HIPAA After Death Rules: The 50-Year Protection Window and What You Can Disclose
HIPAA Does Not End at Death
One of the most common compliance mistakes in hospice care is assuming that privacy protections expire when a patient dies. They do not. Under federal law, HIPAA protections remain fully in force for 50 years following the date of death.
That means the same rules governing disclosure of a living patient's Protected Health Information apply to a deceased patient's records for half a century. Unauthorized disclosure during that window is a federal privacy breach with real consequences — corrective action plans, fines, and potential condition-level deficiencies during survey.
The Two Pathways for Disclosure
Two common pathways for releasing a decedent's information are the personal-representative and family-involvement routes; another valid authorization or HIPAA-permitted basis may also apply.
The Personal Representative Pathway (45 CFR § 164.502(g)(4)). An executor, administrator, or other person with authority under applicable state law to act for the deceased individual or the estate must be treated as a personal representative for PHI relevant to that authority. Hospice staff must verify the requester's identity and authority if not already known; HIPAA does not prescribe a certified death certificate or one specific form of proof. Appointment papers, such as letters testamentary or letters of administration, may establish that authority.
One critical detail that hospice staff frequently miss: a healthcare power of attorney does not by itself give its former agent post-mortem authority over medical records. Personal-representative authority must be established under applicable state law; a probate appointment is one way, but not the only possible source of authority.
The Family Involvement Pathway (45 CFR § 164.510(b)(5)). A covered entity may disclose relevant, limited PHI to family members, close friends, or other persons who were actively involved in the patient's care or payment for care prior to death. The key word is "relevant" — the disclosure must be directly related to that person's specific involvement.
If the patient expressed a preference during life prohibiting disclosure to a specific person, the hospice must honor that restriction after death. This is where bereavement coordinators sometimes face painful situations: a family member requesting records about a patient who explicitly asked that person not receive them.
What You Can and Cannot Say
Confirming that a patient has died is generally not a HIPAA violation. Families ask hospice staff this question, and a straightforward answer is permitted.
What can violate HIPAA: sharing clinical progression details, medication records, diagnostic findings, or post-mortem physical observations with family members who were not involved in care — without a valid authorization or another HIPAA-permitted basis.
The distinction matters in practice. A spouse who was the primary caregiver and made medical decisions can receive relevant clinical information. An estranged adult child who was not involved in care does not get full-chart access merely by being a relative; the hospice should verify any valid authorization or personal-representative authority under state law.
Free Download
Get the Hospice Worker's Family Bereavement Support Guide — Quick Reference
Everything in this article as a printable checklist — plus action plans and reference guides you can start using today.
The Estranged Family Member Scenario
Hospice bereavement coordinators encounter this regularly: a relative contacts the agency requesting the deceased patient's records. They are family. They are grieving. But they were not involved in care, and the patient may have actively excluded them.
The correct response is to verify the requester's legal standing. Are they the estate's personal representative? Can they provide documentation? If not, were they involved in the patient's care or payment, and does the requested information relate to that involvement?
Releasing records without verifying legal standing is one of the most common HIPAA compliance violations in post-mortem hospice care. The verification must be documented.
State Laws Add Complexity
HIPAA interacts with state privacy and access laws. Where a state privacy rule is more stringent, it may continue to apply under 45 CFR § 160.203. Patient-clinician privilege (such as psychotherapist-patient privilege) persists after death in many states and can only be waived by an authorized representative.
State law determines who has authority to act as the personal representative and may provide procedures for requests from next of kin. Verify that authority and the applicable state process before requesting probate documents or accepting an affidavit.
Multi-state hospice providers need to track these variations and apply the requirements that govern each request.
Protecting Your Agency
Every post-mortem record request should follow a documented decision process: verify the requester's identity, determine their legal standing, confirm the scope of permissible disclosure, check for patient-expressed restrictions, and document the entire chain.
The Hospice Worker's Family Bereavement Support Toolkit includes a HIPAA post-mortem disclosure decision tree and standardized release-of-information forms that walk staff through each step — so compliance decisions are made by the process, not by individual judgment under pressure.
Get Your Free Hospice Worker's Family Bereavement Support Guide — Quick Reference
Download the Hospice Worker's Family Bereavement Support Guide — Quick Reference — a printable guide with checklists, scripts, and action plans you can start using today.