# Bioscope Foundry Trust Center — Legal Agreements & Policies

This file contains all legal agreements, terms, and policies for Bioscope Foundry services.

Generated automatically from https://trust.bioscopefoundry.com/

---



<!-- DOCUMENT START: business-associate-agreement.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: as set out in the executed Order · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft template for legal review.** This is a redlinable template, not an executed contract. Prepared from Foundry's platform architecture and standard HIPAA business-associate framework. Not legal advice; have counsel review before signing.

{{< /callout >}}

{{< callout type="info" >}}

This Business Associate Agreement ("**BAA**") is entered into between **Bioscope Foundry, LLC** ("**Foundry**," the "**Business Associate**") and the physician practice that has executed the Master Services Agreement (the "**Practice**" or "**Covered Entity**"). It supplements, amends, and is incorporated into the Master Services Agreement between Foundry and the Practice (the "**Agreement**") and governs each party's obligations regarding Protected Health Information ("**PHI**"). It becomes effective as of the date the Practice executes an Order or the date stated above, whichever is later (the "**BAA Effective Date**"). The Practice must have an Agreement in place for this BAA to be valid.

{{< /callout >}}

## 1. Definitions {#definitions}

Capitalized terms not otherwise defined here have the meaning given to them in HIPAA or in the Agreement.

- **"Breach"** has the meaning given to it under HIPAA.
- **"Business Associate"** has the meaning given to it under HIPAA.
- **"Covered Entity"** has the meaning given to it under HIPAA.
- **"Covered Services"** means the Foundry products and services listed in [Attachment 1: HIPAA-Covered Services](/legal/hipaa-covered-services/), as Foundry may update from time to time with at least 30 days' prior written notice to the Practice (or with such notice as is reasonable under the circumstances for an emergency change).
- **"Designated Record Set"** has the meaning given to it under HIPAA.
- **"HIPAA"** means the Health Insurance Portability and Accountability Act of 1996 and the rules and regulations thereunder, as amended, including the Privacy Rule, Security Rule, and Breach Notification Rule, together with the HITECH Act and its implementing regulations.
- **"Individual"** has the meaning given to it under HIPAA and includes a personal representative qualifying under HIPAA.
- **"Patient"** means an Individual who is a patient of the Practice and for whom the Practice is using the Covered Services in connection with treatment or operations.
- **"PHI"** means Protected Health Information as defined under HIPAA, limited for purposes of this BAA to PHI that Foundry creates, receives, maintains, or transmits on behalf of the Practice through the Covered Services.
- **"Required by Law"** has the meaning given to it under HIPAA.
- **"Secretary"** means the Secretary of the U.S. Department of Health and Human Services or their designee.
- **"Security Incident"** has the meaning given to it under HIPAA.
- **"Subcontractor"** means a person or entity to whom Foundry delegates a function, activity, or service that involves the creation, receipt, maintenance, or transmission of PHI on behalf of the Practice.

## 2. Applicability {#applicability}

This BAA applies to the extent the Practice acts as a Covered Entity (or as a Business Associate to another Covered Entity) creating, receiving, maintaining, or transmitting PHI through a Covered Service, and to the extent Foundry, as a result, acts as a Business Associate or Subcontractor under HIPAA.

This BAA does not apply to: (a) Foundry products, services, or features not listed as Covered Services; (b) PHI that the Practice creates, receives, maintains, or transmits outside of the Covered Services; or (c) services provided by third parties that are not Subcontractors of Foundry, including third-party applications or integrations the Practice elects to use.

## 3. Permitted uses and disclosures of PHI {#permitted}

### 3.1 General limitations {#general-limitations}

Except as otherwise stated in this BAA, Foundry may use and disclose PHI only (i) as permitted or required by the Agreement and this BAA; (ii) as Required by Law; or (iii) as otherwise permitted under HIPAA for a Business Associate. Foundry will not sell PHI and will not use or disclose PHI for marketing as defined under HIPAA except as expressly permitted by this BAA and applicable law.

### 3.2 Service operations {#service-operations}

Foundry may use and disclose PHI as reasonably necessary to perform the Covered Services for the Practice, including to operate the clinical data platform, route administrative communications, schedule and coordinate care operations, generate audit and security records, and otherwise carry out the management services described in the Agreement.

### 3.3 Proper management and administration {#proper-management-and-administration}

Foundry may use and disclose PHI for its proper management and administration and to carry out its legal responsibilities, provided that any disclosure of PHI for these purposes may occur only if (a) Required by Law, or (b) Foundry obtains written reasonable assurances from the recipient that the PHI will be held in confidence, used only for the purpose for which it was disclosed, and that Foundry will be notified of any Breach or Security Incident involving the PHI.

### 3.4 De-identification and aggregation {#de-identification-and-aggregation}

Subject to the Agreement, Foundry may (a) provide data aggregation services relating to the Practice's health care operations and (b) de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c). Once de-identified in accordance with HIPAA, such data is no longer PHI and is not subject to this BAA.

### 3.5 AI-assisted processing {#ai-assisted-processing}

The Practice acknowledges that the Covered Services include AI-assisted features that may process PHI to support the Practice's operations (for example, to draft communications, summarize records, route messages, and surface insights for a clinician's review). Foundry will not use PHI to train or fine-tune general-purpose AI models. Any AI processing of PHI occurs only through HIPAA-eligible services covered by a BAA. AI outputs are intended to augment, not replace, human judgment.

## 4. Practice obligations {#practice-obligations}

### 4.1 Permissible requests {#permissible-requests}

The Practice will not request that Foundry or the Covered Services use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Practice (or by the Covered Entity to which the Practice is a Business Associate), unless expressly permitted under HIPAA for a Business Associate.

### 4.2 Implementation and configuration {#implementation-and-configuration}

The Practice will use the access controls, role assignments, and configuration options available within the Covered Services to ensure that its use of PHI is limited to the Covered Services and to the workforce members who need access. The Practice is solely responsible for ensuring that its and its authorized users' use of the Covered Services complies with HIPAA.

### 4.3 Patient notice and consent {#patient-notice-and-consent}

The Practice is solely responsible for issuing its own Notice of Privacy Practices and obtaining all necessary authorizations and consents from its patients as required by HIPAA and other applicable laws.

### 4.4 Minimum necessary {#minimum-necessary}

The Practice will limit disclosures of PHI to Foundry to the minimum necessary to accomplish the intended purpose, except for disclosures for treatment.

## 5. Appropriate safeguards {#safeguards}

Foundry will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, including electronic PHI, that it creates, receives, maintains, or transmits on behalf of the Practice, in accordance with 45 C.F.R. Part 164, Subpart C. Such safeguards include, without limitation:

- Storage and processing of PHI on a HIPAA-eligible cloud healthcare platform (Foundry's FHIR service, FHIR R4), under Foundry's BAAs with its infrastructure providers;
- Encryption of PHI in transit (TLS 1.2 or higher) and at rest (AES-256, with the option of customer-managed keys);
- Role-based, least-privilege access controls, with passwordless authentication and multi-factor authentication available through the identity provider;
- Audit logging of access to PHI, designed to record identifiers, not PHI content, retained for at least six (6) years;
- Network isolation, managed secret storage, and segregated production environments for systems that touch PHI;
- Workforce confidentiality obligations and security training;
- Communications discipline: SMS and email notifications are designed to avoid containing PHI; clinical content remains within authenticated systems; and
- Backup, continuity, and recovery practices.

The Practice will also use appropriate safeguards designed to prevent unauthorized use or disclosure of PHI in its handling of the Covered Services.

## 6. Reporting and breach notification {#reporting}

### 6.1 Breach notification {#breach-notification}

Foundry will notify the Practice of any Breach of unsecured PHI without unreasonable delay, and in no event later than **thirty (30) calendar days** after Foundry discovers the Breach (and in any event no later than the 60-day outer limit set by HIPAA at 45 C.F.R. § 164.410(b)). Foundry will also notify the Practice of any Security Incident of which Foundry becomes aware, subject to Section 6.3.

### 6.2 Mitigation {#mitigation}

As required by 45 C.F.R. § 164.504(e)(2)(ii)(C), Foundry will mitigate, to the extent practicable, any harmful effect that is known to Foundry of a use or disclosure of PHI by Foundry in violation of the requirements of this BAA, including, where appropriate, providing the Practice with the information necessary to support the Practice's mitigation actions toward affected Individuals.

### 6.3 Notification contents {#notification-contents}

Each notification under Section 6.1 will describe, to the extent then known: (a) the nature of the Breach or Security Incident, including the categories and approximate number of Individuals and PHI records affected; (b) the steps taken to investigate, contain, and mitigate the incident; (c) the steps Foundry recommends the Practice take; and (d) contact information for Foundry's designated security contact. Foundry will provide the information necessary for the Practice to meet its own HIPAA notification obligations under 45 C.F.R. §§ 164.404, 164.406, and 164.408, and will supplement the report as additional information becomes available.

### 6.4 Unsuccessful security incidents {#unsuccessful-security-incidents}

This Section 6.4 serves as notice to the Practice that Foundry periodically receives unsuccessful attempts to access, use, disclose, modify, or destroy information, or to interfere with normal operation of its systems (for example, pings, port scans, blocked login attempts, and unsuccessful denial-of-service attempts). Foundry will not provide individual notice of these events.

### 6.5 Notification method {#notification-method}

Foundry will deliver notifications under this Section 6 to the email address designated by the Practice in the Order or via direct communication with the Practice's designated administrator, or by such other means as the parties agree in writing.

## 7. Subcontractors {#subcontractors}

Foundry will require any Subcontractor that creates, receives, maintains, or transmits PHI on Foundry's behalf to agree in writing to restrictions and conditions that are at least as protective as those that apply to Foundry under this BAA. Foundry remains responsible for the performance of its Subcontractors as if performed by Foundry. A current list of Subcontractors that may handle PHI is maintained at [Subprocessors](/legal/subprocessors/); Foundry will provide the Practice with at least 30 days' prior notice before engaging any new Subcontractor that will have access to PHI.

## 8. Access and amendment {#access}

The Practice is solely responsible for the form and content of PHI maintained by it within the Covered Services, including whether it maintains such PHI in a Designated Record Set within the Covered Services. Foundry will provide the Practice with access to PHI via the Covered Services so that the Practice may fulfill its obligations under HIPAA with respect to Individuals' rights of access and amendment. Foundry will not respond to Individual rights requests directly unless directed in writing by the Practice to do so.

## 9. Accounting of disclosures {#accounting}

Foundry will document disclosures of PHI by Foundry and provide an accounting of such disclosures to the Practice as and to the extent required of a Business Associate under HIPAA and in accordance with 45 C.F.R. § 164.528. On the Practice's reasonable request, Foundry will provide the information necessary for the Practice to respond to an Individual's accounting request within 30 days.

## 10. Access to records {#secretary}

To the extent required by law, and subject to all applicable legal privileges, Foundry will make its internal practices, books, and records concerning the use and disclosure of PHI received from the Practice, or created or received by Foundry on behalf of the Practice, available to the Secretary to determine compliance with this BAA and HIPAA.

## 11. Term and termination {#term}

### 11.1 Term {#term-1}

This BAA becomes effective on the BAA Effective Date and will terminate on the earlier of: (a) a permitted termination in accordance with Section 11.2; or (b) the expiration or termination of all Orders under which the Practice has access to a Covered Service. The default initial term aligns with the Agreement, currently 12 months.

### 11.2 Termination for material breach (cure or report) {#termination-for-material-breach-cure-or-report}

If either party materially breaches this BAA, the non-breaching party may terminate this BAA on 30 days' written notice unless the breach is cured within the 30-day period. If a cure is not reasonably possible, the non-breaching party may immediately terminate this BAA. Consistent with 45 C.F.R. § 164.504(e)(1)(ii), if neither termination nor cure is reasonably possible, the non-breaching party may, in lieu of termination, report the violation to the Secretary of the U.S. Department of Health and Human Services, subject to applicable legal privileges.

### 11.3 Effect of early termination {#effect-of-early-termination}

If this BAA is terminated earlier than the Agreement, the Practice must immediately cease using the Covered Services to create, receive, maintain, or transmit PHI. Foundry will discontinue further creation, receipt, maintenance, or transmission of PHI on behalf of the Practice through the Covered Services, except to the extent necessary to complete return or destruction of PHI under Section 12 or to honor the Practice's HIPAA recordkeeping obligations.

## 12. Return or destruction of PHI {#return}

On termination of the Agreement, Foundry will return or destroy all PHI received from the Practice, or created or received by Foundry on behalf of the Practice, including PHI held by Foundry's Subcontractors. The Practice's clean-offboarding right is described in the Master Services Agreement; PHI export is delivered in standard FHIR R4 within **ninety (90) calendar days** of termination. If return or destruction is not feasible, for example, where PHI is held within immutable backup systems on commercially reasonable retention timers, Foundry will extend the protections of this BAA to the PHI not returned or destroyed, limit further uses and disclosures to those purposes that make return or destruction infeasible, and delete the PHI when the backup retention period expires. Foundry may also retain PHI to the extent required by applicable law, in which case Foundry will isolate and protect the PHI from further processing except as required by law and delete it when no longer required.

## 13. Miscellaneous {#misc}

### 13.1 Survival {#survival}

Sections 6 (Reporting), 10 (Access to Records), 12 (Return or Destruction), and this Section 13 will survive termination or expiration of this BAA.

