The forms binder: consent, financial policy, cancellation, telehealth
Summary
Before the first patient, a solo practice needs five documents ready to sign: informed consent for treatment, a financial policy covering fees and cancellation terms, a telehealth consent where sessions happen by video, a release-of-information form, and a written information-security policy backed by a documented risk analysis. A gap in any one is the first thing a board complaint, a subpoena, or an auditor asks to see.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
The core documents to have ready before day one
A solo practice needs a working set of documents signed and filed before the first session, not assembled reactively after a gap becomes obvious in the room. Five cover the ground that matters most: informed consent for treatment, a financial policy, a telehealth consent where sessions happen by video, a release-of-information template, and a written information-security policy tied to an actual risk analysis.
- Informed consent for treatment — what the service involves, confidentiality and its limits, fees, and the right to stop
- Financial policy — the fee schedule, payment timing, and the cancellation terms a patient agrees to before scheduling
- Telehealth consent — technology risks, location verification, and the plan for an emergency when the visit isn't in person
- Release of information — the form gating any disclosure to another provider, a school, an attorney, or a marketing use of a patient's words
- Written security policy and risk analysis — the practice's own documented safeguards for protected health information, not a template copied and left unread
Each earns its place in the binder because a gap in any one of them is the first thing a licensing board, a subpoenaing attorney, or a payer audit asks to see.
Informed consent for treatment
Informed consent documents what a patient agreed to before treatment began: the nature and purpose of the service, confidentiality and its exceptions (mandatory reporting, danger to self or others, a court order), the fee arrangement, and the right to withdraw consent at any point. A signed consent form is also, functionally, the first document a malpractice inquiry or a board complaint asks a solo clinician to produce.
A professional association's own practice-management guidance is a reasonable place to check a consent form against current norms before finalizing it, since the elements expected in a solid consent form shift slightly by discipline and setting 1Ref 1APA Services, Inc. (2026).Practice — APA Services.That a professional practice organization publishes practice-management guidance clinicians can check consent-form norms against.. The form belongs in the binder as a living document, revisited whenever the practice adds a service line — group work, testing, telehealth — that the original consent didn't anticipate.
The financial policy patients sign
The financial policy patients sign is a separate document from informed consent, and conflating the two is a common first-year mistake: consent covers the clinical relationship, the financial policy covers the money. It should state the fee schedule, when payment is due, what happens on a missed or late payment, and the cancellation-notice window and any associated charge.
For patients with insurance, the financial policy is also where a practice sets expectations honestly: coverage particulars, prior authorization, and timely-filing rules belong to the patient's specific plan, not to a general table the practice can promise in advance. A payer's own provider portal — Anthem's, for one example — publishes its coverage and reimbursement policies directly, and pointing a patient there (or to their own plan documents) is more accurate than a practice trying to summarize what "insurance normally covers" 2Ref 2Anthem (2026).Anthem Provider Policies.Anthem's own published provider policies, used as one named example of a payer publishing coverage/reimbursement terms directly — never presented as what all payers do.. The rule to write into the policy itself: the patient's contract controls, not a house rule of thumb.
A common convention is to require cancellation notice measured in business hours rather than calendar days, with a stated fee for a missed appointment — the exact window and amount are a practice-level choice, not a regulatory one, and should be set deliberately rather than copied from a colleague's form without adjustment.
Telehealth consent and verifying where the patient actually is
A telehealth consent covers ground the in-person consent doesn't: the technology being used, its privacy and connectivity limits, what happens if the connection drops mid-session, and — critically — that the patient's physical location will be verified at every visit, not assumed to be constant. Location matters because licensure is jurisdiction-specific: a patient who logs in from a different state than expected may put the visit outside where the clinician is authorized to practice.
A multistate license compact can extend that authorization further than a single state license alone — the Counseling Compact grants a practice privilege, including telehealth, in other member states for licensed professional counselors 3Ref 3Counseling Compact Commission (2026).Counseling Compact.That the Counseling Compact grants licensed professional counselors a practice privilege, including telehealth, in member states., and the Social Work Licensure Compact does the same for eligible social workers as states enact it 4Ref 4Social Work Licensure Compact (2026).Social Work Licensure Compact.That the Social Work Licensure Compact creates multistate practice privileges for eligible social workers as states enact and implement it. — but the consent form and the intake process both need to actually check the patient's location against what the clinician's license or compact privilege covers, rather than treating telehealth as automatically portable everywhere.
