DirectTrust Outsourced Services accreditation is the Outsourced Services Accreditation Program (OSAP), assessed in 2026 against DirectTrust’s “Outsourced Services v5.1” criteria, with a companion Practice Management System Accreditation Program (PMSAP) for practice management software vendors. It is for cloud service, data center, call center and other outsourced vendors that serve healthcare organizations. Integral Healthcare Solutions (IHS) maps your customer obligations and drafts the oversight and governance records for DirectTrust accreditation; your engineers own the controls.
Last reviewed: October 2026.
What is DirectTrust Outsourced Services accreditation?
DirectTrust says: “The Outsourced Services Accreditation Program (OSAP) assesses the organization in areas such as privacy and confidentiality measures, level-of-service and escalation procedures, transaction response times, and systems availability. It also assesses the security/cybersecurity infrastructure and data integrity measures including disaster recovery, business continuity, contingency plans, and intrusion detection and response.” (source)
OSAP has criteria by service type. DirectTrust lists: “Accountable Care Organizations* Call Center Cloud Service Provider Data Center Disaster Recovery Health Information Exchange technology providers** Media Storage Network Administrator Printing Product Development Scanning” (source). The page marks two entries with asterisks (Accountable Care Organizations and Health Information Exchange technology providers); the pages IHS reviewed do not explain the marks, so confirm with DirectTrust whether either entry is qualified.
For software vendors, “The Practice Management System Accreditation Program (PMSAP) creates a framework of trust to ensure a common level of system functionality across the industry.” It “was designed for Practice Management System vendors who provide the necessary software to keep medical offices running smoothly and facilitate everything from practice management and operations to revenue cycle optimization” (source).
The 2026 governing texts are “Outsourced Services v5.1*” and “Practice Management System v5.1*”. The asterisk “Denotes programs that contain DirectTrust’s standard Privacy and Security criteria.” (source) DirectTrust’s programs “are governed by the organization’s Electronic Healthcare Network Accreditation Commission (EHNAC).” (source) The criteria themselves are “available for request” rather than posted (source), so this page relies on DirectTrust’s public pages. A draft 2027 release is open for comment until November 17, 2026 (source).
Who needs it and what triggers it?
The buyer is a cloud, hosting or other outsourced service vendor serving healthcare, or a practice management system vendor. Triggers named in the sources:
- Audit preparation. DirectTrust says: “Accreditation prepares the organization for third party audits including HIPAA/HITECH compliance audits conducted by the Office of Civil Rights (OCR) on covered entities and business associates.” (source)
- Customers in DirectTrust programs. “Once an Outsourced Services organization is accredited, other DirectTrust candidates who utilize that outsourcer will not have to pay for additional location reviews to that organization.” (source)
- Vendor selection. For practice management systems, DirectTrust says accreditation “Serves as a baseline standard for providers in the process of vendor selection and KLAS reviews.” (source)
- Reaccreditation. “The accreditation cycle is for 2 years,” with the complete self-assessment due “4 months prior to the expiration date.” (source)
How IHS helps
IHS maps your customer obligations and drafts the oversight and governance records the criteria call for. The work runs in this order:
- Gap assessment against the OSAP or PMSAP criteria your organization obtains from DirectTrust.
- A customer-obligation map built from your customer contracts and business associate agreements.
- Document and evidence mapping: each criterion crosswalked to the policy, contract clause or record that answers it.
- Drafting: supplier-oversight, security-governance, incident-coordination and audit-evidence procedures, for your leaders to review and approve.
- Mock review of the self-assessment package.
- Readiness support: drafted responses to assessor findings, for your organization to submit.
What your organization supplies: the criteria, customer contracts, existing security attestations, and your engineers and security staff.
The limit: technical implementation and validation belong to your engineers. IHS does not perform security or penetration testing. Your organization submits its own application and self-assessment.
How the DirectTrust process runs
- Application: “An Accreditation Program Agreement must be signed by the applicant and submitted. A Financial Attestation to verify your organization’s revenue must also be submitted.” (source)
- Self-assessment: “New applicants can submit the self-assessment as soon as it is completed before the due date.” (source)
- Location review and report: “Location reviews are completed, and the Assessor completes the draft Accreditation Report.” (source)
- Decision: “The Commission reviews and votes on the Accreditation Report. The organization will be informed whether the accreditation has been approved or denied.” (source)
DirectTrust does not publish a typical end-to-end timeline on the pages IHS reviewed.
What to have ready
Each item ties to DirectTrust’s published process or its public OSAP and PMSAP descriptions. The criteria text (Outsourced Services v5.1 or Practice Management System v5.1) governs; check each item against your copy.
- The criteria for your program and service type, requested from DirectTrust (criteria available on request).
- A signed Accreditation Program Agreement and a Financial Attestation of revenue (accreditation process).
- Privacy and confidentiality policies (OSAP description).
- Level-of-service and escalation procedures (OSAP description).
- Records of transaction response times and systems availability (OSAP description).
- Security and cybersecurity documentation, including data integrity measures (OSAP description).
- Disaster recovery, business continuity and contingency plans (OSAP description).
- Intrusion detection and response procedures (OSAP description).
- A list of every location to be reviewed, since extra locations carry an Additional Location Fee (fees).
- Evidence that documented practices are carried out; IHS’s expectation for the location review, which DirectTrust’s process page describes only as ‘Location reviews are completed’.
To walk through this list against your own operation, start with the introductory call.
How it compares
Healthcare vendors weighing OSAP often consider these alternatives:
- DirectTrust Management Service Organization accreditation: “This program assesses organizations that offer centralized administrative and hosted technology services.” (source) See IHS’s DirectTrust MSO accreditation page.
