Direct secure messaging is a standardized, encrypted way for healthcare organizations to exchange patient health information electronically, built on the Direct Project specification and governed today by DirectTrust. It works through a system of trusted intermediaries called Health Information Service Providers (HISPs), which route messages between providers the way traditional email routes between mail servers, but with the identity verification and encryption requirements healthcare data exchange needs.
It is not SMS, and it is not regular email, even though it is often described in shorthand as secure email for healthcare. Understanding the difference matters because the three channels serve different purposes and carry different compliance profiles.
Where Direct messaging came from
The Direct Project began in 2010 as part of the federal government's push, coordinated by the Office of the National Coordinator for Health Information Technology (ONC, which carried the dual title ASTP/ONC from July 2024 until HHS reinstated ONC as a single office on March 31, 2026), to create a simple, standards-based method for providers to send clinical documents to each other electronically. It was designed as the push counterpart to more complex query-based health information exchange: instead of a provider searching a shared database, a provider sends a message directly to a known recipient's Direct address, similar to sending an email to a specific person.
Direct addresses look like email addresses, typically a name at a domain, but they route through a HISP rather than a standard email provider. Every message is encrypted, and the identity of both sender and recipient is verified through a trust framework before the exchange happens.
Who runs it today
DirectTrust is the non-profit organization that now operates and governs the trust framework behind Direct exchange. It accredits HISPs, maintains the policies that let HISPs trust each other's identity verification, and publishes network statistics on Direct message volume across the country. A HISP is the infrastructure provider, similar in role to an email service provider, that actually handles the sending, receiving, and encryption of Direct messages on behalf of a healthcare organization.
How Direct messaging differs from SMS and regular email
| Feature | Direct secure messaging | Standard SMS text | Regular email |
|---|---|---|---|
| Primary use | Provider-to-provider clinical document exchange | Patient-facing reminders, alerts, and two-way communication | General business communication |
| Identity verification | Required through the HISP trust framework before exchange | Not inherently verified; based on phone number only | Not inherently verified |
| Encryption | Required between HISPs as part of the trust framework | Carrier-dependent; content encryption is not automatic | Not applied by default without added tools |
| Typical content | Clinical summaries, referrals, discharge documents | Appointment reminders, short alerts, two-way replies | Varies widely, often not suited to PHI without added safeguards |
| Governing framework | DirectTrust accreditation and trust bundles | Carrier and platform-level, plus HIPAA if PHI is involved | Platform-level, plus HIPAA if PHI is involved |
The practical takeaway is that Direct messaging is built for clinical document exchange between organizations that both participate in the trust network. It is not designed for reaching patients on their personal phones, which is where SMS fits a different, complementary role.
What a Direct message actually looks like in practice
From a sender's perspective inside an EHR, sending a Direct message often looks like composing a routine email: choosing a recipient's Direct address, attaching a document such as a continuity of care record, and clicking send. The complexity is handled underneath by the HISP, which encrypts the payload, verifies that the receiving HISP is part of the same trust community, and confirms the recipient's identity before the message is delivered into their inbox, often the same EHR interface on the receiving end.
This matters for understanding why Direct is considered secure by design rather than secure by configuration. Unlike a general communications platform, where security depends heavily on how an organization sets it up, the Direct standard bakes identity verification and encryption into the protocol itself, which is part of why it became the default method for many required clinical data exchange scenarios tied to EHR certification programs.
Trust bundles and how HISPs learn to trust each other
A single HISP does not automatically trust every other HISP on the internet. DirectTrust organizes participating HISPs into trust bundles, which are collections of digital certificates that let one HISP verify the identity of organizations connected through other, accredited HISPs. When a hospital on one HISP sends a Direct message to a physician's office on a different HISP, the trust bundle is what allows the two systems to confirm each other's identity without a manual, one-off verification process for every new connection.
This structure is part of why Direct scaled nationally rather than remaining a collection of isolated, incompatible point-to-point connections. A healthcare organization does not need to individually vet every possible message recipient; it relies on DirectTrust's accreditation process and the trust bundle framework to have already done that verification work for any HISP that carries the accreditation.
This is also why choosing a HISP is not purely a technical decision. An organization is effectively relying on that HISP's accreditation standing and its participation in an active trust bundle to reach the widest possible set of other providers. A HISP that lets its accreditation lapse, or that participates in a smaller trust bundle, can leave an organization unable to exchange with providers it needs to reach, even though the underlying Direct standard itself has not changed.
