DirectTrust Trust Framework and Flow-Down Terms
7 min
clinical direct messaging (cdm) operates within the directtrust trust framework surescripts is an accredited health information service provider (hisp), direct certificate authority (ca), and direct registration authority (ra), and it participates in the directtrust aggregated directory because of this, certain obligations from the governing directtrust policies flow down to you and your end users, and surescripts binds customers to them by agreement these terms apply to cdm as a whole, not only to xdr based messaging, and this section calls out the ones most relevant to cdm implementation and operation; it is not the complete set important this is a plain language summary provided for awareness only it does not reproduce, replace, or interpret the directtrust policies, and it is not legal advice you are responsible for reading and complying with the full, current policies and with your agreement with surescripts if anything here differs from a directtrust policy or your surescripts agreement, those documents take precedence governing policies three directtrust policies contain the obligations summarized here this summary reflects the policy versions noted below; obtain current copies from directtrust at directtrust org/resources/compliance and key policies https //directtrust org/resources/compliance and key policies , or through your surescripts contact, and always work from the current version policy version summarized governs directtrust hisp policy 2 0 3 (july 3, 2025) hisp operation, edge connections, and end user obligations directtrust community x 509 certificate policy 2 1 (may 27, 2025) certificate issuance, identity proofing, and key obligations directtrust aggregated directory data sharing policy 4 0 (october 18, 2023) publishing and using direct address directory data where the hisp policy and the certificate policy conflict, the certificate policy takes precedence (hisp policy, section 1 1 2) certificates for your direct domain as your hisp, ca, and ra, surescripts obtains, holds, and manages the direct certificate and its private keys for your domain, and renews the certificate automatically as long as your account is active and your domain information is current and accurate your obligations protect your server and edge system credentials for connecting to the surescripts service from unauthorized use keep your domain registration information current and accurate promptly notify surescripts if your access credentials are compromised or misused, or if your domain information changes or becomes inaccurate, so surescripts can take any needed action (such as reissuing your access credentials) identity proofing your organization and the businesses you enable during onboarding, surescripts identity proofs your organization and the individuals who act as your organizational representative, information system security officer, or device sponsor you provide accurate registration information, documentation of your organization's legal existence, and attestation of your hipaa category surescripts completes the proofing through an approved identity verification service or, if you prefer, a notary completed form; your implementation contact coordinates either option if you onboard other organizations to your software, you are required to identity proof each organization you enable you must be bound by a legally binding contract with, or an attestation to, surescripts (as the ra) to do so, and you must proof each organization to the assurance level required for its certificate surescripts retains documentation of that binding, and you must make your identity proofing records available on request identity proofing your end users you are responsible for identity proofing each of your end users to the assurance level required for the certificate they use, and for keeping that proofing current as users are added or change your end users must protect their credentials, use them only for authorized and lawful direct messaging, and promptly report a suspected credential compromise your system must keep an accounting of end user access sufficient to identify which end user sent or received messages at a given time, and make it available to surescripts for auditing on request accessing and sharing the directory you are responsible for meeting the directory terms below and for enforcing them with the organizations you onboard publish and maintain your direct addresses and those of the organizations you enable in the surescripts directory access is reciprocal and per organization an organization must publish at least one valid direct address to access the aggregated directory, and an organization that does not contribute does not receive access even if other organizations you serve do keep entries accurate and current, and update them promptly when information changes use directory data only for direct messaging and permitted searches never for marketing, solicitation, surveys, research, or resale, and do not share it outside authorized users ensure non messaging (ancillary) users cannot view or use the direct address field remove an entry promptly when a provider is offboarded or an address is no longer valid, and respond promptly to any inaccuracy or misuse surescripts reports to you (message sending may be blocked otherwise) ensure your users consent to the directory terms before using directory data relationship to your surescripts agreement your surescripts agreement, including any business associate agreement and terms carried through from these policies, may impose additional or more specific requirements than this summary certain obligations also survive the end of your participation prohibited use restrictions continue to apply, and you must remove directory data that is not part of an ongoing exchange relationship