45 CFR § 164.312(e)
Guards against unauthorized access to ePHI being transmitted over electronic networks. Addresses encryption of data in transit, integrity controls for transmitted data, and secure communication channel requirements including email and fax.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy establishes the technical security measures [PRACTICE NAME] implements to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network. It addresses both encryption of transmitted data and integrity controls to ensure data is not improperly modified during transmission.
This policy applies to all electronic transmissions of ePHI, including but not limited to: email, fax (electronic/IP-based), file transfers, remote access sessions, web-based application access, HL7/FHIR interface communications, API calls, and any other method of electronically transmitting ePHI between systems, locations, or entities. It applies to transmissions within [PRACTICE NAME]'s internal network and to transmissions over external networks (the internet).
[PRACTICE NAME] shall implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network, as required by 45 CFR § 164.312(e)(1). The practice shall address both integrity controls (45 CFR § 164.312(e)(2)(i)) and encryption (45 CFR § 164.312(e)(2)(ii)) for ePHI in transit.
Encryption (in transit): The conversion of data into a coded form during transmission so that it cannot be read by unauthorized parties who may intercept the communication.
TLS (Transport Layer Security): A cryptographic protocol designed to provide communications security over a computer network, commonly used for web traffic (HTTPS), email, and other internet communications.
VPN (Virtual Private Network): An encrypted network connection that creates a secure tunnel over a public network (the internet), enabling private data to be sent securely.
SFTP (Secure File Transfer Protocol): A file transfer protocol that provides secure file transfer over SSH (Secure Shell).
End-to-End Encryption: A method of communication where only the communicating users can read the messages, with no intermediary having access to the decryption keys.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.