Privacy Policy
January 1, 2022 2026-08-20 11:34Privacy Policy
Privacy Policy
Blackstone Healthcare Solutions, LLC
Effective Date: August 19, 2026
1. Introduction & Company Overview
Blackstone Healthcare Solutions, LLC (“the Company,” “we,” “our,” or “us”) is a professional healthcare services company headquartered in Maryland. The Company provides the following services to healthcare clients across the United States:
- Medical Coding Services — accurate assignment of diagnostic and procedural codes in accordance with applicable coding guidelines and payer requirements;
- Medical Auditing Services — prospective and retrospective audits of medical records and coding practices to ensure accuracy, compliance, and reimbursement integrity; and
- Compliance Consulting Services — advisory and consulting services to help healthcare organizations develop, implement, and maintain effective compliance programs.
Blackstone Healthcare Solutions, LLC is deeply committed to protecting the privacy, confidentiality, and security of all information it handles — whether that information belongs to website visitors, prospective clients, current clients, or individuals whose health information may be accessed in the course of delivering contracted services.
In performing medical coding, auditing, and compliance consulting services for healthcare provider clients, the Company may access, receive, use, or transmit Protected Health Information (PHI) on behalf of those clients. In such circumstances, the Company acts as a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and its implementing regulations. All access to and handling of PHI is conducted strictly in accordance with applicable law and the terms of executed Business Associate Agreements.
This Privacy Policy governs two distinct but related areas of the Company’s operations: (1) the Company’s public-facing website and digital communications; and (2) the Company’s professional business operations, including the collection, use, disclosure, and protection of information obtained in the course of client engagements. Visitors to the website and clients engaged in professional services relationships with the Company are each subject to the applicable provisions of this Policy.
2. Scope of This Policy
This Privacy Policy applies to the following categories of individuals and information:
- Website Visitors: Individuals who visit the Company’s website, browse its pages, submit contact or inquiry forms, or otherwise interact with the Company’s online presence;
- Prospective Clients: Individuals and organizations that communicate with the Company in connection with evaluating or considering the Company’s services;
- Current and Former Clients: Healthcare organizations, covered entities, and business contacts with whom the Company has entered or previously entered into a services engagement; and
- Individuals Whose PHI Is Accessed: Patients and other individuals whose Protected Health Information may be accessed, reviewed, or processed by the Company in the course of performing contracted medical coding, auditing, or compliance consulting services on behalf of covered entity clients.
Important Distinction Between PHI and General Personal Information: This Policy recognizes and applies different standards to two distinct categories of information:
- Protected Health Information (PHI) is governed by HIPAA, the HITECH Act, and the terms of applicable Business Associate Agreements (BAAs). PHI receives the highest level of protection under this Policy and applicable law.
- General Personal Information — such as business contact details, website usage data, and inquiry information — is governed by this Privacy Policy and applicable federal and state privacy laws.
No Covered Entity–Patient Relationship: This Policy does not create, establish, or imply a direct covered entity–patient relationship between Blackstone Healthcare Solutions, LLC and any individual whose PHI may be handled by the Company. The Company’s access to PHI is conducted solely on behalf of, and under the direction and authority of, its covered entity clients. Any rights that individuals may have with respect to their PHI are exercised through the applicable covered entity, not directly through the Company.
3. Information We Collect
A. Information Collected Through the Website
When you visit or interact with the Company’s website, we may collect the following categories of information:
- Contact Form Submissions: If you complete and submit a contact, inquiry, or request form on the website, we collect information you voluntarily provide, including your name, email address, telephone number, organization or employer name, and the content of your message or inquiry.
- Technical and Device Information: We automatically collect certain technical information when you access the website, including your Internet Protocol (IP) address, browser type and version, operating system, referring URLs, pages viewed, time spent on pages, and general device information. This information is collected to maintain website security, diagnose technical issues, and understand aggregate usage patterns.
- Cookies and Tracking Technologies: The website uses cookies and similar tracking technologies, including analytics cookies (to understand how visitors navigate and use the site), session cookies (to maintain the functionality of the website during a browsing session), and preference cookies (to remember user settings or preferences). Please see Section 6 of this Policy for detailed information regarding our cookie practices.
