DirectTrust medical biller accreditation is the DirectTrust Healthcare Networks Accreditation Program for Medical Billers, assessed against the 2026 criteria version “Healthcare Network for Medical Billers v5.1”, for companies that handle provider data while coding and billing on a provider’s behalf. Integral Healthcare Solutions (IHS) prepares billing companies for it: IHS runs the gap assessment, maps your evidence to the criteria, drafts the policies and evidence file, and runs a mock review, and your billing, security and legal leads own the technical answers.
Last reviewed: October 2026.
What is DirectTrust medical biller accreditation?
It is an organizational accreditation run by DirectTrust. DirectTrust describes the program this way: “Healthcare Networks Accreditation Program for Medical Billers accredits companies that handle sensitive data as part of coding, billing, and other services on behalf of provider organizations including physician practices and hospitals, as well as health systems, labs and other types of healthcare organizations.” (source)
The governing text for 2026 is “Healthcare Network for Medical Billers v5.1”. DirectTrust “announced the release of new versions of program criteria for its 28 accreditation programs starting January 1, 2026.” (source) In that release the Medical Billers version carries an asterisk, which DirectTrust defines as “Denotes programs that contain DirectTrust’s standard Privacy and Security criteria.” (source) DirectTrust also states that “DirectTrust’s accreditation and certification programs are governed by the organization’s Electronic Healthcare Network Accreditation Commission (EHNAC).” (source)
DirectTrust says these programs cover HIPAA compliance “in areas such as privacy, security and cyber security, and confidentiality measures, level-of-service and escalation procedures, transaction response times, and systems availability.” (source) and that “They assess security infrastructure and data integrity measures including disaster recovery; business continuity; contingency plans; and intrusion detection and response.” (source)
The criteria documents themselves are released on request, not published. The descriptions on this page come from DirectTrust’s public program pages, not from the criteria text. DirectTrust has also “announced the draft version of the 2027 Criteria Release” (source), with the comment period ending November 17, 2026 (source).
Who needs it and what triggers it?
The buyer is a medical billing company whose clients, payers or state rules ask for independent evidence of how it protects and processes provider data. The triggers DirectTrust names on its own pages:
- State transaction processing. The Healthcare Networks page says “DirectTrust accreditation is accepted by Maryland and New Jersey to meet the requirement for processing healthcare transactions in those states” (source). DirectTrust’s Financial Services page uses different wording, saying accreditation “is required for processing healthcare transactions in the states of Maryland and New Jersey” (source). IHS has not reviewed the Maryland or New Jersey statutes for this page; read them, or ask your counsel, before relying on either wording.
- A defined accreditation objective: a client contract, a sales requirement, or a decision to formalize the company’s privacy, security and service-level program against an external standard.
How IHS helps
IHS drafts the policies and evidence file for DirectTrust billing accreditation; your billing, security and legal leads own the technical answers. The work runs in this order:
- Gap assessment of your operations against the Healthcare Network for Medical Billers v5.1 criteria your organization requests from DirectTrust.
- Questionnaires on client contracts, subcontractors, data flows and incident history.
- Document and evidence mapping: each criterion crosswalked to the policy, record or system output that answers it.
- Drafting: governance, subcontractor oversight, data handling, incident and complaint policies, for your leaders to review and approve.
- Mock review of the self-assessment and evidence against the criteria.
- Readiness support: drafted responses to findings for your organization to submit.
What your organization supplies: the criteria (requested from DirectTrust), client and subcontractor contracts, security documentation, your coding and compliance leads, and IT staff for technical controls. Your organization signs the agreement and submits its own application and self-assessment.
The limit: IHS does not perform security testing or certify technical controls. Any technical evidence the criteria call for comes from your staff or your security vendor. IHS organizes and documents it.
How the DirectTrust process runs
- Application: “An Accreditation Program Agreement must be signed by the applicant and submitted.” (source) and “A Financial Attestation to verify your organization’s revenue must also be submitted.” (source)
- Self-assessment: “Upon completion of the Application Process and approval, the Self-Assessment zip file will be made available to the organization, the Assessor will be assigned and the organization will be added to the Accredited Organizations page as a Candidate.” (source)
- Location review: “The purpose of a Location Review is to confirm that the practices documented by the organization are being carried out in real life.” (source)
- Decision: “The Commission reviews and votes on the Accreditation Report.” (source)
- Cycle: “The accreditation cycle is for 2 years.” (source) DirectTrust also “offers an optional Midterm Accreditation review.” (source)
DirectTrust does not publish a typical end-to-end timeline on the pages we reviewed.
What to have ready
This list ties to DirectTrust’s published process and its public description of the program. The criteria text (Healthcare Network for Medical Billers v5.1) governs; check each item against your copy.
- A copy of the Healthcare Network for Medical Billers v5.1 criteria, requested from DirectTrust (criteria are available on request).
- A signed Accreditation Program Agreement (accreditation process).
- A Financial Attestation of your organization’s revenue; DirectTrust says fees are based on program(s), location(s) and revenue level (process; fees).
- Privacy, security, cyber security and confidentiality policies (program description).
- Level-of-service and escalation procedures (program description).
- Records of transaction response times and systems availability (program description).
- Disaster recovery, business continuity and contingency plans (program description).
- Intrusion detection and response procedures and records (program description).
- Evidence that your documented practices are carried out, for the location review (process).
If you want to walk through this list against your own operations, start with the introductory call.
How it compares
Other ways to show security and privacy controls, and what the sources say about each:
- DirectTrust Privacy and Security program. A narrower DirectTrust option: “This program accredits organizations against our core criteria including privacy and security, customer service, business practices, personnel requirements, third-party cloud service providers, and more.” (source) The Medical Billers version carries DirectTrust's asterisk for the standard Privacy and Security criteria; the criteria text is available only on request, so what else it contains is not stated on the pages we reviewed.
