SESK: Stuff Everyone Should Know · sesk.info/hipaa-transmission-encryption-addressable
Is encryption required for ePHI sent over a network?
No, transmission encryption is addressable.
- Yes, it is always required
- No, it is addressable ✔
- Only for email, not portals
Why: Encryption for ePHI in transit is an addressable transmission security specification. An entity must assess it and implement or document an equivalent.
Huh, didn't know that: Use of encrypted email or a secure portal can meet this when reasonable.
Why did the email put on a disguise? It wanted to be encrypted in transit.
Like this card?
References
Answer: No, it is addressable. Encryption for ePHI in transit is an addressable transmission security specification. An entity must assess it and implement or document an equivalent.
- 45 CFR 164.312(e)(2)(ii) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
Encryption (Addressable). Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.