Compliance - Massachusetts MGL 93H CMR 17
Massachusetts Data Security Standards (MGL 93H)
Massachusetts General Law Chapter 93H (MGL 93H) is a law requiring all businesses in Massachusetts to take serious measures to prevent identity theft. Any business holding personal information (PI) of a Massachusetts resident is subject to this law. PI includes resident names, social security numbers, driver’s license numbers, financial account numbers (including credit or debit card numbers), etc.
How DMsuite™ Solves the Problem
Axis DMsuite™ is a product that profiles, provisions, and redacts data without slowing down business processes or time-to-market. It integrates seamlessly with all existing platforms and applications, providing a flexible and cost-effective way to secure customer and company data throughout your entire enterprise. Its components work in concert to provide a comprehensive solution to MGL 93H privacy compliance.
- DMProfiler - Understanding where the data is challenging, but it's very important. If you don't know where your data is you can't secure it. The profiler searches databases for personal information, locating and documenting the source and recipient systems throughout the information supply chain.
- DMGenerator – Many people and systems need access to sets of data for entirely legitimate reasons, and preventing or complicating that access can grind your business to a halt. DMgenerator masks and provisions personal information in such a way that it maintains its value for other uses. The enterprise can tailor masking methods to their unique protection needs without application reengineering or any significant impact on testing. DMgenerator produces a clearly auditable result with a measurable, documented, and repeatable process for protecting personal information.
- DMCertify – Data security is never a one-time fix. Changing processes and ongoing development frequently begin to reintroduce personal information into repositories after a masking exercise has been completed. DMcertify periodically evaluates and recertifies environments to ensure ongoing security, and periodically report on compliance.
- DMMonitor – Any security plan needs a watchful eye to identify and stop suspicious activity. DMmonitor continually assesses personal information access, ensuring that only authorized personnel are accessing PHI. Its alerting mechanisms enable immediate action for security breaches.
Contact us today to find out how DMsuite can be meet your data privacy requirements.