- Email List and Newsletter Sign-Ups: If the Company offers newsletter subscriptions or email communications, individuals who voluntarily subscribe provide their name and email address for that purpose.
B. Information Collected in the Course of Business Operations
In the course of providing professional services to clients, the Company collects and maintains the following categories of information:
- Client Business Contact Information: Names, professional titles, organizational affiliations, email addresses, telephone numbers, and mailing addresses of client representatives and business contacts;
- Billing and Financial Information: Invoice details, payment records, and financial documentation necessary to administer and collect fees for services rendered;
- Protected Health Information (PHI): In performing medical coding, auditing, and compliance consulting services, the Company may access, receive, use, or transmit PHI — including patient names, dates of service, diagnosis codes, procedure codes, health plan information, and other individually identifiable health information. Such PHI is accessed solely on behalf of and under the direction of covered entity clients, in strict accordance with applicable BAAs and HIPAA requirements; and
- Audit Logs, Compliance Documentation, and Work Product: Records generated during the performance of services, including audit findings, coding reviews, compliance recommendations, and related work product documentation.
C. Sensitive Information
Protected Health Information (PHI) is recognized as sensitive information of the highest order and is treated accordingly. All PHI accessed or handled by the Company is subject to the strict requirements of HIPAA, the HITECH Act, and the terms of applicable Business Associate Agreements. PHI is not treated as or commingled with general personal data.
The Company does not, under any circumstances, sell, rent, lease, trade, or market PHI to any third party. PHI is used exclusively to perform contracted professional services and only as authorized under the applicable BAA and permitted by law.
4. How We Use Information
Blackstone Healthcare Solutions, LLC uses the information it collects only for lawful, legitimate, and specified purposes. The following describes how we use each category of information:
Website and Contact Information
- To respond to inquiries, questions, and requests submitted through the website or by email;
- To improve the usability and content of the website based on aggregate usage data;
- To analyze website traffic patterns and understand how visitors interact with the site; and
- To send newsletters or informational communications to individuals who have opted in to receive such content.
Client Business Information
- To deliver contracted medical coding, auditing, and compliance consulting services;
- To prepare, issue, and process invoices and payment documentation;
- To communicate professionally with clients regarding ongoing engagements, deliverables, and service matters;
- To maintain business records as required for legal, contractual, and accounting purposes; and
- To fulfill obligations under executed services agreements and Business Associate Agreements.
Protected Health Information (PHI)
- PHI is used exclusively to perform contracted professional services — specifically medical coding, medical auditing, and compliance review — as authorized by the applicable covered entity client and permitted under the terms of the executed BAA and HIPAA;
- PHI is never used for marketing, advertising, secondary commercial purposes, or any purpose beyond the scope expressly authorized by the BAA and applicable law; and
- The Company applies the HIPAA Minimum Necessary Standard to all uses and disclosures of PHI, accessing only the information necessary to accomplish the specific purpose for which it was obtained.
Compliance and Legal Obligations
- To satisfy obligations imposed by HIPAA, the HITECH Act, and other applicable federal and state laws and regulations;
- To respond to lawful requests from regulatory authorities, courts, or law enforcement as required or permitted by law;
- To maintain records required under HIPAA (minimum six-year retention) and other applicable legal requirements; and
- To investigate, document, and report potential privacy or security incidents in accordance with applicable breach notification requirements.
5. Protected Health Information (PHI) and HIPAA Compliance
This section provides important disclosures regarding the Company’s handling of Protected Health Information and its obligations and practices under HIPAA and the HITECH Act.
Definition of Protected Health Information
Protected Health Information (PHI) means individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate. PHI includes any information — whether in paper, electronic, or oral form — that relates to an individual’s past, present, or future physical or mental health condition; the provision of health care to the individual; or the past, present, or future payment for health care services, and that could reasonably identify the individual. Electronic Protected Health Information (ePHI) refers specifically to PHI that is created, received, maintained, or transmitted in electronic form.
The Company’s Role as a Business Associate
When Blackstone Healthcare Solutions, LLC accesses, receives, uses, or transmits PHI on behalf of a covered entity client in the course of performing medical coding, auditing, or compliance consulting services, the Company functions as a Business Associate as defined under HIPAA (45 C.F.R. § 160.103). In this capacity, the Company is directly subject to the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule, as well as to the terms of executed Business Associate Agreements with each covered entity client.
