Security and compliance, built for an MSO that handles PHI on behalf of physicians.
Bioscope Foundry is an AI-enabled management services organization (MSO) for independent U.S. physicians. This Trust Center documents how we protect protected health information (PHI) as a HIPAA business associate, the controls we operate, and the legal agreements that bind our work.
What you'll find here
How we run security and privacy: access control, data protection, incident response, AI governance, BCDR, and more.
HIPAA Security Rule mapping, ISO 27001 and ISO 42001 alignment, OWASP Top 10 status, and the NIST 800-63B baseline.
Privacy Policy, Terms of Service, HIPAA Notice, Business Associate Agreement, MSA, Subprocessors, and Support Terms.
What Foundry is, how your health information is protected, and where your privacy rights live.
Program at a glance
PHI lives only in Foundry’s clinical data plane on AWS, never on workstations, in logs, or in documents. Redaction boundaries are enforced in code.
Zero standing access to production. Elevation is approved, time-bounded, and auto-expires; phishing-resistant MFA protects privileged paths.
Encryption, segmented networks, hardened endpoints, supply-chain pinning, and a secure SDLC: no single failure compromises PHI.
Material decisions stay human-in-the-loop. Agent tiers cap the scope of any AI action, and every read and write of PHI is logged.
Core commitments
Patient records live in Foundry’s clinical data plane on AWS under an executed BAA, never on workstations, in logs, or in generated documents.
PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256), under keys Foundry manages in AWS KMS.
Passwordless, federated sign-on for workforce and providers; phishing-resistant MFA required for privileged access.
Every read and write of PHI is logged, with audit records retained for at least six years.
Any subprocessor that may handle PHI is bound by a BAA. We publish a current list with effective dates.
AI augments, never replaces, human judgment. A redaction layer separates physician-facing surfaces from raw PHI.
Contact & reporting
Security disclosures, BAA requests, and privacy questions all route through the same desk.
Security disclosures & incidentssecurity@bioscopefoundry.com
Privacy & HIPAAprivacy@bioscopefoundry.com
BAA & vendor requestslegal@bioscopefoundry.com