Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.
Breach Investigation and Notification

Breach Investigation and Notification

Policy · v2026.06 · Owner: Security & Privacy Officer · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30

Bioscope Foundry is a HIPAA business associate. When we discover a breach of unsecured PHI in our handling, we notify the affected physician practice (the covered entity) without unreasonable delay and within the timeframes required by HIPAA and the Business Associate Agreement (BAA). The practice, not Foundry, issues the patient, HHS, and (where applicable) media notifications required by the HIPAA Breach Notification Rule. Foundry provides the practice with the information it needs to make those notifications.

1. Purpose & scope

This policy governs how Bioscope Foundry investigates and reports breaches of unsecured PHI that occur in the course of services Foundry provides as a HIPAA business associate. It implements the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the breach-notification obligations Foundry assumes under its BAAs with member practices.

The policy covers PHI that Foundry creates, receives, maintains, or transmits on behalf of a practice, including PHI in Foundry’s FHIR service (R4) store, in transit between Foundry services, in agent decision contexts, and in any audit or operational artifact derived from PHI. Foundry’s PHI boundary is enforced in code: PHI lives only in the FHIR store; it is never written to workstations, agent worktrees, generated documents, or logs.

As a business associate, Foundry’s role differs from a covered entity’s. Foundry reports breaches to the affected practice. The practice is the covered entity and is responsible for notifying its patients, HHS, and (in some circumstances) the media. Where the BAA delegates one of those notifications to Foundry in writing, Foundry executes that delegation; otherwise Foundry provides the practice with the data it needs and supports its work.

2. Policy statements

Bioscope Foundry policy requires that:

(a) Breach notification procedures are invoked upon confirmation of a security incident that results in unauthorized acquisition, access, use, or disclosure of unsecured PHI.

(b) The affected practice (covered entity) is notified without unreasonable delay and in no event later than thirty (30) calendar days from discovery of the breach by Foundry. This commitment is set by Foundry’s Business Associate Agreement and is well inside the 60-calendar-day outer limit at 45 CFR § 164.410. Where a Practice’s negotiated BAA sets a shorter window, that BAA controls.

(c) When a data breach involves unsecured PHI, Foundry provides the practice with all information required under 45 CFR § 164.410(c) so the practice can satisfy its own obligations under 45 CFR §§ 164.404 and 164.406 (and § 164.408 for HHS reporting).

(d) Foundry maintains a breach log and retains breach-investigation documentation for at least six years.

3. “Unsecured PHI” and the encryption safe harbor

“Unsecured PHI” means PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance (currently: encryption to NIST specification, or destruction by a documented destruction method).

PHI in Foundry’s environments is configured to satisfy the safe-harbor conditions when at rest and in transit:

  • At rest. PHI in the FHIR service store is encrypted with provider-managed or customer-managed encryption keys using AES-256.
  • In transit. PHI between Foundry services and between Foundry and the practice is encrypted with TLS 1.2 or higher.

An impermissible acquisition, access, use, or disclosure of PHI that satisfies the safe harbor is not a “breach” requiring notification under the Breach Notification Rule. Foundry still investigates such incidents through the Incident Response process and documents the determination.

4. Breach investigation process

4.1 Discovery

A breach of PHI is “discovered” as of the first day the breach is known to Foundry, or the first day on which the breach would have been known by exercising reasonable diligence. Foundry is deemed to have knowledge of a breach if it is known, or would have been known with reasonable diligence, by any workforce member or agent of Foundry, other than the person committing the breach.

Following discovery of a potential breach, Foundry immediately begins an investigation (see Incident Response), conducts a risk assessment (§4.3), and, based on the assessment, begins the process to notify each affected practice.

4.2 Investigation

The Security Officer names an investigator (typically the Privacy Officer, Security Officer, or a designated incident lead). The investigator is responsible for:

  • Managing the breach investigation;
  • Completing the risk assessment;
  • Coordinating with internal stakeholders (engineering, the SIRT, people operations, legal counsel, and executive leadership);
  • Acting as the key facilitator for notifications to the affected practice and any other authorized recipient.

All documentation related to the investigation, including the risk assessment, is retained for at least six years. The Security and Privacy Officer maintains a breach log (§9).

4.3 Risk assessment

For an acquisition, access, use, or disclosure of PHI to be a “breach,” it must violate the HIPAA Privacy Rule. A use or disclosure that is incident to an otherwise permissible use, occurs despite reasonable safeguards, and follows the minimum-necessary principle is not a Privacy Rule violation and does not qualify as a breach.

