Contact Us
IT Total Care

Blog

Caregiver steadying an older woman with a walker beside a van after a home visit, the care that precedes questions about HIPAA rules for deceased hospice patients.

HIPAA Rules for Deceased Hospice Patients: Who Can See the Record After Death

HIPAA rules for deceased hospice patients do not end when the patient dies. Under 45 CFR 164.502(f), a hospice must keep protecting a decedent’s protected health information for 50 years following the date of death, and during those 50 years only two pathways open the record to anyone outside the agency: the personal representative of the decedent, and family members who were involved in the patient’s care before the death.

For a hospice, that is not an occasional situation. It is the normal condition of nearly every chart on the system. MedPAC’s March 2026 report to Congress found that the median lifetime length of stay among hospice decedents was 19 days in 2024, and that 1.33 million Medicare decedents used hospice that year. Within weeks of admission, the record your team is documenting into is a decedent record.

This is written for hospice administrators, directors of patient care services, and compliance leads across the San Francisco Bay Area, where a June 2026 change in state licensing rules has put hospice documentation under a new kind of scrutiny. It covers who may receive a record after a death, what your staff may say to a grieving family, and the single correction that causes more confusion than anything else in this subject: 50 years of protection is not 50 years of retention.

Do HIPAA Rules for Deceased Hospice Patients Really Last 50 Years?

Yes. Section 164.502(f) requires a covered entity to comply with the Privacy Rule for the protected health information of a deceased individual for a period of 50 years following the date of death. The protection is the same as it was in life. Minimum necessary applies. Identity verification applies. Permitted-purpose limits apply.

Death changes who may exercise the patient’s rights, not whether the information is protected. After 50 years the information is no longer protected health information under 45 CFR 160.103 and falls outside the rule entirely. That end point is real, but it is almost never operationally relevant, because no hospice is deciding today what to do with a chart from 1976. The 50-year figure matters for what it says about the record created last month.

Where does the 50-year clock actually run?

The clock runs on the record wherever it sits, not on the electronic medical record alone. That includes the clinical record in WellSky, MatrixCare, KanTime, Homecare Homebase, or Netsmart, the bereavement file kept separately by the counselor, the census spreadsheet someone exported to a shared drive during the last survey, and the attachments sitting in email threads with a referring facility.

If the information identifies the patient and the hospice holds it, the obligation follows it there. Agencies tend to secure the electronic medical record carefully and lose track of everything downstream of it, which is where post-death disclosures usually go wrong in practice.

Who Can Legally Receive a Deceased Hospice Patient’s Record?

Two groups, and nobody else without a valid authorization: the personal representative of the decedent, and family members or others who were involved in the patient’s care or payment for care before the death. These are separate pathways with separate rules, and confusing them is the most common reason a request either stalls for weeks or becomes an improper disclosure.

What is a personal representative under 164.502(g)(4)?

A personal representative is the executor, the administrator, or whoever else has authority under state law to act on behalf of the decedent or the decedent’s estate. That person holds the same rights the patient held in life, including access to the full record and the ability to authorize disclosures to others.

The status is documented rather than assumed. It is established by letters testamentary, letters of administration, or the California equivalent, and the hospice files a copy alongside the request. Someone who says they are handling the estate is not yet a personal representative, and treating them as one is a disclosure the agency cannot defend later.

What does the family pathway at 164.510(b)(5) permit?

Section 164.510(b)(5) permits a hospice to disclose a decedent’s protected health information to family members and others who were involved in the patient’s care or payment for care before the death. The disclosure is limited to information relevant to that person’s involvement, which puts the daughter who managed the medications and sat through the final two weeks on different ground than the nephew who visited once.

The pathway is also barred where the disclosure would be inconsistent with a prior expressed preference of the patient that the hospice knows about. That limit is easy to honor when someone wrote the preference down while the patient could still state it, and impossible to honor when nobody did.

Does a family member need to sign an authorization?

