
Consent documented at intake prevents disputes later. What to capture and how — as a starting template, not legal advice.
When "we never agreed to that" shows up at week three
A coordinator picks up the phone on a Tuesday afternoon and it's a client's son, furious. The agency told his sister about their mother's medication change over the weekend — and he's the one who signed the service agreement, pays the invoice, and expected to be the first call, not the last to find out. The coordinator pulls the intake folder. There's a signed service agreement. There's an emergency contact list. There is nothing that says, in writing, who is authorized to receive updates about this client and under what circumstances. Just a verbal "sure, keep the family posted" from three weeks earlier, and nobody remembers exactly who said it.
That gap is a consent gap, not a service-agreement gap, and agencies routinely conflate the two. This piece breaks down what a home care consent and authorization form actually needs to capture, how it differs from the agreement that governs services and billing, and how to build one you hand to every new client without rebuilding it from scratch each time.
Consent and authorization aren't the service agreement
A home care service agreement covers what is being delivered: scope of care, hours, rates, cancellation terms, liability language. It's a contract. A consent and authorization form covers something different: who can know what, who can act on the client's behalf, and what the client has explicitly agreed to allow. It's a permission record, not a payment record.
Agencies that fold both into one long document often lose the permission details in the fine print — which is exactly where they get contested later, because nobody remembers signing it, let alone what it said. Separating the two documents at intake makes each one easier to update independently: rates change, permissions rarely do, and when they do, you want a form you can re-sign in five minutes rather than a whole contract you have to redraft.
What a consent and authorization form should actually capture
At minimum, a clean form documents:
- Consent to receive services — the client (or their legal decision-maker) explicitly agrees to the agency providing non-medical home care services as described in the accompanying agreement.
- Authorized contacts and their permission level — not just an emergency contact list, but who is allowed to receive routine updates, who is allowed to receive changes to the plan, and who is allowed to make decisions on the client's behalf if those aren't the same person. This is the section that would have saved the coordinator's Tuesday afternoon.
- Authorization to share information with named individuals — spelled out by name, not by relationship. "Daughter" is not specific enough when there are two daughters and only one is authorized to hear about medication changes.
- Authorization to contact medical providers — whether the agency may call a physician's office, pharmacy, or home health nurse to coordinate care, and for what purpose.
- Power of attorney or legal decision-maker documentation — if someone other than the client is signing, the form should reference the legal instrument (POA, guardianship) that gives them authority, and the agency should keep a copy on file.
- Photo, video, or testimonial consent, if the agency ever uses client stories in marketing — this is easy to forget and awkward to ask for retroactively.
- Consent to the specific services being authorized, particularly anything sensitive: personal care tasks, medication reminders, transportation.
That medication line deserves its own caveat: consent to reminders is not consent to administration, and a form (like a plan) should never blur the two. A home care consent form documents that the family or client has agreed to reminder-and-organization support — not that anyone is authorizing clinical medication management, which is outside the scope of non-medical home care in the first place.
The family-sharing question, and why it isn't a HIPAA question for most agencies
A common instinct is to reach for HIPAA language when drafting the information-sharing section, because "sharing client information with family" sounds like a HIPAA topic. For most non-medical private-pay home care agencies, it usually isn't — HIPAA's Business Associate framework applies where a covered entity (a healthcare provider, health plan, or clearinghouse) shares protected health information with a vendor performing services on its behalf, and that relationship is defined at 45 CFR § 160.103. A private-pay home care agency contracting directly with a client, rather than with a hospital or health plan, is frequently outside that specific framework — but "frequently" is not "always," and the answer depends on how the agency is structured and who it contracts with.
What doesn't depend on that is good practice: whether or not HIPAA technically applies, a client's information should only go to the people the client authorized, and that authorization should be in writing, dated, and specific by name. State licensing requirements for home care agencies typically expect exactly this kind of documented consent regardless of HIPAA's applicability, so building the habit is worth it even where the federal framework doesn't directly reach.
This is also the exact reason a zero-PHI architecture matters for how consent gets acted on day to day, not just documented at intake. When a plan is shared with an authorized family member through a token-authenticated, expiry-configurable read-only link rather than a shared login or an emailed document, the sharing itself follows the permission on file — the coordinator sets who gets a link and for how long, instead of relying on memory about who said what during intake three weeks ago. That's an architecture fact about how the sharing mechanism works, not legal advice about whether a given disclosure is permitted; agencies should still confirm their own obligations with their state licensing body and, where relevant, legal counsel.
A signature on a consent form is only as useful as the form's specificity — "family" is not a name, and "keep them posted" is not a permission level.
Building the form once, using it every time
The form works best as a fixed template with a few variable fields per client: names of authorized contacts, their permission level, medical providers to contact, and any special authorizations (photo consent, POA reference). Trying to draft this from scratch per client is where agencies either skip sections under time pressure or end up with inconsistent language across their client base — which becomes its own problem if a licensing reviewer ever compares files side by side.
A dated, signed version of this form belongs in the same intake record as the service agreement and the initial assessment, and it should be revisited whenever authorized contacts change — a new spouse, an adult child taking over decision-making, a falling-out that revokes someone's access. Treating consent as a one-time signature at intake, rather than a living record, is how agencies end up back at that Tuesday-afternoon phone call.
Where to start
If intake currently means retyping the same permission language client by client, a structured starting point removes the redraft-from-scratch problem: the client intake form walks through what belongs in the intake record overall, the service agreement template covers the contractual half, and the new client onboarding checklist sequences all of it — consent included — into a repeatable process. For agencies building out a full plan structure around intake, the complete guide to the home care plan is the wider frame this fits into.
None of this is legal advice, and it isn't meant to substitute for review by counsel or confirmation with a state licensing authority — it's a drafting starting point, built to be adapted rather than used verbatim. The Client Intake & Onboarding Kit bundles a consent and authorization template alongside the intake form and service agreement, so the whole intake stack starts from one consistent set of documents instead of three drafted at three different times.
Ready to go beyond the guide?
Put these frameworks to work — start a free trial, size up the savings, or grab a done-for-you template.
Get the next guide in your inbox
New ADL/IADL frameworks and documentation tips, published weekly.
Related articles
What a Home Care Service Agreement Should Cover
A service agreement sets expectations and protects both sides. The essentials it should cover — as a starting point, not legal advice.
A New Client Onboarding Checklist for Home Care
Onboarding is where promises become care. A checklist that takes a new client from signed agreement to first shift.
Home Care Intake Process Best Practices
A smooth intake wins the client and starts the file clean. The best practices that make both happen.


