Penalty Amount
$515,000
Consumers Affected
349,255
Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.
Comstar must pay $515,000 and implement security measures including phishing protection software, vulnerability management program, multi-factor authentication, and conduct annual security assessments for three years with reports to the Connecticut and Massachusetts Attorneys General.
In-house legal teams should review vendor agreements, data processing agreements, and Business Associate Agreements (BAAs) with entities like Comstar that handle sensitive patient data. Key clauses to scrutinize include data security standards, breach notification requirements, HIPAA compliance obligations, audit rights, and indemnification provisions. Given the settlement, contracts should be updated to mandate specific security measures such as phishing protection and annual security assessments, ensure prompt breach notification in line with state and federal laws, and include robust indemnification clauses to cover potential liabilities from data breaches involving protected health information.
Entity
Comstar, LLC
Also known as: Comstar
Industry
HealthcareOfficial Press Release
https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-announces-settlement-with-ambulance-billing-vendor
comstar final judgment on stipulation.pdf?rev=a352c9d2fe0b44
https://portal.ct.gov/-/media/ag/press_releases/2026/comstar---final-judgment-on-stipulation.pdf?rev=a352c9d2fe0b4456889717d556bfacdc&hash=AB1B7FC92347A3BA676BA8D0023409A9
Connecticut Attorney General Enforcement Page
https://portal.ct.gov/AG/Privacy/Privacy-Resources
"Comstar, LLC"
"$515,000"
"Health Insurance Portability and Accountability Act (HIPAA)"
"Connecticut and Massachusetts security and consumer protection laws"
"data breach"
"failing to implement basic, necessary security measures"
$515K
Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.
Connecticut Attorney General William Tong joined a coalition of states and local governments in filing suit against NHTSA over its rule weakening fuel economy standards for new passenger cars and light trucks. The lawsuit alleges the rule violates the agency’s statutory mandate and the Administrative Procedure Act; no penalty or final remedy is reported.
Connecticut Attorney General William Tong joined a multistate coalition suing the EPA over its repeal of greenhouse gas pollution limits for power plants and separately filed a notice of intent to sue over regulation of existing gas plants. The coalition asks the court to overturn the repeal and restore the protections; the release reports no monetary penalty or final order.
$400.0M
Connecticut Attorney General William Tong announced a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. resolving allegations that the generic drug manufacturers conspired to inflate prices, limit competition, and restrain trade. The settlement includes consumer restitution and injunctive reforms; court approval was being sought.
Connecticut Attorney General William Tong joined a coalition of 21 attorneys general in submitting a comment letter opposing a DHS rule that allows certain affirmative asylum applications to be referred to removal proceedings without an asylum officer interview. The coalition argues the rule violates federal law and harms asylum seekers, including unaccompanied children; this was a policy opposition letter, not a privacy enforcement action.
Connecticut and Massachusetts co-led a coalition protest urging FERC to reject the proposed NextEra Energy-Dominion Energy merger. The coalition argued that the merger could increase market power and threaten energy affordability, reliability, and competition; the release does not report a final enforcement decision or penalty.