The telehealth consent should also state plainly which services will actually be delivered by video versus require an in-person visit, since payers maintain their own lists of which codes are payable as telehealth at all 5Ref 5Centers for Medicare & Medicaid Services (2026).List of Telehealth Services.That CMS publishes the definitive list of codes payable as Medicare telehealth, supporting the claim that telehealth consent should match which services are actually billable as telehealth. — a mismatch there is a billing problem, not just a consent-form technicality.
Cancellation and no-show policy
A cancellation policy is a practice norm, not a statute, and it belongs in writing precisely because an unwritten one is unenforceable the first time a patient disputes a charge. State the notice window in the financial policy itself rather than as a separate document, since patients sign one packet and a scattered policy across multiple forms is the version that gets skipped.
A common structure: a defined notice window before the fee applies, a clear statement of what the fee is and how it's charged (card on file versus invoice), and an explicit carve-out for the practice's own judgment on emergencies. None of this needs a citation to be legitimate — it needs to be consistent, disclosed before the first session, and applied the same way to every patient, which is what protects the practice if the policy is ever challenged.
Release of information and marketing consent
A release-of-information form is what lets a practice send records to another treating provider, a school, an attorney, or an insurance reviewer — and it should specify what's being released, to whom, for what purpose, and for how long the authorization stands. A blanket, undated release is the version that causes trouble later, when it's unclear whether it still applies.
A separate authorization is required before using a patient's words or image for marketing — a testimonial, a before-and-after post, a website quote — because HIPAA treats that use of protected health information as marketing distinct from treatment, with only narrow exceptions, and requires the patient's specific authorization first 6Ref 6HHS Office for Civil Rights (2026).Marketing.That HIPAA requires authorization before using PHI for marketing, with narrow exceptions, distinct from general treatment consent.. Folding a marketing-consent checkbox into the general release, rather than treating it as implied by the release itself, keeps the practice from later having to prove a patient meant something the form didn't actually say.
The written security policy behind the binder
The Security Rule requires administrative, physical, and technical safeguards for protected health information, scaled to the size of the practice — but scaled down still means a written policy has to exist, not just good habits that live in the clinician's head 7Ref 7HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size but not optional.. A one-person practice's policy can be short: who has access to records, how a lost laptop or phone is handled, how backups happen, and who to call first if something goes wrong.
The fastest way to write a real policy instead of a placeholder is to start from the free risk-assessment tool built for practices this size, since it walks through the same categories a Security Rule review would check and produces the documentation to show for it 8Ref 8Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR publish a free risk-assessment tool sized for small practices, supporting the how-to for producing the documented risk analysis behind the security policy.. Filing the completed assessment alongside the binder — not just the policy itself — is what turns "we have a policy" into something that survives a real audit.
Building this binder is also the moment to line up the intake flow around it, so a new patient signs everything in one sitting rather than trickling forms in over several visits, and to note who at the practice is responsible for updating each document as rules or vendors change — even at a one-person practice, that's worth writing down before the first hire makes it someone else's job too.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.APA Services, Inc. (2026). Practice — APA Services. APA Services, Inc. (APA Practice Organization). linkThat a professional practice organization publishes practice-management guidance clinicians can check consent-form norms against.
- 2.Anthem (2026). Anthem Provider Policies. Anthem provider portal. link ✓Anthem's own published provider policies, used as one named example of a payer publishing coverage/reimbursement terms directly — never presented as what all payers do.
- 3.Counseling Compact Commission (2026). Counseling Compact. Counseling Compact Commission. link ✓That the Counseling Compact grants licensed professional counselors a practice privilege, including telehealth, in member states.
- 4.Social Work Licensure Compact (2026). Social Work Licensure Compact. Social Work Licensure Compact. link ✓That the Social Work Licensure Compact creates multistate practice privileges for eligible social workers as states enact and implement it.
- 5.Centers for Medicare & Medicaid Services (2026). List of Telehealth Services. Centers for Medicare & Medicaid Services (CMS). link ✓That CMS publishes the definitive list of codes payable as Medicare telehealth, supporting the claim that telehealth consent should match which services are actually billable as telehealth.
- 6.HHS Office for Civil Rights (2026). Marketing. U.S. Department of Health and Human Services. linkThat HIPAA requires authorization before using PHI for marketing, with narrow exceptions, distinct from general treatment consent.
- 7.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to practice size but not optional.
- 8.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR publish a free risk-assessment tool sized for small practices, supporting the how-to for producing the documented risk analysis behind the security policy.
https://www.gale.care/for-providers/ln-policies-forms-set · 8 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.