Access to a patient’s medical records after death involves issues related to professional confidentiality, privacy, family members’ rights, and the responsibilities of the institutions that retain and safeguard these documents.
Hospitals, clinics, laboratories, and healthcare professionals should not treat such requests as ordinary administrative matters. Medical records may contain diagnoses, treatments, test results, genetic information, clinical conditions, and records concerning other individuals.
For this reason, both the disclosure and the denial of access should be properly justified and documented.
Can medical records be provided to family members?
Recommendation No. 3/2014 issued by the Federal Council of Medicine (CFM) provides guidance for physicians and healthcare institutions to make a deceased patient’s medical records available when requested by the surviving spouse or partner.
If the spouse or partner is absent or unable to make the request, it may subsequently be submitted by legal heirs in the direct line of succession or by collateral relatives up to the fourth degree.
For disclosure, the guidance establishes two key requirements:
- Documentary evidence of the family relationship;
- Compliance with the applicable order of succession.
This means that merely identifying oneself as a family member is not sufficient. The institution must determine the applicant’s position in the order of succession and verify the documentation submitted.
Any express statement made by the patient during their lifetime opposing the disclosure of their medical records after death must also be taken into consideration.
Is access automatic?
A request submitted by a family member should not automatically result in the immediate disclosure of the records.
The institution must verify the applicant’s identity, the alleged family relationship, whether there are other family members with priority under the order of succession, and the scope of the documents requested.
Certain circumstances may require additional caution, including:
- Conflicts among family members;
- Questions regarding the existence of a domestic partnership;
- Disputes among heirs;
- Requests submitted by representatives or attorneys-in-fact;
- Requests involving only part of the medical record;
- Information concerning third parties;
- The existence of an express objection made by the patient;
- Medical records related to ethical or disciplinary proceedings;
- Court orders establishing specific conditions.
Where material uncertainties exist, the institution should submit the request for legal review before granting or denying access.
Is the LGPD sufficient to resolve the issue?
Medical records contain health-related information, which is classified as sensitive personal data under Brazil’s General Data Protection Law (Lei Geral de Proteção de Dados – LGPD).
However, in cases involving deceased patients, the legal analysis should not be limited exclusively to the LGPD.
Other relevant considerations include the duty of medical confidentiality, professional ethical standards, family members’ rights, civil and succession law, rules governing the retention of medical records, and court decisions applicable to the specific case.
The protection of information does not automatically cease upon the patient’s death. At the same time, confidentiality should not be interpreted in isolation, without taking into account the legitimate rights of successors and the guidance established by professional regulatory bodies.
What are the risks for healthcare institutions?
The absence of an internal procedure may lead to inconsistent decisions. Similar requests may receive different responses, increasing both legal and reputational risks.
Improper disclosure may result in:
- Breach of confidentiality obligations;
- Exposure of sensitive clinical information;
- Disclosure of information concerning third parties;
- Proceedings or inquiries before professional regulatory councils;
- Claims for damages;
- Harm to the relationship of trust with patients and their families.
An improperly justified denial may also have consequences, including administrative complaints, legal proceedings, and potential liability arising from the obstruction of legitimate rights.
How should an internal procedure be structured?
Healthcare institutions should establish a formal policy for receiving and reviewing requests for the medical records of deceased patients.
The procedure may include:
- Formal submission of the request
The request should be submitted in writing and identify the applicant, the patient, and the specific documents requested. - Verification of the relationship
Documents demonstrating the applicant’s status as spouse, partner, or successor should be required. - Verification of the order of succession
The institution should determine whether there are individuals with priority to submit the request. - Review of the patient’s records
It is necessary to verify whether the patient made any express statement opposing disclosure of their medical records after death. - Review of the content
The medical record may contain information concerning third parties or records that require specific treatment before disclosure. - Legal review
Unusual requests, insufficient documentation, family disputes, and questions regarding the applicant’s legal standing should be referred to the legal department. - Documentation of the decision
The institution should retain a record of the request, the documents received, the analysis performed, and the response provided.
Governance reduces risks and improves decision-making
Establishing a standardized process does not prevent an individualized assessment. On the contrary, it enables the specific circumstances of each request to be evaluated according to clear and traceable criteria.
Coordination among legal, compliance, data protection, medical management, and records management teams contributes to safer and more consistent decision-making.
PDK Advogados advises on matters involving Healthcare Law, medical confidentiality, the protection of sensitive information, and the development of internal governance and risk management policies.