Healthcare moves faster when people can trust the systems behind it.

At Basata, privacy, security, and responsible AI are built into how we develop, test, deploy, and monitor our technology. Helping patients get care sooner should never mean compromising the information entrusted to us.

Is patient information protected?

Yes, patient information is protected.

We build every layer of our infrastructure, and vet every partner who touches your data, to safeguard protected health information at every step.

Basata is HIPAA compliant, with administrative, technical and physical safeguards built into our systems, and SOC 2 audited, meaning an independent auditor has verified that the processes behind these safeguards hold up over time.

Every third party that may process protected health information signs a Business Associate Agreement and must meet our security requirements. We also regularly review those partners to make sure those standards continue to be met.

How does Basata approach responsible AI?

Basata’s AI is built to support healthcare administration—not practice medicine. We have strong guardrails and human oversight every step of the way.

Our agents operate within clearly defined roles, with guardrails and human oversight built into the workflow.

Much of what our agents do is read and classify documents, such as identifying what is contained in a fax or referral so it can move into the right workflow. A person reviews that work before it is finalized.

Voice agents operate under the same boundaries. They are given clear rules about what they can and cannot do, including restrictions on providing medical advice or clinical direction, and those rules are tested before deployment.

If an interaction falls outside the agent’s role, it escalates to a person. Patients can also request a human at any time.

Do you use customer data to train?

No, your data is your data.

Customer data is not used to train AI models.

When our systems send a document to an AI provider for analysis, that data isn’t stored or retained afterward. It’s used once, for the task at hand.

We only work with AI providers and subprocessors who meet our privacy and security requirements.

How does Basata test and monitor its AI agents?

Responsible AI requires more than a successful demo.

Every Basata agent goes through a rigorous suite of tests before deployment, including adversarial testing designed to uncover unexpected behavior. We verify that agents follow their instructions, protect patient information, confirm identity when required, and escalate appropriately.

Once deployed, agents are continuously monitored so our team can identify issues and keep improving.

Our testing program is led by CTO Vivin Paliath, whose PhD in Computer Science focused on cybersecurity and machine learning

"We build every agent to operate inside rules it can't cross, tested adversarially before it's ever in front of a patient. That level of rigor isn't optional in healthcare."

Vivin Paliath
Co- founder & CTO

How are Basata’s security controls independently validated?

HIPAA compliant
Administrative, technical, and physical safeguards designed to protect PHI.
SOC 2 audited
Independent validation of the controls supporting the security and reliability of our systems.
Continuous security monitoring
Ongoing monitoring, testing, and alerting—not a one-time review.
Carefully vetted partners
Security reviews, contractual protections, and BAAs (Business Associate Agreement) for subprocessors that may handle PHI.