SecureSBU: Your AI Security Partner
Empowering Healthcare Security Through AI and Real-Time Policy Intelligence
Overview
SecureSBU is an AI-powered, Teams-integrated security chatbot designed for Stony Brook University Hospital (SBUH).
It bridges the gap between complex HIPAA regulations and real-world staff workflows by delivering instant, accurate, and actionable policy guidance.
Core Capabilities
- Instant Policy Guidance — Provides accurate answers to complex security and HIPAA questions.
- Live Policy Updates — Automatically updates its knowledge base when a new policy PDF is uploaded.
- One-Click Incident Reporting — Enables users to report suspicious activities (phishing, data leaks, etc.) directly to the security team in real time.
Inspiration
Healthcare organizations face massive financial and legal risks from HIPAA violations — often caused by simple human mistakes.
Policy documents are long, complex, and constantly changing, making it unrealistic for staff to keep up.
We asked ourselves:
“What if security compliance could evolve as fast as the policies themselves?”
SecureSBU was built to answer that question — creating a living, zero-maintenance policy assistant that always provides the right answer, at the right time.
How It Works
Architecture
- Frontend: React + TypeScript
- Backend: Node.js + Express
- Database: MySQL
Core Technologies
NeuralSeek (RAG Framework)
- The chatbot ingests the full SBUH policy PDF and queries it in real time.
- This enables true “live policy updates” — no retraining or redeployment required.
- The model is strictly grounded in the uploaded document, eliminating hallucinations.
- The chatbot ingests the full SBUH policy PDF and queries it in real time.
Discord Webhook Integration
- When a user reports a critical incident, the system instantly sends a structured alert to the security team’s Discord channel.
- This closes the loop from user detection → incident report → team response within seconds.
- When a user reports a critical incident, the system instantly sends a structured alert to the security team’s Discord channel.
Challenges
Achieving 100% Accuracy
In healthcare, misinformation isn’t just inconvenient — it’s dangerous.
We prevented AI “hallucinations” by leveraging NeuralSeek’s Retrieval-Augmented Generation (RAG), ensuring every answer is backed by verified policy sources.
Building a Smart Workflow
We enhanced the chatbot with risk-aware logic.
If a user query includes sensitive keywords (e.g., PHI, personal email), the bot proactively interrupts its response and offers a “Report Incident” button — transforming it from a passive assistant into an active security guardian.
What We Learned
- RAG-powered AI enables the creation of powerful, accurate, and self-updating enterprise chatbots in hours, not weeks.
- Information is valuable only when it drives action — the Discord integration showcased how to connect user intent to immediate operational response.
- Human-centered design in security tools can drastically reduce errors, improve compliance, and strengthen organizational trust.
Vision
SecureSBU represents a shift from static compliance documents to dynamic, intelligent security infrastructure.
By combining AI precision with human oversight, we’re building a future where every hospital staff member becomes part of the security defense system — effortlessly.
SecureSBU — Protecting Privacy. Empowering People. Elevating Healthcare Security.
Log in or sign up for Devpost to join the conversation.