HIPAA documentation
HIPAA & Security

Access Control and Information Security Overview

Version
1.0
Last updated
July 25, 2026

This overview describes the principles governing access to systems that may create, receive, maintain, transmit, or administer ePHI. Its purpose is to explain the control framework without disclosing sensitive architecture or privileged access methods.

This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.

Our Commitment

Blackstar’s access-control program requires authorization according to legitimate business need, least privilege, and the scope of the applicable healthcare customer. Safeguards are selected according to system risk, service capabilities, contractual requirements, approved use, and verified configurations.

How We Approach This Area

  • Authorized access. Approval requirements cover the purpose, scope, and responsible owner of human and service access.
  • Least privilege. Program requirements limit permissions to the systems, customer context, information, and actions reasonably needed for an assigned function.
  • Individual accountability. Program requirements call for named user accounts where supported and prohibit routine credential sharing.
  • Customer separation. Control requirements address restriction of users and services to assigned customer information and functions.
  • Layered authorization. The program requires protected operations to rely on system-enforced authorization rather than interface visibility alone.
  • Privileged-access governance. Administrative, support, recovery, and other elevated access are subject to narrower authorization, restricted use, and appropriate review.
  • Lifecycle management. Program requirements call for access to be modified or removed when duties, customer relationships, workforce status, or business need changes, with prompt protective action following suspected compromise.
  • Secure testing. Testing requirements favor synthetic, de-identified, or minimized information where practical.

Control-selection criteria tailor authentication, authorization, and audit safeguards to the risk, capability, approved use, and verified configuration of each service.

Roles and Responsibilities

Company responsibilities assign technical access controls and verification to engineering and security operations; authorization and access-review records to workforce governance; and high-risk access decisions and exceptions to privacy and security governance. Workforce requirements address assigned privileges, protection of credentials and devices, and prompt reporting of unexpected access or overprivilege.

Review and Continuous Improvement

The program calls for periodic and event-driven review of access scope, privileged access, service access, authentication dependencies, and removal procedures. Its requirements direct identified limitations into risk-based remediation, restriction, or documented decision-making.

Working With Covered Entities

Customer onboarding and applicable agreements are used to define authorized users, customer scope, support access, sensitive operations, offboarding expectations, and contractual requirements. Customer instructions cannot expand PHI use beyond the governing agreement or applicable law.

Additional Information

Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.

References

Continue your security review.

Return to the public HIPAA library or contact Blackstar for an appropriate review.