Foundri deploys AI agents directly into your AWS or GCP account. Patient data stays inside your perimeter — fully controlled by your IAM policies, your encryption, your network rules. No BAA required. Because Foundri never touches PHI.
Free HIPAA risk assessment. No credit card required.
When you add an AI vendor to your clinical workflow, you inherit their compliance posture. Every vendor with access to PHI requires a Business Associate Agreement — meaning they're responsible for protecting patient data under HIPAA. If they have a breach, you're exposed too. Foundri's BYOC architecture sidesteps this entirely.
PHI leaves your perimeter and travels to their servers for processing. You need a BAA. Their security posture becomes your liability.
AI agents run inside your AWS or GCP. PHI never leaves your infrastructure. No BAA required. Foundri receives only telemetry.
Vendor breach = your HIPAA incident. Patient data potentially exposed. OCR investigation likely.
No PHI to expose. Foundri never sees patient data. Even if Foundri's control plane is compromised, no PHI is at risk.
Vendor SOC 2 Type II = your audit surface expands. Additional compliance requirements, additional risk.
No PHI access = no HIPAA scope expansion. Your compliance checklist gets smaller, not larger.
How it works
AI agents run as native workloads inside your cloud environment. HIPAA compliance is structural — not contractual.
Agents execute inside your VPC. Patient data is processed by your Lambda, ECS, or EKS workloads. Foundri's control plane never sees PHI — only performance telemetry and execution summaries.
Agents run under scoped IAM roles you define. You decide what they can access, what they can't. Revoke permissions at any time through your existing identity management.
Without access to PHI, Foundri isn't a Business Associate under HIPAA — you're just using a software tool that runs in your own environment. No BAAs, no vendor liability.
For your own compliance posture, Foundri generates audit-ready evidence automatically. AWS configuration checks, IAM audit logs, encryption verification — all documented.
Patient intake processing, appointment reminders, clinical documentation workflows, insurance verification — all handled by agents that never see raw PHI in transit.
For organizations with data residency requirements, Foundri supports air-gapped deployment. PHI never crosses regional boundaries.
HIPAA compliance
When your AI vendor never touches PHI, the hardest HIPAA requirements simply don't apply to them.
A Business Associate Agreement is required when a vendor creates, receives, maintains, or transmits PHI on your behalf. Foundri's agents process data inside your cloud environment — they never receive or store PHI. This means Foundri is not a Business Associate under HIPAA, and no BAA is required. Your legal team will appreciate the simplicity.
Architecture
The agent runs inside your VPC. Foundri receives only telemetry — scan summaries, performance metrics, and execution logs. No patient data crosses your perimeter.
Pricing
No per-patient fees. No BAAs. No surprise compliance charges. Flat monthly pricing that scales with your organization.
For healthcare teams starting their compliance automation journey
For healthcare organizations with active compliance programs
For health systems with multi-region or air-gapped requirements
Beta users get 60 days free — no credit card required to join.
Foundri's BYOC agents run inside your infrastructure. No BAA. No vendor HIPAA liability. Just AI that works within your security perimeter.
Request Early Access →Free HIPAA risk assessment included. No credit card required.
No. A BAA is required when a vendor creates, receives, maintains, or transmits PHI on your behalf. Foundri's agents run inside your cloud — they never receive or store PHI. Foundri receives only telemetry (scan summaries, execution logs). This means Foundri is not a Business Associate under HIPAA and no BAA is required.
Because Foundri never touches PHI, the HIPAA Security Rule's technical safeguard requirements don't apply to Foundri's infrastructure. Your security team can verify this by reviewing our architecture documentation — the agent runs inside your VPC, under your IAM policies, processing data that never leaves your perimeter.
All processing happens inside your cloud environment. Patient data stays in your RDS, S3, or other data stores — the agent accesses it through scoped IAM roles you define, processes it locally, and outputs results locally. Foundri's control plane never sees the data. No PHI leaves your infrastructure.
Yes. For healthcare organizations with data residency or air-gapped requirements, Foundri supports fully isolated deployments. Agent updates are delivered via secure, signed packages rather than direct network connection. Contact us to discuss your specific requirements.
Foundri's Security Agent continuously monitors your AWS infrastructure — IAM configurations, S3 bucket policies, encryption settings, VPC security groups. All findings are logged, timestamped, and mapped to SOC 2 controls automatically. This creates audit-ready evidence without a compliance consultant. BYOC architecture also eliminates 11 of 15 compliance checklist items because Foundri never sees your data.