- DirectTrust Privacy and Security accreditation (v3.1), listed among the 2026 programs (source). The pages IHS reviewed do not set out how its scope differs from OSAP.
- HITRUST certification and SOC 2 reports. The DirectTrust pages IHS reviewed do not compare them with OSAP or say whether either substitutes for it. Whether a customer accepts one in place of another is set by that customer. See IHS’s HITRUST page.
- DirectTrust’s own advisory help. DirectTrust program pages say: “Learn about our Consulting and Advisory Services which have been designed to provide additional guidance in completing these programs.” (source)
Related DirectTrust pages: DirectTrust HIE accreditation consulting; DirectTrust identity and trust service accreditation consulting; DirectTrust medical biller accreditation consulting. All IHS accreditation services are listed on the Accreditation Consulting page.
What does DirectTrust OSAP accreditation cost?
The cost has two parts: DirectTrust’s fees, set by program, location and revenue level, and the cost of preparing. DirectTrust says: “Accreditation fees are based on program(s), location(s), and revenue-level. Accredited organizations incur an Annual Fee. Every other year when an organization pursues accreditation (their On-Cycle year), they additionally incur Assessment, Location, and (if applicable) Multi-Program Discounted and Program-Specific Fees, as appropriate. On Off-Cycle years, organizations pay only the Annual Fee.” (source)
Three of the six revenue tiers on DirectTrust’s apply page (fetched October 2, 2026):
| Tier (as published) | Annual Fee | Multi-Program Discounted Fee | Assessment Fee | Assessment Fee for Additional Programs | Additional Location Fee |
|---|---|---|---|---|---|
| 1 – Very Small – Under $3M | $3,100 | $1,550 | $5,500 | $1,500 | $3,500 |
| Small (includes federal, state and non-profit organizations) | $4,300 | $2,150 | $6,000 | $2,000 | $4,000 |
| 6 – Very Large – Greater than $75M | $27,500 | $13,750 | $15,000 | $5,000 | $6,000 |
Verify current fees with DirectTrust before budgeting. IHS scopes each engagement after a free introductory call.
What this is not
- IHS is not an accrediting body and does not grant, predict or influence DirectTrust’s decision.
- IHS does not submit anything to DirectTrust. IHS drafts; your organization submits.
- IHS does not perform security or penetration testing, and this page is not legal advice on your customer contracts or business associate agreements.
Frequently asked questions
What is DirectTrust Outsourced Services accreditation (OSAP) and which vendors does it cover?
OSAP assesses outsourced vendors on privacy and confidentiality, level-of-service and escalation, transaction response times, systems availability, security and data integrity. DirectTrust lists criteria for accountable care organizations, call centers, cloud service providers, data centers, disaster recovery, HIE technology providers, media storage, network administrators, printing, product development and scanning. The page marks two entries with asterisks (Accountable Care Organizations and Health Information Exchange technology providers); the pages IHS reviewed do not explain the marks, so confirm with DirectTrust whether either entry is qualified. The 2026 version is Outsourced Services v5.1.
Is OSAP available for cloud service providers and data centers serving healthcare?
Yes. Cloud Service Provider and Data Center both appear on DirectTrust's list of OSAP service types with accreditation criteria. The criteria for each service type are released on request.
How does DirectTrust OSAP compare with HITRUST or SOC 2 for a healthcare cloud vendor?
The DirectTrust pages IHS reviewed do not compare OSAP with HITRUST or SOC 2 or say whether either substitutes for it. Which one a customer asks for is that customer's decision.
Will DirectTrust accreditation help us pass customer security questionnaires and BAA reviews?
DirectTrust says accreditation prepares the organization for third party audits, including HIPAA/HITECH compliance audits by OCR on covered entities and business associates. It does not say customers must accept it in place of their own questionnaires. Each customer decides what evidence it accepts.
What does the Practice Management System accreditation (PMSAP) review?
DirectTrust describes PMSAP as a framework of trust to ensure a common level of system functionality, designed for vendors of software covering practice management, operations and revenue cycle. The 2026 version is Practice Management System v5.1, which contains DirectTrust's standard Privacy and Security criteria. DirectTrust says it serves as a baseline standard for providers in vendor selection and KLAS reviews.
What are the steps and timeline from application to accreditation decision?
Complete the application, sign the Accreditation Program Agreement, submit a Financial Attestation, then complete the self-assessment. Location reviews follow, the Assessor drafts the Accreditation Report, and the Commission votes. DirectTrust does not publish a typical timeline on the pages IHS reviewed.
How much does DirectTrust accreditation cost for a vendor under $3M in revenue?
DirectTrust's Very Small tier (under $3M) is published at a $3,100 Annual Fee, a $5,500 Assessment Fee and a $3,500 Additional Location Fee, as read on October 2, 2026. Verify current fees with DirectTrust. IHS scopes its own engagement after a free introductory call.
Do our customers save location-review fees if we are accredited?
DirectTrust says that once an Outsourced Services organization is accredited, other DirectTrust candidates who use that outsourcer will not have to pay for additional location reviews to that organization.
What evidence do assessors expect on supplier oversight, incident coordination and disaster recovery?
DirectTrust's OSAP description names disaster recovery, business continuity, contingency plans, and intrusion detection and response among the areas assessed. The criteria text for your service type sets the evidence. IHS crosswalks each criterion to the plan, procedure or record that answers it.
How often must we renew, and what is due in the off-cycle year?
The accreditation cycle is 2 years. In the off-cycle year, DirectTrust says organizations pay only the Annual Fee. For renewal, the complete self-assessment is due 4 months before expiration.