Business Associate Agreements (BAAs)
The Company requires a fully executed Business Associate Agreement (BAA) with every covered entity client before any PHI is accessed, received, or handled on that client’s behalf. No work involving PHI will commence prior to the execution of a BAA. Each BAA sets forth the permitted and required uses and disclosures of PHI, the obligations of both parties, and the remedies available in the event of a breach or non-compliance. BAAs are maintained in the Company’s records and are reviewed periodically to ensure continued compliance with applicable law.
Permitted Uses and Disclosures of PHI
The Company uses and discloses PHI only as permitted or required by the applicable BAA, the HIPAA Privacy Rule (45 C.F.R. Part 164, Subpart E), and applicable law. Permitted uses include performing the specific healthcare operations services contracted by the covered entity, and as otherwise expressly authorized in writing by the covered entity or required by law.
HIPAA Security Rule Compliance
The Company maintains a comprehensive information security program designed to comply with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) with respect to all ePHI it creates, receives, maintains, or transmits. This program includes:
- Administrative Safeguards: Security management processes, workforce training and management, information access management, security awareness programs, and contingency planning;
- Physical Safeguards: Facility access controls, workstation use and security policies, and device and media controls; and
- Technical Safeguards: Access controls, audit controls, integrity controls, and transmission security measures, including encryption.
The Company conducts regular security risk analyses and implements security measures sufficient to reduce identified risks to ePHI to a reasonable and appropriate level, consistent with 45 C.F.R. § 164.306.
Minimum Necessary Standard
The Company applies the HIPAA Minimum Necessary Standard to all uses, disclosures, and requests for PHI. The Company accesses, uses, and discloses only the minimum amount of PHI reasonably necessary to accomplish the specific purpose of the applicable service engagement, consistent with 45 C.F.R. § 164.502(b).
No Sale or Marketing of PHI
Blackstone Healthcare Solutions, LLC will never sell, rent, trade, barter, or otherwise exchange PHI for remuneration. PHI will not be used for marketing purposes, whether the Company’s own or any third party’s. This prohibition is absolute and unconditional.
Subcontractors and Downstream Business Associates
In the event that any subcontractor, vendor, or agent of the Company may have access to PHI in the course of assisting with contracted services, the Company requires that such parties enter into a fully executed Business Associate Agreement prior to any access to or receipt of PHI. The Company takes reasonable steps to ensure that all downstream business associates comply with applicable HIPAA requirements and the terms of their BAAs.
Retention of PHI and Related Records
PHI and PHI-related work product are retained by the Company for a minimum of six (6) years from the date of creation or the date the information was last in effect, whichever is later, consistent with HIPAA requirements (45 C.F.R. § 164.530(j)). PHI may be retained for longer periods where required by the terms of an applicable BAA or by state law. Upon expiration of the applicable retention period, PHI and related records are securely destroyed in accordance with the Company’s data destruction policies described in Section 11 of this Policy.
6. Website Data Practices & Cookies
This section describes how Blackstone Healthcare Solutions, LLC collects and uses data through its website, including through the use of cookies and similar tracking technologies.
Types of Cookies Used
The Company’s website may use the following categories of cookies:
- Strictly Necessary Cookies: These cookies are essential for the basic operation and functionality of the website. They enable core features such as navigation and access to secure areas and cannot be disabled without impairing website functionality. No personal identifying information is stored by these cookies beyond the browser session.
- Analytics Cookies: These cookies help the Company understand how visitors interact with the website by collecting information about pages visited, session duration, referral sources, and navigation paths. This data is used in aggregate, anonymized form to improve website content and user experience. Analytics cookies do not identify individual visitors by name or contact information.
- Preference Cookies: These cookies allow the website to remember settings or preferences selected by the visitor (such as language or display preferences) to provide a more personalized browsing experience.
No PHI Collected Through the Website
The Company’s website is not designed, intended, or configured to collect, transmit, or store Protected Health Information. Visitors to the website should not submit PHI through any website form, contact field, or communication channel. Any inadvertently submitted PHI will be treated in accordance with applicable HIPAA requirements and deleted as soon as practicable.
