CSIDB logo
Incident

Starling Physicians

Incident posture

Attack window
Feb 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-26 00:00

Linked entities

Victim
Starling Physicians
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Starling Physicians experienced a cyber-phishing attack compromising several employee email accounts. The Connecticut-based healthcare group secured the affected accounts and engaged a forensic security firm to investigate, which later confirmed unauthorized access to sensitive patient data. Exposed information included patient names, addresses, dates of birth, passport numbers, Social Security numbers, medical details, and health insurance or billing records. The organization notified impacted individuals following the completion of the forensic review.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On February 8, 2019, Starling Physicians, a Connecticut-based healthcare provider, experienced a cybersecurity incident involving unauthorized access to employee email accounts through a phishing attack. The organization detected the breach and immediately secured the compromised accounts to prevent further unauthorized access. Following containment, Starling engaged a forensic security firm to investigate the incident’s scope and origin. The investigation, completed on September 12, 2019, determined that attackers had infiltrated email accounts containing sensitive patient information. The breach did not extend beyond the email system, and no evidence suggested misuse of the accessed data at the time of discovery.

The compromised data included patients’ names, addresses, dates of birth, passport numbers, Social Security numbers, medical information, and health insurance or billing details. Starling notified affected individuals about the breach in November 2019, approximately nine months after the initial incident and two months after concluding the investigation. The delayed notification was attributed to the time required to identify impacted patients and validate contact information. While the breach exposed highly sensitive personal and medical data, Starling’s public statement did not specify the number of affected individuals or confirm whether ransomware or data exfiltration occurred. The organization reiterated its commitment to enhancing security protocols but did not disclose specific remedial measures taken beyond securing the email accounts and initiating the forensic review.

Sources

Sources available to members: 1 source.

CSIDB