Service

DirectTrust HISP accreditation is DirectTrust’s accreditation for Health Information Services Providers that operate Direct Secure Messaging, assessed against the 2026 criteria version “Health Information Services Provider (HISP) v2.2”. It is for vendors running secure health messaging services. Integral Healthcare Solutions (IHS) builds the organizational policies and evidence for HISP accreditation and runs a mock review; your engineers own technical conformance.

Last reviewed: October 2026.

What is DirectTrust HISP accreditation?

DirectTrust says the program “recognizes that an organization operates at a very high level of privacy, security, and trust in identity, and signals to users/subscribers that it is a trustworthy agent and service provider for Direct Secure Messaging.” (source) The program page adds: “It focuses on various aspects including HIPAA privacy, security, cyber security, technical and operational capabilities, and policy adherence.” (source)

The program has mandatory criteria. DirectTrust says it “emphasizes mandatory criteria that applicants must fully meet and respond to, including demonstrating compliance with HIPAA requirements, participating in the Aggregated Directory, and managing private and public key pairs in accordance with the DirectTrust Certificate Policy and DirectTrust HISP Policy.” (source)

The governing text for 2026 is “Health Information Services Provider (HISP) v2.2”, one of the new versions DirectTrust released for “its 28 accreditation programs starting January 1, 2026.” (source) Unlike several other DirectTrust programs, the HISP version has no asterisk in that release, so it does not itself contain DirectTrust’s standard Privacy and Security criteria (source). On IHS’s reading (October 2026), this is why the program has a separate HIPAA prerequisite, described below. DirectTrust states its programs “are governed by the organization’s Electronic Healthcare Network Accreditation Commission (EHNAC).” (source)

The criteria are released on request, and IHS did not review the DirectTrust Certificate Policy or HISP Policy for this page; this page relies on DirectTrust’s public program pages. A draft 2027 criteria release is out for comment until November 17, 2026 (source).

Who needs it and what triggers it?

The buyer is a vendor operating a secure health messaging service that wants to act as a HISP for Direct Secure Messaging. The trigger is a defined DirectTrust accreditation objective, or building the operating program the accreditation expects.

The HIPAA prerequisite

DirectTrust says: “Organizations seeking HISP accreditation must demonstrate compliance with HIPAA privacy and security regulations.” (source) It accepts three forms of proof (source):

Settle which route you will use before starting the HISP self-assessment, because it decides whether you are preparing for one program or two.

How IHS helps

IHS covers the organizational and documentation side of HISP accreditation only. The work runs in this order:

  1. Gap assessment of your organizational controls against the Health Information Services Provider (HISP) v2.2 criteria your organization requests from DirectTrust.
  2. Questionnaires on participant onboarding, identity proofing records, agreements and incidents.
  3. Document and evidence mapping: each criterion crosswalked to the policy, record or engineering artifact that answers it.
  4. Drafting: governance, onboarding, agreement oversight and incident procedures, for your leaders to review and approve.
  5. Mock review of the organizational evidence against the criteria.
  6. Readiness support: drafted responses to findings for your organization to submit.

What your organization supplies: the criteria, your agreements, onboarding records, and engineering and security staff for every technical conformance item. Your organization submits its own application.

The limit: the technical side of HISP accreditation (messaging, certificates, Aggregated Directory participation, key management) is your engineers’ work. IHS documents and organizes it and does not test it.

How the DirectTrust process runs

DirectTrust does not publish a typical end-to-end timeline on the pages we reviewed.

What to have ready

This list ties to DirectTrust’s published process and the HISP program page. The criteria text (Health Information Services Provider (HISP) v2.2) governs; check each item against your copy.

  1. A copy of the Health Information Services Provider (HISP) v2.2 criteria, requested from DirectTrust (criteria are available on request).
  2. Your chosen proof of HIPAA compliance: DirectTrust Privacy and Security accreditation, another qualifying DirectTrust accreditation, or qualifying HITRUST certification (HISP program page).
  3. Copies of the DirectTrust Certificate Policy and DirectTrust HISP Policy, and your procedures for managing private and public key pairs under them (HISP program page).
  4. Evidence of participation in the Aggregated Directory (HISP program page).
  5. HIPAA privacy, security and cyber security policies (HISP program page).
  6. Documentation of technical and operational capabilities, prepared by your engineers (HISP program page).
  7. Records showing your staff follow your own policies (policy adherence) (HISP program page).
  8. A signed Accreditation Program Agreement and a Financial Attestation of revenue (accreditation process).
  9. Evidence that your documented practices are carried out, for the location review (process).

If you want to walk through this list against your own operations, start with the introductory call.

