To help ensure our customers’ data is kept private and secure, Updox undergoes a rigorous accreditation process that evaluates our policies, security controls, IT procedures, data centers, disaster recovery, software development life cycle, customer service, staff training, human resource management, and more.
The Updox accreditation is through the Electronic Healthcare Network Accreditation Commission (EHNAC) . Their accreditation program includes the same criteria as the HITRUST certification plus additional criteria that covers the Updox Direct Secure Messaging service.
HIT Vendor: Updox
Date Certified: 7/20/2017
Certificate #: 15.04.04.2484.Updo.18.104.22.168720
Version: 2016.1 (if using the new Updox Patient Engagement Portal)
Date Certified: 7/20/2017
Certificate #: 15.04.04.2484.Updo.22.214.171.124720
- 170.315 (d)(1) Authentication, Access Control, Authorization
- 170.315 (d)(2) Auditable Events and Tamper-resistance
- 170.315 (d)(3) Audit Reports
- 170.315 (d)(5) Automatic Access Timeout
- 170.315 (d)(7) End User Device Encryption
- 170.315 (d)(9) Trusted Connection
- 170.315 (e)(1) View, Download, Transmit
- 170.315 (e)(2) Secure Messaging
- 170.315 (g)(1) Automated Numerator Recording
- 170.315 (g)(4) Quality System Management
- 170.315 (g)(5) Accessibility Centered Design
- 170.315 (g)(6) Consolidated CDA Creation Performance
- 170.315 (h)(2) Direct Project, Edge Protocol, and XDR/XDM
Clinical Quality Measures
- None (not applicable to Updox services)
Additional Software Required
- Certified Electronic Health Record (EHR) software
Updox is ONC Health IT 2015 Edition compliant and has been certified by an ONC-ACB in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services. This certification does not represent an endorsement by the U.S. Department of Health and Human Services.
This functionality allows practice/hospital users to securely exchange Direct messages with external providers. Direct messages may include clinical data, notes, and other healthcare related information. The process for sending/receiving Direct messages varies depending on the EHR vendor partnered with Updox.
This functionality allows practice/hospital users to send and receive secure messages to/from patients using the Updox Patient Portal. The process for sending/receiving secure messages varies depending on the EHR vendor partnered with Updox.
This functionality enables a practice/hospital to give their patients online access to their health information, exchange secure messages with providers, and transmit clinical care summaries to other parties using Direct messaging or standard email. The Patient Portal is associated with a single practice/hospital.
Costs or Fees
This product may require a one-time integration fee, monthly Direct messaging subscription per address, monthly Patient Portal subscription per provider, and identity verification fee per attempt. The applicable costs are specified in the business contracts between Updox and its EHR vendor partners.
Updox Direct Messaging requires:
- Acceptance of the user agreements for identity verification and the provider direct address directory
- A trust relationship between Updox and the Health Information Services Provider (HISP) for the other party in the Direct message exchange (trust is already established with other Updox customers and with participants in the DirectTrust network)
Technical or Practical Limitations
Additionally, this product requires:
- Electronic Health Record (EHR) software integrated with Updox
- Direct addresses issued by Updox (may be individual, department, and/or organizational)
Supported internet browser on user workstation:
- Internet Explorer 9+
- Microsoft Edge 20+
- Firefox 20+
- Chrome 28+
- Safari 6+
Since the Patient Electronic Access measure counts patients with access via the Patient Portal plus patients with access via Application Program Interfaces APIs, contact your EHR vendor for instructions on this measure calculation.
Date Certified: 4/10/2015
Certificate #: 04102015-0178-5
- 170.314 (e)(1) View, Download, Transmit
- 170.314 (e)(3) Secure Messaging
- 170.314 (g)(1) Automated Numerator Recording
- 170.314 (g)(4) Quality System Management
- 170.314 (h)(1) Direct Messaging
Costs, Contractual Limitations, and Technical/Practical Limitations are the same as above.
Updox HISP Practices Statement
Updox Certificate Practices Statement