HIPAA documentation
HIPAA & Security

Security Monitoring and Auditability Overview

Version
1.0
Last updated
July 25, 2026

This overview explains Blackstar’s risk-based approach to security logging, auditability, activity review, and the protection of monitoring information. It intentionally omits log sources, event schemas, queries, alert logic, and other diagnostic details.

This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.

Our Commitment

Blackstar’s security-monitoring program establishes requirements for identifying security-relevant activity, reviewing available information, investigating material anomalies, and preserving appropriate records. Logging and review scope are selected according to system capability, risk, contractual obligations, applicable law, and verified configuration.

How We Approach This Area

  • Risk-based event selection. Program requirements call for security-relevant authentication, authorization, administrative, access, configuration, and incident activity to be considered according to the system and risk.
  • Log protection. Control requirements address restricted access and protection against unauthorized alteration, disclosure, or deletion.
  • Data minimization. Logging requirements call for avoidance of unnecessary PHI, credentials, message content, recordings, and sensitive request data.
  • Operational versus compliance records. Program requirements distinguish diagnostic telemetry from records intended to demonstrate a required review, decision, or action.
  • Activity review. Review requirements use risk-based and event-driven criteria appropriate to available security information.
  • Anomaly handling. The program requires material or unexplained activity to be investigated and escalated through incident-response processes when warranted.
  • Coverage evaluation. Review requirements call for monitoring scope to be reassessed as systems, vendors, PHI flows, risks, or customer obligations change.
  • Restricted evidence. Detailed filters, findings, screenshots, and investigative material are kept in access-controlled records rather than public documents.

Monitoring and auditability controls are tailored to the relevant service, event risk, available audit capabilities, and evidentiary purpose.

Roles and Responsibilities

Company responsibilities assign event selection, monitoring safeguards, and technical review to engineering and security operations; material findings and auditability needs to privacy and security governance; review and authorization records to workforce and vendor governance; and heightened evidence preservation during significant events to incident-response functions.

Review and Continuous Improvement

The program calls for periodic evaluation of monitoring coverage, data minimization, access restrictions, retention decisions, and review effectiveness. Material incidents or changes to authentication, authorization, vendors, data flows, or architecture trigger event-driven evaluation as appropriate.

Working With Covered Entities

Applicable agreements and incident processes address security-event responsibilities, contractually required reporting, customer-specific access needs, and appropriate evidence during a qualified review or incident. Restricted monitoring details are shared only when justified and protected.

Additional Information

Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.

References

Continue your security review.

Return to the public HIPAA library or contact Blackstar for an appropriate review.