This public policy describes the requirements governing PHI requests, uses, disclosures, access, displays, and secondary copies. It also recognizes that sufficient information may be needed for accurate service delivery, transaction integrity, support, incident response, and legal obligations.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s program permits PHI use and disclosure only as authorized by applicable law, the governing BAA and service agreement, and lawful customer instructions within that scope. When the HIPAA minimum-necessary standard applies, program requirements call for reasonable efforts to limit PHI to what is needed for the intended purpose.
How We Approach This Area
- Purpose limitation. Program requirements associate PHI with an authorized service, support, security, compliance, or legal purpose.
- Data minimization. The program limits collection, display, access, transfer, and storage to information reasonably needed for the approved activity.
- Role and customer scope. Access requirements constrain workforce and service access by function and the applicable covered entity.
- Secondary-copy control. Handling requirements cover minimization, restriction, and disposition of logs, exports, screenshots, support artifacts, and temporary copies.
- Restricted channels. Program requirements prohibit PHI in unapproved communications, personal storage, billing metadata, public tools, or other services outside an approved PHI scope.
- Vendor boundaries. A vendor, feature, account, or service is not used for PHI merely because it is technically available; contractual and security review must support the proposed use.
- Safe testing. Synthetic or de-identified information is used for development and testing by default.
- Prohibited unrelated use. Blackstar does not authorize PHI for unrelated marketing, sale, model training, benchmarking, or unrelated analytics without separate lawful authority and written terms.
The minimum-necessary standard has regulatory exceptions. The program requires any asserted exception to be evaluated against the actual facts and role rather than applied as a general exemption.
Roles and Responsibilities
Company responsibilities assign minimum-necessary criteria and exceptions to privacy and security governance; field, display, response, logging, and retention safeguards to engineering and security operations; and customer and third-party restrictions to workforce and vendor governance. Workforce requirements limit access and disclosure to the needs of the assigned task.
Review and Continuous Improvement
The program calls for periodic and event-driven review of PHI-handling decisions when fields, features, logs, exports, vendors, customer instructions, or legal requirements materially change. Review criteria cover the full data lifecycle, including access, onward disclosure, backup behavior, retention, and deletion.
Working With Covered Entities
Covered entities help define permitted workflows, appropriate data scope, authoritative records, restrictions, and retention requirements. Applicable onboarding and agreement processes address customer-specific decisions involving transcripts, recordings, exports, support access, and other sensitive processing where relevant.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.