- SSAE / SOC attestation. DirectTrust's Financial Services page says that program's additional criteria make IT controls “more comprehensive to assist in the preparation of other audits, such as SSAE 16 (formerly SAS 70) or Sarbanes-Oxley”; the pages we reviewed do not say the same of the Medical Billers program. The pages we reviewed do not say whether a SOC 2 report substitutes for DirectTrust accreditation.
- HITRUST certification. DirectTrust accepts HITRUST certification as the HIPAA prerequisite for a different program, its HISP accreditation (source). The pages we reviewed do not say HITRUST substitutes for Medical Billers accreditation.
Related DirectTrust pages: DirectTrust MSO accreditation consulting; DirectTrust HISP accreditation consulting; DirectTrust Financial Services and Lockbox accreditation consulting. All IHS accreditation services are listed on the Accreditation Consulting page.
What does DirectTrust accreditation cost?
DirectTrust publishes its fee schedule. The cost has two parts: DirectTrust's own fees, which DirectTrust sets by program, location and revenue level, and the cost of preparing, which depends on how much of the evidence your organization already has. DirectTrust says: “Accreditation fees are based on program(s), location(s), and revenue-level. Accredited organizations incur an Annual Fee. Every other year when an organization pursues accreditation (their On-Cycle year), they additionally incur Assessment, Location, and (if applicable) Multi-Program Discounted and Program-Specific Fees, as appropriate. On Off-Cycle years, organizations pay only the Annual Fee.” (source)
Three of the six revenue tiers on DirectTrust's apply page (fetched October 2, 2026):
| Revenue tier (as published) | Annual Fee | Multi-Program Discounted Fee | Assessment Fee | Assessment Fee for Additional Programs | Additional Location Fee |
|---|---|---|---|---|---|
| 1 – Very Small – Under $3M | $3,100 | $1,550 | $5,500 | $1,500 | $3,500 |
| 3 – Medium – Greater than $8 Less than $20M | $8,700 | $4,350 | $9,500 | $2,500 | $4,000 |
| 6 – Very Large – Greater than $75M | $27,500 | $13,750 | $15,000 | $5,000 | $6,000 |
- DirectTrust places federal, state and non-profit organizations in its Small tier, listed at $4,300 annual and $6,000 assessment (source).
- “Travel expenses are not included and will be invoiced after any physical location review(s) occur.” (source)
- DirectTrust lists “a charge of $250/hour for the Assessor time per additional submission of documentation.” (source)
Verify current fees with DirectTrust before budgeting. IHS scopes each engagement after a free introductory call.
What this is not
- IHS is not an accrediting body. IHS does not grant, predict or influence DirectTrust’s decision; the Commission votes on the Accreditation Report.
- IHS does not submit anything to DirectTrust. IHS drafts; your organization submits its application, self-assessment and responses.
- This page is not legal advice, and IHS does not perform security testing or certify technical controls.
Frequently asked questions
What is DirectTrust medical biller accreditation?
It is DirectTrust's Healthcare Networks Accreditation Program for Medical Billers, which accredits companies that handle sensitive data while coding and billing on behalf of providers. The 2026 criteria version is Healthcare Network for Medical Billers v5.1. DirectTrust says its programs are governed by its Electronic Healthcare Network Accreditation Commission (EHNAC).
Does my medical billing company need DirectTrust accreditation, or is it voluntary?
DirectTrust's pages tie it to processing healthcare transactions in Maryland and New Jersey, but its own pages differ: one says accreditation is accepted there, another says it is required. IHS has not reviewed those state statutes for this page. Check your payer and client contracts for what they require.
What do the DirectTrust Healthcare Network for Medical Billers criteria cover?
The criteria are released on request, so the public description is DirectTrust's summary: privacy, security and cyber security, confidentiality, level-of-service and escalation procedures, transaction response times and systems availability. DirectTrust also says the programs assess disaster recovery, business continuity, contingency plans and intrusion detection and response. Version 5.1 includes DirectTrust's standard Privacy and Security criteria.
How long does DirectTrust accreditation take from application to Commission vote?
DirectTrust does not publish a typical timeline on the pages IHS reviewed. The steps are the application and agreement, the self-assessment, a location review, and a Commission vote on the Accreditation Report.
How much does DirectTrust accreditation cost for a small billing company?
DirectTrust's published schedule lists its Very Small tier (under $3M revenue) at a $3,100 Annual Fee and a $5,500 Assessment Fee, with travel for location reviews invoiced separately. Verify current fees with DirectTrust. IHS scopes its own engagement after a free introductory call.
DirectTrust vs HITRUST vs SOC 2 for a medical billing company: which do clients ask for?
That depends on your clients and payers, and the DirectTrust pages IHS reviewed do not answer it. DirectTrust's Financial Services page says that program's additional criteria help in preparing other audits such as SSAE 16 or Sarbanes-Oxley; the pages we reviewed do not say the same of the Medical Billers program. DirectTrust accepts HITRUST as the HIPAA prerequisite for its HISP program. Check what your contracts require.
How often must a billing company renew DirectTrust accreditation?
The accreditation cycle is two years. DirectTrust asks renewing organizations to submit a complete self-assessment 4 months prior to the expiration date, and it offers an optional midterm review. An Annual Fee applies every year.
What are common reasons a self-assessment is sent back for resubmission?
DirectTrust does not publish a list of reasons on the pages IHS reviewed. It does charge $250 per hour of assessor time for each additional submission of documentation, which makes a complete first submission worth the effort. A mock review against the criteria before submission is how IHS checks for gaps.
