HugoScore hugoscore.org

Full review

BastionGPT CAIHL draft report

Evidence-linked HugoScore draft report for a health AI tool that affects patients.

HugoScore CAIHL Draft Report: BastionGPT

  • Status: Draft for human review
  • Last reviewed: 2026-07-27
  • Review method: Deep public-source review of current product, scribe, clinical-validation, security, privacy, terms, BAA, consent, retention, training, error, export, and regulatory-position materials; the peer-reviewed PICU feasibility study; current FDA clinical-decision-support guidance; and the public APA 2025 exhibitor record. No live account or deployment testing, contract or private assurance review, vendor or user interview, security/model/accessibility audit, legal review, regulatory determination, or independent validation of the current commercial platform.
  • Service: BastionGPT
  • Vendor: FortaTech Security, LLC, doing business as Bastion Intelligence
  • URL: https://bastiongpt.com/
  • Category: Clinical decision support

Submission Provenance

BastionGPT was submitted for review through HugoScore's public tool-submission channel on 2026-07-27. It was not selected by the project owner. The project owner identifies it as HugoScore's first tool added from an external submission. Publishing this draft records HugoScore's response to that submission; it is not an endorsement of the submitted description, the vendor, or the product.

1. Executive Summary

BastionGPT is a multi-model generative-AI workspace for clinicians, therapists, practices, and health systems. It combines clinical chat, long-document and image analysis, note and report drafting, an ambient and uploaded-audio scribe, patient-facing document generation, and clinical suggestions. The vendor markets GPT, Claude, and Gemini access in a HIPAA-oriented environment with a Business Associate Agreement on every plan.

Under CAIHL, BastionGPT is strongly institution-directed and clinician-mediated. Professional users and organizations choose the tool, supply patient data, select or accept a model, review outputs, and decide what enters the record or reaches a patient. Patients may benefit through more clinician attention, clearer summaries, or better communication, but they usually do not choose or govern the AI.

The public record includes meaningful protections: contractual no-model-training language for customer content, a BAA, named Microsoft and Google subprocessors, encryption and testing claims, clinician review requirements, and explicit warnings that AI can hallucinate or omit information.

Important agency concerns remain:

  • The scribe is marketed as joining online visits with “no visible bot,” while notice and refusal depend on the deploying professional or organization.
  • Current public retention statements conflict: one page says a 30-day maximum, while a more detailed support article says chats may remain until deletion, uploads may remain while an account is active, and transcript retention can be set from 1 to 365 days.
  • Terms list Microsoft and Google as customer-content subprocessors but not Anthropic, despite marketed Claude access.
  • The peer-reviewed 99.3% result came from a small, supervised, 14-parent, 10-minute PICU feasibility study of a GPT-4o-based chatbot. It does not validate the current multi-model product, scribe, imaging, assessment, or treatment-support functions.
  • The vendor calls the product an assistant rather than a medical device, while current marketing includes patient-specific intervention, imaging, assessment, and plan-support uses. Current FDA guidance is function-specific. This draft makes no regulatory determination.
  • Agency posture: Mixed, strongly institution-directed
  • Agency axis position: 16 of 100
  • Confidence: Medium draft, extensive official documentation plus one small peer-reviewed feasibility study; deployment-specific patient controls and broader validation remain incomplete

The agency axis shows who chooses and controls the tool. It is not a safety, accuracy, privacy, quality, or effectiveness score.

2. CAIHL Question

Who does BastionGPT serve?

BastionGPT primarily serves healthcare professionals and organizations seeking documentation efficiency, a compliant environment for PHI, access to multiple frontier models, and reusable clinical workflows. Patients are usually participants in recorded encounters, subjects of uploaded records, and recipients of clinician-approved outputs rather than product users.

Potential patient value is real but indirect:

  • Less clinician typing may improve attention.
  • Clearer notes, discharge summaries, education, and reports may improve understanding.
  • Record review may help a clinician notice missing information.
  • A supervised parent-facing research chatbot showed promising short-session results.

Provider and vendor interests remain central: documentation time, workflow speed, reuse of PHI, subscription revenue, model aggregation, adoption, and clinical-platform scale.

CAIHL classification: Institutional, clinician-mediated clinical AI assistant and documentation platform.

Primary users: Clinicians, therapists, healthcare staff, practices, and health systems.

Hosting and control: Vendor-hosted by default, with an enterprise customer-cloud option described publicly. Professionals and organizations control inputs, prompts, model selection, outputs, and record use.

3. What the Service Does

Public materials describe:

  • A healthcare-focused ChatGPT-like workspace.
  • Automatic or manual GPT, Claude, and Gemini model selection.
  • Analysis of records, long documents, images, charts, spreadsheets, and audio.
  • Live or uploaded-audio transcription for sessions up to four hours.
  • Identification of as many as ten speakers using acoustic fingerprinting or voice prints.
  • Drafting of SOAP, DAP, BIRP, H&P, discharge, referral, treatment-plan, assessment, insurance, education, and custom documents.
  • Patient-facing summaries and education mediated by clinicians.
  • Clinical “safety net,” assessment-interpretation, imaging-observation, and intervention-support examples.
  • Copy-and-paste transfer into EHRs and other systems.

