This overview describes Blackstar’s governance principles for human and service authentication, account protection, sessions, recovery, and credential compromise. Technical configuration and recovery details are restricted because they could increase security risk.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s authentication and account-security program establishes safeguards designed to support identity verification, protect PHI-capable access, and enable prompt response to suspected compromise. Controls are selected based on risk, privilege, service capability, customer obligations, and verified configuration.
How We Approach This Area
- Distinct identities. Individual workforce accounts are used where supported, and service identities are assigned a defined purpose and scope.
- Password hygiene. Passwords or passphrases, when used, must be unique, protected through approved services, and not transmitted or stored in ordinary communications or documentation.
- Credential protection. Program requirements treat credentials, authentication codes, session material, and recovery information as restricted and exclude them from public documentation and ordinary logs.
- Session governance. Logout, revocation, duration, device behavior, and response to role changes or compromise are evaluated for PHI-capable services.
- Abuse resistance. Control requirements address guessing, replay, enumeration, and automated abuse according to the relevant service and risk.
- Compromise response. Suspected account or credential compromise triggers containment, revocation or replacement as appropriate, activity review, and assessment of possible PHI impact.
- Accurate classification. Authentication terminology follows the factors and configuration verified for the relevant service scope.
Roles and Responsibilities
Company responsibilities assign authentication, session, and service-identity controls to engineering and security operations; identity and authorization records to workforce governance; and material exceptions and risk decisions to privacy and security governance. Workforce requirements address account, recovery-method, and device protection and prompt reporting of suspicious activity.
Review and Continuous Improvement
The program calls for periodic and event-driven review of authentication methods, privileged access, recovery dependencies, service identities, and revocation behavior. Safeguard requirements are reconsidered as risks, contractual requirements, and platform capabilities evolve.
Working With Covered Entities
Customer onboarding and applicable agreements address authorized user populations, customer-facing account administration, offboarding, and security requirements. Specific authentication capabilities and configurations may be addressed during an appropriately scoped security review.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.