Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.

Privacy & Consent

Policy · v2026.06 · Owner: Privacy Officer · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30

Bioscope Foundry is committed to protecting the privacy of the people we deal with as an MSO, visitors to bioscopefoundry.com, physicians who apply or join, and the workforce of member practices. This is the program-level privacy policy. The public-facing privacy notice lives at /legal/privacy-policy.html. PHI handled on behalf of a member practice is governed by the Business Associate Agreement and described in the HIPAA Notice & Business Associate Statement, not by this policy.

1. Purpose & scope

This policy sets Foundry’s program-level requirements for privacy and consent across the MSO. It covers the information Foundry collects about visitors, applicants, physician members, and member-practice staff in the course of operating the business.

This policy is about Foundry-as-MSO information collection. Patient health information (PHI) that Foundry handles for a physician practice is not governed here; it is governed by the Business Associate Agreement (BAA) between Foundry and the practice and described in the HIPAA Notice & Business Associate Statement. Patient rights flow through the practice’s own Notice of Privacy Practices, not through Foundry.

2. Policy statements

Foundry policy requires that:

(a) A privacy notice is published and kept current so visitors, applicants, and member practices can understand how Foundry collects, uses, secures, and shares information.

(b) Valid consent is obtained for information collected from a person where consent is the lawful basis, and the purposes for which the information will be used are disclosed. Where applicable, the person is offered a meaningful opt-in or opt-out. Material changes to processing trigger a refreshed disclosure and, where required, re-consent.

(c) Foundry does not sell personal information and does not share personal information for cross-context behavioral advertising.

(d) AI-assisted processing is disclosed at the point of collection. AI processing that touches PHI occurs only through HIPAA-eligible services covered by a BAA, with human-in-the-loop review for material decisions.

(e) Individual rights requests (access, correction, deletion, portability, opt-out) are routed, verified, and responded to within statutory timelines, with refusals limited to legally permitted grounds and an internal appeal path.

3. Controls & procedures

3.1 Privacy notice

Foundry’s current public-facing privacy notice is published at /legal/privacy-policy.html and at bioscopefoundry.com under the standard footer link. The notice describes:

  • Who Foundry is (a Delaware MSO supporting independent U.S. physician practices);
  • The two distinct environments, the marketing site and the authenticated operating platform, and the privacy practices for each;
  • What information Foundry collects from visitors, applicants, and member-practice users;
  • How Foundry uses that information, including AI-assisted processing;
  • Categories of recipients (service providers under contract, parties acting on a person’s direction, legal and safety disclosures, business-transfer recipients);
  • Retention defaults and the relationship to the Data Management policy;
  • How individuals exercise their rights and how Foundry handles requests;
  • Contact information for the Privacy Officer and how to escalate.

The notice is reviewed at least annually and whenever a material change to processing, vendors, or applicable law warrants it. Material changes trigger an updated “Last updated” date and, where required, prominent notification before the change takes effect.

3.2 Consent and choice

Foundry distinguishes between information that is necessary to provide a service and information collected on a consent basis.

  • Required for service. Information needed to evaluate an application, sign a contract, provision an account, run payroll for a member practice, or operate the platform is collected as part of performing the agreement. Refusal means Foundry cannot provide that service.
  • Consent-based. Optional processing is offered with a clear opt-in. The most consequential example is the voice-first onboarding interview: Foundry tells the applicant before recording begins, captures consent, explains how the audio and transcripts will be used and retained, and permits withdrawal at any time.
  • Marketing communications. Marketing email is opt-in for non-customers and includes an unsubscribe mechanism. Transactional communications about an existing account are sent on the contractual basis and not subject to opt-out.
  • Cookies and analytics. The marketing site uses cookies and may use analytics; the operating platform uses only strictly necessary cookies for security and authentication. The notice provides cookie-control guidance.

Consent records are retained alongside the corresponding account or application so Foundry can demonstrate, on request, when and how consent was obtained.

3.3 Notice of Privacy Practices (not applicable)

Foundry is not a HIPAA covered entity and does not provide healthcare services directly to patients. Foundry therefore does not issue a patient-facing Notice of Privacy Practices. Each member practice issues its own NPP to its patients; patient rights regarding PHI are exercised through the practice. The HIPAA Notice & Business Associate Statement explains Foundry’s role as a business associate.

