Penalty Amount
$515,000
Consumers Affected
349,255
Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.
Comstar must pay $515,000 and implement security measures including phishing protection software, vulnerability management program, multi-factor authentication, and conduct annual security assessments for three years with reports to the Connecticut and Massachusetts Attorneys General.
In-house legal teams should review vendor agreements, data processing agreements, and Business Associate Agreements (BAAs) with entities like Comstar that handle sensitive patient data. Key clauses to scrutinize include data security standards, breach notification requirements, HIPAA compliance obligations, audit rights, and indemnification provisions. Given the settlement, contracts should be updated to mandate specific security measures such as phishing protection and annual security assessments, ensure prompt breach notification in line with state and federal laws, and include robust indemnification clauses to cover potential liabilities from data breaches involving protected health information.
Entity
Comstar, LLC
Also known as: Comstar
Industry
HealthcareOfficial Press Release
https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-announces-settlement-with-ambulance-billing-vendor
comstar final judgment on stipulation.pdf?rev=a352c9d2fe0b44
https://portal.ct.gov/-/media/ag/press_releases/2026/comstar---final-judgment-on-stipulation.pdf?rev=a352c9d2fe0b4456889717d556bfacdc&hash=AB1B7FC92347A3BA676BA8D0023409A9
Connecticut Attorney General Enforcement Page
https://portal.ct.gov/AG/Privacy/Privacy-Resources
"Comstar, LLC"
"$515,000"
"Health Insurance Portability and Accountability Act (HIPAA)"
"Connecticut and Massachusetts security and consumer protection laws"
"data breach"
"failing to implement basic, necessary security measures"
$515K
Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.
$2.0M
Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.
Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.
$275K
Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.
$4.0M
Connecticut Attorney General William Tong and the Federal Trade Commission announced a $4 million settlement with Manchester City Nissan (Chase Nissan LLC) resolving allegations that the dealership double-charged for 'certified pre-owned' vehicles and collected unauthorized junk fees. The settlement requires payment for consumer redress, prohibits misrepresentations, mandates clear disclosure of the maximum total price, and requires express informed consent for all charges.
Attorney General Tong and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and DHS to block demands for the personal information of 17 million CDL drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data transfer.