XDR Overview
8 min
introduction surescripts clinical direct messaging (cdm) enables the secure, electronic exchange of clinical information between health care organizations built on the direct standard maintained by directtrust, cdm allows providers, hospitals, health plans, and other authorized participants to send and receive clinical documents such as referrals, transitions of care, discharge summaries, and care coordination notes within their existing workflows surescripts is an accredited health information service provider (hisp), direct certificate authority (ca), and direct registration authority (ra) through directtrust together, these accredited roles allow surescripts to issue and manage the trust credentials, validate participant identity, and operate the messaging infrastructure that makes secure direct message exchange possible across the community of directtrust accredited hisps cdm holds certified health it status under office of the national coordinator (onc) requirements and supports promoting interoperability program measures cross enterprise document reliable interchange (xdr) is one of the connectivity methods cdm supports this guide focuses on the xdr based messaging model as implemented by surescripts about xdr what it is xdr is an ihe (integrating the healthcare enterprise) integration profile that defines how clinical documents are securely exchanged between systems using web services and standardized metadata it is one of the transport methods supported by cdm for exchanging clinical documents between participants, and it enables secure exchange even in the absence of a document sharing infrastructure such as an xds registry and repository how it works xdr packages clinical content and its required metadata into a single message that is electronically routed between a sending system and a receiving system each message is delivered using the ihe provide and register document set b transaction \[iti 41], carried over web services for each message that is sent, a response message is returned, and the type of response defines the status of the delivery why it matters xdr allows participants to exchange clinical documents while preserving message integrity and traceability throughout delivery depending on how each participant is configured, xdr can also support delivery status notifications that communicate the outcome of message processing bottom line xdr provides a secure, standards based method to move clinical documents between health care systems, with visibility into message processing and delivery scope, limitations, and what is included this guide describes base xdr based messaging as implemented by surescripts it covers how customers send and receive xdr messages, how messages are addressed and routed, how notifications and tracking work, how clinical documents and metadata are packaged, the connectivity and certificate requirements, and the requirements a customer's application must meet to be certified on the surescripts network as a cdm connectivity method, xdr based messaging includes the surescripts hisp, direct ca, and direct ra services message routing across the surescripts network and electronic message delivery are included with the service xdr is well suited to point to point exchange of clinical documents (for example, consolidated clinical document architecture \[c cda] documents and pdfs), transitions of care and discharge summaries, and public health reporting specific use cases built on xdr such as electronic case reporting (ecr) and closed loop referrals (360x) are outside the scope of this version of the guide and may be addressed in a future revision surescripts places specific limitations on xdr relative to the base ihe profile those limitations are detailed in differences from standard ihe xdr docid\ daga7uw8atariylz3rtu9 trust framework and flow down terms xdr based messaging operates within the directtrust trust framework certain trust framework obligations flow down to every participant that sends or receives messages on the surescripts network these flow down terms are an important part of participating in the network note the full flow down terms are provided in directtrust trust framework and flow down terms docid\ pmvq7uy 7ymakt3xdroa1 about this guide this guide provides an overview of the xdr specifications and describes the message structures, workflows, and examples required to support xdr based document exchange it is intended for participants responsible for designing, developing, or supporting system integrations that use xdr based messaging this guide supports and further clarifies the applicable ihe and directtrust specifications as used on the surescripts network; it does not reproduce those standards in full requirements beyond those in the referenced standards are called out in this guide and are enforceable customers should read and understand the associated standards, listed in the document references below, before implementing document references this guide should be read together with the following materials external standards must be obtained by the customer from the issuing organization surescripts provided materials reference description connectivity and authentication guide docid\ yj54zgjrqh5jj6r71e7w communication and security protocol requirements, mutual tls and certificate details, and the ip addresses associated with surescripts services directory implementation guide docid\ wewxqy1rx7 g9qxaspwyx direct address search, display, and publishing requirements (see application certification requirements docid\ wsfitp7dv6u1yrn7zbxd8 , acrs c 200 c 202) network operations guide docid\ wyngrikd7vjk2a6avmebn network operations, support, and the escalation matrix external materials to be obtained by the customer reference where to obtain directtrust xdr and xdm for direct secure messaging specification , version 2 1 https //directtrust org/standards https //directtrust org/standards ihe iti technical framework, volume 1, section 15 xdr (cross enterprise document reliable interchange) https //profiles ihe net/iti/tf/volume1/ch 15 html https //profiles ihe net/iti/tf/volume1/ch 15 html ihe iti technical framework, volume 1, section 16 xdm (cross enterprise document media interchange) https //profiles ihe net/iti/tf/volume1/ch 16 html https //profiles ihe net/iti/tf/volume1/ch 16 html ihe iti technical framework, volume 2b, section 3 41 provide and register document set b \[iti 41] https //profiles ihe net/iti/tf/volume2/ https //profiles ihe net/iti/tf/volume2/ ihe iti technical framework, volume 3 metadata https //profiles ihe net/iti/tf/volume3/ https //profiles ihe net/iti/tf/volume3/ w3c soap version 1 2 https //www w3 org/tr/soap12/ https //www w3 org/tr/soap12/ w3c web services addressing 1 0 core https //www w3 org/tr/ws addr core/ https //www w3 org/tr/ws addr core/ w3c soap message transmission optimization mechanism (mtom) https //www w3 org/tr/soap12 mtom/ https //www w3 org/tr/soap12 mtom/ ws i basic profile 2 0 http //ws i org/profiles/basicprofile 2 0 2010 11 09 html http //ws i org/profiles/basicprofile 2 0 2010 11 09 html hl7 consolidated cda (c cda) https //www hl7 org/ccdasearch/ https //www hl7 org/ccdasearch/ hl7 oid registry https //www hl7 org/oid/index cfm https //www hl7 org/oid/index cfm sources of authority different aspects of an xdr implementation are governed by different documents this guide clarifies how they apply on the surescripts network but does not supersede them; where it states a requirement beyond the referenced standards, that requirement is called out and is enforceable area source of authority message structure and the iti 41 transaction ihe it infrastructure technical framework ( document references docid\ zt9op0w2lvchwqv38e85w ), as clarified in this guide metadata requirements ihe and directtrust xdr/xdm specifications ( document references docid\ zt9op0w2lvchwqv38e85w ); surescripts does not enforce metadata beyond the standards connectivity, certificates, endpoints, networking, and transport surescripts connectivity and authentication guide direct address directory (publishing, search, and use) surescripts directory implementation guide and the directtrust aggregated directory data sharing policy what surescripts validates for production surescripts application certification requirements and additional business rules applied during certification trust framework and flow down obligations directtrust trust framework and flow down terms docid\ pmvq7uy 7ymakt3xdroa1 best practice guidance (recommended, not required) application certification requirements docid\ wsfitp7dv6u1yrn7zbxd8