Framework crosswalk: HIPAA · CCPA/CPRA · ISO/IEC 27001:2022 · SOC 2
Frameworks · Crosswalk · v2026.06 · One consolidated reference. Foundry policies on the left, control requirements from each framework on the right. Use this to find the policy that satisfies a control, or to see which controls a policy supports.
How to use this page
- If you have a control to satisfy (e.g., “ISO 27001 A.5.15 Access control”), jump to the framework deep-dive section and follow the link to the Foundry policy.
- If you have a Foundry policy and want to see what it supports, the master matrix shows every policy on one row with the controls it touches.
Implemented Control documented and operational N/A Not applicable to Foundry’s role / scope
Master matrix: Foundry policies × frameworks
For each Foundry policy, the matrix names the specific control sections from each framework that the policy supports. Cells with a single citation refer to the most directly relevant section; cells may cite multiple where the policy spans the framework’s organization.
| Foundry policy | HIPAA | CCPA / CPRA | ISO/IEC 27001:2022 | SOC 2 (TSC) |
|---|---|---|---|---|
| Program overview | §164.308(a)(1) Security management process | §1798.100(b) Notice at collection | Clauses 4–10; A.5.1 Information security policies | CC1.1 Control environment; CC2.1 Information & communication |
| Policy management | §164.316(a)(b) Policies, procedures, documentation | §1798.135(c) Public-facing notices upkeep | A.5.1, A.5.36 Policy compliance | CC1.4; CC5.3 Policy & procedure deployment |
| Roles, responsibilities & training | §164.308(a)(2)–(a)(5) Security responsibility & awareness | §1798.130(a) Workforce training | A.5.2, A.6.3 Training | CC1.4 Competence; CC2.2 Communication |
| Risk management | §164.308(a)(1)(ii)(A) Risk analysis; (B) Risk management | §1798.185(a)(15) Risk assessment (regs) | Clauses 6.1, 8.2, 8.3; A.5.4 | CC3.1–CC3.4 Risk assessment |
| Security architecture | §164.306(a) General requirements | §1798.150(a) Reasonable security | A.8.1, A.8.9, A.8.20–A.8.25 | CC5.1; CC6 series; CC7 series |
| AI governance | §164.502(b) Minimum necessary | §1798.185(a)(16) ADMT (proposed) | A.5.31 Legal & statutory; A.8.27 Secure dev | PI1.1 Processing integrity; PI1.4 Output accuracy |
| Access control | §164.308(a)(3)(4); §164.312(a)(1)(d) Authentication | §1798.100(d) Reasonable security; §1798.150(a) | A.5.15–A.5.18; A.8.2–A.8.5 Privileged & secure auth | CC6.1, CC6.2, CC6.3 Logical access |
| HR & personnel security | §164.308(a)(3) Workforce security; (a)(5) Awareness | §1798.130(a)(5) Personnel | A.6.1–A.6.6 People controls | CC1.4, CC1.5 Workforce |
| Asset management | §164.310(d)(1)(2) Device & media controls | §1798.100(a)(3) Retention | A.5.9–A.5.14 Asset management | CC6.7 Asset disposal; CC6.5 Removal |
| Endpoint & MDM | §164.310(c) Workstation security; (b) Workstation use | §1798.100(d) Reasonable security | A.7.8 Equipment; A.8.1 User endpoints | CC6.7, CC6.8 Asset / endpoint |
| Facility & physical security | §164.310(a) Facility access controls | §1798.100(d) Reasonable security | A.7.1–A.7.14 Physical controls | CC6.4, CC6.5 Physical access |
| Data management | §164.308(a)(7)(ii)(E) Data backup; §164.514 De-identification | §1798.100(a)(3) Retention; §1798.105 Right to delete; §1798.106 Right to correct | A.5.12 Classification; A.5.34 Privacy & PII | C1.1 Confidential information identification; P3.1 Collection consistency |
| Data protection (encryption) | §164.312(a)(2)(iv) Encryption; (e)(2)(ii) Transmission | §1798.150(a)(1) “Encrypted or redacted” safe harbor | A.8.24 Cryptography; A.5.33 Records protection | CC6.1 Logical & physical access; CC6.6 Boundary protection |
