HR & Personnel Security
Policy · v2026.06 · Owner: Head of People & Security Officer (joint) · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30
1. Purpose & scope
This policy governs the security and conduct expectations placed on Bioscope Foundry’s workforce, employees, contractors, interns, and any other person acting on Foundry’s behalf, from the time of offer through termination. It addresses the HIPAA Workforce Security and Information Access Management standards (45 CFR § 164.308(a)(3) and § 164.308(a)(4)).
HIPAA Security Rule, Privacy Rule, and Breach Notification Rule govern this policy. Mapping to other frameworks (CCPA, ISO/IEC 27001, SOC 2) is maintained in the framework crosswalk.
Foundry is a remote-first MSO. Workforce members work primarily from their homes; the Carmel office is a coordination space, not a PHI-bearing facility. Every workforce member supports independent physician practices that remain the covered entities for their own patients; the privacy expectations below sit on top of, not in place of, each practice’s own conduct standards.
2. Policy statements
In addition to the cross-functional roles set out in Roles, Responsibilities & Training, Foundry policy requires every workforce member to comply with the acceptable-use and HR-security expectations of this document and with the practice-supplied policies that bind their work for a specific covered entity.
Foundry policy requires that:
- Background verification is performed on every candidate for employment or contract engagement, in accordance with applicable U.S. federal and state law and proportional to the role’s exposure to PHI, finances, and credentials. PHI-access roles require a satisfactory background check before access is granted.
- Every employee, contractor, and third-party user signs the terms of their engagement, including a confidentiality agreement and Foundry’s acceptable-use policy, before being provisioned.
- Workforce members disclose outside activities and potential conflicts of interest in accordance with the Conflict of Interest process below.
- Workforce members complete onboarding that introduces them to Foundry’s environments, policies, security expectations, and HIPAA obligations as a business associate. Ongoing security and HIPAA awareness training is required and audited.
- Offboarding reiterates any duties that survive termination (confidentiality, IP, non-disparagement), removes access, recovers company assets, and confirms the workforce member’s last day in the HR system.
- Foundry and its workforce take reasonable measures to ensure that PHI and other confidential data are not transmitted through unsanctioned channels (personal email, personal chat, social media, generative-AI services without a BAA).
- Foundry maintains a list of prohibited activities (e.g. downloading PHI to personal devices, taking generative-AI screenshots of patient records, sharing credentials) and updates the list as the threat landscape evolves.
- Suspected breaches of security or policy are investigated through a fair disciplinary process. Multiple factors, intent, prior history, role, harm, inform the response. Foundry reserves the right to terminate engagement for serious misconduct, and immediate termination is the default response to any deliberate violation of the PHI boundary.
3. Controls & procedures
3.1 HR system of record
Foundry uses a dedicated HRIS platform as the system of record for workforce identity, role, employment status, training completion, and policy acknowledgments. The HRIS is the trigger source for downstream provisioning and termination workflows tracked in Linear.
3.2 Organization structure
A reporting structure aligned to Foundry’s lines of business is maintained in the HRIS and made visible to every workforce member. The organization chart shows reporting lines, role labels, and PHI-access tags. Updates flow through People Operations.
3.3 Job descriptions
Position descriptions are documented in the HRIS and updated as roles evolve. Each description identifies:
- The expected skills and responsibilities;
- The data classifications the role may reach (including whether the role is PHI-access);
- Required certifications or background screens; and
- The training catalog applicable to the role.
3.4 Performance reviews
Workforce members receive ongoing feedback from their manager and peers, with a formal annual review documented in the HRIS. Reviews capture both performance outcomes and conduct, including adherence to security and HIPAA obligations.
4. Acceptable use of end-user computing
Foundry requires every workforce member to comply with the following acceptable-use rules:
- Workforce members are considered remote users at all times and follow the remote-access controls in Access Control regardless of physical location.
- Use of Foundry computing systems is subject to monitoring by IT and Security, consistent with applicable law and any notice given at hire.
- Computing devices used for business purpose, including company-issued laptops, mobile phones, and any approved peripheral, may not be left unattended in public spaces.
- Workforce members take Foundry-issued laptops with them when leaving the Carmel office or any travel location; devices are not stored overnight in shared offices or vehicles.
- Full-disk encryption (FileVault on macOS) is enforced through MDM. Mobile devices accessing Foundry data have device encryption enabled and meet the device-baseline controls in Endpoint & MDM.
