Guide

Card-on-file: consent, security, and the fine print

Summary

Yes: no federal law bans keeping a card on file, and most states allow it under ordinary contract law. What makes it legal is documented, explicit patient consent naming what can be charged and when. What makes it wise is separate — tokenizing the card through your payment processor instead of storing numbers yourself, disclosing charges clearly, and keeping the authorization itself as a retained record.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

The security side: PCI, tokenization, and what not to store

Card networks require anyone storing card data to meet PCI DSS security standards, and almost no solo practice wants to be the one storing raw numbers — the compliance burden is real, while your payment processor's card processing agreement typically includes a tokenization service built for exactly this. When a processor tokenizes a card, your system keeps a reference token, not the actual number, so a breach of your own systems doesn't expose payment data at all.

Ask any processor you're evaluating whether card-on-file tokens live in their vault or get passed to you in raw form — the answer determines whether card-on-file adds meaningful compliance weight to your practice or stays entirely on the vendor's side of the line. The same discipline applies whether the stored card is an ordinary credit card or one of the hsa/fsa cards a patient might use — the storage and tokenization rules don't change based on which account funds the charge.

Treat the record like any other patient record

Treat the signed authorization and the transaction log the same way you'd treat any other patient record — subject to a defined retention period and disposed of deliberately rather than left to accumulate indefinitely. Professional record-keeping guidance frames retention as a deliberate policy choice with security and disposition planning built in, not an afterthought, always deferring to whatever your state's own retention rule requires on top of that baseline 3.

A card-on-file authorization that outlives its usefulness — the patient stopped treatment two years ago — is stored risk with no corresponding benefit. Building an expiration or periodic-reconfirmation step into your policy keeps the file from quietly turning into a liability nobody remembers to clean up, and it gives you a natural point to re-verify the card is still valid rather than discovering that at the worst moment.

When card-on-file crosses into a collections problem

Charging a card on file per a signed authorization is first-party billing, not debt collection, and that distinction matters for which rules apply. The Fair Debt Collection Practices Act governs third-party debt collectors — an outside agency working a balance on your behalf — not a practice charging its own patient's card for its own bill 4. That doesn't make a mischarged charge consequence-free, though.

An unauthorized or disputed card-on-file charge can still trigger chargebacks through the card network's own process, reversing the payment and adding a fee regardless of who's technically right, and enough of them can put your merchant account itself at risk with your processor. The practical takeaway: card-on-file authorization discipline is what keeps a convenience tool from turning into a collections-adjacent problem, not a legal technicality you can skip because a signature exists somewhere in the chart.

Is it wise? The tradeoffs

Whether keeping a card on file is wise is a separate question from whether it's legal, and the tradeoffs run in both directions. It shortens the time between a patient's explanation of benefits landing and the balance actually getting paid, and it removes a step from your own collections workflow — no statement to mail, no phone call to make, for a charge the patient already agreed to.

The cost side is trust and dispute risk: a patient who sees an unexpected charge on a stored card, even a correct one, tends to experience it differently than a bill they had time to review, and unclear authorization language is what turns a correct charge into a complaint. The practices that get the most value from card-on-file are the ones that over-invest in the authorization language and under-invest in surprising the patient — a text or email notice before each charge costs almost nothing and removes most of the friction.

What a card-on-file policy should say

A card-on-file policy worth keeping is short enough to actually follow and specific enough to hold up if a charge is ever disputed later. At minimum, it should cover five concrete things, in writing, before you ever store a patient's first card.

  • What triggers a charge — no-show fee, copay at check-in, remaining balance after the EOB posts — named individually, not as a single catch-all category.
  • How the patient is notified before each charge, even a small or routine one, and through what channel.
  • How the patient revokes or updates the authorization, and how quickly that request takes effect.
  • Where the card data actually lives — your processor's vault, never a spreadsheet, a sticky note, or your EHR's free-text field.
  • How long the signed authorization and transaction log are retained, and when they're disposed of.

Put this in the same intake packet as your financial policy, not a separate form patients sign without reading — the two are describing the same relationship from different angles.

Common questions

No single federal statute requires a specific card-on-file disclosure form. What you need is documented, specific consent — what can be charged, under what conditions, and how to revoke it — which is a contract and payment-processing question more than a statutory one. Vague blanket authorization language is the actual risk, not the absence of a named law.

You can, but almost no solo practice should. Storing raw card numbers puts your own systems in scope for PCI DSS compliance, a burden built for organizations with dedicated security staff. Tokenizing through your payment processor keeps only a reference token on your side, so a breach of your own systems never exposes actual payment data.

If the charge falls within what the signed authorization actually covers, it's authorized even without a fresh heads-up each time — but that's a legal floor, not good practice. A short notice before each charge, even a routine one, is what keeps a technically-authorized charge from reading to the patient as a surprise.

The charge routes through the card network's chargeback process, which can reverse the payment and add a fee to your merchant account regardless of whether the charge was actually authorized. Your signed, specific authorization form is your primary evidence in that dispute, which is exactly why vague authorization language costs you more than an extra line on the form.

That's a practice-level judgment call, not a legal requirement either way. Practices commonly reserve it for patients with recurring visits or a history of late payment, and offer it as an option rather than a condition of care for everyone else — but nothing in federal law sets that policy for you.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Centers for Medicare & Medicaid Services (2026). No Surprise Billing. Centers for Medicare & Medicaid Services (CMS). linkThat the No Surprises Act requires good-faith estimates for uninsured/self-pay patients and creates the patient-provider dispute-resolution process a card-on-file overcharge can trigger
  2. 2.Office of the Federal Register (2026). 45 CFR Part 149 — Surprise Billing and Transparency Requirements. eCFR. linkThe operative regulation text for the NSA's good-faith-estimate content/timing requirements and the patient-provider dispute process
  3. 3.American Psychological Association (2007). Record Keeping Guidelines. American Psychological Association. linkThat retention of records — including payment authorizations — should follow a deliberate policy with security and disposition planning, deferring to state law
  4. 4.Federal Trade Commission (2026). Fair Debt Collection Practices Act. Federal Trade Commission (FTC). linkThat the FDCPA governs third-party debt collectors, not a practice's own first-party card-on-file billing of its own patient

https://www.gale.care/for-providers/pp-card-on-file-legal · 4 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)