HIPAA Security Rule mapping
HIPAA Security Rule mapping
Frameworks · HIPAA · v2026.06 · Administrative, Physical, and Technical safeguards (45 CFR §§ 164.308–164.312) mapped to Foundry policies and platform controls. Last refreshed June 2026.
Bioscope Foundry, LLC is a business associate to member physician practices, not a covered entity. The HIPAA Security Rule applies to Foundry directly under HITECH § 13401(a). This page lists each Security Rule standard and implementation specification, the Foundry policy that satisfies it, and a status pill. See the HIPAA Notice & Business Associate Statement for the narrative version.
Status Implemented Not applicable as a BA
Administrative safeguards: 45 CFR § 164.308
| Standard | Implementation specification | How Foundry satisfies it | Policy | Status |
|---|---|---|---|---|
| § 164.308(a)(1) Security management process | Risk analysis · Risk management · Sanction policy · Information system activity review | Documented risk register with quarterly refresh; risk treatment options track each finding; workforce sanctions follow the HR & personnel security policy; system-activity review against audit logs is part of monthly security operations. | Risk management, System audits | Implemented |
| § 164.308(a)(2) Assigned security responsibility | (Required) | Security Officer and Privacy Officer named in Roles, responsibilities & training. | Roles & training | Implemented |
| § 164.308(a)(3) Workforce security | Authorization & supervision · Workforce clearance · Termination procedures | Pre-hire background checks; manager-approved access grants; same-day deprovisioning on departure tracked in the joiner/mover/leaver workflow. | HR & personnel security, Access control | Implemented |
| § 164.308(a)(4) Information access management | Isolating healthcare clearinghouse · Access authorization · Access establishment & modification | Role-based access enforced before requests reach the FHIR store; clinic-scoped agents (Tier-3) cannot see other clinics’ data; sandboxed workers (Tier-4 Moltworkers) cannot hold PHI at all. Clearinghouse isolation is not applicable. | Access control, Security architecture | Implemented |
| § 164.308(a)(5) Security awareness and training | Security reminders · Malware protection · Login monitoring · Password management | Annual HIPAA + security training is required for all workforce members; phishing and login-anomaly monitoring is wired into the IdP; password rules follow NIST 800-63B; an AI-literacy module covers Atlas and Forge Agents. | Roles & training | Implemented |
| § 164.308(a)(6) Security incident procedures | Response and reporting | Incident response runbook with detect → triage → contain → eradicate → recover → learn phases; ties into the breach-notification workflow at § 164.410. | Incident response, Breach notification | Implemented |
| § 164.308(a)(7) Contingency plan | Data backup · Disaster recovery · Emergency mode operations · Testing & revision · Applications & data criticality analysis | AWS regional posture for the clinical data plane with documented RTO/RPO targets; backup integrity tested per the BCDR policy; criticality analysis classifies the clinical workflow database, the FHIR service, the audit log store, and the identity provider as Tier-1. | Business continuity & DR | Implemented |
| § 164.308(a)(8) Evaluation | (Required) | Annual security program review; ad-hoc reviews after material change to environment, regulation, or platform. | Program overview, Compliance & audits | Implemented |
| § 164.308(b)(1) Business associate contracts & other arrangements | Written contract or other arrangement | Foundry signs a BAA with each member practice before any PHI is handled, and a BAA with each PHI-handling subcontractor (Amazon Web Services and others). Standard BAA available on request. | BAA, Vendor & third-party risk | Implemented |
Physical safeguards: 45 CFR § 164.310
| Standard | Implementation specification | How Foundry satisfies it | Policy | Status |
|---|---|---|---|---|
| § 164.310(a)(1) Facility access controls | Contingency operations · Facility security plan · Access control & validation · Maintenance records | PHI is stored in Amazon Web Services data centers; Foundry inherits AWS’s facility safeguards under its BAA. The Carmel, IN office holds no PHI media; access is keyed and logged. Workforce is remote-first. | Facility & physical security | Implemented |
| § 164.310(b) Workstation use | (Required) | Workstation baseline forbids PHI on local disk; workforce policies define acceptable use, screen-lock, and the prohibition on storing PHI outside the FHIR store. | Endpoint & MDM | Implemented |
| § 164.310(c) Workstation security | (Required) | MDM-enrolled endpoints with FileVault, automatic patching, host-based firewall, posture checks gating access to operational systems. | Endpoint & MDM | Implemented |
