Support Terms
Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026
1. Scope
1.1 Included Support
During the Subscription Term, Foundry provides the following at no additional charge:
- Assistance with platform functionality and usage;
- Troubleshooting of technical issues and errors;
- Guidance on best practices for using the operating platform;
- Account management, role-assignment, and access-control support;
- Routine platform maintenance, security patches, and platform updates;
- Performance monitoring and infrastructure maintenance;
- Onboarding assistance for new Authorized Users and access to user-facing documentation.
1.2 Excluded
The following are not included in Support Services and may be available as professional services for an additional fee:
- Custom development or modifications to the platform;
- Integration with third-party systems not listed on the Order;
- Training beyond standard onboarding and documentation;
- Data migration from legacy systems;
- Issues caused by the Practice’s misuse of the Services or breach of the Agreement;
- Issues arising from the Practice’s devices, network, or third-party software outside Foundry’s control;
- Restoration of data lost due to actions or negligence of the Practice or its Authorized Users;
- Support for unsupported browsers, operating systems, or devices;
- Medical, clinical, legal, tax, or regulatory advice.
2. Support tiers and severity levels
2.1 Support tiers
Foundry offers three support tiers; the Practice’s tier is set out in the Order.
| Tier | Audience | SEV-1 availability | Channels | Named contact |
|---|---|---|---|---|
| Standard (default) | All member Practices | 24x7 for SEV-1 | Email & in-platform | Shared support queue |
| Priority | Practices with extended onboarding or higher operational tempo | 24x7 for SEV-1 and SEV-2 | Email, in-platform, and a dedicated escalation address | Named Foundry operations contact |
| Critical | Practices with elevated risk or multi-location footprint | 24x7 for SEV-1 and SEV-2; same-business-day for SEV-3 | Email, in-platform, and a named on-call contact | Named operations lead with backup |
Tier-specific pricing and entitlements are set out on the Order.
2.2 Severity levels
SEV-1: Critical
- Definition: Complete loss of the operating platform affecting all or substantially all Authorized Users, or any security or privacy incident reasonably believed to involve PHI.
- Examples: platform unavailable; suspected or confirmed unauthorized access to PHI; loss of clinical record access for an active patient encounter.
- Response: immediate prioritization on receipt.
- Workaround / mitigation: continuous effort until critical functionality is restored or an acceptable workaround is in place.
- Availability: 24x7, every day.
SEV-2: High
- Definition: Significant functionality is impaired and a workaround is not readily available, affecting multiple Authorized Users.
- Examples: a key workflow (scheduling, messaging, agent surface) is broken; significant performance degradation; an integration is failing.
- Response: prioritized ahead of routine work, during Business Hours (24x7 for Priority and Critical tiers).
- Resolution: commercially reasonable efforts toward prompt resolution.
- Availability: Business Hours (24x7 for Priority and Critical tiers).
SEV-3: Medium
- Definition: Minor functionality issue with a workaround available.
- Response: handled during Business Hours in priority order.
- Resolution: commercially reasonable efforts, prioritized by impact.
- Availability: Business Hours.
SEV-4: Low
- Definition: Questions, documentation clarifications, feature requests, cosmetic issues.
- Response: addressed during Business Hours as capacity allows, typically in an upcoming release.
- Target resolution: Best effort.
- Availability: Business Hours.
2.3 Priority assignment
Foundry assigns severity in good faith based on the criteria above. If the Practice believes a request should be escalated, it may request escalation with justification; the operations lead reviews escalation requests.
3. Channels
- Email, general support: support@bioscopefoundry.com
- Email, security incidents: security@bioscopefoundry.com
- Email, privacy inquiries: privacy@bioscopefoundry.com
- In-platform: contextual help, ticket submission, and status updates.
- Documentation: user guides and operational references available in the platform.
SEV-1 requests should use the in-platform incident button or the dedicated escalation address provided to Priority and Critical-tier Practices. Phone-based on-call is not offered at launch.
4. Response targets and availability
4.1 Business hours
Foundry’s standard business hours are Monday through Friday, 9:00 a.m. to 6:00 p.m. Eastern Time, excluding U.S. federal holidays.
4.2 How targets are measured
Response time is measured from receipt of a properly submitted support request to Foundry’s initial substantive response. Resolution time is measured from receipt to the time the issue is resolved or an acceptable workaround is in place. Times for non-SEV-1 issues are computed against Business Hours; SEV-1 times run continuously.
4.3 Continuous effort for SEV-1
For SEV-1 issues, Foundry will use commercially reasonable efforts to provide continuous updates and to work toward restoration or an acceptable workaround until the critical functionality is restored.
5. Escalation
- Level 1: Support engineer. Initial triage and response.
- Level 2: The Operations lead is reached automatically for SEV-1 and SEV-2 and is reachable by the Practice on request.
- Level 3: Security & privacy lead. Engaged for any incident reasonably believed to involve PHI or the security of the platform; the security and privacy lead is the Practice’s HIPAA point of contact.
- Level 4: Executive sponsor. Available for sustained, unresolved issues at Priority and Critical tiers.
Foundry maintains an internal on-call rotation; on-call coverage is 24x7 for SEV-1 incidents.
6. Remote access and PHI controls
Support work is conducted under the same HIPAA safeguards that apply to the production environment.
- No PHI export by Foundry support. Foundry support personnel do not download, copy, or otherwise export PHI to local devices, email, screenshots, or third-party tools. Any data needed for diagnosis is reviewed in place under the production access controls.
- Least-privilege, just-in-time access. Support access to systems containing PHI is role-based, time-bound, and recorded; standing access is minimized.
- All access is logged. Each support session that touches a PHI-bearing system produces an audit log entry, who, when, which records, what action, retained for at least six years.
- No PHI in support tickets. Practices and Foundry agree not to include PHI in ticket text, email subject lines, or attachments. References should use record identifiers, not patient content.
- Workforce safeguards. Support personnel are bound by confidentiality obligations, complete HIPAA training, and are subject to the workforce sanctions process for violations.
- Remote-control sessions. Where a live screen-share is needed, the Practice initiates and controls the session; Foundry does not maintain persistent remote-control capability over Practice devices.
7. Maintenance windows
7.1 Scheduled maintenance
- Standard window: Sundays, 02:00-06:00 Eastern Time, up to twice per month.
- Notice: at least 72 hours in advance for scheduled maintenance, posted in-platform and emailed to designated contacts.
- Emergency maintenance may be performed at any time to address a security vulnerability, critical bug, or system-stability issue; Foundry will give as much advance notice as is reasonably practicable.
7.2 Platform availability
Foundry works to keep the operating platform available and communicates scheduled maintenance in advance as described in Section 7.1. Foundry responds to availability incidents affecting the operating platform under the severity framework and response targets in Sections 2 and 4. Foundry is a management services organization and the operating platform depends on third-party cloud and SaaS providers; accordingly, these Support Terms do not make any numeric availability commitment and do not provide service credits. This does not limit the Practice’s other rights under the Agreement (including termination for material breach) or Foundry’s HIPAA obligations to the Practice as a Business Associate.
7.3 Inadvertent PHI in support communications
If the Practice submits a ticket, email, or screen-share that contains PHI, Foundry will: (a) redact the PHI from the support record on receipt; (b) destroy the original PHI-bearing artifact; (c) log the inadvertent disclosure in the audit record (identifier only, no PHI body); and (d) confirm completion of (a)–(c) to the submitter. Live screen-share sessions are not recorded by Foundry by default; if a session is recorded with the Practice’s consent, the recording is retained in the Foundry-controlled environment, treated as PHI-sensitive, and deleted on the Practice’s request.
8. Practice responsibilities
For Foundry to investigate and resolve issues effectively, the Practice will:
- Provide contact information, environment details, and a description of the issue (steps to reproduce, expected vs. actual behavior, time of occurrence, impact);
- Designate a primary support contact and at least one backup;
- Not include PHI in ticket text or attachments; use record identifiers only;
- Cooperate with Foundry’s troubleshooting, including implementing reasonable workarounds while permanent fixes are developed;
- Maintain reasonable backups and independent records of any data the Practice considers business-critical, beyond what Foundry maintains for the platform;
- Use support resources reasonably and refrain from abusing emergency channels for non-critical issues.
9. Limitations and disclaimers
- Best-effort response and resolution times. Response and resolution times are targets based on commercially reasonable efforts, not guarantees; Foundry does not offer service credits or any other financial remedy for missed targets or for platform availability.
- Workarounds. Foundry may provide a workaround or temporary solution while a permanent fix is in progress.
- Beta features. Features labeled beta, preview, or experimental are provided as-is with limited support and may be modified or withdrawn.
- Third-party issues. Foundry is not responsible for issues caused by third-party services, the Practice’s network or devices, or events beyond Foundry’s reasonable control.
- No clinical advice. Support personnel are not licensed healthcare providers and do not interpret clinical results, make clinical recommendations, or provide medical advice.
10. Changes to these Terms
Foundry may modify these Support Terms from time to time by posting an updated version here and notifying the Practice’s primary contact. Changes that expand support coverage or improve service levels may take effect immediately. Changes that materially reduce support coverage or service levels take effect thirty (30) days after notice. Continued use of the Services after the effective date constitutes acceptance.
11. Contact
Bioscope Foundry, LLC
Support: support@bioscopefoundry.com
Security incidents: security@bioscopefoundry.com
Privacy: privacy@bioscopefoundry.com
11939 N. Meridian Street, Suite 125, Carmel, IN 46032
Related: Master Services Agreement · Business Associate Agreement · Incident response policy.
© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.