HugoScore hugoscore.org

Clinical decision support

BastionGPT

BastionGPT remains a professional-controlled AI workspace. August terms strengthen restrictions on model evaluation and derivative-data creation. Those commitments protect data without transferring clinical goals, capture, or output authority to patients.

AI-assisted draft Read full report Open directory

Published September 8, 2026 as an AI-assisted draft. The public report separates documented facts, agency judgments and unresolved questions.

16 /100 toward patient-directed
Agency posture Mixed, strongly institution-directed
The question we ask Who does BastionGPT serve in this deployment?
Control Professional and institution-controlled clinical AI workspace.
Agency read Mixed, strongly institution-directed
Vendor
FortaTech Security, LLC, doing business as Bastion Intelligence
Who it serves
Institutional, clinician-mediated clinical AI assistant and documentation platform
Primary User
Clinicians, therapists, healthcare staff, practices, and health systems
Control Model
Professional or institution-configured service. Patient controls depend on the deployment.
Patient Impact
Clinician review and patient-facing documents may help, but no direct patient access to prompts, source transcripts or an individual appeal process was established. The narrow prior PICU study cannot validate this broader platform.
Profile Status
AI-assisted draft
Last assessed
Sep 8, 2026
Review Confidence
Medium for contractual changes, limited for local practice (AI-assisted draft)
AI / Model
OpenAI Codex / GPT-6
Human Review
Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Summary judgment · 16 out of 100 toward patient-directed

Professional and institution-controlled clinical AI workspace. Preserve the July 27 external-submission disclosure and 16 baseline, not an endorsement.

Mixed, strongly institution-directed

BastionGPT remains a professional-controlled AI workspace. August terms strengthen restrictions on model evaluation and derivative-data creation. Those commitments protect data without transferring clinical goals, capture, or output authority to patients.

Patient agency

How this tool changes agency

Expands agency when

Clinician review and patient-facing documents may help, but no direct patient access to prompts, source transcripts or an individual appeal process was established. The narrow prior PICU study cannot validate this broader platform.

Limits agency when

Enforcement, actual routing, local refusal and access to source artifacts were not tested. The older broad security-page retention wording was not separately rechecked.

Patient agency assessment

Who sets and changes the goal?

Patient authority

Professionals retain prompt, model, retention and output authority. Stronger vendor contractual restrictions protect patients' data without giving patients direct control over clinical objectives, capture or correction.

What can the patient understand, question, or do?

Critical capacity

Clinician review and patient-facing documents may help, but no direct patient access to prompts, source transcripts or an individual appeal process was established. The narrow prior PICU study cannot validate this broader platform.

Can the patient evaluate the conditions of use?

Informed control

Credit the explicit new model-evaluation and derivative-data prohibitions. The retention explanation now needs content-specific wording. Listed processors still do not completely explain every marketed model path, and local patient notice remains a separate requirement from professional account controls.

Text findings

Why is this tool included?

First externally submitted tool; not selected or endorsed by the project owner

BastionGPT was submitted for review through HugoScore's public tool-submission channel on 2026-07-27. The project owner states that it was not selected by them and is HugoScore's first tool added from an external submission. Publishing this draft records the review response and does not endorse the submission, vendor, or product.

Conditions of use

Published controls and their limits

Credit the explicit new model-evaluation and derivative-data prohibitions. The retention explanation now needs content-specific wording. Listed processors still do not completely explain every marketed model path, and local patient notice remains a separate requirement from professional account controls.

What remains unknown?

Not tested or not established

Enforcement, actual routing, local refusal and access to source artifacts were not tested. The older broad security-page retention wording was not separately rechecked.

Who evaluated this?

AI-assisted public-source draft

Vendor statements describe published conditions, not independently verified behavior. No clinical, security, accessibility, or legal validation is claimed. Earlier evidence remains dated in the report and history.

Sources checked

Source-specific findings and retrieval limitations are recorded in the full report.

Review provenance

Criteria

CAIHL-derived HugoScore framework and September 7 qualitative review priorities. Draft v1.2 numerical anchors remain unadopted.

Reviewer

AI-assisted public-source reassessment prepared in OpenAI Codex.

AI / model

OpenAI Codex / GPT-6

Human review

Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Review date

2026-09-08

Limitations

Enforcement, actual routing, local refusal and access to source artifacts were not tested. The older broad security-page retention wording was not separately rechecked. No live product use, patient-data upload, account creation, code audit, clinical evaluation, or independent implementation validation.

Review method

Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.

AI-assisted draft · Medium for contractual changes, limited for local practice (AI-assisted draft)