### 13.2 Regulatory changes {#regulatory-changes}

The parties agree to take such action as is reasonably necessary to amend this BAA from time to time as required for compliance with changes in HIPAA or other applicable law.

### 13.3 Interpretation {#interpretation}

Any ambiguity in this BAA will be interpreted to permit compliance with HIPAA. In the event of any conflict between this BAA and the Agreement with respect to PHI, this BAA controls.

### 13.4 Governing law {#governing-law}

This BAA is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules. The dispute-resolution provisions of the Agreement apply to this BAA.

### 13.5 No third-party beneficiaries {#no-third-party-beneficiaries}

Nothing in this BAA is intended to confer rights or remedies on any person other than the parties, except that Individuals may exercise their rights under HIPAA as provided by law.

### 13.6 Entire agreement {#entire-agreement}

This BAA, together with the Agreement and any applicable Orders, constitutes the entire agreement between the parties with respect to its subject matter and supersedes any prior business-associate arrangements between them.

## 14. Contact {#contact}

Questions about this BAA, or to request execution of a BAA before exchanging PHI, contact:

Bioscope Foundry, LLC\
Attn: Privacy Officer\
Privacy: <privacy@bioscopefoundry.com>\
Security: <security@bioscopefoundry.com>\
Legal: <legal@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

See also: [HIPAA Notice & Business Associate Statement](/legal/hipaa-notice/) · [List of HIPAA-covered services](/legal/hipaa-covered-services/) · [Subprocessors](/legal/subprocessors/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: business-associate-agreement.md -->

---



<!-- DOCUMENT START: cookie-policy.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** Cookie inventories evolve with the product; verify before publication. confirmation.

{{< /callout >}}

{{< callout type="info" >}}

This Cookie Policy explains how **Bioscope Foundry, LLC** ("Foundry," "we," "us," or "our") uses cookies and similar technologies. Foundry operates two environments with different cookie practices: the public **marketing site** ([bioscopefoundry.com](https://bioscopefoundry.com)) and the authenticated **operating platform** for member practices. **We do not use third-party advertising or behavioral-tracking cookies anywhere.**

{{< /callout >}}

## Two environments, two practices {#environments style="margin-top: 24px"}

### Marketing site (`bioscopefoundry.com`) {#marketing-site-bioscopefoundrycom}

Public, informational. Uses **essential** cookies for site functionality and security, plus **privacy-respecting analytics** to understand how the site is used. **Does not process PHI.**

### Operating platform

Authenticated tools for member practices. Uses **only essential cookies**: security, authentication, and session. No analytics, no marketing, no third-party trackers.

## 1. What cookies are {#what}

Cookies are small text files stored on your device when you visit a website. They allow a site to remember your actions across pages and visits, and they support security (for example, detecting tampered sessions). Similar technologies include local storage, session storage, and web beacons; this policy treats them together.

## 2. Cookies on the marketing site {#marketing}

The marketing site uses two categories of cookies.

### 2.1 Essential cookies {#essential-cookies}

Required for the site to function and to remain secure. These cannot be disabled without breaking the site.

| Name            | Purpose                                                                | Duration   | Provider         |
| --------------- | ---------------------------------------------------------------------- | ---------- | ---------------- |
| `__cf_bm`       | Cloudflare bot management: distinguishes humans from bots.             | 30 minutes | Cloudflare       |
| `cf_clearance`  | Cloudflare security verification.                                      | 1 year     | Cloudflare       |
| `CookieConsent` | Stores your cookie consent choices.                                    | 1 year     | Bioscope Foundry |
| `bf_session`    | Short-lived session identifier for form submissions and waitlist flow. | Session    | Bioscope Foundry |

### 2.2 Analytics cookies {#analytics-cookies}

Used to understand how the site is performing in aggregate (page views, referrers, broad usage patterns). Where required by law, we ask for your consent before setting analytics cookies; you can withdraw consent at any time.

| Name | Purpose | Duration | Provider |
| ---- | ------- | -------- | -------- |

We do not use advertising or cross-site behavioral tracking pixels (no LinkedIn Insight Tag, no Facebook Pixel, no Google Ads remarketing). Analytics tooling is being finalized; any measurement will be privacy-respecting, and this policy will be updated before any analytics cookie is set.

## 3. Cookies on the operating platform {#platform}

The authenticated operating platform uses only **strictly necessary** cookies. These maintain authenticated sessions, secure form submissions, and enforce HIPAA-relevant session timeouts.

| Name        | Purpose                                                                | Duration                                             | Flags                          |
| ----------- | ---------------------------------------------------------------------- | ---------------------------------------------------- | ------------------------------ |
| `bf_auth`   | Encrypted authentication session identifier.                           | Session (idle timeout 30 minutes, absolute 24 hours) | HttpOnly, Secure, SameSite=Lax |
| `bf_csrf`   | Cross-site request forgery protection token.                           | Session                                              | Secure, SameSite=Strict        |
| `bf_device` | Device identifier for anomaly detection and risk-based authentication. | Persistent                                           | HttpOnly, Secure               |

**No analytics, no marketing, no third-party trackers on the operating platform.** This restriction is intentional and is part of how we protect PHI. Blocking strictly-necessary cookies will prevent sign-in.

## 4. What we never use {#never}

- Third-party advertising cookies (no Google Ads, no LinkedIn Ads, no Meta Pixel, no TikTok Pixel).
- Cross-site behavioral tracking or fingerprinting.
- "Sale" or "sharing" of personal information for cross-context behavioral advertising under California, Colorado, or Virginia consumer-privacy laws.
- Tracking cookies, pixels, or session-replay tools on the operating platform.

## 5. Your choices {#controls}

- **Marketing site consent.** We present a cookie banner on `bioscopefoundry.com` that lets you accept or reject non-essential cookies and change your preferences later. Non-essential cookies are off by default until you opt in.
- **Browser controls.** Most browsers let you view, delete, or block cookies; check your browser's privacy settings. Note that blocking essential cookies will break sign-in to the operating platform.
- **Global Privacy Control (GPC).** When your browser or extension sends a [Global Privacy Control](https://globalprivacycontrol.org) signal, we treat it as a valid opt-out request under California Code of Regulations title 11, § 7025. Because we do not sell or share personal information for cross-context behavioral advertising, the GPC signal does not change which cookies we set, but it is recorded against your visit as an opt-out preference for any future change to that practice and is honored across the marketing site.
- **Do Not Track signals.** DNT is treated as informational only. GPC (above) is the signal we honor as an opt-out. Both are recorded; the GPC determination governs.
- **Privacy rights.** See our [Privacy Policy](/legal/privacy-policy/) for additional rights and how to exercise them.

## 6. Changes to this Cookie Policy {#changes}

We may update this policy from time to time. We will post the revised version here and update the "Last updated" date.

## 7. Contact {#contact}

Bioscope Foundry, LLC\
Privacy: <privacy@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

Related: [Privacy Policy](/legal/privacy-policy/) · [HIPAA Notice](/legal/hipaa-notice/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: cookie-policy.md -->

---



<!-- DOCUMENT START: hipaa-covered-services.md -->


_Legal · Attachment 1 to the BAA · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** The services and safeguards listed here describe Foundry's operating platform as currently architected. Not legal advice; have counsel review before publishing.

{{< /callout >}}

{{< callout type="info" >}}

The following Bioscope Foundry products and services are **"Covered Services"** under the [Business Associate Agreement (BAA)](/legal/business-associate-agreement/) when used by a physician practice in accordance with the Master Services Agreement and the BAA. Services not listed here are not Covered Services and must not be used to create, receive, maintain, or transmit PHI. PHI is stored in two Foundry-operated stores running on Foundry's cloud subprocessor: a clinical workflow database (relational) that is the workflow source of truth, and a Foundry-operated FHIR R4 service that serves clinical resources. PHI is never written to local disk, logs, prompts, or generated documents.

{{< /callout >}}

## 1. Operating platform (Conductor) {#platform}

Foundry's authenticated operating platform, internally referred to as _Conductor_, is the system of record for clinical and administrative workflows.

### 1.1 Clinical workflow database {#clinical-workflow-database}

| Attribute               | Detail                                                                                                                                                                                                                               |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Function                | Source of truth for clinical workflow: appointments, tasks, messaging, encounter state, follow-up tracking, and team coordination. Patient identifiers and clinical workflow context live here.                                      |
| Underlying subprocessor | Cloud infrastructure provider: managed relational database (see [Subprocessors](/legal/subprocessors/)). The database is Foundry-configured and Foundry-operated software running on the provider's managed service.               |
| PHI handled?            | Yes                                                                                                                                                                                                                                  |
| BAA in place?           | Yes, with the underlying cloud subprocessor.                                                                                                                                                                                         |
| Safeguards              | AES-256 encryption at rest under customer-managed KMS keys; TLS 1.2+ in transit; network-perimeter isolation; role-based access via the operating platform; short session timeouts; audit logging of all access (≥6-year retention). |
| HIPAA scope             | Designated Record Set for the Practice; access and amendment supported through Conductor.                                                                                                                                            |

### 1.2 FHIR clinical-resource service {#fhir-clinical-resource-service}

| Attribute               | Detail                                                                                                                                                                                                                                   |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Function                | FHIR R4 clinical-resource boundary: demographics, encounters, observations, medications, lab orders & results, clinical notes, and related resources served through a private, Foundry-operated HAPI FHIR service.                       |
| Underlying subprocessor | Cloud infrastructure provider: the FHIR service runs as a Foundry-controlled workload on the provider's managed compute; the FHIR software itself is HAPI FHIR (open source), self-hosted by Foundry and not a third-party subprocessor. |
| PHI handled?            | Yes                                                                                                                                                                                                                                      |
| BAA in place?           | Yes, with the underlying cloud subprocessor. No separate FHIR-vendor BAA is required because the FHIR service is Foundry-operated.                                                                                                       |
| Safeguards              | Private network reachability (no public endpoint); TLS 1.2+ in transit; underlying storage encrypted at rest under customer-managed KMS keys; role-based access via the operating platform's FHIR client; audit logging of all access.   |
| HIPAA scope             | Clinical-resource records for the Practice.                                                                                                                                                                                              |

### 1.3 Audit log & compliance surface {#audit-log-compliance-surface}

| Attribute               | Detail                                                                                                                                                       |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Function                | Audit log of access to PHI, who, when, which record(s), outcome, and compliance reporting surface.                                                           |
| Underlying subprocessor | Cloud infrastructure provider: managed logging plus application-level audit-events table in the workflow database.                                           |
| PHI handled?            | Identifiers only: audit rows record actor, action, target-type, target-id, and outcome using machine-readable codes; PHI content is not written to logs.     |
| BAA in place?           | Yes                                                                                                                                                          |
| Safeguards              | ≥6-year retention; access restricted to security and compliance roles; UPDATE and DELETE revoked at the database level for audit rows; integrity monitoring. |

## 2. Multi-agent system (Atlas & Forge Agents) {#agents}

Foundry's agent-orchestration platform, internally referred to as the _Foundry Master Agent_, coordinates a tiered set of AI agents that support practice operations. Tier eligibility for PHI is enforced at the policy spine; sandboxed public workers cannot hold PHI.

### 2.1 Atlas (Tier-0 orchestrator) {#atlas-tier-0-orchestrator}

| Attribute                | Detail                                                                                                                                                                                                                                                                                              |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Function                 | Tier-0 orchestration: routes work, applies policy, manages placement and migration of tasks across the agent fleet.                                                                                                                                                                                 |
| Underlying subprocessors | AWS-managed compute; Anthropic Claude API (under BAA) for reasoning; Foundry-controlled policy spine.                                                                                                                                                                                               |
| PHI handled?             | Yes: Atlas may receive PHI in agent reasoning contexts where Tier-3 clinical workflows require it; PHI flows to the Anthropic Claude API under BAA. The Beacon Layer enforces redaction before PHI crosses into physician-facing surfaces and before any task is dispatched to a Tier-4 Moltworker. |
| BAA in place?            | Yes                                                                                                                                                                                                                                                                                                 |
| Safeguards               | Policy-spine redaction before any cross-tier hop; never exposes raw PHI or peer-private memory to lower tiers.                                                                                                                                                                                      |

### 2.2 Tier-1 executive assistants (Goose & Maverick) {#tier-1-executive-assistants-goose-maverick}

| Attribute                | Detail                                                                                                                        |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------- |
| Function                 | Foundry-internal executive assistants supporting administrative workflows for Foundry staff (not Practice-scoped).            |
| Underlying subprocessors | Anthropic Claude API (Goose), under BAA; OpenAI API (Maverick) operates outside PHI scope.                                    |
| PHI handled?             | No, by policy: Tier-1 assistants operate over Foundry-internal data, not Practice PHI.                                        |
| BAA in place?            | Yes (defense-in-depth)                                                                                                        |
| Safeguards               | Policy spine blocks PHI from entering Tier-1 context; workforce confidentiality obligations; audit logs of agent invocations. |

### 2.3 Tier-2 Foundry ops & specialist agents {#tier-2-foundry-ops-specialist-agents}

| Attribute                | Detail                                                                                                 |
| ------------------------ | ------------------------------------------------------------------------------------------------------ |
| Function                 | Specialist agents for Foundry operations (vendor management, security operations, knowledge curation). |
| Underlying subprocessors | Anthropic Claude API (under BAA); Foundry-controlled hosts.                                            |
| PHI handled?             | No, by policy                                                                                          |
| BAA in place?            | Yes                                                                                                    |
| Safeguards               | Operations scope; no Practice or patient-scoped queries permitted.                                     |

