-keeping statutes for their licensees.

Conclusion

The federal program comes first, and the Massachusetts layer sits on top of it: the Attorney General and OCABR notices, the written information security program, and the separate consent forms for HIV, genetic, and mental health records. One Guy Consulting's Full-Scope plan builds the federal program and maps the state layer onto it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading