Endpoint & Mobile Device Management
Policy · v2026.06 · Owner: IT Lead · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30
1. Purpose & scope
This policy governs Foundry’s workforce endpoints (laptops and mobile devices), the mobile-device-management (MDM) configuration applied to them, and the handling of storage media. It addresses the HIPAA Security Rule device-and-media controls (45 CFR § 164.310(d)). It applies to every device that authenticates to a Foundry-managed system or that holds Foundry-confidential data.
HIPAA Security Rule, Privacy Rule, and Breach Notification Rule govern this policy. Mapping to other frameworks (CCPA, ISO/IEC 27001, SOC 2) is maintained in the framework crosswalk.
Foundry’s architecture keeps PHI inside Foundry’s FHIR service (R4); endpoints never read or write PHI to local storage. Customer-managed FHIR data is therefore not present on Foundry laptops, on backup tapes, or on removable media. This policy’s mobile-and-media controls exist to make that boundary enforceable and to govern the small set of legitimate use cases that remain.
2. Policy statements
Foundry policy requires that:
All Foundry-issued media that may hold company data must be encrypted at rest; encryption is enforced by MDM and verified continuously.
Critical data, including PHI and any data classified Restricted in Data Management, must not be stored on mobile devices, removable media, or backup tapes held by Foundry. The platform’s FHIR-only PHI boundary makes the PHI case a structural prohibition, not just a procedural one.
Any destruction or disposal of media that may have held PHI is performed in accordance with federal and state law and with Foundry’s retention schedule:
- Records that have satisfied their retention period are destroyed or disposed of in an appropriate manner.
- Records involved in any open investigation, audit, or litigation are not destroyed until the matter is concluded.
Where any media could plausibly have held PHI, the media is rendered forensically inaccessible prior to reuse or disposal.
Mobile devices used in support of business operations are managed and auditable by Foundry IT and Security.
Where Foundry or a workforce member believes that customer data (including PHI) has been moved, copied, or transferred onto a personal device, the workforce member:
- Notifies Foundry Security immediately;
- Surrenders the device to Foundry Security for confirmation;
- Permits Security to securely remove the data, including a wipe or factory restore if required;
- Deletes any backup of that data, including encrypted and cloud-hosted backups, on confirmation.
Any such event is opened as an incident under Incident Response.
3. Controls & procedures
3.1 Approved devices
- Standard workforce device: Apple Silicon MacBook on a currently supported macOS release.
- Engineering exception: Linux laptops (Ubuntu LTS or equivalent) on Foundry-provisioned hardware, enrolled in MDM and brought under the EDR baseline.
- Mobile devices: Foundry-issued iPhones running a currently supported iOS release for workforce members whose role requires a managed mobile device. Personal mobile devices are not enrolled.
4. Endpoint baseline
The Foundry endpoint baseline applies to every managed laptop:
- Disk encryption. FileVault (macOS) or LUKS (Linux) is enforced by MDM. The recovery key is escrowed in MDM and accessible only to IT and the Security Officer through a dual-control workflow.
- Host firewall. The macOS firewall is enabled with stealth mode; all inbound connections are blocked by default. Linux endpoints run an equivalent configuration (e.g.
nftablesbaseline). - Endpoint Detection and Response (EDR). The EDR agent is installed and running. Detections feed the centralized log platform; tamper-resistance is enabled and audited.
- Screen-lock requirements. Automatic lock after no more than 5 minutes of inactivity; the lock requires authentication (passkey or password).
- Password / passkey. The local account uses a strong password meeting the credential baseline in Access Control, supplemented by Touch ID where the hardware supports it.
- Automatic OS & security updates. Critical updates install automatically; major OS upgrades are coordinated by IT within a published cadence (typically within 30 days of stable release).
- Browser baseline. Managed browser (Chrome or Safari) with enterprise policies that restrict installation of unknown extensions, enforce safe-browsing, and require sign-in to the managed workforce browser profile.
- DNS & outbound filtering. Workforce DNS is routed through the workforce DNS filter to block known-malicious destinations.
- Software inventory. Installed applications are inventoried through MDM. Only approved software with a valid license is installed.
- Time sync. NTP is enforced from a trusted source to keep audit timestamps coherent across the fleet.
- Lock screen content. Notifications on the lock screen do not expose message bodies. Notifications never carry PHI by design.
