SecureSBU: Your AI Security Partner

Empowering Healthcare Security Through AI and Real-Time Policy Intelligence


Overview

SecureSBU is an AI-powered, Teams-integrated security chatbot designed for Stony Brook University Hospital (SBUH).
It bridges the gap between complex HIPAA regulations and real-world staff workflows by delivering instant, accurate, and actionable policy guidance.

Core Capabilities

  • Instant Policy Guidance — Provides accurate answers to complex security and HIPAA questions.
  • Live Policy Updates — Automatically updates its knowledge base when a new policy PDF is uploaded.
  • One-Click Incident Reporting — Enables users to report suspicious activities (phishing, data leaks, etc.) directly to the security team in real time.

Inspiration

Healthcare organizations face massive financial and legal risks from HIPAA violations — often caused by simple human mistakes.
Policy documents are long, complex, and constantly changing, making it unrealistic for staff to keep up.

We asked ourselves:

“What if security compliance could evolve as fast as the policies themselves?”

SecureSBU was built to answer that question — creating a living, zero-maintenance policy assistant that always provides the right answer, at the right time.


How It Works

Architecture

  • Frontend: React + TypeScript
  • Backend: Node.js + Express
  • Database: MySQL

Core Technologies

  1. NeuralSeek (RAG Framework)

    • The chatbot ingests the full SBUH policy PDF and queries it in real time.
    • This enables true “live policy updates” — no retraining or redeployment required.
    • The model is strictly grounded in the uploaded document, eliminating hallucinations.
  2. Discord Webhook Integration

    • When a user reports a critical incident, the system instantly sends a structured alert to the security team’s Discord channel.
    • This closes the loop from user detection → incident report → team response within seconds.

Challenges

Achieving 100% Accuracy

In healthcare, misinformation isn’t just inconvenient — it’s dangerous.
We prevented AI “hallucinations” by leveraging NeuralSeek’s Retrieval-Augmented Generation (RAG), ensuring every answer is backed by verified policy sources.

Building a Smart Workflow

We enhanced the chatbot with risk-aware logic.
If a user query includes sensitive keywords (e.g., PHI, personal email), the bot proactively interrupts its response and offers a “Report Incident” button — transforming it from a passive assistant into an active security guardian.


What We Learned

  • RAG-powered AI enables the creation of powerful, accurate, and self-updating enterprise chatbots in hours, not weeks.
  • Information is valuable only when it drives action — the Discord integration showcased how to connect user intent to immediate operational response.
  • Human-centered design in security tools can drastically reduce errors, improve compliance, and strengthen organizational trust.

Vision

SecureSBU represents a shift from static compliance documents to dynamic, intelligent security infrastructure.
By combining AI precision with human oversight, we’re building a future where every hospital staff member becomes part of the security defense system — effortlessly.


SecureSBU — Protecting Privacy. Empowering People. Elevating Healthcare Security.

Share this project:

Updates