No. No authorization is required on the family pathway, which disposes of the widespread belief that every conversation with a bereaved family needs signed consent first. Two other limits matter more than the paperwork does.

First, the pathway is permissive rather than mandatory. The hospice may disclose; it is not obligated to. Second, relationship by itself authorizes nothing. Being the spouse or the adult child is not, on its own, either pathway. The family pathway turns on involvement in the care, and the personal representative pathway turns on legal authority over the estate.

What Can Hospice Staff Say to a Bereaved Family?

Staff may share information relevant to that family member’s involvement in the patient’s care, without an authorization, once someone has established which pathway the person is on. That covers most of what families actually ask after a death: what happened in the final hours, what the nurse documented on the last visit, whether the patient seemed to be in pain.

The minimum necessary standard applies to post-death disclosures exactly as it applies in life, so the answer to a question about the last visit is the last visit, not the full chart. What the rule does not support is a blanket refusal. A hospice that turns down every post-death request because HIPAA supposedly forbids it is getting the rule wrong in the other direction, and the cost lands on the bereavement relationship the agency exists to hold. Families remember being refused, and they rarely hear it as compliance.

Where Do Post-Death Requests Show Up in a Hospice?

Post-death requests arrive through ordinary channels, usually by phone and usually without warning, and they almost never announce themselves as privacy questions. These are the situations that recur across agencies:

  • A daughter calls three weeks after her mother’s death asking what the nurse documented on the last visit.
  • A son who was never involved in the care asks for the full chart, and the intake coordinator does not know which pathway he is on.
  • A bereavement counselor holds notes on surviving family members, which are a different record about living people and carry different rules.
  • A funeral director requests information, which 45 CFR 164.512(g) addresses separately from either family pathway.
  • A volunteer who sat with a patient for six months is asked by the family what happened at the end. Volunteers are workforce members under 45 CFR 160.103 and are subject to the same rules as paid staff.
  • An interdisciplinary group meeting references a deceased patient by name in a room that includes volunteers.

The common failure here is structural rather than clinical. Post-death requests land on whoever answers the phone, and that person has no pathway to apply, no script to read from, and nobody specific to hand the call to.

Does the 50-Year Rule Mean You Must Keep the Record for 50 Years?

No, and this correction is worth making once and making clearly. HHS stated in the final rule that the 50-year period of protection is not a record retention requirement, and that covered entities may destroy records at the time permitted by state or other applicable law. Protection and retention are two different questions.

How long the record is protected is federal and fixed at 50 years. How long you are required to keep it comes from somewhere else entirely, and for a California hospice the answer is longer than most published guidance says.

That second answer changed on June 22, 2026, when the California Department of Public Health’s emergency hospice licensing regulations at Title 22, sections 74800 through 74908, took effect. They are the first comprehensive hospice licensing framework the state has ever had, and they moved documentation standards out of the category of internal custom and into the category of license conditions a CDPH surveyor can cite. They remain emergency regulations, and CDPH has said it intends to pursue regular rulemaking to make the same requirements permanent.

One more source of confusion belongs here. HIPAA does contain a six-year rule, at 164.530(j)(2) for Privacy Rule documentation and 164.316(b)(2)(i) for Security Rule policies and procedures. It governs the agency’s own paperwork: policies, notices, and required written records. It has never applied to clinical records, and applying it to charts is how agencies destroy records years before they are permitted to.

How Should a Hospice Build a Post-Death Disclosure Process?

Build it around one named responsible party and a written pathway determination. Post-death requests are not frequent enough for staff to develop instinct about them, so the process has to carry the knowledge instead of the person. Eight steps cover it:

  1. Route every post-death request to one named responsible party rather than to whoever answers the phone.
  2. Establish which pathway the requester is on before anything at all is disclosed.
  3. Write the determination down, including the date and the basis for it.
  4. For a personal representative, obtain and file the documentation: letters testamentary, letters of administration, or the state-law equivalent.
  5. For a family request, record what involvement in the care the person had and what information was relevant to that involvement.
  6. Capture any prior expressed preference while the patient can still state it, because the limit still applies after the death and nobody can reconstruct it then.
  7. Apply minimum necessary to post-death disclosures exactly as you would in life.
  8. Give bereavement and clinical staff a written answer to the question they will actually be asked: what may I tell this family member who is standing in front of me.