### 2.4 Tier-3 clinic-scoped clinical agents {#tier-3-clinic-scoped-clinical-agents}

| Attribute                | Detail                                                                                                                                                                                                                                                         |
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Function                 | Practice-scoped agents that may handle PHI to support clinical-adjacent workflows (record summarization, message drafting, intake triage, prior-auth assembly). Outputs are advisory; a clinician reviews material decisions.                                  |
| Underlying subprocessors | Anthropic Claude API (under BAA); the managed FHIR service as the source of record.                                                                                                                                                                            |
| PHI handled?             | Yes                                                                                                                                                                                                                                                            |
| BAA in place?            | Yes                                                                                                                                                                                                                                                            |
| Safeguards               | Clinic-scoped data isolation; minimum-necessary PHI in any prompt; PHI not used to train or fine-tune general-purpose models; outputs logged; human-in-the-loop for clinical and compliance decisions; Beacon Layer redaction before any cross-tier surfacing. |

### 2.5 Tier-4 workers (Moltworkers) {#tier-4-workers-moltworkers}

| Attribute                | Detail                                                                                                                                                                                                 |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Function                 | Sandboxed-public workers for non-clinical, non-Practice tasks (for example, public-document drafting, marketing research, public-data ingestion).                                                      |
| Underlying subprocessors | Sandboxed compute on Foundry-managed hosts; LLM providers vary by task.                                                                                                                                |
| PHI handled?             | No, never                                                                                                                                                                                              |
| BAA in place?            | N/A (PHI is not permitted into this tier)                                                                                                                                                              |
| Safeguards               | **Tier-4 Moltworkers cannot handle PHI, clinic-scoped data, or peer-private memory.** The policy spine and host-agent enforcement prevent placement of any such workload on a `sandboxed_public` host. |

## 3. Communications surfaces {#communications}

### 3.1 Secure in-platform messaging {#secure-in-platform-messaging}

| Attribute               | Detail                                                                                                                     |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Function                | Authenticated messaging between Practice staff, providers, and patients within Conductor.                                  |
| Underlying subprocessor | Foundry-operated services on AWS, with content persisted in Foundry's FHIR service.                                        |
| PHI handled?            | Yes                                                                                                                        |
| BAA in place?           | Yes                                                                                                                        |
| Safeguards              | TLS in transit; AES-256 at rest; role-based access; audit logging; short idle timeouts; minimum-necessary patient context. |

### 3.2 Patient notification routing (SMS & email) {#patient-notification-routing-sms-email}

| Attribute                | Detail                                                                                                                                                                                    |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Function                 | Out-of-band notifications (appointment reminders, login codes, secure-message-waiting alerts). Designed to **avoid containing PHI**: clinical content stays inside authenticated systems. |
| Underlying subprocessors | Amazon SES (AWS, covered by the AWS BAA) for transactional email; SMS delivery, when enabled, will use a provider listed on the subprocessor page.                                        |
| PHI handled?             | Identifiers only by design.                                                                                                                                                               |
| BAA in place?            | Yes for the providers involved.                                                                                                                                                           |
| Safeguards               | Templates restrict content to non-PHI; rate limiting; audit logging; opt-out support.                                                                                                     |

## 4. Integrations & EHR bridges {#integrations}

| Attribute                | Detail                                                                                                                                                                                    |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Function                 | Integration with third-party clinical and administrative systems (EHR/EMR connectors, lab interfaces, e-fax, pharmacy connections) where elected by the Practice and listed on the Order. |
| Underlying subprocessors | Vary by integration; each PHI-touching integration is listed on the [Subprocessors](/legal/subprocessors/) page.                                                                        |
| PHI handled?             | Yes, where the integration carries PHI.                                                                                                                                                   |
| BAA in place?            | Yes with PHI-handling integration partners before any PHI flow.                                                                                                                           |
| Safeguards               | BAA execution gates production traffic; data flowing through Foundry is brokered through the FHIR R4 layer; per-integration audit logging.                                                |

## 5. What is _not_ a Covered Service {#out-of-scope}

The following are **not** Covered Services and must not be used to handle PHI:

- **The public marketing site** ([bioscopefoundry.com](https://bioscopefoundry.com)). It does not process PHI. Do not submit patient information through public forms.
- **Tier-4 Moltworkers** running on `sandboxed_public` hosts.
- **Workforce communication tools** Foundry uses internally (e.g., Slack, Linear); these are not on the PHI plane by policy; PHI is not introduced into them.
- **Beta, preview, or experimental features** not yet listed in this Attachment 1.
- **Third-party tools or integrations** the Practice elects to use outside the Services.

## 6. Cross-cutting safeguards {#safeguards}

All Covered Services are subject to the safeguards described in the BAA and the Foundry security program, including:

- **Encryption**: TLS 1.2+ in transit; AES-256 at rest; customer-managed keys available for the FHIR store.
- **Identity & access**: passwordless authentication, MFA-available, least-privilege role-based access, short idle/absolute session timeouts.
- **Audit logging**: every access to PHI is logged; logs record identifiers, not PHI content; retained for at least six years.
- **Network & secrets**: network-perimeter isolation around the PHI-handling account; managed secret broker; credentials never stored in source code.
- **Beacon Layer**: physician-facing insight surface is sanitized; raw PHI and peer-private memory never leak across tier boundaries.
- **Workforce**: confidentiality obligations, security and privacy training, sanctions process for violations.
- **Subprocessor governance**: every PHI-handling subprocessor is under a BAA; current list at [Subprocessors](/legal/subprocessors/).

## 7. Updates to this list {#updates}

Foundry may update this list of Covered Services from time to time. Foundry will provide at least 30 days' prior written notice to the Practice before removing a Covered Service that the Practice is actively using or before adding a new PHI-handling subprocessor under a Covered Service. Emergency security changes may occur on shorter notice with prompt follow-up notification.

See also: [Business Associate Agreement](/legal/business-associate-agreement/) · [HIPAA Notice](/legal/hipaa-notice/) · [Subprocessors](/legal/subprocessors/) · [Data protection policy](/docs/data-protection/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: hipaa-covered-services.md -->

---



<!-- DOCUMENT START: hipaa-notice.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** Prepared from Bioscope Foundry's platform architecture and HIPAA's business-associate framework. Not legal advice; have counsel review before publishing.

{{< /callout >}}

{{< callout type="info" >}}

Bioscope Foundry, LLC ("Foundry") is a management services organization. When we handle protected health information ("PHI") in the course of supporting a physician practice, we act as a **business associate** under the Health Insurance Portability and Accountability Act of 1996 and its regulations ("HIPAA"). The physician practice is the **covered entity**. This statement explains how we handle PHI on a practice's behalf and the commitments we make. **It is not a patient Notice of Privacy Practices**; each practice issues its own.

{{< /callout >}}

## 1. Our role under HIPAA {#role}

Foundry is not a healthcare provider and does not practice medicine. We provide operational and administrative services to independent physician practices. In doing so, we may create, receive, maintain, or transmit PHI on a practice's behalf, which makes us a HIPAA business associate to that practice. Each practice remains the covered entity responsible for its own privacy practices and its patient relationship.

**Where PHI is handled.** Our public website ([bioscopefoundry.com](https://bioscopefoundry.com)) does not process PHI. PHI is handled only within our authenticated operating platform, on HIPAA-eligible infrastructure, and only to the extent permitted by the practice's Business Associate Agreement.

## 2. Business Associate Agreements {#baa}

Before we handle PHI for a practice, we enter into a written Business Associate Agreement (BAA) with that practice. The BAA governs how we may use and disclose PHI, the safeguards we maintain, our breach-notification obligations, and the return or destruction of PHI when our engagement ends. Where required, we also obtain BAAs from our own subcontractors that may handle PHI. A copy of our standard BAA is available to prospective and current member practices on request at the contact below.

## 3. PHI we handle and why {#phi}

The PHI we handle depends on the services a practice uses and may include patient demographics, clinical records, encounters, medications, lab orders and results, and related documents. We handle this information only to support the practice's operations, for example, to operate the clinical and administrative platform, support communications and scheduling, route notifications, and maintain audit and security records, and only as permitted by the BAA.

## 4. Permitted uses and disclosures {#uses}

We use and disclose PHI only:

- To perform the services described in our agreement with the practice;
- As the practice directs and authorizes;
- For our proper management and administration, or to carry out our legal responsibilities, consistent with HIPAA; and
- As otherwise required by law.

We do not sell PHI, and we do not use or disclose PHI for marketing or for any purpose not permitted by the BAA or required by law.

## 5. Minimum necessary {#minimum}

We apply the "minimum necessary" principle: access to PHI is limited to the workforce members and systems that need it to perform a task, and to the least amount of PHI needed for that task.

## 6. Safeguards {#safeguards}

We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including:

- **Dedicated clinical data platform.** Patient records are stored and processed in Foundry's clinical data plane, a Foundry-operated workflow database and a private FHIR R4 service, both running on Foundry's HIPAA-eligible cloud infrastructure subprocessor, not on local devices.
- **Encryption.** PHI is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256, with the option of customer-managed keys).
- **Access controls.** Role-based, least-privilege access (provider, staff, patient) enforced before any request reaches the data store. Authentication is passwordless, federated single sign-on for staff and providers, and email or SMS one-time passcodes for patients, with multi-factor authentication available through the identity provider and short idle and absolute session timeouts.
- **Audit logging.** Access to PHI is logged, who, when, which records, and the outcome, with audit records retained for at least six years; logs are designed to record identifiers, not PHI content.
- **Network isolation and secret management.** Network perimeters around the PHI environment, restricted ingress, and a managed secret broker protect PHI systems and credentials; credentials that grant access to PHI are never stored in source code.
- **Communications discipline.** SMS and email notifications are designed to avoid containing PHI; clinical content stays within authenticated systems.
- **Backup and recovery.** Backup, continuity, and recovery practices are part of how the platform operates.
- **Workforce safeguards.** Workforce members are subject to confidentiality obligations and security practices.

Our security and AI-management program is structured to align with recognized standards, including ISO/IEC 27001 and ISO/IEC 42001, and follows practices informed by OWASP and NIST guidance. References to these frameworks describe our program structure; they do not assert third-party certification.

## 7. Subcontractors {#subs}

Where we use subcontractors that may handle PHI on our behalf, we require them, by written agreement, to provide protections at least as protective as those in our BAA with the practice. PHI-handling subprocessors operate under Business Associate Agreements (for example, our infrastructure provider, Amazon Web Services). A current list of subprocessors is maintained on the Foundry Trust Center.

## 8. Breach notification {#breach}

If we discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and in no event later than **thirty (30) calendar days** from discovery, well within the 60-calendar-day outer limit set by HIPAA at 45 CFR § 164.410(b). Where a practice's negotiated BAA sets a shorter window, that BAA controls. We will provide the practice with the information it needs to meet its own notification obligations and we will mitigate, to the extent practicable, any harmful effect known to us of any use or disclosure of PHI in violation of the BAA. We maintain an incident-response process for identifying, investigating, and responding to security incidents.

## 9. Supporting individual rights {#rights}

HIPAA gives patients rights over their health information, including rights to access, amend, and obtain an accounting of disclosures as provided by HIPAA. Those rights are exercised through the covered entity (the practice). As a business associate, we support practices in fulfilling these requests, for example, by making relevant records and audit information available, but we do not respond to patient rights requests directly unless the practice directs us to.

### 10. Information for patients {#patients style="margin-top: 0"}

If you are a patient, your rights regarding your health information are described in the **Notice of Privacy Practices issued by your physician's practice**. Please direct requests about your records, access, copies, amendments, or questions about how your information is used, to your practice. Foundry supports practices behind the scenes and is not your healthcare provider.

## 11. Contact {#contact}

Practices and partners with questions about Foundry's HIPAA practices or to request a BAA:

Bioscope Foundry, LLC\
HIPAA / Privacy contact: <privacy@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice. It is a business-associate statement, not a covered-entity Notice of Privacy Practices.

<!-- DOCUMENT END: hipaa-notice.md -->

---



<!-- DOCUMENT START: master-services-agreement.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: as set out in the executed Order · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft template for legal review.** A redlinable master services agreement, not an executed contract. Prepared from Foundry's MSO model. Not legal advice; have counsel review before signing.

{{< /callout >}}

{{< callout type="info" >}}

This Master Services Agreement (this "**Agreement**") is entered into between **Bioscope Foundry, LLC**, a Delaware limited liability company ("**Foundry**"), and the physician-owned medical practice identified in the executed Order (the "**Practice**"). It governs the administrative and management services Foundry provides to the Practice and the operating platform Foundry makes available to the Practice and its authorized personnel. **Foundry does not practice medicine and does not own any interest in the Practice.** The Practice remains 100% owned by its physician owner(s) and remains solely responsible for the practice of medicine and all clinical decisions.

