Legal & compliance hub.
Trust for clinics. Privacy for patients. Clear terms for between-visit texting. All in one place.
Start here
Public documents.
Clinics
Terms of service
The agreement that governs clinic use of Ekco, provided by Ekco Health Ltd. Fees, acceptable use, liability, and governing law.
Clinics
Trust & security
For clinics, procurement, and IT. BAA, controls, and clinic responsibilities.
Patients + clinics
Data & privacy
Plain-language privacy for patients and clinic staff. Encryption, access, and your choices.
Patients
Messaging terms
Patient opt-in terms for health-related texts. Channel limits, STOP, and your responsibilities.
Clinics
Business Associate Agreement
Click-through BAA at clinic signup. Counter-signed BAA available on annual contracts.
Policy index
Fifteen policies, not three bullets.
Ekco maintains a written compliance program reviewed annually and on material change. Summaries below; full policy text available on procurement request.
| # | Policy | Scope |
|---|---|---|
| 01 | HIPAA Privacy Policy | Patient rights, permitted uses, and complaint handling. |
| 02 | HIPAA Security Policy | Administrative, physical, and technical safeguards for PHI. |
| 03 | Access Control Policy | Least privilege, authentication, and access reviews. |
| 04 | Incident Response Plan | Detection, containment, notification, and recovery. |
| 05 | Data Retention & Destruction | Seven-year audit retention, secure deletion, destruction certificates. |
| 06 | Acceptable Use Policy | Workforce and contractor expectations for systems and data. |
| 07 | Workforce Training Plan | Annual HIPAA training and onboarding requirements. |
| 08 | Breach Notification Plan | Customer and regulatory notification timelines. |
| 09 | Risk Management Policy | Annual risk assessment and remediation tracking. |
| 10 | Vendor / Subprocessor Management | Due diligence, BAAs, and ongoing vendor reviews. |
| 11 | Encryption Policy | TLS in transit, encryption at rest, and key management. |
| 12 | Logging & Audit Policy | Tamper-evident audit log, retention, and review cadence. |
| 13 | Business Continuity / DR | Backup, recovery objectives, and failover procedures. |
| 14 | Software Development Lifecycle | Secure development, code review, and release gates. |
| 15 | Change Management Policy | Production change approval, rollback, and documentation. |
Questions?
Procurement & questionnaires: contact@helose.com
Security inquiries: security@helose.com
Privacy complaints: privacy@helose.com