| Privacy | §164.502–§164.514 Privacy Rule support | §§1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121 (SPI), 1798.125, 1798.130, 1798.135 | A.5.34 PII privacy | P series (all) |
| Secure SDLC | §164.308(a)(8) Evaluation | §1798.100(d) Reasonable security | A.8.25–A.8.31 Secure development | CC8.1 Change mgmt; CC7.1 Detection; PI1.1 Processing |
| Vulnerability management | §164.308(a)(1)(ii)(B) Risk management; (a)(8) Evaluation | §1798.100(d) Reasonable security | A.8.8 Technical vulnerabilities | CC7.1 System monitoring; CC4.1 Monitoring activities |
| Threat management | §164.308(a)(6) Security incident procedures | §1798.100(d) Reasonable security | A.5.7 Threat intelligence; A.8.16 Monitoring activities | CC7.2 Anomalies; CC7.3 Communicate detected events |
| Configuration & change management | §164.312(b) Audit controls; §164.312(c) Integrity | §1798.100(d) Reasonable security | A.8.9, A.8.32 Configuration & change | CC8.1 Change management; CC6.8 Configuration |
| Incident response | §164.308(a)(6) Security incident procedures | §1798.150 Civil action for breach | A.5.24–A.5.28 Incident management | CC7.3, CC7.4, CC7.5 Incident lifecycle |
| Breach investigation & notification | §164.410, §164.402, §164.404, §164.406, §164.408 Breach notification | §1798.82 (Cal. Civ. Code) Security-breach notification | A.5.24 Planning; A.5.27 Learn from incidents | CC2.3 External communication; CC7.4 Incident response |
| BC / DR | §164.308(a)(7) Contingency plan; §164.310(a)(2)(i) | §1798.100(d) Reasonable security | A.5.29, A.5.30, A.8.13, A.8.14 Continuity | A1.1, A1.2, A1.3 Availability |
| System audits & monitoring | §164.308(a)(1)(ii)(D) Information system activity review; §164.312(b) Audit controls | §1798.100(e) Records of compliance | A.8.15, A.8.16, A.8.17 Logging & monitoring | CC4.1, CC4.2 Monitoring; CC7.2 Anomalies |
| Compliance, audits & external comms | §164.314 Organizational requirements (BAA) | §1798.135(b)(4) Compliance evidence | A.5.31, A.5.35, A.5.36 Compliance | CC2.3 External communication |
| Vendor & third-party risk | §164.308(b), §164.314(a) BA contracts & subcontractors | §1798.140(j)(k) Service provider / contractor; §1798.100(d)(4) | A.5.19–A.5.23 Supplier relationships | CC9.2 Vendor & business partner management |
HIPAA deep-dive: Security Rule, Privacy Rule, Breach Notification
HIPAA is the binding framework today. The mapping below covers required (R) and addressable (A) specifications of the Security Rule. Privacy Rule and Breach Notification rows describe Foundry’s posture as a business associate; primary covered-entity obligations remain with the practice.
Security Rule §164.308: Administrative safeguards
| Standard | Required / Addressable | Foundry policy | Status |
|---|---|---|---|
| §164.308(a)(1)(i) Security management process | R | Program overview, Risk mgmt | Implemented |
| §164.308(a)(1)(ii)(A) Risk analysis | R | Risk mgmt | Implemented |
| §164.308(a)(1)(ii)(B) Risk management | R | Risk mgmt, Vuln mgmt | Implemented |
| §164.308(a)(1)(ii)(C) Sanction policy | R | HR & personnel | Implemented |
| §164.308(a)(1)(ii)(D) Information system activity review | R | System audits | Implemented |
| §164.308(a)(2) Assigned security responsibility | R | Roles | Implemented |
| §164.308(a)(3)(i) Workforce security | R | HR, Access | Implemented |
| §164.308(a)(3)(ii)(A) Authorization & supervision | A | Access | Implemented |
| §164.308(a)(3)(ii)(B) Workforce clearance | A | HR | Implemented |
| §164.308(a)(3)(ii)(C) Termination procedures | A | HR, Access | Implemented |
| §164.308(a)(4) Information access management | R | Access | Implemented |
| §164.308(a)(5) Security awareness & training | R | Training | Implemented |
| §164.308(a)(6) Security incident procedures | R | IR, Breach | Implemented |
