Security and compliance, built for an MSO that handles PHI on behalf of physicians.
Bioscope Foundry is an AI-enabled management services organization (MSO) for independent U.S. physicians. This Trust Center documents how we protect protected health information (PHI) as a HIPAA business associate, the controls we operate, and the legal agreements that bind our work.
What you'll find here
How we run security and privacy: access control, data protection, incident response, AI governance, vendor management, BCDR, and more. Rewritten for an MSO that handles PHI as a business associate.
HIPAA Security Rule control mapping, ISO 27001:2022 and ISO 42001:2023 alignment matrices, OWASP Top 10 status, and the NIST 800-63B credential baseline.
Privacy Policy, Terms of Service, the HIPAA Notice & Business Associate Statement, Business Associate Agreement, Master Services Agreement, Subprocessors list, and Support Terms.
What Foundry is, how your health information is protected, and where your privacy rights live.
Program at a glance
PHI lives in Foundry’s clinical data plane on AWS: a clinical workflow database and a private Foundry-operated FHIR service. It never lands on workstations, in logs, in agent memory, or in generated documents. Redaction boundaries are enforced in code, not by convention.
Zero standing access to production; break-glass elevation requires practice approval and auto-expires, with automated just-in-time elevation tooling being finalized. Phishing-resistant MFA for privileged paths, quarterly access reviews, and identity boundaries that honor the practice-as-covered-entity model.
Encryption at rest and in transit, segmented networks, hardened endpoints, supply-chain pinning, secure SDLC, and continuous vulnerability management; controls stack so that a single failure does not compromise PHI.
Material decisions stay human-in-the-loop. Tiered agent permissions cap the scope of any single AI action, sanitized surfaces separate physicians from raw PHI, and every read and write of PHI is logged with six-year retention.
Core commitments
Patient records live in Foundry’s clinical data plane on AWS: a Foundry-operated clinical workflow database (Amazon RDS for PostgreSQL) and a private Foundry-operated FHIR R4 service (Amazon ECS), under an executed BAA. PHI does not land on workstations, agent worktrees, logs, or generated documents. Worker tiers that cannot hold PHI run on a separate sandboxed network.
PHI is encrypted in transit and at rest. Customer-managed encryption keys are available on request through the BAA.
Federated single sign-on for workforce and providers; email or SMS one-time passcodes for patients. Phishing-resistant MFA is required for privileged access.
Every read and write of PHI is logged (who, when, which patient, which record, and the outcome), with audit records retained for at least six years.
Any subprocessor that may handle PHI is bound by a BAA. We maintain a current list with effective dates.
AI outputs augment, not replace, human judgment. A redaction layer separates sanitized physician-facing surfaces from raw PHI.
Contact & reporting
Security disclosures, BAA requests, and privacy questions all route through the same desk.
Security disclosures & incidentssecurity@bioscopefoundry.com
Privacy & HIPAAprivacy@bioscopefoundry.com
BAA & vendor requestslegal@bioscopefoundry.com
11939 N. Meridian Street, Suite 125
Carmel, IN 46032