DirectTrust Developing Standard for Trusted Instant Messaging

July 30, 2019
Goal is to enable secure real-time electronic transmission of healthcare information incorporating trust network concepts

Instant messaging and collaboration tools are becoming essential in healthcare settings, but this form of communication faces technical, security, privacy and policy constraints. To address these issues, the nonprofit standards organization DirectTrust has developed a standards initiative for secure instant messaging in healthcare.

The Washington, D.C.-based group said that its Trusted Instant Messaging+ (TIM+) is the first industry standard to enable real-time communication of health information that incorporates trust network concepts to ensure secure transmissions between known, trusted entities within and across enterprises.

“While unsecured messaging may occur via text message, iMessage, products like Slack and others, there currently is no standard for secure instant messaging in healthcare, especially between disparate systems. Furthermore, use of unsecured messaging poses great risk that HIPAA and other privacy regulations may be violated,” stated Scott Stuewe, DirectTrust president and CEO, in a prepared statement. “The goal of the TIM+ standard is to create a secure and protected instant messaging standard for providers to communicate with each other, as well as with patients and other care team members. This is critical to eliminating the risk of violating HIPAA and other privacy regulations, and for the storing and sharing of protected health information,” he added.

DirectTrust says the TIM+ standard will bridge the communication gap between technology providers while keeping all participants within their native workflows and technology provider choices to maximize efficiency. TIM+ users will be able to communicate both within a given enterprise messaging implementation and across multiple technology providers using a common standard.

 The TIM+ standard determines the availability or presence of trusted endpoints, with near real-time changes in availability status and endpoint authorization control of viewing status, the organization says. It supports text-based communication, including one-on-one messaging, group or “room”-based messaging and feedback notification of message status. It also supports file transfers.

 DirectTrust has issued a “call for participation” for the TIM+ Consensus Body, a group of industry stakeholders that will help finalize development of the TIM+ standard, finalize policies regarding TIM+ use and assist with its ongoing maintenance. Participation in DirectTrust standards initiatives is open to any person or company that has a direct and material interest within the respective scope of the work of standards development.

TIM+ is the second initiative of DirectTrust Standards, a division of DirectTrust. The organization received accreditation from the American National Standards Institute (ANSI) in March 2019. DirectTrust Standards’ goal is to develop standards and specifications that enable and enhance healthcare interoperability and identity. 

Sponsored Recommendations

Enhancing Healthcare Through Strategic IT and AI Innovations

Learn how strategic IT and AI innovations are transforming healthcare - join Tomas Gregorio as he explores practical applications that enhance clinical decision-making, optimize...

The Intersection of Healthcare Compliance and Security in the Age of Deepfakes

As healthcare regulations struggle to keep up with rapid advancements in AI-driven threats like deepfakes, the security gaps have never been more concerning.

Increasing Healthcare Security Behind and Beyond the Firewall

Read how 5 identity security solutions can help you protect against these threats while improving user experience and reducing costs.

Improve and Secure Healthcare Delivery with Digital Identity

Get a deep understanding of how Digital Identity can help secure your healthcare organization while offering seamless access to your growing portfolio of apps and APIs.