Privacy Policy

Last updated: 2026-02-06

Summary

We process dictation and visit summaries that you provide to generate structured clinical notes. You are responsible for ensuring your inputs do not contain patient identifiers. We store only the minimum data needed to operate the service.

What we collect

  • Account info (email, username, organization name if provided).
  • Usage counters (audio minutes and note generations).
  • Saved templates and preferences you choose to store.
  • Operational metadata for troubleshooting (non-PHI audit events).
  • Usage metadata for service improvement (note format, discipline, generation timing).

What we do not store

  • Dictation audio files.
  • Dictation transcripts or generated notes. Visit content is processed in real-time and is not retained on our servers.
  • The system is designed to be used without patient identifiers. Advisory PHI detection warns you if potential identifiers are found, but does not block or remove them. You are responsible for keeping identifiers out of your dictation.

Data retention

Usage counters, templates, and audit events are retained to support billing, security, and troubleshooting. Dictation transcripts and generated notes are not stored on our servers. Only usage metadata (note format, discipline, generation timing) is retained for service improvement.

Third-party processing

EchoMed relies on subprocessors to operate. Subprocessor agreements (Business Associate Agreements where applicable, data processing agreements otherwise) are on file and available for review on request.

  • AI and speech processing — Cloud-hosted AI services intended to be covered by a Business Associate Agreement Addendum. These services process your dictation as provided — you are responsible for keeping patient identifiers out of your inputs.
  • Database hosting — Stores user accounts and usage data only. Clinical content is not retained.
  • Payment processing — PCI-DSS-compliant subscription billing.
  • Email delivery — Transactional email only (account verification, password reset). No clinical content.
  • CDN and security — DNS, TLS termination, and DDoS protection.

Secure note sharing

EchoMed offers a "Send Secure Link" feature for sharing generated notes. Notes are encrypted with a key that exists only in the recipient's link — our server cannot read the content. Links are single-use, time-limited, and automatically deleted.

Contact

Questions? Email business@echomedvoice.com.