Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.
Framework crosswalk

Framework crosswalk: HIPAA · CCPA/CPRA · ISO/IEC 27001:2022 · SOC 2

Frameworks · Crosswalk · v2026.06 · One consolidated reference. Foundry policies on the left, control requirements from each framework on the right. Use this to find the policy that satisfies a control, or to see which controls a policy supports.

Foundry policies address HIPAA as the operative framework: Foundry is a HIPAA business associate to physician practices. This crosswalk shows how the same policies also address CCPA/CPRA obligations for California residents, align with the controls in ISO/IEC 27001:2022, and supply evidence for the SOC 2 Trust Services Criteria. CCPA applies to Foundry-collected personal information; PHI is excluded by the HIPAA carve-out (Cal. Civ. Code § 1798.146). This page is a mapping reference; it does not assert third-party certification.

How to use this page

  • If you have a control to satisfy (e.g., “ISO 27001 A.5.15 Access control”), jump to the framework deep-dive section and follow the link to the Foundry policy.
  • If you have a Foundry policy and want to see what it supports, the master matrix shows every policy on one row with the controls it touches.

Implemented Control documented and operational N/A Not applicable to Foundry’s role / scope

Master matrix: Foundry policies × frameworks

For each Foundry policy, the matrix names the specific control sections from each framework that the policy supports. Cells with a single citation refer to the most directly relevant section; cells may cite multiple where the policy spans the framework’s organization.

Foundry policyHIPAACCPA / CPRAISO/IEC 27001:2022SOC 2 (TSC)
Program overview§164.308(a)(1) Security management process§1798.100(b) Notice at collectionClauses 4–10; A.5.1 Information security policiesCC1.1 Control environment; CC2.1 Information & communication
Policy management§164.316(a)(b) Policies, procedures, documentation§1798.135(c) Public-facing notices upkeepA.5.1, A.5.36 Policy complianceCC1.4; CC5.3 Policy & procedure deployment
Roles, responsibilities & training§164.308(a)(2)–(a)(5) Security responsibility & awareness§1798.130(a) Workforce trainingA.5.2, A.6.3 TrainingCC1.4 Competence; CC2.2 Communication
Risk management§164.308(a)(1)(ii)(A) Risk analysis; (B) Risk management§1798.185(a)(15) Risk assessment (regs)Clauses 6.1, 8.2, 8.3; A.5.4CC3.1–CC3.4 Risk assessment
Security architecture§164.306(a) General requirements§1798.150(a) Reasonable securityA.8.1, A.8.9, A.8.20–A.8.25CC5.1; CC6 series; CC7 series
AI governance§164.502(b) Minimum necessary§1798.185(a)(16) ADMT (proposed)A.5.31 Legal & statutory; A.8.27 Secure devPI1.1 Processing integrity; PI1.4 Output accuracy
Access control§164.308(a)(3)(4); §164.312(a)(1)(d) Authentication§1798.100(d) Reasonable security; §1798.150(a)A.5.15–A.5.18; A.8.2–A.8.5 Privileged & secure authCC6.1, CC6.2, CC6.3 Logical access
HR & personnel security§164.308(a)(3) Workforce security; (a)(5) Awareness§1798.130(a)(5) PersonnelA.6.1–A.6.6 People controlsCC1.4, CC1.5 Workforce
Asset management§164.310(d)(1)(2) Device & media controls§1798.100(a)(3) RetentionA.5.9–A.5.14 Asset managementCC6.7 Asset disposal; CC6.5 Removal
Endpoint & MDM§164.310(c) Workstation security; (b) Workstation use§1798.100(d) Reasonable securityA.7.8 Equipment; A.8.1 User endpointsCC6.7, CC6.8 Asset / endpoint
Facility & physical security§164.310(a) Facility access controls§1798.100(d) Reasonable securityA.7.1–A.7.14 Physical controlsCC6.4, CC6.5 Physical access
Data management§164.308(a)(7)(ii)(E) Data backup; §164.514 De-identification§1798.100(a)(3) Retention; §1798.105 Right to delete; §1798.106 Right to correctA.5.12 Classification; A.5.34 Privacy & PIIC1.1 Confidential information identification; P3.1 Collection consistency
Data protection (encryption)§164.312(a)(2)(iv) Encryption; (e)(2)(ii) Transmission§1798.150(a)(1) “Encrypted or redacted” safe harborA.8.24 Cryptography; A.5.33 Records protectionCC6.1 Logical & physical access; CC6.6 Boundary protection
Privacy§164.502–§164.514 Privacy Rule support§§1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121 (SPI), 1798.125, 1798.130, 1798.135A.5.34 PII privacyP series (all)
Secure SDLC§164.308(a)(8) Evaluation§1798.100(d) Reasonable securityA.8.25–A.8.31 Secure developmentCC8.1 Change mgmt; CC7.1 Detection; PI1.1 Processing
Vulnerability management§164.308(a)(1)(ii)(B) Risk management; (a)(8) Evaluation§1798.100(d) Reasonable securityA.8.8 Technical vulnerabilitiesCC7.1 System monitoring; CC4.1 Monitoring activities
Threat management§164.308(a)(6) Security incident procedures§1798.100(d) Reasonable securityA.5.7 Threat intelligence; A.8.16 Monitoring activitiesCC7.2 Anomalies; CC7.3 Communicate detected events
Configuration & change management§164.312(b) Audit controls; §164.312(c) Integrity§1798.100(d) Reasonable securityA.8.9, A.8.32 Configuration & changeCC8.1 Change management; CC6.8 Configuration
Incident response§164.308(a)(6) Security incident procedures§1798.150 Civil action for breachA.5.24–A.5.28 Incident managementCC7.3, CC7.4, CC7.5 Incident lifecycle
Breach investigation & notification§164.410, §164.402, §164.404, §164.406, §164.408 Breach notification§1798.82 (Cal. Civ. Code) Security-breach notificationA.5.24 Planning; A.5.27 Learn from incidentsCC2.3 External communication; CC7.4 Incident response
BC / DR§164.308(a)(7) Contingency plan; §164.310(a)(2)(i)§1798.100(d) Reasonable securityA.5.29, A.5.30, A.8.13, A.8.14 ContinuityA1.1, A1.2, A1.3 Availability
System audits & monitoring§164.308(a)(1)(ii)(D) Information system activity review; §164.312(b) Audit controls§1798.100(e) Records of complianceA.8.15, A.8.16, A.8.17 Logging & monitoringCC4.1, CC4.2 Monitoring; CC7.2 Anomalies
Compliance, audits & external comms§164.314 Organizational requirements (BAA)§1798.135(b)(4) Compliance evidenceA.5.31, A.5.35, A.5.36 ComplianceCC2.3 External communication
Vendor & third-party risk§164.308(b), §164.314(a) BA contracts & subcontractors§1798.140(j)(k) Service provider / contractor; §1798.100(d)(4)A.5.19–A.5.23 Supplier relationshipsCC9.2 Vendor & business partner management

HIPAA deep-dive: Security Rule, Privacy Rule, Breach Notification

HIPAA is the binding framework today. The mapping below covers required (R) and addressable (A) specifications of the Security Rule. Privacy Rule and Breach Notification rows describe Foundry’s posture as a business associate; primary covered-entity obligations remain with the practice.

Security Rule §164.308: Administrative safeguards

StandardRequired / AddressableFoundry policyStatus
§164.308(a)(1)(i) Security management processRProgram overview, Risk mgmtImplemented
§164.308(a)(1)(ii)(A) Risk analysisRRisk mgmtImplemented
§164.308(a)(1)(ii)(B) Risk managementRRisk mgmt, Vuln mgmtImplemented
§164.308(a)(1)(ii)(C) Sanction policyRHR & personnelImplemented
§164.308(a)(1)(ii)(D) Information system activity reviewRSystem auditsImplemented
§164.308(a)(2) Assigned security responsibilityRRolesImplemented
§164.308(a)(3)(i) Workforce securityRHR, AccessImplemented
§164.308(a)(3)(ii)(A) Authorization & supervisionAAccessImplemented
§164.308(a)(3)(ii)(B) Workforce clearanceAHRImplemented
§164.308(a)(3)(ii)(C) Termination proceduresAHR, AccessImplemented
§164.308(a)(4) Information access managementRAccessImplemented
§164.308(a)(5) Security awareness & trainingRTrainingImplemented
§164.308(a)(6) Security incident proceduresRIR, BreachImplemented
§164.308(a)(7) Contingency planRBCDRImplemented
§164.308(a)(8) EvaluationRCompliance & auditsImplemented
§164.308(b) Business associate contracts & other arrangementsRVendor, BAAImplemented

Security Rule §164.310: Physical safeguards

StandardR/AFoundry policyStatus
§164.310(a)(1) Facility access controlsRFacilityImplemented
§164.310(a)(2)(i) Contingency operationsABCDRImplemented
§164.310(a)(2)(ii) Facility security planAFacilityImplemented
§164.310(a)(2)(iii) Access control & validationAFacilityImplemented
§164.310(a)(2)(iv) Maintenance recordsAFacilityImplemented
§164.310(b) Workstation useREndpointImplemented
§164.310(c) Workstation securityREndpointImplemented
§164.310(d)(1) Device & media controlsRAssetsImplemented
§164.310(d)(2)(i) DisposalRAssets, Data mgmtImplemented
§164.310(d)(2)(ii) Media re-useRAssetsImplemented
§164.310(d)(2)(iii) AccountabilityAAssetsImplemented
§164.310(d)(2)(iv) Data backup & storageABCDRImplemented

Security Rule §164.312: Technical safeguards

StandardR/AFoundry policyStatus
§164.312(a)(1) Access controlRAccessImplemented
§164.312(a)(2)(i) Unique user identificationRAccessImplemented
§164.312(a)(2)(ii) Emergency accessRAccess, BCDRImplemented
§164.312(a)(2)(iii) Automatic logoffAAccess, EndpointImplemented
§164.312(a)(2)(iv) Encryption & decryptionAData protectionImplemented
§164.312(b) Audit controlsRAuditsImplemented
§164.312(c)(1) IntegrityRData protection, CCMImplemented
§164.312(c)(2) Mechanism to authenticate ePHIAData protectionImplemented
§164.312(d) Person or entity authenticationRAccessImplemented
§164.312(e)(1) Transmission securityRData protectionImplemented
§164.312(e)(2)(i) Integrity controls in transitAData protectionImplemented
§164.312(e)(2)(ii) Encryption in transitAData protectionImplemented

Privacy Rule & Breach Notification Rule highlights (as a BA)

ProvisionFoundry obligation as BAPolicy
§164.502(b) Minimum necessaryRestrict workforce and agent access to the minimum PHI necessary for the task.Access, AI gov
§164.504(e) BA contractsExecute BAA with covered entity before PHI flow; subcontractor BAAs flow down “at least as protective.”BAA, Vendor
§164.524 Access by individualsSupport practice in responding to access requests; practice serves as point of contact.Privacy
§164.526 AmendmentSupport practice in processing amendment requests.Privacy
§164.528 Accounting of disclosuresMaintain disclosure records to support practice’s accounting.Audits
§164.410 BA notification to CENotify affected practice of any breach of unsecured PHI without unreasonable delay; default contractual window in BAA.Breach, BAA
§164.402 “Breach” definition & safe harborApply encryption / destruction safe-harbor analysis; document risk assessment for any acquisition / disclosure not falling within an exception.Breach

CCPA / CPRA deep-dive

The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA) applies to Foundry’s collection of California residents’ personal information, for example, physicians and prospective member-practice staff who interact with our marketing site or onboarding. Medical information governed by HIPAA is excluded by § 1798.146(a)(1)(A) and the CMIA carve-out: Foundry handles that data as PHI under the BAA, not as PI under CCPA.

CCPA / CPRA requirementSourceFoundry policy or documentStatus
Notice at collection§1798.100(a), (b); §1798.135Privacy PolicyImplemented
Right to know: categories collected, sources, purposes, recipients§1798.100(a); §1798.110; §1798.115Privacy PolicyImplemented
Right to delete§1798.105Privacy Policy, Data mgmtImplemented
Right to correct§1798.106Privacy PolicyImplemented
Right to portability§1798.100(d)(3); §1798.130(a)(2)Privacy PolicyImplemented
Right to opt out of sale or sharing§1798.120; §1798.135Privacy PolicyImplemented (we do not sell or share)
Right to limit use of Sensitive Personal Information§1798.121Privacy PolicyImplemented
Non-discrimination for exercising rights§1798.125Privacy PolicyImplemented
Retention disclosure (per category)§1798.100(a)(3)Privacy Policy, Data mgmtImplemented
Authorized agent process§1798.140(b); regs §7063Privacy PolicyImplemented
Service-provider / contractor contracting§1798.140(j), (k); §1798.100(d)Vendor, SubprocessorsImplemented
Global Privacy Control (GPC) honoringregs §7025Cookie Policy, Privacy PolicyImplemented
Automated Decision-Making Technology (ADMT) disclosures§1798.185(a)(16) (regs in development)Privacy Policy, AI govImplemented
Reasonable security§1798.100(d); §1798.150(a)Security architecture, Data protectionImplemented
Breach notification (Cal. Civ. Code §1798.82)Cal. Civ. Code §1798.82BreachImplemented

ISO/IEC 27001:2022 deep-dive (Annex A)

The mapping below shows how Foundry’s policies address each Annex A theme. Per-control status is summarized by group.

Annex A themeControl rangePrimary Foundry policiesStatus
A.5 Organizational controlsA.5.1–A.5.37 (37 controls)Overview, Policy mgmt, Risk, Vendor, Access, IR, Breach, Compliance, AI gov, PrivacyImplemented
A.6 People controlsA.6.1–A.6.8 (8 controls)HR & personnel, TrainingImplemented
A.7 Physical controlsA.7.1–A.7.14 (14 controls)Facility, Assets, EndpointImplemented: remote-first model; data-center physical controls inherited from cloud subprocessors
A.8 Technological controlsA.8.1–A.8.34 (34 controls)Access, Data protection, SDLC, Vuln mgmt, Threat, CCM, Audits, BCDRImplemented

ISO 27001 main-body clauses (4–10)

ClauseTopicFoundry policy / artifactStatus
4Context of the organizationProgram overviewImplemented
5LeadershipRolesImplemented
6PlanningRisk mgmtImplemented
7Support (competence, awareness, communication, documented info)Training, Policy mgmtImplemented
8Operation (risk treatment, change)Risk, CCMImplemented
9Performance evaluation (monitoring, audit, mgmt review)Audits, ComplianceImplemented
10ImprovementIR, Policy mgmtImplemented

SOC 2 deep-dive (Trust Services Criteria)

Foundry’s policies are structured as control narratives against the SOC 2 Trust Services Criteria. The mapping below shows the policy or document that supports each criterion.

Trust Services CriteriaRequired for?Foundry policy / control source
CC1 Control environmentAll reportsOverview, Roles, HR, Policy mgmt
CC2 Communication & informationAll reportsPolicy mgmt, Compliance & external comms
CC3 Risk assessmentAll reportsRisk mgmt, Vendor risk
CC4 Monitoring activitiesAll reportsAudits, Threat
CC5 Control activitiesAll reportsArchitecture, Access
CC6 Logical & physical accessSecurityAccess, Facility, Endpoint, Assets, Data protection
CC7 System operationsSecurityThreat, Vuln, IR, Audits
CC8 Change managementSecurityCCM, SDLC
CC9 Risk mitigationSecurityRisk mgmt, Vendor, BCDR
A1 Availability (A1.1–A1.3)AvailabilityBCDR, Audits
C1 Confidentiality (C1.1–C1.2)ConfidentialityData mgmt, Data protection, Privacy
P1–P8 PrivacyPrivacyPrivacy, Privacy Policy, AI gov
PI1 Processing integrityProcessing IntegritySDLC, AI gov, CCM

Aggregate status by framework

FrameworkPosture
HIPAA Security & Privacy Rules; Breach NotificationImplemented
CCPA / CPRAImplemented
ISO/IEC 27001:2022Implemented (policy alignment)
ISO/IEC 42001:2023Implemented (policy alignment)
SOC 2 Trust Services CriteriaImplemented (control narrative)

Maintenance

This crosswalk is the single source of truth for framework mapping. Individual policies reference HIPAA only and link here for other frameworks. Update this page when a policy is added, retired, or materially changed, and on any change to the framework posture (e.g., upon completing a SOC 2 Type I).