Skip to main content
Category: Individual Rights

Personal Representative

Simply put

Under the HIPAA Privacy Rule, a personal representative is a person who is legally authorized to make health care decisions for another individual, and who generally may act on that individual's behalf when it comes to their protected health information (PHI). In most cases, a covered entity must treat the personal representative the same as the individual for purposes of exercising rights over PHI, such as accessing records. This role is defined by applicable law and can include a parent acting for a minor or an executor handling the affairs of a deceased person.

Formal definition

In the HIPAA Privacy Rule context, a personal representative is an individual who, under applicable law, has authority to act on behalf of another person in making decisions related to health care. As HHS guidance describes it, the personal representative "stands in the shoes of the individual" and may exercise the individual's rights with respect to their PHI, subject to the scope of that authority. The determination of who qualifies as a personal representative generally depends on state or other applicable law rather than being defined solely by federal HIPAA text; the scope of the representative's authority over PHI is typically limited to the matters for which the person is authorized to act. Note that the term "personal representative" also carries a distinct meaning in probate and estate law, an executor, administrator, or person appointed to administer a decedent's estate, which overlaps with, but is not identical to, its HIPAA usage. For deceased individuals, the person authorized under applicable law to act on behalf of the decedent or the estate may be treated as a personal representative for relevant PHI purposes. Practitioners should verify specific qualifying relationships and any exceptions against the current regulatory text and applicable state law, which may impose additional requirements.

Why it matters

The personal representative concept is central to how covered entities handle situations where an individual cannot or does not act directly on their own PHI. Because HHS guidance describes the personal representative as someone who "stands in the shoes of the individual," a covered entity generally must treat that person the same as the individual for purposes of exercising rights over PHI, such as accessing records or authorizing disclosures. Getting this determination right is essential: granting representative status to someone without proper authority can result in an improper disclosure of PHI, while wrongly denying a legitimate representative can result in an improper denial of access rights.

A key complication is that the term "personal representative" carries a distinct meaning in probate and estate law, an executor, administrator, or person in charge of a decedent's property, that overlaps with, but is not identical to, its HIPAA usage. Covered entities that deal with the records of deceased individuals must be careful not to assume that estate-law status and HIPAA representative status are automatically the same, and must instead confirm that the person is authorized under applicable law to act on the decedent's behalf for the relevant PHI matters.

Because qualifying relationships generally depend on state or other applicable law rather than being defined solely by federal HIPAA text, the analysis is not one-size-fits-all. The scope of a representative's authority over PHI is typically limited to the matters for which that person is authorized to act, so a covered entity cannot treat a limited authorization as blanket access. Practitioners should verify specific qualifying relationships and exceptions against the current regulatory text and applicable state law, which may impose additional requirements.

Who it's relevant to

Privacy Officers and Compliance Staff
Those responsible for HIPAA Privacy Rule compliance must establish procedures for verifying personal representative status before granting access to or disclosing PHI. Because qualification generally turns on applicable state law, their processes should account for jurisdictional differences and document the basis for treating someone as a representative.
Health Information Management and Records Staff
Personnel who process requests for access to records frequently encounter requests from parents, court-appointed representatives, and executors. They need clear guidance on when a requester stands in the shoes of the individual and on the limits of that authority, which is typically confined to the matters for which the person is authorized to act.
Legal Counsel Advising Covered Entities
Attorneys must navigate the overlap between HIPAA's use of "personal representative" and the distinct probate and estate-law meaning of the term. They are well positioned to confirm qualifying relationships against current regulatory text and applicable state law, and to advise on situations involving deceased individuals and their estates.
Staff Handling Records of Deceased Individuals
Those managing PHI for decedents must determine whether a requester is authorized under applicable law to act on behalf of the decedent or the estate. This requires careful attention because estate-law status such as executor or administrator overlaps with, but does not automatically establish, HIPAA personal representative status for all PHI purposes.

Inside Personal Representative

Definition Under the Privacy Rule
A personal representative is generally a person authorized under applicable law to act on behalf of an individual in making decisions related to health care. Under the HIPAA Privacy Rule, a covered entity must generally treat a personal representative as the individual with respect to protected health information relevant to the scope of that representation.
Basis of Authority
The authority to serve as a personal representative typically derives from state or other applicable law rather than from HIPAA itself. Examples commonly include a person holding a health care power of attorney, a court-appointed guardian, or an executor or administrator of a deceased individual's estate.
Scope of Representation
The rights of a personal representative are generally limited to the PHI that is relevant to the matters on which the person is authorized to act. A representative empowered only for a specific purpose is not necessarily entitled to the individual's full record.
Deceased Individuals
For a deceased individual, the person with authority to act on behalf of the estate (such as an executor or administrator under applicable law) may generally be treated as a personal representative for PHI relevant to that authority.
Minors and Parents
A parent, guardian, or other person acting in loco parentis is generally the personal representative of an unemancipated minor, subject to exceptions that vary and that may be governed by state law, including situations where the minor may consent to care independently.
Discretion to Deny Representative Status
The Privacy Rule permits a covered entity, in specified circumstances such as reasonable belief of abuse, neglect, or endangerment, to decline to treat a person as a personal representative if doing so is in the individual's best interest as determined in the exercise of professional judgment.

