Roles, Responsibilities & Training
Policy · v2026.06 · Owner: Security Officer · Effective: 2026-06-30 · Reviewed: 2026-06-30 · Next review: 2027-06-30
1. Purpose & scope
This policy assigns accountability for Foundry’s security and privacy programs and establishes the training that every workforce member completes. Most cybersecurity incidents begin with the compromise of an end-user computing device, social engineering, human error, or insider misuse. The workforce is therefore both the first line of defense and the most common point of failure, and training is essential.
In this and all related policies the term workforce member includes full-time and part-time employees in all job roles, founders, temporary staff, contractors, subcontractors, volunteers, interns, advisors, managers, and executives at Bioscope Foundry. Where HIPAA uses the term “workforce” we use the same meaning here.
2. Policy statements
Foundry policy requires that:
(a) A Security Officer and a Privacy Officer (45 CFR § 164.308(a)(2) and § 164.530(a)(1)) are appointed to lead the maintenance and enforcement of safeguards for the confidentiality, integrity, and availability of PHI. The Security Officer’s responsibilities focus on the HIPAA Security Rule; the Privacy Officer’s focus on the HIPAA Privacy Rule and the Breach Notification Rule.
(b) Security and compliance are the responsibility of every workforce member. Every workforce member is required to:
- Complete all required security trainings, including HIPAA awareness on hire and annually thereafter, and any additional training required by job role;
- Follow all security requirements set out in Foundry’s policies and procedures, including access control, acceptable use, the PHI boundary, and the AI-tool use rules;
- See something, say something: follow the incident reporting procedure to report all suspicious activities to the Security Officer.
(c) Workforce members are required to report non-compliance with Foundry policies to the Security Officer or designee. Individuals who report concerns in good faith are protected against intimidation, threats, coercion, discrimination, or any other retaliatory action.
(d) Workforce members are required to cooperate with federal, state, and local law-enforcement activities and legal investigations. Interfering with such an investigation through willful misrepresentation, omission, or threats is strictly prohibited.
(e) Workforce members who violate Foundry policies are subject to sanctions in proportion to the severity of the violation, up to and including termination, as detailed in the HR & Personnel Security policy.
(f) Segregation of duties is maintained where applicable to ensure proper checks and balances, minimize conflict of interest, reduce the opportunity for fraud and insider misuse, and eliminate single points of compromise in critical systems.
(g) Workforce safeguards apply not only to Foundry-employed individuals but also to any contractor or third party acting on Foundry’s behalf with access to Foundry systems or PHI. Contractor agreements include the same confidentiality and security obligations.
3. Security & Privacy Officers
3.1 Appointment
The Security Officer and the Privacy Officer are appointed by, and report to, the Foundry CEO and, where established, the Board of Directors. At these two roles may be held by one individual; whenever a single individual holds both roles, that fact is recorded and the dual-control safeguards in §6 are reinforced.
Foundry has formally designated a Security Officer and a Privacy Officer; current assignments are recorded in internal governance records.
3.2 Security Officer responsibilities
The Security Officer is accountable for the Foundry information security program. The Security Officer or designee:
- Builds and maintains the security program to satisfy regulatory and contractual requirements (HIPAA and the frameworks tracked in the framework crosswalk);
- Establishes, documents, distributes, and updates security policies, standards, and procedures;
- Oversees, enforces, and documents the activities necessary to maintain compliance, including verifying that those activities are in alignment with the program;
- Monitors, analyzes, distributes, and escalates security alerts and information from internal and external sources;
- Develops and maintains the security incident response and escalation procedures;
- Administers user accounts, additions, deletions, and modifications, in coordination with HR and engineering;
- Monitors and controls access to critical systems and data, including PHI and ePHI;
- Performs risk assessment, remediation, and ongoing risk management (see Risk Management);
- Delivers regular security awareness and compliance training, plus periodic updates and reminder communications;
- Maintains a program that incentivizes the right behaviors, supports timely and proper reporting and investigation of violations, implements effective mitigation, and applies fair sanctions when necessary;
- Assists in the administration and oversight of Business Associate Agreements (BAAs) with member practices and with subprocessors;
- Facilitates audits and external assessments to validate compliance efforts;
- Works with the finance lead to ensure that security objectives receive appropriate consideration in the budgeting process.
3.3 Privacy Officer responsibilities
The Privacy Officer is accountable for the Foundry privacy program and for Foundry’s obligations under the HIPAA Privacy Rule and Breach Notification Rule as a business associate. The Privacy Officer or designee:
- Maintains Foundry’s HIPAA business-associate posture, including the standard BAA and any practice-specific addenda;
- Reviews uses and disclosures of PHI by Foundry and its subprocessors against the BAA and the minimum-necessary standard;
- Coordinates support to member practices when patients exercise individual rights under HIPAA: access, amendment, accounting of disclosures, restriction requests, confidential communications;
- Owns the breach risk assessment and the notification timeline to affected practices in the event of a breach of unsecured PHI (see Breach Notification);
- Leads privacy training content for the workforce and for role-based curricula;
- Maintains the subprocessor list and the BAAs that bind PHI-handling subprocessors;
- Acts as the contact for member practices on privacy questions and for regulators on Foundry’s privacy practices.
4. Security Committee
The Security Committee is chaired by the Security Officer and includes the Privacy Officer plus designated representatives from engineering, operations, and administration. At the committee membership is:
- Security Officer: chair;
- Privacy Officer;
- The Engineering Lead;
- The Operations Lead.
The committee meets at least quarterly and is responsible for reviewing the security scorecard, the risk register, open exceptions, significant incidents, and the schedule of policy reviews. The committee is the standing forum for cross-functional decisions affecting the security program. Decisions are recorded in the meeting notes in internal governance records.
