HugoScore hugoscore.org

Full review

BastionGPT CAIHL draft report

Evidence-linked HugoScore draft report for a health AI tool that affects patients.

BastionGPT: CAIHL reassessment

September 8, 2026. Published AI-assisted draft.

BastionGPT remains a professional-controlled AI workspace. August terms strengthen restrictions on model evaluation and derivative-data creation. Those commitments protect data without transferring clinical goals, capture, or output authority to patients.

Scope and agency posture

Professional and institution-controlled clinical AI workspace. Preserve the July 27 external-submission disclosure and 16 baseline, not an endorsement.

Posture: Mixed, strongly institution-directed.

Axis: 16/100, retained provisionally. No numerical recalibration was performed.

Sources and documented findings

  • The terms effective August 28 expressly prohibit training, fine-tuning, evaluation or improvement of any AI model using Customer Data across chat, uploads, transcription, API and beta features. They also prohibit creating anonymized, de-identified or aggregate derivatives from Customer Data and prohibit that substitution for deletion. Microsoft and Google remain the listed content processors. This is materially more specific than the July profile's no-training summary.
  • The current retention explanation separates account chats and documents from adjustable transcript retention and processing logs. It describes inactivity deletion and up to 30 days for underlying deletion. It does not make 30 days a universal limit on active-account content.
  • The current consent guidance still calls templates optional. Templates include refusal and withdrawal, but implementation belongs to the practice.

Patient authority

Inference from the documented workflow: Professionals retain prompt, model, retention and output authority. Stronger vendor contractual restrictions protect patients' data without giving patients direct control over clinical objectives, capture or correction.

Critical capacity

Editorial assessment: Clinician review and patient-facing documents may help, but no direct patient access to prompts, source transcripts or an individual appeal process was established. The narrow prior PICU study cannot validate this broader platform.

Informed control

Editorial assessment: Credit the explicit new model-evaluation and derivative-data prohibitions. The retention explanation now needs content-specific wording. Listed processors still do not completely explain every marketed model path, and local patient notice remains a separate requirement from professional account controls.

Assessment and limits

Change the governance description to recognize stronger published conditions without inferring patient decision authority or implementation from a contract. A stronger privacy commitment alone does not justify moving the agency-axis number.

Confidence: Medium for contractual changes, limited for local practice.

Remaining uncertainty: Enforcement, actual routing, local refusal and access to source artifacts were not tested. The older broad security-page retention wording was not separately rechecked.

Published documentation is evidence of stated conditions, not proof of actual implementation. Unknowns did not receive automatic negative points. Funding, sponsorship, and public code do not determine agency by themselves.

Review provenance

  • Reviewer/model: OpenAI Codex / GPT-6.
  • Method: Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
  • Human review: Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
  • Earlier review: 2026-07-27. Historical assessment. Earlier claims are not automatically reverified by this publication.

Disclosures

First externally submitted tool. not selected or endorsed by the project owner. BastionGPT was submitted for review through HugoScore's public tool-submission channel on 2026-07-27. The project owner states that it was not selected by them and is HugoScore's first tool added from an external submission. Publishing this draft records the review response and does not endorse the submission, vendor, or product.