The Massachusetts Office of Consumer Affairs and Business Regulation has extended the deadline for compliance with the state's new information security regulations from January 1, 2009, to May 1, 2009. The regulations require all businesses that own, license, store or maintain personal information about a resident of Massachusetts to adopt a comprehensive, written information security program. The security program must include a computer security system that encrypts all records and files containing personal information, including all employee and consumer information.
The Massachusetts regulator has extended the deadline to accommodate businesses that may be experiencing financial challenges brought on by recent economic conditions. The new Massachusetts compliance coincides with the FTC's extended compliance date for the "Red Flag" information security and identity theft rules.