We are committed to providing outstanding solutions to out-of-hospital healthcare providers and our industry accreditations validate.

These in-depth surveys and certifications assure customers that our system will exceed your expectations for security, privacy, trust assurance, certificate management, policies and procedures, business practices and more.

Privacy & Security Accreditation (EHNAC)

To help ensure our customers’ data is kept private and secure, Updox undergoes a rigorous accreditation process that evaluates our policies, security controls, IT procedures, data centers, disaster recovery, software development life cycle, customer service, staff training, human resource management, and more.

The Updox accreditation is through the Electronic Healthcare Network Accreditation Commission (EHNAC) . Their accreditation program includes the same criteria as the HITRUST certification plus additional criteria that covers the Updox Direct Secure Messaging service.

Direct Secure Messaging Accreditations (DirectTrust)

As a provider for Direct Secure Messaging, Updox also undergoes extensive accreditations for each of the three functions involved:

• Health Information Services Provider (HISP)

• Registration Authority (RA)

• Certification Authority (CA)

A HISP is an organization that provides Direct messaging services to securely transmit healthcare information over the internet.

An RA is an organization that verifies the identity of individuals using Direct messaging. Identity verification helps further security by verifying that users “are who they say they are.”

A CA is an organization that issues digital certificates to Direct messaging organizations and users. Certificates help to ensure that Direct messaging is secure.

This accreditation is through DirectTrust, a pioneer in the technical trust and confidence in the secure exchange of healthcare information.

ONC 2015 Edition Health Information 
Technology Certification

HIT Vendor: Updox
Version: 2016.0
Date Certified: 7/20/2017
Certificate #:
Version: 2016.1 (if using the new Updox Patient Engagement Portal)
Date Certified: 7/20/2017
Certificate #:


  • 170.315 (d)(1) Authentication, Access Control, Authorization
  • 170.315 (d)(2) Auditable Events and Tamper-resistance
  • 170.315 (d)(3) Audit Reports
  • 170.315 (d)(5) Automatic Access Timeout
  • 170.315 (d)(7) End User Device Encryption
  • 170.315 (d)(9) Trusted Connection
  • 170.315 (e)(1) View, Download, Transmit
  • 170.315 (e)(2) Secure Messaging
  • 170.315 (g)(1) Automated Numerator Recording
  • 170.315 (g)(4) Quality System Management
  • 170.315 (g)(5) Accessibility Centered Design
  • 170.315 (g)(6) Consolidated CDA Creation Performance
  • 170.315 (h)(2) Direct Project, Edge Protocol, and XDR/XDM

ONC Certified Health IT Products List (CHPL)

Clinical Quality Measures

  • None (not applicable to Updox services)

Additional Software Required

  • Certified Electronic Health Record (EHR) software

Updox is ONC Health IT 2015 Edition compliant and has been certified by an ONC-ACB in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services. This certification does not represent an endorsement by the U.S. Department of Health and Human Services.

Direct Messaging

This functionality allows practice/hospital users to securely exchange Direct messages with external providers. Direct messages may include clinical data, notes, and other healthcare related information. The process for sending/receiving Direct messages varies depending on the EHR vendor partnered with Updox.

Secure Messaging

This functionality allows practice/hospital users to send and receive secure messages to/from patients using the Updox Patient Portal.  The process for sending/receiving secure messages varies depending on the EHR vendor partnered with Updox.

Patient Portal

This functionality enables a practice/hospital to give their patients online access to their health information, exchange secure messages with providers, and transmit clinical care summaries to other parties using Direct messaging or standard email. The Patient Portal is associated with a single practice/hospital.

Costs or Fees

This product may require a one-time integration fee, monthly Direct messaging subscription per address, monthly Patient Portal subscription per provider, and identity verification fee per attempt. The applicable costs are specified in the business contracts between Updox and its EHR vendor partners. 

Ready to get started?

Getting started is simple:

Let Updox simplify the business of healthcare enabling a better healthcare experience for the patients and consumers you serve.

Updox makes it easy:

  • Broad solution that works together better than any individual product
  • Understand and be ready to use in less than 30 minutes
  • Designed specifically for out-of-hospital providers and pharmacists
  • Dedicated On-Boarding and Customer Success expertise
  • Phone, email and live chat support