Legal & compliance hub.

Trust for clinics. Privacy for patients. Clear terms for between-visit texting. All in one place.

Policy index

Fifteen policies, not three bullets.

Ekco maintains a written compliance program reviewed annually and on material change. Summaries below; full policy text available on procurement request.

#PolicyScope
01HIPAA Privacy PolicyPatient rights, permitted uses, and complaint handling.
02HIPAA Security PolicyAdministrative, physical, and technical safeguards for PHI.
03Access Control PolicyLeast privilege, authentication, and access reviews.
04Incident Response PlanDetection, containment, notification, and recovery.
05Data Retention & DestructionSeven-year audit retention, secure deletion, destruction certificates.
06Acceptable Use PolicyWorkforce and contractor expectations for systems and data.
07Workforce Training PlanAnnual HIPAA training and onboarding requirements.
08Breach Notification PlanCustomer and regulatory notification timelines.
09Risk Management PolicyAnnual risk assessment and remediation tracking.
10Vendor / Subprocessor ManagementDue diligence, BAAs, and ongoing vendor reviews.
11Encryption PolicyTLS in transit, encryption at rest, and key management.
12Logging & Audit PolicyTamper-evident audit log, retention, and review cadence.
13Business Continuity / DRBackup, recovery objectives, and failover procedures.
14Software Development LifecycleSecure development, code review, and release gates.
15Change Management PolicyProduction change approval, rollback, and documentation.

Questions?

Procurement & questionnaires: contact@helose.com
Security inquiries: security@helose.com
Privacy complaints: privacy@helose.com