How to Secure Death Records in Healthcare: HIPAA Compliance, Access Controls, and Best Practices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Secure Death Records in Healthcare: HIPAA Compliance, Access Controls, and Best Practices

Kevin Henry

HIPAA

April 19, 2026

6 minutes read
Share this article
How to Secure Death Records in Healthcare: HIPAA Compliance, Access Controls, and Best Practices

HIPAA Protection Period for Decedent Information

Under the HIPAA Privacy Rule, Decedent Health Information Privacy is protected for 50 years after the date of death. During this period, death records and any ePHI remain PHI and require safeguards and permissible-use checks before any disclosure.

You must apply the Minimum Necessary Standard to all uses and disclosures, limiting access to what is reasonably needed for the task. Covered entities and business associates share accountability for safeguarding decedent information and documenting disclosures.

Practical controls

  • Record the verified date of death and automatically calculate the 50-year protection end date.
  • Flag decedent charts to route all requests through Release of Information (ROI) with enhanced review.
  • Encrypt repositories containing death records and enforce multifactor authentication for remote access.
  • Audit disclosures related to estates, insurance, and research for adherence to the Minimum Necessary Standard.

Personal Representative Access Rights

Personal Representative HIPAA Rights place the authorized executor, administrator, or other legally designated person in the shoes of the individual. They may access the designated record set to settle the estate, subject to verification and any lawful limitations.

You should validate identity and authority before release, scope the disclosure to estate-related needs, and respond within HIPAA’s standard access timelines. Document your decision, rationale, and materials released.

Step-by-step process

  • Collect proof of authority (e.g., letters testamentary or equivalent) and government ID.
  • Confirm the request’s purpose and apply the Minimum Necessary Standard to the requested items.
  • Exclude materials not subject to access (e.g., psychotherapy notes) and withhold items under legal hold.
  • Provide copies in a secure format, log the disclosure, and retain request records per policy.

Disclosure to Family Members Guidelines

HIPAA permits disclosures to family members and others involved in the patient’s care or payment prior to death when relevant to their involvement and not inconsistent with the decedent’s known preferences. This is narrower than the authority of a personal representative.

Always document who was involved in care, what information is pertinent, and any objections known from the patient. Apply the Minimum Necessary Standard and limit disclosures to the specific context, such as billing clarification or care coordination after death.

Implementation tips

  • Use a standard assessment to verify prior involvement in care or payment.
  • Route complex or disputed requests to Privacy/Compliance for review.
  • Record the basis for disclosure, content shared, and the recipient in the disclosure log.

Facility Access Controls Implementation

Physical safeguards must prevent unauthorized entry to locations housing ePHI, including paper death records and data centers. Implement layered defenses, validate access, and maintain Facility Access Logs to support investigations and audits.

Core elements include a facility security plan, access control and validation procedures, contingency operations for emergencies, and maintenance records for doors, locks, cameras, and alarm systems.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Best-practice controls

  • Zone sensitive areas (HIM, server rooms) with badge readers and anti-tailgating measures.
  • Require visitor registration, escorts, temporary badges, and sign-in/out with photo ID.
  • Store death records in locked rooms and cabinets; restrict keys and manage key inventories.
  • Capture Facility Access Logs automatically, reconcile them weekly, and retain them long enough to support investigations and HIPAA documentation requirements.
  • Test camera coverage and door alarms quarterly; remediate and document gaps.

Role-Based Access Control Mechanisms

Role-Based Access Control aligns workforce permissions with job duties to enforce the Minimum Necessary Standard. Define roles for ROI specialists, HIM managers, clinicians, coroner/medical examiner liaisons, and privacy officers with only the capabilities each needs.

Use unique user IDs, multifactor authentication, time-based access, and automated provisioning/deprovisioning. Conduct quarterly access reviews, separation-of-duties checks, and just-in-time elevation for rare tasks, all with heightened auditing.

Example role design

  • ROI Specialist: view and disclose decedent records via approved workflows; cannot alter clinical content.
  • Clinician: read-only access to relevant decedent charts for continuity and quality review.
  • Privacy Officer: audit logs, approve exceptions, and oversee Emergency Access Protocols.
  • Coroner Liaison: limited release module for legally permitted disclosures with automatic logging.

Record Retention and Destruction Policies

HIPAA sets a 50-year protection period for decedent PHI but does not prescribe how long medical records must be retained. Follow applicable federal, state, and accreditation rules for record retention, and keep HIPAA-required documentation and disclosure logs for at least six years from the date of creation or last effective date.

Adopt a clear retention schedule for death records, with triggers for legal holds, audits, and investigations. When the retention period ends, apply Defensible Record Destruction that is authorized, documented, and consistently executed.

Defensible destruction methods

  • Paper: cross-cut shredding, pulping, or incineration with custody tracking and certificates of destruction.
  • Electronic media: crypto-erase or sanitize in line with recognized media-sanitization standards; verify by sampling and maintain asset inventories.
  • Vendors: use contracts requiring secure transport, monitored processing, and proof of destruction.

Emergency Access Procedures for ePHI

Emergency Access Procedures ensure authorized personnel can obtain ePHI during incidents such as disasters, system outages, or urgent clinical events. Define Emergency Access Protocols that specify who can activate emergency access, permissible scope, and how access is monitored and terminated.

Implement “break-the-glass” with strong identity checks where feasible, reason capture, tight time limits, enhanced logging, and post-event review by privacy or compliance. Test procedures during downtime drills and include read-only fallbacks, offline access packets, and priority restoration of systems holding death records.

Core elements

  • Clear activation criteria and on-call authorization
  • Temporary role elevation with automatic expiration
  • Real-time alerts to privacy and security teams
  • Comprehensive audit trails and rapid post-incident review
  • Regular training and scenario-based testing

FAQs

How long is a deceased person's health information protected under HIPAA?

HIPAA protects a decedent’s PHI for 50 years from the date of death. After 50 years, the information is no longer PHI under HIPAA, though other laws and ethical standards may still guide prudent handling.

Who can access death records under HIPAA regulations?

The personal representative (such as an executor or court-appointed administrator) has the same access rights as the individual. Family members or others involved in prior care or payment may receive information relevant to their involvement, provided it is not inconsistent with the decedent’s known wishes and conforms to the Minimum Necessary Standard.

What are the best practices for facility access controls to secure ePHI?

Use layered physical security with validated entry, monitored Facility Access Logs, visitor controls, locked storage for paper charts, and surveillance in sensitive areas. Test access points, document maintenance, reconcile logs, and retain records long enough to support investigations and compliance reviews.

How should healthcare organizations handle destruction of death records?

Follow your retention schedule and confirm no legal hold applies, then perform Defensible Record Destruction. Use secure shredding or pulping for paper and cryptographic erasure or sanitization for electronic media, document the process, obtain certificates of destruction, and update inventories and audit logs.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles