Card-on-file: consent, security, and the fine print
Summary
Yes: no federal law bans keeping a card on file, and most states allow it under ordinary contract law. What makes it legal is documented, explicit patient consent naming what can be charged and when. What makes it wise is separate — tokenizing the card through your payment processor instead of storing numbers yourself, disclosing charges clearly, and keeping the authorization itself as a retained record.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Is card-on-file legal?
No federal statute bans a practice from keeping a patient's card on file, and most state contract law treats it the same as any other stored authorization to charge — the legality question isn't really "can I," it's "did I get the consent right." What turns a stored card into a legal charge, rather than an unauthorized one, is a documented authorization the patient actually agreed to, naming what can be charged and under what conditions.
Where practices run into trouble isn't the storage itself; it's charging the card for something the authorization didn't cover — a balance the patient never approved, an amount that changed after insurance adjudicated, or a fee added after the fact. The card being "on file" doesn't expand what you're allowed to charge it for, and treating it as blanket permission is the single most common way a legal tool turns into a disputed one.
The consent that makes it legal
A card-on-file authorization that holds up is specific, not a blanket permission slip: it names the estimated range of what might be charged, the categories of charge it covers (copay, coinsurance, no-show fee, remaining patient responsibility after adjudication), and how the patient can revoke or update it. A signature on a form that just says "I authorize charges to this card" is thinner protection than one that spells out what those charges are for.
This dovetails with the good-faith-estimate obligation the No Surprises Act already puts on you for uninsured and self-pay patients 1Ref 1Centers for Medicare & Medicaid Services (2026).No Surprise Billing.That the No Surprises Act requires good-faith estimates for uninsured/self-pay patients and creates the patient-provider dispute-resolution process a card-on-file overcharge can trigger2Ref 2Office of the Federal Register (2026).45 CFR Part 149 — Surprise Billing and Transparency Requirements.The operative regulation text for the NSA's good-faith-estimate content/timing requirements and the patient-provider dispute process: if the card gets charged for materially more than the estimate you gave, the patient can invoke the same patient-provider dispute process that governs any other estimate overshoot, regardless of whether the payment method was a stored card or an invoice 1Ref 1Centers for Medicare & Medicaid Services (2026).No Surprise Billing.That the No Surprises Act requires good-faith estimates for uninsured/self-pay patients and creates the patient-provider dispute-resolution process a card-on-file overcharge can trigger2Ref 2Office of the Federal Register (2026).45 CFR Part 149 — Surprise Billing and Transparency Requirements.The operative regulation text for the NSA's good-faith-estimate content/timing requirements and the patient-provider dispute process. Writing the card-on-file authorization to track your estimate language, rather than as a separate blanket form, keeps the two consistent instead of contradicting each other.
The security side: PCI, tokenization, and what not to store
Card networks require anyone storing card data to meet PCI DSS security standards, and almost no solo practice wants to be the one storing raw numbers — the compliance burden is real, while your payment processor's card processing agreement typically includes a tokenization service built for exactly this. When a processor tokenizes a card, your system keeps a reference token, not the actual number, so a breach of your own systems doesn't expose payment data at all.
Ask any processor you're evaluating whether card-on-file tokens live in their vault or get passed to you in raw form — the answer determines whether card-on-file adds meaningful compliance weight to your practice or stays entirely on the vendor's side of the line. The same discipline applies whether the stored card is an ordinary credit card or one of the hsa/fsa cards a patient might use — the storage and tokenization rules don't change based on which account funds the charge.
Treat the record like any other patient record
Treat the signed authorization and the transaction log the same way you'd treat any other patient record — subject to a defined retention period and disposed of deliberately rather than left to accumulate indefinitely. Professional record-keeping guidance frames retention as a deliberate policy choice with security and disposition planning built in, not an afterthought, always deferring to whatever your state's own retention rule requires on top of that baseline 3Ref 3American Psychological Association (2007).Record Keeping Guidelines.That retention of records — including payment authorizations — should follow a deliberate policy with security and disposition planning, deferring to state law.
