Comstar Ransomware Investigation Uncovers HIPAA Risk Analysis Failure
An investigation of a 2022 ransomware attack at Comstar uncovered a HIPAA risk analysis failure. Comstar settled the alleged HIPAA violation and paid a $75,000 financial penalty. Comstar is a Massachusetts-based provider of billing, collection, consulting, Electronic Patient Care Reporting (ePCR) hosting, and client/patient services for non-profit and municipal ambulance services. As a business associate of HIPAA-covered entities, Comstar is required to comply with the HIPAA Rules.
On March 26, 2022, Comstar learned that a threat actor had gained access to its network and used ransomware to encrypt files, with its IT services vendor started receiving support tickets. The investigation revealed that the threat actor first accessed its network on March 19, 2022. OCR was notified about the data breach, currently listed on the OCR breach portal as a network server hacking incident affecting 68,957 individuals, and launched an investigation to determine if Comstar was compliant with the HIPAA Rules.
Currently, OCR’s main focus is whether HIPAA-regulated entities have conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). This is the most commonly identified HIPAA Security Rule violation, and by focusing on this requirement, OCR will be able to clear its backlog of data breach investigations more quickly.
OCR reports that at the time of the ransomware attack, Comstar had more than 70 HIPAA-covered entity clients, and the breach involved the protected health information of 585,621 individuals. OCR determined that a HIPAA-compliant risk analysis had not been conducted prior to the breach, and notified Comstar of its intention to impose a financial penalty. Comstar accepted OCR’s offer of settling the alleged HIPAA violation informally, and agreed to pay a $75,000 financial penalty and adopt a corrective action plan. Comstar is required to conduct a HIPAA-compliant risk analysis, subject any identified risks to a risk management process to mitigate those risks, and develop and implement policies and procedures to ensure HIPAA compliance. The workforce must be provided with the revised policies and procedures and receive training.
This was the 9th enforcement action under OCR’s risk analysis enforcement initiative to result in a financial penalty, and OCR’s 16th financial penalty of the year to resolve HIPAA violations, equaling last year’s total of 16 financial penalties in just the first 5 months of the year.