Business Associate Agreement
Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: as set out in the executed Order · Last updated: June 23, 2026
1. Definitions
Capitalized terms not otherwise defined here have the meaning given to them in HIPAA or in the Agreement.
- “Breach” has the meaning given to it under HIPAA.
- “Business Associate” has the meaning given to it under HIPAA.
- “Covered Entity” has the meaning given to it under HIPAA.
- “Covered Services” means the Foundry products and services listed in Attachment 1: HIPAA-Covered Services, as Foundry may update from time to time with at least 30 days’ prior written notice to the Practice (or with such notice as is reasonable under the circumstances for an emergency change).
- “Designated Record Set” has the meaning given to it under HIPAA.
- “HIPAA” means the Health Insurance Portability and Accountability Act of 1996 and the rules and regulations thereunder, as amended, including the Privacy Rule, Security Rule, and Breach Notification Rule, together with the HITECH Act and its implementing regulations.
- “Individual” has the meaning given to it under HIPAA and includes a personal representative qualifying under HIPAA.
- “Patient” means an Individual who is a patient of the Practice and for whom the Practice is using the Covered Services in connection with treatment or operations.
- “PHI” means Protected Health Information as defined under HIPAA, limited for purposes of this BAA to PHI that Foundry creates, receives, maintains, or transmits on behalf of the Practice through the Covered Services.
- “Required by Law” has the meaning given to it under HIPAA.
- “Secretary” means the Secretary of the U.S. Department of Health and Human Services or their designee.
- “Security Incident” has the meaning given to it under HIPAA.
- “Subcontractor” means a person or entity to whom Foundry delegates a function, activity, or service that involves the creation, receipt, maintenance, or transmission of PHI on behalf of the Practice.
2. Applicability
This BAA applies to the extent the Practice acts as a Covered Entity (or as a Business Associate to another Covered Entity) creating, receiving, maintaining, or transmitting PHI through a Covered Service, and to the extent Foundry, as a result, acts as a Business Associate or Subcontractor under HIPAA.
This BAA does not apply to: (a) Foundry products, services, or features not listed as Covered Services; (b) PHI that the Practice creates, receives, maintains, or transmits outside of the Covered Services; or (c) services provided by third parties that are not Subcontractors of Foundry, including third-party applications or integrations the Practice elects to use.
3. Permitted uses and disclosures of PHI
3.1 General limitations
Except as otherwise stated in this BAA, Foundry may use and disclose PHI only (i) as permitted or required by the Agreement and this BAA; (ii) as Required by Law; or (iii) as otherwise permitted under HIPAA for a Business Associate. Foundry will not sell PHI and will not use or disclose PHI for marketing as defined under HIPAA except as expressly permitted by this BAA and applicable law.
3.2 Service operations
Foundry may use and disclose PHI as reasonably necessary to perform the Covered Services for the Practice, including to operate the clinical data platform, route administrative communications, schedule and coordinate care operations, generate audit and security records, and otherwise carry out the management services described in the Agreement.
3.3 Proper management and administration
Foundry may use and disclose PHI for its proper management and administration and to carry out its legal responsibilities, provided that any disclosure of PHI for these purposes may occur only if (a) Required by Law, or (b) Foundry obtains written reasonable assurances from the recipient that the PHI will be held in confidence, used only for the purpose for which it was disclosed, and that Foundry will be notified of any Breach or Security Incident involving the PHI.
3.4 De-identification and aggregation
Subject to the Agreement, Foundry may (a) provide data aggregation services relating to the Practice’s health care operations and (b) de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c). Once de-identified in accordance with HIPAA, such data is no longer PHI and is not subject to this BAA.
3.5 AI-assisted processing
The Practice acknowledges that the Covered Services include AI-assisted features that may process PHI to support the Practice’s operations (for example, to draft communications, summarize records, route messages, and surface insights for a clinician’s review). Foundry will not use PHI to train or fine-tune general-purpose AI models. Any AI processing of PHI occurs only through HIPAA-eligible services covered by a BAA. AI outputs are intended to augment, not replace, human judgment.
4. Practice obligations
4.1 Permissible requests
The Practice will not request that Foundry or the Covered Services use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Practice (or by the Covered Entity to which the Practice is a Business Associate), unless expressly permitted under HIPAA for a Business Associate.
