Skip to main content
Category: De-identification and PHI Types

Data in Motion

Also known as: Data in Transit, Data in Flight
Simply put

Data in motion is digital information that is actively being transferred from one location to another, such as between applications, devices, or networks. This is different from data that is stored and sitting still. In a HIPAA context, this concept typically applies to electronic protected health information (ePHI) as it travels, for example over email or across a network connection.

Formal definition

Data in motion (also called data in transit or data in flight) refers to the transmission of digital information as it moves between two locations, whether between two devices on the same network or across separate networks. For HIPAA purposes, this term is most relevant to electronic protected health information (ePHI) in transit, which falls under the scope of the HIPAA Security Rule; the Security Rule governs only ePHI, whereas the Privacy Rule covers PHI in all forms including oral and paper. Under the Security Rule's technical safeguards, transmission security is generally addressed through implementation specifications such as encryption, which is designated as addressable rather than required, noting that addressable does not mean optional, but instead requires a covered entity or business associate to assess whether the specification is reasonable and appropriate and, if not, to document its reasoning and implement an equivalent alternative where appropriate. The specific safeguard requirements, implementation specifications, and applicable citations should be verified against the current regulatory text, and readers should note that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional requirements beyond HIPAA.

Why it matters

Data in motion represents one of the moments when electronic protected health information (ePHI) is most exposed. When information sits at rest in a database, access controls and physical safeguards can create a defined perimeter around it. But as ePHI travels, over email, across a network connection, or between applications, it can pass through paths and intermediaries that a covered entity or business associate does not fully control, creating opportunities for interception or unauthorized access if the transmission is not adequately protected.

Under the HIPAA Security Rule, transmission security is one of the technical safeguards that regulated organizations must address, and it applies specifically to ePHI rather than to PHI in every form. Because the Security Rule governs only electronic information, the concept of data in motion is most relevant when analyzing how ePHI moves rather than how paper or oral information is shared, those forms are addressed under the Privacy Rule instead. Failing to secure ePHI in transit can contribute to a breach and to potential enforcement action by HHS OCR, though the specific consequences depend on the facts and on current guidance.

Organizations should also recognize that HIPAA is not the only source of obligations here. The HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more stringent requirements for protecting data as it travels. HITRUST certification, in particular, is not a legal requirement and does not by itself establish HIPAA compliance, so securing data in motion should be evaluated against the applicable regulatory text and any other frameworks an organization has committed to.

Who it's relevant to

Security Officers and IT Teams
Those responsible for implementing the Security Rule's technical safeguards need to identify where ePHI travels within and outside their environment and evaluate transmission security measures such as encryption. Because encryption for transmission is an addressable specification, these teams must be prepared to assess whether it is reasonable and appropriate, document their reasoning, and implement equivalent alternatives where needed.
Privacy and Compliance Officers
Compliance staff should understand that data in motion applies specifically to ePHI under the Security Rule, while the Privacy Rule governs PHI in all forms including oral and paper. They should also account for the possibility that the HITECH Act, state law, or frameworks such as the HITRUST CSF impose additional requirements beyond HIPAA and confirm obligations against current guidance.
Business Associates and Their Subcontractors
Vendors that transmit ePHI on behalf of covered entities carry Security Rule obligations that generally flow through business associate agreements. When ePHI moves between an organization and its business associates or subcontractors, each party in that defined relationship should confirm how transmission security is handled in transit.
Auditors and Assessors
Professionals evaluating an organization's safeguards need to review how ePHI in transit is protected and how addressable specifications like transmission encryption were assessed and documented. They should confirm that findings are measured against the current regulatory text and, where relevant, the current HITRUST CSF version rather than assuming certification alone establishes HIPAA compliance.

Inside Data in Motion

Data in Transit (Synonym)
Data in motion refers to electronic protected health information (ePHI) that is actively moving from one location to another, such as across a network, between systems, or over the internet. It is distinguished from data at rest (stored ePHI) and data in use (ePHI being processed).
Transmission Security Under the Security Rule
The HIPAA Security Rule addresses data in motion primarily through its technical safeguards, which include transmission security measures intended to guard against unauthorized access to ePHI as it is transmitted over an electronic communications network. This category applies only to ePHI, not to PHI in oral or paper form.
Encryption as an Addressable Specification
Encryption of ePHI in motion is generally treated as an addressable implementation specification under the Security Rule. Addressable does not mean optional; a covered entity or business associate must assess whether the measure is reasonable and appropriate, implement it, or document why not and adopt an equivalent alternative where reasonable.
Integrity Controls
Transmission security also contemplates integrity controls to ensure that ePHI is not improperly modified without detection while in motion. This addresses the accuracy and completeness of data during transmission, separate from confidentiality protections.
Scope of Regulated Relationships
Obligations to protect data in motion attach to covered entities and to business associates and subcontractors through defined relationships and business associate agreements. HIPAA does not directly regulate every network or vendor that data may traverse; responsibility flows through these defined relationships.