The Terms say outputs are drafts, clinicians must review them, and the service is not a medical device or substitute for professional judgment. The marketed scope goes beyond clerical transcription, so high-stakes functions need separate evidence and review.

4. Patient-Impact Pathway

1. A clinician or organization deploys BastionGPT. 2. The professional types, uploads, records, or copies identifiable clinical content. 3. BastionGPT and applicable subprocessors route the request to an automatically or manually selected model. 4. The system returns a transcript, note, summary, report, suggestion, or patient-facing document. 5. A clinician is expected to review and edit it. 6. The result may enter the EHR, inform clinical thinking, reach a patient, or affect billing, coverage, school, disability, or legal documentation. 7. Patients depend on the clinician or organization for notice, refusal, record access, amendment, and complaint handling.

5. Evidence Table

| Source | Main finding | Evidence limits |
| --- | --- | --- |
| https://bastiongpt.com/ | Multi-model clinical assistant, scribe, EHR workflow, patient-facing outputs, “no visible bot,” and vendor scale/security claims. | Vendor marketing; no live testing or independent audit in this review. |
| https://bastiongpt.com/medical-chatgpt | Clinical drafting, record analysis, model names, pricing, and professional focus. | Vendor-authored and dynamic. |
| https://bastiongpt.com/ai-medical-scribe | Live/uploaded recording, multi-speaker attribution, four-hour sessions, and note generation. | No deployment, consent, or accuracy test inspected. |
| https://bastiongpt.com/security | BAA, encryption, tenant isolation, penetration testing, 30-day wording, and NDA trust-center materials. | Vendor-authored; public page references infrastructure-provider SOC 2/HITRUST attestations rather than establishing Bastion-owned certification. |
| https://bastionintelligence.com/privacy | User-content processing, no-training rule, deletion requests, advertising separation, and data-subject rights. | General policy; patient rights in customer content remain mediated by providers. |
| https://bastionintelligence.com/terms | Clinician-review boundary, Microsoft and Google subprocessors, no training, retention, BAA, and security terms. | Anthropic is absent from the displayed subprocessor list despite marketed Claude access. |
| https://bastionintelligence.com/baa | PHI-use limits, safeguards, incident notice, subcontractors, return/destruction, and customer obligations. | Contractual posture, not deployment proof; no direct patient product rights. |
| https://support.bastiongpt.com/en/articles/15826869-how-long-does-bastiongpt-keep-my-data-and-how-do-i-delete-it | Chats until deletion, uploads while active, configurable transcript retention, and processing retention up to 30 days. | Conflicts with broader 30-day statements elsewhere. |
| https://support.bastiongpt.com/en/articles/14464971-do-you-have-consent-form-templates-for-healthcare-ai-use | Optional consent templates and right-to-decline language. | Guidance, not a built-in patient consent or refusal guarantee. |
| https://support.bastiongpt.com/en/articles/14462130-does-ai-ever-make-mistakes | Acknowledges hallucination, outdated information, contextual errors, and review needs. | Guardrail results are not public. |
| https://support.bastiongpt.com/en/articles/15826874-can-bastiongpt-diagnose-patients-is-it-fda-approved | Vendor says it is not cleared or approved and describes it as clinician support; also describes imaging and clinical “safety net” suggestions. | Vendor regulatory position only. |
| https://bastiongpt.com/clinical-validation | Internal testing framework and 99.3% accuracy claim. | Broad internal results are not reproducible publicly; the cited study was narrow. |
| https://pubmed.ncbi.nlm.nih.gov/41860987/ | Peer-reviewed PICU feasibility study: 14 parents, 10-minute GPT-4o sessions, 1,225 sentences, eight minor errors, 99.3% sentence accuracy, NPS +57. | Small, single-center, English-only, no control or long-term outcome; abstract does not name the commercial platform. |
| https://www.fda.gov/medical-devices/digital-health-center-excellence/step-6-software-function-intended-provide-clinical-decision-support | Current FDA function-specific CDS guidance on images, directives, and independent review. | General guidance; no product determination here. |
| https://s36.a2zinc.net/clients/apa/apa25/Public/eBooth.aspx?BoothID=105872&Task=Products | Public APA 2025 record lists BastionGPT as exhibitor, booth 215. | Confirms exhibitor status, not public clinical endorsement or validation. |