4.2 Implementation and configuration
The Practice will use the access controls, role assignments, and configuration options available within the Covered Services to ensure that its use of PHI is limited to the Covered Services and to the workforce members who need access. The Practice is solely responsible for ensuring that its and its authorized users’ use of the Covered Services complies with HIPAA.
4.3 Patient notice and consent
The Practice is solely responsible for issuing its own Notice of Privacy Practices and obtaining all necessary authorizations and consents from its patients as required by HIPAA and other applicable laws.
4.4 Minimum necessary
The Practice will limit disclosures of PHI to Foundry to the minimum necessary to accomplish the intended purpose, except for disclosures for treatment.
5. Appropriate safeguards
Foundry will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, including electronic PHI, that it creates, receives, maintains, or transmits on behalf of the Practice, in accordance with 45 C.F.R. Part 164, Subpart C. Such safeguards include, without limitation:
- Storage and processing of PHI on a HIPAA-eligible cloud healthcare platform (Foundry’s FHIR service, FHIR R4), under Foundry’s BAAs with its infrastructure providers;
- Encryption of PHI in transit (TLS 1.2 or higher) and at rest (AES-256, with the option of customer-managed keys);
- Role-based, least-privilege access controls, with passwordless authentication and multi-factor authentication available through the identity provider;
- Audit logging of access to PHI, designed to record identifiers, not PHI content, retained for at least six (6) years;
- Network isolation, managed secret storage, and segregated production environments for systems that touch PHI;
- Workforce confidentiality obligations and security training;
- Communications discipline: SMS and email notifications are designed to avoid containing PHI; clinical content remains within authenticated systems; and
- Backup, continuity, and recovery practices.
The Practice will also use appropriate safeguards designed to prevent unauthorized use or disclosure of PHI in its handling of the Covered Services.
6. Reporting and breach notification
6.1 Breach notification
Foundry will notify the Practice of any Breach of unsecured PHI without unreasonable delay, and in no event later than thirty (30) calendar days after Foundry discovers the Breach (and in any event no later than the 60-day outer limit set by HIPAA at 45 C.F.R. § 164.410(b)). Foundry will also notify the Practice of any Security Incident of which Foundry becomes aware, subject to Section 6.3.
6.2 Mitigation
As required by 45 C.F.R. § 164.504(e)(2)(ii)(C), Foundry will mitigate, to the extent practicable, any harmful effect that is known to Foundry of a use or disclosure of PHI by Foundry in violation of the requirements of this BAA, including, where appropriate, providing the Practice with the information necessary to support the Practice’s mitigation actions toward affected Individuals.
6.3 Notification contents
Each notification under Section 6.1 will describe, to the extent then known: (a) the nature of the Breach or Security Incident, including the categories and approximate number of Individuals and PHI records affected; (b) the steps taken to investigate, contain, and mitigate the incident; (c) the steps Foundry recommends the Practice take; and (d) contact information for Foundry’s designated security contact. Foundry will provide the information necessary for the Practice to meet its own HIPAA notification obligations under 45 C.F.R. §§ 164.404, 164.406, and 164.408, and will supplement the report as additional information becomes available.
6.4 Unsuccessful security incidents
This Section 6.4 serves as notice to the Practice that Foundry periodically receives unsuccessful attempts to access, use, disclose, modify, or destroy information, or to interfere with normal operation of its systems (for example, pings, port scans, blocked login attempts, and unsuccessful denial-of-service attempts). Foundry will not provide individual notice of these events.
6.5 Notification method
Foundry will deliver notifications under this Section 6 to the email address designated by the Practice in the Order or via direct communication with the Practice’s designated administrator, or by such other means as the parties agree in writing.
7. Subcontractors
Foundry will require any Subcontractor that creates, receives, maintains, or transmits PHI on Foundry’s behalf to agree in writing to restrictions and conditions that are at least as protective as those that apply to Foundry under this BAA. Foundry remains responsible for the performance of its Subcontractors as if performed by Foundry. A current list of Subcontractors that may handle PHI is maintained at Subprocessors; Foundry will provide the Practice with at least 30 days’ prior notice before engaging any new Subcontractor that will have access to PHI.
8. Access and amendment
The Practice is solely responsible for the form and content of PHI maintained by it within the Covered Services, including whether it maintains such PHI in a Designated Record Set within the Covered Services. Foundry will provide the Practice with access to PHI via the Covered Services so that the Practice may fulfill its obligations under HIPAA with respect to Individuals’ rights of access and amendment. Foundry will not respond to Individual rights requests directly unless directed in writing by the Practice to do so.
