We are tracking 50+ companies that sent data breach notification letters to Massachusetts residents and reported to the Massachusetts Attorney General. If you received a notice, you may qualify for compensation — at no cost to you.
Massachusetts Data Security Regulations (201 CMR 17.00) & M.G.L. c. 93H
Massachusetts has some of the nation's most rigorous data security requirements. 201 CMR 17.00 requires every company holding Massachusetts resident data to maintain a written information security program (WISP) — and failure to have one is itself a violation. Notification is required within a reasonable time and AG must be notified.
Massachusetts residents can pursue claims under Chapter 93A, which provides minimum $25 per violation — and triple damages for intentional violations. If a company lacked a proper security program, that's automatic liability.
Showing 50 most recent notification letters · Massachusetts has additional cases on file
Received a data breach notification letter from a company in Massachusetts? Find out if you qualify for compensation — no cost, no obligation.
Check My Eligibility →