HIPAA Security Overview

Last updated: September 2026

HIPAA Aligned
SOC2 Type II Ready
AES-256 Encryption
Bilateral PMS Sync

1. HIPAA Alignment

Bastaa is architected to align with the HIPAA Security Rule. We execute Business Associate Agreements (BAAs) with covered-entity clients before processing Protected Health Information (PHI).

2. Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Keys are managed with restricted access and rotation policies.

3. Access Controls

Role-based access controls limit PHI to authorized personnel. Audit logs capture access events. Multi-factor authentication is enforced for administrative access.

4. Subprocessors

Subprocessors that may contact PHI are bound by BAAs and reviewed for security posture. A current list is available on request.

5. Incident Response

We maintain an incident response plan aligned with the HIPAA Breach Notification Rule. Suspected incidents are investigated and notified per regulatory requirements.

6. Contact

Security inquiries: info@bastaa.ai.