Skip to content

Cyber Liability by state

Massachusetts data breach notification law and cyber insurance

Direct answer

What is Massachusetts's data breach notification law?

Massachusetts's breach notification law (Mass. Gen. Laws ch. 93H) requires businesses to notify affected residents as soon as practicable and without unreasonable delay after a breach of personal information. Massachusetts requires businesses to notify affected residents, the Attorney General, and the Office of Consumer Affairs of breaches of unencrypted personal information without unreasonable delay.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Massachusetts requires businesses to notify affected residents, the Attorney General, and the Office of Consumer Affairs of breaches of unencrypted personal information without unreasonable delay. Cyber liability insurance typically covers the forensics, notification, and legal review this statute requires.

Consumer notification deadline
As soon as practicable and without unreasonable delay
Regulator notice
Notify the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation as soon as practicable and without unreasonable delay.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired.
Enforcement
Violations are enforceable by the Attorney General under the state's consumer protection law, which authorizes civil penalties.

Statutes and sources

  • Massachusetts Data Breach Notification Law

    Mass. Gen. Laws ch. 93H

Regulator: Massachusetts Attorney General . Last verified 2026-07-29 from the official source .

Get Massachusetts coverage handled

Share a few details and an agent will respond within one business day.