For organizations evaluating EHR vendors or standalone Direct services, it is worth asking directly which trust bundle a HISP participates in and how that compares to the bundles used by the organizations they most frequently need to exchange documents with, such as referring specialists, hospitals, or public health agencies.
Adoption of Direct exchange has been driven substantially by its tie to federal EHR certification requirements rather than by voluntary uptake alone, which is part of why many healthcare organizations already have some form of Direct capability available through their existing EHR even if staff rarely interact with it directly. DirectTrust publishes network volume statistics for organizations that want current figures.
Where Direct fits alongside patient texting
A common point of confusion is assuming Direct messaging and HIPAA compliant SMS solve the same problem. They do not. Direct messaging moves structured clinical data, such as a continuity of care document, between a hospital's EHR and a referring physician's EHR. Patient text messaging is a different channel entirely, used for appointment reminders, intake instructions, and two-way patient communication, and it has its own compliance requirements under the HIPAA Security Rule rather than the DirectTrust framework. For a full breakdown of what makes texting itself compliant, see whether standard texting is HIPAA compliant.
Organizations that need both structured provider-to-provider exchange through Direct and patient-facing texting through SMS typically run them as two separate, purpose-built systems rather than trying to force one channel to do both jobs. When a healthcare organization wants patient SMS to pull data from the same EHR that feeds its Direct messaging, that connection point needs its own safeguards. See how that typically works in this guide to EHR-to-SMS integration.
Where FRANSiS fits
FRANSiS is not a HISP and does not replace Direct messaging for provider-to-provider clinical exchange. It is built for the patient-facing side of communication, appointment reminders, intake, and two-way messaging, with the safeguards that channel requires. See FRANSiS's healthcare messaging tools for how patient texting is typically layered alongside a Direct-enabled EHR rather than replacing it.
This article is general information, not medical or legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel, your EHR vendor, or the relevant regulator.
Frequently Asked Questions
What is Direct secure messaging in healthcare?
Direct secure messaging is a standardized, encrypted method for exchanging clinical health information electronically between providers, built on the ONC-originated Direct Project specification and governed today by DirectTrust. Messages route through accredited Health Information Service Providers (HISPs) that verify identity and encrypt content before delivery.
Is Direct messaging the same as email?
No, though it resembles email in format. Direct addresses look similar to email addresses, but the underlying system requires identity verification and encryption through a HISP trust framework before any exchange happens, which standard email does not provide by default.
What is a HISP?
A Health Information Service Provider (HISP) is the infrastructure organization that handles sending, receiving, and encrypting Direct messages on behalf of a healthcare provider or organization, similar in role to an email service provider but built to meet DirectTrust's identity and security requirements.
Who governs the Direct messaging standard today?
DirectTrust, a non-profit organization, governs the trust framework behind Direct exchange today. It accredits HISPs and maintains the policies that allow different HISPs to trust each other's identity verification, building on the original specification developed through the Direct Project under ONC.
Is Direct messaging the same as texting patients?
No. Direct messaging is designed for provider-to-provider clinical document exchange through EHR systems, not for reaching patients on their personal phones. Patient text messaging is a separate channel with its own compliance requirements under HIPAA, typically used for reminders and two-way patient communication rather than clinical document transfer.
Do all EHR systems support Direct messaging?
Most certified EHR systems support Direct messaging because it has been tied to federal certification requirements and, historically, to the Meaningful Use program now known as Promoting Interoperability, but the specific implementation and which HISP an EHR connects through varies by vendor. Confirm an EHR's specific Direct capabilities directly with the vendor.
Is Direct messaging required by law?
Direct messaging itself is not a HIPAA requirement; HIPAA is technology-neutral and does not mandate a specific method for health information exchange. Direct became widely adopted because it was promoted through federal EHR certification and incentive programs coordinated by ONC, not because HIPAA names it directly.
Can Direct messages contain any type of health information?
Direct messaging is commonly used for structured clinical documents such as continuity of care documents, referrals, and discharge summaries, but the standard itself can carry various message content. What is sent through Direct is governed by the same HIPAA minimum-necessary and security principles that apply to any transmission of PHI.
Patient texting that complements your clinical exchange
FRANSiS handles the patient-facing side of communication, with a signed BAA and access controls built for PHI, while an EHR's Direct messaging continues handling provider-to-provider exchange. Contact us to see how the two typically work side by side.


