Comstar LLC
ent_022451cc19d7f3e61651c834
Disclosures
13
HHS OCR enforcement · State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
585,621
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Comstar LLC
- Normalized
- comstar— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- FEDERALHHS OCR enforcementas victim2025-05-30
HHS OCR settled a HIPAA investigation with Comstar, LLC, a business associate providing services to ambulance services, for $75,000. The settlement resolved allegations that Comstar failed to conduct a thorough risk analysis prior to a March 2022 ransomware attack that affected 585,621 individuals' PHI. Comstar agreed to a Corrective Action Plan including risk analysis, risk management, policy updates, and workforce training.
- New Hampshire State AGas victim2022-08-26
Comstar LLC, an ambulance billing service, reported a data event discovered on March 26, 2022, involving unauthorized access to servers. The incident potentially exposed PHI, SSNs, driver's licenses, and financial data of 90,756 New Hampshire residents. Comstar engaged third-party experts, notified law enforcement, and provided 12 months of credit monitoring. This filing is a second supplemental notice dated August 22, 2022.
- Maine State AGas victim2022-08-22
Comstar LLC reported an external system breach that occurred between March 19, 2022, and March 26, 2022. The breach was discovered on March 26, 2022. The compromised information includes names and financial account numbers or credit/debit card numbers with their access codes. A total of 16,433 Maine residents were affected. Comstar LLC offered 12 months of credit monitoring and identity theft insurance through Equifax to those affected.
- California State AGas victim2022-08-22
Comstar, LLC reported a cyber-attack where unauthorized access occurred to certain files on its network between March 19 and March 26, 2022. The company discovered suspicious activity on March 26, 2022. Potentially impacted data includes names, dates of birth, Social Security numbers, medical assessments, medication administration records, and health insurance information. Comstar engaged third-party experts, secured its network, and is offering credit monitoring and identity theft restoration services through Equifax. The incident affected residents of multiple states including California and Rhode Island.
- Maine State AGas victim2022-06-30
Comstar LLC, a professional services firm based in Rowley, MA, reported an external system breach occurring between March 19 and March 26, 2022. The incident affected 565,790 individuals, including 16,220 Maine residents. The breach involved the unauthorized acquisition of names and financial account numbers (including credit/debit card numbers with security codes/PINs). Comstar notified affected consumers in writing in May and June 2022 and provided 12 months of credit monitoring and identity theft insurance through Equifax.
- California State AGas victim2022-06-30
Comstar LLC reported a cyber-attack impacting its network between March 19 and March 26, 2022. The company discovered suspicious activity on March 26, 2022. Unauthorized access potentially affected files containing names, dates of birth, Social Security numbers, medical assessments, medication administration records, and health insurance information. Comstar engaged third-party experts, secured its network, and is offering credit monitoring services to affected individuals.
- California State AGas victim2022-06-14
Comstar, LLC notified the California Attorney General of a cyber-attack impacting its network between March 19 and March 26, 2022. The company discovered suspicious activity on March 26, 2022. The incident potentially exposed personal information including names, dates of birth, Social Security numbers, medical assessments, medication administration records, and health insurance information. Comstar engaged third-party experts, secured its network, and is offering credit monitoring services to affected individuals. The incident involved both customer and employee data.
- New Hampshire State AGas victim2022-05-27
Comstar, LLC notified the NH AG of a data event discovered March 26, 2022, affecting 18,692 NH residents. Unauthorized access to servers exposed PHI, SSNs, driver's licenses, and financial data. Comstar engaged third-party experts, notified law enforcement, and offered 12 months of credit monitoring.
- MASSACHUSETTSHHS OCRas victim2022-05-26
Comstar, LLC (a Business Associate located in MA) reported to HHS OCR on 2022-05-26 a Hacking/IT Incident affecting 68,957 individuals. Breached information was located on a Network Server. A business associate was present. No further details were available in the web description.
- Indiana State AGas victim2022-05-25
Comstar, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2022-03-19 and was reported on 2022-05-25. 164 Indiana residents were affected. 164,414 individuals affected in total.
- Montana State AGas victim2022-05-25
Comstar, LLC notified individuals of a cyber-attack discovered on March 26, 2022, involving unauthorized access to servers. Potentially impacted data included names, SSNs, DOBs, medical info, and financial accounts. Comstar engaged third-party experts, notified law enforcement, and offered credit monitoring.
- Massachusetts State AGas victim2022-05-24
Comstar, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-05-24. 306,058 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-05-23
Comstar LLC experienced a hacking incident impacting 446 Maine residents. The breach occurred from March 19 to March 26, 2022, and was discovered on March 26, 2022. The compromised data included names and financial account numbers or credit/debit card numbers with their corresponding security codes or PINs. Affected individuals were notified on May 23, 2022, and offered 12 months of credit monitoring and identity theft insurance through Equifax.