5. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036
The requirements for Stage 2
1. CPOE
2. E‐Prescribing
3. Record demographics
4. Record vitals
5. Record smoking status
6. Use clinical decision support
7. Patients view, download, transmit
8. Clinical summaries to patients
9. Protect electronic health
information
10. Incorporate lab results
11. Generate patient lists
12. Reminders for follow‐up care
13. Patient educational resources
14. Medication reconciliation
15. Transmit care summaries for
transitions of care
16. Report immunizations
17. Secure messaging with patients
plus menu items……
18. Report syndromic data
19. Record electronic notes
20. Imaging results
21. Record family history
22. Report cancer cases
23. Report other registry cases
6. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036
The HIE requirements for Stage 2
1. CPOE
2. E‐Prescribing
3. Record demographics
4. Record vitals
5. Record smoking status
6. Use clinical decision support
7. Patients view, download, transmit
8. Clinical summaries to patients
9. Protect electronic health
information
10. Incorporate lab results
11. Generate patient lists
12. Reminders for follow‐up care
13. Patient educational resources
14. Medication reconciliation
15. Transmit care summaries for
transitions of care
16. Report immunizations
17. Secure messaging with patients
plus menu items……
18. Report syndromic data
19. Record electronic notes
20. Imaging results
21. Record family history
22. Report cancer cases
23. Report other registry cases
7. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036
The Direct HIE requirements for Stage 2
1. CPOE
2. E‐Prescribing
3. Record demographics
4. Record vitals
5. Record smoking status
6. Use clinical decision support
7. Patients view, download, transmit
8. Clinical summaries to patients
9. Protect electronic health
information
10. Incorporate lab results
11. Generate patient lists
12. Reminders for follow‐up care
13. Patient educational resources
14. Medication reconciliation
15. Transmit care summaries for
transitions of care
16. Report immunizations
17. Secure messaging with patients
plus menu items……
18. Report syndromic data
19. Record electronic notes
20. Imaging results
21. Record family history
22. Report cancer cases
23. Report other registry cases
13. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036 1313
Health Information Service
Provider (HISP)
Healthcare
Organization (HCO)
Identity vetting at
a specific level of
Assurance, LoA.
Certificate Authority (CA)
Certificate
Validation Service
X.509 Certificate
Issuance Service
Revocation
Services
Certificate Signing
Services
Registration Authority (RA)
Compile/Validate Identity and Trust
Documentation
The CA and RA
enforce the
policies specified
in the DirectTrust
and FBCA
Certificate Policy
(CP).
Crediential issued
on the basis of RA’s
Identity vetting at
specific LoA..
HCO Direct
Addressees
Basic services for user: DNS
discovery; encryption;
certificate signing and
validation; send/receive
MDNs; provide HISP-side of
edge protocol connection
compliance with Direct
standard,
The HISP enforces the
policies specified in the
DirectTrust HISP Policy (HP),
and MUST use accredited RA
and CA.
The HCO relies on HISP, CA,
and RA as accredited trusted
agents, and bears ultimate
responsibility for HIPAA
privacy and security.
NOTE: Three separate roles and
responsibilities from “trusted agents”
combine to enable Direct exchange
1.
2.
3.
23. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036 2323
Health Information Service
Provider (HISP)
Healthcare
Organization (HCO)
Identity vetting at
a specific level of
Assurance, LoA.
Certificate Authority (CA)
Certificate
Validation Service
X.509 Certificate
Issuance Service
Revocation
Services
Certificate Signing
Services
Registration Authority (RA)
Compile/Validate Identity and Trust
Documentation
The CA and RA
enforce the
policies specified
in the DirectTrust
and FBCA
Certificate Policy
(CP).
Crediential issued
on the basis of RA’s
Identity vetting at
specific LoA..
HCO Direct
Addressees
Basic services for user: DNS
discovery; encryption;
certificate signing and
validation; send/receive
MDNs; provide HISP-side of
edge protocol connection
compliance with Direct
standard,
The HISP enforces the
policies specified in the
DirectTrust HISP Policy (HP),
and MUST use accredited RA
and CA.
The HCO relies on HISP, CA,
and RA as accredited trusted
agents, and bears ultimate
responsibility for HIPAA
privacy and security.
How Direct works: Three separate roles and
responsibilities from “trusted agents”
combine to enable Direct exchange
1.
2.
3.
25. www.DirectTrust.org
1101 Connecticut Ave NW, Washington, DC 20036
DirectTrust Anchor Bundle for
“scaling” of trust relationships
Trust Community Anchor Distribution Site
Bu
Trust Bundle
(PKCS7)
HISP B
Trust
Store
HISP C
Trust
Store
HISP D
Trust
Store
HISP A
Trust
Store
HTTP(S)
As of September, 2013,
there are 10 accredited
HISPs’ trust anchors in the
Trust Anchor Bundle, leveraging
90 separate connections between
the HISPs, and linking over
1,000 health care organizations
to the DirectTrust network.
https://bundles.directtrust.org