HIPAA documentation
HIPAA & Security

Security and Privacy Training Overview

Version
1.0
Last updated
July 25, 2026

This overview describes Blackstar’s requirements for workforce privacy, security, and operational training. It explains curriculum and governance principles without publishing individual training records, assessment results, or internal readiness information.

This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.

Our Commitment

Blackstar’s workforce-security program requires role-appropriate privacy and security training as a condition of PHI-capable access. Training is designed to address the business-associate role, appropriate PHI use, system and device protection, threat recognition, incident reporting, and covered-entity support obligations.

How We Approach This Area

  • Access prerequisite. Required initial training and acknowledgment are linked to workforce authorization before PHI-capable access is granted.
  • Core privacy topics. Curriculum addresses permitted PHI use and disclosure, minimum necessary, patient-rights routing, secure communication, retention, and disposal.
  • Core security topics. Training addresses authentication, credential protection, phishing, social engineering, session practices, approved devices, remote work, and incident reporting.
  • Role-based content. Additional instruction is assigned for engineering, operations, privacy, vendor management, support, and other duties with specialized risk.
  • Customer and vendor boundaries. Training requirements address covered-entity decision-making, approved service scope, and restrictions on unapproved providers or communication channels.
  • Event-driven updates. Material policy changes, incidents, new threats, changed duties, or observed control failures may trigger targeted reminders or retraining.
  • Understanding and remediation. Completion records may include an assessment, scenario, or documented discussion, with follow-up where understanding needs improvement.
  • Accountability. Failure to complete required training may result in delayed, restricted, or suspended access and may enter the policy-enforcement process.

Training assurance is based on documented assignment, completion, acknowledgment, and role-based authorization records for the relevant workforce scope.

Roles and Responsibilities

Company responsibilities assign curriculum, training assignments, completion information, and acknowledgments to workforce governance; privacy, incident, breach, and risk content to privacy and security governance; and system- and threat-specific guidance to engineering and security operations. Workforce requirements cover assigned training, escalation of uncertainty, and prompt reporting of suspected incidents or violations.

Review and Continuous Improvement

The program calls for periodic and event-driven review of training content and effectiveness, including following material legal guidance, service or vendor changes, new workforce roles, incidents, sanctions matters, or evidence that expected behavior was not achieved.

Working With Covered Entities

Customer-specific workflows, agreements, permitted uses, reporting channels, and assistance obligations may be incorporated into role-based instruction. Covered entities remain responsible for training their own workforce unless an agreement expressly provides otherwise.

Additional Information

Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.

References

Continue your security review.

Return to the public HIPAA library or contact Blackstar for an appropriate review.