Privacy Policy
Echo Scribe ("Echo") is a Chrome extension developed and operated by Pujols Consulting LLC ("we," "us") for the healthcare practices we serve, currently Orion Health and MP Primary Care Services. It helps authorized clinicians document patient visits in the Tebra electronic health record. This policy explains what information Echo handles, how it is used, and how it is protected.
Who can use Echo
Echo is an internal clinical tool, not a consumer product. It can only be used by clinicians who have been issued an Echo login by their practice. Echo does not collect information from members of the public.
Information Echo processes
- Visit audio and transcript. When a clinician starts an encounter, Echo captures the conversation through the microphone and converts it to text in real time.
- Patient details. Information the clinician selects or enters for the visit, such as the patient's name, date of birth, and appointment.
- Clinical content. The draft clinical note and the suggested diagnosis, procedure, and quality-measure codes generated from the transcript, along with any edits and confirmations the clinician makes.
- Clinician account information. The clinician's work email and sign-in credentials. Passwords are handled by Amazon Cognito and are never stored by Echo.
How the information is used
This information is used only to provide Echo's single purpose: to transcribe the visit, draft the note and code suggestions for the clinician's review, and, when the clinician chooses, insert the reviewed note into the patient's chart in Tebra and submit the confirmed charge to Tebra as a draft encounter. Echo never signs a note or submits a charge without the clinician's explicit confirmation.
Where information is processed and shared
- Amazon Web Services (AWS). Audio, transcripts, draft notes, and code suggestions are processed within a HIPAA-eligible AWS environment covered by a Business Associate Agreement, using Amazon Transcribe for transcription, Amazon Bedrock for note and code generation, and AWS Lambda for processing. AWS does not use this content to train AI models.
- Tebra. Notes and charges are sent to the practice's Tebra account only when the clinician explicitly pushes a note or confirms a charge.
We do not sell personal or health information. We do not share it with advertisers, data brokers, or analytics providers, and we do not use it for any purpose unrelated to Echo's function or to determine creditworthiness or lending eligibility.
What is stored, and for how long
- On the clinician's device. Echo keeps the clinician's sign-in session, their settings, and a backup of recent encounters in the browser's local extension storage so an interrupted visit can be recovered. Encounter backups are deleted automatically after 72 hours.
- In the practice's AWS environment. A record of each processed encounter, which may include the draft note and codes, is kept in a secured AWS database for auditing and support, and is retained in line with the practice's record-retention requirements.
- In Tebra. Notes and charges that a clinician sends to Tebra become part of the practice's medical and billing records and are governed by the practice's own policies.
Security
All data is encrypted in transit using TLS. Access to Echo requires a practice-issued login. Echo only runs on the Tebra website and on pages where a clinician explicitly opens it, and it only writes into the specific note fields it is directed to.
Patients' rights and requests
Protected health information handled by Echo belongs to the patient's healthcare practice. Patients who want to access, correct, or ask about their health information should contact their healthcare provider directly, and we will support the practice in responding as required by HIPAA.
Changes to this policy
We may update this policy as Echo changes. The effective date above will reflect the latest version.
Contact
Questions about this policy or Echo's handling of information can be sent to Pujols Consulting LLC, Orlando, Florida, at pujolsconsulting@gmail.com.