HIPAA documentation
HIPAA & Security

Vendor and Subprocessor Governance Overview

Version
1.0
Last updated
July 25, 2026

This overview describes the requirements governing vendors and subprocessors that may support healthcare services or handle PHI on Blackstar’s behalf. Vendor account details, service plans, configuration evidence, sensitive contacts, and architecture boundaries remain restricted.

This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.

Our Commitment

Blackstar’s vendor-governance program requires an appropriate review before a third party may be approved to create, receive, maintain, or transmit PHI. Approval requirements cover the documented service, features, account or environment, data purpose, customer scope, written terms, and safeguards supported by available evidence.

How We Approach This Area

  • Role determination. Review requirements address whether a provider is a subcontractor or performs another role relevant to HIPAA and the proposed data flow.
  • Written assurances. Applicable BAAs or other required written arrangements must cover the actual PHI-bearing services before use.
  • Scoped approval. Approval depends on review of the particular service, plan, features, account, data use, and applicable written terms.
  • Security review. Reviews consider access, authentication, incident reporting, data handling, retention, deletion, export, resilience, support access, and downstream providers as applicable.
  • Data limitation. Approved data categories, purposes, customer scope, and prohibited uses or features are documented.
  • Change management. Review requirements address material changes to legal entity, service scope, features, subprocessors, or security conditions.
  • Incident coordination. Blackstar seeks information from relevant providers in time to evaluate and meet its customer, contractual, and legal responsibilities.
  • Offboarding. Program requirements address access, integrations, data return or export, deletion requests, remaining-data limitations, and required records when a service ends.

Public vendor and subprocessor statements are limited to relationships, services, and contractual scopes that have been verified and approved for disclosure.

Roles and Responsibilities

Company responsibilities assign intake, written terms, evidence, review, and offboarding to vendor governance; PHI scope and material risk decisions to privacy and security governance; technical safeguard review to engineering and security operations; and provider-event coordination to incident-response functions. Legal interpretation and contract approval may be referred to qualified counsel.

Review and Continuous Improvement

The program calls for periodic and event-driven review of approved third-party relationships. Review depth is proportionate to PHI scope, criticality, access, risk, and material changes to services, contracts, features, subprocessors, incidents, or security conditions.

Working With Covered Entities

Applicable agreements address contractual restrictions, permitted third parties, incident terms, retention, return or destruction, and customer-specific approval rights. Any public subprocessor list is maintained as a separately reviewed disclosure.

Additional Information

Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.

References

Continue your security review.

Return to the public HIPAA library or contact Blackstar for an appropriate review.