| §164.308(a)(7) Contingency plan | R | BCDR | Implemented |
| §164.308(a)(8) Evaluation | R | Compliance & audits | Implemented |
| §164.308(b) Business associate contracts & other arrangements | R | Vendor, BAA | Implemented |
Security Rule §164.310: Physical safeguards
| Standard | R/A | Foundry policy | Status |
|---|---|---|---|
| §164.310(a)(1) Facility access controls | R | Facility | Implemented |
| §164.310(a)(2)(i) Contingency operations | A | BCDR | Implemented |
| §164.310(a)(2)(ii) Facility security plan | A | Facility | Implemented |
| §164.310(a)(2)(iii) Access control & validation | A | Facility | Implemented |
| §164.310(a)(2)(iv) Maintenance records | A | Facility | Implemented |
| §164.310(b) Workstation use | R | Endpoint | Implemented |
| §164.310(c) Workstation security | R | Endpoint | Implemented |
| §164.310(d)(1) Device & media controls | R | Assets | Implemented |
| §164.310(d)(2)(i) Disposal | R | Assets, Data mgmt | Implemented |
| §164.310(d)(2)(ii) Media re-use | R | Assets | Implemented |
| §164.310(d)(2)(iii) Accountability | A | Assets | Implemented |
| §164.310(d)(2)(iv) Data backup & storage | A | BCDR | Implemented |
Security Rule §164.312: Technical safeguards
| Standard | R/A | Foundry policy | Status |
|---|---|---|---|
| §164.312(a)(1) Access control | R | Access | Implemented |
| §164.312(a)(2)(i) Unique user identification | R | Access | Implemented |
| §164.312(a)(2)(ii) Emergency access | R | Access, BCDR | Implemented |
| §164.312(a)(2)(iii) Automatic logoff | A | Access, Endpoint | Implemented |
| §164.312(a)(2)(iv) Encryption & decryption | A | Data protection | Implemented |
| §164.312(b) Audit controls | R | Audits | Implemented |
| §164.312(c)(1) Integrity | R | Data protection, CCM | Implemented |
| §164.312(c)(2) Mechanism to authenticate ePHI | A | Data protection | Implemented |
| §164.312(d) Person or entity authentication | R | Access | Implemented |
| §164.312(e)(1) Transmission security | R | Data protection | Implemented |
| §164.312(e)(2)(i) Integrity controls in transit | A | Data protection | Implemented |
| §164.312(e)(2)(ii) Encryption in transit | A | Data protection | Implemented |
Privacy Rule & Breach Notification Rule highlights (as a BA)
| Provision | Foundry obligation as BA | Policy |
|---|---|---|
| §164.502(b) Minimum necessary | Restrict workforce and agent access to the minimum PHI necessary for the task. | Access, AI gov |
| §164.504(e) BA contracts | Execute BAA with covered entity before PHI flow; subcontractor BAAs flow down “at least as protective.” | BAA, Vendor |
| §164.524 Access by individuals | Support practice in responding to access requests; practice serves as point of contact. | Privacy |
| §164.526 Amendment | Support practice in processing amendment requests. | Privacy |
| §164.528 Accounting of disclosures | Maintain disclosure records to support practice’s accounting. | Audits |
| §164.410 BA notification to CE | Notify affected practice of any breach of unsecured PHI without unreasonable delay; default contractual window in BAA. | Breach, BAA |
| §164.402 “Breach” definition & safe harbor | Apply encryption / destruction safe-harbor analysis; document risk assessment for any acquisition / disclosure not falling within an exception. | Breach |
CCPA / CPRA deep-dive
The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA) applies to Foundry’s collection of California residents’ personal information, for example, physicians and prospective member-practice staff who interact with our marketing site or onboarding. Medical information governed by HIPAA is excluded by § 1798.146(a)(1)(A) and the CMIA carve-out: Foundry handles that data as PHI under the BAA, not as PI under CCPA.