{{< /callout >}}

## 1. Definitions {#definitions}

- **"Authorized User"** means an individual employed or contracted by the Practice who is authorized by the Practice to access the Services.
- **"Applicable Laws"** means all federal, state, and local laws, rules, regulations, and orders applicable to the parties' performance under this Agreement, including HIPAA and state corporate-practice-of-medicine laws.
- **"BAA"** means the [Business Associate Agreement](/legal/business-associate-agreement/) between Foundry and the Practice, incorporated by reference.
- **"Confidential Information"** means any non-public information disclosed by one party to the other that is marked confidential or that a reasonable person would understand to be confidential.
- **"Documentation"** means the user guides, technical documentation, and policy references that Foundry makes available for the Services.
- **"Foundry IP"** means the Services (including the operating platform, software, models, configurations, and underlying technology), Documentation, and any aggregated or de-identified data, and all improvements thereto.
- **"Order"** means an executed order form (or signed services schedule) that references and incorporates this Agreement and sets out the Services purchased, fees, and term.
- **"Patient"** means an individual who is a patient of the Practice.
- **"PHI"** has the meaning given to it under HIPAA.
- **"Practice Data"** means data, content, or information that the Practice or its Authorized Users input into, generate within, or otherwise provide to the Services, including PHI handled under the BAA.
- **"Services"** means the administrative, operational, and technology services Foundry provides under this Agreement and any Order, including access to Foundry's operating platform and the management services described in Section 2.
- **"Subscription Term"** means the term specified in the Order and any renewal terms.
- **"Support Terms"** means Foundry's then-current [Support Terms](/legal/support-terms/), incorporated by reference.

## 2. Services {#services}

### 2.1 Scope of Services {#scope-of-services}

Foundry provides administrative and management services to the Practice, including, as set out in the Order:

- Access to Foundry's operating platform (patient record management on Foundry's FHIR service / FHIR R4, scheduling, communications routing, and team coordination);
- Back-office and administrative support (intake, billing operations, vendor management, and compliance operations);
- An AI-enabled agent system that supports administrative and clinical-adjacent workflows under the safeguards described in this Agreement and the BAA;
- Identity, access, and security administration;
- Practice launch, growth, and onboarding support; and
- The Support Services described in the Support Terms.

**Administrative and management services only.** The Services are administrative and managerial; **Foundry does not provide medical, clinical, legal, tax, or accounting advice** and does not practice medicine. AI-assisted outputs are intended to augment, not replace, a physician's professional judgment.

### 2.2 License {#license}

Subject to the Practice's compliance with this Agreement and timely payment of fees, Foundry grants the Practice (and its Authorized Users) a non-exclusive, non-transferable, limited right during the Subscription Term to access and use the operating platform and Documentation solely for the Practice's internal business purposes in connection with operating the Practice.

### 2.3 Restrictions {#restrictions}

The Practice will not (and will not permit any Authorized User or third party to): (a) copy, modify, or create derivative works of any Foundry IP; (b) reverse engineer, decompile, or attempt to derive source code from Foundry IP; (c) sublicense, sell, rent, or otherwise transfer Foundry IP to any third party; (d) interfere with the security or operation of Foundry IP, or use Foundry IP in any manner that violates Applicable Laws; (e) use the Services to develop a competing service; or (f) use any robot, spider, scraper, or automated means to access the Services without Foundry's prior written consent.

### 2.4 Changes {#changes}

Foundry may modify the Services, Documentation, and Support Terms from time to time, including to comply with Applicable Laws, add or remove non-material functionality, or improve security. Foundry will provide reasonable advance notice of any material adverse change to the core Services.

## 3. Ownership and control of the Practice {#ownership-control}

The Practice is owned 100% by its physician owner(s). Nothing in this Agreement transfers ownership of, or grants Foundry any equity, voting right, or other ownership interest in, the Practice. **All clinical decisions, including diagnosis, treatment, prescribing, professional licensure, and the practice of medicine, remain the sole and exclusive responsibility of the Practice and its licensed physicians.** The parties intend that this Agreement complies with state laws restricting the corporate practice of medicine; nothing in this Agreement should be interpreted in a manner inconsistent with that intent.

## 4. Practice obligations {#practice-obligations}

### 4.1 Authorized Users {#authorized-users}

The Practice will determine the access controls and permissions of its Authorized Users and is solely responsible for activity occurring under its and its Authorized Users' accounts. The Practice will safeguard credentials, not share access, and will notify Foundry promptly of any unauthorized use or other suspected security breach.

### 4.2 Equipment {#equipment}

The Practice will maintain the internet access, devices, and supporting infrastructure required to access and use the Services.

### 4.3 Practice Data {#practice-data}

The Practice is solely responsible for Practice Data, including its accuracy, legality, and quality, and represents and warrants that it has the necessary rights and consents to provide Practice Data to Foundry and to permit Foundry's use of Practice Data to perform the Services. The Practice is solely responsible for obtaining patient authorizations and consents and for issuing its own Notice of Privacy Practices.

### 4.4 Compliance {#compliance}

The Practice will use the Services in compliance with Applicable Laws and the Practice's professional obligations, and will not request that Foundry use or disclose PHI in any manner that would violate HIPAA.

## 5. Fees and payment {#fees}

Fees for the Services, the billing schedule, and the mechanics of collection are set out in the applicable Order. Fees are exclusive of taxes; the Practice is responsible for applicable sales, use, and similar taxes (other than taxes on Foundry's net income). Changes to recurring fees take effect at the start of the next renewal term, with written notice before the renewal date.

## 6. Term, renewal, and offboarding {#term}

### 6.1 Term {#term-1}

The initial Subscription Term is set out in the Order and is, by default, 12 months from the Effective Date. Unless either party gives written notice of non-renewal at least 60 days before the end of the then-current term, the Subscription Term will automatically renew for successive periods equal to the initial term.

### 6.2 Clean offboarding {#clean-offboarding}

Foundry commits to a **90-day clean offboarding**. On termination or expiration of this Agreement, Foundry will, at the Practice's direction:

- Export Practice Data, including PHI, in standard, machine-readable formats (FHIR R4 for clinical data) within 90 days of termination;
- Transfer custody of practice-owned assets (domain, email, brand materials, patient records) to the Practice or a successor designated in writing by the Practice;
- Cooperate reasonably with a successor MSO or vendor to support continuity of care; and
- Return or destroy PHI as set out in the BAA.

Foundry will not condition offboarding on the resolution of any billing or commercial dispute or on entering a new commercial relationship.

## 7. Termination and suspension {#termination}

### 7.1 Termination for cause {#termination-for-cause}

A party may terminate this Agreement on written notice if the other party commits a material breach and fails to cure within 30 days of receiving notice of the breach. A party may also terminate immediately on written notice if the other party becomes insolvent, files for bankruptcy, or makes an assignment for the benefit of creditors.

### 7.2 Termination for convenience {#termination-for-convenience}

The Practice may terminate this Agreement for convenience on at least 90 days' prior written notice; any refund treatment is as set out in the Order, and the Practice retains its 90-day offboarding rights.

### 7.3 Suspension {#suspension}

Foundry may temporarily suspend access to the Services if (i) undisputed amounts due under the Order remain unpaid after written notice, (ii) Foundry reasonably determines continued use creates a security or compliance risk to the Services or to other practices, or (iii) Foundry reasonably believes the Practice is materially breaching this Agreement. Foundry will use commercially reasonable efforts to give prior notice and to promptly restore access once the issue is resolved.

### 7.4 Survival {#survival}

Sections that by their nature should survive (including Sections 3, 5, 6.2, 8, 9, 10, 12, 13, and 14) will survive termination or expiration of this Agreement.

## 8. Intellectual property {#ip}

### 8.1 Foundry IP {#foundry-ip}

Foundry owns and retains all right, title, and interest, including all intellectual-property rights, in and to Foundry IP and any modifications, enhancements, and derivative works thereof. No rights are granted by implication or estoppel.

### 8.2 Practice IP {#practice-ip}

The Practice owns and retains all right, title, and interest in Practice Data, the Practice's brand (including practice name, logo, and patient-facing materials), and the Practice's own clinical records and operational know-how. Foundry receives a limited, non-exclusive license to use Practice Data solely to perform the Services and as otherwise permitted under this Agreement and the BAA.

### 8.3 Aggregated and de-identified data {#aggregated-and-de-identified-data}

The Practice agrees that Foundry may generate aggregated and de-identified data from use of the Services (subject to the de-identification standard in the BAA and 45 C.F.R. § 164.514). Such data is owned by Foundry and may be used by Foundry to operate, secure, improve, and develop the Services, provided that it cannot reasonably be used to identify the Practice or any Patient.

### 8.4 Feedback {#feedback}

If the Practice or any Authorized User provides feedback or suggestions about the Services, Foundry may freely use that feedback without obligation, restriction, or compensation.

## 9. Practice data and PHI {#data}

### 9.1 PHI {#phi}

To the extent the Services involve PHI, each party's obligations regarding PHI are governed by the [Business Associate Agreement](/legal/business-associate-agreement/) incorporated into this Agreement by reference. The BAA controls any conflict between this Agreement and the BAA with respect to PHI.

### 9.2 Security {#security}

Foundry maintains administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Practice Data, as described in the BAA and in Foundry's published security program.

### 9.3 Acceptable use {#acceptable-use}

The Practice will not use the Services in any manner that violates Applicable Laws, infringes third-party rights, or introduces malware or other harmful code. The Practice will not use the Services to develop, train, or fine-tune competing AI systems or to extract Foundry IP.

## 10. Confidentiality {#confidentiality}

Each party will protect the other party's Confidential Information using at least the degree of care it uses to protect its own confidential information of similar sensitivity, but in no event less than reasonable care, and will use Confidential Information solely to perform under this Agreement; Confidential Information does not include information that (a) was known without a duty of confidentiality before disclosure; (b) is or becomes publicly available without breach; (c) is rightfully received from a third party without a duty of confidentiality; or (d) is independently developed without use of the Confidential Information. The receiving party may disclose Confidential Information if compelled by law, after giving the disclosing party prompt notice (if legally permitted) and reasonable cooperation to seek protective measures.

## 11. Representations and warranties {#warranties}

### 11.1 Mutual {#mutual}

Each party represents and warrants that (a) it is duly organized and validly existing under the laws of its jurisdiction of formation; (b) it has the full power and authority to enter into and perform this Agreement; and (c) this Agreement, when executed, will constitute a valid and binding obligation enforceable against it in accordance with its terms.

### 11.2 Foundry {#foundry}

Foundry will provide the Services in a professional and workmanlike manner and in material conformance with the Documentation. As the Practice's sole and exclusive remedy for a breach of this warranty, Foundry will use commercially reasonable efforts to remediate the issue identified in writing by the Practice.

### 11.3 Practice {#practice}

The Practice represents and warrants that:

- \(a\) it has all necessary rights, licenses, consents, and authorizations to provide Practice Data to Foundry and to permit Foundry's use of Practice Data to provide the Services;
- \(b\) it is, and at all times during the Subscription Term will remain, **100% owned by one or more physicians licensed in the United States (MD or DO)** who hold the entirety of its equity interests; no non-physician person or entity holds a direct or indirect equity interest in the Practice;
- \(c\) the Practice's structure, the relationship contemplated by this Agreement, and the Services Foundry provides comply with all applicable state corporate-practice-of-medicine, fee-splitting, anti-kickback, and self-referral laws of every jurisdiction in which the Practice operates, and the Practice has obtained any independent legal advice it deems necessary to make this representation;
- \(d\) all clinical decisions affecting Patients are made exclusively by licensed physicians or other appropriately licensed clinicians under the Practice's supervision; Foundry's role is administrative and non-clinical;
- \(e\) the Practice maintains its own professional-liability (malpractice) insurance, its HIPAA covered-entity obligations, and any state-specific health-information notices its Patients are entitled to receive; and
- \(f\) it will promptly notify Foundry if any representation in this Section 11.3 ceases to be true.

### 11.4 Disclaimer {#disclaimer}

EXCEPT FOR THE EXPRESS WARRANTIES IN THIS SECTION, THE SERVICES, FOUNDRY IP, AND ALL ASSOCIATED MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE," AND FOUNDRY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE. AI-ASSISTED OUTPUTS ARE NOT MEDICAL ADVICE; PHYSICIANS REMAIN SOLELY RESPONSIBLE FOR CLINICAL DECISIONS.

## 12. Indemnification {#indemnification}

### 12.1 By Foundry {#by-foundry}

Foundry will defend the Practice from and against any third-party claim arising out of:

- \(a\) **Intellectual property infringement**: an allegation that the Services, as provided by Foundry and used in accordance with this Agreement, infringe a third party's U.S. copyright, patent, or trademark; or
- \(b\) **Foundry breach or administrative negligence**: a claim arising from Foundry's material breach of the Business Associate Agreement, Foundry's gross negligence or willful misconduct in its handling of PHI or Practice Data, or a security incident affecting the Foundry-operated Services that is caused by Foundry (and not by the Practice, its Authorized Users, or factors outside Foundry's reasonable control). Without limiting the foregoing, this clause (b) includes the Practice's reasonable costs of HIPAA breach notification to affected Individuals, HHS, and the media, and the Practice's reasonable costs of responding to an HHS Office for Civil Rights investigation, where the breach is determined to have been caused by Foundry's act or omission.

