A Funeral Home Called Me About a HIPAA Violation
A few years ago, I got a call from an administrator at a mid-size hospital system. A funeral home had contacted a nurse directly to ask about a deceased patient's cause of death. The nurse, trying to be helpful, pulled up the chart and read off the details over the phone. No authorization. No verification. No documentation.
The administrator wanted to know: does HIPAA even apply after someone dies? The answer caught her off guard. If you're wondering how long is PHI protected after death, the answer under federal law is clear — and it's a lot longer than most people expect.
HIPAA protects a deceased individual's protected health information for 50 years after the date of death. That's not a typo. Fifty years. And the rules around who can access that information, how it's disclosed, and what your organization must do to safeguard it are far more specific than most covered entities realize.
The 50-Year Rule: What HIPAA Actually Says
The HIPAA Privacy Rule doesn't quietly sunset when a patient dies. Under 45 CFR Part 164, Subpart E, the protections that apply to a living individual's PHI continue to apply to a decedent's PHI for 50 years following the date of death.
This means your organization must treat a deceased patient's medical records, lab results, billing information, and any other individually identifiable health information with the same care you'd give a living patient's data — for half a century.
After that 50-year window closes, the information is no longer considered PHI under HIPAA. But here's the catch: state laws may impose longer or stricter protections. You always follow whichever rule is more protective.
Who Can Access a Deceased Patient's PHI?
This is where I see organizations stumble the most. Staff assume that once someone dies, the family automatically gets full access to everything. That's wrong.
The Personal Representative Rule
Under HIPAA, a deceased individual's personal representative — typically the executor or administrator of the estate — steps into the shoes of the patient. They have the same rights the patient would have had, including the right to access, amend, and authorize disclosure of PHI.
HHS has published clear guidance on this. According to the HHS guidance on decedent PHI, covered entities must treat the personal representative as they would the individual for purposes of the Privacy Rule.
But a grieving spouse who walks into your office isn't automatically a personal representative. Your staff needs to verify legal authority — typically through court-issued letters testamentary or letters of administration — before handing over records.
Disclosures for Cause of Death and Other Purposes
There are limited circumstances where you can disclose a decedent's PHI without authorization from the personal representative:
- To a coroner, medical examiner, or funeral director as needed for their duties
- For law enforcement purposes under specific conditions
- For research purposes, with certain protections in place
- To organ procurement organizations when relevant to donation
Each of these has specific guardrails. Your workforce needs to know them — not guess at them.
The $1.9 Million Mistake: Why Decedent PHI Matters to OCR
The Office for Civil Rights doesn't consider death a get-out-of-HIPAA card. OCR has investigated complaints involving decedent records, and the broader enforcement landscape makes it clear that mishandling any PHI — living or deceased — can trigger serious consequences.
In 2018, OCR settled with Cottage Health for $3 million after ePHI was exposed due to a server misconfiguration. The exposed data included records of patients across many years — some of whom were deceased. The point is simple: your security obligations don't expire when a patient does.
I've also seen smaller practices get tripped up. A solo practitioner in the Midwest received a complaint after a family member was denied access to a deceased parent's records. The practice didn't have a policy for handling decedent PHI requests. No policy meant no consistent process, which meant the complaint landed on OCR's desk.
What Your Breach Notification Obligations Look Like for Decedent PHI
If your organization experiences a breach involving a deceased patient's PHI, you still have breach notification obligations. Under the HIPAA Breach Notification Rule, you must notify the personal representative of the deceased individual if a breach of unsecured PHI occurs.
If you can't identify or locate a personal representative, you still need to follow the standard breach notification procedures — including notifying HHS and, in breaches affecting 500 or more individuals, prominent media outlets.
I've reviewed breach reports where organizations didn't realize decedent records were part of the compromised data set. They notified living patients but skipped the deceased. That's a gap OCR can and will identify.
How Long Is PHI Protected After Death? A Quick-Reference Answer
HIPAA protects a deceased individual's PHI for 50 years after the date of death. During this period, covered entities and their business associates must continue to apply all Privacy Rule and Security Rule protections — including access controls, minimum necessary standards, and breach notification. After 50 years, the information no longer qualifies as PHI under HIPAA, though state laws may still apply.
Three Gaps I See in Almost Every Organization
In my consulting work, I've reviewed dozens of privacy programs that handle living patient PHI reasonably well but fall apart when it comes to decedent records. Here are the three most common gaps.
1. No Written Policy for Decedent PHI Requests
Your Privacy Rule policies need to explicitly address how your organization handles requests for deceased patient records. Who verifies the personal representative's authority? What documentation do you require? Where do you log the disclosure? If your team can't answer these questions without improvising, you have a policy gap.
2. Staff Don't Know the Rules
Front desk staff, medical records clerks, and nurses are the ones who field these requests in real time. If they haven't been trained on decedent PHI handling, they'll default to one of two extremes — they'll either refuse all access or hand everything over without verification. Both are wrong.
Building this into your annual workforce training isn't optional. Our HIPAA training catalog includes modules that cover decedent PHI scenarios so your team knows exactly what to do when the call comes in.
3. Retention Schedules That Ignore the 50-Year Window
Some organizations destroy records on a 7- or 10-year cycle. If a patient died two years before that clock started, you could be destroying PHI that's still protected under HIPAA. Your record retention schedule needs to account for the 50-year protection window — or you need to document why state law dictates a different approach.
State Laws Can Extend the Clock
HIPAA sets the floor, not the ceiling. Several states have their own rules about access to deceased patient records, and some impose requirements beyond what HIPAA mandates.
For example, some states grant access rights to a broader set of family members than HIPAA's personal representative framework allows. Others have specific statutes governing how long medical records must be retained — which can interact with the 50-year PHI window in complicated ways.
My advice: map your state requirements against HIPAA's 50-year rule and follow whichever is more protective. If you operate in multiple states, this exercise isn't optional — it's essential.
What You Should Do This Quarter
Here's a practical checklist I give every covered entity I work with:
- Audit your decedent PHI policy. If you don't have one, write one. If you do, make sure it addresses personal representative verification, minimum necessary, and documentation.
- Train your workforce. Decedent PHI scenarios should be part of your regular HIPAA training cycle. Explore our HIPAA workforce training options to find modules that fit your team's needs.
- Review your record retention schedule. Confirm it accounts for the 50-year protection period after death.
- Update your breach response plan. Make sure your incident response procedures include steps for identifying and notifying personal representatives of deceased individuals.
The Bottom Line on Protecting PHI After Death
Death doesn't end your HIPAA obligations. Not even close. For 50 years after a patient dies, their PHI carries the same protections — and your organization carries the same risks — as it does for any living patient.
I've watched organizations treat this as a footnote. Then a complaint lands, or a breach exposes decades-old records, and suddenly it's the most important policy they never wrote.
Don't let that be your organization. Build the policy, train your people, and get the retention schedules right. The 50-year clock is already ticking on every patient you've ever lost.