Massachusetts data breach notifications
Persons holding personal information about Massachusetts residents must notify the Office of Consumer Affairs and Business Regulation and the Attorney General following discovery of a breach.
How DisclosureLens indexes Massachusetts filings
DisclosureLens polls the Massachusetts AG portal on a regular schedule, fetches each new notice, extracts a structured BreachDisclosure v1 record, resolves the affected entity to its LEI/CIK when possible, and publishes via the REST API (webhooks and STIX/TAXII delivery are planned).
Extraction provenance
Extracted records carry per-field source citations into the Massachusetts AG notice they came from, plus a per-record confidence score and a full extraction audit trail. Massachusetts filings inherit the same BreachDisclosure v1 schema as SEC 8-Ks, HHS OCR notices, and EU DPA registers — same fields, same provenance metadata, deduped against same-incident filings in other jurisdictions. Full pipeline details: Sources & Methodology.
Statute
M.G.L. c. 93H
Authoritative source
https://www.mass.gov/lists/data-breach-reports
Corrections
Email corrections@disclosurelens.com — 48-hour SLA from receipt.