Skip to main content
Category: De-identification and PHI Types

Deceased Individuals

Also known as: Decedent, Deceased Person, Health Information of Decedents
Simply put

Under HIPAA, a deceased individual is a person who has died, and their health information remains protected for a period of time after death. The HIPAA Privacy Rule generally protects a decedent's individually identifiable health information for 50 years following the date of death. After that period, information about the person is generally no longer treated as protected health information under HIPAA, though other laws may still apply.

Formal definition

In the HIPAA context, a 'deceased individual' (also referred to legally as a 'decedent') is a person who has died and whose individually identifiable health information continues to be regulated as protected health information (PHI) under the HIPAA Privacy Rule for 50 years following the date of death. This protection is a function of the Privacy Rule, which governs PHI in all forms; it does not, by itself, alter Security Rule obligations for ePHI during that period. Once the 50-year period following death elapses, the information generally ceases to meet the Privacy Rule's definition of PHI and falls outside HIPAA protection. Practitioners should note that access to and disclosure of a decedent's PHI (for example, to personal representatives, executors, or others involved in the individual's care or payment) is subject to specific Privacy Rule provisions, and that state law governing estates, medical records, and confidentiality may impose additional or differing requirements beyond HIPAA. The term 'deceased individual' as used in the Privacy Rule should not be conflated with broader colloquial or estate-law usages of 'decedent.' Readers should verify the current regulatory text and applicable state law for specific access, disclosure, and time-period requirements.

Why it matters

Health information does not lose its sensitivity the moment a patient dies. The HIPAA Privacy Rule recognizes this by continuing to protect a decedent's individually identifiable health information for 50 years following the date of death. During that window, a covered entity or business associate handling a deceased person's records must treat that information as protected health information (PHI) and apply the same Privacy Rule obligations that would govern a living individual's records, subject to the Rule's specific provisions for decedents. Compliance staff who assume that death terminates HIPAA obligations risk making improper disclosures that could expose the organization to enforcement by HHS OCR.

The 50-year period matters for records retention, access requests, and disclosure decisions alike. Family members, journalists, researchers, and others frequently seek information about someone who has died, but not every requester is entitled to access under the Privacy Rule, and the analysis differs depending on the requester's relationship to the decedent and the purpose of the request. Getting this wrong in either direction, withholding information from a person legally entitled to it, or releasing PHI to someone who is not, creates compliance and legal risk.

This area is also one where HIPAA rarely operates alone. State law governing estates, medical records, and confidentiality may impose additional or differing requirements, and the term 'decedent' carries a distinct meaning in estate and trust law that should not be conflated with its narrower use in the Privacy Rule. Organizations should build their decedent-records practices around both HIPAA and applicable state requirements rather than treating the 50-year rule as the complete picture.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers must ensure their organizations continue to treat a decedent's health information as PHI throughout the 50-year post-death period and apply the Privacy Rule's specific provisions when responding to access and disclosure requests. They should also account for state estate and medical-records laws that may add requirements beyond HIPAA.
Health Information Management and Records Retention Teams
Teams responsible for medical records must reflect the 50-year protection period in retention schedules and access controls, recognizing that death does not immediately end HIPAA obligations. They should confirm both the current regulatory text and applicable state retention rules when setting policy.
Personal Representatives, Executors, and Families
Individuals seeking a decedent's records, such as personal representatives or executors, may be entitled to access under specific Privacy Rule provisions tied to their relationship to the deceased and the purpose of the request. Entitlement is not automatic and may also be shaped by state estate law.
Legal Counsel and Estate Professionals
Attorneys advising on decedent records should note that the Privacy Rule's use of 'deceased individual' is narrower than the estate-law concept of a 'decedent,' and that HIPAA, the HITECH Act, and state confidentiality and estate laws may each impose distinct obligations that must be reconciled.

Inside Deceased Individuals

Continued PHI Protection After Death
Under the HIPAA Privacy Rule, the protected health information of a deceased individual generally remains protected. Covered entities and business associates must continue to safeguard a decedent's PHI rather than treating it as unprotected simply because the individual has died.
50-Year Protection Period
The Privacy Rule generally limits the protection of a decedent's PHI to a period of time following the date of death, after which the information is no longer treated as protected health information under the Rule. Practitioners should verify the exact duration and its effective date against the current regulatory text.
Personal Representative of the Decedent
A person authorized under applicable law to act on behalf of a deceased individual or the individual's estate (such as an executor or administrator) is generally treated as a personal representative for purposes of exercising the decedent's rights under the Privacy Rule, subject to the scope of that authority.
Permitted Disclosures Related to Decedents
The Privacy Rule permits certain disclosures of a decedent's PHI in defined circumstances, such as to coroners, medical examiners, and funeral directors to carry out their duties, and in some cases to family members or others involved in the decedent's care, subject to the applicable conditions and professional judgment.
Scope Limited to the Privacy Rule
Provisions addressing deceased individuals sit within the HIPAA Privacy Rule, which covers PHI in all forms. The Security Rule's separate obligations apply to electronic PHI regardless of whether the individual is living or deceased, so long as the information remains protected.

