HIPAA documentation
HIPAA & Security

Device and Workplace Security Overview

Version
1.0
Last updated
July 25, 2026

This overview describes Blackstar’s expectations for devices, workstations, remote work, media, and physical environments used to access PHI-capable services. Workplace locations, device inventories, configuration details, and physical access arrangements remain restricted.

This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.

Our Commitment

Blackstar’s device and workplace-security program requires PHI-capable access to occur through approved devices and work environments subject to safeguards appropriate to the device, platform, access level, and risk. Physical and device controls are designed to reduce unauthorized viewing, access, storage, theft, tampering, and disclosure.

How We Approach This Area

  • Approved-device baseline. Device requirements address applicable encryption, individual authentication, automatic locking, supported software, security updates, host protections, and secure disposition capabilities where technically supported.
  • Inventory and authorization. Approved devices are associated with an authorized user, purpose, status, and disposition record appropriate to the access risk.
  • Workstation protection. Workforce requirements address unattended-device locking, screen exposure, unauthorized use, and protection of PHI during screen sharing or conversation.
  • Secure connectivity. Program requirements call for approved services and protected connections and restrict untrusted networks and remote-administration features according to risk.
  • Local-storage limitation. Downloading, printing, removable media, and local PHI storage are prohibited by default and require an authorized, minimum-necessary purpose and disposition plan when allowed.
  • Physical safeguards. Work areas, devices, paper, and media are protected from unauthorized persons, theft, tampering, and foreseeable environmental hazards.
  • Repair and disposal. Program requirements address protection or removal of information before device transfer and sanitization or destruction methods appropriate to sensitivity and technology.
  • Loss response. Loss, theft, unexplained physical access, or inability to account for PHI-bearing media triggers prompt incident handling.

Physical safeguards operated by infrastructure providers are addressed through vendor review, contractual allocation, and evidence appropriate to the service scope.

Roles and Responsibilities

Company responsibilities assign device requirements, technical inventory, and secure-disposal controls to engineering and security operations; exceptions and incidents to privacy and security governance; and authorization and attestation records to workforce governance. Workforce requirements address protection of assigned devices and workspaces and prompt reporting of concerns.

Review and Continuous Improvement

The program calls for periodic and event-driven review of device and workplace safeguards, including following device loss, physical-security incidents, moves, new device classes, remote-work changes, workforce growth, or regulatory developments. Material gaps may require corrective action, restricted access, or replacement.

Working With Covered Entities

Applicable agreements address customer requirements affecting device use, remote access, local copies, media, or incident notification. Covered entities remain responsible for physical and device controls within their own environments unless otherwise agreed.

Additional Information

Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.

References

Continue your security review.

Return to the public HIPAA library or contact Blackstar for an appropriate review.