How it compares

DirectTrust runs related programs, and HITRUST appears in the HISP prerequisite. What the sources say:

Related DirectTrust pages: DirectTrust medical biller accreditation consulting; DirectTrust MSO accreditation consulting; DirectTrust Financial Services and Lockbox accreditation consulting. All IHS accreditation services are listed on the Accreditation Consulting page.

What does DirectTrust accreditation cost?

DirectTrust publishes its fee schedule. The cost has two parts: DirectTrust's own fees, which DirectTrust sets by program, location and revenue level, and the cost of preparing, which depends on how much of the evidence your organization already has. DirectTrust says: “Accreditation fees are based on program(s), location(s), and revenue-level. Accredited organizations incur an Annual Fee. Every other year when an organization pursues accreditation (their On-Cycle year), they additionally incur Assessment, Location, and (if applicable) Multi-Program Discounted and Program-Specific Fees, as appropriate. On Off-Cycle years, organizations pay only the Annual Fee.” (source)

Three of the six revenue tiers on DirectTrust's apply page (fetched October 2, 2026):

Revenue tier (as published)Annual FeeMulti-Program Discounted FeeAssessment FeeAssessment Fee for Additional ProgramsAdditional Location Fee
1 – Very Small – Under $3M$3,100$1,550$5,500$1,500$3,500
3 – Medium – Greater than $8 Less than $20M$8,700$4,350$9,500$2,500$4,000
6 – Very Large – Greater than $75M$27,500$13,750$15,000$5,000$6,000

DirectTrust’s schedule lists a Multi-Program Discounted Fee and an Assessment Fee for Additional Programs (source). Ask DirectTrust how those columns apply to a Privacy and Security plus HISP pairing before budgeting.

Verify current fees with DirectTrust before budgeting. IHS scopes each engagement after a free introductory call.

What this is not

Frequently asked questions

What is DirectTrust HISP accreditation?

It is DirectTrust's accreditation for Health Information Services Providers operating Direct Secure Messaging. The 2026 criteria version is Health Information Services Provider (HISP) v2.2. DirectTrust says it covers HIPAA privacy, security, cyber security, technical and operational capabilities, and policy adherence.

Who needs HISP accreditation to operate Direct Secure Messaging?

DirectTrust describes the program as signaling to users and subscribers that an organization is a trustworthy agent and service provider for Direct Secure Messaging. The buyer is a vendor operating that service. The DirectTrust pages IHS reviewed do not say whether DirectTrust network membership is also required; ask DirectTrust's application team.

What is the HIPAA prerequisite for HISP accreditation?

Applicants must show compliance with HIPAA privacy and security regulations. DirectTrust accepts a valid DirectTrust Privacy and Security accreditation, another DirectTrust program containing Privacy and Security with the full HISP environment in scope, or qualifying HITRUST certification.

Can HITRUST certification satisfy the DirectTrust HISP prerequisite?

Yes, for the prerequisite only. DirectTrust accepts HITRUST certification covering the full HISP environment and including the scoping factors HIPAA Privacy, HIPAA Security and HIPAA Breach. It does not replace HISP accreditation itself.

What are the mandatory HISP criteria?

DirectTrust names three on its program page: demonstrating compliance with HIPAA requirements, participating in the Aggregated Directory, and managing private and public key pairs in accordance with the DirectTrust Certificate Policy and DirectTrust HISP Policy. Applicants must fully meet and respond to the mandatory criteria.

How long does HISP accreditation take?

DirectTrust does not publish a typical timeline on the pages IHS reviewed. If you still need the HIPAA prerequisite, that work comes first. After that, the self-assessment, location review and Commission vote follow the standard DirectTrust process.

How much does HISP accreditation cost, including the prerequisite program?

DirectTrust publishes revenue-tiered fees. Its schedule lists a Multi-Program Discounted Fee and an Assessment Fee for Additional Programs. Ask DirectTrust how those columns apply to a Privacy and Security plus HISP pairing before budgeting. Verify current fees with DirectTrust. IHS scopes its own engagement after a free introductory call.

HISP vs Certificate Authority vs Registration Authority accreditation: which does my organization need?

On IHS's reading, they cover different roles. HISP accreditation is for the organization operating the Direct Secure Messaging service; DirectTrust says Certificate Authority and Registration Authority accreditation means an organization's anchor certificates may be included in the DirectTrust Network. Your role in Direct exchange decides which applies.

How often is HISP accreditation renewed?

The DirectTrust accreditation cycle is two years, with an Annual Fee every year. Renewing organizations submit a complete self-assessment 4 months prior to the expiration date.

What organizational policies does a HISP need beyond the technical controls?

DirectTrust lists HIPAA privacy and security, policy adherence and operational capabilities among the program's areas. In practice that means governance, participant onboarding, agreement oversight and incident procedures, which is the part IHS drafts for your leaders to approve.

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Schedule a Free Discovery Session