Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.
Facility & Physical Security

Facility & Physical Security

Policy · v2026.06 · Owner: Head of Operations & Security Officer (joint) · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30

No PHI is stored or processed at any Foundry physical office. Protected health information lives only in Foundry’s FHIR service (R4), under HIPAA-eligible cloud infrastructure controls. Because no PHI is present at Foundry’s premises, the HIPAA Security Rule’s physical-safeguard requirements (45 CFR § 164.310) apply primarily to the cloud data centers operated by our cloud infrastructure providers, and, to a limited extent, to the workforce devices held at Foundry’s Carmel coordination office.

1. Purpose & scope

This policy governs the physical security of Foundry’s operating environments: the Carmel, Indiana coordination office; the cloud data centers operated by Foundry’s HIPAA-eligible infrastructure providers; and the workforce home offices from which most of Foundry’s work is performed. It addresses the HIPAA Security Rule’s facility-access controls, workstation use, and workstation security standards (45 CFR § 164.310(a)–(c)).

HIPAA Security Rule, Privacy Rule, and Breach Notification Rule govern this policy. Mapping to other frameworks (CCPA, ISO/IEC 27001, SOC 2) is maintained in the framework crosswalk.

Foundry is a remote-first MSO. The Carmel office is a coordination and team space, not a clinical or production facility. PHI is stored and processed only in Foundry’s FHIR service; physical safeguards therefore concentrate on the cloud providers’ data centers and on workforce devices.

2. Policy statements

Foundry policy requires that:

  1. No PHI or other Restricted data (per Data Management) is stored, printed, displayed on a fixed monitor in a public-visible way, or otherwise maintained at any Foundry physical office.
  2. Physical office security at the Carmel office is provided by the building / co-tenancy facility manager in accordance with their published security procedures. Foundry complies with and supplements those procedures.
  3. Physical security of production data centers is provided by Foundry’s cloud-infrastructure subprocessor, Amazon Web Services (AWS), under its own independently attested controls and under the BAA Foundry holds with AWS.
  4. Every workforce member is responsible for reporting physical security incidents, unauthorized access attempts, suspicious activity, lost or stolen devices, missing access cards, to Foundry Security.
  5. Workstations are locked when unattended, taken home from the Carmel office at the end of the work day, and never left in vehicles or other publicly accessible spaces.
  6. Building safety provisions, fire safety, emergency exits, evacuation procedures, at the Carmel office are maintained by the facility provider in accordance with applicable laws and regulations. Workforce members participate in announced drills.
  7. Visitors at the Carmel office sign in through the facility’s process and are escorted within Foundry’s leased footprint by a workforce member.

3. Controls & procedures

4. Carmel coordination office

Foundry maintains a coordination office in Carmel, Indiana.

The space is in a professionally managed office building. Physical access controls, building security, surveillance, and facility maintenance are managed by the building’s property manager.

The facility manager maintains controls including:

  • Building access control (key-card or equivalent badge access);
  • Surveillance and monitoring of common areas;
  • Building security staffing or after-hours monitoring per the facility’s standard;
  • Fire safety and emergency-response systems;
  • Visitor management at the lobby.

Foundry-specific controls inside Suite 125:

  • The suite door is locked outside of business hours and whenever no Foundry workforce member is on-site.
  • Access keys / cards to the suite are issued only to workforce members and tracked by the Head of Operations.
  • Guest access (vendors, candidates, visitors) is approved in advance, the visit is logged, and a workforce member escorts the guest while they are inside the suite.
  • Surveillance inside the suite, if any, is operated by the facility provider; Foundry does not store private spaces of recordings.
  • Where physical credentials or media are held on-site, they are kept in locked storage with access restricted to authorized workforce members.

Workforce members at the Carmel office:

  • Comply with the facility manager’s published security procedures;
  • Report any security concern or incident to Foundry Security;
  • Follow the facility’s visitor-management procedure for any guest entering the lobby, and supplement it with the suite-level escort described above.

5. Cloud data centers

Foundry’s production workloads run in:

  • Amazon Web Services (AWS): Foundry’s clinical data plane and platform infrastructure: the clinical workflow database (Amazon RDS for PostgreSQL), a private, Foundry-operated HAPI FHIR service (R4) running on Amazon ECS, object storage encrypted under AWS KMS customer-managed keys, the platform compute and messaging tiers, the managed secrets store, and the audit-logging surface. PHI lives only in the dedicated PHI account, behind network perimeter controls.

AWS operates physical security at the data center level and publishes independent attestations:

  • 24×7 staffing and surveillance;
  • Multi-factor physical access (badge plus biometric);
  • Environmental controls (power, cooling, fire suppression) with redundancy;
  • HIPAA-eligibility attestations published by AWS, along with their independent third-party attestations.

