HIPAA Security Overview
Last updated: September 2026
1. HIPAA Alignment
Bastaa is architected to align with the HIPAA Security Rule. We execute Business Associate Agreements (BAAs) with covered-entity clients before processing Protected Health Information (PHI).
2. Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Keys are managed with restricted access and rotation policies.
3. Access Controls
Role-based access controls limit PHI to authorized personnel. Audit logs capture access events. Multi-factor authentication is enforced for administrative access.
4. Subprocessors
Subprocessors that may contact PHI are bound by BAAs and reviewed for security posture. A current list is available on request.
5. Incident Response
We maintain an incident response plan aligned with the HIPAA Breach Notification Rule. Suspected incidents are investigated and notified per regulatory requirements.
6. Contact
Security inquiries: info@bastaa.ai.