Roles, Responsibilities & Training
1. Purpose & scope
This policy assigns accountability for Foundry’s security and privacy programs and establishes the training that every workforce member completes. Most cybersecurity incidents begin with the compromise of an end-user computing device, social engineering, human error, or insider misuse. The workforce is therefore both the first line of defense and the most common point of failure, and training is essential.
In this and all related policies the term workforce member includes full-time and part-time employees in all job roles, founders, temporary staff, contractors, subcontractors, volunteers, interns, advisors, managers, and executives at Bioscope Foundry. Where HIPAA uses the term “workforce” we use the same meaning here.
2. Policy statements
Foundry policy requires that:
(a) A Security Officer and a Privacy Officer (45 CFR § 164.308(a)(2) and § 164.530(a)(1)) are appointed to lead the maintenance and enforcement of safeguards for the confidentiality, integrity, and availability of PHI. The Security Officer’s responsibilities focus on the HIPAA Security Rule; the Privacy Officer’s focus on the HIPAA Privacy Rule and the Breach Notification Rule.
(b) Security and compliance are the responsibility of every workforce member. Every workforce member is required to:
- Complete Foundry’s security and HIPAA awareness training at onboarding and annually thereafter;
- Follow all security requirements set out in Foundry’s policies and procedures, including access control, acceptable use, the PHI boundary, and the AI-tool use rules;
- See something, say something: follow the incident reporting procedure to report all suspicious activities to the Security Officer.
(c) Workforce members are required to report non-compliance with Foundry policies to the Security Officer or designee. Individuals who report concerns in good faith are protected against intimidation, threats, coercion, discrimination, or any other retaliatory action.
(d) Workforce members are required to cooperate with federal, state, and local law-enforcement activities and legal investigations. Interfering with such an investigation through willful misrepresentation, omission, or threats is strictly prohibited.
(e) Workforce members who violate Foundry policies are subject to sanctions in proportion to the severity of the violation, up to and including termination, as detailed in the HR & Personnel Security policy.
(f) Segregation of duties is maintained where applicable to ensure proper checks and balances, minimize conflict of interest, reduce the opportunity for fraud and insider misuse, and eliminate single points of compromise in critical systems.
(g) Workforce safeguards apply not only to Foundry-employed individuals but also to any contractor or third party acting on Foundry’s behalf with access to Foundry systems or PHI. Contractor agreements include the same confidentiality and security obligations.
3. Security & Privacy Officers
3.1 Appointment
The Security Officer and the Privacy Officer are appointed by, and report to, the Foundry CEO and, where established, the Board of Directors. The two roles may be held by one individual; whenever a single individual holds both, that fact is recorded and the dual-control safeguards in §6 are reinforced.
Foundry has formally designated a Security Officer and a Privacy Officer; current assignments are recorded in internal governance records.
3.2 Security Officer responsibilities
The Security Officer is accountable for the Foundry information security program. The Security Officer or designee:
- Builds and maintains the security program to satisfy regulatory and contractual requirements (HIPAA and the frameworks tracked in the framework crosswalk);
- Establishes, documents, distributes, and updates security policies, standards, and procedures;
- Oversees, enforces, and documents the activities necessary to maintain compliance, including verifying that those activities are in alignment with the program;
- Monitors, analyzes, distributes, and escalates security alerts and information from internal and external sources;
- Develops and maintains the security incident response and escalation procedures;
- Administers user accounts, additions, deletions, and modifications, in coordination with HR and engineering;
- Monitors and controls access to critical systems and data, including PHI and ePHI;
- Performs risk assessment, remediation, and ongoing risk management (see Risk Management);
- Delivers the annual security and HIPAA awareness training, plus reminder communications;
- Maintains a program that incentivizes the right behaviors, supports timely and proper reporting and investigation of violations, implements effective mitigation, and applies fair sanctions when necessary;
- Assists in the administration and oversight of Business Associate Agreements (BAAs) with member practices and with subprocessors;
- Facilitates audits and external assessments to validate compliance efforts;
- Works with the finance lead to ensure that security objectives receive appropriate consideration in the budgeting process.
3.3 Privacy Officer responsibilities
The Privacy Officer is accountable for the Foundry privacy program and for Foundry’s obligations under the HIPAA Privacy Rule and Breach Notification Rule as a business associate. The Privacy Officer or designee:
- Maintains Foundry’s HIPAA business-associate posture, including the standard BAA and any practice-specific addenda;
- Reviews uses and disclosures of PHI by Foundry and its subprocessors against the BAA and the minimum-necessary standard;
- Coordinates support to member practices when patients exercise individual rights under HIPAA: access, amendment, accounting of disclosures, restriction requests, confidential communications;
- Owns the breach risk assessment and the notification timeline to affected practices in the event of a breach of unsecured PHI (see Breach Notification);
- Owns the privacy content in Foundry’s annual workforce training;
- Maintains the subprocessor list and the BAAs that bind PHI-handling subprocessors;
- Acts as the contact for member practices on privacy questions and for regulators on Foundry’s privacy practices.
4. Security Committee
The Security Committee is chaired by the Security Officer and includes the Privacy Officer plus designated representatives from engineering, operations, and administration. Committee membership is:
- Security Officer: chair;
- Privacy Officer;
- The Engineering Lead;
- The Operations Lead.
