Why trust Echo

Trust is built through architecture, not promises. Here is how Echo protects patient data, enforces consent, and maintains accountability.

Patient consent is explicit, not assumed

Patients control their own consent

The provider portal cannot accept consent on behalf of a patient. This is enforced architecturally — the consent acceptance endpoint returns an error for all provider roles. Only the patient can accept.

SMS consent requires an explicit opt-in

Before any SMS check-in messages are sent, the patient must actively check an unchecked consent checkbox in the mobile app. The checkbox includes program description, message frequency, data rates, opt-out instructions, and links to the Privacy Policy, Terms, and SMS Messaging Policy. Consent is timestamped and revocable at any time.

Consent is revocable

Patients can revoke SMS consent through the mobile app Settings or by replying STOP to any message. Revocation takes effect immediately. The historical consent record is preserved for audit purposes.

Data protection

Your data is completely separate

Every organization's patient data is isolated at the database level. No other organization can see or access your patients' information.

Everything is encrypted

Patient data is encrypted when stored and when transmitted. Access is restricted to authorized users only.

Every action is logged

Every data access, consent change, and administrative action is recorded with a timestamp and the identity of who performed it.

People see only what they should

Providers see their patients. Patients see their own data. Administrators manage their organization. No one sees anything beyond their role.

Two-step login required

Provider and administrative accounts require multi-factor authentication. A password alone is not enough.

Text messages contain no clinical data

SMS check-ins contain only the task name — for example, 'Did you complete your follow-up appointment?' No diagnoses, no medications, no clinical details.

What Echo does not do

Clarity about boundaries is part of trust.

Echo does not make clinical decisions. All clinical judgment remains with the care team.

Echo does not diagnose, prescribe, or recommend treatments.

Echo does not replace the patient-provider relationship.

Echo does not share patient phone numbers with third parties.

Echo does not send marketing or promotional messages.

Echo does not require patients to download an app to receive SMS check-ins.

Technical validation

Verified across 66 acceptance criteria

The Echo platform has been tested against 66 specific acceptance criteria covering consent enforcement, data isolation, care plan delivery, SMS check-in scheduling, and audit logging — across mobile app, coordinator dashboard, and backend services.

Designed for healthcare from the beginning

Echo was not adapted from a consumer product. Multi-tenant isolation, purpose-based consent, and audit logging are foundational architectural decisions, not features added later.

Policies

Who builds Echo

Hospitals create care plans every day. Patients take them home. What happens next has always been difficult to see — and the consequences of that invisibility are preventable readmissions, missed follow-ups, and avoidable crises. Echo was built to close that gap. Jamal Bacchus designed and built the platform end-to-end — from the consent architecture to the SMS delivery system — because the problem demanded a system that worked within healthcare's constraints, not around them.

Echo is a small company by design. Every design decision and every compliance control was made by the people who will be in the room when you evaluate a pilot. That means faster answers, honest assessments, and direct accountability.