$0 When Your Employee or Colleague Dies — First Steps Guide

HIPAA and the Deceased Employee: Privacy Rules Employers Must Follow

HIPAA Doesn't End at Death

One of the most common mistakes employers make after an employee dies is assuming that HIPAA protections expire with the person. They don't. Under the HIPAA Privacy Rule (45 CFR § 164.502(f)), identifiable health information held by a covered entity or business associate remains protected for 50 years after an individual's death. The rule generally does not govern employment records an employer maintains in its capacity as an employer, even when those records contain health information.

For an employer that sponsors a health plan, plan records and employment records have different HIPAA status. A covered plan or provider that discloses PHI without an authorization or another permitted basis can face HIPAA enforcement; employer-held medical information may also be subject to separate confidentiality rules, including the ADA.

What Counts as Protected Information

HIPAA generally applies to the following health information when it is held by a covered plan, provider, or business associate:

  • Self-insured group health plan records: claims data, diagnoses, treatment histories, and pharmacy records held by the covered plan
  • Flexible Spending Account (FSA) documentation: claim submissions and supporting medical documentation held by a covered plan or its business associate
  • Employee Assistance Program (EAP) records: clinical records held by an EAP provider or plan that is subject to HIPAA
  • ADA accommodation records: employer-held accommodation information is not PHI under HIPAA solely because it is medical, but the ADA requires it to be kept confidential
  • FMLA medical certifications: certifications maintained by an employer as employment records are not HIPAA PHI solely because they contain health information; separate confidentiality rules apply

The Privacy Rule excludes employment records that a covered entity maintains in its capacity as an employer, including standard HR files, performance reviews, disciplinary records, attendance logs, and employment records maintained solely for personnel administration.

Can the Employer Disclose the Cause of Death?

HIPAA does not generally govern an employer's announcement based on information learned in its capacity as an employer. It restricts disclosures of PHI by a covered plan, provider, or business associate; other confidentiality laws and company policies may separately restrict what an employer shares.

When You Cannot Disclose

Do not disclose identifiable medical information from a covered plan or provider record unless the disclosure is authorized or otherwise permitted by the Privacy Rule. The fact that an employer learned information in its employment role does not automatically make that information PHI, but ADA and other confidentiality obligations may still apply.

For workplace announcements, follow the family's privacy preferences and do not confirm or elaborate on medical details from confidential records.

When You Can Disclose

If a covered plan, provider, or business associate receives a valid written authorization from the individual or a personal representative recognized under applicable law, it may disclose the information specified in that authorization, to the persons specified, and for the purposes specified. Other disclosures are allowed only when the Privacy Rule provides a separate permission.

When a disclosure relies on authorization, the authorization must identify what information may be disclosed, to whom, and for what purpose. A verbal "go ahead and tell the team" does not meet HIPAA's written-authorization requirement.

The Practical Approach

Most organizations handle this by:

  1. Designating a single family liaison who asks the next of kin early in the process: "What would you like us to share with the team about the circumstances?"
  2. Documenting the family's response in writing
  3. If disclosure involves PHI held by a covered plan, provider, or business associate, share only what a legally recognized personal representative has authorized; for other company announcements, follow applicable confidentiality rules and the family's documented preferences
  4. If the family requests confidentiality, the company announcement simply says the employee has passed away, without elaboration

Free Download

Get the When Your Employee or Colleague Dies — First Steps Guide

Everything in this article as a printable checklist — plus action plans and reference guides you can start using today.

HIPAA and the Personal Representative

After death, the HIPAA Privacy Rule treats a personal representative recognized under applicable law as standing in the shoes of the individual for PHI rights, subject to the Rule's exceptions. That representative may exercise the deceased person's rights to access and authorize disclosure of PHI.

To exercise these rights, the personal representative must provide documentation of their authority:

  • Letters testamentary (for an executor named in a will) or letters of administration (for a court-appointed administrator); the plan or provider must confirm that the person has authority over the deceased's health information under applicable law
  • In some states, a surviving spouse has statutory authority over health records without formal estate appointment

A covered entity generally must act on an access request within 30 days; it may take one additional 30 days if it gives written notice explaining the delay. That duty belongs to the covered plan or provider, not an employer's HR office solely because it employed the deceased person.

ADA Confidentiality: A Parallel Obligation

The Americans with Disabilities Act imposes its own confidentiality requirements on medical information obtained through employment, and these obligations survive the employee's death.

If the deceased employee had an ADA accommodation — modified schedule, ergonomic equipment, reassigned duties — the employer's medical-information confidentiality duty continues after employment ends, subject to limited exceptions. Managers should not disclose the accommodation to the team or a replacement unless a specific exception permits it.

This matters practically when the deceased's workspace shows visible evidence of an accommodation (specialized equipment, a modified workstation layout). Remove or normalize these before the space is reassigned, without explaining why to the team.

EU and International Considerations

Under the EU's General Data Protection Regulation (GDPR), the regulation does not apply to deceased persons' personal data. Member States may provide their own rules for processing that data.

In the UK, the Data Protection Act 2018 similarly focuses on living individuals, but the common law duty of confidence can extend post-mortem, particularly for health records. Employers with UK-based staff should consult with data protection officers before disclosing any personal information about a deceased employee.

In Australia, the federal Privacy Act 1988 generally does not cover personal information about a deceased person. Information that also identifies living people can remain protected, and state or territory health-records laws may impose separate obligations.

Building Privacy Into the Response Protocol

Privacy compliance after an employee's death isn't just a legal checkbox — it's a trust signal to the surviving team. Employees watch how the company handles a deceased colleague's information. If leadership casually shares medical details or cause of death without authorization, every employee in the room updates their trust calculus.

The When Your Employee or Colleague Dies toolkit includes a privacy alignment checklist that walks the family liaison through the disclosure conversation, the authorization documentation requirements, and the communication boundaries — so the company gets it right from the first announcement.

Get Your Free When Your Employee or Colleague Dies — First Steps Guide

Download the When Your Employee or Colleague Dies — First Steps Guide — a printable guide with checklists, scripts, and action plans you can start using today.

Learn More →