9. Accounting of disclosures
Foundry will document disclosures of PHI by Foundry and provide an accounting of such disclosures to the Practice as and to the extent required of a Business Associate under HIPAA and in accordance with 45 C.F.R. § 164.528. On the Practice’s reasonable request, Foundry will provide the information necessary for the Practice to respond to an Individual’s accounting request within 30 days.
10. Access to records
To the extent required by law, and subject to all applicable legal privileges, Foundry will make its internal practices, books, and records concerning the use and disclosure of PHI received from the Practice, or created or received by Foundry on behalf of the Practice, available to the Secretary to determine compliance with this BAA and HIPAA.
11. Term and termination
11.1 Term
This BAA becomes effective on the BAA Effective Date and will terminate on the earlier of: (a) a permitted termination in accordance with Section 11.2; or (b) the expiration or termination of all Orders under which the Practice has access to a Covered Service. The default initial term aligns with the Agreement, currently 12 months.
11.2 Termination for material breach (cure or report)
If either party materially breaches this BAA, the non-breaching party may terminate this BAA on 30 days’ written notice unless the breach is cured within the 30-day period. If a cure is not reasonably possible, the non-breaching party may immediately terminate this BAA. Consistent with 45 C.F.R. § 164.504(e)(1)(ii), if neither termination nor cure is reasonably possible, the non-breaching party may, in lieu of termination, report the violation to the Secretary of the U.S. Department of Health and Human Services, subject to applicable legal privileges.
11.3 Effect of early termination
If this BAA is terminated earlier than the Agreement, the Practice must immediately cease using the Covered Services to create, receive, maintain, or transmit PHI. Foundry will discontinue further creation, receipt, maintenance, or transmission of PHI on behalf of the Practice through the Covered Services, except to the extent necessary to complete return or destruction of PHI under Section 12 or to honor the Practice’s HIPAA recordkeeping obligations.
12. Return or destruction of PHI
On termination of the Agreement, Foundry will return or destroy all PHI received from the Practice, or created or received by Foundry on behalf of the Practice, including PHI held by Foundry’s Subcontractors. The Practice’s clean-offboarding right is described in the Master Services Agreement; PHI export is delivered in standard FHIR R4 within ninety (90) calendar days of termination. If return or destruction is not feasible, for example, where PHI is held within immutable backup systems on commercially reasonable retention timers, Foundry will extend the protections of this BAA to the PHI not returned or destroyed, limit further uses and disclosures to those purposes that make return or destruction infeasible, and delete the PHI when the backup retention period expires. Foundry may also retain PHI to the extent required by applicable law, in which case Foundry will isolate and protect the PHI from further processing except as required by law and delete it when no longer required.
13. Miscellaneous
13.1 Survival
Sections 6 (Reporting), 10 (Access to Records), 12 (Return or Destruction), and this Section 13 will survive termination or expiration of this BAA.
13.2 Regulatory changes
The parties agree to take such action as is reasonably necessary to amend this BAA from time to time as required for compliance with changes in HIPAA or other applicable law.
13.3 Interpretation
Any ambiguity in this BAA will be interpreted to permit compliance with HIPAA. In the event of any conflict between this BAA and the Agreement with respect to PHI, this BAA controls.
13.4 Governing law
This BAA is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules. The dispute-resolution provisions of the Agreement apply to this BAA.
13.5 No third-party beneficiaries
Nothing in this BAA is intended to confer rights or remedies on any person other than the parties, except that Individuals may exercise their rights under HIPAA as provided by law.
13.6 Entire agreement
This BAA, together with the Agreement and any applicable Orders, constitutes the entire agreement between the parties with respect to its subject matter and supersedes any prior business-associate arrangements between them.
14. Contact
Questions about this BAA, or to request execution of a BAA before exchanging PHI, contact:
Bioscope Foundry, LLC
Attn: Privacy Officer
Privacy: privacy@bioscopefoundry.com
Security: security@bioscopefoundry.com
Legal: legal@bioscopefoundry.com
11939 N. Meridian Street, Suite 125, Carmel, IN 46032
See also: HIPAA Notice & Business Associate Statement · List of HIPAA-covered services · Subprocessors.
© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.