HHS settles with Comstar over cyber risk analysis failures

An investigation found that lapses in risk assessment contributed to a massive ransomware breach at the ambulance billing service.

The Department of Health and Human Services (HHS) Office of Civil Rights (OCR) announced a $75,000 settlement with ambulance collection and billing service provider Comstar over a 2022 ransomware breach that compromised the clinical data of nearly 600,000 individuals.

As part of the settlement, the company also agreed to undertake a corrective action

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Weekly podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in