This document summarizes new privacy laws and regulations in Massachusetts, including the Massachusetts Data Privacy Regulations that take effect March 1, 2010. It discusses requirements for developing a comprehensive written information security program under the new regulations, including designating a compliance officer, identifying risks, imposing security policies, overseeing vendors, and more. It also outlines specific computer system security requirements, such as encryption, firewalls, passwords, and employee training. Breach notification requirements are summarized, including when and how to notify individuals and the Attorney General of a breach.