HIPAA Compliance for Hospice: Families, Volunteers, and the Records

Practical guidance for healthcare teams and business associates

Tuesday morning, interdisciplinary group meeting. A nurse, a social worker, a chaplain, the medical director, the volunteer coordinator, and two volunteers sit around a table with a census of forty patients on the screen. By Thursday one of those patients has died, the family is asking what the death certificate will say, and a volunteer has drafted a heartfelt Facebook post about the gentleman she sat with every Sunday. Every one of those moments is governed by HIPAA, and hospice is the setting where the rules keep running after the patient is gone.

The HHS Office for Civil Rights (OCR) enforcement listing shows what the ordinary failures cost: a $240,000 settlement over snooping in medical records by hospital security guards (June 2023), a settlement over improper disposal of protected health information (August 2022), and an $800,000 settlement in a medical records dumping case (June 2014). None was a hospice. Each failure is one a hospice faces daily across homes, inpatient units, and nursing facilities.

This guide covers why HIPAA applies to a hospice, what protected health information looks like when the family is the unit of care, the violations specific to end-of-life work, how to build a program that includes volunteers, and which vendors need a Business Associate Agreement.

HIPAA Compliance for Hospice: Why Death Does Not End the Obligation

Why HIPAA Applies to a Hospice

45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." The first covered transaction listed is "health care claims or equivalent encounter information." A Medicare-certified hospice bills the Medicare hospice benefit electronically, so it is a covered entity, bound by the Privacy Rule, the Security Rule, and the Breach Notification Rule. The definition itself is explained in what is a covered entity under HIPAA.

The definition that makes hospice different is workforce. 160.103 defines it as "employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid." Volunteers are named outright. And hospice is the one provider type that is required by federal regulation to use them: the Medicare hospice Conditions of Participation at 42 CFR 418.78(e) state that volunteers "must provide day-to-day administrative and/or direct patient care services in an amount that, at a minimum, equals 5 percent of the total patient care hours of all paid hospice employees and contract staff." A hospice therefore has a legally mandated corps of unpaid workforce members, and HIPAA holds the hospice responsible for every one of them: training, access limits, sanctions, and mistakes.

What P.H.I. Looks Like in Hospice

P.H.I. (Protected Health Information) is individually identifiable health information in any form. In hospice it is unusually intimate, and it extends to people who are not the patient.

  • The terminal diagnosis and prognosis. The physician's determination of terminal illness, the related conditions, and the plan of care built around them.
  • Interdisciplinary group (IDG) records. Meeting notes, the comprehensive assessment, and the updated plan of care, which combine medical, psychosocial, and spiritual information in one document.
  • Family and caregiver information. The Conditions of Participation at 42 CFR 418.64(d) require counseling for "the patient and family." The psychosocial assessment, the caregiver's health and coping notes, and the bereavement plan of care all contain information about spouses and children who are not patients but whose details sit inside the patient's record.
  • Spiritual assessments. Religious affiliation and beliefs, which 45 CFR 164.510(a) treats as directory information that may be shared with clergy only after the patient has had a chance to object.
  • Comfort kit and controlled substance records. Medication counts, disposal witness forms, and pharmacy records for morphine in a private home.
  • Advance directives, DNR orders, and portable medical orders. Documents that travel with the patient between home, inpatient unit, and hospital.
  • Bereavement records. 418.64(d)(1)(ii) requires bereavement services "up to 1 year following the death of the patient." Every call log, mailing, and grief group roster from that year references a deceased patient and is P.H.I.
  • Nursing facility charts. When a hospice patient lives in a nursing home, two providers document the same person in two records, and the hospice's notes sit in the facility's chart.

Common Violations in Hospice Settings

Treating the deceased patient's information as fair game. 45 CFR 164.502(f) is blunt: "A covered entity must comply with the requirements of this subpart with respect to the protected health information of a deceased individual for a period of 50 years following the death of the individual." The memorial newsletter, the annual remembrance slideshow, the volunteer's social media tribute, and the "patient story" on the fundraising page all disclose P.H.I. of a person HIPAA still protects. The authorization has to come from the personal representative, which under 164.502(g)(4) is the "executor, administrator, or other person" with authority to act for the deceased or the estate. The full picture is in HIPAA and deceased patients: the 50-year rule.

Family disclosures without the patient's say. While the patient is alive and able to decide, 164.510(b)(2) permits disclosure to family and close friends involved in care only if the hospice "obtains the individual's agreement," gives "the opportunity to object," or "reasonably infers from the circumstances" that the patient does not object. After death, 164.510(b)(5) permits disclosure to family members "who were involved in the individual's care or payment for health care prior to the individual's death," relevant to that involvement, "unless doing so is inconsistent with any prior expressed preference of the individual." The estranged son who calls for the first time after the funeral is not covered by that paragraph, and the patient's stated wishes control. Document the preference while the patient can still state it.

Volunteers with no training and unlimited access. A volunteer is workforce. 164.530(b)(1) requires a covered entity to "train all members of its workforce," and 164.308(a)(3) requires policies to ensure "all members of its workforce have appropriate access." A volunteer who sits with one patient does not need the census, and the minimum necessary standard at 164.502(b) says so. The daily version of that rule is in the HIPAA minimum necessary rule in daily operations.

Social media and tributes. The enforcement listing shows a $10,000 settlement with a dental practice over social media disclosures of patients' protected health information (October 2019). A hospice tribute post with a name, a photo, or enough detail to identify the patient is the same act. The guardrails are in HIPAA and social media: staff mistakes to avoid.

