Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Massachusetts Opens Data Breach Notification Archive to Public

The Commonwealth of Massachusetts this week made an important step toward improving data breach transparency, as the Office of Consumer Affairs and Business Regulation (OCABR) made its Data Breach Notification Archive publicly available online.

The Commonwealth of Massachusetts this week made an important step toward improving data breach transparency, as the Office of Consumer Affairs and Business Regulation (OCABR) made its Data Breach Notification Archive publicly available online.

As its name suggests, the Data Breach Notification Archive was meant to keep records of accidental or intentional/malicous compromise of personal information. The archive was built as notifications came from entities that keep a Massachusetts resident’s personal information, because all are required by the Massachusetts Data Security Law to notify affected residents, OCABR, and the Attorney General’s Office of such incidents.

Previously, the information maintained by OCABR was available only through Public Records Requests, but that changed yesterday when the archive became publicly accessible.

The data breach reports are available on OCABR’s website in the form of PDF files that include information on when the breach was reported, the affected organization, the number of impacted residents, and information on the type of compromised personal information.

The reports include details on cyber-attacks, as well as information on incidents that occur in the physical word. Information on external hacks, unintentional data leaks, insider attacks, misplaced documents or devices, and other similar incidents is included in these reports.

Data included in the reports was gathered from various industries, including financial, manufacturing, retail, healthcare, hospitality, education, and more. Each entry is marked as an electronic (cyber) compromise or not.

A quick look at the 2016 Data Breach Report (PDF) shows that hundreds of such incidents have been reported last year, and that tens of thousands of Massachusetts residents were affected. Some 33,000 were impacted by the malware attack that hit Eddie Bauer stores, for example, while the Omni Hotels incident impacted only 1,000.

“The Data Breach Notification Archive is a public record that the public and media have every right to view. Making it easily accessible by putting it online is not only in keeping with the guidelines suggested in the new Public Records law, but also with Governor Baker’s commitment to greater transparency throughout the Executive Office,” Consumer Affairs Undersecretary John Chapman said.

Advertisement. Scroll to continue reading.

Related: MIT Network Under Frequent DDoS Assault: Report

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Watch Now

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

People on the Move

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.