Third-Party Analytics
The Company may use third-party analytics tools (such as web analytics platforms) to collect anonymized usage data, including pages visited, session duration, and referral source information. These tools are configured to minimize data collection and are not permitted to use the data collected for their own advertising or marketing purposes. Third-party analytics providers operate under their own privacy policies and are selected and managed to ensure appropriate data handling standards.
Cookie Opt-Out
Visitors may opt out of non-essential cookies (including analytics and preference cookies) at any time by adjusting browser settings to block or delete cookies. Most modern browsers provide controls for managing cookie preferences. Note that disabling strictly necessary cookies may impair website functionality. Cookie preference tools, where available on the website, may also be used to manage consent.
Do Not Track (DNT) Signals
Some web browsers transmit Do Not Track (DNT) signals to websites to indicate a visitor’s preference not to be tracked. The Company’s website acknowledges and respects DNT browser signals where technically feasible. When a DNT signal is detected, the Company endeavors to limit the collection of non-essential tracking data during that session. Because DNT standards are not yet uniformly implemented across all platforms and tracking technologies, the Company cannot guarantee complete DNT compliance in all technical environments.
Session Data
Data collected through strictly necessary (session) cookies is not retained beyond the duration of the browser session. Upon closing the browser, session data associated with necessary cookies is deleted and not stored on Company servers.
Cookies and Individual Identification
Cookies used on the Company’s website do not identify individual visitors by name, contact information, or any other personally identifying detail unless the visitor voluntarily submits such information through a website form (e.g., a contact or inquiry form). In such cases, any information submitted is handled in accordance with the terms of this Privacy Policy.
7. Disclosure of Information to Third Parties
Blackstone Healthcare Solutions, LLC does not sell, rent, lease, or trade personal information to third parties for their own marketing, advertising, or commercial purposes. The Company may share information only in the limited circumstances described below.
Service Providers and Vendors
The Company may share personal information with trusted third-party service providers engaged to support business operations, including but not limited to:
- Information technology support and managed security service providers;
- Cloud hosting and data storage providers;
- Accounting, billing, and financial management software providers;
- Email service and communication platform providers; and
- Other vendors providing administrative or operational support services.
All third-party service providers with access to personal information are required to maintain the confidentiality of that information under written confidentiality or data processing agreements and are permitted to use the information only to the extent necessary to perform services on the Company’s behalf.
Legal and Regulatory Authorities
The Company may disclose personal information to government agencies, regulators, courts, law enforcement authorities, or other third parties when required to do so by applicable law, court order, subpoena, or other legal process, or where the Company believes in good faith that disclosure is necessary to comply with a legal obligation, protect the rights or safety of individuals, or respond to a lawful regulatory inquiry.
Business Succession
In the event of a merger, acquisition, sale of assets, reorganization, or other business transaction in which the Company or a portion of its assets is transferred to a successor entity, personal information held by the Company may be transferred to the successor as part of that transaction. The Company will use commercially reasonable efforts to ensure that any successor entity provides comparable privacy protections. Affected individuals will be notified of any material changes in accordance with Section 14 of this Policy.
Disclosures of PHI
PHI is disclosed only in strict accordance with the applicable Business Associate Agreement and HIPAA. PHI may be shared with subcontractors who assist in the delivery of contracted services, provided that such subcontractors have executed BAAs and are obligated to comply with applicable HIPAA requirements. PHI is never disclosed to third parties for marketing, advertising, or any other unauthorized purpose.
No Marketing or Advertising Disclosures
The Company does not disclose personal information — of any category — to third parties for marketing or advertising purposes. This prohibition applies regardless of whether monetary compensation would be received for such disclosure.
8. Data Security
Blackstone Healthcare Solutions, LLC maintains a comprehensive, risk-based information security program designed to protect personal information and PHI against unauthorized access, use, disclosure, alteration, or destruction. The Company’s security program incorporates administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements and industry best practices.
Administrative Safeguards
- A designated Privacy and Security Officer responsible for overseeing the Company’s compliance with HIPAA and applicable privacy and security policies;
- Formal written privacy and security policies and procedures, reviewed and updated on a regular basis;
- Mandatory workforce training on HIPAA requirements, data privacy obligations, and security best practices upon hire and annually thereafter;
- Role-based access controls limiting employee access to PHI and personal information to the minimum necessary for each employee’s job function;
- Regular security risk analyses to identify and address vulnerabilities in systems handling sensitive information; and
- Documented sanction policies for workforce members who violate privacy or security policies.
