Direct Secure Messaging is a viable push channel for delivering finalized pharmacogenomics reports to clinicians when three prerequisites are in place: an EHNAC-DTAAP-accredited HISP handling certificate exchange, Message Disposition Notifications confirming delivery, and structured payloads (with a PDF fallback) mapped to LOINC and SNOMED-CT. Without those three, you get a fax machine with better encryption.
TL;DR:
- Direct Secure Messaging requires accreditation, certificate exchange, and structured payloads mapped to LOINC and SNOMED-CT for reliable PGx report delivery.
- Onboarding involves selecting an accredited HISP, verifying recipient addresses, conducting ping-pong tests, and setting SLAs for MDN confirmations within one hour.
- Labs should use HL7 ORU messages or FHIR bundles for structured results, attaching PDFs as a fallback when ingestion capabilities are limited.
- MDNs with "processed" status confirm successful delivery, and automated retries should be triggered if the 1-hour window expires without confirmation.
- SignalPGx simplifies compliance by providing a white-label platform that automates workflow, enabling labs to go live in 5 to 7 days without extensive HISP integration.
Table of Contents
- What Makes Direct Secure Messaging PGx Delivery Work?
- How Do Labs Onboard for Direct Secure Messaging?
- What Format Should PGx Report Payloads Use?
- How Do You Verify PGx Report Delivery?
- How Do You Get PGx Results Actually Used, Not Just Delivered?
- What's the Rollout Sequence for Direct-Based PGx Delivery?
- Getting Direct Right Takes Weeks, Not Days
- How SignalPGx Shortens the Path to Compliant PGx Delivery
- Sources
- FAQ
What Makes Direct Secure Messaging PGx Delivery Work?
Direct is sender-initiated, making it the right transport for finalized pharmacogenomics reports as explained in this role of secure messaging in healthcare guide. Your lab knows exactly who needs the report, and Direct pushes it to that recipient's inbox the moment the medical director signs off. That makes it the right transport for finalized PGx reports, urgent phenotype flags, and any scenario where a known clinician needs a document now, not a data element they have to go looking for.
FHIR APIs solve a different problem. When a receiving EHR wants to pull discrete elements, like a diplotype call or a specific CPIC recommendation, into a clinical decision support rule, FHIR's query model fits better than a pushed document. Interoperability guidance increasingly treats Direct and FHIR as complementary rather than competing standards.
A practical split: use Direct to deliver the finalized report and notify the ordering clinician the moment it's ready. Use FHIR when the receiving health system wants structured genomic data available for real-time prescribing alerts. Most labs end up running both, with Direct as the default and FHIR reserved for partners with the infrastructure to consume it.

How Do Labs Onboard for Direct Secure Messaging?
Onboarding is where most PGx delivery projects stall, usually because someone assumes Direct works like regular email. It doesn't, and the accreditation layer is non-negotiable for a lab handling reportable genetic results.
- Select an EHNAC-DTAAP/DirectTrust-accredited HISP. EHNAC's HISP accreditation program exists specifically to verify that a Health Information Service Provider meets security and trust requirements before it moves patient data.
- Complete certificate exchange with every receiving HISP your ordering clinicians use, since Direct trust relationships are established HISP to HISP, not lab to clinician.
- Verify recipient Direct addresses against DirectTrust and NPPES registries, and set up group addresses for clinics or pharmacy teams to cut down on individual inbox clutter.
- Run ping-pong connectivity tests with each receiving HISP. State health information networks like MiHIN require exactly this kind of ping-pong testing and message header verification as a condition of onboarding.
- Set SLAs for MDN wait times. Define a failure window (1 hour is the common default) and an escalation path before you send a single production message.
Pro Tip: Log every ping-pong test result with a timestamp and HISP name. When a delivery fails six months later, that log is what tells you whether the problem is new or a certificate that quietly expired.
What Format Should PGx Report Payloads Use?
The payload decision determines whether a receiving EHR can actually act on your report or just file it. Structured data wins whenever the receiving system can ingest it.
- HL7 v2.5.1 ORU messages remain the most broadly supported structured format for lab results, including PGx findings, across hospital and clinic EHRs.
- FHIR Genomics Reporting bundles, specifically the Therapeutic Implication profile, give receiving systems a standardized structure for phenotype, diplotype, and medication-assessed recommendations built for CDS consumption.
- Transitional patterns matter for labs mid-migration: Sync for Genes demonstration projects documented embedding FHIR bundles inside HL7 ORU messages, or using HL7 reference pointers to FHIR resources, as ways to ease adoption without a full rip-and-replace.
- A human-readable PDF fallback should ride alongside structured data whenever the receiver's ingestion capability is unknown or limited.
One number worth remembering: some implementations have used Direct gateways to convert HL7-encoded lab results into PDF or HL7 attachments and process returning MDNs into HL7 ACKs sent back to the lab's own system, closing the loop without manual reconciliation.
Skip the temptation to cram every codeable data point into the payload. Bloated messages slow parsing and increase the odds a partial or malformed bundle gets rejected. Code what CPIC and clinical relevance actually require, using LOINC and SNOMED-CT consistently, and let the PDF carry narrative context.
How Do You Verify PGx Report Delivery?
A read receipt tells you a human opened an email. It tells you nothing about whether the message reached its destination intact, which is why CLIA-conscious labs shouldn't rely on it for reportable results.
- MDNs with a "processed" disposition are the authoritative signal that a Direct message reached the receiving system successfully.
- Configure your HISP to forward every MDN back to your LIS automatically, rather than leaving delivery confirmation to a person checking a portal.
- Set a 1-hour MDN wait window as your default failure threshold. DirectTrust's own guidance recommends a sending HISP wait no longer than an hour before declaring a transmission failed, unless a specific SLA says otherwise.
- Log MDNs and failures directly in the LIS, generating structured audit records the medical director can review without pulling logs from three different systems.
- Trigger automated retries or alternate routing the moment the SLA window closes without a processed MDN, rather than waiting for a clinician to call asking where the report went.
How Do You Get PGx Results Actually Used, Not Just Delivered?
Delivering a report and getting it used are two different achievements. A PDF that lands in an inbox and gets archived unread has failed the point of pharmacogenomic testing, even if the transmission worked perfectly.
- Code consistently with LOINC and SNOMED-CT, and align therapeutic implications to the FHIR Genomics Reporting profile so receiving systems can wire results into CDS rules rather than treating them as static attachments.
- Confirm ingestion capability with each receiving site ahead of go-live. Some will map structured fields into discrete EHR data; others will only ever archive the PDF, and you need to know which before you assume anything.
- Build group addresses and routing rules so PGx reports land with the pharmacist or clinician team actually managing medication decisions. Peer-reviewed practice reviews flag clinician inbox overload as a real risk when routing isn't deliberate.
- Plan the amended-report pathway now. Living reanalysis means a PGx report can change months after initial delivery as guidelines evolve, and your Direct workflow needs a clear way to flag an update as a revision, not a duplicate.
Pro Tip: Ask receiving clinics directly which fields they'll pull into structured data and which they'll only ever read as PDF. That single conversation prevents months of assuming your FHIR bundle is being used when it's actually sitting unopened next to the PDF.
What's the Rollout Sequence for Direct-Based PGx Delivery?
A phased rollout beats a big-bang launch every time a new transport touches patient-facing results.
- Pilot with a small clinician cohort, ideally one already receiving other lab results via the same HISP.
- Normalize certificates and addresses before sending anything live. Wrong Direct addresses and expired certificates cause the majority of early failures.
- Test payload formatting for both structured messages and PDF fallback, checking that codes map correctly on the receiving end.
- Validate MDN and SLA behavior under real conditions, not just in a sandbox.
- Cut over to production only after confirming downstream consumption, not just successful transmission.
Oversized payloads, missing LOINC/SNOMED codes, and mismatched Direct addresses account for most rollout delays. Catch them in the pilot, not in week three of production.
Getting Direct Right Takes Weeks, Not Days