5. Workforce supervision
The Security Officer oversees the security program but does not personally supervise every workforce member’s daily activity. Supervision of users of Foundry’s systems, applications, servers, workstations, and data is a shared responsibility:
- Team leads and supervisors monitor their teams’ use of Foundry systems for unauthorized use, tampering, and theft, and report non-compliance to the Security Officer in line with the Incident Response policy.
- Team leads assist the Security and Privacy Officers in ensuring that role-based access is appropriate for each individual on their team.
- Team leads take all reasonable steps to hire, retain, and promote workforce members who comply with the Security Rule and Foundry’s policies, and to grant access only to users who do so.
- Co-workers are expected to report observed non-compliance through the same channels.
6. Segregation of duties
Foundry assigns the security and compliance job function to dedicated personnel. Segregation of duties is achieved through a combination of role assignment and automated enforcement of software-defined processes, including:
- Production deployments require pull-request review by an engineer other than the author;
- Changes to PHI-handling systems require concurrence from the Security Officer in addition to engineering approval;
- Financial transactions over an established threshold require dual approval;
- Access reviews are performed by someone other than the access grantor;
- Audit-log integrity controls are owned by a role other than the one administering the systems whose logs they collect.
Where the team is too small to fully separate two functions, the Security Officer documents the gap in the risk register and applies compensating controls (for example, additional automated alerting or external review).
7. Training program
7.1 Cadence
The Security and Privacy Officers, with HR support, facilitate the training of all workforce members:
- New workforce members complete onboarding training within their first 30 days of employment or engagement.
- Existing workforce members complete annual refresher training.
- Workforce members whose functions are affected by a material change in policies or procedures complete supplemental training within one month after the change takes effect.
- The Security Officer may require additional training in response to changes in Foundry’s security and risk posture (for example, after a notable incident or after the introduction of a new agent tier or new subprocessor).
Training session materials, attendance, and completion records are retained for a minimum of seven years.
7.2 Subjects covered
Training covers, but is not limited to, the following subjects defined in Foundry’s security and privacy policies:
- HIPAA Privacy, Security, and Breach Notification Rules as they apply to Foundry as a business associate;
- Risk management procedures and how workforce members contribute to them;
- Auditing: Foundry may monitor access and activities of all users of its systems;
- Acceptable use: workstations and Foundry accounts are used only to perform assigned job responsibilities;
- Reporting obligations: malicious software, unauthorized attempts, uses, or theft of Foundry systems or workstations, unauthorized access to facilities, suspicious log-in events, and suspected security incidents are reported to the Security Officer immediately;
- The PHI boundary: PHI lives only in Foundry’s FHIR service. Workforce members must never copy, export, or paste PHI into local files, logs, prompts, third-party AI tools, or generated documents;
- Use of AI tools: the AI-tool guardrails in the AI Governance policy, including the prohibition on entering PHI into third-party AI tools;
- The contingency plan: what to do during a service degradation or disaster;
- Credential hygiene: passwordless authentication, phishing-resistant MFA, no credential sharing under any circumstance;
- Automatic session timeout on applications that access PHI;
- Supervisor responsibilities: reporting terminations and role changes promptly so that access can be adjusted;
- Backup, hardware-disposal, and media-handling procedures for any device that has been provisioned to access Foundry systems;
- Secrets management: keys, tokens, and credentials are stored only in the approved secret broker, never in source code, chat, or local files.
8. Ongoing awareness
Foundry delivers periodic security-awareness content to all workforce members throughout the year, not only at the annual refresh. Awareness content is tailored to actual Foundry use cases and current security risks, for example, real-world social-engineering scenarios, threat-intelligence updates relevant to healthcare, and practical guidance on identifying and responding to phishing, prompt-injection, vishing, and similar threats. Progress is tracked by workforce member and required topic.
HIPAA-specific awareness training is required within 30 days of onboarding and annually thereafter. The training record is captured in HR and/or in the learning management system.
Role-based supplemental training is required for:
| Role | Additional training |
|---|---|
| Engineering & data | Secure SDLC, Foundry’s secure-development standards, threat modeling, secure use of LLM APIs and Foundry’s FHIR service, key management. |
| Clinical / practice ops | HIPAA Privacy Rule applied to BA workflows, minimum necessary, communication discipline (no PHI in SMS or email body), patient-rights routing back to the practice. |
| Operations & IT | Identity administration, MDM operations, audit-log review, incident-response runbooks, BCDR drills. |
| Workforce members operating agent tooling | Agent operating-model boundaries (Atlas, Forge Agents, Moltworkers, Beacon Layer), prompt-injection awareness, AI-tool use limits. |
| All workforce members | HIPAA awareness, acceptable use, AI-tool guardrails, incident reporting. |
9. Internal communications
9.1 Company-wide updates
Foundry holds a company-wide roundtable on a regular cadence (at least quarterly) to communicate updates across business operations, performance, and objectives. Senior management sends additional company-wide announcements through pre-established internal channels, primarily email and the Foundry Slack workspace (#general and topic-specific channels).
9.2 Team-level updates
Regular performance and status updates are communicated by each department, functional team, or designated individual through pre-established channels. Engineering project teams maintain their own committed cadence and channel, for example, daily standups or weekly team meetings.
9.3 Security-specific communications
Security-relevant updates, policy changes, incidents, awareness reminders, and the quarterly scorecard summary, are communicated by the Security Officer through a dedicated security channel and, for material items, by email to all workforce members.
10. Review & revision
This policy is reviewed at least annually and whenever a change in organizational structure, workforce composition, regulatory environment, or risk posture makes a section stale. Material revisions are approved by the Security Officer with concurrence from the Privacy Officer, in coordination with the Policy Management process.