Comstar Settles HIPAA Violations with State Attorneys General for $515,000

Massachusetts Attorney General Andrea Joy Campbell has announced a settlement has been agreed with the ambulance billing company Comstar LLC to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and Massachusetts Data Security Regulations.

The settlement includes a $515,000 financial penalty, $415,000 of which will be paid to the Office of the Attorney General of Massachusetts, and $100,000 will be paid to the Office of the Attorney General of Connecticut, which participated in the action.

An investigation was launched in response to a March 2022 ransomware attack. A threat actor gained access to Comstar’s servers, exfiltrated files, and encrypted data. The file review confirmed that the stolen files included protected health information (PHI) such as names, Social Security numbers, driver’s license numbers, financial account information, and medical assessment information. The PHI of 585,621 individuals was compromised in the incident, including 326,426 Massachusetts residents and 22,829 Connecticut residents.

AG Campbell alleged that Comstar had not maintained an adequate Written Information Security Program (WISP) prior to the ransomware attack, which should have allowed Comstar to identify reasonably foreseeable risks and evaluate the effectiveness of its cybersecurity safeguards.

In addition to paying the financial penalty, Comstar is required to develop and maintain an effective WISP and implement additional security measures, including anti-phishing software, multifactor authentication, and security software for all desktop computers and laptops on its network. Comstar is also required to develop and maintain an accurate asset inventory and must conduct a security assessment at least once a year for the next three years. The results of the assessments must be submitted to both the Massachusetts and Connecticut Attorneys General. The consent judgment was filed in the Suffolk Superior Court on January 28, 2026, and is awaiting approval from the court.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/