We protect the health information your clinic shares with us.

Check-ins and reorder texts can include names, replies, and light care context. We treat that as protected health information from day one. BAA at signup. US servers. Published controls. Not a certification wish list.

Core commitments

How we protect PHI.

  • Encryption & US servers

    Encrypted while moving through Echo systems and while stored. Patient health information stays on servers in the United States.

  • Only what we need

    We collect what is needed for check-ins and reorders. We do not sell your data, train models on patient health information, or use it for advertising.

  • Clinics stay separate

    Each clinic's patients stay in their own workspace. Staff only see what their job requires. Reads are logged. Clinics cannot see each other's data.

  • Your data, your clinic

    Export on cancel. Delete within 30 days. Certificate of destruction on request. Audit logs per your BAA.

PHI surfaces

Where PHI can show up.

One BAA covers check-in texts, portal flows, staff queues, and the clinic app. Same isolation, encryption, and audit logging everywhere.

  • Patient-facing

    Patient texts

    Health info in scope

    Message bodies and replies live in the patient thread from your clinic branded contact card. Staff approve the playbook once from a fixed template list. Echo runs those texts on the schedule in that playbook. How often a patient hears from you follows what they chose, plus event-driven texts such as running-low. Staff step in for exceptions. Texts stay short: check-ins, reorder prompts, simple replies. When more detail is needed, patients get a link to a secure page (or a short "you have a message" notice). Not for diagnoses or emergency triage.

  • Clinic-facing

    clinic app

    Health info in scope

    Your team can open a recap of the thread before a visit: last visit plan, check-in replies, and reorder confirms. Clinical interpretation stays with your clinicians.

In place today

Controls on every text and visit summary.

  • HIPAA security program

    Administrative, physical, and technical safeguards aligned to the HIPAA Security Rule. BAA with Ekco Health Ltd. required before patient health information is in scope.

  • Encryption

    Standard encryption while data moves through Echo systems and while it is stored. Patient phones may still show lock-screen previews. Standard cellular texts are not always encrypted end to end on the path to the device.

  • Staff approval & playbook

    Staff approve a short playbook once. Echo runs those texts on the schedule in that playbook. Starts stay on a fixed message list so content stays short and easier to keep within your consent rules.

  • Clinics stay separate

    Database controls keep each clinic's patients in their own workspace. One clinic cannot read another's patients.

  • Audit logging

    Tamper-evident audit log records reads and messaging actions. Logs are retained for seven years per our data retention policy, then destroyed per your BAA.

  • HIPAA Security Risk Assessment

    Completed and maintained on a regular review cycle. Summary available on request.

Compliance detail

BAA, TCPA, and complaints.

Expand only what you need. Full legal detail stays here, not spread across the scroll.

Your data

Lifecycle, step by step.

  • What we receive

    Patient identifiers, message content and replies, schedule details, and the context your team needs in the clinic app. Only what is required to run check-ins and reorders for your clinic.

  • What we use it for

    Staff-approved check-in texts, reorder confirms, and staff queues. A recap of those threads for your team before a visit. Audit trail for your compliance team. Nothing else.

  • Where it lives

    Patient health information stays on servers in the United States. Encrypted while moving through Echo systems and while stored.

  • If you leave

    Cancel anytime. We export your data in a portable format and delete it from our systems within 30 days. A certificate of destruction is available on request. Audit logs are retained per your BAA (up to seven years), then destroyed per your agreement.

De-identified data. We may use properly de-identified, aggregated data to improve product accuracy and publish benchmarks. Details are in your BAA and available on request.

FAQ

Questions clinics ask first.

Need receipts?

Security questionnaires are typically turned around within five business days. Detailed documentation available on request.

contact@helose.comsecurity@helose.comprivacy@helose.com