HIPAA Notice & Business Associate Statement
Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026
1. Our role under HIPAA
Foundry is not a healthcare provider and does not practice medicine. We provide operational and administrative services to independent physician practices. In doing so, we may create, receive, maintain, or transmit PHI on a practice’s behalf, which makes us a HIPAA business associate to that practice. Each practice remains the covered entity responsible for its own privacy practices and its patient relationship.
Where PHI is handled. Our public website (bioscopefoundry.com) does not process PHI. PHI is handled only within our authenticated operating platform, on HIPAA-eligible infrastructure, and only to the extent permitted by the practice’s Business Associate Agreement.
2. Business Associate Agreements
Before we handle PHI for a practice, we enter into a written Business Associate Agreement (BAA) with that practice. The BAA governs how we may use and disclose PHI, the safeguards we maintain, our breach-notification obligations, and the return or destruction of PHI when our engagement ends. Where required, we also obtain BAAs from our own subcontractors that may handle PHI. A copy of our standard BAA is available to prospective and current member practices on request at the contact below.
3. PHI we handle and why
The PHI we handle depends on the services a practice uses and may include patient demographics, clinical records, encounters, medications, lab orders and results, and related documents. We handle this information only to support the practice’s operations, for example, to operate the clinical and administrative platform, support communications and scheduling, route notifications, and maintain audit and security records, and only as permitted by the BAA.
4. Permitted uses and disclosures
We use and disclose PHI only:
- To perform the services described in our agreement with the practice;
- As the practice directs and authorizes;
- For our proper management and administration, or to carry out our legal responsibilities, consistent with HIPAA; and
- As otherwise required by law.
We do not sell PHI, and we do not use or disclose PHI for marketing or for any purpose not permitted by the BAA or required by law.
5. Minimum necessary
We apply the “minimum necessary” principle: access to PHI is limited to the workforce members and systems that need it to perform a task, and to the least amount of PHI needed for that task.
6. Safeguards
We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including:
- Dedicated clinical data platform. Patient records are stored and processed in Foundry’s clinical data plane, a Foundry-operated workflow database and a private FHIR R4 service, both running on Foundry’s HIPAA-eligible cloud infrastructure subprocessor, not on local devices.
- Encryption. PHI is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256, with the option of customer-managed keys).
- Access controls. Role-based, least-privilege access (provider, staff, patient) enforced before any request reaches the data store. Authentication is passwordless, federated single sign-on for staff and providers, and email or SMS one-time passcodes for patients, with multi-factor authentication available through the identity provider and short idle and absolute session timeouts.
- Audit logging. Access to PHI is logged, who, when, which records, and the outcome, with audit records retained for at least six years; logs are designed to record identifiers, not PHI content.
- Network isolation and secret management. Network perimeters around the PHI environment, restricted ingress, and a managed secret broker protect PHI systems and credentials; credentials that grant access to PHI are never stored in source code.
- Communications discipline. SMS and email notifications are designed to avoid containing PHI; clinical content stays within authenticated systems.
- Backup and recovery. Backup, continuity, and recovery practices are part of how the platform operates.
- Workforce safeguards. Workforce members are subject to confidentiality obligations and security practices.
Our security and AI-management program is structured to align with recognized standards, including ISO/IEC 27001 and ISO/IEC 42001, and follows practices informed by OWASP and NIST guidance. References to these frameworks describe our program structure; they do not assert third-party certification.
7. Subcontractors
Where we use subcontractors that may handle PHI on our behalf, we require them, by written agreement, to provide protections at least as protective as those in our BAA with the practice. PHI-handling subprocessors operate under Business Associate Agreements (for example, our infrastructure provider, Amazon Web Services). A current list of subprocessors is maintained on the Foundry Trust Center.
8. Breach notification
If we discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and in no event later than thirty (30) calendar days from discovery, well within the 60-calendar-day outer limit set by HIPAA at 45 CFR § 164.410(b). Where a practice’s negotiated BAA sets a shorter window, that BAA controls. We will provide the practice with the information it needs to meet its own notification obligations and we will mitigate, to the extent practicable, any harmful effect known to us of any use or disclosure of PHI in violation of the BAA. We maintain an incident-response process for identifying, investigating, and responding to security incidents.
9. Supporting individual rights
HIPAA gives patients rights over their health information, including rights to access, amend, and obtain an accounting of disclosures as provided by HIPAA. Those rights are exercised through the covered entity (the practice). As a business associate, we support practices in fulfilling these requests, for example, by making relevant records and audit information available, but we do not respond to patient rights requests directly unless the practice directs us to.
10. Information for patients
If you are a patient, your rights regarding your health information are described in the Notice of Privacy Practices issued by your physician’s practice. Please direct requests about your records, access, copies, amendments, or questions about how your information is used, to your practice. Foundry supports practices behind the scenes and is not your healthcare provider.
11. Contact
Practices and partners with questions about Foundry’s HIPAA practices or to request a BAA:
Bioscope Foundry, LLC
HIPAA / Privacy contact: privacy@bioscopefoundry.com
11939 N. Meridian Street, Suite 125, Carmel, IN 46032
© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice. It is a business-associate statement, not a covered-entity Notice of Privacy Practices.