Back|
B
Bastaa AI

HIPAA & Security

How Bastaa protects patient data and your clinic's compliance posture.

Last updated: April 2025

HIPAA-Aligned Infrastructure

AES-256 Encryption

Access Controls

Secure Cloud Infrastructure

1. Our Commitment to Healthcare Data

Bastaa serves dental clinics — healthcare providers who handle sensitive patient information daily. We take that responsibility seriously. Our infrastructure, policies, and operational practices are designed to align with the requirements of the Health Insurance Portability and Accountability Act (HIPAA), giving you confidence that patient data is handled with the care it deserves.

2. Business Associate Agreement (BAA)

If your clinic uses Bastaa's AI receptionist to handle calls involving Protected Health Information (PHI) — such as appointment scheduling, patient identification, or any information that could identify a patient — a Business Associate Agreement (BAA) is required under HIPAA.

Bastaa makes a BAA available to all clinic customers upon request. To receive a BAA or to ask questions about your compliance obligations, contact us at bastaateam@gmail.com.

Important Note

If you are a HIPAA-covered entity and intend to use Bastaa for patient-facing communications, please request a BAA before going live. This protects both your clinic and your patients.

3. Security Practices

3.1 Encryption

All data transmitted between your clinic, patients, and Bastaa's infrastructure is encrypted using TLS 1.2 or higher. Data stored in our systems — including call logs, patient interaction summaries, and clinic configurations — is encrypted at rest using AES-256, the same standard used by financial institutions and government agencies.

3.2 Access Controls

Access to sensitive data is restricted on a strict need-to-know basis. Our team uses role-based access controls (RBAC), meaning each person can only access the data required for their specific function. All internal access to production data is logged and auditable.

3.3 Infrastructure

Bastaa is built on enterprise-grade cloud infrastructure with high availability, automated failover, and geographic redundancy. Our hosting providers maintain their own compliance certifications (including SOC 2 Type II), and we operate under data processing agreements with all infrastructure vendors.

3.4 Monitoring & Incident Response

We continuously monitor our systems for anomalous activity, unauthorized access attempts, and potential threats. In the event of a security incident involving your data, we commit to notifying you promptly and providing clear information on what happened and what steps are being taken.

4. What 'HIPAA-Aligned' Means

You'll see us use the phrase "HIPAA-aligned infrastructure" across our site. Here's what that means in practice:

  • We apply technical safeguards consistent with the HIPAA Security Rule
  • We have administrative policies governing how PHI may be accessed and handled
  • We execute BAAs with covered entities as required
  • We do not use or disclose PHI beyond what is necessary to provide the contracted service

Note: "HIPAA-aligned" reflects our commitment to compliance practices. It is not a certification — HIPAA compliance is ultimately a shared responsibility between Bastaa and your practice.

5. Your Responsibilities

As a dental clinic using Bastaa, you remain responsible for your own HIPAA compliance posture, including staff training, patient consent practices, and your broader Privacy and Security Rules obligations. Bastaa supports you as a Business Associate — we do not replace your clinic's own compliance program.

6. Questions

Have a specific security question? Conducting a vendor review? We're happy to help. Reach us at bastaateam@gmail.com and we'll respond promptly.

© 2026 Bastaa AI. All rights reserved.