Penalty Amount
$515,000
Consumers Affected
349,255
Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.
Comstar must pay $515,000 and implement security measures including phishing protection software, vulnerability management program, multi-factor authentication, and conduct annual security assessments for three years with reports to the Connecticut and Massachusetts Attorneys General.
In-house legal teams should review vendor agreements, data processing agreements, and Business Associate Agreements (BAAs) with entities like Comstar that handle sensitive patient data. Key clauses to scrutinize include data security standards, breach notification requirements, HIPAA compliance obligations, audit rights, and indemnification provisions. Given the settlement, contracts should be updated to mandate specific security measures such as phishing protection and annual security assessments, ensure prompt breach notification in line with state and federal laws, and include robust indemnification clauses to cover potential liabilities from data breaches involving protected health information.
Entity
Comstar, LLC
Also known as: Comstar
Industry
HealthcareOfficial Press Release
https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-announces-settlement-with-ambulance-billing-vendor
comstar final judgment on stipulation.pdf?rev=a352c9d2fe0b44
https://portal.ct.gov/-/media/ag/press_releases/2026/comstar---final-judgment-on-stipulation.pdf?rev=a352c9d2fe0b4456889717d556bfacdc&hash=AB1B7FC92347A3BA676BA8D0023409A9
Connecticut Attorney General Enforcement Page
https://portal.ct.gov/AG/Privacy/Privacy-Resources
"Comstar, LLC"
"$515,000"
"Health Insurance Portability and Accountability Act (HIPAA)"
"Connecticut and Massachusetts security and consumer protection laws"
"data breach"
"failing to implement basic, necessary security measures"
$515K
Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.
$29.6M
Attorney General Jennifer Davenport joined a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, for allegedly conspiring to artificially inflate and manipulate prices, reduce competition, and restrain trade for numerous generic prescription drugs. The settlement includes cooperation in ongoing litigations and internal reforms to ensure fair competition.
$29.6M
Attorney General William Tong led a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, to resolve allegations of a widespread conspiracy to artificially inflate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. The settlement includes cooperation from Glenmark in ongoing multistate litigations and internal reforms to ensure fair competition and compliance with antitrust laws.
$18.0M
Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.
Attorney General William Tong joined a coalition of 12 attorneys general in suing to block the $110 billion acquisition of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in theatrical film distribution and basic cable television licensing, which would harm consumers through higher prices and reduced quality.
Attorney General William Tong and 48 other attorneys general submitted comments to the FCC urging stronger rules to prevent scammers from accessing legitimate telephone numbers for illegal robocalls. The coalition is responding to the FCC's proposed rules and asks for measures such as stronger certification, reporting, and prohibitions on number cycling.