Common questions

Answers to the questions practitioners most commonly ask about Deceased Individuals.

Does HIPAA protection for an individual's PHI end as soon as they die?
No. Under the HIPAA Privacy Rule, the protected health information of a deceased individual generally remains protected for a period of time after death (as specified in the regulatory text). During that period, a covered entity or business associate must continue to protect the decedent's PHI in substantially the same manner as for living individuals, subject to certain exceptions. After the applicable period elapses, the information is generally no longer treated as PHI under the Privacy Rule. Because the exact duration and its calculation are set by regulation, readers should verify the current period against the applicable Privacy Rule text.
Since the Security Rule covers ePHI, does it stop applying to a deceased person's electronic records?
The Security Rule protects ePHI, and information generally remains ePHI for as long as it remains PHI under the Privacy Rule. In most cases, while a decedent's information is still treated as protected under the Privacy Rule, the corresponding administrative, physical, and technical safeguards continue to apply to it. Once the information is no longer PHI, the Security Rule's obligations tied to that information generally no longer attach. Organizations should not assume that a person's death by itself removes electronic records from safeguard requirements.
Who can authorize disclosure of a deceased individual's PHI?
Under the Privacy Rule, a personal representative of a deceased individual, generally the executor, administrator, or other person authorized under applicable law to act on behalf of the decedent or the estate, may typically exercise the rights the individual would have held, including authorizing disclosures. The scope of a personal representative's authority is defined by applicable state or other law. Organizations should confirm the representative's legal standing before treating them as authorized, and note that state law may impose additional requirements.
Can a covered entity disclose a decedent's PHI to family members involved in their care?
In certain circumstances the Privacy Rule permits a covered entity to disclose relevant PHI to family members, relatives, or others who were involved in the individual's care or payment for care prior to death, unless doing so is inconsistent with any prior expressed preference of the individual that is known to the entity. This is generally a permitted disclosure limited to information relevant to that person's involvement. Because these permissions have specific conditions, verify the applicable provisions and any known individual preferences before disclosing.
How should we handle a research request for deceased individuals' PHI?
The Privacy Rule contains provisions that may permit use or disclosure of decedents' PHI for research under specified conditions, which typically include representations by the researcher about the purpose and, in many cases, documentation regarding the decedents' status. The precise conditions are set by the regulation, so organizations should confirm the current requirements and their internal review processes, and consider whether other frameworks or state law impose additional obligations. This entry does not substitute for that verification.
When can we stop applying HIPAA safeguards to a deceased person's records for retention purposes?
Generally, HIPAA safeguard obligations tied to a decedent's information continue for as long as that information remains PHI under the Privacy Rule, after which the Privacy and Security Rule protections associated with it generally cease. However, records retention is often driven by separate requirements, including state law, the Security Rule's own documentation retention provisions, and other legal or contractual obligations, which may require retaining and continuing to protect records beyond the point at which decedent PHI protections lapse. Confirm all applicable retention requirements before altering how records are stored or safeguarded.

Common misconceptions

Once a patient dies, HIPAA no longer applies to their health information.
The Privacy Rule generally continues to protect a decedent's PHI for a defined period following death. The obligation to safeguard the information does not end at the moment of death, and covered entities and business associates should continue to apply appropriate protections until the protection period lapses under the current regulation.
Any family member automatically has the right to access a deceased relative's records.
Access rights generally flow to a personal representative authorized under applicable law to act for the decedent or the estate, not to every relative by default. Certain limited disclosures to family members involved in care may be permitted, but broad access typically requires the requester to qualify as a personal representative, and state law may impose additional conditions.
Decedent PHI can be shared freely for research, publication, or other secondary uses.
Disclosures of a decedent's PHI are still governed by the Privacy Rule's permitted-use framework. Some uses have specific pathways and conditions, and information does not become generally releasable simply because the individual has died. Practitioners should confirm the applicable basis before disclosing.

Best practices

Treat a decedent's PHI as protected and apply the same handling, access-control, and disclosure discipline used for living individuals until the applicable post-death protection period has clearly lapsed.
Verify a requester's status as a personal representative under applicable law before granting access to a decedent's records, and document the authority relied upon.
Confirm the exact duration and effective date of the post-death protection period against the current Privacy Rule text rather than assuming a fixed timeframe.
Confirm that any disclosure to coroners, medical examiners, funeral directors, or family members fits a permitted-disclosure pathway and its conditions before releasing information.
Check applicable state law, which may impose additional or stricter requirements on access to and disclosure of a decedent's records beyond the HIPAA baseline.
Update workforce training and policies so staff understand that HIPAA obligations do not automatically end at a patient's death, reducing the risk of improper disclosure.