This overview describes the requirements governing vendors and subprocessors that may support healthcare services or handle PHI on Blackstar’s behalf. Vendor account details, service plans, configuration evidence, sensitive contacts, and architecture boundaries remain restricted.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s vendor-governance program requires an appropriate review before a third party may be approved to create, receive, maintain, or transmit PHI. Approval requirements cover the documented service, features, account or environment, data purpose, customer scope, written terms, and safeguards supported by available evidence.
How We Approach This Area
- Role determination. Review requirements address whether a provider is a subcontractor or performs another role relevant to HIPAA and the proposed data flow.
- Written assurances. Applicable BAAs or other required written arrangements must cover the actual PHI-bearing services before use.
- Scoped approval. Approval depends on review of the particular service, plan, features, account, data use, and applicable written terms.
- Security review. Reviews consider access, authentication, incident reporting, data handling, retention, deletion, export, resilience, support access, and downstream providers as applicable.
- Data limitation. Approved data categories, purposes, customer scope, and prohibited uses or features are documented.
- Change management. Review requirements address material changes to legal entity, service scope, features, subprocessors, or security conditions.
- Incident coordination. Blackstar seeks information from relevant providers in time to evaluate and meet its customer, contractual, and legal responsibilities.
- Offboarding. Program requirements address access, integrations, data return or export, deletion requests, remaining-data limitations, and required records when a service ends.
Public vendor and subprocessor statements are limited to relationships, services, and contractual scopes that have been verified and approved for disclosure.
Roles and Responsibilities
Company responsibilities assign intake, written terms, evidence, review, and offboarding to vendor governance; PHI scope and material risk decisions to privacy and security governance; technical safeguard review to engineering and security operations; and provider-event coordination to incident-response functions. Legal interpretation and contract approval may be referred to qualified counsel.
Review and Continuous Improvement
The program calls for periodic and event-driven review of approved third-party relationships. Review depth is proportionate to PHI scope, criticality, access, risk, and material changes to services, contracts, features, subprocessors, incidents, or security conditions.
Working With Covered Entities
Applicable agreements address contractual restrictions, permitted third parties, incident terms, retention, return or destruction, and customer-specific approval rights. Any public subprocessor list is maintained as a separately reviewed disclosure.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.