DirectTrust(R) Releases New 2027 Accreditation Criteria Versions for Public Review Through November 17, 2026
Monday, 21 September 2026 09:00 AM
Company Update
Criteria updates include streamlined criteria for non-HIPAA entities, enhanced criteria for business associates and other organizations
WASHINGTON, D.C. / ACCESS Newswire / September 21, 2026 / DirectTrust®, a non-profit healthcare industry alliance focused on furthering trust in healthcare data exchange through standards, accreditation, and other services, today announced it has posted new versions of program criteria for its 23 accreditation programs for public review and comment. The open process for adopting criteria commenced on September 18 and closes on November 17, 2026.
A key update for 2027 is the introduction of streamlined criteria for smaller, non-HIPAA entities, and enhanced criteria applicable to business associates and other organizations. The enhanced scoping capabilities allow organizations to include either fewer or more criteria in scope than under the previous approach. This is particularly relevant for organizations that are not subject to HIPAA.
Criteria enhancements include requirements related to:
- Information blocking
- Substance use disorder (SUD)
- California Consumer Privacy Act (CCPA) regulatory changes
- Post-quantum cryptography (PQC)
- AI governance
This release establishes a more targeted and scalable approach to accreditation. It retains a common security foundation while allowing additional criteria to be applied according to regulatory obligations, organizational characteristics, and program scope. It also provides more granular scoping capabilities. For example, a new "Industry Best Practices" (IBP) code allows organizations to optionally select certain criteria that were previously included by default.
"Accreditation should reflect the regulatory requirements and operational realities of the organization being assessed," said Lesley Berkeyheiser, Senior Director of Accreditation Strategy and Development. "The 2027 criteria create a more precise way to determine what belongs in scope, particularly for non-HIPAA entities, while strengthening expectations for organizations with broader responsibilities."
"As healthcare organizations take on different roles and obligations, we want accreditation to remain rigorous while ensuring the criteria applied are appropriate to each organization." Berkeyheiser continued. "The goal is to make each assessment more intentional and closely tied to the risks and obligations of the organization being evaluated. Including areas such as AI governance and post-quantum cryptography also helps candidates prepare for issues that may not be fully mature today, but are quickly becoming part of the security and governance decisions healthcare organizations need to make."
DirectTrust's accreditation and certification programs are governed by the organization's Electronic Healthcare Network Accreditation Commission (EHNAC). The criteria review process is an essential part of DirectTrust's methodology and commitment to transparency, allowing stakeholders involved with health technology and data exchange to voice their recommendations and help shape standards-based accreditation within the healthcare industry.
Criteria versions for the following 23 enhanced programs are available for review:
- Artificial Intelligence (AI) v1.1
- Certificate Authority (CA) v2.3
- CARIN Code of Conduct for Consumer-Facing Applications v1.2
- Digital Therapeutics v1.2
- E-Prescribing Electronic Health Network v10.2*
- Electronic Prescriptions for Controlled Substances for Pharmacy Vendors v4.7
- Electronic Prescriptions for Controlled Substances for Prescribing Vendors v4.7
- Financial Services Electronic Health Network v6.2*
- Financial Services Lockbox v6.2*
- Health App v2.2*
- Health Information Exchange (HIE) v5.2*
- Health Information Services Provider (HISP) v2.3
- Healthcare Network v14.2*
- Identity Provider (IdP) v1.2
- Management Service Organization (MSO) v5.2*
- Outsourced Services v5.2*
- Privacy and Security v3.2*
- Registration Authority (RA) v1.4
- Registration Authority for Federal PKI v1.4
- UDAP Client App v1.3
- UDAP Client App - Basic v1.3
- UDAP Identity Provider Criteria v1.3
- UDAP Server v1.3
* Denote programs that contain DirectTrust's standard Privacy and Security criteria.
Visit DirectTrust.org for additional details, or visit the organization's accreditation criteria page to review the latest criteria and submit feedback during this comment period.
About DirectTrust®
DirectTrust® is a non-profit, vendor-neutral alliance dedicated to establishing trust in a connected world. The organization serves as a forum for a consensus-driven community focused on health communication and cybersecurity, an ANSI standards development organization, an accreditation and certification body governed by EHNAC, and a developer of technical trust frameworks and supportive services for secure information exchange like Direct Secure Messaging and identity-verified credentials.
The goal of DirectTrust is to develop, promote, and, as necessary, help enforce the rules and best practices necessary to maintain privacy, security, and trust for stakeholders across and beyond healthcare. In addition, DirectTrust is committed to fostering widespread public confidence in the interoperable exchange of health information while promoting quality service, innovation, cooperation, and open competition in healthcare. To learn more, visit: DirectTrust.org.
###
Media contact:
Dave Anderson
andersoni.com
[email protected]
SOURCE: DirectTrust