5. MDM enforcement
Foundry uses a dedicated MDM platform as the source of truth for endpoint configuration. The MDM:
- Enrolls every Foundry-issued device automatically through Apple Business Manager (or equivalent for Linux);
- Pushes the baseline configurations above and continuously asserts compliance;
- Reports drift back to the Security team via the SIEM;
- Supports remote lock and remote wipe for lost or stolen devices;
- Escrows FileVault recovery keys;
- Records last-check-in time, OS version, applied profile version, and EDR status for each device.
The Security team reviews fleet compliance weekly. Devices that fall out of compliance (missed check-in, EDR offline, OS unpatched beyond the window) are escalated; access is suspended for chronically out-of-compliance devices until they are remediated.
6. Mobile devices
Foundry-issued mobile devices are configured to a minimum baseline:
- Device passcode required, with biometric unlock supplementing it;
- Device encryption enabled by default (the iOS / Android standard);
- MDM enrollment with separation between the work profile and any personal content;
- Remote lock and remote wipe available to IT;
- OS at a currently supported major version;
- Sideloaded applications prohibited;
- Conditional access: only enrolled, compliant mobile devices can authenticate to the workforce the identity provider tenant.
Mobile devices are not used to connect directly to production environments. PHI is not viewed, transmitted, or stored on mobile devices; any workflow that would require this is routed through the desktop platform instead.
7. Storage media & removable devices
Foundry uses cloud storage for production data; workforce members do not routinely use removable media. The policy on USB drives, external SSDs, and similar media is therefore restrictive:
- PHI: never on removable media, under any circumstance.
- Other Restricted / Confidential data (per Data Management): permitted on removable media only as a documented exception, on Security-approved hardware-encrypted devices.
- Removable-media use requires a Linear ticket approved by IT and Security, identifying the workforce member, the data being transferred, the destination, and the expected duration.
- On completion of the transfer, the device is securely wiped and returned to the IT Lead, who verifies the wipe and re-checks the device into inventory.
- USB devices that are not hardware-encrypted Foundry-approved devices are blocked by the EDR’s device-control policy.
8. Media disposal
IT and Security ensure that media which may have held critical or sensitive data is disposed of securely:
- Methods of destruction, disposal, and reuse are reassessed periodically against current technology, accepted practice, and cost-effectiveness. Methods may include:
- Cryptographic erasure: destruction of the encryption key for media encrypted under a strong algorithm (AES-256);
- Secure overwrite using NIST SP 800-88 Rev. 1-compliant patterns where the media supports it;
- Physical destruction (shredding, degaussing) where overwrite or key-destruction is not adequate.
- For Foundry-issued laptops, end-of-life follows the asset-management retirement workflow in Asset Management: MDM-driven wipe, cryptographic erasure of FileVault, and inventory closeout.
- If records are requested in a judicial or administrative hearing, a qualified protective order is obtained to ensure their return or proper disposal by the requesting party.
- Subcontractors (per Vendor & Third-Party Risk) are contractually required to return or destroy Foundry data on contract termination. Where return or destruction is infeasible, the contract limits the use and disclosure of the data to the purposes that prevent its return or destruction.
- For a member practice terminating its engagement with Foundry, data return or disposal follows the BAA and the published offboarding procedure. After return, the practice is solely responsible for ongoing safeguards on the data; Foundry retains only the audit records and any data the BAA expressly requires it to keep.
9. BYOD posture
Foundry provides workforce members with company-issued laptops and, where applicable, mobile devices. BYOD (Bring Your Own Device) for workforce work on Foundry systems is not supported. Personal devices do not enroll in MDM and are not allowed to access PHI-bearing surfaces or to install Foundry-licensed software.
Where engineering self-configures a Foundry-issued laptop:
- The workforce member follows a documented configuration baseline maintained by IT and Security;
- The device is still enrolled in MDM, runs EDR, and is audited daily for baseline compliance;
- Configurations that diverge from the baseline are flagged and remediated.
10. Roles & responsibilities
- IT Lead: owns the MDM, the endpoint baseline, the asset register tie-in, and the disposal workflow.
- Security Officer: owns the EDR program, the SIEM tie-in, exception approvals, and the device-control policy.
- Workforce members: keep their devices in compliance (no jailbreaking, no disabling EDR, no installing unapproved software), report loss or theft immediately, and surrender devices to Security on request.
11. Review & revision
This policy is reviewed at least annually and whenever the endpoint stack, MDM vendor, or OS baseline changes materially. Material revisions are approved by the IT Lead and the Security Officer in coordination with the Policy Management process.