Cyber Incident Victim: Comstar LLC
Date:
Mar 2022
Location:
United States of America
Summary
A data breach at Comstar LLC exposed sensitive patient information following unauthorized network access discovered during suspicious server activity. The compromised data included names, dates of birth, medical assessment details, medication administration records, health insurance information, driver's licenses, financial account data, and Social Security numbers. The company secured its network, initiated an investigation with third-party experts, and later reviewed affected systems to identify impacted individuals for notification purposes. While the investigation could not confirm specific data accessed, free credit monitoring services were offered to potentially affected patients.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 26, 2022, Comstar LLC, a US ambulance billing service, detected suspicious activity involving some of its servers, indicating a network intrusion. The company immediately secured its network and initiated an investigation with third-party experts to assess the incident's nature and scope. The investigation, concluded on April 21, 2022, confirmed unauthorized access to certain systems within Comstar's network. While the investigation could not definitively identify which specific data was accessed during the breach, a subsequent review of the compromised systems revealed that exposed information included patients' names, dates of birth, medical assessment details, medication administration records, health insurance information, driver's licenses, financial account details, and Social Security numbers. Comstar did not disclose the number of affected individuals in its June 14 breach notification but acknowledged the incident impacted "certain individuals" whose data resided on the accessed systems.

Comstar undertook a comprehensive review of the compromised systems following the April 21 confirmation of unauthorized access to identify the specific information contained within those systems and determine which individuals required notification. The company offered free credit monitoring services to potentially impacted individuals as a remedial measure, though it provided no further details regarding the attack vector, threat actor, or forensic findings. The breach exposed highly sensitive healthcare and financial data, creating risks of identity theft and medical fraud for affected patients. Comstar's public disclosure occurred nearly three months after the initial detection, with the June 14 notification marking the first official confirmation of the incident's data impact. No information was released regarding system restoration timelines, regulatory penalties, or whether data exfiltration occurred beyond unauthorized access.
