§164.312(e)(1)
Transmission Security
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Use technical measures that guard ePHI against unauthorized access or modification while transmitted over electronic networks.
Points of focus
- Protect ePHI confidentiality during network transmission
- Detect or prevent improper alteration in transit
- Address encryption when reasonable and appropriate
Implementation notes
Enforce modern TLS on public and internal ePHI paths, prohibit sensitive query parameters, authenticate message senders, and test partner endpoints and downgrade behavior before production exchange. Operationalize protect ephi confidentiality during network transmission in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain tls policy and endpoint scan results with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that internal service traffic carrying ephi is excluded from encryption requirements Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample tls policy and endpoint scan results with dates and named reviewers. Be ready to walk through how you detect and correct: internal service traffic carrying ephi is excluded from encryption requirements
Evidence auditors typically request:
- TLS policy and endpoint scan results
- Secure file-transfer or API configuration for healthcare partners
- Network and message-integrity design documentation
Common gaps
- Internal service traffic carrying ePHI is excluded from encryption requirements
- A fallback endpoint accepts obsolete TLS or sends ePHI in verbose query strings
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.312(e)(1) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.312(e)(1)