| CCPA / CPRA requirement | Source | Foundry policy or document | Status |
|---|---|---|---|
| Notice at collection | §1798.100(a), (b); §1798.135 | Privacy Policy | Implemented |
| Right to know: categories collected, sources, purposes, recipients | §1798.100(a); §1798.110; §1798.115 | Privacy Policy | Implemented |
| Right to delete | §1798.105 | Privacy Policy, Data mgmt | Implemented |
| Right to correct | §1798.106 | Privacy Policy | Implemented |
| Right to portability | §1798.100(d)(3); §1798.130(a)(2) | Privacy Policy | Implemented |
| Right to opt out of sale or sharing | §1798.120; §1798.135 | Privacy Policy | Implemented (we do not sell or share) |
| Right to limit use of Sensitive Personal Information | §1798.121 | Privacy Policy | Implemented |
| Non-discrimination for exercising rights | §1798.125 | Privacy Policy | Implemented |
| Retention disclosure (per category) | §1798.100(a)(3) | Privacy Policy, Data mgmt | Implemented |
| Authorized agent process | §1798.140(b); regs §7063 | Privacy Policy | Implemented |
| Service-provider / contractor contracting | §1798.140(j), (k); §1798.100(d) | Vendor, Subprocessors | Implemented |
| Global Privacy Control (GPC) honoring | regs §7025 | Cookie Policy, Privacy Policy | Implemented |
| Automated Decision-Making Technology (ADMT) disclosures | §1798.185(a)(16) (regs in development) | Privacy Policy, AI gov | Implemented |
| Reasonable security | §1798.100(d); §1798.150(a) | Security architecture, Data protection | Implemented |
| Breach notification (Cal. Civ. Code §1798.82) | Cal. Civ. Code §1798.82 | Breach | Implemented |
ISO/IEC 27001:2022 deep-dive (Annex A)
The mapping below shows how Foundry’s policies address each Annex A theme. Per-control status is summarized by group.
| Annex A theme | Control range | Primary Foundry policies | Status |
|---|---|---|---|
| A.5 Organizational controls | A.5.1–A.5.37 (37 controls) | Overview, Policy mgmt, Risk, Vendor, Access, IR, Breach, Compliance, AI gov, Privacy | Implemented |
| A.6 People controls | A.6.1–A.6.8 (8 controls) | HR & personnel, Training | Implemented |
| A.7 Physical controls | A.7.1–A.7.14 (14 controls) | Facility, Assets, Endpoint | Implemented: remote-first model; data-center physical controls inherited from cloud subprocessors |
| A.8 Technological controls | A.8.1–A.8.34 (34 controls) | Access, Data protection, SDLC, Vuln mgmt, Threat, CCM, Audits, BCDR | Implemented |
ISO 27001 main-body clauses (4–10)
| Clause | Topic | Foundry policy / artifact | Status |
|---|---|---|---|
| 4 | Context of the organization | Program overview | Implemented |
| 5 | Leadership | Roles | Implemented |
| 6 | Planning | Risk mgmt | Implemented |
| 7 | Support (competence, awareness, communication, documented info) | Training, Policy mgmt | Implemented |
| 8 | Operation (risk treatment, change) | Risk, CCM | Implemented |
| 9 | Performance evaluation (monitoring, audit, mgmt review) | Audits, Compliance | Implemented |
| 10 | Improvement | IR, Policy mgmt | Implemented |
SOC 2 deep-dive (Trust Services Criteria)
Foundry’s policies are structured as control narratives against the SOC 2 Trust Services Criteria. The mapping below shows the policy or document that supports each criterion.
| Trust Services Criteria | Required for? | Foundry policy / control source |
|---|---|---|
| CC1 Control environment | All reports | Overview, Roles, HR, Policy mgmt |
| CC2 Communication & information | All reports | Policy mgmt, Compliance & external comms |
| CC3 Risk assessment | All reports | Risk mgmt, Vendor risk |
| CC4 Monitoring activities | All reports | Audits, Threat |
| CC5 Control activities | All reports | Architecture, Access |
| CC6 Logical & physical access | Security | Access, Facility, Endpoint, Assets, Data protection |
| CC7 System operations | Security | Threat, Vuln, IR, Audits |
| CC8 Change management | Security | CCM, SDLC |
| CC9 Risk mitigation | Security | Risk mgmt, Vendor, BCDR |
| A1 Availability (A1.1–A1.3) | Availability | BCDR, Audits |
| C1 Confidentiality (C1.1–C1.2) | Confidentiality | Data mgmt, Data protection, Privacy |
| P1–P8 Privacy | Privacy | Privacy, Privacy Policy, AI gov |
| PI1 Processing integrity | Processing Integrity | SDLC, AI gov, CCM |
Aggregate status by framework
| Framework | Posture |
|---|---|
| HIPAA Security & Privacy Rules; Breach Notification | Implemented |
| CCPA / CPRA | Implemented |
| ISO/IEC 27001:2022 | Implemented (policy alignment) |
| ISO/IEC 42001:2023 | Implemented (policy alignment) |
| SOC 2 Trust Services Criteria | Implemented (control narrative) |
Maintenance
This crosswalk is the single source of truth for framework mapping. Individual policies reference HIPAA only and link here for other frameworks. Update this page when a policy is added, retired, or materially changed, and on any change to the framework posture (e.g., upon completing a SOC 2 Type I).