Skip to Primary Navigation

HHS settles with Comstar over cyber risk analysis failures

Police car lights at night in city with selective focus and bokeh.
Photo: Jun Li/Getty Images

An investigation found that lapses in risk assessment contributed to a massive ransomware breach at the ambulance billing service.

The Department of Health and Human Services (HHS) Office of Civil Rights (OCR) announced a $75,000 settlement with ambulance collection and billing service provider Comstar over a 2022 ransomware breach that compromised the clinical data of nearly 600,000 individuals.

As part of the settlement, the company also agreed to undertake a corrective action

Get full access, free for a month

This is a Premium article. Start your 28-day free trial to continue reading and access all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience