Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.
HIPAA Security Rule mapping

HIPAA Security Rule mapping

Frameworks · HIPAA · v2026.06 · Administrative, Physical, and Technical safeguards (45 CFR §§ 164.308–164.312) mapped to Foundry policies and platform controls. Last refreshed June 2026.

Bioscope Foundry, LLC is a business associate to member physician practices, not a covered entity. The HIPAA Security Rule applies to Foundry directly under HITECH § 13401(a). This page lists each Security Rule standard and implementation specification, the Foundry policy that satisfies it, and a status pill. See the HIPAA Notice & Business Associate Statement for the narrative version.

Status Implemented Not applicable as a BA

Administrative safeguards: 45 CFR § 164.308

StandardImplementation specificationHow Foundry satisfies itPolicyStatus
§ 164.308(a)(1) Security management processRisk analysis · Risk management · Sanction policy · Information system activity reviewDocumented risk register with quarterly refresh; risk treatment options track each finding; workforce sanctions follow the HR & personnel security policy; system-activity review against audit logs is part of monthly security operations.Risk management, System auditsImplemented
§ 164.308(a)(2) Assigned security responsibility(Required)Security Officer and Privacy Officer named in Roles, responsibilities & training.Roles & trainingImplemented
§ 164.308(a)(3) Workforce securityAuthorization & supervision · Workforce clearance · Termination proceduresPre-hire background checks; manager-approved access grants; same-day deprovisioning on departure tracked in the joiner/mover/leaver workflow.HR & personnel security, Access controlImplemented
§ 164.308(a)(4) Information access managementIsolating healthcare clearinghouse · Access authorization · Access establishment & modificationRole-based access enforced before requests reach the FHIR store; clinic-scoped agents (Tier-3) cannot see other clinics’ data; sandboxed workers (Tier-4 Moltworkers) cannot hold PHI at all. Clearinghouse isolation is not applicable.Access control, Security architectureImplemented
§ 164.308(a)(5) Security awareness and trainingSecurity reminders · Malware protection · Login monitoring · Password managementAnnual HIPAA + security training is required for all workforce members; phishing and login-anomaly monitoring is wired into the IdP; password rules follow NIST 800-63B; an AI-literacy module covers Atlas and Forge Agents.Roles & trainingImplemented
§ 164.308(a)(6) Security incident proceduresResponse and reportingIncident response runbook with detect → triage → contain → eradicate → recover → learn phases; ties into the breach-notification workflow at § 164.410.Incident response, Breach notificationImplemented
§ 164.308(a)(7) Contingency planData backup · Disaster recovery · Emergency mode operations · Testing & revision · Applications & data criticality analysisAWS regional posture for the clinical data plane with documented RTO/RPO targets; backup integrity tested per the BCDR policy; criticality analysis classifies the clinical workflow database, the FHIR service, the audit log store, and the identity provider as Tier-1.Business continuity & DRImplemented
§ 164.308(a)(8) Evaluation(Required)Annual security program review; ad-hoc reviews after material change to environment, regulation, or platform.Program overview, Compliance & auditsImplemented
§ 164.308(b)(1) Business associate contracts & other arrangementsWritten contract or other arrangementFoundry signs a BAA with each member practice before any PHI is handled, and a BAA with each PHI-handling subcontractor (Amazon Web Services and others). Standard BAA available on request.BAA, Vendor & third-party riskImplemented

Physical safeguards: 45 CFR § 164.310

StandardImplementation specificationHow Foundry satisfies itPolicyStatus
§ 164.310(a)(1) Facility access controlsContingency operations · Facility security plan · Access control & validation · Maintenance recordsPHI is stored in Amazon Web Services data centers; Foundry inherits AWS’s facility safeguards under its BAA. The Carmel, IN office holds no PHI media; access is keyed and logged. Workforce is remote-first.Facility & physical securityImplemented
§ 164.310(b) Workstation use(Required)Workstation baseline forbids PHI on local disk; workforce policies define acceptable use, screen-lock, and the prohibition on storing PHI outside the FHIR store.Endpoint & MDMImplemented
§ 164.310(c) Workstation security(Required)MDM-enrolled endpoints with FileVault, automatic patching, host-based firewall, posture checks gating access to operational systems.Endpoint & MDMImplemented
§ 164.310(d)(1) Device and media controlsDisposal · Media re-use · Accountability · Data backup & storageNo removable PHI media is issued. Decommissioned laptops are wiped via MDM remote-wipe and tracked in the asset register; cloud-backed FHIR data has its own backup discipline.Asset management, BCDRImplemented

Technical safeguards: 45 CFR § 164.312

StandardImplementation specificationHow Foundry satisfies itPolicyStatus
§ 164.312(a)(1) Access controlUnique user identification · Emergency access · Automatic logoff · Encryption & decryptionFederated SSO assigns a unique identity per workforce member; break-glass access is logged and reviewed; short idle and absolute session timeouts on the operating platform; PHI encrypted at rest (AES-256) with optional CMEK.Access control, Data protectionImplemented
§ 164.312(b) Audit controls(Required)Every read and write of PHI is logged, who, when, which patient, which record, the outcome, the practice, and the reason, using machine-readable audit codes, not free-text PHI bodies. Audit retention is at least six years.System auditsImplemented
§ 164.312(c)(1) IntegrityMechanism to authenticate ePHIFHIR resource versioning + audit history; mount-security and integrity checks in the agent operating system; backup hash verification.Data protection, Security architectureImplemented
§ 164.312(d) Person or entity authentication(Required)Doctor onboarding uses email magic links with short-lived, HttpOnly sessions; the production workforce IdP is being selected under ADR-011. Phishing-resistant WebAuthn passkeys are the preferred MFA factor and are enforced today on the AWS root account (dedicated hardware security keys are planned as sealed break-glass). SMS one-time codes are prohibited for workforce (see NIST 800-63B mapping).Access controlImplemented
§ 164.312(e)(1) Transmission securityIntegrity controls · EncryptionTLS 1.2+ for all transmissions; PHI never traverses SMS or unauthenticated email channels; notifications are designed to avoid containing PHI in the message body.Data protectionImplemented

Privacy Rule highlights (as a business associate)

The Privacy Rule applies to Foundry only to the extent specified in the BAA with each practice. Practices remain accountable for their patient-facing notice and rights workflows; we support them.

Privacy Rule areaFoundry posture as a BAPolicyStatus
§ 164.504(e) Business associate contractsStandard BAA describes permitted uses, safeguards, subcontractor flow-down, breach reporting, and return/destruction of PHI on termination.BAAImplemented
§ 164.502(b) Minimum necessaryAccess policies enforce minimum-necessary at the API layer; agent tiers (T0–T4) gate visibility by role and clinic.Access control, PrivacyImplemented
§ 164.508 Sale of PHI · § 164.501 MarketingFoundry does not sell PHI and does not use PHI for marketing. Stated in BAA, Privacy Policy, and HIPAA Notice.Privacy PolicyImplemented
§ 164.524 Individual right of access · § 164.526 Amendment · § 164.528 Accounting of disclosuresPatient requests are exercised through the covered entity. Foundry supports practices by making relevant records and audit information available on request.PrivacyImplemented
§ 164.520 Notice of Privacy PracticesIssued by the covered entity (the practice). Not applicable to Foundry as a BA.N/ANot applicable as a BA

Breach Notification Rule: 45 CFR §§ 164.400–414

RequirementFoundry commitmentPolicyStatus
§ 164.402 Breach definition & risk assessmentFour-factor risk assessment runs on every reportable incident; outcome is documented in the incident-response record.Breach notificationImplemented
§ 164.410 BA notification to covered entityFoundry notifies the affected practice without unreasonable delay and no later than thirty (30) calendar days from discovery of a breach of unsecured PHI, well within the HIPAA 60-day outer limit at 45 CFR § 164.410(b). Where a Practice’s negotiated BAA sets a shorter window, that BAA controls.Breach notification, BAAImplemented
§ 164.404 Notice to individuals · § 164.406 Notice to media · § 164.408 Notice to HHSThese obligations are the covered entity’s responsibility. Foundry provides the practice the information it needs (affected individuals, records, dates, the breach narrative) to meet them.Breach notificationNot applicable as a BA
§ 164.414 Burden of proof & documentationDocumentation of every reportable incident, including those judged not to be breaches, is retained for at least six years.Breach notificationImplemented

Reading this page as a buyer or auditor? The HIPAA Notice & Business Associate Statement at /legal/hipaa-notice.html is the narrative companion to this matrix. The Business Associate Agreement at /legal/business-associate-agreement.html is the contract that binds Foundry to the safeguards above.