Curiosity in the chart. The $240,000 snooping settlement above is the price of workforce members reading records they had no role in. In a small community, the neighbor and the former teacher show up on the census eventually. 164.308(a)(1)(ii)(D) requires regular review of "audit logs, access reports," and the sanction policy at 164.308(a)(1)(ii)(C) has to be applied when the review finds something.

Paper coming home after a death. The home folder and the visit notes come back to the office in a bag after the patient dies. 164.530(c) requires safeguards for paper P.H.I., and 164.310(d)(2)(i) makes disposal a Required specification for electronic media. Shred it or lock it; a dumpster produced the $800,000 case.

Building the Program

Risk analysis that includes every setting. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI (electronic P.H.I.). A hospice's ePHI lives on field laptops, in an inpatient unit, in nursing facility kiosks, on volunteer phones that receive schedule texts, and in the bereavement coordinator's mail-merge spreadsheet. The analysis has to name all of them. The method is in the risk assessment guide.

Policies hospice actually needs. Beyond the standard set, write three specific to this work: a deceased-patient policy (who may authorize a memorial use, what the tribute rules are), a family communication policy (how the patient's preferences are captured and where staff find them), and a volunteer confidentiality policy (what a volunteer may see, say, and keep).

Training that reaches volunteers. 164.530(b)(2)(i)(B) requires training for each new workforce member "within a reasonable period of time after the person joins." Fold HIPAA into the volunteer orientation that 42 CFR 418.78(a) already requires, and document it. The record must be retained for six years under 164.530(j)(2).

Authorizations for stories and photos. 164.508(a)(3) requires an authorization for marketing, and a fundraising appeal built on a patient's story needs the form, signed by the patient or the personal representative. The form must carry every element in 164.508(c).

Business Associate Agreements. 164.502(e) and 164.308(b) require written assurances from every business associate before it handles P.H.I.

Vendor B.A.A. Checklist for Hospice

A business associate under 160.103 is a person who, on the hospice's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function, or provides "legal, actuarial, accounting, consulting, data aggregation ... management, administrative, accreditation, or financial services" involving P.H.I. The same section excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual."

Vendor categoryTypical examplesB.A.A. required?
Hospice EHRWellSky, Homecare Homebase, MatrixCare, NetsmartYes
Hospice pharmacy servicesThe pharmacy benefit or medication management service that handles formulary, claims, and medication data for the hospiceYes for the management service. A dispensing pharmacy is a provider for treatment disclosures.
Bereavement mailing and grief-support vendorsAny service that sends condolence letters or runs grief groups from the hospice's listYes. The list identifies deceased patients and their families.
Volunteer management softwareAny scheduling tool that pairs volunteers with patientsYes, if patient names appear in it
After-hours answering or triage serviceAny service taking patient and family calls for the hospiceYes
Billing, coding, or revenue cycle firmAny third-party billing companyYes. Billing is named in the definition.
IT managed services, cloud fax, secure messagingThe MSP and the communication platformsYes
Shredding and record storageAny document destruction or storage companyYes
Nursing facility, hospital, attending physician, DME supplierProviders the hospice coordinates care withNo, for treatment disclosures. Both sides remain responsible for their own safeguards.
Funeral homeThe funeral director receiving the death informationNo. 164.512(g)(2) permits disclosure to funeral directors "as necessary to carry out their duties." Limit it to what they need.
Contracted chaplain, social worker, or per-diem nurseIndividuals under the hospice's direct controlNo. They are workforce and need training instead.

The Proposed Security Rule Update (Proposed, Not Final)

HHS published a Notice of Proposed Rulemaking on January 6, 2025 to strengthen the Security Rule. It remains proposed, not final, and OCR is not enforcing it. Among other things it would make encryption and multifactor authentication required rather than addressable, require a written asset inventory and network map, require restoration of critical systems within 72 hours, and require automated vulnerability scans "at least once every six months." Current status is tracked in HIPAA Security Rule delayed to 2027.

For a hospice, that asset inventory would reach the inpatient unit, the field laptops, and every volunteer device that receives patient information. It is already the first page of a proper risk analysis under the existing rule, so build it now.

---

FAQ

Is a hospice a covered entity under HIPAA?

Yes, if it transmits health information electronically for a covered transaction such as a claim. A Medicare-certified hospice bills electronically, which makes it a covered entity under 45 CFR 160.103 and subject to the Privacy, Security, and Breach Notification Rules.

Are hospice volunteers covered by HIPAA?

Yes. 45 CFR 160.103 defines workforce to include volunteers under the covered entity's direct control, whether or not they are paid. The hospice must train them, limit their access to what their role needs, and apply its sanction policy to them.

Can a hospice share information with the family after the patient dies?

Within limits. 45 CFR 164.510(b)(5) permits disclosure to family members who were involved in the patient's care or payment before death, limited to information relevant to that involvement, unless the patient expressed a contrary preference. Record the patient's preferences while the patient can still state them.

Can the hospice post a memorial or a patient story on social media?

Not without a valid authorization. HIPAA protects a deceased person's information for 50 years under 164.502(f), and a tribute that identifies the patient needs an authorization under 164.508 signed by the personal representative, typically the executor or administrator of the estate.

How long do HIPAA protections last after a hospice patient dies?

Fifty years. 45 CFR 164.502(f) requires a covered entity to comply with the Privacy Rule for a deceased individual's protected health information for 50 years following death, and 160.103 removes the information from the definition of PHI only after that period.

Conclusion

A hospice program that already runs an interdisciplinary group, a volunteer corps, and a bereavement plan has most of the structure HIPAA asks for. What is usually missing is the paperwork that proves it: the risk analysis, the deceased-patient policy, the volunteer training log, and a signed B.A.A. for every vendor. One Guy Consulting's Full-Scope plan supplies all of it, with consulting time to fit the policies to how the hospice actually works. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading