Security · BastionGPT

Built with security as our first priority.

BastionGPT was designed from day one for healthcare. HIPAA-compliant, BAA included, independently tested, and continuously assessed by a team of healthcare security veterans.

HIPAA Compliant3rd Party CertifiedNIST CSF
Our Security Practice

Healthcare security is complicated.
BastionGPT makes it easy.

We invest in security the way the regulated industries we serve expect: continuously, independently, and on a published cadence. Here's what that looks like in practice.

Our approach

BastionGPT is built and operated by a team that has spent decades inside healthcare. Our CEO previously led technology and security for one of the largest medical centers in the country, and that experience shapes every decision we make. We treat HIPAA compliance, encryption (in transit and at rest), role-based access, and audit logging as defaults, not enterprise upsells. Every customer is entered into a signed Business Associate Agreement on every paid plan, and your data is never used to train any underlying AI model.

For a plain-language walkthrough of what happens to your data, step by step, see our support center.

Risk assessment as investment, not expense

Most companies treat third-party risk assessments as a regulatory tax. We treat them as one of the most valuable signals we get. BastionGPT engages outside security firms on a recurring basis to evaluate our environment against the HIPAA Security Rule, the HHS recognized security practices, and broader cyber frameworks like NIST CSF and NIST 800-53. The findings get tracked, prioritized, and remediated in the same systems our engineers ship product changes through, so security work compounds instead of getting filed away.

Penetration tests and code reviews

BastionGPT is independently penetration tested at least annually by a third-party offensive-security firm, with additional targeted tests around major platform changes. Tests cover the web application, API surface, authentication and tenant isolation, and the AI inference pipeline itself, including prompt-injection and data-exfiltration scenarios specific to LLM applications. We also run static and dynamic code analysis on every change, and our codebase is reviewed by senior engineers before anything reaches production.

Data assessment and controls

We follow a data minimization model. BastionGPT collects only what's necessary to provide the service, segregates customer data by tenant, and encrypts it both in transit (TLS 1.2+) and at rest (AES-256). Customer prompts and outputs are not retained for model training, and data residency for protected health information sits within hardened, BAA-covered infrastructure.

Our support article Does BastionGPT train AI on my data? explains these commitments in more detail.

Safe by default, not by configuration

Most AI platforms ship every feature they can build and leave it to each customer's compliance and security team to work out which ones are safe to enable, then to keep watching as defaults change. BastionGPT takes the opposite approach: the capabilities that most often put patient data at risk are not in the product at all. There is no web search, because even de-identification that is 99.9% effective before a query leaves our boundary is not 100%, and neither Google nor Bing offers a BAA covering search queries. There is no cross-conversational memory, because context that follows you from one conversation to the next can surface one patient's information inside another patient's chart, and most patient consent language never contemplated one patient's data shaping another's record. When a capability is genuinely needed, we build it into the service itself, or show you how to bring your own content into a session, so a risky integration never becomes the workaround.

Security history

BastionGPT has been in market for three years and serves more than 10,000 healthcare organizations. In that time we have had zero reportable breaches of protected health information. Every security event, no matter how minor, is logged and reviewed; material findings are disclosed to affected customers under our incident response policy and the timelines required by the HIPAA Breach Notification Rule.

Trust & Compliance Center

Everything your security team would want to see, already documented.

Our BAA template, third-party penetration test summary, HIPAA Security Rule mapping, infrastructure attestations from our SOC 2 and HITRUST-certified infrastructure providers, and architecture overview all live in one continuously-updated trust center, available under NDA when an enterprise security review needs it. Our full Terms of Use, Privacy Policy, Sub-Processor List and HIPAA BAA are published openly.

Preview of the BastionGPT Trust & Compliance Center, showing certifications, policies, and downloadable security documentation.
Frequently Asked

Security & Compliance FAQs

The questions enterprise security, privacy, and procurement teams ask us most often.

Is the system HIPAA- and 42 CFR Part 2–compliant?+

Yes, BastionGPT is engineered to support the requirements of both HIPAA and 42 CFR Part 2 for the handling of sensitive health information.

Will the vendor sign a Business Associate Agreement (BAA)?+

Yes, all of our plans automatically incorporate a BAA. You can review our BAA and related terms here. Where preferred, BAA's can be routed via Docusign for no additional cost.

What is the recommended procedure to spread BAAs?+

For most customers, the standard BastionGPT BAA executed automatically during your electronic acceptance of Terms at the start of a trial covers all users in that organization, including additional users added later. For multi-entity organizations (e.g., a parent organization with several legal subsidiaries), we generally recommend executing a separate BAA per legal entity. Our support team can help you scope this if you would like assistance. HIPAA BAA can be routed for mutual signature via DocuSign by request.

