This overview explains the requirements for supporting covered entities with individual-rights requests involving PHI within the applicable service scope. When Blackstar creates, receives, maintains, or transmits PHI on behalf of a healthcare customer, Blackstar operates as a business associate under the applicable BAA.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s patient-rights assistance program establishes requirements to support covered entities with access, amendment, accounting-of-disclosures, restriction, confidential-communication, and related Privacy Rule responsibilities. Covered-entity decisions and communications remain with the covered entity unless a function is expressly delegated in writing.
How We Approach This Area
- Authorized intake. Intake requirements call for approved channels and verified covered-entity authority or another basis permitted by the governing arrangement.
- Covered-entity control. Unless expressly delegated, the covered entity verifies the individual, determines designated-record-set scope, makes approval or denial decisions, selects formats and deadlines, and communicates with the individual.
- Patient inquiry routing. A person who contacts Blackstar directly is guided to the applicable covered entity without unnecessary confirmation or disclosure of PHI.
- Minimum-necessary access. Program requirements limit workforce and provider access to what is needed to support the authorized request.
- Record integrity. Handling requirements address preservation of source information, provenance, history, and relevant audit information without silently rewriting historical records.
- Secure transfer. Transfer requirements cover customer-scope review, approved secure channels, and authorized recipients.
- Transparent limitations. The program requires provider dependencies, unavailable information, technical constraints, and known limitations to be communicated to the covered entity.
- Temporary-copy disposition. Exports and working files are restricted and disposed of when authorized and no hold or other obligation applies.
Designated-record-set scope and direct-response responsibilities are determined by the covered entity and the applicable written allocation of responsibilities.
Roles and Responsibilities
Company responsibilities assign intake, scope, secure delivery, and escalation to privacy and security governance; responsive-information handling and authorized technical action to engineering and security operations; and customer authority, agreement terms, provider dependencies, and request records to workforce and vendor governance. Workforce requirements preserve covered-entity decision authority unless delegation is documented.
Review and Continuous Improvement
The program calls for periodic and event-driven review after delayed or failed requests, complaints, new responsive systems, material agreement changes, incidents affecting request data, or relevant regulatory developments.
Working With Covered Entities
Client onboarding should define authorized contacts, request channels, authoritative sources, designated-record-set decisions, secure delivery, provider coordination, and responsibility allocation. Response timing follows the applicable agreement, covered-entity requirements, and governing law.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.