Applicability Statement for Secure Health Transport
The Direct Standard specifies a secure, authenticated, scalable method for sending health information to known recipients using profiled internet messaging, public-key infrastructure, certificate discovery, trust, and delivery notifications.
What the authority record establishes
The Direct Standard specifies a secure, authenticated, scalable method for sending health information to known recipients using profiled internet messaging, public-key infrastructure, certificate discovery, trust, and delivery notifications.
Voluntary unless incorporated into certification, contract, network policy, or program requirements
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
Direct remains a durable push-exchange path for referrals, transitions, notifications, and document delivery. Buyers should distinguish messaging capability, address discovery, trust participation, workflow integration, and delivery evidence.
Affected operating stages
- Address Provisioning
- Certificate And Trust Management
- Message Composition
- Secure Transport
- Delivery Notification
- Directory Operations
- Audit
Capabilities to examine
C-CDA Document Exchange
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for C-CDA document exchange.
Direct Secure Messaging
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for Direct secure messaging.
Provider Directory And Endpoint Discovery
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for provider directory and endpoint discovery.
Consent, Authorization, And Data Segmentation
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for consent, authorization, and data segmentation.
Operational Monitoring And Exception Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for operational monitoring and exception management.
Affected buyer audiences
- healthcare providers
- HISPs
- EHR developers
- care-coordination teams
- network and directory operators
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
A Direct address or HISP connection does not establish that the recipient will reconcile the information, that the document is complete, or that the disclosure is authorized.