Common questions

Answers to the questions practitioners most commonly ask about Data in Motion.

Does the HIPAA Security Rule specifically require encryption of data in motion?
Not in absolute terms. Under the Security Rule's technical safeguards, encryption of ePHI transmitted over electronic communications networks is generally an addressable implementation specification rather than a strictly required one. Addressable does not mean optional; a covered entity or business associate must assess whether encryption is reasonable and appropriate for its environment, implement it where it is, or document why not and adopt an equivalent alternative measure. Because interpretation depends on the current regulatory text and your risk analysis, confirm the specifics against the applicable CFR provisions and current OCR guidance.
If we encrypt data in motion, are we fully HIPAA compliant and protected against breaches?
No. Encrypting data in transit addresses only one aspect of the technical safeguards and does not by itself establish HIPAA compliance or guarantee that no breach will occur. The Security Rule requires a broader set of administrative, physical, and technical safeguards, and the Privacy Rule and Breach Notification Rule impose additional obligations. Encryption also does not protect data at rest, endpoints, or against misconfiguration and human error. It should be treated as one component of a documented, risk-based safeguard program rather than a compliance guarantee.
How should we decide whether encryption of data in motion is 'reasonable and appropriate' for our organization?
This determination generally flows from your risk analysis. Consider the sensitivity and volume of ePHI transmitted, the networks and channels used (for example, internal networks versus the open internet), the likelihood and potential impact of interception, and the cost and feasibility of encryption relative to those risks. Document the analysis and the decision. If you choose not to encrypt a given transmission, the addressable framework generally requires documenting why it was not reasonable and appropriate and what equivalent alternative measure you adopted. Verify the current regulatory expectations against applicable guidance.
What types of transmissions typically fall under 'data in motion' that we should account for?
Data in motion generally refers to ePHI moving across networks or between systems, which can include email, file transfers, messaging, transmissions to and from business associates, remote access sessions, and data exchanged with external partners. The Security Rule's transmission security provisions apply to ePHI specifically, so this concept is scoped to electronic health information rather than oral or paper PHI, which fall under the broader Privacy Rule. Inventorying your transmission channels as part of your risk analysis helps ensure none are overlooked.
Do business associates have their own obligations for protecting data in motion?
Yes. Business associates and their subcontractors are generally directly subject to the Security Rule's requirements, including its transmission security provisions, and these obligations are typically reinforced through business associate agreements. Covered entities should confirm that agreements address how ePHI is protected in transit, but the underlying Security Rule duties attach to business associates through their defined relationships rather than only through contract language. Review your agreements and each party's safeguards against current requirements.
How does protecting data in motion relate to the HITRUST CSF?
The HITRUST CSF includes controls that address transmission protection and can help organize and demonstrate safeguards for data in motion in a structured, certifiable way. However, HITRUST is a private framework, and HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. Meeting a CSF control for transmission security does not automatically satisfy the Security Rule, and organizations should map controls back to the applicable HIPAA requirements. Confirm specifics against the current HITRUST CSF version and current regulatory guidance.

Common misconceptions

Encryption of data in motion is optional because the Security Rule labels it addressable.
Addressable is not the same as optional. A regulated entity must evaluate whether encryption is reasonable and appropriate for its risk environment, and either implement it, or document the rationale and adopt a reasonable equivalent alternative. The determination should be based on a risk analysis and documented.
The Security Rule's data-in-motion protections cover all protected health information.
The Security Rule applies only to ePHI. Protections for data in motion under the Security Rule do not extend to oral disclosures or paper records; those forms of PHI are addressed by the Privacy Rule, which has a broader scope covering PHI in all forms.
Encrypting data in motion guarantees HIPAA compliance and prevents all breaches.
No single measure guarantees compliance or prevents all breaches. Encryption is one control that reduces risk to ePHI during transmission, but compliance generally requires a combination of administrative, physical, and technical safeguards, ongoing risk analysis, and appropriate policies. State law and the HITECH Act may impose additional requirements.

Best practices

Conduct and document a risk analysis to determine where ePHI is transmitted and whether encryption and integrity controls are reasonable and appropriate for each transmission path.
Where encryption is determined not reasonable and appropriate, document that decision and implement a reasonable equivalent alternative, retaining the supporting rationale.
Apply integrity controls alongside confidentiality measures so that improper modification of ePHI in motion can be detected, not just prevented from disclosure.
Ensure business associate agreements with vendors, subcontractors, or service providers that transmit ePHI on your behalf address transmission security obligations, since these responsibilities flow through defined relationships.
Confirm that protections for oral and paper PHI are handled under Privacy Rule policies, recognizing that Security Rule transmission safeguards apply only to ePHI.
Verify current requirements against the applicable regulatory text and consider whether state law or the HITECH Act imposes additional obligations, rather than treating any single safeguard as sufficient for full compliance.