The CMS Conditions of Participation require hospice agencies to provide bereavement services to surviving families for a period of no less than one year following the patient's death. This requirement means that every hospice organisation maintains an active relationship — and an active, growing data file — with families who have lost a loved one under hospice care for up to 13 months after the patient's death. The data collected in this relationship is PHI for as long as it can be linked to the deceased patient's record. HIPAA's protections for PHI do not expire at the patient's death. The bereavement record — family member names, grief assessment scores, mental health referrals, family dynamic observations, and bereavement support communications — remains fully subject to HIPAA's privacy, security, and retention requirements throughout the bereavement programme period and for the applicable retention period after the case closes.
Most hospice HIPAA programmes address bereavement data management as an afterthought to the clinical data protection framework. The clinical programme team receives significant compliance infrastructure attention. The bereavement programme team — typically a small group of bereavement coordinators and trained volunteers — receives considerably less. This disparity creates a compliance gap that is both preventable and significant. The bereavement programme data is sensitive, it involves people in a grief-vulnerable state whose trust in the hospice extends beyond the patient's death, and it is held for a longer period than most acute-episode healthcare data.
What Bereavement Programme Data Contains and Why Its Sensitivity Is Underestimated
A complete bereavement programme record for a hospice family typically contains five categories of information, each with distinct sensitivity characteristics:
• Family member identifying information: names, addresses, telephone numbers, and email addresses of family members involved in the bereavement relationship. This information is PHI because it is linked to the deceased patient's record. It includes the home addresses of people who have been through a period of significant emotional vulnerability and who have an expectation that information shared with the hospice in that context will be protected.
• Grief assessment scores and narrative notes: the bereavement coordinator's assessment of each family member's grief trajectory, risk factors, and support needs. Grief assessment narrative — which may describe a family member's history of depression, anxiety, or prior loss, their relationship quality with the deceased, their current functioning, and the bereavement coordinator's clinical judgement about their risk level — is among the most sensitive psychosocial documentation the hospice holds.
• Mental health referral documentation: when bereavement assessment identifies a family member who needs mental health support beyond what the bereavement programme provides, the referral documentation — the referral source, the receiving provider, and the reason for referral — sits in the bereavement record. Mental health referral documentation carries the additional sensitivity that applies to all behavioural health information under HIPAA and under state laws that may provide enhanced protections for mental health records.
• Bereavement support communications: letters, cards, anniversary acknowledgements, and any special outreach provided to the family. These communications are part of the care record and are subject to HIPAA retention requirements even when they appear to be simple correspondence.
• Family dynamics and care history observations: the bereavement coordinator's notes from interactions with the family during the active care episode — observations about family relationships, conflict, financial concerns, and the family's experience of the patient's final period — that inform the bereavement support approach. This content is particularly sensitive because it reflects observations made when family members were in their most vulnerable state.
The Bereavement Data Retention Calculation — The Complexity Most Compliance Officers Miss
The retention timeline for bereavement programme data is more complex than for most hospice PHI, and the complexity creates compliance exposure when it is not explicitly worked through. Three overlapping retention frameworks apply simultaneously.
Framework 1: HIPAA Documentation Retention
HIPAA's Security Rule documentation retention requirement (45 CFR § 164.316(b)(2)) requires that security programme documentation be retained for six years from the date of creation or last in effect. The bereavement programme policies, the privacy notice provided to family members, and the HIPAA compliance documentation governing the bereavement programme are subject to this six-year requirement from the date of each document's creation or last modification.
Framework 2: State Medical Record Retention
Patient clinical records — which in most states are interpreted to include the clinical record maintained throughout the care episode, and potentially the bereavement records linked to that episode — are governed by state medical record retention laws. New York requires six years from date of service. California requires ten years. Massachusetts requires seven years. For bereavement records linked to a deceased patient's record, the "date of service" interpretation varies by state — in some states the bereavement programme period is considered part of the hospice care episode, extending the retention clock to include the full 13-month bereavement service period.
Framework 3: The CMS CoP Bereavement Service Requirement
The CMS CoP requirement for one year of bereavement services means that the bereavement record is actively growing — new assessments, new communications, new referral documentation being added — for up to 13 months after the patient's death. The retention clock for the bereavement record does not start at the patient's death. It starts when the bereavement programme closes the family's case — which may be 13 months after the death if bereavement services continued for the full required period.
The Practical Retention Calculation
Working through these three frameworks for a hospice serving patients in New York State:
• Patient dies in January 2024
• Bereavement programme closes the family's case in February 2025 (13 months later, after the one-year service requirement is met)
• New York's six-year medical record retention requirement runs from the date of service — applying the most conservative interpretation, from the bereavement case close date of February 2025
• Retention obligation: the bereavement record must be maintained until February 2031 — more than seven years after the patient's death
Most hospice compliance programmes that have a bereavement data retention policy at all calculate retention from the patient's death date rather than the bereavement case close date. The difference — 13 months of additional retention in this example — is compounded across every bereavement case the programme manages. The correct calculation requires working from the bereavement case close date and applying the applicable state medical record retention period from that date.
Access Controls for Bereavement Records
The Minimum Necessary Standard Applied to Bereavement
Bereavement records should be subject to a defined access profile that limits visibility to the bereavement programme team and clinical supervisors with direct oversight responsibility. The default EHR access configuration that grants the full clinical care team access to all records associated with a patient's hospice episode should explicitly exclude bereavement records from that default access — or alternatively, the bereavement records should be maintained in a separate system or folder structure with its own access controls rather than in the main clinical record.
