Direct Secure Messaging in Healthcare: How It Works, Benefits & Security
In 2025, healthcare organizations exchanged 1.894 billion messages using one specific, federally recognized method: Direct Secure Messaging. That's not a typo. It's also a 42% jump from the year before. If you've never heard of Direct Secure Messaging by name, there's a good chance your own care team already uses it every day, just not called that.
- Direct Secure Messaging (DSM) is a federal standard for encrypted, identity-verified health information exchange between organizations.
- 1.894 billion DSM transactions happened in 2025 alone, a 42% increase from 2024, bringing the total since 2014 to 7.95 billion.
- More than 3.1 million trusted Direct addresses and 196,517 organizations were active on the network by late 2025.
- DSM works like secure email: identity-verified addresses, encrypted transport, delivered through an accredited Health Information Service Provider (HISP).
- It's not the same as regular email, SMS, or a consumer messaging app, and it's specifically built to support HIPAA-compliant exchange.
What Is Direct Secure Messaging?
Direct Secure Messaging, often just called "Direct," is a standard created by the U.S. Office of the National Coordinator for Health IT (ONC). It lets healthcare organizations send protected health information to each other electronically, safely and reliably.
Think of it like email, but built specifically for healthcare. Each user gets a Direct address, similar to an email address. But unlike regular email, every address is tied to a verified identity, and every message is encrypted in transit.
| Metric | 2025 Figure |
|---|---|
| Total Direct messages exchanged | 1.894 billion (↑42% vs. 2024) |
| Cumulative messages since 2014 | 7.95 billion |
| Trusted Direct addresses | 3.1+ million |
| Organizations served | 196,517 |
| Patients/consumers with access | 643,424 |
"In 2025, we saw the highest annual transaction volume to date, reflecting not just increased adoption, but sustained, real-world use to support critical healthcare, social care, and public health use cases."
How Direct Secure Messaging Actually Works
The process behind DSM is simpler than it sounds. Here's the basic flow:
- Get a Direct address. A healthcare organization or provider signs up through an accredited HISP (Health Information Service Provider), similar to getting an email account through a provider like Gmail, but built for healthcare.
- Identity gets verified. Before an address is issued, the HISP confirms who the person or organization actually is. This step doesn't exist in regular email.
- A message gets sent. The sender writes a message, attaches records if needed, and sends it to the recipient's Direct address.
- Encryption protects it in transit. The message is encrypted the entire way, so it can't be read if intercepted.
- It lands in the recipient's inbox or EHR. Many systems integrate Direct messaging straight into the electronic health record, so it shows up where clinicians already work.
What Direct Secure Messaging Is Actually Used For
DSM isn't limited to one narrow use case. Real, common workflows include:
- Referrals between primary care and specialists
- Discharge summaries sent from a hospital to a patient's regular doctor
- Lab results delivered directly to the ordering provider
- Electronic Case Reporting (eCR) to public health agencies, a growing driver of DSM volume
- Continuity-of-care exchanges between health plans, as part of newer payer-to-payer data sharing requirements
Why Direct Secure Messaging Isn't the Same as Email or Text
It's easy to assume "secure messaging" just means "encrypted email." DSM is built to a higher, healthcare-specific standard.
| Feature | Direct Secure Messaging | Regular Email/SMS |
|---|---|---|
| Identity verification | Required, through accredited HISP | None |
| Encryption in transit | Required | Not guaranteed |
| Built for PHI/HIPAA | Yes, by design | No |
| Trust framework/accreditation | Yes (DirectTrust, EHNAC) | No |
| EHR integration | Common | Rare |
This distinction matters specifically for the transport and identity-verification layer of healthcare messaging. For the broader picture of how encryption requirements apply across clinical communication generally, see our guide on end-to-end encryption in clinical communication platforms.
How Secure Is Direct Secure Messaging, Really?
DSM's security isn't just a vendor claim, it's built into a formal, audited trust framework.
- Accreditation: HISPs are accredited against DirectTrust and EHNAC security standards, not self-certified.
- Ongoing scrutiny: DirectTrust has continued strengthening its accreditation criteria, including new cyber-resilience requirements, as adoption scales.
- Identity-first design: Every address on the network is tied to a verified identity, closing a gap regular email and SMS never addressed.
Secure Messaging for Your Whole Care Team
DSM handles organization-to-organization exchange. HosTalky brings that same identity-verified, encrypted approach to everyday team communication inside your care team.
See How HosTalky WorksThe Bottom Line
Direct Secure Messaging is one of the quieter success stories in healthcare interoperability: no flashy branding, but 7.95 billion messages exchanged since 2014 and still accelerating. It solves a specific problem, identity-verified, encrypted exchange between healthcare organizations, and it does it at a scale most people outside health IT never notice.
FAQs
What is Direct Secure Messaging?
Direct Secure Messaging (DSM) is a federally recognized, standardized method for healthcare organizations to send encrypted health information to each other electronically. It's based on the ONC's Direct Project standard, uses email-like addresses, and requires identity verification through an accredited Health Information Service Provider (HISP), unlike regular email or SMS.
How many organizations actually use Direct Secure Messaging?
DirectTrust reported 196,517 organizations served by its accredited HISPs in Q4 2025, with more than 3.1 million trusted Direct addresses able to securely exchange health information. In 2025 alone, 1.894 billion Direct messages were exchanged, a 42% increase from the prior year.
How is Direct Secure Messaging different from regular email or text messaging?
Regular email and SMS don't verify the identity of the sender or recipient and typically aren't encrypted end-to-end for healthcare use. DSM requires both parties to have a verified Direct address issued through an accredited HISP, encrypts the message in transit, and is built specifically to meet HIPAA security requirements for exchanging protected health information.
Is Direct Secure Messaging secure enough for HIPAA compliance?
Yes. DSM is built around a trust framework accredited by DirectTrust and audited against DirectTrust and EHNAC security standards. It requires identity-verified addresses, encrypted transport, and is designed specifically to support HIPAA-compliant exchange of protected health information between healthcare organizations.
Sources and References
- DirectTrust. (2026). DirectTrust Reports Record High Exchange Activity in 2025, With Nearly 1.9 Billion Direct Exchange Transactions.
- ONC (Office of the National Coordinator for Health IT). Direct Project Certification Criterion.
- DirectTrust. Access Standards & The Direct Standard.