Physical Safeguards
- Controlled physical access to facilities where PHI or sensitive personal information is maintained;
- Locked storage for physical records containing sensitive information;
- Clean desk and clear screen policies requiring that sensitive information not be left visible or unattended; and
- Secure disposal of physical records containing PHI or personal information through cross-cut shredding or equivalent destruction methods.
Technical Safeguards
- Encryption of ePHI in transit using Transport Layer Security (TLS) 1.2 or higher;
- Encryption of ePHI and sensitive personal information at rest using industry-standard encryption protocols;
- Multi-factor authentication (MFA) required for access to systems, applications, and platforms containing PHI or sensitive personal data;
- Comprehensive audit logging of access to and activity within systems containing PHI, with regular review of audit logs; and
- Regular vulnerability assessments, penetration testing, and security risk assessments of systems handling sensitive information.
Third-Party Vendor Security
Prior to engaging any third-party vendor with access to PHI or sensitive personal information, the Company conducts a security assessment of the vendor’s information security practices. Vendors must demonstrate compliance with applicable security standards and agree to appropriate contractual security requirements before engagement.
Incident Response
The Company maintains documented incident response procedures for identifying, containing, evaluating, and reporting potential privacy or security incidents, including breaches of PHI. All workforce members are trained to identify and promptly report potential security incidents. The Company’s incident response program is designed to ensure compliance with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and applicable state breach notification laws.
Note: No information security program can guarantee absolute security. While the Company employs commercially reasonable safeguards, we cannot guarantee that unauthorized parties will never be able to defeat those measures.
9. Breach Notification
Blackstone Healthcare Solutions, LLC maintains breach notification policies and procedures designed to comply fully with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and applicable state data breach notification laws, including the Maryland Personal Information Protection Act (Md. Code Ann., Com. Law § 14-3501 et seq.).
Breaches of Unsecured PHI
In the event of a discovered breach of unsecured PHI that the Company accesses or maintains in its capacity as a Business Associate, the Company will:
- Notify the affected covered entity client(s) of the breach without unreasonable delay and in no event later than sixty (60) calendar days following the Company’s discovery of the breach, consistent with 45 C.F.R. § 164.410;
- Provide the covered entity with all information reasonably available to the Company to allow the covered entity to fulfill its own HIPAA breach notification obligations to affected individuals and, where applicable, to the U.S. Department of Health and Human Services (HHS) and the media; and
- Cooperate fully with the covered entity in investigating the breach, mitigating harm to affected individuals, and remediating identified vulnerabilities.
Large Breaches Affecting 500 or More Individuals
Where a breach of unsecured PHI affects 500 or more individuals in a single state or jurisdiction, the covered entity client is responsible for notifying HHS and, where required, prominent media outlets serving that state or jurisdiction. The Company will provide all information and cooperation necessary to enable the covered entity to fulfill these obligations within the timeframes required by HIPAA.
Annual Log for Small Breaches
For breaches of unsecured PHI affecting fewer than 500 individuals, the Company maintains a written log of all such breaches discovered during each calendar year. This log is provided to covered entity clients as needed to fulfill their obligation to report small breaches to HHS on an annual basis, no later than 60 days after the close of each calendar year.
Website and General Data Breaches
In the event of a breach of general personal information (not PHI) collected through the website or in the course of business operations, the Company will notify affected individuals and regulatory authorities in accordance with applicable state breach notification laws, including the Maryland Personal Information Protection Act, within the timeframes required by law. Notifications will include a description of the breach, the categories of information involved, steps taken to address the breach, and recommended steps for affected individuals to protect themselves.
10. Client and Individual Rights
A. HIPAA Rights Regarding PHI Handled on Behalf of Covered Entity Clients
Rights with respect to Protected Health Information — including the right of access, the right to request amendment, and the right to an accounting of disclosures — are rights that individuals hold with respect to the covered entity that maintains their health records. These rights are exercised through the applicable covered entity (the Company’s client), not directly through Blackstone Healthcare Solutions, LLC.
