Why trust Echo
Trust is built through architecture, not promises. Here is how Echo protects patient data, enforces consent, and maintains accountability.
Patient consent is explicit, not assumed
The provider portal cannot accept consent on behalf of a patient. This is enforced architecturally — the consent acceptance endpoint returns an error for all provider roles. Only the patient can accept.
Before any SMS check-in messages are sent, the patient must actively check an unchecked consent checkbox in the mobile app. The checkbox includes program description, message frequency, data rates, opt-out instructions, and links to the Privacy Policy, Terms, and SMS Messaging Policy. Consent is timestamped and revocable at any time.
Patients can revoke SMS consent through the mobile app Settings or by replying STOP to any message. Revocation takes effect immediately. The historical consent record is preserved for audit purposes.
Data protection
Every organization's patient data is isolated at the database level. No other organization can see or access your patients' information.
Patient data is encrypted when stored and when transmitted. Access is restricted to authorized users only.
Every data access, consent change, and administrative action is recorded with a timestamp and the identity of who performed it.
Providers see their patients. Patients see their own data. Administrators manage their organization. No one sees anything beyond their role.
Provider and administrative accounts require multi-factor authentication. A password alone is not enough.
SMS check-ins contain only the task name — for example, 'Did you complete your follow-up appointment?' No diagnoses, no medications, no clinical details.
What Echo does not do
Clarity about boundaries is part of trust.
Echo does not make clinical decisions. All clinical judgment remains with the care team.
Echo does not diagnose, prescribe, or recommend treatments.
Echo does not replace the patient-provider relationship.
Echo does not share patient phone numbers with third parties.
Echo does not send marketing or promotional messages.
Echo does not require patients to download an app to receive SMS check-ins.
Technical validation
The Echo platform has been tested against 66 specific acceptance criteria covering consent enforcement, data isolation, care plan delivery, SMS check-in scheduling, and audit logging — across mobile app, coordinator dashboard, and backend services.
Echo was not adapted from a consumer product. Multi-tenant isolation, purpose-based consent, and audit logging are foundational architectural decisions, not features added later.
Policies
Who builds Echo
Hospitals create care plans every day. Patients take them home. What happens next has always been difficult to see — and the consequences of that invisibility are preventable readmissions, missed follow-ups, and avoidable crises. Echo was built to close that gap. Jamal Bacchus designed and built the platform end-to-end — from the consent architecture to the SMS delivery system — because the problem demanded a system that worked within healthcare's constraints, not around them.
Echo is a small company by design. Every design decision and every compliance control was made by the people who will be in the room when you evaluate a pilot. That means faster answers, honest assessments, and direct accountability.