Oxford, England
ProjectsMarch 18, 2024

EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care
From March to July 2024 I worked as an Enterprise Associate at Birmingham City University on an Innovate UK funded Accelerated Knowledge Transfer (AKT2I) project with PBL Care Limited, a home care provider. I led the feasibility study for automating PBL Care's complaint handling and built a proof of concept, which we called EchoCare. PBL Care handled complaints, feedback, and operational requests on paper. Complaints came in by phone, in person, by letter, and by email, and were processed by hand. That created four problems:
  • Delays and errors: manual processing slowed responses and increased the chance of human error
  • Hard to analyse: paper archives made it hard to spot trends or serious incidents
  • Long resolution times: the procedure allowed up to 28 working days to resolve a complaint
  • Hard to access: the process was difficult for service users with impairments or limited technical skills
All of this had to work within the Care Quality Commission (CQC) standards for service user engagement, responsiveness, safety and safeguarding, and equity.
  • Mapped PBL Care's six-stage complaint life cycle, from receipt and acknowledgement (within 3 working days) through investigation, resolution, escalation, and record keeping
  • Catalogued the ten internal and external forms the business relied on, from spot checks to probation reviews, with the complaint types each one captures and who should be able to see it
  • Reviewed CQC, GDPR, and Caldicott requirements, then built privacy by design, data minimisation, and role-based access into the design
  • Carried out data protection impact considerations and documented the risks and retention needs
  • Benchmarked ten existing tools, including osTicket, OTRS, Zammad, Zendesk, Freshdesk, and Salesforce Health Cloud, against cost, compliance, AI/ML capability, security, and scalability
  • Designed and built the proof of concept described below
  • Digital forms: CQC-standard web forms for feedback, complaint investigations, and spot checks, replacing the paper versions. Each submission gets a unique ID and is categorised as a complaint, compliment, or suggestion.
  • Database: submissions are stored in a MySQL database, with a separate store for internal forms and digitised historical records.
  • NLP classification: Python (NLTK and spaCy) classifies complaints by type and tracks keyword frequency to surface the most common issues.
  • Dashboard: a Chart.js dashboard shows complaint investigations, spot checks, feedback volumes, and sentiment in real time.
  • API integration: the system connects through APIs to PBL Care's scheduling and planning application, feeding a single database and a unified dashboard.
  • Data validation: a lightweight Python/Node.js GUI tool checks data validity and integrity. It was later merged into PHP for the API integration.
The market research found a clear gap: no existing tool combined NLP for digitising and classifying complaints with LLM-generated reporting, in a package built around CQC standards. I designed an extended framework that adds LLM-based sentiment analysis and automatic report generation to fill that gap. The project delivered:
  • the feasibility study and market research
  • a working proof of concept with CQC-standard forms, a database, NLP classification, and a live dashboard
  • an assessment of whether the system could become an off-the-shelf SaaS product for other care providers
The work also set out a proposed follow-on project, Complaint Prediction for Prevention (CPP-AI). It would use AI/ML to spot potential complaints before they happen, shifting from reacting to complaints to preventing them. .NET Core, MySQL, Python (NLTK, spaCy), Node.js, PHP, Chart.js, REST APIs.

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Xcevia: a security consultancy in the making
In development

Xcevia: a security consultancy in the making

A practitioner-led security consultancy for UK SMEs that I'm building on the side. It's not trading yet. The groundwork is being laid for Cyber Essentials Plus readiness, cloud security, and DevSecOps support.
Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage

A vendor review at a UK health-tech company. I consolidated onto one platform that covers every operating system and the cloud, then closed the one remaining gap with a dedicated patch management tool.
Incident response and endpoint security in health tech

Incident response and endpoint security in health tech

Owning day-to-day alert handling across a multi-OS estate at a UK health-tech company, correlating cloud activity with endpoint telemetry, and leading the response to a live, high-severity security incident.
Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines

Adding static application security testing (SAST) to a health-tech company's delivery pipelines, so developers find code-level vulnerabilities before release rather than after.
Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance

Preparing the organisation for Cyber Essentials Plus certification, running the annual penetration testing programme, and keeping security policy, BCP/DR and awareness training aligned with ISO 27001 and GDPR.