Data in Motion
Data in motion is digital information that is actively being transferred from one location to another, such as between applications, devices, or networks. This is different from data that is stored and sitting still. In a HIPAA context, this concept typically applies to electronic protected health information (ePHI) as it travels, for example over email or across a network connection.
Data in motion (also called data in transit or data in flight) refers to the transmission of digital information as it moves between two locations, whether between two devices on the same network or across separate networks. For HIPAA purposes, this term is most relevant to electronic protected health information (ePHI) in transit, which falls under the scope of the HIPAA Security Rule; the Security Rule governs only ePHI, whereas the Privacy Rule covers PHI in all forms including oral and paper. Under the Security Rule's technical safeguards, transmission security is generally addressed through implementation specifications such as encryption, which is designated as addressable rather than required, noting that addressable does not mean optional, but instead requires a covered entity or business associate to assess whether the specification is reasonable and appropriate and, if not, to document its reasoning and implement an equivalent alternative where appropriate. The specific safeguard requirements, implementation specifications, and applicable citations should be verified against the current regulatory text, and readers should note that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional requirements beyond HIPAA.
Why it matters
Data in motion represents one of the moments when electronic protected health information (ePHI) is most exposed. When information sits at rest in a database, access controls and physical safeguards can create a defined perimeter around it. But as ePHI travels, over email, across a network connection, or between applications, it can pass through paths and intermediaries that a covered entity or business associate does not fully control, creating opportunities for interception or unauthorized access if the transmission is not adequately protected.
Under the HIPAA Security Rule, transmission security is one of the technical safeguards that regulated organizations must address, and it applies specifically to ePHI rather than to PHI in every form. Because the Security Rule governs only electronic information, the concept of data in motion is most relevant when analyzing how ePHI moves rather than how paper or oral information is shared, those forms are addressed under the Privacy Rule instead. Failing to secure ePHI in transit can contribute to a breach and to potential enforcement action by HHS OCR, though the specific consequences depend on the facts and on current guidance.
Organizations should also recognize that HIPAA is not the only source of obligations here. The HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more stringent requirements for protecting data as it travels. HITRUST certification, in particular, is not a legal requirement and does not by itself establish HIPAA compliance, so securing data in motion should be evaluated against the applicable regulatory text and any other frameworks an organization has committed to.
Who it's relevant to
Inside Data in Motion
Common questions
Answers to the questions practitioners most commonly ask about Data in Motion.