HugoScore hugoscore.org

Clinical decision support

BastionGPT

BastionGPT is a multi-model generative-AI workspace for healthcare professionals and organizations, combining clinical chat, long-document and image analysis, note and report drafting, an ambient and uploaded-audio scribe, patient-facing document generation, and clinician-facing suggestions. Its BAA, no-model-training commitment, named subprocessors, and clinician-review rules are meaningful safeguards. Patient agency remains indirect: the ambient scribe is marketed as having no visible bot, notice and refusal depend on local deployment, patients lack a documented direct correction route, retention statements conflict, and the exact model/subprocessor path is incomplete. A small peer-reviewed PICU feasibility study is encouraging for one supervised GPT-4o parent-chatbot workflow but does not validate the current multi-model commercial platform or its broader scribe, imaging, assessment, and treatment-support uses.

Public-source research has been drafted, often with AI assistance. No comprehensive human review is recorded unless the profile provenance says so.

16 /100 toward patient-directed
Agency posture Mixed, strongly institution-directed
The question we ask Who does BastionGPT serve in this deployment?
Control Institutional or clinician-mediated use with patient impact
Agency read May help care, but must be tested for visibility, consent, correction, and institutional priority drift.
Vendor
FortaTech Security, LLC, doing business as Bastion Intelligence
Who it serves
Institutional, clinician-mediated clinical AI assistant and documentation platform
Primary User
Clinicians, therapists, healthcare staff, practices, and health systems
Control Model
Vendor-hosted multi-model platform by default, with an enterprise customer-cloud option; professionals and organizations control inputs, prompts, model selection or routing, outputs, and record use
Patient Impact
Visit recording and speaker attribution; clinical note, assessment, report, treatment-plan, discharge, referral, patient-education, insurance, and appeal drafting; long-record and image analysis; clinician-facing suggestions; and possible clinician-mediated or supervised patient communication
Profile Status
Draft profile
Last Reviewed
Jul 27, 2026
Review Confidence
Medium draft, extensive official documentation plus a small peer-reviewed feasibility study; deployment-specific patient controls and broader validation remain incomplete
AI / Model
OpenAI Codex / GPT-5.
Human Review
No comprehensive human review has been completed or claimed for this draft profile.

Summary judgment · 16% toward patient-directed

Mixed, strongly institution-directed

BastionGPT may indirectly benefit patients through clinician attention, clearer documents, and a more appropriate PHI environment than consumer AI. Clinicians and organizations nevertheless choose and govern the system, while patients have no documented direct control over model choice, prompts, retention, source artifacts, or vendor-level correction.

Patient agency

How this tool changes agency

Expands agency when

Clinicians can generate patient-facing summaries, discharge information, education, and reports. A small peer-reviewed PICU study found encouraging satisfaction and sentence-level accuracy in a supervised parent-chatbot pilot, but routine commercial use remains clinician-mediated and that study does not validate the broader current product.

Limits agency when

Consent templates mention a right to decline or withdraw, but the vendor describes them as optional and leaves implementation to practices. No public product workflow guarantees disclosure, refusal without reduced care, withdrawal, or patient control over downstream drafting, retention, and record use.

Patient-facing signals

Who does this AI serve?

Clinicians, practices, and health systems

Professional users and organizations buy, configure, prompt, review, and operationalize BastionGPT. Patients may benefit from attention, documentation, and communication, but they are generally subjects of processing or recipients of clinician-approved outputs rather than product users.

Can patients tell AI is involved?

Partial and deployment-dependent

BastionGPT publishes optional patient-consent templates, but its homepage markets online-visit scribing with no visible bot. Public materials do not establish a required patient notice gate or persistent AI label for notes, summaries, education, recommendations, or other outputs.

Can patients meaningfully choose?

Not established; partial only in strong local deployments

Consent templates mention a right to decline or withdraw, but the vendor describes them as optional and leaves implementation to practices. No public product workflow guarantees disclosure, refusal without reduced care, withdrawal, or patient control over downstream drafting, retention, and record use.

Can patients correct or challenge what the AI produces?

Partial, clinician-mediated

Clinicians can review and edit drafts before EHR insertion, and patients may use ordinary provider record-amendment processes. No public BastionGPT patient workflow provides direct access to source audio, transcripts, prompts, model identity, outputs, deletion, correction, investigation, or appeal.

Does it help patients understand or act?

Indirectly, with one narrow encouraging research example

Clinicians can generate patient-facing summaries, discharge information, education, and reports. A small peer-reviewed PICU study found encouraging satisfaction and sentence-level accuracy in a supervised parent-chatbot pilot, but routine commercial use remains clinician-mediated and that study does not validate the broader current product.

Text findings

Why is this tool included?

First externally submitted tool; not selected or endorsed by the project owner

BastionGPT was submitted for review through HugoScore's public tool-submission channel on 2026-07-27. The project owner states that it was not selected by them and is HugoScore's first tool added from an external submission. Publishing this draft records the review response and does not endorse the submission, vendor, or product.

Who is left out or burdened?

Access, language, speech, disability, consent, and review burdens remain insufficiently evaluated

Use requires a participating professional or institution and clinician capacity to review. Vendor pages claim multilingual and accent handling, but language lists, subgroup results, interpreter workflows, speech-disability performance, and noisy-room evidence are not public. The PICU study was English-only at one center and reported underrepresentation of Hispanic and Black families.

What happens to patient data?

Meaningful contractual safeguards, conflicting retention and incomplete model-path disclosure

Public terms incorporate a BAA for covered PHI use, list Microsoft and Google as customer-content subprocessors, and prohibit model training on chat and transcription content. A current support article says chats may remain until deletion, uploads while an account is active, transcripts from 1 to 365 days, and processing logs up to 30 days, conflicting with broader 30-day-max wording. Anthropic is absent from the displayed subprocessor table despite Claude marketing, and voice-print handling is not separately disclosed.

Are the clinical boundaries clear?

Clear clinician-review rule, broader marketed function boundary needs review

Terms say outputs may contain errors, require qualified-clinician review, and are not medical advice or a substitute for judgment. Marketing also includes patient-specific intervention suggestions, assessment interpretation, imaging observations, treatment-plan drafting, and diagnosis/plan safety-net review. Current FDA guidance is function-specific; this draft makes no regulatory determination.

Who defined what good looks like?

Mostly vendor, advisory-board, clinician, and institution-defined, with one narrow peer-reviewed pilot

The vendor describes a broad internal validation catalog but does not publish reproducible test sets, model versions, denominators, thresholds, document-type results, or subgroup findings. The 14-parent PICU study supports one supervised GPT-4o research workflow, not the current full platform. The public APA record confirms exhibitor status, not a public clinical endorsement or evaluation report.

Review provenance

Criteria

Same HugoScore CAIHL-derived criteria for every tool; public criteria are displayed from site/data/criteria.json, with fuller method notes in SCORING_FRAMEWORK.md.

Reviewer

AI-assisted public-source draft prepared in OpenAI Codex; no named human reviewer recorded.

AI / model

OpenAI Codex / GPT-5.

Human review

No comprehensive human review has been completed or claimed for this draft profile.

Review date

2026-07-27

Limitations

No account creation, live clinical or scribe workflow, patient consent form, customer contract, private trust-center artifact, penetration-test or assurance report, security/model/accessibility audit, vendor or user interview, legal review, regulatory determination, or independent validation of the current commercial platform.

Review method

Deep public-source review of current BastionGPT product, scribe, medical-notes, company, clinical-validation, security, privacy, terms, BAA, AI-principles, consent, retention, model-training, error, export, and FDA-status materials; the peer-reviewed PICU feasibility study and PubMed record; current FDA clinical-decision-support guidance; and the public APA 2025 exhibitor record. No account creation, live deployment testing, patient consent form, customer contract, private trust-center document, security/model/accessibility audit, vendor or user interview, legal review, regulatory determination, or independent validation of the current commercial platform.

Draft profile · Medium draft, extensive official documentation plus a small peer-reviewed feasibility study; deployment-specific patient controls and broader validation remain incomplete