This overview explains how Blackstar governs workforce access from initial authorization through role changes and termination. It applies to employees, contractors, and other persons under Blackstar’s direct control whose duties may involve PHI-capable systems.
This public overview summarizes Blackstar’s approach and does not replace Blackstar’s internal policies, procedures, contractual obligations, or client-specific requirements.
Our Commitment
Blackstar’s workforce-access program requires PHI-capable access to be limited to workforce members whose identity, relationship, duties, training, device safeguards, and business need have been appropriately evaluated and authorized. The program requires access to change or end promptly when the underlying need changes.
How We Approach This Area
- Pre-access authorization. Approval requirements cover the defined role, business purpose, customer scope, system scope, and privilege level.
- Role-appropriate review. Authorization requirements match clearance considerations, confidentiality duties, training, and device safeguards to the sensitivity of proposed access.
- Named access. The program requires individual accounts and approved authentication safeguards where supported.
- Minimum access. Onboarding requirements call for the narrowest permissions reasonably needed and verification of prohibited access paths.
- Temporary access. The program requires time-limited, support, and contractor access to be scoped to the task and removed when the purpose ends.
- Role changes. Lifecycle requirements call for unnecessary permissions to be removed as duties change and for new permissions to follow the ordinary authorization process.
- Termination controls. Revocation requirements cover system, vendor, communication, recovery, and device-related access in coordination with the end of authorized work.
- Asset and information return. Offboarding requirements address return, transfer, preservation, or secure disposal of company records, approved local artifacts, credentials, and devices.
Customer-facing assurance about access populations and reviews is based on authorization, prerequisite, and review records for the relevant scope.
Roles and Responsibilities
Company responsibilities assign relationship, authorization, training, device, and access records to workforce governance; technical access administration to engineering and security operations; and elevated-risk decisions and exceptions to privacy and security governance. Workforce requirements address protection of assigned access, credential sharing, and prompt reporting of loss, misuse, or unexpected access.
Review and Continuous Improvement
The program calls for periodic and event-driven review of workforce and access records, including after role changes, terminations, customer offboarding, incidents, or material changes to PHI-capable services. Review outcomes may require permission reduction, reauthorization, retraining, technical changes, or suspension of access.
Working With Covered Entities
Customer onboarding and applicable agreements identify authorized customer users, client-specific scope, onboarding and offboarding expectations, and any contractual requirements for access approval or notification. Covered entities remain responsible for managing their own workforce and accounts unless an agreement expressly assigns a task to Blackstar.
Additional Information
Additional information may be made available to customers and qualified prospective customers through an appropriate security, legal, or procurement review. Certain implementation details are restricted to protect Blackstar’s systems, customers, and security operations.