Foundry will indemnify the Practice for damages and reasonable costs (including attorneys' fees) finally awarded against it or agreed in settlement under (a) or (b), provided that the Practice (i) promptly notifies Foundry in writing of the claim, (ii) gives Foundry sole control of the defense and settlement (subject to the Practice's right to participate at its own expense with counsel of its choice), and (iii) reasonably cooperates with the defense. The obligation in clause (a) does not apply to claims arising from (1) use of the Services in combination with data, software, hardware, or technology not provided by Foundry; (2) modifications not made by Foundry; (3) Practice Data; or (4) third-party services the Practice elects to use. The obligation in clause (b) does not apply to claims caused by the Practice's misuse, the Practice's breach of this Agreement or the BAA, or factors outside Foundry's reasonable control.

### 12.2 By the Practice {#by-the-practice}

The Practice will defend Foundry from and against any third-party claim arising out of (a) the Practice's (or its Authorized Users') misuse of the Services or Foundry IP; (b) Practice Data; (c) the Practice's violation of Applicable Laws or breach of its representations and warranties under this Agreement; or (d) any claim by or on behalf of a Patient relating to clinical care or outcomes, and will indemnify Foundry for damages and reasonable costs finally awarded or agreed in settlement.

## 13. Limitation of liability {#liability}

NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, CONSEQUENTIAL, INCIDENTAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES, OR FOR LOSS OF REVENUE, PROFITS, GOODWILL, OR DATA, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THESE LIMITATIONS ARE ESSENTIAL TERMS AND APPLY EVEN IF ANY REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

## 14. General {#general}

### 14.1 Independent contractors {#independent-contractors}

The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, franchise, agency, or employer-employee relationship.

### 14.2 Assignment {#assignment}

Neither party may assign this Agreement without the other's prior written consent, except in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets or equity. Any attempted assignment in violation of this Section is void.

### 14.3 Force majeure {#force-majeure}

Neither party will be liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, so long as the party uses commercially reasonable efforts to mitigate.

### 14.4 Notices {#notices}

Notices must be in writing and delivered to the addresses set out in the Order. Notice by email is effective on confirmed receipt.

### 14.5 Governing law and venue {#governing-law-and-venue}

This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules. The state and federal courts located in New Castle County, Delaware will have exclusive jurisdiction over any dispute arising out of or relating to this Agreement, and each party irrevocably submits to that jurisdiction and venue. The U.N. Convention on Contracts for the International Sale of Goods does not apply.

### 14.6 Integration {#integration}

This Agreement, together with the BAA, the Support Terms, any Orders, and any exhibits or addenda, constitutes the entire agreement between the parties on the subject matter and supersedes any prior or contemporaneous agreements or understandings. Terms in any purchase order or order documentation (other than the Order itself) are not incorporated. In the event of a conflict, the BAA controls with respect to PHI; otherwise, the Order controls over this Agreement, which controls over the Support Terms.

### 14.7 Severability {#severability}

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions will remain in full force and effect.

### 14.8 No third-party beneficiaries {#no-third-party-beneficiaries}

This Agreement is for the benefit of the parties only and does not confer rights on any third party.

## 15. Contact {#contact}

Bioscope Foundry, LLC\
Attn: Legal\
<legal@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

Related: [Business Associate Agreement](/legal/business-associate-agreement/) · [HIPAA-covered services](/legal/hipaa-covered-services/) · [Support Terms](/legal/support-terms/) · [Subprocessors](/legal/subprocessors/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: master-services-agreement.md -->

---



<!-- DOCUMENT START: privacy-policy.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** Prepared from Bioscope Foundry's public site and platform architecture. Not legal advice; review with qualified counsel before publication.

{{< /callout >}}

{{< callout type="info" >}}

This Privacy Policy explains how **Bioscope Foundry, LLC** ("Foundry," "we," "us," or "our") collects, uses, and shares information through [bioscopefoundry.com](https://bioscopefoundry.com) and the business and operational services we provide to physicians and their practices (together, the "Services"). **It does not govern protected health information (PHI) that we handle on behalf of a physician practice.** That information is governed by our Business Associate Agreement with the practice and described in our [HIPAA Notice & Business Associate Statement](/legal/hipaa-notice/).

{{< /callout >}}

## Our two environments {#environments style="margin-top: 24px"}

Foundry operates two distinct environments with different privacy and security practices. Where it matters, this policy notes which environment applies.

### Marketing site

`bioscopefoundry.com`: our public, informational website and application/waitlist. It uses cookies for site functionality and may use analytics. **It does not process PHI.** Do not submit patient information through public forms.

### Operating platform

The authenticated tools we operate for member practices and their staff. This environment runs under enhanced safeguards, uses only the cookies needed for security and authentication, and may handle PHI **solely as a business associate** under a BAA.

## 1. Who we are {#who}

Bioscope Foundry is an AI-enabled management services organization (MSO) that helps independent U.S. physicians (MD/DO) start, operate, and grow their own practices. We provide an operating layer, communication and scheduling support, team coordination, protocols and knowledge management, identity and access administration, systems integration, and launch and growth infrastructure, with AI assistance woven throughout. Physicians retain 100% ownership of their practices.

## 2. Scope of this policy {#scope}

This policy applies to information we collect from:

- **Visitors** to our marketing site, including people who contact us or join our waitlist.
- **Applicants and prospective members**: physicians who apply to or are evaluated for a founding cohort or membership.
- **Physician members and their staff** who use the operating platform and administrative tools we operate on their behalf.

This policy does **not** cover:

- **Patient health information (PHI) and other "medical information."** When we create, receive, maintain, or transmit PHI on behalf of a physician practice, we act as a HIPAA _business associate_. That information is governed by the Business Associate Agreement (BAA) between Foundry and the practice and described in our [HIPAA Notice](/legal/hipaa-notice/). Patients should consult their practice's own Notice of Privacy Practices for their rights regarding their health information. _For California consumers:_ medical information governed by HIPAA and the California Confidentiality of Medical Information Act (CMIA) is expressly excluded from the California Consumer Privacy Act under **Cal. Civ. Code § 1798.146(a)(2)–(3)**, so the California-specific disclosures in this policy do not apply to PHI we process as a business associate.
- **Third-party websites or services** that we link to but do not control.

## 3. Notice at collection {#notice-at-collection}

At or before the point we ask you for personal information, including on our waitlist form, applicant intake forms, the voice-first onboarding interview consent screen, payment forms, and e-signature flows, we present a short notice that identifies (i) the categories of personal information and sensitive personal information we are collecting at that moment, (ii) the business or commercial purposes for which it will be used, (iii) whether the information is sold or shared (it is not), and (iv) the retention period or the criteria used to determine it. That at-collection notice links back to this Privacy Policy for the full disclosures required by Cal. Civ. Code § 1798.100(b) and the CCPA regulations. The categories, sources, purposes, recipients, and retention periods that apply to each touchpoint are enumerated in the tables in §§4 and 11 below.

## 4. Information we collect {#collect}

The table below maps the personal information we collect from visitors, applicants, members, and practice staff to the categories enumerated in Cal. Civ. Code § 1798.140(v), and identifies the sources, business purposes, categories of recipients, and retention period for each. It covers the prior 12 months and our current practices.

| CCPA category (§ 1798.140(v))                                                  | Examples Foundry collects                                                                                                                                                                                           | Sources                                                                                                                                                  | Business purpose                                                                                                                                                                              | Categories of recipients                                                                                                                                                     | Retention                                                                                                                                                 |
| ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **A. Identifiers**                                                             | Legal name, email address, postal address, phone number, IP address, account identifiers, National Provider Identifier (NPI), Employer Identification Number (EIN) of the practice entity, doctor's date of birth.  | Directly from you (waitlist, application, onboarding); from CRM/pipeline tools when you are referred; from professional-credential verification sources. | Evaluate applications; verify professional eligibility; provision accounts, domains, and email; administer agreements; communicate with you; security and fraud prevention; legal compliance. | Service providers (hosting, email, CRM, identity/credential verification, registered-agent, workspace provisioning, e-signature); legal/regulatory recipients when required. | Active account + 7 years after closure (or the period required by applicable tax, corporate, or HIPAA recordkeeping rules, whichever is longer).          |
| **B. Customer records / commercial information** (§ 1798.140(v)(1)(B), (D))    | Practice name, specialty, planned or existing business details, agreements and signed contracts, payment-method tokens and transaction references (we do not store full card numbers), invoice and billing history. | Directly from you; from our payment processor and e-signature provider.                                                                                  | Provide, operate, and bill for the Services; administer agreements; maintain audit trails; tax and accounting compliance.                                                                     | Payment processor; e-signature provider; accounting and tax service providers; banking partner.                                                                              | 7 years from the close of the calendar year of the transaction (tax/business records); contracts retained for the longer of contract term + 7 years.      |
| **C. Internet or other electronic network activity** (§ 1798.140(v)(1)(F))     | IP address, browser and device type, pages viewed, referring URLs, session timing, interactions with the marketing site, authentication and audit-log events on the operating platform.                             | Automatically from your browser/device when you visit the marketing site or use the operating platform; from analytics and security tooling.             | Operate and secure the Services; understand site usage; detect and prevent fraud, abuse, and security incidents.                                                                              | Hosting provider (Cloudflare); analytics provider (being finalized); security/logging provider.                                                                              | Marketing-site analytics: up to 14 months. Platform audit/security logs: at least 6 years (HIPAA-aligned).                                                |
| **D. Geolocation data** (§ 1798.140(v)(1)(G))                                  | Approximate (city/region-level) location inferred from IP address for security and fraud-prevention purposes. We do **not** intentionally collect precise geolocation (within 1,850 feet).                          | Automatically from your IP address.                                                                                                                      | Security, fraud prevention, login anomaly detection, regional service routing.                                                                                                                | Hosting provider; security tooling.                                                                                                                                          | 90 days for fraud/security signals; longer where embedded in a retained audit log.                                                                        |
| **E. Audio, electronic, visual, or similar information** (§ 1798.140(v)(1)(H)) | Voice recordings of the onboarding interview, generated transcripts and structured fields derived from those responses, and any voice/video submitted to support.                                                   | Directly from you, with notice and consent obtained before recording begins.                                                                             | Conduct the onboarding interview; generate a practice launch plan; evaluate fit for membership; train internal reviewers; quality assurance.                                                  | Voice-AI provider under contract; internal reviewers; e-signature/CRM where the transcript is attached to an application.                                                    | Raw audio: 24 months after the interview, then deleted (extracted transcripts and structured fields retained for the life of the application/membership). |
| **F. Professional or employment-related information** (§ 1798.140(v)(1)(I))    | Medical license number and state, NPI, specialty, board certifications, training/credential history, current and prior practice affiliations, professional references.                                              | Directly from you; from credential-verification sources (e.g., state medical-board lookups, NPPES); from references you authorize us to contact.         | Verify eligibility for membership; perform compliance and quality-of-care diligence; provision regulated accounts that require NPI.                                                           | Credential-verification providers; e-signature/CRM; legal/regulatory recipients on request.                                                                                  | Life of the application or membership + 7 years.                                                                                                          |
| **G. Inferences drawn from the above** (§ 1798.140(v)(1)(K))                   | Internal scores, tags, and summaries derived from your application materials and interview (e.g., readiness indicators, launch-timeline categorizations, internal fit notes).                                       | Generated by Foundry from the categories above; AI-assisted draft outputs reviewed by humans before any material decision.                               | Evaluate applications; tailor onboarding; internal analytics. Inferences are not used for advertising and are not sold or shared.                                                             | Internal personnel only; the underlying inputs may reach the recipients listed elsewhere in this table.                                                                      | Life of the application or membership; deleted on request unless retention is required by law.                                                            |

We do not knowingly collect personal information from minors (see §15). We do not collect biometric identifiers within the meaning of § 1798.140(v)(1)(E) for identification purposes; voice audio collected during onboarding is treated as Sensitive Personal Information (see §5).

### Information from third parties

We receive information from our customer-relationship and pipeline tools when a physician is referred or progresses through evaluation, and from identity- and credential-verification sources (including state medical-board lookups and the NPPES NPI registry) used to confirm professional eligibility.

## 5. Sensitive Personal Information {#spi}

Under Cal. Civ. Code § 1798.140(ae) and § 1798.121, specified categories of personal information are designated **Sensitive Personal Information** ("SPI"). The SPI Foundry collects, and the purpose for each, is:

- **Account log-in credentials** in combination with any password, security question, or access code that would permit access to an account, collected only to authenticate you to the operating platform; secrets are stored hashed or in managed secret stores, never in plain text.
- **National Provider Identifier (NPI)**: treated as a professional identifier used to verify physician eligibility and to provision regulated accounts that require it.
- **Payment-method tokens** (financial account information), collected via our payment processor to bill for the Services. Foundry does not store full card numbers.
- **Voice recordings** made during the onboarding interview, audio data is processed only to conduct the interview, generate transcripts, and inform membership decisions. Recordings are not used for biometric identification.
- **Precise geolocation**, if and only if we ever collect it (see §4(D)). We currently do not, and would update this section before doing so.

Foundry uses Sensitive Personal Information **only for the purposes permitted by Cal. Civ. Code § 1798.121(b) and 11 CCR § 7027**: namely: performing the services you have requested; preventing, detecting, and investigating security incidents; resisting malicious, deceptive, fraudulent, or illegal actions and prosecuting those responsible; ensuring the physical safety of individuals; short-term, transient processing (such as non-personalized advertising shown as part of your current interaction); performing services on behalf of the business (such as account servicing); verifying or maintaining the quality of services; and the limited internal uses to build or improve our offering that the regulation permits. We do **not** use SPI to infer characteristics about you. See §13 for your right to limit our use of SPI.