Are all recordings and transcripts encrypted?+

Yes, sensitive data such as recordings and transcripts are encrypted using industry standard security measures such as TLS 1.2+) for data in transit and AES-256 for data at rest. Please note there are manual options to copy or download data to plaintext formats such as .mp4 and .txt files.

Is my data used for AI training?+

Data entered into BastionGPT is never sold or used for training AI models. BastionGPT makes no claim to any data that you provide. This is contractually guaranteed in our privacy policy and terms.

Does BastionGPT use web search or third-party integrations?+

No. BastionGPT does not include web search, browsing, plugins, or cross-conversational memory. Even 99.9% effective de-identification is not 100%, and search providers such as Google and Bing do not offer BAAs covering search queries, so patient data would leave BAA-covered infrastructure the moment a query went out. Capabilities our customers need are built directly into the service instead, and you can always add your own reference content to a session or obtain approval for API access to add in additional capabilities.

Is it safe and compliant to enter Protected Health Information (PHI)?+

Users have the ability to enter PHI into the system, where it will be transmitted and stored appropriately in line with HIPAA requirements.

For practical guidance, read Is it safe to upload patient records? in our support center.

Can data be deleted immediately after use?+

BastionGPT provides the option to immediately delete specific items or all data at once. Data is maintained for up to 30 days in our secure audit vault to support required auditing, such as monitoring for illegal or prohibited system use.

Does it support MFA and role-based access?+

Yes, our Enterprise plans support the use of your organization's existing Single Sign-On (SSO) and authentication platform. All other plans support email-based MFA with adaptive authentication.

Is data stored on U.S.-based servers?+

Yes, customers with a USA billing address will store and process sensitive data within the USA. Sensitive data from customers with billing addresses in Canada or Australia will default to residing in their respective country.

Are audit logs available for all access and actions?+

Audit logs are maintained and monitored internally by our security team and can be requested ad-hoc as needed by the customer. Frequent audit log requests may incur administrative fees. Customers utilizing the Enterprise plans have access to automated data feeds if desired.

Has the system undergone a recent SOC 2 Type II or penetration test?+

Yes, BastionGPT routinely performs internal and external (3rd party) penetration tests to validate our systems security.

BastionGPT exclusively operates on HITRUST CSF Certified and SOC 2 Type II attested infrastructure for all services processing, storing, or transmitting sensitive or confidential customer data, including all data submitted through the BastionGPT API and user interface. Our infrastructure providers maintain current certifications with annual audits.

Additionally, BastionGPT is pursuing its own HITRUST CSF Certification and SOC 2 Type II attestation. We are currently undergoing readiness activities, with no significant technical gaps observed to date. In the interim, we maintain comprehensive security controls aligned with HITRUST CSF and HIPAA requirements.

Is there a documented incident response plan?+

Yes, we maintain a documented incident response plan that is regularly reviewed and tested in accordance with industry best practices and compliance requirements.

Review our confidential security whitepaper and architecture with a cybersecurity expert.

30 minutes with our cybersecurity advisor. We'll walk through how BastionGPT protects your patient data and answer any questions specific to your practice.

Schedule a call →
Proven Security

Vetted by the people who lead security in healthcare.

BastionGPT's security posture is signed off by leaders who have spent their careers running security and compliance programs at the largest health systems in the country.

Josh Spencer

"BastionGPT was built using the same playbook I used to protect patient data at a major academic medical center. Defense in depth, recognized security practices, and an honest paper trail. We don't ship a control we can't evidence."

Josh Spencer
CEO, Bastion Intelligence · 13 years leading technology & security at UT Southwestern
Abir Dhar

"During my testing process, I was impressed by the robustness and resilience of this application. BastionGPT is one of the most secure platforms I have tested."

Abir Dhar
Cybersecurity Expert · Independent Penetration Tester
Keep evaluating

Choosing an AI tool for your practice?

Our plain-English guide covers what makes an AI HIPAA compliant: the BAA, the technical safeguards, and the data-use restrictions to verify before patient data touches any tool. Then see how BastionGPT compares with Claude Team & Enterprise, Microsoft Copilot, Heidi Health, Hathr AI, Abridge, Suki, Nabla, DAX Copilot, and Freed.

We also compare BastionGPT with Ambience Healthcare, Commure, CompliantChatGPT, DeepCura, DeepScribe, Lyrebird Health, Mentalyc, and Twofold Health.

For security researchers

Responsible disclosure

Found something we should know about? We welcome coordinated disclosure from the security research community and respond to every report.