Labs that treat Direct as a checkbox integration usually resend the project six months later. In practice, HISP accreditation, certificate exchange, and ping-pong testing with each receiving partner take real weeks, not an afternoon, especially once you're coordinating with multiple clinic systems.
The part that separates a working deployment from a stalled one isn't the transport protocol. It's whether medical-director signoff, MDN audit logging, and living-report notification flows are built in from day one. Standards compliance without that operational discipline just means you're sending well-formatted messages nobody trusts.
— Tarek
How SignalPGx Shortens the Path to Compliant PGx Delivery
SignalPGx is built for labs that don't want to become HISP integration specialists just to get PGx reports into clinician hands. The platform's white-label PGx reporting infrastructure pairs native HL7/FHIR integration with automated support for certificate management, Direct address verification, and MDN monitoring, so your team isn't manually tracking delivery notifications in a spreadsheet.

Labs deploying on SignalPGx typically reach production in 5 to 7 days, with the compliance and security controls (HIPAA and GDPR, detailed on our security page) already built into the pipeline rather than bolted on afterward. Living reanalysis means amended reports flow through the same verified Direct channel automatically as CPIC guidance updates, without your team rebuilding the delivery logic each time. If you're evaluating how to get standards-based PGx delivery live without a multi-month HISP integration project, review the medication intelligence graph or request a pilot walkthrough.
Sources
- MiHIN: Statewide Lab Orders-Results implementation guide
- HL7 FHIR Genomics Reporting: Pharmacogenomics
- Delivery notifications in Direct: the key to resilient health information exchange
- Direct Secure Messaging in practice: addressing workflow challenges
FAQ
Is Direct Secure Messaging HIPAA-compliant for PGx reports?
Yes, when delivered through an EHNAC-DTAAP-accredited HISP with proper certificate exchange, Direct meets the encryption and trust requirements for transmitting protected health information, including pharmacogenomic results.
How long should a lab wait for an MDN before treating delivery as failed?
DirectTrust guidance recommends a 1-hour wait for a destination MDN before declaring a transmission failure, unless a specific SLA states otherwise.
Should PGx reports use HL7 or FHIR when sent via Direct?
Most labs send structured HL7 v2.5.1 ORU messages or FHIR Genomics Reporting bundles as the primary payload, with a PDF attached as a fallback for receivers without structured ingestion capability.
Can Direct messaging cause clinician inbox overload for PGx results?
It can if routing isn't configured deliberately; research on Direct Secure Messaging workflows recommends group addresses and clear routing rules to direct reports to the right clinician or pharmacist team.
Does SignalPGx support Direct Secure Messaging delivery?
SignalPGx integrates with HL7/FHIR standards and supports the certificate, address, and MDN monitoring workflows labs need for standards-based Direct delivery, typically reaching production within 5 to 7 days.
