This document summarizes how Blackstar Systems LLC (“Blackstar”) governs privacy and security when providing services that may involve protected health information (PHI) or electronic protected health information (ePHI) for healthcare customers. When Blackstar creates, receives, maintains, or transmits PHI on behalf of a healthcare customer, Blackstar operates as a business associate under the applicable Business Associate Agreement (BAA).
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s HIPAA privacy and security program establishes requirements appropriate to its role when operating as a business associate. The program is designed to protect the confidentiality, integrity, and availability of ePHI through administrative, physical, and technical safeguards selected according to risk, applicable law, contractual obligations, service capabilities, and verified configurations.
How We Approach This Area
- Defined governance. The program assigns company-level privacy, security, engineering, workforce, vendor, and incident-response responsibilities.
- Risk-based safeguards. The program requires evaluation of risks to ePHI and selection of reasonable and appropriate safeguards in light of the service, data, threat environment, contractual requirements, and available capabilities.
- Controlled PHI scope. Program requirements limit PHI processing to approved purposes, systems, recipients, and customer instructions and require appropriate review of new uses or disclosures.
- Business-associate boundaries. Governance requirements distinguish Blackstar’s business-associate duties from duties retained by covered entities, including decisions that have not been delegated in writing.
- Documented accountability. Documentation requirements cover material privacy and security decisions, exceptions, incidents, and corrective actions through restricted internal processes.
- Vendor governance. Approval requirements address the role, scope, safeguards, written assurances, and offboarding obligations of services that may handle PHI.
- Change awareness. Review requirements address privacy and security implications when products, vendors, data flows, laws, or customer requirements materially change.
- Claims discipline. Public assurance statements are limited to the applicable evidence, scope, and recognized form of assurance.
Roles and Responsibilities
Company responsibilities assign program oversight, risk decisions, policy administration, minimum-necessary practices, and breach-related coordination to privacy and security governance. Technical safeguards are assigned to engineering and security operations; authorization, training, vendor review, and compliance records to workforce and vendor governance; and containment, recovery, communications, and lessons learned to incident-response functions. Workforce requirements include following approved procedures and promptly reporting concerns.
Review and Continuous Improvement
The governance framework calls for periodic review of the program, risk analysis, safeguards, documentation, and contractual alignment, as well as event-driven review following material changes, significant incidents, control failures, or relevant legal developments. Program requirements direct findings into risk-based treatment, corrective action, or documented decision-making consistent with applicable obligations.
Working With Covered Entities
Applicable agreements and customer-specific requirements define PHI scope, permitted uses, responsibilities, safeguards, incident coordination, retention, return or destruction, and assistance obligations. The program also provides for reasonable customer security and procurement review while preserving restricted implementation details.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.