| § 164.310(d)(1) Device and media controls | Disposal · Media re-use · Accountability · Data backup & storage | No removable PHI media is issued. Decommissioned laptops are wiped via MDM remote-wipe and tracked in the asset register; cloud-backed FHIR data has its own backup discipline. | Asset management, BCDR | Implemented |
Technical safeguards: 45 CFR § 164.312
| Standard | Implementation specification | How Foundry satisfies it | Policy | Status |
|---|---|---|---|---|
| § 164.312(a)(1) Access control | Unique user identification · Emergency access · Automatic logoff · Encryption & decryption | Federated SSO assigns a unique identity per workforce member; break-glass access is logged and reviewed; short idle and absolute session timeouts on the operating platform; PHI encrypted at rest (AES-256) with optional CMEK. | Access control, Data protection | Implemented |
| § 164.312(b) Audit controls | (Required) | Every read and write of PHI is logged, who, when, which patient, which record, the outcome, the practice, and the reason, using machine-readable audit codes, not free-text PHI bodies. Audit retention is at least six years. | System audits | Implemented |
| § 164.312(c)(1) Integrity | Mechanism to authenticate ePHI | FHIR resource versioning + audit history; mount-security and integrity checks in the agent operating system; backup hash verification. | Data protection, Security architecture | Implemented |
| § 164.312(d) Person or entity authentication | (Required) | Doctor onboarding uses email magic links with short-lived, HttpOnly sessions; the production workforce IdP is being selected under ADR-011. Phishing-resistant WebAuthn passkeys are the preferred MFA factor and are enforced today on the AWS root account (dedicated hardware security keys are planned as sealed break-glass). SMS one-time codes are prohibited for workforce (see NIST 800-63B mapping). | Access control | Implemented |
| § 164.312(e)(1) Transmission security | Integrity controls · Encryption | TLS 1.2+ for all transmissions; PHI never traverses SMS or unauthenticated email channels; notifications are designed to avoid containing PHI in the message body. | Data protection | Implemented |
Privacy Rule highlights (as a business associate)
The Privacy Rule applies to Foundry only to the extent specified in the BAA with each practice. Practices remain accountable for their patient-facing notice and rights workflows; we support them.
| Privacy Rule area | Foundry posture as a BA | Policy | Status |
|---|---|---|---|
| § 164.504(e) Business associate contracts | Standard BAA describes permitted uses, safeguards, subcontractor flow-down, breach reporting, and return/destruction of PHI on termination. | BAA | Implemented |
| § 164.502(b) Minimum necessary | Access policies enforce minimum-necessary at the API layer; agent tiers (T0–T4) gate visibility by role and clinic. | Access control, Privacy | Implemented |
| § 164.508 Sale of PHI · § 164.501 Marketing | Foundry does not sell PHI and does not use PHI for marketing. Stated in BAA, Privacy Policy, and HIPAA Notice. | Privacy Policy | Implemented |
| § 164.524 Individual right of access · § 164.526 Amendment · § 164.528 Accounting of disclosures | Patient requests are exercised through the covered entity. Foundry supports practices by making relevant records and audit information available on request. | Privacy | Implemented |
| § 164.520 Notice of Privacy Practices | Issued by the covered entity (the practice). Not applicable to Foundry as a BA. | N/A | Not applicable as a BA |
Breach Notification Rule: 45 CFR §§ 164.400–414
| Requirement | Foundry commitment | Policy | Status |
|---|---|---|---|
| § 164.402 Breach definition & risk assessment | Four-factor risk assessment runs on every reportable incident; outcome is documented in the incident-response record. | Breach notification | Implemented |
| § 164.410 BA notification to covered entity | Foundry notifies the affected practice without unreasonable delay and no later than thirty (30) calendar days from discovery of a breach of unsecured PHI, well within the HIPAA 60-day outer limit at 45 CFR § 164.410(b). Where a Practice’s negotiated BAA sets a shorter window, that BAA controls. | Breach notification, BAA | Implemented |
| § 164.404 Notice to individuals · § 164.406 Notice to media · § 164.408 Notice to HHS | These obligations are the covered entity’s responsibility. Foundry provides the practice the information it needs (affected individuals, records, dates, the breach narrative) to meet them. | Breach notification | Not applicable as a BA |
| § 164.414 Burden of proof & documentation | Documentation of every reportable incident, including those judged not to be breaches, is retained for at least six years. | Breach notification | Implemented |
Reading this page as a buyer or auditor? The HIPAA Notice & Business Associate Statement at /legal/hipaa-notice.html is the narrative companion to this matrix. The Business Associate Agreement at /legal/business-associate-agreement.html is the contract that binds Foundry to the safeguards above.