- Only approved software with a valid license is installed on Foundry devices. Personal software is not installed on Foundry devices, and Foundry-licensed software is not used for personal purposes.
- Sensitive or confidential content sent by email is sent through Foundry’s tenanted the identity provider and, when content would otherwise be exposed, is protected by the identity provider’s confidential mode or an equivalent control. PHI is not sent by email under any circumstances; it stays inside the platform.
- Workforce members do not post sensitive or confidential content (including PHI, customer identifiers, credentials, or internal strategy) in public forums, third-party chat tools, or generative-AI products that do not have a Foundry-executed BAA or equivalent contract. If a public post is necessary for technical support, content is sanitized before posting and reviewed by Security.
- EDR or anti-malware protection is installed and actively running on every endpoint that can be affected.
- Storage media (USB drives, external SSDs, removable backups) are managed under the data-classification scheme in Data Management. Use of removable media for confidential data is prohibited absent a Security-approved exception.
- It is strictly forbidden to download or store any PHI on end-user computing devices. PHI is reached only through the Foundry platform’s audited APIs and UIs and remains inside the FHIR service environment. Screenshots, copy/paste, file exports, and AI-tool ingestion of PHI are all prohibited.
- Mobile devices are not used to connect directly to production environments. The standard production-access path uses a managed laptop authenticating through the workforce identity provider with MFA.
- Workforce members do not use personal email, personal cloud storage, or personal generative-AI accounts to process Foundry or member-practice data.
5. Screening & onboarding
5.1 Pre-employment screening
Background verification is performed before the start date of any employment or contract engagement. Verification is scaled to the role:
- All workforce roles: identity verification, right-to-work check, criminal background check consistent with applicable U.S. federal, state, and local law, and employment / education verification.
- PHI-access roles: the above plus an OIG/SAM exclusion check against the U.S. Department of Health & Human Services Office of Inspector General List of Excluded Individuals/Entities and the General Services Administration’s System for Award Management.
- Finance- or credential-bearing roles: add a credit history check where permitted by law.
Screening is performed by an approved third-party vendor under contract. Results are stored in the HRIS subject to access controls. A workforce member may not be granted PHI access, production-cloud access, or repository-admin access until screening clears.
5.2 Onboarding
People Operations creates an onboarding record in the HRIS for every new workforce member and opens a corresponding onboarding ticket in Linear. The onboarding workflow has three required pillars before any access is provisioned beyond the standard bundle:
- Training and policy acceptance.
- The new workforce member completes Foundry’s core training: security policy walkthrough, acceptable-use policy, HIPAA business-associate awareness, the PHI boundary, the Conflict of Interest process, and an overview of the platform’s audit logging.
- The workforce member signs the confidentiality agreement, the acceptable-use policy acknowledgment, and the conflict-of-interest disclosure form.
- Records are kept in the HRIS.
- Training and signed acknowledgments must be completed within 30 days of start. Access to PHI-bearing systems is not provisioned until the HIPAA portion is complete.
- Access provisioning.
- The standard bundle for the workforce member’s role is provisioned per the workflow in Access Control.
- Any access beyond the standard bundle is requested separately, with a business justification, and is approved by the Security Officer.
- PHI-access group membership is granted only after the workforce member has completed HIPAA training and signed the acknowledgment, and only when the role requires it.
- Device configuration.
- The workforce member’s MacBook is shipped from inventory or handed off in person, enrolled in MDM, configured to the endpoint baseline (FileVault, host firewall, EDR, automatic lock under 5 minutes), and audited as enrolled before first-day sign-in.
- Engineering workforce who self-configure follow a documented baseline; their devices are enrolled in MDM and audited just like default devices.
5.3 PHI-access onboarding gates
Workforce members tagged as PHI-access pass additional gates before being added to the PHI-access group in the identity provider:
- Background check cleared, including OIG/SAM check.
- HIPAA business-associate training completed and acknowledged.
- PHI handling walkthrough with a Security or Clinical Operations lead, covering minimum necessary, audit logging, the PHI boundary, and the consequences of any download or off-platform exfiltration.
- Phishing-resistant MFA factor (WebAuthn security key preferred, platform passkey acceptable) issued and registered where the target console supports it; a strong TOTP factor where WebAuthn is not yet supported by the surface.
- Confidentiality agreement signed (or re-signed with the PHI-access addendum).