3.4 Platform use terms and consent

Terms of use for Foundry’s operating platform are hosted at /legal/terms-of-service.html and surfaced in-product at first sign-in. Material changes require an updated acceptance step before continued use, except for non-material updates which are notified by email and by in-product banner.

Service-specific consents (for example, the onboarding interview recording, agreement signatures, or specific authorizations from member-practice administrators) are captured in-flow, time-stamped, and stored with the corresponding account.

3.5 AI-assisted processing

AI assistance is part of how Foundry’s services work. Examples include the voice-first onboarding interview, summarization and triage of communications, and analyst support for back-office workflows. The privacy notice describes AI processing at the level a reasonable visitor or applicant needs to understand it.

Foundry policy:

  • AI outputs augment, not replace, human judgment. A person reviews material decisions, including membership, compliance, and clinical-policy determinations.
  • AI processing of PHI occurs only through HIPAA-eligible services covered by a BAA. The foundry-master-agent tiering model enforces this: clinical-tier agents are PHI-eligible inside the conductor authorization boundary; sandboxed worker tiers (Moltworkers) cannot hold PHI or clinic-scoped data.
  • The Beacon Layer redacts PHI before sanitized insights surface to physician-facing dashboards or external reports.
  • De-identified or aggregated information may be used to improve services, consistent with HIPAA’s de-identification standard and other applicable law.
  • Individuals may ask the Privacy Officer about AI processing that affects them, including the categories of inputs, the role of human review, and the option to request a re-review where a decision was based on automated processing.

Foundry’s alignment with non-HIPAA frameworks (including AI-management and information-security standards) is described in the framework crosswalk.

3.6 Individual rights handling

Depending on residency, individuals may have the right to access, correct, delete, port, or restrict the processing of their personal information, and to opt out of processing covered by applicable law. Foundry handles those requests through a single intake at privacy@bioscopefoundry.com.

  1. Intake. Requests are logged with date, requester, scope, and applicable jurisdiction.
  2. Identity verification. Foundry verifies identity proportionate to the sensitivity of the request before disclosing or modifying information.
  3. Triage. Requests that concern patient health information are redirected to the relevant physician practice (the covered entity) and the requester is informed of the routing.
  4. Response. Foundry responds within the statutory window for the applicable jurisdiction (for example, 45 days under most U.S. state privacy laws, extendable once where the law permits).
  5. Refusal & appeal. If a request is refused, Foundry states the basis in writing and offers an internal appeal path; some jurisdictions also provide a regulator escalation path, which Foundry references in the response.

3.7 Sharing and sale of personal information

Foundry does not sell personal information and does not share personal information for cross-context behavioral advertising. Personal information is shared only:

  • With service providers acting on Foundry’s behalf under contract, including BAAs where the provider may handle PHI;
  • With parties at the individual’s direction (for example, vendors engaged to stand up a practice);
  • To comply with law, subpoena, or legal process; to enforce agreements; or to protect the rights, safety, and property of Foundry, its members, or others;
  • In connection with a merger, acquisition, financing, or asset sale, where Foundry will seek assurances that the recipient honors this policy.

4. Roles & responsibilities

  • Privacy Officer: owns this policy, the public-facing privacy notice, and the rights-request intake; coordinates with the Security Officer on PHI-adjacent matters.
  • Security Officer: owns the safeguards that this policy relies on (see Data Protection).
  • Legal: owns the Terms of Service, BAA template, MSA, and the interface to regulators when an escalation is needed.
  • Engineering leads: implement consent capture, preference management, and right-to-delete workflows in the systems they own; preserve PHI boundary controls.
  • Workforce members: collect only what is needed, route rights requests to the Privacy Officer, and never write PHI to local files, prompts, or generated documents.

5. Review & revision

This policy is reviewed at least annually and whenever a material change in business activity, vendors, AI tooling, or applicable law warrants it. Material revisions are approved by the Privacy Officer in coordination with Legal and the Security Officer, and processed through Policy Management.

6. Related policies