Massachusetts-based ambulance billing and collections firm Comstar agreed to pay $515,000 to settle allegations by the Massachusetts and Connecticut attorneys general that it violated HIPAA and state data security requirements following a March 2022 ransomware attack. Reporting indicates the intruder accessed Comstar’s network, exfiltrated files, and then encrypted systems with ransomware; exposed data included names, Social Security numbers, driver’s license numbers, financial data, and medical/assessment information. The incident ultimately affected ~585,621 individuals (including large numbers of Massachusetts and Connecticut residents), and regulators cited failures such as not conducting a comprehensive risk analysis for ePHI; separate federal enforcement by HHS OCR was resolved via a $75,000 penalty and a corrective action plan.
The Comstar case is being highlighted as a practical example that healthcare breaches can trigger stacked consequences—federal enforcement, state AG actions, and class-action litigation—in addition to extortion demands from ransomware operators. The breach’s downstream impact extended to organizations that had used Comstar as a vendor years earlier, with some providers reporting that their patients’ data was implicated even if the provider was no longer a Comstar client at the time of the incident. Separate reporting on class-action settlements involving Texas and New Jersey dermatology practices concerns different incidents and does not materially add to the Comstar enforcement story.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-28, the Massachusetts and Connecticut Attorneys General filed a proposed $515,000 settlement in Suffolk Superior Court over alleged HIPAA and Massachusetts data security violations. The consent judgment requires Comstar to implement a written information security program, specific security controls, and annual third-party assessments for three years.
In May 2025, HHS OCR announced a $75,000 settlement with Comstar and imposed a corrective action plan. OCR found Comstar had failed to conduct a comprehensive and accurate HIPAA risk analysis for ePHI and cited delayed detection of the intrusion.
Class-action litigation stemming from the Comstar breach was filed, later consolidated, and settled in December 2022. The settlement terms were not made public.
In May 2022, Comstar reported that patient personal data and protected health information had been encrypted in the incident. It later notified HHS that 68,957 patients were affected.
On 2022-03-26, Comstar detected a ransomware incident in which a threat actor exfiltrated files and encrypted data. A forensic investigation later confirmed protected health information and other sensitive data had been stolen.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.