Direct Secure Messaging

Direct Secure Messaging in Healthcare: How It Works, Benefits & Security

Posted 18 Aug 2026 · Updated 18 Aug 2026 · 7 min read

In 2025, healthcare organizations exchanged 1.894 billion messages using one specific, federally recognized method: Direct Secure Messaging. That's not a typo. It's also a 42% jump from the year before. If you've never heard of Direct Secure Messaging by name, there's a good chance your own care team already uses it every day, just not called that.

Quick Summary
  • Direct Secure Messaging (DSM) is a federal standard for encrypted, identity-verified health information exchange between organizations.
  • 1.894 billion DSM transactions happened in 2025 alone, a 42% increase from 2024, bringing the total since 2014 to 7.95 billion.
  • More than 3.1 million trusted Direct addresses and 196,517 organizations were active on the network by late 2025.
  • DSM works like secure email: identity-verified addresses, encrypted transport, delivered through an accredited Health Information Service Provider (HISP).
  • It's not the same as regular email, SMS, or a consumer messaging app, and it's specifically built to support HIPAA-compliant exchange.
Quick Answer
Direct Secure Messaging is a standardized, encrypted way for healthcare organizations to send patient information to each other electronically. It uses verified addresses and encrypted transport through an accredited HISP, and in 2025 alone carried 1.894 billion messages across the U.S. healthcare system.
Direct Secure Messaging in Healthcare: How It Works, Benefits & Security

What Is Direct Secure Messaging?

Direct Secure Messaging, often just called "Direct," is a standard created by the U.S. Office of the National Coordinator for Health IT (ONC). It lets healthcare organizations send protected health information to each other electronically, safely and reliably.

Think of it like email, but built specifically for healthcare. Each user gets a Direct address, similar to an email address. But unlike regular email, every address is tied to a verified identity, and every message is encrypted in transit.

DirectTrust Network, 2025
Metric2025 Figure
Total Direct messages exchanged1.894 billion (↑42% vs. 2024)
Cumulative messages since 20147.95 billion
Trusted Direct addresses3.1+ million
Organizations served196,517
Patients/consumers with access643,424

"In 2025, we saw the highest annual transaction volume to date, reflecting not just increased adoption, but sustained, real-world use to support critical healthcare, social care, and public health use cases."

— Scott Stuewe, President and CEO, DirectTrust

How Direct Secure Messaging Actually Works

The process behind DSM is simpler than it sounds. Here's the basic flow:

  • Get a Direct address. A healthcare organization or provider signs up through an accredited HISP (Health Information Service Provider), similar to getting an email account through a provider like Gmail, but built for healthcare.
  • Identity gets verified. Before an address is issued, the HISP confirms who the person or organization actually is. This step doesn't exist in regular email.
  • A message gets sent. The sender writes a message, attaches records if needed, and sends it to the recipient's Direct address.
  • Encryption protects it in transit. The message is encrypted the entire way, so it can't be read if intercepted.
  • It lands in the recipient's inbox or EHR. Many systems integrate Direct messaging straight into the electronic health record, so it shows up where clinicians already work.

What Direct Secure Messaging Is Actually Used For

DSM isn't limited to one narrow use case. Real, common workflows include:

  • Referrals between primary care and specialists
  • Discharge summaries sent from a hospital to a patient's regular doctor
  • Lab results delivered directly to the ordering provider
  • Electronic Case Reporting (eCR) to public health agencies, a growing driver of DSM volume
  • Continuity-of-care exchanges between health plans, as part of newer payer-to-payer data sharing requirements

Why Direct Secure Messaging Isn't the Same as Email or Text

It's easy to assume "secure messaging" just means "encrypted email." DSM is built to a higher, healthcare-specific standard.

Direct vs. Regular Email/SMS
FeatureDirect Secure MessagingRegular Email/SMS
Identity verificationRequired, through accredited HISPNone
Encryption in transitRequiredNot guaranteed
Built for PHI/HIPAAYes, by designNo
Trust framework/accreditationYes (DirectTrust, EHNAC)No
EHR integrationCommonRare

This distinction matters specifically for the transport and identity-verification layer of healthcare messaging. For the broader picture of how encryption requirements apply across clinical communication generally, see our guide on end-to-end encryption in clinical communication platforms.

How Secure Is Direct Secure Messaging, Really?

DSM's security isn't just a vendor claim, it's built into a formal, audited trust framework.

  • Accreditation: HISPs are accredited against DirectTrust and EHNAC security standards, not self-certified.
  • Ongoing scrutiny: DirectTrust has continued strengthening its accreditation criteria, including new cyber-resilience requirements, as adoption scales.
  • Identity-first design: Every address on the network is tied to a verified identity, closing a gap regular email and SMS never addressed.
Beyond Provider-to-Provider

Secure Messaging for Your Whole Care Team

DSM handles organization-to-organization exchange. HosTalky brings that same identity-verified, encrypted approach to everyday team communication inside your care team.

See How HosTalky Works

The Bottom Line

Direct Secure Messaging is one of the quieter success stories in healthcare interoperability: no flashy branding, but 7.95 billion messages exchanged since 2014 and still accelerating. It solves a specific problem, identity-verified, encrypted exchange between healthcare organizations, and it does it at a scale most people outside health IT never notice.

FAQs

What is Direct Secure Messaging?

Direct Secure Messaging (DSM) is a federally recognized, standardized method for healthcare organizations to send encrypted health information to each other electronically. It's based on the ONC's Direct Project standard, uses email-like addresses, and requires identity verification through an accredited Health Information Service Provider (HISP), unlike regular email or SMS.

How many organizations actually use Direct Secure Messaging?

DirectTrust reported 196,517 organizations served by its accredited HISPs in Q4 2025, with more than 3.1 million trusted Direct addresses able to securely exchange health information. In 2025 alone, 1.894 billion Direct messages were exchanged, a 42% increase from the prior year.

How is Direct Secure Messaging different from regular email or text messaging?

Regular email and SMS don't verify the identity of the sender or recipient and typically aren't encrypted end-to-end for healthcare use. DSM requires both parties to have a verified Direct address issued through an accredited HISP, encrypts the message in transit, and is built specifically to meet HIPAA security requirements for exchanging protected health information.

Is Direct Secure Messaging secure enough for HIPAA compliance?

Yes. DSM is built around a trust framework accredited by DirectTrust and audited against DirectTrust and EHNAC security standards. It requires identity-verified addresses, encrypted transport, and is designed specifically to support HIPAA-compliant exchange of protected health information between healthcare organizations.

Sources and References

  • DirectTrust. (2026). DirectTrust Reports Record High Exchange Activity in 2025, With Nearly 1.9 Billion Direct Exchange Transactions.
  • ONC (Office of the National Coordinator for Health IT). Direct Project Certification Criterion.
  • DirectTrust. Access Standards & The Direct Standard.


Hanna Mae Rico

Written by

Hanna Mae Rico

Hanna Mae Rico is a healthcare communications writer covering clinical operations, patient safety, and the systems shaping frontline care delivery. Her work focuses on translating complex healthcare communication challenges into practical insights for nurses, hospital leaders, and clinical teams navigating high-pressure care environments.

View all articles by Hanna ->