These gates are tracked as checklist items on the onboarding Linear ticket. Each item is signed off by a designated owner.
6. Training & awareness
- HIPAA awareness training is required at hire and annually thereafter for every workforce member, regardless of PHI-access status, because every workforce member could plausibly encounter PHI in a routed message or a misdirected ticket.
- Role-specific training is layered on top: engineering completes secure-coding refreshers, Clinical Operations and Practice Success complete an additional clinical-workflow training, IT and Security complete vendor-specific platform training.
- Annual training completion is tracked in the HRIS; non-completion within 30 days of the due date results in suspension of access until the requirement is met.
- Just-in-time training is delivered after a security event, a policy update, or the introduction of a new system. Acceptance is recorded.
- Continuous-education budgets are available for conferences, courses, and certifications relevant to the workforce member’s role.
7. Termination & offboarding
People Operations maintains the master offboarding checklist in the HRIS. The checklist is the same whether the separation is voluntary, involuntary, or end-of-contract; the only variable is the timing.
- People Operations (or the workforce member’s manager) opens an offboarding ticket in Linear and notifies Security on the day the decision is final. For involuntary separations affecting a PHI-access workforce member, the notification is given before the conversation with the workforce member.
- HR or the manager notifies Security to terminate access whenever there is evidence or reason to believe that:
- A workforce member has been using their access inappropriately;
- A workforce member’s credentials have been compromised;
- An unauthorized individual is using a workforce member’s identity. (In any of these cases an incident report is also filed; see Incident Response.)
- Security disables the workforce member’s identity-provider account, which cascades through SSO to revoke application access. MFA credentials, MDM enrollment, repository organizations, time-bound access grants, and any unfederated SaaS administrator role are reconciled the same business day.
- For any workforce member who has held PHI access, all revocations are completed the same business day as separation. For all other workforce members, revocation is completed within one business day.
- The workforce member returns the company-issued laptop, security keys, and any other equipment. Devices are wiped through MDM and re-imaged before reissue.
- Security audits workforce identities at least quarterly and removes accounts that have not authenticated for an extended period (defaulting to 90 days), accelerated review when the role has touched PHI.
8. Issue escalation & whistleblowing
8.1 Escalation
Workforce members escalate issues through the procedures published in the employee handbook. Issues that reach the Escalation Team are assigned a designated owner. The membership of the Escalation Team is maintained by the CEO or delegate.
Security incidents, particularly those involving PHI, are handled per Incident Response. Where an incident involves a breach of PHI, the Security Officer manages the response per Breach Notification, which covers the BA-to-covered-entity reporting obligation Foundry owes to the affected practice. If a workforce member is unsure whether something is a security incident, the default is to contact Security immediately; over-reporting is welcomed.
The incident owner:
- Creates a Linear issue in the Security Issues tracker (or, for incidents touching PHI, the dedicated Incidents tracker).
- Investigates and documents the issue, moving it to Review when a conclusion or remediation is reached.
- Has the issue reviewed by another member of the Escalation Team. If rejected, the issue is re-investigated.
- On approval, marks the issue Done with any pertinent notes.
- Notifies the workforce member who originated the report of the outcome.
8.2 Whistleblower process
Foundry requires every workforce member to observe high standards of business and personal ethics. Each workforce member is encouraged to report serious concerns so they can be addressed, including questionable accounting matters, violations of company policy or ethics, and suspected violations of laws or regulations.
- Acting in good faith. Reports must be made in good faith with reasonable grounds. Allegations made maliciously or known to be false are themselves serious disciplinary offenses.
- Confidentiality. The confidentiality of a reporter is maintained to the extent possible. Identity may be disclosed where required to conduct a thorough investigation, to comply with the law, or to afford the accused their legal right of defense.
- No retaliation. Workforce members who report concerns in good faith are not subject to retaliation. Retaliation is itself a sanctionable offense, up to and including termination.
- Reporting. Concerns may be filed directly with the CEO, the Security Officer, or the Privacy Officer. Anonymous reporting is supported by an anonymous reporting channel. Additional reporting paths are documented in the employee handbook.
9. Conflicts of interest
Workforce members make decisions on Foundry’s behalf every day. Those decisions must be made in Foundry’s interest and independent of outside influences. Where personal or outside interests could influence judgment, the appearance of a conflict can be as harmful as the conflict itself. The default in any case of doubt is disclosure.