Keep bereavement records on surviving family members separate from the patient’s clinical record. Those are records about living people who were never your patients, and filing them together is how a routine request for a decedent’s chart turns into a disclosure about the widow.

Where Do Hospices Get HIPAA Rules for Deceased Hospice Patients Wrong?

The errors run in both directions, and the over-restrictive ones are as common as the permissive ones. Six patterns account for most of what agencies discover when they look:

  • A grieving spouse is refused everything on a blanket reading of HIPAA, when 164.510(b)(5) permitted the disclosure.
  • A full chart goes to an adult child on the strength of the relationship alone, with no representative documentation on file.
  • Volunteers are trained once at orientation and never again, against a written program that says annually.
  • A volunteer posts about a patient’s death on social media, and nobody had ever named that as a violation.
  • A California hospice is still operating on a retention policy written before June 2026.
  • The HIPAA six-year documentation rule is applied to charts, and clinical records are destroyed years before either the federal or the state period has run.

What Can an IT Partner Do About HIPAA Rules for Deceased Hospice Patients?

An IT partner cannot make the disclosure decisions. Determining whether a requester is a personal representative, and deciding what a family member may receive, are the hospice’s determinations.

Nor can an IT partner set your retention policy, because the period comes from federal rule, state licensing regulation, and Medicare enrollment conditions rather than from a system setting. What an IT partner supplies is the infrastructure underneath those decisions: the access control that determines who could have reached the record, the audit trail that shows who actually did, and the ability to produce or destroy a record on schedule and prove it happened. Agencies should expect an IT provider to help support HIPAA compliance. No provider can hold that compliance for you.

How do you control who reaches the record?

  • Named accounts for every workforce member, volunteers included. A shared login makes the audit trail unusable for exactly the question that arises after a death, because it cannot tell you who opened the chart. Identity controls such as multi-factor authentication at a home-based care agency start in the same place.
  • Role-scoped access, so that a bereavement volunteer, an administrative volunteer, and a clinician do not see the same thing.
  • Device controls on the tablets volunteers and clinicians carry into homes, so an unlocked screen left on a kitchen table is not the exposure. Building a device inventory list at a home-based care agency is the first step, since a device nobody has recorded is a device nobody controls.
  • Documentation timeliness supported rather than assumed. California’s 30-day completion window and 48-hour correction window are system behaviors before they are staff behaviors.

What should you ask an IT provider before signing?

  • How do you provision and deprovision volunteers as distinct from paid staff?
  • Do you work with hospices specifically, or with medical practices generally?

The second question separates providers quickly. Hospice carries workforce categories, survey exposure, and record obligations that a general medical practice does not, and a provider who has not seen a CDPH hospice survey will learn on your license.

Post-Death Requests Are Predictable, So Treat Them That Way

Almost every hard post-death question a hospice faces has a known answer. Fifty years of protection, two disclosure pathways, documentation for one and evidence of involvement for the other, minimum necessary throughout, and a retention clock that is a separate question with a separate answer. What agencies are missing is rarely the rule. It is the named responsible party, the written determination, and the systems that can show afterward who reached the record and when.

Ready to Put a Process Behind Post-Death Requests?

IT Total Care works with hospice, home health, and home care agencies throughout the San Francisco Bay Area on the systems these obligations rest on: named accounts and role-scoped access, audit trails that can answer a question months after a death, device controls in the field, and the documentation a surveyor asks to see. Our home-based care IT support covers access control, device management, and the evidence that makes a disclosure decision defensible. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.

Leave a Comment

Your email address will not be published. Required fields are marked *