Clinical staff who provided direct care during the active hospice episode have no ongoing need to access bereavement records after the patient's death unless they have a specific role in the bereavement programme. The nurse who provided weekly visits during the patient's final month has a clinical relationship with the patient's family but not a bereavement programme role — her access to the bereavement coordinator's grief assessments of those family members is not necessary for any current clinical function and should not be provided by default.
Mental Health Referral Documentation: Enhanced Access Restriction
Mental health referral documentation in the bereavement record warrants enhanced access restriction beyond the standard bereavement programme access profile. Many states provide heightened privacy protections for mental health records beyond standard HIPAA protections — including restrictions on disclosure that apply even within the treating organisation. A family member referred to mental health services through the bereavement programme has an enhanced privacy expectation for that referral documentation that the bereavement coordinator's general assessment notes do not carry.
Configure the bereavement record system to maintain mental health referral documentation in a restricted sub-category with access limited to the bereavement coordinator who made the referral, the director of the bereavement programme, and the clinical supervisor with oversight responsibility. Other bereavement staff supporting the family should not have default access to the mental health referral documentation — they should access it only through a documented clinical need request that the programme director authorises.
Volunteer Access in the Bereavement Programme: A Different Model Than Clinical Volunteers
Hospice bereavement programmes use trained volunteers differently than clinical programmes use volunteers. Clinical volunteers typically follow a structured visit schedule — weekly visits during the active care episode — with clear start and end points. Bereavement volunteers typically maintain a less structured, longer-term relationship with specific families — phone check-ins, anniversary acknowledgements, grief support group facilitation — that may extend over the full 13-month bereavement service period and potentially beyond if the family relationship continues informally.
This different engagement model creates a different access provisioning challenge. A clinical volunteer whose access is provisioned at programme enrollment and terminated when the scheduled visits end has a clean access lifecycle. A bereavement volunteer who may have intermittent contact with a family over 13 or more months has a longer and less predictable access lifecycle that requires specific management.
The Bereavement Volunteer Access Protocol
• Access provisioning: bereavement volunteers who access any family information through the hospice's systems — including simply looking up a family member's phone number in the bereavement platform — must be provisioned with individual credentials before any system access occurs. No shared accounts, no coordinator-mediated lookups that allow the volunteer access through the coordinator's credentials.
• Access scope: bereavement volunteer access should be limited to the specific family contact information necessary for the volunteer's assigned support role. A volunteer facilitating a grief support group needs access to participant contact information. They do not need access to individual bereavement assessment scores or mental health referral documentation for group participants.
• Access review frequency: because bereavement volunteer engagement may be intermittent, access reviews for bereavement volunteers should occur quarterly rather than annually — confirming that each volunteer with active system access is currently engaged in an active bereavement support relationship that justifies continued access.
• Access termination: bereavement volunteer accounts must be deactivated when the volunteer leaves the programme. Unlike clinical volunteer deactivation — which can be tied to the end of a scheduled visit cycle — bereavement volunteer departure may occur at any time during an active family support relationship. The deactivation protocol must be initiated immediately when a bereavement volunteer notifies the programme of their departure, regardless of whether active family relationships are ongoing.
• HIPAA training documentation: bereavement volunteers must complete the same HIPAA privacy and security training as clinical volunteers, with individual completion records maintained for the six-year HIPAA documentation retention period. The training content should specifically address bereavement-context privacy obligations — the sensitivity of grief assessment information, the enhanced privacy expectations around mental health referrals, and the confidentiality standards that apply to family information shared in bereavement support conversations.
The Bereavement Programme Compliance Documentation Set
The bereavement programme requires its own set of HIPAA compliance documentation distinct from — though consistent with — the clinical programme documentation. Maintaining this documentation ensures that when an OCR audit or a CoP survey examines the bereavement programme specifically, the compliance infrastructure is documented and producible:
• Bereavement data retention policy: the specific retention calculation applied to bereavement records, the triggering event (bereavement case close date), the applicable state law, and the resulting retention period — documented explicitly so that future compliance staff can apply the calculation consistently
• Bereavement volunteer access policy: the access provisioning, scope, review frequency, and termination protocol for bereavement volunteers, distinct from the clinical volunteer access policy
• Mental health referral documentation access policy: the enhanced access restriction applied to mental health referral documentation in the bereavement record, with the authorisation process for access beyond the standard bereavement programme access profile
• Bereavement HIPAA training records: individual completion records for all bereavement staff and volunteers, maintained separately from clinical programme training records to allow bereavement-specific compliance verification
• Bereavement programme privacy notice: confirmation that families are provided with information about how their data will be used during the bereavement programme period — the privacy notice that the clinical programme provides at admission may not adequately describe the bereavement programme data practices if it was written without the bereavement programme in mind
ShieldForce builds the bereavement programme security framework — access controls, volunteer provisioning protocol, mental health referral documentation restrictions, and retention policy with the complete retention calculation — as a standard component of every hospice managed service engagement. The bereavement programme is not an afterthought in our hospice compliance approach. It is a distinct compliance area with its own documentation set and its own access control architecture. Start with a free assessment.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

