This overview describes the requirements governing evaluation and management of risks and vulnerabilities that may affect ePHI. Detailed system boundaries, threat scenarios, findings, scores, control gaps, residual-risk decisions, and remediation plans are restricted.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s risk-management program requires security risks to ePHI to be evaluated and appropriate treatment activities to be tracked. Scope extends beyond source code to relevant systems, vendors, people, devices, data flows, recovery dependencies, and operational environments.
How We Approach This Area
- Complete-scope intent. Risk analysis considers where ePHI may be created, received, maintained, transmitted, displayed, backed up, administered, or supported.
- Threat and vulnerability analysis. Reasonably anticipated threats and vulnerabilities are evaluated for potential confidentiality, integrity, and availability impact.
- Consistent evaluation. Risk is assessed using a repeatable qualitative or quantitative method appropriate to the available evidence.
- Evidence awareness. Implemented and verified controls are distinguished internally from planned, assumed, or externally dependent safeguards.
- Treatment planning. Risks may be mitigated, avoided, transferred, or accepted when permissible, with responsibility and follow-up appropriate to severity.
- Control validation. Closure criteria require treatment, validation, evidence, and an appropriate residual-risk decision.
- Change-driven updates. New services, vendors, PHI uses, customer requirements, incidents, vulnerabilities, and control failures can trigger reassessment.
- Restricted disclosure. Risk-register details and security findings are not published because doing so could expose weaknesses or distort context.
Cost, company size, and technical capability may inform the reasonableness of a safeguard, but they do not remove applicable requirements or justify unsupported conclusions.
Roles and Responsibilities
Company responsibilities assign risk methodology, scope, and risk decisions to privacy and security governance; technical inventory, analysis, testing, and remediation evidence to engineering and security operations; workforce, customer, contract, and third-party information to workforce and vendor governance; and event and resilience lessons to incident-response functions. Qualified specialists may be used when the risk or required expertise warrants.
Review and Continuous Improvement
The program calls for periodic review of risk analysis, treatment activities, evidence, and material environmental changes. Review depth and cadence are based on potential impact, scope, contractual requirements, and relevant changes or incidents.
Working With Covered Entities
Customer requirements, intended workflows, PHI categories, contractual safeguards, and shared responsibilities inform risk analysis. Qualified customers may receive appropriately scoped information about the risk-management process while attack-relevant findings and treatment details remain restricted.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.