Deceased Individuals
Under HIPAA, a deceased individual is a person who has died, and their health information remains protected for a period of time after death. The HIPAA Privacy Rule generally protects a decedent's individually identifiable health information for 50 years following the date of death. After that period, information about the person is generally no longer treated as protected health information under HIPAA, though other laws may still apply.
In the HIPAA context, a 'deceased individual' (also referred to legally as a 'decedent') is a person who has died and whose individually identifiable health information continues to be regulated as protected health information (PHI) under the HIPAA Privacy Rule for 50 years following the date of death. This protection is a function of the Privacy Rule, which governs PHI in all forms; it does not, by itself, alter Security Rule obligations for ePHI during that period. Once the 50-year period following death elapses, the information generally ceases to meet the Privacy Rule's definition of PHI and falls outside HIPAA protection. Practitioners should note that access to and disclosure of a decedent's PHI (for example, to personal representatives, executors, or others involved in the individual's care or payment) is subject to specific Privacy Rule provisions, and that state law governing estates, medical records, and confidentiality may impose additional or differing requirements beyond HIPAA. The term 'deceased individual' as used in the Privacy Rule should not be conflated with broader colloquial or estate-law usages of 'decedent.' Readers should verify the current regulatory text and applicable state law for specific access, disclosure, and time-period requirements.
Why it matters
Health information does not lose its sensitivity the moment a patient dies. The HIPAA Privacy Rule recognizes this by continuing to protect a decedent's individually identifiable health information for 50 years following the date of death. During that window, a covered entity or business associate handling a deceased person's records must treat that information as protected health information (PHI) and apply the same Privacy Rule obligations that would govern a living individual's records, subject to the Rule's specific provisions for decedents. Compliance staff who assume that death terminates HIPAA obligations risk making improper disclosures that could expose the organization to enforcement by HHS OCR.
The 50-year period matters for records retention, access requests, and disclosure decisions alike. Family members, journalists, researchers, and others frequently seek information about someone who has died, but not every requester is entitled to access under the Privacy Rule, and the analysis differs depending on the requester's relationship to the decedent and the purpose of the request. Getting this wrong in either direction, withholding information from a person legally entitled to it, or releasing PHI to someone who is not, creates compliance and legal risk.
This area is also one where HIPAA rarely operates alone. State law governing estates, medical records, and confidentiality may impose additional or differing requirements, and the term 'decedent' carries a distinct meaning in estate and trust law that should not be conflated with its narrower use in the Privacy Rule. Organizations should build their decedent-records practices around both HIPAA and applicable state requirements rather than treating the 50-year rule as the complete picture.
Who it's relevant to
Inside Deceased Individuals
Common questions
Answers to the questions practitioners most commonly ask about Deceased Individuals.