To determine whether an impermissible use or disclosure constitutes a breach, the investigator performs the four-factor risk assessment required by 45 CFR § 164.402:

  • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
  • The unauthorized person who used the PHI or to whom the disclosure was made;
  • Whether the PHI was actually acquired or viewed;
  • The extent to which the risk to the PHI has been mitigated.

The investigator also documents, for the internal record but separately from the four-factor analysis, the cause of the incident and the party responsible, the practice, Foundry, or a subprocessor, and the resulting remediation plan.

The risk assessment is documented as part of the investigation and recorded in the Linear incident ticket. Foundry bears the burden of demonstrating that all required notifications were made and, where Foundry concludes that no breach occurred, that the underlying impermissible use or disclosure did not in fact rise to the level of a breach under the rule.

5. Timing of notification

Upon discovery of a breach, Foundry notifies the affected practice without unreasonable delay and in no event later than thirty (30) calendar days from discovery, well inside the 60-calendar-day outer limit at 45 CFR § 164.410(b). Where a Practice’s negotiated BAA sets a shorter window, that BAA controls.

Foundry maintains evidence demonstrating that all notifications were made within the required timeframes, including documentation of any circumstances that necessitated a delay.

6. Content of the notification to the practice

The notification to the practice contains, to the extent possible at the time of notice (45 CFR § 164.410(c)):

  • The identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach;
  • A brief description of what happened, including the date of the breach (if known) and the date of discovery;
  • A description of the types of unsecured PHI involved (such as name, Social Security number, date of birth, home address, account number, diagnosis, disability code, lab result, or other types of information);
  • Any steps the practice or its patients should take to protect themselves from potential harm;
  • A brief description of what Foundry is doing to investigate the breach, mitigate harm, and protect against further breaches; and
  • Contact procedures for follow-up questions, including a Foundry contact, a phone or email address, and (when relevant) a web page with status updates.

Where information required by 45 CFR § 164.410(c) is not available at the time of the initial notification, Foundry provides it to the practice promptly as it becomes available.

7. Method of notification

The affected practice is notified by Foundry through the contact and method established in the BAA, typically a written notice delivered by email to the practice’s designated privacy contact, with phone follow-up by the Security Officer. Where the BAA specifies a different mechanism, Foundry uses the specified mechanism. The notification is documented in the Linear incident ticket and the breach log.

8. Law-enforcement delay (45 CFR § 164.412)

If a law-enforcement official states to Foundry that a notification, notice, or posting would impede a criminal investigation or cause damage to national security:

  • If the statement is in writing and specifies the time for which a delay is required, Foundry delays the notification, notice, or posting for the time period specified by the official.
  • If the statement is made orally, Foundry documents the statement (including the identity of the official) and delays the notification, notice, or posting temporarily, for no longer than 30 days from the date of the oral statement, unless a written statement specifying the required delay is submitted during that time.

Any delay invoked under § 164.412 is logged in the incident ticket with the official’s name, agency, and contact information.

9. Breach log and recordkeeping

In addition to the per-incident record described in the Incident Response policy, Foundry maintains a breach log capturing all breaches of unsecured PHI regardless of the number of records and practices affected. For each breach, the log captures:

  • A description of what happened, including the date of the breach, the date of discovery, and the number of records and individuals affected (if known);
  • The affected practice(s);
  • A description of the types of unsecured PHI involved (such as name, Social Security number, date of birth, home address, account number, diagnosis);
  • The date Foundry notified the affected practice and the method used;
  • Any law-enforcement delay invoked under § 164.412;
  • Resolution steps taken to mitigate the breach and to prevent recurrence.

Breach log entries and supporting investigation documentation are retained for at least six years, consistent with HIPAA documentation requirements at 45 CFR § 164.530(j).

10. Practice (covered entity) responsibilities

Once notified by Foundry, the affected practice is responsible for these notifications under the HIPAA Breach Notification Rule:

  • Breaches affecting 500 or more individuals in a single state or jurisdiction. The practice notifies HHS contemporaneously with notifying individuals (without unreasonable delay and in no event later than 60 calendar days from the practice’s discovery), and provides notice to prominent media outlets serving the state or jurisdiction within the same window.
  • Breaches affecting fewer than 500 individuals. The practice notifies individuals without unreasonable delay and in no event later than 60 calendar days from discovery. The practice reports such breaches to HHS through the OCR Breach Portal no later than 60 days after the end of the calendar year in which the breach was discovered. Media notification is not required.

