Transmission security: PHI in motion is still PHI
45 CFR 164.312(e) covers ePHI while it moves, not just while it sits still. An emailed progress note, a synced session video, a text about a client, all count, whether or not they feel like transmission.
Last verified: 2026-09-08
Ask a clinic owner if their data is secure and most answers describe devices: encrypted laptops, locked tablets, a password on the EHR. Almost nobody describes what happens to the data the moment it leaves one of those devices and travels somewhere else. That gap is exactly what transmission security exists to close.
What the rule actually requires
Transmission security is a Required standard: implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network (45 CFR 164.312(e)(1)).
Two implementation specifications, both Addressable:
- Integrity controls (164.312(e)(2)(i)). Ensure that electronically transmitted ePHI is not improperly modified without detection, until disposed of.
- Encryption (164.312(e)(2)(ii)). Implement a mechanism to encrypt ePHI whenever deemed appropriate.
“Whenever deemed appropriate” is the softest phrase in the Security Rule, and it gets misread constantly as an opt-out. It is not permission to skip encryption because it sounds discretionary. It is still an Addressable specification, which still routes through the same 164.306(d)(3) assessment every other Addressable item does: is this reasonable and appropriate for your clinic, given your actual risks. For ePHI crossing an external network, the assessment rarely lands on no.
Why “we encrypt our laptops” is not the same claim
Encrypting a device protects data at rest, while it sits on that device. It does nothing for the same data the moment it leaves, by email, by sync, by message. These are two different exposures, and a clinic that has fully solved one can still have completely ignored the other. A locked laptop with an unencrypted email attachment has solved the easier half of the problem.
“Whenever deemed appropriate is the softest phrase in the Security Rule. It is not permission.”
What counts as transmission in an ABA clinic
This is broader than most people assume, because “transmission” sounds like something formal and technical rather than something that happens constantly in ordinary clinic operations:
- Emailing a progress note to a parent.
- Moving a session video off a phone into cloud storage.
- A data collection app syncing session data over a family’s home wifi during an in-home visit.
- Texting a colleague about a client, even a first name and a scheduling note.
- Uploading documentation to a payer portal.
None of these feel like “transmitting ePHI over an electronic communications network.” All of them are exactly that.
What a real answer looks like, next to what most clinics have
| What the rule requires | What most clinics actually have | |
|---|---|---|
| Devices | Encrypted at rest | Often genuinely covered, this part gets attention |
| Data in motion | Encrypted or otherwise protected while moving between systems | Rarely assessed at all |
| Assessment | A documented reasonable-and-appropriate call under 164.306(d)(3) | “We encrypt our laptops” treated as the whole answer |
| Everyday channels | Email, sync, text, and portal uploads all in scope | Treated as informal and outside the rule’s reach |
The clinics that fail this standard rarely fail it through a conscious decision. They fail it because the assessment never happened, transmission was never treated as its own category separate from the device it started on.
The short version
- Transmission security (164.312(e)(1)) requires technical measures to guard ePHI against unauthorized access while it is being transmitted over an electronic network.
- Two implementation specifications, both Addressable: integrity controls during transmission (164.312(e)(2)(i)) and encryption (164.312(e)(2)(ii)).
- 'Whenever deemed appropriate' in the encryption specification is not permission to skip it. It is still Addressable, which still routes through the 164.306(d)(3) assessment, not through personal preference.
- What counts as transmission in an ABA clinic is broader than most assume: emailing a progress note, syncing a session video to the cloud, texting a colleague about a client, a data app syncing over a family's home wifi.
- Data at rest and data in transit are two different exposures. Encrypting a device does nothing for the note that just left it by email.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Technical safeguards, including transmission security45 CFR 164.312(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
Encrypted in motion, not just at rest.
WiseUpHIPAA checks whether PHI moves encrypted between the systems your clinic actually uses, not just whether devices are locked down. The gap between those two is where most exposure actually lives.