Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.
For patients of practices Foundry supports

For patients of practices Foundry supports

Patient FAQ · Plain-language answers about how Bioscope Foundry handles your health information. Last updated June 2026.

Important. Bioscope Foundry is not your healthcare provider. Your doctor’s practice is. We support the practice behind the scenes: we do not see you, treat you, or make clinical decisions for you. For questions about your care or your medical records, please contact your practice directly.

Who is Bioscope Foundry?

Bioscope Foundry, LLC is a management services organization (MSO). We help independent U.S. physicians run their own practices, by providing technology, administrative support, and AI assistance for tasks like scheduling, communication routing, and clinical-workflow tooling. Each practice we support is an independent business, owned by its physicians. Foundry does not practice medicine.

What is our role under HIPAA?

When we handle protected health information (“PHI”) on a practice’s behalf, we act as a HIPAA business associate. The practice is the covered entity. That means:

  • The practice is responsible for issuing its own Notice of Privacy Practices.
  • We protect PHI under a written Business Associate Agreement (BAA) with the practice.
  • We don’t use PHI for our own purposes; we use it only as the practice directs and as HIPAA permits.

Where is my information stored?

Your medical record lives inside a HIPAA-eligible cloud environment operated by Bioscope Foundry, a private clinical workflow database and a private FHIR R4 service, together making up Foundry’s clinical data plane, not on local devices or desktops. Access is logged. The same goes for any AI-assisted feature your practice uses, your protected health information is handled only inside this protected environment.

How do I exercise my privacy rights?

HIPAA gives you rights over your health information, including the right to access, amend, or get an accounting of disclosures of your records. Because we are a business associate, those requests are handled by your practice. We support the practice in responding, for example, by making relevant records available, but we don’t respond to patient requests directly.

Please direct your privacy requests to the privacy contact listed in your practice’s own Notice of Privacy Practices.

Will I get text messages or emails from Foundry?

Operational messages from the platform we run on behalf of your practice may come from a Foundry-affiliated address or number, depending on what your practice has configured. These are designed to not contain medical information; clinical content stays inside the authenticated portal your practice uses. You can opt out of non-essential SMS notifications by replying STOP to any message; opting out will not affect your relationship with your practice or your access to your medical records.

Does Foundry use AI?

Yes. AI assistance is part of how we operate behind the scenes for your practice. Your physician makes all medical decisions. AI helps the practice run more efficiently, by routing communications, drafting summaries for clinician review, and supporting administrative work, but it does not diagnose you, treat you, or replace your clinician’s judgment. Where AI touches PHI, it does so only through HIPAA-eligible services covered by a Business Associate Agreement.

What if I think there has been a privacy issue?

If you have a privacy concern, please contact your practice first; they are the covered entity. If you would also like to reach us, you may email privacy@bioscopefoundry.com. You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights without fear of retaliation.

Where can I learn more?