Ask three different clinics how a referral note, a discharge summary, or an outside lab result actually gets from one electronic health record (EHR) to another, and you will likely get three different answers — because there genuinely are three different mechanisms in play. Health information exchange (HIE) in the United States runs on a mix of "push" and "pull" workflows, each governed by its own standards and trust framework. For an Arizona practice evaluating an EHR upgrade, an HIE connection, or a health-IT vendor to manage that work, understanding which workflow does what — and which one a given vendor actually supports — is the difference between a connection that quietly works and one that leaves staff faxing records in 2026.
Query-Based Exchange: Pulling Records on Demand
Query-based exchange, often called "pull" exchange, is what happens when a clinician needs information they do not already have — a patient shows up in an urgent care visit from out of town, or a specialist needs history before a first appointment. Rather than waiting for another organization to send something, the requesting system searches for and retrieves it directly. This workflow depends on Integrating the Healthcare Enterprise (IHE) profiles: Cross-Community Patient Discovery (XCPD) first determines whether a patient is known to another community and resolves their identity across systems, and Cross-Community Access (XCA) then queries and retrieves the actual clinical documents from that community once a match is found. Because it is initiated by the party who needs the data, query-based exchange is the natural fit for unplanned or emergency care, where nobody upstream knew in advance that a request was coming.
Directed Exchange: Direct Secure Messaging Between Known Parties
Directed exchange is the opposite motion — a "push," not a pull. A provider who already knows who should receive a document sends it directly, encrypted, to a specific recipient. This is the backbone of routine, planned care coordination: a referral packet going from primary care to a specialist, a discharge summary going back to the referring physician, or lab results routed to an ordering provider. The technical and trust layer underneath most directed exchange in the U.S. is Direct secure messaging, governed by DirectTrust, a non-profit that accredits the network operators and certificate authorities responsible for keeping the exchange trustworthy. Because the sender already knows exactly who the recipient is, directed exchange does not need a discovery step the way query-based exchange does — it needs a verified address and a trusted delivery channel.
Record Locator Services: Finding Records Before You Can Pull Them
A record locator service (RLS) is not a third, competing workflow so much as an accelerant for query-based exchange. Patient records for a single individual are frequently scattered across multiple unaffiliated EHRs and organizations, and an RLS keeps a master index — not the records themselves, but a directory of where they live — searchable by patient identifiers, data type, or geography. Two national efforts do most of this work today: Carequality operates as a framework connecting different health-data-sharing networks to one another, and CommonWell Health Alliance runs operational, cross-vendor services including patient identity management and record location. The two are interoperable: CommonWell functions as a Carequality implementer, meaning a CommonWell-connected practice can reach Carequality participants through directed queries, and Carequality has worked with CommonWell to make a Carequality-compliant version of its record locator available. In practice, an RLS is what turns "query-based exchange" from a targeted request to one known partner into a genuine nationwide search.
How the Three Workflows Compare
| Workflow | Direction | Typical use case | Governing standard/network |
|---|---|---|---|
| Query-based exchange | Pull | Unplanned or emergency care, new-patient history | IHE XCA / XCPD |
| Directed exchange | Push | Referrals, discharge summaries, routine results | Direct secure messaging / DirectTrust |
| Record locator service | Discovery layer for pull | Finding which organizations hold a patient's records | Carequality, CommonWell Health Alliance |
Why the Distinction Matters When Choosing a Vendor
These are not interchangeable capabilities, and not every EHR module or HIE connection supports all three. A practice that only has Direct secure messaging can send and receive with known partners but cannot pull a record from an organization it has never worked with before. A practice connected to a query-based network without record locator participation can search, but only within a limited set of pre-established relationships rather than the broader Carequality/CommonWell footprint. When evaluating an EHR onboarding partner, an HIE connection, or a broader health-IT vendor, it is worth asking directly:
- Does the platform support Direct secure messaging for referrals and results, and is it DirectTrust-accredited?
- Is the practice connected to a query-based exchange network, and through which framework?
- Does that connection include record locator participation through Carequality, CommonWell, or both — or only messaging between pre-arranged partners?
- Who handles patient identity matching, and how are duplicate or mismatched records resolved?
A vendor that cannot answer these plainly is likely reselling a narrower connection than a practice actually needs. For clinics navigating this decision without in-house health-IT expertise, working through a neutral matching process — one that is not itself selling a single platform — is often the fastest way to find a vendor whose HIE capabilities actually match the practice's referral patterns and care-coordination needs, rather than discovering the gaps after go-live.
The Bottom Line
Query-retrieve, directed messaging, and record locator services solve different problems: finding a record you did not know existed, sending one to a partner you already trust, and locating where a patient's history actually lives across a fragmented system. Most well-connected practices end up using all three in combination. Understanding which is which — and confirming which ones a prospective health-IT vendor genuinely supports — is a small amount of diligence that prevents a much larger integration headache later.