This overview summarizes Blackstar’s approach to contingency planning, backup governance, disaster recovery, emergency-mode operation, and service restoration for systems that may support ePHI. Recovery sources, providers, environments, commands, credentials, and restoration sequences are restricted.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s resilience program establishes contingency-planning requirements designed to support the availability and integrity of ePHI during disruptive events. Backup, restoration, emergency operations, and recovery priorities are governed according to system criticality, customer needs, contractual obligations, risk, and verified service capabilities.
How We Approach This Area
- Criticality analysis. Services, data, authentication, customer operations, audit information, and key dependencies are considered according to business and patient-impact risk.
- Backup governance. Recoverable copies and recovery material are selected according to service criticality, information risk, contractual requirements, and verified provider capabilities.
- Recovery planning. Internal requirements address recovery sources, authorization, data integrity, application validation, and safe service re-enablement.
- Emergency-mode protection. Safeguards for ePHI remain part of decision-making when normal operations are disrupted.
- Integrity before re-enablement. Potentially unsafe or ambiguous operations remain restricted until relevant data and system state can be validated.
- Provider dependencies. Third-party recovery, retention, support, and availability capabilities are incorporated into continuity planning according to the responsibilities allocated to each party.
- Testing and revision. The program calls for contingency procedures to be evaluated and revised periodically and after material changes or events.
- Evidence preservation. Activation, recovery decisions, validation, communications, limitations, and corrective actions are documented in restricted records.
Customer-specific recovery objectives and service commitments are established through applicable agreements and an appropriate security or procurement review.
Roles and Responsibilities
Company responsibilities assign activation, priorities, communications, and recovery decisions to incident-response leadership; relevant backup, recovery, and technical-validation requirements to engineering and security operations; ePHI safeguards during emergency operations to privacy and security governance; and customer, provider, access, and contractual matters to workforce and vendor governance.
Review and Continuous Improvement
The program calls for periodic and event-driven review of contingency scope, criticality, provider dependencies, recovery documentation, and risk treatment. Material system, data, authentication, vendor, or customer changes and significant disruptions may trigger additional validation and revision.
Working With Covered Entities
Customer-specific recovery expectations, manual operating procedures, authoritative records, notification requirements, and shared dependencies are established through onboarding and applicable agreements. Responsibility for covered-entity and independent-provider systems remains allocated to the party that controls them unless otherwise agreed.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.