As a Business Associate, Blackstone Healthcare Solutions, LLC does not maintain a direct relationship with patients or individuals whose PHI it may access. However, the Company will cooperate fully and in good faith with covered entity clients to support the exercise of individual HIPAA rights, including by providing covered entity clients with access to PHI maintained by the Company, assisting with the incorporation of amendments, and documenting disclosures as required. Individuals wishing to exercise HIPAA rights should contact the applicable covered entity directly.
B. General Privacy Rights for Website Visitors and Business Contacts
Individuals whose general personal information (not PHI) is held by the Company have the following rights, subject to applicable legal limitations and retention obligations:
- Right to Know: The right to know what categories of personal information the Company collects, the purposes for which it is used, and with whom it may be shared;
- Right to Correction: The right to request correction or updating of inaccurate or incomplete personal information maintained by the Company;
- Right to Deletion: The right to request deletion of personal information, subject to the Company’s legal obligations to retain certain records under HIPAA, tax law, applicable contracts, and other regulatory requirements;
- Right to Opt Out of Non-Essential Communications: The right to opt out of receiving non-essential communications, such as newsletters or marketing emails, at any time by following the unsubscribe instructions in such communications or by contacting the Company directly.
To exercise any of the above rights, individuals may contact the Company using the contact information provided in Section 15 of this Policy. The Company will respond to verifiable requests within a reasonable time and in accordance with applicable law.
C. California Residents — CCPA/CPRA Rights
Residents of California may have additional privacy rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including:
- Right to Know: The right to request disclosure of the specific pieces and categories of personal information collected, sources of collection, purposes for collection, and categories of third parties with whom information is shared;
- Right to Delete: The right to request deletion of personal information, subject to applicable exceptions;
- Right to Correct: The right to request correction of inaccurate personal information;
- Right to Opt Out of Sale or Sharing: The right to opt out of the sale or sharing of personal information. The Company does not sell or share personal information as defined under the CCPA/CPRA; and
- Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising CCPA/CPRA rights.
California residents wishing to exercise CCPA/CPRA rights or submit a privacy request may contact the Company using the information provided in Section 15 of this Policy. Please include “California Privacy Request” in the subject line of your communication. The Company will respond to verifiable California privacy requests within the timeframes required by applicable law.
11. Data Retention
Blackstone Healthcare Solutions, LLC retains personal information and PHI for the periods described below, or for as long as necessary to fulfill the purposes described in this Policy, whichever is longer, subject to applicable legal obligations:
Category of Information | Retention Period | Basis |
Website data and general contact information (inquiry forms, email correspondence) | Up to 3 years from date of collection or last contact | Legitimate business purposes; applicable statute of limitations |
Client business contact and engagement records | 7 years after end of engagement | Legal, contractual, and professional liability requirements |
PHI and PHI-related work product | Minimum 6 years from date of creation or last effective date; longer if required by contract or state law | HIPAA (45 C.F.R. § 164.530(j)); applicable BAA; state law |
Billing and financial records | 7 years | Applicable tax, accounting, and regulatory requirements |
HIPAA policies, procedures, and documentation | 6 years from date of creation or last effective date | HIPAA (45 C.F.R. § 164.530(j)) |
Security incident and breach logs | 6 years minimum; longer as required | HIPAA; legal and regulatory requirements |
Secure Disposal
Upon expiration of the applicable retention period, the Company disposes of personal information and PHI using the following secure methods:
- Paper Records: Shredded using cross-cut or micro-cut shredders to render the information unreadable and unrecoverable; and
- Electronic Records: Securely wiped, degaussed, or destroyed in accordance with National Institute of Standards and Technology (NIST) Special Publication 800-88 guidelines for media sanitization, ensuring that information cannot be recovered or reconstructed.
12. Children’s Privacy
The Company’s website is not directed to children under the age of thirteen (13), and the Company does not knowingly collect, use, or disclose personal information from children under the age of 13.
Blackstone Healthcare Solutions, LLC’s services are exclusively business-to-business in nature, directed to healthcare organizations, covered entities, and professional contacts. The website is intended solely for adults, including healthcare professionals, prospective clients, and business representatives.
The Company complies with the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and its implementing regulations. The Company does not knowingly solicit or accept personal information from children under 13 through its website or any other digital channel.