Common questions

Answers to the questions practitioners most commonly ask about Personal Representative.

Does a personal representative have the same access rights as the individual, or only limited access?
Under the HIPAA Privacy Rule, a personal representative generally must be treated as the individual with respect to protected health information relevant to the scope of the representation. This is not automatically limited access; however, the access typically extends only to PHI relevant to the matters for which the person is authorized to act. A covered entity should confirm the scope of the representative's authority under applicable law and treat them accordingly within that scope. Readers should verify specific requirements against the current regulatory text.
Is anyone acting on a patient's behalf, such as a family member helping with care, automatically a personal representative?
No. Being involved in a patient's care or assisting them does not by itself make someone a personal representative. Personal representative status generally derives from a person's authority under applicable law to make health care decisions for the individual. The Privacy Rule separately addresses disclosures to family members and others involved in care, which is a distinct provision with different conditions. Covered entities should not conflate the two. Verify the applicable standards against current regulation and relevant state law.
How should a covered entity verify that someone is a personal representative before granting access?
The Privacy Rule generally requires covered entities to verify the identity and authority of persons requesting PHI when that identity or authority is not already known. In practice, this typically involves reviewing documentation of the person's legal authority to act on behalf of the individual, such as documentation appropriate under applicable law. The specific acceptable forms of documentation may depend on state law and the nature of the representation. Organizations should confirm their verification procedures against current regulatory guidance.
Can a covered entity refuse to treat someone as a personal representative?
In certain circumstances, the Privacy Rule permits a covered entity to decline to treat a person as a personal representative. This generally includes situations where the entity reasonably believes the individual may be subject to abuse, neglect, or endangerment by that person, and where treating the person as the representative would not be in the individual's best interest. The application of this discretion depends on the specific facts and professional judgment. Readers should review the current regulatory text and consult legal counsel where appropriate.
How does personal representative status apply to minors and their parents?
In most cases, a parent, guardian, or person acting in loco parentis is the personal representative of an unemancipated minor. However, there are exceptions where a minor may control their own PHI, such as when the minor consents to care and no other consent is required by law, or where state or other applicable law addresses minor access to particular services. Because state law significantly influences these situations, covered entities should confirm the applicable requirements for their jurisdiction rather than relying on a single general rule.
How is a deceased individual's personal representative handled for access purposes?
The Privacy Rule generally provides that a person authorized under applicable law to act on behalf of a deceased individual or the individual's estate may be treated as a personal representative with respect to relevant PHI. The scope of that authority is typically defined by applicable law governing estates and decedents. Covered entities should verify the person's legal authority and note that additional or differing requirements may arise under state law before disclosing a decedent's PHI.

Common misconceptions

A personal representative has unlimited access to all of an individual's PHI.
Access is generally limited to PHI relevant to the scope of the person's authority. Someone authorized for a narrow purpose is not automatically entitled to the individual's entire record.
HIPAA itself determines who qualifies as a personal representative.
Whether a person qualifies is generally determined by state or other applicable law. HIPAA directs how covered entities treat such persons but does not itself create the underlying legal authority, so state law and other frameworks must be consulted.
A covered entity must always treat an authorized person as a personal representative.
The Privacy Rule allows a covered entity to decline to do so in specified circumstances, such as a reasonable belief of abuse, neglect, or endangerment, where honoring the request would not be in the individual's best interest based on professional judgment.

Best practices

Verify the legal basis for a person's claimed authority (for example, a power of attorney, guardianship order, or estate documentation) before treating them as a personal representative, and consult applicable state law where the scope is unclear.
Limit disclosures to the PHI that is relevant to the scope of the representative's authority rather than releasing the individual's entire record by default.
Document the verification of a personal representative's authority and the scope of PHI disclosed to support accountability and consistency.
Establish clear policies and staff training for handling minors, deceased individuals, and situations involving potential abuse, neglect, or endangerment, since these areas involve exceptions and professional judgment.
Recognize that state law and other frameworks may impose additional or differing requirements, and confirm current requirements against the applicable regulatory text rather than relying on general assumptions.
Apply the Privacy Rule's discretion to decline representative status carefully, using and documenting the professional judgment supporting any decision made in the individual's best interest.