HIPAA security and privacy program.
Blackstar publishes these documents to help healthcare organizations evaluate how we govern PHI, security risk, workforce access, vendors, incident response, resilience, and secure system development.
- Published
- 18 documents
- Version
- 1.0
- Last updated
- July 25, 2026
- BAA
- Available
A Business Associate Agreement is executed before Blackstar handles PHI on a healthcare client's behalf.
Governance and PHI use
HIPAA Governance
This document summarizes how Blackstar Systems LLC (“Blackstar”) governs privacy and security when providing services that may involve protected health…
Minimum Necessary and PHI Handling
This public policy describes the requirements governing PHI requests, uses, disclosures, access, displays, and secondary copies. It also recognizes that…
Covered-Entity & Patient Rights
This overview explains the requirements for supporting covered entities with individual-rights requests involving PHI within the applicable service scope.…
Policy Enforcement & Accountability
This overview summarizes Blackstar’s approach to suspected violations of privacy, security, contractual, and operational requirements. It explains…
Access and workforce security
Access Control & Information Security
This overview describes the principles governing access to systems that may create, receive, maintain, transmit, or administer ePHI. Its purpose is to…
Workforce Access Lifecycle
This overview explains how Blackstar governs workforce access from initial authorization through role changes and termination. It applies to employees,…
Authentication & Account Security
This overview describes Blackstar’s governance principles for human and service authentication, account protection, sessions, recovery, and credential…
Device & Workplace Security
This overview describes Blackstar’s expectations for devices, workstations, remote work, media, and physical environments used to access PHI-capable…
Security & Privacy Training
This overview describes Blackstar’s requirements for workforce privacy, security, and operational training. It explains curriculum and governance…
Monitoring, risk, and response
Security Monitoring & Auditability
This overview explains Blackstar’s risk-based approach to security logging, auditability, activity review, and the protection of monitoring information.…
Security Incident Response
This overview describes Blackstar’s framework for identifying, responding to, documenting, and learning from suspected security incidents involving…
Breach Response & Notification
This overview explains Blackstar’s approach to suspected impermissible uses or disclosures and potential breaches of unsecured PHI. When Blackstar…
Security Risk Management
This overview describes the requirements governing evaluation and management of risks and vulnerabilities that may affect ePHI. Detailed system…
Vulnerability Management
This overview explains Blackstar’s risk-based approach to identifying, assessing, treating, and documenting vulnerabilities that may affect ePHI.…
Data, vendors, and resilience
Vendor & Subprocessor Governance
This overview describes the requirements governing vendors and subprocessors that may support healthcare services or handle PHI on Blackstar’s behalf.…
Data Retention & Secure Disposal
This overview describes Blackstar’s principles for retaining, returning, deleting, and securely disposing of PHI and related records. It avoids publishing…
Resilience & Business Continuity
This overview summarizes Blackstar’s approach to contingency planning, backup governance, disaster recovery, emergency-mode operation, and service…
Secure Development & Change Management
This overview describes how Blackstar incorporates privacy, security, authorization, data integrity, and operational risk into changes that may affect…
Need documentation for your review?
Contact Blackstar for an appropriate security, legal, procurement, or BAA review.