Mass. law requires data to be protected

SENSITIVE SUBJECT: Eric Shorr of PC Troubleshooters, standing, speaks at last weeks’ panel discussion on data protection at the Providence Marriott. /
SENSITIVE SUBJECT: Eric Shorr of PC Troubleshooters, standing, speaks at last weeks’ panel discussion on data protection at the Providence Marriott. /

When an employee loses a laptop or a BlackBerry, you can replace the device easily enough. The real worry, however, is what could happen to the data stored inside it, such as credit card numbers or other sensitive information.
And thanks to a new law in Massachusetts, businesses with customers and/or employees from the Bay State are getting very concerned. The state recently adopted a new identity protection law that applies to every company – within the borders or beyond – that has personal financial information on any resident of the state.
With that in mind, Rhode Island business owners are educating themselves about the new law – which took effect May 1 – and are taking steps to ensure they comply. Many recently showed up at the Providence Marriott Downtown for a panel discussion on the issue hosted by Ananke IT Solutions and PC Troubleshooters Inc.
“There is a question as to whether the Massachusetts attorney general can enforce these regulations outside the state,” attorney Mark Schreiber, a litigation partner in the Boston office of Edwards Angell Palmer & Dodge, told the crowd. “But you don’t want to be the test case.”
The main message at the forum: Every company that handles customers’ credit information, employees’ social security numbers, or other personal financial data should be taking steps to protect that information.
“A lot of you have customers who trust you with their data,” said panel member Matthew Putvinski, director of the information technology assurance group at the accounting and consulting firm Wolf & Co. “When they provide it, you have to protect it.”
John Conway, Ananke president and CEO, pointed out that the negative publicity surrounding a security breach could harm a company, regardless of the outcome of any resulting litigation. “If there’s a law suit, regardless of who wins, you lose,” he said.
The Massachusetts law specifies that businesses must implement a written information-security program to safeguard personal financial data. They are required to encrypt personal information that will be transmitted over the Internet or stored on laptops and other portable devices, and to utilize up-to-date firewall protection. In addition, companies must ensure that only authorized users have access to data. Those businesses that fail to do so could face fines of up to $5,000 for each violation, plus restitution costs. There are also fines for improper data disposal.
Massachusetts lawmakers adopted the measure in the wake of worldwide headlines about the 2007 hacking episode involving The TJX Companies Inc. that eventually cost companies and insurers more than $200 million.
“For companies across the country, the Massachusetts law is dictating what their security plan will be,” Schreiber said. “But that’s not necessarily a bad thing.” And it’s not likely to be the last such law enacted, he said.
Schreiber noted there are also new federal regulations – called “Red Flag Rules” – that require creditors and financial institutions to implement identity theft prevention programs as well. Companies that comply with the Massachusetts law will meet the federal standards, he said.
Putvinski outlined a number of steps companies can take to protect data:
• Identify which vendors are provided with sensitive information, and make sure they are taking proper security precautions.
• Protect any paper records stored at your office. Tell employees to clean paperwork off their desks at the end of the day.
• Train all employees on security measures, and set aside time to ensure they review them yearly.
• Prepare for a breach. “You can’t plan for every breach, but you can know who you’ll call to handle forensics. … You can know what sort of message you’ll release,” Putvinski said.
Many of those who attended the event are already on the way to meeting the new Massachusetts requirements.
“I sell cruises in Rhode Island, but Massachusetts residents are probably half my clientele,” said Dick Bowman of North Providence, who books vacations as owner of the Cruise One franchise.
Chris Sheehan, a compliance agent with Shred-It, a secure disposal company based in Cranston, said he’s been certified in the Massachusetts regulations, and is now helping clients write their policies.
“It makes it easier for me to reassure folks,” he said. “I’m very busy now because of the law.” •

No posts to display