- What is a conflict of interest? A conflict arises when a workforce member’s personal or outside interests conflict with Foundry’s. Examples include outside employment with a competitor, customer, or vendor (including advisory or board roles); engaging in other work during Foundry working hours; investments that could influence judgment; personal relationships with another workforce member who can influence pay, performance rating, or promotion; use of Foundry’s name, logo, or property for personal purposes; and any activity that could lead to disclosure of confidential information or PHI.
- Policy requirements. Outside activity must not interfere with the workforce member’s Foundry duties, must not compete with Foundry’s products or services, must not violate Foundry’s compliance obligations (including BAAs and the conduct expectations of member practices), and must not lead to disclosure of confidential information. Where in doubt, the workforce member raises the activity to their manager and to People Operations in advance.
- Disclosure responsibility. Every workforce member completes the Conflict of Interest Disclosure Form at hire and whenever a relevant change occurs. The form is filed in the HRIS. Where a conflict is confirmed, Foundry and the workforce member agree mitigations; in some cases the workforce member may need to step back from a specific decision or recuse themselves from a specific account.
- Resolution. Conflicts are resolved fairly and as early as possible. Final decisions on contested conflicts rest with senior leadership.
10. Non-compliance & sanctions
Workforce members report suspected non-compliance with this or any Foundry policy to the Security Officer or to their manager. Reports made in good faith are not subject to retaliation.
- The Security Officer facilitates a prompt investigation, with assistance from other personnel as needed. The investigation:
- Builds an audit trail covering the violation and the sequence of events;
- Interviews workforce members with relevant knowledge;
- Gives the workforce members suspected of non-compliance an opportunity to explain their actions;
- Is documented contemporaneously, including the names of every person involved.
- Violation of any security policy or procedure by a workforce member may result in corrective disciplinary action up to and including termination. Violation by a business associate’s subcontractor, vendor, or customer may result in termination of the relationship and may carry civil or criminal penalties under applicable law.
- A fair disciplinary process is followed. Factors considered include prior history, intent, the workforce member’s training, the harm caused, and contractual obligations.
- Foundry reserves the right to terminate workforce members for serious misconduct.
- A violation that results in unauthorized disclosure of PHI, an integrity loss to PHI, or an availability loss preventing authorized users from reaching PHI is grounds for immediate termination of the workforce member.
- The Security Officer facilitates steps to prevent recurrence, additional training, control changes, policy clarification, where feasible.
- Where an insider threat is suspected, the Security Officer and the Privacy Officer convene a small team to investigate and mitigate. Workforce members are encouraged to come forward, including anonymously.
- The Security Officer maintains documentation of the investigation, sanctions, and remediation for at least seven years after the conclusion of the matter.
- When a formal sanction process is opened, the appropriate manager or supervisor is notified within 24 hours. The notification identifies the individual, the reason for the sanction, and the specific procedures for service or account restriction or revocation.
10.1 Clean desk
Workforce members secure all sensitive or confidential information in their workspace at the end of the work day and whenever the workspace is unattended. This includes:
- Computers, laptops, and tablets: locked (screen lock active) when unattended; taken home from the Carmel office after the workday.
- Removable storage (the rare USB drive, an external SSD): locked in a drawer when not in use; never used for PHI.
- Printed material: Foundry does not generate printed PHI; for the small set of permitted printed material (e.g. signed contracts), output is collected from the printer immediately and stored in a locked drawer when not in use.
- Passwords are never written down or stored physically. Recovery codes are stored in the workforce password manager.
- Office keys and access cards (Carmel office) are not left unattended.
11. Roles & responsibilities
- Head of People / People Operations: owns the HRIS, the onboarding/offboarding checklists, performance reviews, and the conflict-of-interest register.
- Security Officer: co-owns this policy, approves PHI-access onboarding completion, runs the sanctions process, owns annual HIPAA training delivery.
- Hiring managers: write accurate job descriptions, sponsor access requests, sign off on a new workforce member’s onboarding checklist completion.
- Privacy Officer: receives whistleblower reports related to privacy and PHI; coordinates investigations with the Security Officer.
- Every workforce member: completes training on time, signs and abides by policy acknowledgments, discloses conflicts as they arise, reports suspected violations.
12. Review & revision
This policy is reviewed at least annually and whenever business, technology, or regulatory change makes it stale. Material revisions are approved jointly by the Head of People and the Security Officer in coordination with the Policy Management process.