If a parent or legal guardian believes that their child under the age of 13 has submitted personal information to the Company through the website or any other means, they should contact the Company immediately using the contact information provided in Section 15 of this Policy. The Company will promptly review the matter and, to the extent required by law or reasonably feasible, delete such information from its records.
13. Third-Party Links
The Company’s website may contain hyperlinks to third-party websites, including professional associations, industry organizations, government and regulatory agencies (such as the U.S. Department of Health and Human Services, the Centers for Medicare and Medicaid Services, or the HHS Office for Civil Rights), and other external resources that the Company believes may be of interest or relevance to website visitors.
These hyperlinks are provided for informational convenience only. Blackstone Healthcare Solutions, LLC does not control, operate, or maintain third-party websites and is not responsible for the content, accuracy, privacy practices, or data security of any third-party site. The inclusion of a hyperlink to a third-party website does not constitute an endorsement of that website or its operators by the Company.
The privacy practices of third-party websites are governed by those websites’ own privacy policies, which may differ materially from this Privacy Policy. Visitors who follow links to third-party websites are strongly encouraged to review the privacy policies of those external sites before submitting any personal information. The Company is not responsible for the collection, use, or disclosure of personal information by third-party websites.
14. Changes to This Privacy Policy
Blackstone Healthcare Solutions, LLC reserves the right to modify, update, or revise this Privacy Policy at any time to reflect changes in the Company’s practices, applicable law, regulatory requirements, or operational circumstances. All revisions are effective immediately upon posting to the Company’s website, unless otherwise stated.
The current effective date of this Policy, as posted at the top of this document, will be updated each time a revision is made. Visitors and clients are encouraged to review this Policy periodically to stay informed of any changes.
In the event of a material change to this Privacy Policy — meaning a change that substantially affects how the Company collects, uses, or discloses personal information or PHI — the Company will make commercially reasonable efforts to communicate the change directly to current clients, including by email notification or written notice, in advance of the change taking effect where practicable.
Continued use of the Company’s website following the posting of a revised Privacy Policy constitutes acceptance of the updated terms. If you do not agree with the terms of this Policy or any revised version, you should discontinue use of the website and contact the Company to address any ongoing business relationship.
Changes to the terms governing PHI handling are subject to the requirements of applicable Business Associate Agreements. Material changes to BAA-related practices will be addressed in accordance with the terms of those agreements.
15. Contact Information
For general privacy inquiries, questions about this Privacy Policy, or to exercise any of the rights described in Section 10 of this Policy, please contact Blackstone Healthcare Solutions, LLC using the information below:
Blackstone Healthcare Solutions, LLC
Privacy Office
PO Box 544
Upper Marlboro, MD 20773
Email: contact@bhsolutions01.com
For HIPAA-specific inquiries, Business Associate Agreement matters, or questions related to the Company’s handling of PHI on behalf of covered entity clients, please use the contact information above and include “HIPAA/BAA Inquiry” in the subject line of your communication. The Company’s designated Privacy and Security Officer will respond to HIPAA-specific inquiries.
Right to File a Complaint
Individuals who believe that their privacy rights under HIPAA or this Privacy Policy have been violated have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR):
HHS Office for Civil Rights
Website: https://www.hhs.gov/ocr/complaints
Toll-Free: 1-800-368-1019
TDD: 1-800-537-7697
Complaints may be filed with OCR online, by mail, or by email. There are no fees associated with filing a complaint with OCR. The Company strictly prohibits retaliation of any kind against any individual who, in good faith, files a complaint with HHS OCR or who otherwise exercises rights under HIPAA or this Privacy Policy. Retaliation against complainants is expressly prohibited by HIPAA (45 C.F.R. § 164.530(g)) and Company policy.
Individuals located in Maryland who have concerns about the Company’s handling of general personal information may also contact the Maryland Attorney General’s Consumer Protection Division.
Response Timeframes
The Company will acknowledge receipt of privacy inquiries within five (5) business days and will use commercially reasonable efforts to provide a substantive response within thirty (30) calendar days of receipt of a verifiable request. Where additional time is required, the Company will notify the requestor and provide a revised estimated response date.
This Privacy Policy is effective as of August 19, 2026. All prior versions of this policy are superseded as of the effective date above.
© 2026 Blackstone Healthcare Solutions, LLC. All rights reserved.
Maryland