Inventory documents by purpose and entity

List every policy, notice, consent and authorization visible on the site or sent during intake. Record the issuing entity, audience, purpose, location, version, effective date and owner. Include the checkout, portal, email and mobile experience. A footer link may cover public browsing while a separate clinical process needs its own document. Copying a competitor's policy cannot establish that it describes your entities, vendors or data use.

This guide is an educational inventory framework, not a complete statement of legal requirements. Counsel should determine which documents and permissions apply to your business and target jurisdictions. Clinical leadership should approve care-related explanations and workflows. A checkbox is an implementation detail, not evidence that every underlying obligation has been addressed.

Distinguish a privacy policy from a HIPAA notice

A public privacy policy explains the relevant website or business practices. A HIPAA Notice of Privacy Practices has a defined role for covered entities subject to that requirement. HHS guidance addresses the notice's content, effective date, availability and delivery. Have counsel identify the responsible entity and process instead of renaming a general website policy as a HIPAA notice.

Use the health data flow map to check whether statements match the implementation. If the policy says information is not shared with advertisers, inspect the configured tracking and integrations. If a notice names a privacy contact, verify that the inbox reaches an authorized person who knows the response process. A published promise should connect to an operating procedure.

Source context: HHS: Notice of Privacy Practices for Protected Health Information

Give telehealth consent a clinical workflow

HHS explains that specific telehealth informed-consent laws vary by state and recommends legal review of medical and intake forms. Ask clinical and legal leads to identify when consent must occur, the required content, the method of documentation and how changes are handled. Avoid assuming that agreement to website terms is the same as informed consent for care.

Test the workflow with a new patient, a returning patient facing a revised document and a patient who cannot complete the default digital path. Decide who explains the process and where questions are escalated. Keep the version and evidence required by the reviewed process accessible to the appropriate entity. Support should help people navigate the system without answering clinical-consent questions beyond its approved role.

Source context: HHS: Obtaining Informed Consent

Make billing and marketing choices understandable

Inventory price disclosures, recurring charges if offered, refund and cancellation explanations, and the relationship between payment and clinical review. Ask counsel to assess applicable consumer-protection and subscription requirements. The operations team should then verify that receipts, account settings and support responses match the reviewed offer. Explain the relevant process before a patient commits rather than leaving material terms to a later conversation.

Keep marketing permissions separate in the inventory from care-related documents. Define the purpose of each permission, the communication channels and how a withdrawal is processed. FTC health advertising guidance focuses on accurate express and implied claims. Review the full page, including checkout language, so policy text does not conflict with a prominent promise. Pair this with the advertising review checklist.

Source context: FTC: Health Products Compliance Guidance

Test versions, records and exceptions

For every document, record who can edit it, who approves changes and who releases them. Preserve the prior version and a change log. Decide when a change needs renewed acknowledgement, consent or authorization with counsel and clinical leadership. Confirm that every location shows the intended version and that records identify the document presented when required by the reviewed process.

Walk through a privacy question, missing consent record, broken policy link and disputed cancellation. The assigned owner should find the governing version and route the issue without guessing. Connect this inventory to the responsibility matrix. A policy owner is responsible for maintenance, implementation and exceptions, not merely for keeping a document in a shared folder.

Policy and consent ownership register

Confirm legal applicability before implementation. For each applicable item, add its issuing entity, approved version, presentation trigger, evidence and exception owner.

On small screens, scroll the table sideways to view every column.

Policy and consent ownership register
Item to assessPurposeOwner to confirmWorkflow evidence
Website privacy policyDescribe applicable browsing and business data practicesBrand privacy and legal leadsPublished version matches configured data flows
HIPAA Notice of Privacy PracticesExplain covered entity practices and rights where requiredResponsible covered entityReviewed delivery and acknowledgement process
Telehealth informed consentExplain and document consent for the care processClinical organization with counselRequired version and clinical documentation
Billing and service termsExplain charges, service process and relevant optionsCommercial owner with counselCheckout, receipt and support consistency
Marketing permissionDocument reviewed communication choicesMarketing and privacy leadsPermission purpose and withdrawal handling
Download this worksheet as CSV

Before you move forward

  • Identify the entity and purpose of every document.
  • Review legal applicability and clinical content.
  • Check published promises against configured workflows.
  • Preserve approved versions and required records.
  • Test exceptions with the assigned response owners.

Sources and scope

Source check: October 10, 2026. Primary sources support the rules and vendor descriptions cited above. Worksheets are original planning tools, not provider commitments or forecasts. Requirements can change; confirm current terms for your program.

  1. HHS: Notice of Privacy Practices for Protected Health Information

    Supports the purpose, content, delivery and effective-date requirements of applicable HIPAA notices. Checked October 10, 2026.

  2. FTC: Health Products Compliance Guidance

    Supports review of express and implied claims and the overall impression of health marketing. Checked October 10, 2026.