A card-on-file authorization that outlives its usefulness — the patient stopped treatment two years ago — is stored risk with no corresponding benefit. Building an expiration or periodic-reconfirmation step into your policy keeps the file from quietly turning into a liability nobody remembers to clean up, and it gives you a natural point to re-verify the card is still valid rather than discovering that at the worst moment.
When card-on-file crosses into a collections problem
Charging a card on file per a signed authorization is first-party billing, not debt collection, and that distinction matters for which rules apply. The Fair Debt Collection Practices Act governs third-party debt collectors — an outside agency working a balance on your behalf — not a practice charging its own patient's card for its own bill 4Ref 4Federal Trade Commission (2026).Fair Debt Collection Practices Act.That the FDCPA governs third-party debt collectors, not a practice's own first-party card-on-file billing of its own patient. That doesn't make a mischarged charge consequence-free, though.
An unauthorized or disputed card-on-file charge can still trigger chargebacks through the card network's own process, reversing the payment and adding a fee regardless of who's technically right, and enough of them can put your merchant account itself at risk with your processor. The practical takeaway: card-on-file authorization discipline is what keeps a convenience tool from turning into a collections-adjacent problem, not a legal technicality you can skip because a signature exists somewhere in the chart.
Is it wise? The tradeoffs
Whether keeping a card on file is wise is a separate question from whether it's legal, and the tradeoffs run in both directions. It shortens the time between a patient's explanation of benefits landing and the balance actually getting paid, and it removes a step from your own collections workflow — no statement to mail, no phone call to make, for a charge the patient already agreed to.
The cost side is trust and dispute risk: a patient who sees an unexpected charge on a stored card, even a correct one, tends to experience it differently than a bill they had time to review, and unclear authorization language is what turns a correct charge into a complaint. The practices that get the most value from card-on-file are the ones that over-invest in the authorization language and under-invest in surprising the patient — a text or email notice before each charge costs almost nothing and removes most of the friction.
What a card-on-file policy should say
A card-on-file policy worth keeping is short enough to actually follow and specific enough to hold up if a charge is ever disputed later. At minimum, it should cover five concrete things, in writing, before you ever store a patient's first card.
- What triggers a charge — no-show fee, copay at check-in, remaining balance after the EOB posts — named individually, not as a single catch-all category.
- How the patient is notified before each charge, even a small or routine one, and through what channel.
- How the patient revokes or updates the authorization, and how quickly that request takes effect.
- Where the card data actually lives — your processor's vault, never a spreadsheet, a sticky note, or your EHR's free-text field.
- How long the signed authorization and transaction log are retained, and when they're disposed of.
Put this in the same intake packet as your financial policy, not a separate form patients sign without reading — the two are describing the same relationship from different angles.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Centers for Medicare & Medicaid Services (2026). No Surprise Billing. Centers for Medicare & Medicaid Services (CMS). link ✓That the No Surprises Act requires good-faith estimates for uninsured/self-pay patients and creates the patient-provider dispute-resolution process a card-on-file overcharge can trigger
- 2.Office of the Federal Register (2026). 45 CFR Part 149 — Surprise Billing and Transparency Requirements. eCFR. link ✓The operative regulation text for the NSA's good-faith-estimate content/timing requirements and the patient-provider dispute process
- 3.American Psychological Association (2007). Record Keeping Guidelines. American Psychological Association. link ✓That retention of records — including payment authorizations — should follow a deliberate policy with security and disposition planning, deferring to state law
- 4.Federal Trade Commission (2026). Fair Debt Collection Practices Act. Federal Trade Commission (FTC). link ✓That the FDCPA governs third-party debt collectors, not a practice's own first-party card-on-file billing of its own patient
https://www.gale.care/for-providers/pp-card-on-file-legal · 4 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.