This overview explains Blackstar’s approach to suspected impermissible uses or disclosures and potential breaches of unsecured PHI. When Blackstar creates, receives, maintains, or transmits PHI on behalf of a healthcare customer, Blackstar operates as a business associate under the applicable BAA.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s breach-response program establishes requirements to record discovery, contain and mitigate harm, preserve appropriate evidence, assess whether PHI was involved, evaluate applicable breach standards, and notify affected covered entities in accordance with governing agreements and law. Assessment requirements call for uncertainty to be documented and evaluated using available facts.
How We Approach This Area
- Immediate clock awareness. Discovery and relevant report times are recorded so that contractual and legal deadlines can be evaluated promptly.
- Fact-based classification. Classification requirements distinguish alerts, security incidents, impermissible uses or disclosures, presumed breaches, and breaches of unsecured PHI.
- Regulatory assessment. Potential exceptions and the required probability-of-compromise factors are considered based on documented facts when applicable.
- Evidence-based assessment. Assessment conclusions require the applicable facts and factors rather than reliance solely on observed misuse.
- Safeguard evaluation. Any conclusion that PHI was rendered unusable, unreadable, or indecipherable is tied to applicable HHS guidance and evidence for the affected event.
- Timely covered-entity notice. Program requirements call for notice without unreasonable delay and within the period required by applicable law, subject to any shorter valid contractual obligation.
- Supplemental updates. Initial notice may rely on facts then known, with additional information supplied as the investigation develops.
- Restricted records. Assessments, affected-person information, legal analysis, notices, and proof of delivery are maintained in appropriately protected records.
Under the HIPAA Breach Notification Rule, a business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery. The controlling agreement may require earlier reporting or separate reporting of security incidents and impermissible uses or disclosures.
Roles and Responsibilities
Company responsibilities assign containment and timelines to incident-response functions; breach classification and assessment to privacy and security governance; technical scope and evidence preservation to engineering and security operations; and contractual duties and approved notice delivery to workforce and vendor governance. Qualified legal counsel may review legal conclusions; operational roles do not substitute for counsel.
Review and Continuous Improvement
The program calls for review after suspected breaches and when relevant agreements, laws, incident processes, or service boundaries materially change. Lessons may inform safeguards, vendor oversight, training, risk analysis, and customer coordination.
Working With Covered Entities
Unless expressly delegated in writing, the covered entity remains responsible for individual, HHS, and media notifications. Applicable agreements require business-associate support through available facts, mitigation information, affected-person details where known, and other information reasonably needed for covered-entity obligations.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.