Court Rules
All enforcement actions
SettlementMedium RiskMultistate

CT and MA AGs Settle with Comstar for $515K Over Patient Data Breach

Comstar, LLCJanuary 28, 2026Connecticut Attorney General

Penalty Amount

$515,000

Consumers Affected

349,255

Summary

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

Remedy

Comstar must pay $515,000 and implement security measures including phishing protection software, vulnerability management program, multi-factor authentication, and conduct annual security assessments for three years with reports to the Connecticut and Massachusetts Attorneys General.

Monetary PenaltyCompliance ProgramAudit RequirementReporting Requirements

Laws Cited

Connecticut and Massachusetts security and consumer protection lawsHealth Insurance Portability and Accountability Act (HIPAA)

Violation Types

Entity Details

Entity

Comstar, LLC

Also known as: Comstar

Industry

Healthcare

Multistate Coalition

Official Sources

Related Enforcement Actions

MA

Comstar, LLC

$515K

Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.

CT

Spruce Power 3, LLC

$100K

The Connecticut Attorney General announced a $100,000 settlement with Spruce Power 3, LLC to resolve an investigation into billing, customer service, and warranty issues stemming from consumer complaints. The settlement includes refunds for improper charges and requires reforms to improve billing practices and response times. Separately, an investigation was initiated into SunStrong Management LLC based on approximately 65 consumer complaints regarding warranty failures, unresponsiveness, and fees.

CT

U.S. Department of Education

Connecticut Attorney General William Tong joined a coalition of 17 attorneys general in filing a lawsuit against the U.S. Department of Education to stop new data reporting requirements under IPEDS that demand detailed student information. The coalition argues the requirements are unlawful, arbitrary, and jeopardize student privacy by requesting in-depth data that could lead to inadvertent errors and baseless investigations. The lawsuit seeks an injunction to block the implementation of these requirements.

CT

Department of Education

Connecticut Attorney General William Tong, joined by 17 other attorneys general, filed a lawsuit against the U.S. Department of Education to block new IPEDS data reporting requirements that demand student information disaggregated by race and sex. The coalition argues the rushed implementation is unlawful, invades student privacy, and risks unreliable data and baseless investigations. They seek an injunction to halt the data collection and protect student privacy.

CT

Aquarion Company

PURA preliminarily approved the sale of Aquarion Water Company to a new nonprofit Aquarion Water Authority, expected to double water rates. Attorney General Tong opposes the decision, citing loss of public oversight and high costs to consumers. The conversion removes PURA regulation, placing rate approvals under a board with no history of rejecting hikes.

CT

JRK Property Holdings

$5.1M

Connecticut Attorney General William Tong secured a $5.1 million financial relief package for tenants of the Concierge Apartments in Rocky Hill following an investigation into unsafe living conditions and landlord mismanagement. The agreement provides cash payments, free rent, and utility waivers to displaced and affected tenants, with a second agreement pending to address long-term accountability and communications.