## 6. How we use information {#use}

We use the information above to:

- Respond to inquiries, manage the waitlist, and evaluate applications;
- Provide, operate, maintain, and improve the Services;
- Conduct onboarding interviews and generate practice launch plans;
- Provision accounts, domains, email, and related infrastructure;
- Process payments and administer agreements;
- Communicate with you about your application, account, and service updates;
- Maintain security, prevent fraud and abuse, and keep audit trails; and
- Comply with legal, regulatory, and contractual obligations.

We rely on your consent (for example, before recording an interview), the performance of our agreement with you, our legitimate business interests, and our legal obligations as the bases for these uses.

## 7. AI-assisted processing & automated decision-making {#ai}

AI assistance is part of how the Services operate. Our onboarding interview uses a third-party generative-AI voice model to conduct the conversation and to help extract structured information from your responses, AI assistance supports back-office workflows, and our internal "Beacon Layer" surfaces de-identified, sanitized insights to physicians. AI outputs are intended to **augment, not replace,** human judgment.

**Automated decision-making technology notice (Cal. Code Regs. tit. 11 §§ 7220–7222).** Foundry uses automated decision-making technology ("ADMT") to assist with:

- **AI-assisted onboarding interviews**: a voice-AI agent conducts a structured conversation and extracts fields and themes from your responses;
- **AI-assisted membership and compliance evaluations**: internal drafts of fit, readiness, and risk indicators are prepared by AI and presented to a human reviewer; and
- **Beacon Layer insight generation**: sanitized, identifier-stripped operational signals are summarized for physicians' own decision-making.

**Logic and intended outcomes.** The systems use general-purpose large language and speech models prompted to (i) elicit and structure factual information you provide, (ii) compare your application materials against documented eligibility and quality criteria, and (iii) draft summaries for human review. They do not make final decisions about acceptance, denial, pricing, or termination on their own; **a qualified Foundry team member reviews and is responsible for any material decision before it takes effect.**

**Your rights.** You may (a) request a plain-language explanation of how ADMT was used in a decision that significantly affects you, (b) ask that a human reconsider the decision, and (c) where the regulations require, opt out of the ADMT use. Submit requests to <privacy@bioscopefoundry.com>; we will respond within the time required by applicable law.

Any AI processing of PHI occurs only through HIPAA-eligible services covered by a Business Associate Agreement. We may use de-identified or aggregated data (which cannot reasonably identify you) to improve our services, as permitted by law. Our program aligns with recognized AI-management and information-security standards (including ISO/IEC 42001 and ISO/IEC 27001); references to these standards describe our program structure.

## 8. How we share information {#share}

We do **not sell** personal information and do **not share** it for cross-context behavioral advertising as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah). We disclose personal information only as described here:

- **Service providers and contractors** processing information on our behalf under written contracts that restrict their use to the disclosed business purposes (see §9). Categories include hosting and infrastructure; email/communications; CRM and pipeline tools; payment processing; e-signature; identity and credential verification; voice-AI for onboarding interviews; registered-agent and entity-formation; workspace provisioning; security, audit, and observability tooling; legal, accounting, and professional advisors.
- **With your direction**: for example, with providers we engage to stand up your practice.
- **Legal and safety**: to comply with law, subpoena, or legal process; to enforce our agreements; or to protect the rights, safety, and property of Foundry, our members, or others.
- **Business transfers**: in connection with a merger, acquisition, financing, or sale of assets, where we will seek assurances that the recipient honors this policy.

## 9. Service providers {#providers}

We rely on a limited set of vetted service providers to host data, deliver email, process payments, and otherwise operate the Services, and we impose contractual limits on their use of information they process on our behalf. The current list is maintained at our [Subprocessors](/legal/subprocessors/) page. **Where any service provider may create, receive, maintain, or transmit PHI, we enter into a Business Associate Agreement requiring HIPAA-compliant protections before any PHI is shared.**

## 10. Cookies & analytics {#cookies}

Cookie use differs by environment:

- **Marketing site (`bioscopefoundry.com`).** We use cookies and similar technologies to operate the site, remember preferences, and understand usage, and we may use analytics.
- **Operating platform.** We use only the cookies strictly necessary for security and authentication, and we do not use analytics or marketing tracking there.

You can control cookies through your browser settings; disabling some cookies may affect site functionality. See our [Cookie Policy](/legal/cookie-policy/) for the cookie inventory, durations, and how we honor opt-out preference signals such as Global Privacy Control.

## 11. Data retention {#retention}

We retain each category of personal information for the period set out below, or for as long as needed to provide the Services, operate our business, and meet legal, tax, and regulatory obligations, whichever is longer, after which we delete or de-identify it. Retention is determined by reference to (a) the duration of our relationship with you and any contractual obligations, (b) statutory and regulatory recordkeeping requirements (including HIPAA's six-year minimum for required documentation and seven-year tax recordkeeping), (c) the limitations period for legal claims, and (d) the operational need to maintain security and audit trails.

| Category                                                                      | Retention period                                                                                                                           | Criteria                                                                                     |
| ----------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------- |
| Waitlist and inquiry data (visitors)                                          | 24 months from last contact, then deleted.                                                                                                 | Operational need; deletes earlier on request.                                                |
| Application materials (non-accepted applicants)                               | 24 months from final disposition.                                                                                                          | Defense of decisions; civil-rights limitations periods.                                      |
| Member account data (identifiers, customer records, professional information) | Life of the membership + 7 years.                                                                                                          | Contract performance; tax/business recordkeeping.                                            |
| Voice interview audio                                                         | 24 months after the interview, then deleted; extracted transcripts and structured fields retained as application/membership records above. | Minimization of audio retention; preserve the structured outputs that informed any decision. |
| Payment-method tokens and transaction records                                 | 7 years from the calendar year of the transaction.                                                                                         | Tax and financial recordkeeping.                                                             |
| Marketing-site analytics                                                      | Up to 14 months.                                                                                                                           | Provider default; reduced where the provider supports it.                                    |
| Security, access, and audit logs (operating platform)                         | At least 6 years.                                                                                                                          | HIPAA § 164.316(b)(2); incident-response needs.                                              |
| Cookies (per-cookie durations)                                                | See [Cookie Policy](/legal/cookie-policy/).                                                                                              | Functional/preference/security needs.                                                        |
| Records associated with PHI (governed by HIPAA, not this policy)              | Per the BAA; HIPAA-required documentation retained for at least 6 years from creation or last effective date.                              | HIPAA § 164.316(b)(2).                                                                       |

## 12. How we protect information {#security}

We maintain administrative, physical, and technical safeguards designed to protect information, including:

- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or customer-managed keys);
- Passwordless authentication and role-based, least-privilege access controls;
- Audit logging and monitoring of access to sensitive systems;
- Network isolation and managed secret storage for credentials; and
- Backup, continuity, and recovery practices.

No system is perfectly secure; we work to keep our safeguards current and review them as the business changes.

## 13. Your privacy rights {#rights}

Depending on where you live, you may have the right to **access**, **correct**, **delete**, and receive a **portable** copy of your personal information, to **opt out** of processing activities covered by applicable law, and to be free from **discrimination** for exercising these rights. We respond within the time required by applicable law (generally 45 days for CCPA, extendable by 45 days with notice). To make a request, contact <privacy@bioscopefoundry.com>; we will verify your identity before responding and will explain any denial in writing. If we deny a request, you may appeal by replying to our response.

Because Foundry acts as a service provider/business associate for PHI, requests about _patient health information_ are directed to the relevant physician practice. If you believe we have processed your information unlawfully, you may also contact the attorney general of your state of residence.

## 14. California consumers {#california}

California residents receive the following disclosures required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), and the implementing regulations (11 CCR §§ 7000 _et seq._). It supplements, and where it conflicts, controls over, the rest of this policy for California consumers. PHI that we process as a HIPAA business associate is excluded from the CCPA under Cal. Civ. Code § 1798.146 and is governed by the BAA and our [HIPAA Notice](/legal/hipaa-notice/) instead.

### 14.1 Your California rights {#your-california-rights}

- **Right to know** (Cal. Civ. Code §§ 1798.110, 1798.115). You have the right to request, twice per 12-month period, that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting or sharing it, and the categories of third parties to whom we have disclosed it. The categorical disclosures appear in §4 above; for specific pieces, submit a verifiable request to <privacy@bioscopefoundry.com>.
- **Right to delete** (§ 1798.105). You may request that we delete personal information we collected from you, subject to the statutory exceptions (for example, to complete a transaction, detect security incidents, comply with legal obligations, or for internal uses reasonably aligned with your expectations).
- **Right to correct** (§ 1798.106). You may request that we correct inaccurate personal information we maintain about you. We will use commercially reasonable efforts to correct verified inaccuracies, taking into account the nature of the information and the purposes for which we use it.
- **Right to data portability** (§ 1798.130(a)(3)). When you exercise your right to know, you may receive your personal information in a _structured, commonly used, and machine-readable format_ that allows you to transmit it to another entity without hindrance, typically JSON or CSV.
- **Right to opt out of sale or sharing** (§ 1798.120). **Foundry does not sell personal information and does not share it for cross-context behavioral advertising.** No "Do Not Sell or Share My Personal Information" link is therefore required by § 1798.135(b)(1). If at any time we change this practice, we will update this policy and post the required opt-out link before any sale or sharing begins. We honor browser-based **Global Privacy Control (GPC)** signals as a valid consumer request to opt out of sale or sharing per 11 CCR § 7025, even though we have determined we do not sell or share.
- **Right to limit use and disclosure of Sensitive Personal Information** (§ 1798.121). You may direct us to use the Sensitive Personal Information listed in §5 only for the purposes permitted by § 1798.121(b) and 11 CCR § 7027. Because we already restrict our use of SPI to those permitted purposes, no separate "Limit the Use of My Sensitive Personal Information" link is required by § 1798.135(a)(2); if our practices change, we will post one before expanding our use of SPI.
- **Right to non-discrimination** (§ 1798.125). We will not deny goods or services, charge different prices or rates, provide a different level or quality of service, or retaliate against you for exercising any of these rights. Foundry does not operate financial-incentive or loyalty programs that would require additional disclosures under § 1798.125(b).
- **Right regarding automated decision-making** (Cal. Code Regs. tit. 11 §§ 7220–7222). See §7 above for our ADMT disclosure and how to exercise the access and opt-out rights it provides.
- **Right of consumers under 16 to opt in** (§ 1798.120(c)). Foundry does not knowingly collect personal information from consumers under 16, and we do not sell or share personal information of any consumer, including minors. If we change this practice, we will obtain affirmative opt-in consent from consumers between 13 and 16, and parental opt-in for those under 13, before any sale or sharing.
- **Shine the Light** (Cal. Civ. Code § 1798.83). California residents may request information about disclosures of personal information to third parties for those third parties' direct-marketing purposes. We do not disclose personal information for third-party direct marketing.

### 14.2 How to submit a request {#how-to-submit-a-request}

Submit a verifiable consumer request by emailing <privacy@bioscopefoundry.com>. Include enough information for us to verify your identity, typically your name, the email address(es) we have on file, and a description of the request. We may ask for additional information to confirm your identity (for example, matching information against records you have previously provided), and we will not require you to create an account solely to submit a request. We will confirm receipt within 10 business days and respond substantively within 45 calendar days (extendable by an additional 45 days with notice). If we deny a request, you may appeal by replying to our response.

### 14.3 Authorized agents {#authorized-agents}

You may use an authorized agent to submit a request on your behalf, in accordance with Cal. Civ. Code § 1798.140(b) and 11 CCR § 7063. For us to act on an agent's request, we will require (i) written, signed permission from you authorizing the agent to act on your behalf (or a valid power of attorney under Cal. Probate Code §§ 4000–4465), (ii) verification of your own identity directly with us, and (iii) confirmation from you that you have authorized the agent. Agents that are businesses must be registered with the California Secretary of State as required by § 1798.140(b). We may deny a request from an agent that does not submit proof of authorization.

### 14.4 Notice at collection {#notice-at-collection-1}

Per Cal. Civ. Code § 1798.100(b), we provide a short notice at or before the point of collection on intake forms (waitlist, applications, voice-interview consent, payment, e-signature) summarizing the categories collected, the business purposes, retention, and a link to this policy. See §3 above.

### 14.5 Other California laws {#other-california-laws}

California Civil Code § 1798.83 ("Shine the Light") is addressed above. California Insurance Information and Privacy Protection Act and California Financial Information Privacy Act do not apply to Foundry's services.

## 15. Children's privacy {#children}

The marketing site and Services are intended for physicians and their businesses and are not directed to children, and we do not knowingly collect personal information from children through the site.

## 16. U.S. operations {#intl}

Foundry serves U.S. physicians and operates in the United States. If you access the site from outside the U.S., you understand your information will be processed in the United States.

## 17. Changes to this policy {#changes}

We may update this policy from time to time. We will post the revised version here and update the "Last updated" date. **Material changes that reduce your rights or materially expand the categories of personal information we collect, the purposes for which we use it, or the parties with whom we share it will take effect no sooner than 30 days after we post the updated policy**, and we will provide additional notice where required by law (for example, by email to account holders or a banner on the marketing site). Clarifications, corrections, and changes that _expand_ your rights or _narrow_ our practices may take effect immediately.