The committee meets at least quarterly and is responsible for reviewing the security scorecard, the risk register, open exceptions, significant incidents, and the schedule of policy reviews. The committee is the standing forum for cross-functional decisions affecting the security program. Decisions are recorded in the meeting notes in internal governance records.
5. Workforce supervision
The Security Officer oversees the security program but does not personally supervise every workforce member’s daily activity. Supervision of users of Foundry’s systems, applications, servers, workstations, and data is a shared responsibility:
- Team leads and supervisors monitor their teams’ use of Foundry systems for unauthorized use, tampering, and theft, and report non-compliance to the Security Officer in line with the Incident Response policy.
- Team leads assist the Security and Privacy Officers in ensuring that role-based access is appropriate for each individual on their team.
- Team leads take all reasonable steps to hire, retain, and promote workforce members who comply with the Security Rule and Foundry’s policies, and to grant access only to users who do so.
- Co-workers are expected to report observed non-compliance through the same channels.
6. Segregation of duties
Foundry assigns the security and compliance job function to dedicated personnel. Segregation of duties is achieved through a combination of role assignment and automated enforcement of software-defined processes, including:
- Production deployments require pull-request review by an engineer other than the author;
- Changes to PHI-handling systems require concurrence from the Security Officer in addition to engineering approval;
- Financial transactions over an established threshold require dual approval;
- Access reviews are performed by someone other than the access grantor;
- Audit-log integrity controls are owned by a role other than the one administering the systems whose logs they collect.
Where the team is too small to fully separate two functions, the Security Officer documents the gap in the risk register and applies compensating controls (for example, additional automated alerting or external review).
7. Training program
Foundry operates one required workforce training program: security and HIPAA privacy awareness training, delivered at onboarding and refreshed annually. The Security and Privacy Officers own its content; People Operations tracks completion.
7.1 Cadence
- New workforce members complete the training within their first 30 days of employment or engagement.
- Every workforce member completes an annual refresh thereafter.
- The Security Officer may require an out-of-cycle refresh in response to a material policy change, a notable incident, or another change in Foundry’s risk posture.
Training materials, attendance, and completion records are retained for a minimum of seven years.
7.2 Subjects covered
The training covers, but is not limited to, the following subjects drawn from Foundry’s security and privacy policies:
- HIPAA Privacy, Security, and Breach Notification Rules as they apply to Foundry as a business associate;
- Risk management procedures and how workforce members contribute to them;
- Auditing: Foundry may monitor access and activities of all users of its systems;
- Acceptable use: workstations and Foundry accounts are used only to perform assigned job responsibilities;
- Reporting obligations: malicious software, unauthorized attempts, uses, or theft of Foundry systems or workstations, unauthorized access to facilities, suspicious log-in events, and suspected security incidents are reported to the Security Officer immediately;
- The PHI boundary: PHI lives only in Foundry’s FHIR service. Workforce members must never copy, export, or paste PHI into local files, logs, prompts, third-party AI tools, or generated documents;
- Use of AI tools: the AI-tool guardrails in the AI Governance policy, including the prohibition on entering PHI into third-party AI tools;
- The contingency plan: what to do during a service degradation or disaster;
- Credential hygiene: passwordless authentication, phishing-resistant MFA, no credential sharing under any circumstance;
- Automatic session timeout on applications that access PHI;
- Supervisor responsibilities: reporting terminations and role changes promptly so that access can be adjusted;
- Backup, hardware-disposal, and media-handling procedures for any device that has been provisioned to access Foundry systems;
- Secrets management: keys, tokens, and credentials are stored only in the approved secret broker, never in source code, chat, or local files.
8. Completion tracking
Completion is tracked per workforce member and required topic. The record is held in the HRIS. The HIPAA portion is required within 30 days of onboarding and annually thereafter; PHI-access group membership is not granted until it is complete (see HR & Personnel Security).
Training content is written against Foundry’s actual use cases and current risks rather than generic material: real-world social-engineering scenarios plus practical guidance on recognizing and responding to phishing, vishing, and prompt-injection attempts.
Role-based supplemental curricula are planned and not yet deployed. The planned tracks are secure development for engineering, HIPAA Privacy Rule application for clinical and practice-operations roles, identity and audit-log operations for IT and Security, and agent-boundary handling for workforce members operating agent tooling.
9. Internal communications
9.1 Company-wide updates
Foundry holds a company-wide roundtable on a regular cadence (at least quarterly) to communicate updates across business operations, performance, and objectives. Senior management sends additional company-wide announcements through pre-established internal channels, primarily email and Foundry’s Slack workspace.
9.2 Team-level updates
Regular performance and status updates are communicated by each department, functional team, or designated individual through pre-established channels. Engineering project teams maintain their own committed cadence and channel, for example, daily standups or weekly team meetings.
9.3 Security-specific communications
Security-relevant updates (policy changes, incidents, awareness reminders, and the quarterly scorecard summary) are communicated by the Security Officer through a dedicated security channel and, for material items, by email to all workforce members.
10. Review & revision
This policy is reviewed at least annually and whenever a change in organizational structure, workforce composition, regulatory environment, or risk posture makes a section stale. Material revisions are approved by the Security Officer with concurrence from the Privacy Officer, in coordination with the Policy Management process.