6. Mixed HugoScore Profile

| Public question | Answer | Rationale |
| --- | --- | --- |
| Who does this AI serve? | Clinicians, practices, and health systems | Professional users and organizations buy, prompt, review, and operationalize it. |
| Can patients tell AI is involved? | Partial and deployment-dependent | Consent guidance exists, but the scribe is marketed as having no visible bot and downstream drafting may not be labeled. |
| Can patients meaningfully choose? | Not established; partial only in strong local deployments | Optional templates do not ensure disclosure, refusal without penalty, or withdrawal. |
| Can patients correct or challenge what the AI produces? | Partial, clinician-mediated | Clinicians edit drafts; no direct BastionGPT patient transcript, correction, deletion, or appeal workflow is documented. |
| Does it help patients understand or act? | Indirectly | Patient-facing documents and one narrow research pilot show potential, but routine use is professionally controlled. |

Equity Burden

Use depends on a participating professional or institution and clinician review. Vendor pages claim multilingual and accent handling, but language lists, subgroup results, interpreter performance, speech-disability performance, and noisy-room evidence are not public.

The PICU study was English-only at one quaternary center and reported underrepresentation of Hispanic and Black families. It cannot establish equitable benefit across languages, literacy levels, disabilities, settings, or populations.

Data Governance

Positive commitments include a BAA, encryption, named Microsoft and Google customer-content subprocessors, no advertising use of PHI, and contractual no-model-training language.

Material gaps remain:

  • Account content can outlive the broad “30-day maximum” claim.
  • Deletion may take up to 30 days to propagate through underlying systems.
  • Anthropic is not in the current displayed subprocessor table despite Claude marketing.
  • Public pages use inconsistent language about whether third-party providers process content for service delivery.
  • Acoustic-fingerprint or voice-print handling is not separately disclosed.
  • Patients generally depend on the provider for access and amendment.

Clinical Boundaries

Formal terms require clinician review and acknowledge error risk. Practical uses include patient-specific interventions, image observations, assessment interpretation, treatment-plan drafting, and safety-net review. FDA's current approach is function-specific. Qualified review should examine each marketed function; HugoScore makes no device-status judgment.

Evaluation Ownership

The vendor and its advisory board define the internal validation program. Public methods do not include reproducible test sets, denominators, acceptance thresholds, model versions, document-type results, or subgroup findings.

The PICU study is useful peer-reviewed evidence, but it tested a narrow research workflow. The vendor identifies BastionGPT as the platform; the PubMed abstract describes a HIPAA-compliant GPT-4o chatbot without naming it. The official APA record confirms an exhibitor booth, not a public product-evaluation report.

7. Key Unknowns

  • Live patient notice, consent, refusal, withdrawal, and equivalent-care workflow.
  • AI labels on final notes and patient communications.
  • Patient access to audio, transcript, prompt, output, model identity, and audit history.
  • Direct patient correction, deletion, complaint, and appeal routes.
  • Complete model-routing and subprocessor map, including Claude.
  • Retention by content type, plan, model, backup, audit, and abuse-monitoring layer.
  • Creation, storage, reuse, and deletion of speaker voice prints.
  • Administrator, support, and vendor access to clinical content.
  • Scope and results of audits, certifications, penetration tests, and incident review.
  • Reproducible accuracy, safety, and equity results for each major feature.
  • Error escalation, rollback, and patient notification.
  • Function-specific FDA and other regulatory analysis.
  • Accessibility and independent clinical validation.

8. Patient Agency Interpretation

BastionGPT can improve an institutional workflow. A clinician may listen more, write clearer documents, or catch a missing detail. Its BAA and no-training commitment are meaningful safeguards compared with unsuitable consumer accounts.

Patients still control little. They usually do not choose the model, see the prompt, govern retention, inspect source transcripts, or challenge the vendor directly. Strong clinician oversight can protect them, but it also leaves agency with professionals and institutions.

The most agency-supportive deployment would require clear notice before capture, refusal without reduced care, transparent model and data paths, understandable retention, visible AI provenance, patient access to relevant artifacts, easy correction, subgroup monitoring, and independent validation of high-stakes functions.

9. Publication Recommendation

Publish as a medium-confidence, AI-assisted public-source draft under Clinical decision support. Do not mark reviewed or verified.

Human review should prioritize live notice and refusal, retention conflicts, model and subprocessor paths, voice-print handling, patient correction rights, reproducible validation, security-attestation scope, the APA claim, and function-specific regulatory review.

Review Provenance

  • Criteria: HugoScore patient agency framework derived from CAIHL, using the same public questions and mixed answer types applied to every tool.
  • Submission: Externally submitted for review through HugoScore's public channel on 2026-07-27; not selected by the project owner; identified by the project owner as the first externally submitted tool added to the directory.
  • Reviewer: AI-assisted public-source draft prepared in OpenAI Codex; no named human reviewer is recorded.
  • AI / model: OpenAI Codex / GPT-5.
  • Human review: No comprehensive human review has been completed or claimed.
  • Review date: 2026-07-27.
  • Limitations: No live account or deployment testing, private assurance or contract review, vendor or user interview, security/model/accessibility audit, legal review, regulatory determination, or independent validation of the current commercial platform.