## 18. Contact us {#contact}

Questions or requests about this policy or your information:

Bioscope Foundry, LLC\
Privacy contact: <privacy@bioscopefoundry.com>\
General: <info@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: privacy-policy.md -->

---



<!-- DOCUMENT START: subprocessors.md -->


_Legal · Transparency · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** List is current as of June 2026. Foundry provides advance notice of changes per the BAA. Not legal advice.

{{< /callout >}}

{{< callout type="info" >}}

Bioscope Foundry engages the third-party service providers listed below ("**subprocessors**") to deliver the Services. Subprocessors that may create, receive, maintain, or transmit Protected Health Information ("PHI") on Foundry's behalf are bound by a Business Associate Agreement ("BAA") providing protections at least as protective as those Foundry owes its member practices. PHI lives only inside a Foundry-operated FHIR R4 service running on Foundry's cloud infrastructure subprocessor (see the entry below); the FHIR service itself is self-hosted by Foundry and is therefore not a distinct third-party subprocessor.

{{< /callout >}}

## 1. PHI-bound subprocessors (BAA in place) {#phi-bound}

These providers may handle PHI on Foundry's behalf and are operating under an executed BAA.

| Subprocessor                         | Purpose                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Location     | PHI?                                       | BAA?                                         | Effective     |
| ------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------ | ------------------------------------------ | -------------------------------------------- | ------------- |
| **Amazon Web Services, Inc.**        | Cloud infrastructure provider for the operating platform. Hosts the clinical workflow database (Amazon RDS for PostgreSQL), the private Foundry-operated HAPI FHIR service (Amazon ECS) that serves clinical FHIR resources, encrypted object storage (S3 with AWS KMS-CMK), the managed secrets store (AWS Secrets Manager) that brokers Foundry-owned credentials, and the onboarding control-plane workloads (EventBridge / Scheduler / SQS). PHI resides in the RDS clinical database and the HAPI FHIR service. AWS is the relevant cloud subprocessor for PHI infrastructure; the FHIR service itself is not a distinct third party; it is Foundry-operated software running inside AWS. | U.S. regions | Yes (PHI is stored on AWS-managed storage) | Yes                                          | On engagement |
| **Google LLC: Google Workspace**     | Workforce identity, corporate email, and productivity (Docs / Drive / Calendar / Meet). Used for internal collaboration; PHI is prohibited from Workspace surfaces by policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | U.S. regions | Identifiers only                           | Yes (precaution; PHI scope is out by design) | On engagement |
| **Anthropic, PBC**                   | Claude API: AI reasoning for the multi-agent system, including clinic-scoped (Tier-3) workflows that may include PHI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | U.S.         | Yes                                        | Yes                                          | On engagement |
| **OpenAI OpCo, LLC**                 | OpenAI API. Powers the Maverick Tier-1 executive assistant; not used by Atlas / Tier-3 clinical agents (those run on Anthropic). PHI scope is excluded by Foundry policy and routing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | U.S.         | No                                         | BAA in progress                              | On engagement |
| **Amazon SES (Amazon Web Services)** | Out-of-band transactional email (login codes, secure-message-waiting alerts). PHI excluded from message body by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | U.S.         | Identifiers only                           | Yes (covered by the AWS BAA)                 | On engagement |

## 2. Non-PHI subprocessors {#non-phi}

These providers support Foundry's business operations and do not handle PHI. PHI is not permitted into these systems by policy.

| Subprocessor                             | Purpose                                                                                                                                                                                                                                                                                                                                               | Location                              | PHI?                  | BAA?                                         | Effective     |
| ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------- | --------------------- | -------------------------------------------- | ------------- |
| **Cloudflare, Inc.**                     | CDN, DNS, edge security, and Workers Static Assets hosting for the customer-marketing and exploratory web surfaces (`bioscopefoundry.com` and other public Foundry web properties). No PHI traverses the edge.                                                                                                                                        | Global edge (origin in U.S.)          | No                    | N/A                                          | On engagement |
| **1Password, Inc. (AgileBits)**          | Workforce password manager and credential vault. Two configurations: (a) a Foundry-operated Stage-1 vault used to provision new Practice administrator credentials during onboarding, and (b) the Connect API used to deliver Stage-2 vaults to Practice owners. Stores credentials and MFA material for Foundry's operational SaaS accounts. No PHI. | U.S.                                  | No (credentials only) | N/A                                          | On engagement |
| **GitHub, Inc.** (Microsoft)             | Source-code hosting and continuous integration. No PHI in source or CI by policy.                                                                                                                                                                                                                                                                     | U.S.                                  | No                    | N/A                                          | On engagement |
| **Slack Technologies, LLC** (Salesforce) | Workforce communications. PHI is not introduced into Slack by policy.                                                                                                                                                                                                                                                                                 | U.S.                                  | No                    | N/A                                          | On engagement |
| **Linear Orbit, Inc.**                   | Engineering and operations work tracking. PHI is not introduced into Linear by policy.                                                                                                                                                                                                                                                                | U.S.                                  | No                    | N/A                                          | On engagement |
| **Notion Labs, Inc.**                    | Internal documentation and knowledge management. PHI is not introduced into Notion by policy.                                                                                                                                                                                                                                                         | U.S.                                  | No                    | N/A                                          | On engagement |
| **Stripe, Inc.**                         | Payment processing for Practice fees (non-PHI).                                                                                                                                                                                                                                                                                                       | U.S.                                  | No                    | N/A                                          | On engagement |
| **DocuSeal**                             | Electronic signature for agreements (MSA, BAA, Orders), self-hosted by Foundry. No PHI in signature envelopes.                                                                                                                                                                                                                                        | U.S. (Foundry-controlled environment) | No                    | N/A (self-hosted, no third-party processing) | On engagement |
| **Mercury Technologies, Inc.**           | Banking and treasury operations for Foundry (internal). No customer data.                                                                                                                                                                                                                                                                             | U.S.                                  | No                    | N/A                                          | On engagement |
| **Attio Ltd.**                           | Customer relationship management (CRM) for prospective and current member practices. Business contact data only, no PHI.                                                                                                                                                                                                                              | U.S. / U.K.                           | No                    | N/A                                          | On engagement |
| **Granola Labs, Inc.**                   | Meeting-notes tooling (internal). No PHI by policy.                                                                                                                                                                                                                                                                                                   | U.S.                                  | No                    | N/A                                          | On engagement |

## 3. Notice of changes {#notice}

This list is current as of **June 2026**. Foundry will:

- Provide member Practices at least **30 days' prior written notice** before engaging any new subprocessor that may handle PHI, per the [BAA](/legal/business-associate-agreement/);
- Update this page when subprocessors are added, removed, or materially change in scope; and
- Maintain BAAs with all PHI-handling subprocessors before any PHI flow.

If a Practice objects to a new PHI-handling subprocessor on a reasonable, articulable risk basis, the Practice may exercise its termination rights as set out in the BAA and the Master Services Agreement.

## 4. Contact {#contact}

Questions about Foundry's subprocessors or to request additional detail:

Bioscope Foundry, LLC\
Privacy: <privacy@bioscopefoundry.com>\
Security: <security@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

Related: [Business Associate Agreement](/legal/business-associate-agreement/) · [HIPAA-covered services](/legal/hipaa-covered-services/) · [Vendor & third-party risk policy](/docs/vendor/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: subprocessors.md -->

---



<!-- DOCUMENT START: support-terms.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** Prepared from Foundry's operations practices. Not legal advice; have counsel and the operations lead review before publishing.

{{< /callout >}}

{{< callout type="info" >}}

These Support Terms govern the technical and operational support services ("**Support Services**") that Bioscope Foundry, LLC ("Foundry") provides to a physician practice (the "Practice") under the [Master Services Agreement](/legal/master-services-agreement/), and are incorporated into it by reference. In the event of a conflict between these Support Terms and the Agreement, the Agreement controls; with respect to PHI, the [BAA](/legal/business-associate-agreement/) controls.

{{< /callout >}}

## 1. Scope {#scope}

### 1.1 Included Support {#included-support}

During the Subscription Term, Foundry provides the following at no additional charge:

- Assistance with platform functionality and usage;
- Troubleshooting of technical issues and errors;
- Guidance on best practices for using the operating platform;
- Account management, role-assignment, and access-control support;
- Routine platform maintenance, security patches, and platform updates;
- Performance monitoring and infrastructure maintenance;
- Onboarding assistance for new Authorized Users and access to user-facing documentation.

### 1.2 Excluded {#excluded}

The following are not included in Support Services and may be available as professional services for an additional fee:

- Custom development or modifications to the platform;
- Integration with third-party systems not listed on the Order;
- Training beyond standard onboarding and documentation;
- Data migration from legacy systems;
- Issues caused by the Practice's misuse of the Services or breach of the Agreement;
- Issues arising from the Practice's devices, network, or third-party software outside Foundry's control;
- Restoration of data lost due to actions or negligence of the Practice or its Authorized Users;
- Support for unsupported browsers, operating systems, or devices;
- Medical, clinical, legal, tax, or regulatory advice.

## 2. Support tiers and severity levels {#tiers}

### 2.1 Support tiers {#support-tiers}

Foundry offers three support tiers; the Practice's tier is set out in the Order.

| Tier                   | Audience                                                       | SEV-1 availability                                    | Channels                                               | Named contact                     |
| ---------------------- | -------------------------------------------------------------- | ----------------------------------------------------- | ------------------------------------------------------ | --------------------------------- |
| **Standard** (default) | All member Practices                                           | 24x7 for SEV-1                                        | Email & in-platform                                    | Shared support queue              |
| **Priority**           | Practices with extended onboarding or higher operational tempo | 24x7 for SEV-1 and SEV-2                              | Email, in-platform, and a dedicated escalation address | Named Foundry operations contact  |
| **Critical**           | Practices with elevated risk or multi-location footprint       | 24x7 for SEV-1 and SEV-2; same-business-day for SEV-3 | Email, in-platform, and a named on-call contact        | Named operations lead with backup |

Tier-specific pricing and entitlements are set out on the Order.

### 2.2 Severity levels {#severity-levels}

#### SEV-1: Critical {#sev-1-critical}

- **Definition:** Complete loss of the operating platform affecting all or substantially all Authorized Users, or any security or privacy incident reasonably believed to involve PHI.
- **Examples:** platform unavailable; suspected or confirmed unauthorized access to PHI; loss of clinical record access for an active patient encounter.
- **Response:** immediate prioritization on receipt.
- **Workaround / mitigation:** continuous effort until critical functionality is restored or an acceptable workaround is in place.
- **Availability:** 24x7, every day.

#### SEV-2: High {#sev-2-high}

- **Definition:** Significant functionality is impaired and a workaround is not readily available, affecting multiple Authorized Users.
- **Examples:** a key workflow (scheduling, messaging, agent surface) is broken; significant performance degradation; an integration is failing.
- **Response:** prioritized ahead of routine work, during Business Hours (24x7 for Priority and Critical tiers).
- **Resolution:** commercially reasonable efforts toward prompt resolution.
- **Availability:** Business Hours (24x7 for Priority and Critical tiers).

#### SEV-3: Medium {#sev-3-medium}

- **Definition:** Minor functionality issue with a workaround available.
- **Response:** handled during Business Hours in priority order.
- **Resolution:** commercially reasonable efforts, prioritized by impact.
- **Availability:** Business Hours.

#### SEV-4: Low {#sev-4-low}

- **Definition:** Questions, documentation clarifications, feature requests, cosmetic issues.
- **Response:** addressed during Business Hours as capacity allows, typically in an upcoming release.
- **Target resolution:** Best effort.
- **Availability:** Business Hours.

### 2.3 Priority assignment {#priority-assignment}

Foundry assigns severity in good faith based on the criteria above. If the Practice believes a request should be escalated, it may request escalation with justification; the operations lead reviews escalation requests.

## 3. Channels {#channels}

- **Email, general support:** <support@bioscopefoundry.com>
- **Email, security incidents:** <security@bioscopefoundry.com>
- **Email, privacy inquiries:** <privacy@bioscopefoundry.com>
- **In-platform**: contextual help, ticket submission, and status updates.
- **Documentation**: user guides and operational references available in the platform.

SEV-1 requests should use the in-platform incident button or the dedicated escalation address provided to Priority and Critical-tier Practices. Phone-based on-call is not offered at launch.

## 4. Response targets and availability {#response}

### 4.1 Business hours {#business-hours}

Foundry's standard business hours are Monday through Friday, 9:00 a.m. to 6:00 p.m. Eastern Time, excluding U.S. federal holidays.

### 4.2 How targets are measured {#how-targets-are-measured}

Response time is measured from receipt of a properly submitted support request to Foundry's initial substantive response. Resolution time is measured from receipt to the time the issue is resolved or an acceptable workaround is in place. Times for non-SEV-1 issues are computed against Business Hours; SEV-1 times run continuously.

### 4.3 Continuous effort for SEV-1 {#continuous-effort-for-sev-1}

For SEV-1 issues, Foundry will use commercially reasonable efforts to provide continuous updates and to work toward restoration or an acceptable workaround until the critical functionality is restored.

## 5. Escalation {#escalation}

- **Level 1: Support engineer.** Initial triage and response.
- **Level 2:** The Operations lead is reached automatically for SEV-1 and SEV-2 and is reachable by the Practice on request.
- **Level 3: Security & privacy lead.** Engaged for any incident reasonably believed to involve PHI or the security of the platform; the security and privacy lead is the Practice's HIPAA point of contact.
- **Level 4: Executive sponsor.** Available for sustained, unresolved issues at Priority and Critical tiers.