Where a practice agrees in its BAA to delegate one of these notifications to Foundry (for example, where Foundry maintains the practice’s contact list and is best positioned to send patient notifications), Foundry executes the delegated obligation in accordance with the BAA and the rule. Absent a delegation, Foundry’s role is limited to providing the practice with the information required by § 164.410(c) and supporting the practice’s own notification work.

11. Sample notification letter to the affected practice

[Date]

[Privacy / Compliance Contact Name]
[Practice Name]
[Practice Address]

Re: Notification under 45 CFR § 164.410, Business Associate report of breach
    affecting protected health information

Dear [Name]:

I am writing on behalf of Bioscope Foundry, LLC, your HIPAA business associate
under the Business Associate Agreement effective [BAA effective date], to
notify you of a breach of unsecured protected health information ("PHI") that
affects [Practice Name]. Foundry discovered this breach on [date of discovery].
Based on the information available at this time, the breach occurred on or
about [date of breach].

What happened
[Brief description of what occurred, the systems involved, and the period of
exposure.]

Who is affected
[Identification of each affected individual whose unsecured PHI has been, or
is reasonably believed to have been, accessed, acquired, used, or disclosed.
Where the list is large, attach as a separate, encrypted file delivered
through the channel agreed in the BAA.]

Types of PHI involved
[A description of the types of unsecured PHI involved, for example, name,
date of birth, address, FHIR resource types, diagnosis, medication, lab
results, to the extent known.]

What we are doing
[A description of Foundry's investigation, containment, and remediation
steps; mitigation measures already taken; and steps being taken to prevent
recurrence.]

What you should consider doing
[Steps the practice or its patients may wish to take to protect themselves
from potential harm.]

How to reach us
For follow-up questions, please contact [Foundry contact name, role, email,
phone]. We will provide additional information required by 45 CFR
§ 164.410(c) as it becomes available, and will support your patient, HHS,
and (where applicable) media notification obligations under 45 CFR §§ 164.404
and 164.406.

Sincerely,

[Name]
Security & Privacy Officer
Bioscope Foundry, LLC
privacy@bioscopefoundry.com

12. Workforce training

Foundry trains all workforce members on the policies and procedures relevant to PHI as necessary and appropriate for each member’s role. Training covers how to identify a potential breach, how to report it through the channels in the Incident Response policy, and the prohibition on attempting to investigate or remediate independently of the SIRT. Training is delivered at onboarding and refreshed annually, with completion tracked.

13. Complaints, sanctions, non-retaliation

Complaints. Foundry provides a process for individuals (including practice workforce, patients via their practice, and Foundry workforce members) to make complaints about Foundry’s privacy practices or its compliance with those practices. Complaints can be sent to privacy@bioscopefoundry.com and are tracked in Linear.

Sanctions. Foundry applies appropriate sanctions against workforce members, contractors, and subprocessors who fail to comply with this policy or with the relevant BAA, ranging from required retraining to termination of employment or engagement.

Non-retaliation and non-waiver. Foundry does not intimidate, threaten, coerce, discriminate against, or take retaliatory action against any individual for exercising a privacy right or for filing a complaint, participating in an investigation, or opposing an act or practice that the individual believes in good faith violates HIPAA. Foundry does not require individuals to waive their privacy rights as a condition of any service.

14. Authority contacts

These contacts are provided for reference. Foundry, as a business associate, does not notify HHS, individuals, or the media on a practice’s behalf unless the BAA expressly delegates that responsibility. The affected practice manages these communications.

U.S. Department of Health and Human Services (HHS), Office for Civil Rights

  • Phone: 1-877-696-6775
  • HHS Breach Portal: https://ocrportal.hhs.gov/ocr/breach/wizard_breach.jsf
  • Mailing Address: Centralized Case Management Operations, U.S. Department of Health and Human Services, 200 Independence Avenue, S.W., Room 509F HHH Bldg., Washington, D.C. 20201

Federal Trade Commission

15. Roles & responsibilities

  • Security & Privacy Officer: owns this policy, makes the breach determination, names the investigator, signs notifications to practices, and maintains the breach log.
  • Investigator (per-incident): performs the risk assessment, coordinates internal teams, drafts the notification to the practice.
  • Legal counsel: supports breach analysis and any regulator or law-enforcement engagement.
  • Affected practice (covered entity): receives Foundry’s notification; conducts its own analysis; issues required notifications to patients, HHS, and (where applicable) media.
  • Workforce members: promptly report suspected breaches through any documented channel.

16. Review & revision

This policy is reviewed at least annually and whenever business, technology, or regulatory change makes it stale (for example, an HHS rulemaking that alters the Breach Notification Rule). Material revisions are approved by the Security Officer in coordination with the Policy Management process.

17. Related policies