How BASG Operates as a Trustworthy IT & AI Partner
This page explains the frameworks, controls, and subprocessors BASG uses to protect client data — for healthcare practices subject to HIPAA, defense contractors aligning to CMMC, and any mid-market business that wants its IT vendor held to a real standard.
Compliance Frameworks BASG Operates Under
BASG is not certified to all frameworks at all times — but our delivery model is built so client environments can pass audits in each.
HIPAA Security & Privacy Rules
BASG operates as a Business Associate for healthcare clients and signs current BAAs. We support the 2026 HIPAA Security Rule Final Rule, including mandatory encryption, MFA, biannual vulnerability scans, 72-hour recovery, and 24-hour business-associate breach notification.
CMMC Levels 1–3
For defense-industrial-base clients, BASG aligns controls to CMMC Level 1 (Foundational), Level 2 (Advanced, NIST 800-171), and Level 3 (Expert, NIST 800-172) and supports continuous evidence collection for contractor self-assessment and C3PAO assessment.
NIST CSF & SP 800-171
BASG's baseline managed-cybersecurity stack is mapped to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover) and to NIST SP 800-171 controls.
Florida Information Protection Act (FIPA)
BASG supports FIPA breach-notification timelines (30 days) and reasonable-security-measures requirements for clients operating in Florida.
HIPAA Business Associate Agreements
BASG executes Business Associate Agreements (BAAs) with all healthcare clients as required by the HIPAA Privacy and Security Rules. We sign the BAA before any access to systems containing electronic protected health information (ePHI). Our BAA covers permitted uses and disclosures, safeguards, breach notification (24-hour business-associate timeline), subcontractor management, and termination obligations.
BASG supports the 2026 HIPAA Security Rule Final Rule, which moves several previously "addressable" controls to "required" — including mandatory encryption, MFA, biannual vulnerability scans, 72-hour recovery, and 24-hour business-associate breach reporting.
Technical Controls
The baseline security posture BASG deploys for managed clients.
Encryption
Full-disk encryption (BitLocker / FileVault) on managed endpoints. TLS 1.2+ for all transport. Encryption at rest for backups and cloud storage. Customer-controlled key escrow available.
Identity & MFA
Multi-factor authentication enforced across managed accounts via Microsoft Entra ID. Conditional access policies, FIDO2/passkey support for clinical and field users, and a least-privilege admin model.
24/7 SOC Monitoring
Endpoint detection and response (EDR), SIEM aggregation, and 24/7 SOC monitoring. Average detection time under 30 minutes, automated containment within seconds of confirmed malicious activity.
Backup & Recovery
Immutable backups with documented RPO/RTO objectives. Periodic restore testing. Healthcare clients tested against the 2026 HIPAA 72-hour recovery requirement.
Vulnerability Management
Scheduled vulnerability scans — biannual minimum, more frequent for healthcare clients per the 2026 HIPAA Final Rule. CVSS-prioritized remediation with documented tracking.
Incident Response
Defined IR runbooks, 24-hour business-associate breach reporting (HIPAA), 30-day breach notification (FIPA), and tabletop exercises run with each managed client.
Subprocessors
BASG uses a small set of named subprocessors to deliver managed services. Specific tooling within each category is disclosed under MSA. BASG performs vendor security reviews before adding subprocessors and notifies clients of material changes.
| Subprocessor | Purpose |
|---|---|
| Microsoft | Microsoft 365, Azure, Entra ID, Defender, Intune |
| Amazon Web Services | Selected workload-specific cloud hosting |
| Google Cloud Platform | Selected workload-specific cloud hosting |
| EDR / SIEM vendors | Endpoint detection, SIEM aggregation, SOC tooling — exact stack disclosed under MSA |
| Backup providers | Immutable backup storage — exact provider disclosed under MSA |
Insurance & Liability
BASG maintains commercial general liability, professional liability (errors and omissions), and cyber liability insurance. Specific coverage limits are shared with clients under MSA and certificates of insurance are available on request.
BASG's master service agreement defines liability allocation, indemnification, and cyber-incident response obligations consistent with industry-standard MSP terms.
Security & Compliance FAQ
Common questions about how BASG handles security, privacy, and compliance.
Need our SOC 2 / HIPAA documentation package?
If you're a prospective or current client running through procurement or vendor risk, request our security documentation package.