Skip to main content
Post-Mortem PHI: The 50-Year Rule You're Probably ViolatingRegulatory Framework
4 min readFor Privacy Officers

Post-Mortem PHI: The 50-Year Rule You're Probably Violating

What changed: The 2013 HHS Omnibus Rule established a 50-year protection period for deceased individuals' Protected Health Information (PHI), replacing the previous indefinite timeline. This change created a clear rule balancing privacy interests with historical research needs, but it also introduced a compliance gap most organizations haven't closed.

Your organization is likely treating deceased patient records as "expired privacy concerns" the moment the death certificate is filed. That assumption puts you at risk.

Key Findings

1. The 50-year clock starts at death, not at last contact

HIPAA's Privacy Rule protects the individually identifiable health information of a deceased person for 50 years after their date of death. This isn't a records retention mandate; state law still governs how long you must physically store records. However, it is an access control requirement. Every disclosure during that window must meet the same authorization standards you'd apply to a living patient, with specific exceptions.

2. Personal representatives get full access, but verification is your job

Your organization must treat a deceased individual's legal personal representative (the executor or administrator of the estate) exactly as you would treat the patient. That person can access the complete medical record and authorize third-party disclosures. The compliance trap: many organizations hand over records to "the spouse" or "the oldest child" without verifying legal authority. If that person isn't the court-appointed executor, you've disclosed PHI to an unauthorized party.

3. Family involvement before death doesn't equal blanket access after

You may disclose PHI to a family member or friend involved in the patient's care or payment for care prior to death, but only information relevant to that involvement. This is where most violations occur. A daughter who drove her father to appointments can receive information about those visits. She cannot receive his full psychiatric history, substance abuse treatment records, or genetic test results unless she's the legal executor.

4. The "famous case" exception doesn't exist

Staff discussing "interesting" or high-profile deaths with colleagues, the media, or on social media are committing reportable HIPAA violations. The decedent's notoriety doesn't waive privacy protections, nor does clinical curiosity.

5. Coroners and funeral directors have a built-in exception

Covered entities may disclose PHI to coroners, medical examiners, and funeral directors as necessary for them to carry out their legal duties. This exception is narrow: it covers cause-of-death determination, body identification, and burial arrangements. It doesn't authorize sharing the decedent's full medical history with the funeral home for a memorial service slideshow.

What This Means for Your Team

Your current intake process for records requests probably doesn't distinguish between living and deceased patients. That's a problem. Post-mortem requests require a different verification workflow:

  • You need a system to flag deceased patient records in your health information management system.
  • Your front-desk staff must know not to release records to "family" without Privacy Official review.
  • Your release-of-information team needs a checklist for executor verification (letters testamentary, court orders, state-specific documentation).

The 50-year timeline also creates a records access problem you might not have considered: if your organization has been in operation for decades, you're sitting on PHI for patients who died 30, 40, or 49 years ago. Those records are still protected. If you're migrating to a new electronic health record system or digitizing paper archives, you must maintain the same access controls for those older decedent records as you do for active patients.

Action Items by Priority

Immediate (this quarter):

  1. Audit your release-of-information procedures. Do they explicitly address deceased patient requests? If your form says "patient or patient's legal representative," add a verification step: "If patient is deceased, request documentation of executor/administrator status."

  2. Train your front-line staff. Receptionists, patient access representatives, and medical records clerks must understand that "I'm the spouse" or "I'm the daughter" doesn't authorize release. Create a one-page job aid: "If the patient is deceased, route the request to [Privacy Official name]."

  3. Review your last 90 days of deceased patient disclosures. Pull a sample of 10-15 records requests where the patient was deceased at the time of the request. Did you verify executor status? Did you limit disclosures to family members based on their prior involvement? Document any gaps and determine whether you need to report a breach.

Short-term (next six months):

  1. Build a post-mortem request workflow. Your Privacy Official needs a decision tree: Is the requestor the legal executor? (Verify and release full record.) Is the requestor a family member? (Determine prior involvement and limit disclosure accordingly.) Is the requestor a researcher? (Apply the 50-year rule and your organization's research authorization process.)

  2. Update your Notice of Privacy Practices. Most NPPs don't mention post-mortem protections. Add a section: "If you pass away, your health information remains protected for 50 years. Your legal personal representative will have the same access rights you had during your lifetime."

  3. Flag high-risk scenarios in your risk analysis. Post-mortem disclosures are a known vulnerability. Document the specific controls you've implemented (verification procedures, staff training, access logs) and test them annually.

Ongoing:

  1. Monitor public areas and staff communications. Workforce members discussing a patient's death in an elevator, cafeteria, or parking lot are violating HIPAA whether the patient died yesterday or ten years ago. Your culture-of-compliance training should explicitly cover post-mortem scenarios.

  2. Review state law. Some states provide additional protections or different timelines for deceased individuals' health information. Your organization must comply with the more restrictive standard.

The 50-year rule isn't an obscure edge case. It's a daily compliance requirement for any organization that treats patients who die. If you're waiting for an executor to challenge an improper disclosure before you tighten your procedures, you're betting your organization's reputation and your OCR audit results on luck.

You Might Also Like