Foundry’s BAA with AWS binds AWS to safeguard PHI consistent with HIPAA. AWS attestations are available under NDA on request and are reviewed in the annual Vendor & Third-Party Risk cycle.

6. Workstation security

All Foundry computing equipment is secured to protect confidential company information and credentials:

  • Workstations and laptops are accessed and used only by the authorized workforce member to whom they are assigned.
  • Workforce members monitor their devices and report any unauthorized access attempt to Security, in line with Access Control and Incident Response.
  • Workstations are locked (password / passkey protected) when unattended, automatically after no more than five minutes and manually whenever the workforce member steps away.
  • Laptops are not left unattended in public areas at the Carmel office or at any other location. Portable devices are taken home at the end of the work day or secured in a locked drawer in the suite. Laptops are not left in vehicles overnight.
  • Workstations are company property; they are issued through and returned through the workflows in Asset Management.
  • Lost or stolen devices are reported to IT and Security immediately, per Incident Response. The device is remotely locked and wiped through MDM.

7. Clean desk

Workforce members secure confidential information whenever they leave their workspace.

Electronic information:

  • Workstations, laptops, and tablets are locked when unattended.
  • Portable devices are taken home or locked away at the end of the work day.
  • Removable storage (where it exists at all) is locked away when not in use.
  • Credentials are not written down, photographed, or stored physically. Recovery codes live in the workforce password manager.

Physical information:

  • PHI is never printed at the Carmel office, never stored at the Carmel office, never displayed on shared monitors at the Carmel office. Any inadvertent printing of PHI is a reportable incident.
  • Confidential business documents (executed contracts, signed forms) are immediately collected from the printer.
  • Confidential printed materials are stored in a locked drawer or destroyed through cross-cut shredding when no longer needed.
  • Sensitive documents are not left on desks overnight or while away from the workspace.

Keys and access cards:

  • Building or suite access cards are not left unattended.
  • Lost or stolen access cards are reported to the facility manager and to Foundry IT / Security on the same day.

8. Remote work environments

Foundry is remote-first; most workforce time is spent in home offices and, less often, in coworking spaces or travel locations. The physical-safeguard expectations on those environments are proportionate to their use:

  • Display privacy. Workforce members position their screens so that unauthorized observers cannot easily read confidential content. Use of a privacy filter is encouraged in public or shared spaces and required when working with PHI in any non-private setting.
  • Audio privacy. Calls discussing PHI or other confidential information are conducted in private space or with appropriate audio isolation (headphones, closed-door room). Calls discussing PHI are never recorded by the workforce member’s own device without an explicit business reason and contract authority.
  • Lock when stepping away. The screen-lock requirement applies in home offices too. A laptop on a kitchen counter or in a coworking space is locked the moment the workforce member moves out of line of sight.
  • Family / cohabitant access. Other people in the workforce member’s residence do not use the Foundry-issued laptop. The device is treated as an exclusively-assigned business tool.
  • Travel. Workforce members notify IT and Security before travel that takes them outside the United States; PHI access is suspended for the duration of the trip (per Access Control §4). Devices are not stored in checked baggage.
  • Network. Workforce members use trusted networks where possible; on untrusted Wi-Fi, the device’s DNS filter and the platform’s TLS protect the session. Foundry does not maintain a workforce VPN as a primary control because production access requires federated SSO with MFA (WebAuthn where the target console supports it), and every session runs over TLS.

9. Incident reporting

Workforce members report physical security incidents to security@bioscopefoundry.com, including:

  • Unauthorized access or attempted access to the Carmel suite, a workforce member’s home office, or any device;
  • Lost or stolen laptops, mobile devices, security keys, or access cards;
  • Suspicious activity at the Carmel office building or its parking;
  • Any concern about the physical security of a Foundry-issued device or credential.

Incidents are handled per Incident Response. Where there is any plausible exposure of PHI, which, given the FHIR-only PHI boundary, would itself indicate a separate failure, the matter is escalated to Breach Notification so the affected practice can be notified within the BAA’s timeframes.

10. Roles & responsibilities

  • Head of Operations: manages the Carmel office relationship with the facility provider, controls suite access, owns visitor procedures.
  • Security Officer: owns this policy, the workstation baseline, the lost-device workflow, and the incident-response intake.
  • IT Lead: administers MDM remote-lock and remote-wipe, replaces lost devices, reconciles the asset register.
  • Workforce members: lock devices, protect their workspaces, report incidents promptly.

11. Review & revision

This policy is reviewed at least annually and whenever Foundry’s facility footprint changes (new office, change of building, new coworking arrangement). Material revisions are approved by the Head of Operations and the Security Officer in coordination with the Policy Management process.

12. Related policies