Foundry maintains an internal on-call rotation; on-call coverage is 24x7 for SEV-1 incidents.

## 6. Remote access and PHI controls {#remote}

Support work is conducted under the same HIPAA safeguards that apply to the production environment.

- **No PHI export by Foundry support.** Foundry support personnel do not download, copy, or otherwise export PHI to local devices, email, screenshots, or third-party tools. Any data needed for diagnosis is reviewed in place under the production access controls.
- **Least-privilege, just-in-time access.** Support access to systems containing PHI is role-based, time-bound, and recorded; standing access is minimized.
- **All access is logged.** Each support session that touches a PHI-bearing system produces an audit log entry, who, when, which records, what action, retained for at least six years.
- **No PHI in support tickets.** Practices and Foundry agree not to include PHI in ticket text, email subject lines, or attachments. References should use record identifiers, not patient content.
- **Workforce safeguards.** Support personnel are bound by confidentiality obligations, complete HIPAA training, and are subject to the workforce sanctions process for violations.
- **Remote-control sessions.** Where a live screen-share is needed, the Practice initiates and controls the session; Foundry does not maintain persistent remote-control capability over Practice devices.

## 7. Maintenance windows {#maintenance}

### 7.1 Scheduled maintenance {#scheduled-maintenance}

- **Standard window:** Sundays, 02:00-06:00 Eastern Time, up to twice per month.
- **Notice:** at least 72 hours in advance for scheduled maintenance, posted in-platform and emailed to designated contacts.
- **Emergency maintenance** may be performed at any time to address a security vulnerability, critical bug, or system-stability issue; Foundry will give as much advance notice as is reasonably practicable.

### 7.2 Platform availability {#platform-availability}

Foundry works to keep the operating platform available and communicates scheduled maintenance in advance as described in Section 7.1. Foundry responds to availability incidents affecting the operating platform under the severity framework and response targets in Sections 2 and 4. Foundry is a management services organization and the operating platform depends on third-party cloud and SaaS providers; accordingly, these Support Terms do not make any numeric availability commitment and do not provide service credits. This does not limit the Practice's other rights under the Agreement (including termination for material breach) or Foundry's HIPAA obligations to the Practice as a Business Associate.

### 7.3 Inadvertent PHI in support communications {#inadvertent-phi-in-support-communications}

If the Practice submits a ticket, email, or screen-share that contains PHI, Foundry will: (a) redact the PHI from the support record on receipt; (b) destroy the original PHI-bearing artifact; (c) log the inadvertent disclosure in the audit record (identifier only, no PHI body); and (d) confirm completion of (a)–(c) to the submitter. Live screen-share sessions are not recorded by Foundry by default; if a session is recorded with the Practice's consent, the recording is retained in the Foundry-controlled environment, treated as PHI-sensitive, and deleted on the Practice's request.

## 8. Practice responsibilities {#practice-responsibilities}

For Foundry to investigate and resolve issues effectively, the Practice will:

- Provide contact information, environment details, and a description of the issue (steps to reproduce, expected vs. actual behavior, time of occurrence, impact);
- Designate a primary support contact and at least one backup;
- Not include PHI in ticket text or attachments; use record identifiers only;
- Cooperate with Foundry's troubleshooting, including implementing reasonable workarounds while permanent fixes are developed;
- Maintain reasonable backups and independent records of any data the Practice considers business-critical, beyond what Foundry maintains for the platform;
- Use support resources reasonably and refrain from abusing emergency channels for non-critical issues.

## 9. Limitations and disclaimers {#limitations}

- **Best-effort response and resolution times.** Response and resolution times are targets based on commercially reasonable efforts, not guarantees; Foundry does not offer service credits or any other financial remedy for missed targets or for platform availability.
- **Workarounds.** Foundry may provide a workaround or temporary solution while a permanent fix is in progress.
- **Beta features.** Features labeled beta, preview, or experimental are provided as-is with limited support and may be modified or withdrawn.
- **Third-party issues.** Foundry is not responsible for issues caused by third-party services, the Practice's network or devices, or events beyond Foundry's reasonable control.
- **No clinical advice.** Support personnel are not licensed healthcare providers and do not interpret clinical results, make clinical recommendations, or provide medical advice.

## 10. Changes to these Terms {#changes}

Foundry may modify these Support Terms from time to time by posting an updated version here and notifying the Practice's primary contact. Changes that expand support coverage or improve service levels may take effect immediately. Changes that materially reduce support coverage or service levels take effect **thirty (30) days** after notice. Continued use of the Services after the effective date constitutes acceptance.

## 11. Contact {#contact}

Bioscope Foundry, LLC\
Support: <support@bioscopefoundry.com>\
Security incidents: <security@bioscopefoundry.com>\
Privacy: <privacy@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

Related: [Master Services Agreement](/legal/master-services-agreement/) · [Business Associate Agreement](/legal/business-associate-agreement/) · [Incident response policy](/docs/ir/).

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: support-terms.md -->

---



<!-- DOCUMENT START: terms-of-service.md -->


_Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026_

{{< callout type="warning" >}}

**Draft for legal review.** Prepared from Bioscope Foundry's public site and platform architecture. Not legal advice; have counsel review before publishing.

{{< /callout >}}

{{< callout type="info" >}}

These Terms of Service ("Terms") govern your access to and use of [bioscopefoundry.com](https://bioscopefoundry.com) and its content, forms, and waitlist (the "Site"). They are an agreement between you and **Bioscope Foundry, LLC** ("Foundry," "we," "us," or "our"). The Site is informational. **Foundry's management services to a physician practice are provided only under a separate written services agreement**; if that agreement conflicts with these Terms for those services, the services agreement controls.

{{< /callout >}}

## 1. Acceptance of these Terms {#accept}

By accessing or using the Site, you agree to these Terms and to our [Privacy Policy](/legal/privacy-policy/). If you do not agree, do not use the Site.

## 2. Eligibility {#eligibility}

The Site is intended for use by individuals who are at least 18 years old. The Services are offered to licensed U.S. physicians (MD/DO) and their authorized personnel. By applying, you represent that the information you provide is accurate and that you are authorized to provide it.

## 3. The Site and the Services {#site}

The Site describes Foundry's MSO operating layer and lets you learn about, apply for, or join the waitlist for membership. Content on the Site is provided for general informational purposes and may change without notice. Nothing on the Site is an offer, guarantee of acceptance, or commitment to provide services. Foundry does not practice medicine, does not provide medical, legal, tax, or accounting advice, and does not own or control member practices, which remain owned by their physicians.

**Reliance on information.** We do not warrant that information on the Site is accurate, complete, or current, and any reliance you place on it is at your own risk. We may update content from time to time but are under no obligation to do so; the Site does not process patient information; do not submit protected health information through it.

## 4. Applications and waitlist {#waitlist}

Submitting an application or joining the waitlist does not create a services relationship and does not guarantee admission to any cohort or program. Foundry may accept, decline, or prioritize applications at its discretion. Any services we later provide are governed by a separate written agreement.

## 5. No medical advice {#nomedical}

The Site does not provide medical advice, diagnosis, or treatment, and nothing on it should be relied upon for clinical decisions. Physicians remain solely responsible for the practice of medicine and for clinical decisions, professional licensure, and compliance with applicable laws and standards of care.

## 6. Accessing the Site {#access}

We reserve the right to withdraw or amend the Site, and any service or material we provide on it, in our sole discretion and without notice. We will not be liable if for any reason all or any part of the Site is unavailable at any time or for any period, and we may restrict access to parts or all of the Site from time to time. To access the Site or some of its features, you may be asked to provide registration details or other information; it is a condition of your use that all such information is correct, current, and complete, and you consent to our handling of it consistent with our [Privacy Policy](/legal/privacy-policy/).

## 7. Accounts and security {#accounts}

If you are granted access to a member portal or onboarding tools, you must treat your access credentials as confidential and must not disclose them to, or share access with, anyone else. Your account is personal to you, and you are responsible for all activity under it. Authentication is passwordless; protect the email account and devices used to sign in, ensure you exit your account at the end of each session, and notify us immediately of any unauthorized access or other breach of security. We may disable any credential or identifier at any time in our sole discretion, including if we believe you have violated these Terms.

## 8. Prohibited uses {#acceptable}

You may use the Site only for lawful purposes and in accordance with these Terms. You agree not to:

- Use the Site in any way that violates any applicable federal, state, local, or international law or regulation;
- Submit information you are not authorized to share, or that is false or misleading;
- Upload or transmit patient health information through the Site's public forms;
- Use the Site in any manner that could disable, overburden, damage, or impair it, or interfere with any other party's use of the Site;
- Attempt to gain unauthorized access to, interfere with, damage, or disrupt the Site, the server on which it is stored, or any connected server, computer, or database, or attack the Site via a denial-of-service or distributed denial-of-service attack;
- Introduce any viruses, Trojan horses, worms, logic bombs, or other material that is malicious or technologically harmful, or circumvent security or rate limits;
- Use any robot, spider, scraper, or other automatic device, process, or means to access, monitor, or copy the Site or its content without our prior written consent;
- Use the Site or any of its content to train, develop, or fine-tune any deep-learning, machine-learning, large language model, or other artificial-intelligence system, including any neural network, statistical-learning algorithm, or reinforcement-learning system; or
- Infringe the rights of Foundry or any third party.

## 9. Intellectual property {#ip}

The Site and its entire contents, features, and functionality, including all text, design, graphics, logos, images, and the selection and arrangement thereof, are owned by Foundry, its affiliates, or its licensors and are protected by United States and international copyright, trademark, patent, trade secret, and other intellectual-property laws. Certain names and logos on the Site, including "Bioscope Foundry," are trademarks of Foundry or its affiliates; you must not use them without our prior written permission. These Terms permit you to use the Site for your personal, non-commercial use only. You must not reproduce, distribute, modify, create derivative works of, publicly display, republish, download, store, or transmit any material on the Site except as necessary to access and use it for its intended purpose. No right, title, or interest in the Site is transferred to you, and all rights not expressly granted are reserved. Consistent with Foundry's ownership model, physician members own their own practice brand, clinical records, and core practice assets as set out in their services agreement.

## 10. Links from the Site {#thirdparty}

The Site may contain links to third-party websites and services (for example, scheduling, payments, e-signature, and communications providers, or informational resources). These links are provided for your convenience only; we have no control over and accept no responsibility for the content of those sites or services or for any loss or damage that may arise from your use of them. If you access any third-party link, you do so at your own risk and subject to that third party's terms.

## 11. Privacy {#privacy}

Our [Privacy Policy](/legal/privacy-policy/) describes how we handle information collected through the Site and Services. Protected health information we handle on behalf of a practice is governed by our [HIPAA Notice](/legal/hipaa-notice/) and the applicable Business Associate Agreement.

## 12. Geographic restrictions {#geo}

Foundry is based in the United States and offers the Site and Services to U.S. physicians. We make no claims that the Site or its content is accessible or appropriate outside the United States; if you access the Site from elsewhere, you do so on your own initiative and are responsible for compliance with local law.

## 13. Disclaimer of warranties {#disclaimer}

You understand that we cannot and do not guarantee that files available for downloading from the internet or the Site will be free of viruses or other destructive code, and you are responsible for implementing sufficient safeguards and anti-virus protection and for maintaining a means external to the Site to reconstruct any lost data.

The Site, its content, and any services or items obtained through it are provided "as is" and "as available" without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability and fitness, as well as warranties of title and non-infringement. We do not warrant that the Site will be accurate, reliable, error-free, uninterrupted, or secure, that defects will be corrected, or that the Site or its server are free of viruses or other harmful components.

## 14. Limitation of liability {#liability}

To the fullest extent permitted by law, in no event will Foundry, its affiliates, or their officers, directors, employees, contractors, agents, suppliers, and service providers be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenues, data, or goodwill, arising out of or relating to your use of, or inability to use, the Site, even if advised of the possibility of such damages. To the fullest extent permitted by law, Foundry's total liability arising out of or relating to the Site will not exceed one hundred U.S. dollars (\$100).

Some jurisdictions do not allow these limitations, so some of the above may not apply to you; these limits do not apply to liabilities that cannot be limited by law.

## 15. Indemnification {#indemnity}

You agree to defend, indemnify, and hold harmless Foundry, its affiliates, and their officers, directors, employees, contractors, agents, suppliers, and service providers from and against any claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees (including reasonable attorneys' fees) arising out of your misuse of the Site, your violation of these Terms, or your violation of any law or third-party right.

## 16. Governing law and jurisdiction {#law}

These Terms and any dispute or claim arising out of or related to them or the Site are governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws rules. Any legal suit, action, or proceeding arising out of or relating to these Terms or the Site will be instituted exclusively in the state or federal courts located in New Castle County, Delaware, and you waive any objection to the exercise of jurisdiction over you by, and to venue in, those courts.

## 17. Changes to these Terms {#changes}

We may revise and update these Terms from time to time in our sole discretion. All changes are effective immediately when posted and apply to all access to and use of the Site thereafter. Your continued use of the Site following the posting of revised Terms means you accept the changes.

## 18. Contact {#contact}

Bioscope Foundry, LLC\
Email: <info@bioscopefoundry.com>\
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.

<!-- DOCUMENT END: terms-of-service.md -->

---

