Medical Documentation

First Patient Visit Documents - the Complete Set You Must Collect

Author:

GDPR notice, patient record, procedure consent, authorization and additional consents - the order to collect documents at a first visit, and why combining them into one form is a common mistake.

Aneta has run a physiotherapy practice for three years, and at a new patient's first visit she does what most therapists do -- she pulls out one sheet with an intake interview, adds "consent to therapy" at the bottom, and asks for a signature. The patient signs without reading it, and the therapist starts the treatment. It's only when a KIF inspection shows up and asks about the GDPR information notice, the authorization for the daughter who sometimes collects records on her mother's behalf, and a separate consent for reminder SMS messages, that it turns out one sheet of paper was supposed to serve as five different documents at once. None of them was complete.

This isn't bad intent -- it's a missing system. The first visit is the moment a practice has to collect, within a few minutes, a set of documents with different legal character -- informational, consent-based, authorization-based -- and do it in a specific order, because some of them must precede others. In this article we show which documents to collect at a patient's first visit, in what order to collect them, and why combining them into one form is one of the most common mistakes at small practices.

Why the order of documents matters

From the patient's point of view, the first visit looks like one continuous administrative procedure before the treatment begins. From a legal standpoint, however, it's several separate actions, each with a different legal basis and a different purpose. An information notice is not consent. Consent to a procedure is not an authorization for a close person. Consent to a newsletter is not medical consent. Collecting them together, on one form, in any order, leads to a situation where the practice formally "has a signature" but has no proof that it fulfilled a specific obligation.

That's why the flow below is worth treating as a step-by-step checklist, not a set of documents to sign "along the way."

Step 1: GDPR information notice -- before you collect any data

Before the receptionist asks the patient the first question about their name or phone number, the practice is obliged to inform them who is processing their data, for what purpose, for how long, and what rights they have. This is an obligation of the data controller arising directly from GDPR -- not a request for consent.

The key distinction many therapists confuse: an information notice is not consent and does not require the patient's signature. It's enough that the patient had a real opportunity to read it -- at reception, in a layered format, or on the registration form. Adding a signature line under the notice is a common mistake that only confuses the patient about the nature of the document. We describe the full set of mandatory elements of the notice and how to make it properly available in the article on the GDPR information notice for a physiotherapy practice.

Step 2: Intake interview and patient record -- opening the medical records

Only once the information obligation is fulfilled does the practice actually start collecting data -- and that's where medical records proper begin. The patient record opened at the first visit is the foundation for all further therapy: the interview, functional examination, diagnosis, and a therapy plan with measurable goals.

A common mistake is treating the record as a formality to tick off -- a terse entry like "back pain, massage" with no further detail protects neither the patient nor the therapist in the event of a dispute. We explain how to correctly keep a patient record step by step, along with legal requirements and a template, in the guide on the physiotherapy patient record.

Consent to a procedure is a separate document from the patient record and from the information notice. Without it, the therapist has no formal basis for performing any intervention, and in a dispute it's the records -- not the therapist's memory -- that determine what the patient was told.

For standard techniques (massage, manual therapy, kinesiotherapy) a regular, basic consent is enough -- covered in the article on patient consent to a physiotherapy procedure. Things look different for higher-risk techniques such as dry needling, shockwave therapy, or HVLA techniques -- here a general form is no longer sufficient, and a written, detailed consent describing the risk of the specific procedure is needed. We explain exactly when to use this second variant in the article on extended informed consent.

Step 4: Authorization for a close person -- collected separately, not "along the way"

This is the document that most often gets lost in the rush of a first visit -- and its absence surfaces at the worst possible moment, when a worried family member calls the practice asking about the course of therapy. Without the patient's explicit authorization, the practice has no right to share either health information or access to records -- not even with the closest family member.

An authorization is not a field to add at the bottom of the patient record. It's a separate form that the patient fills out deliberately, naming a specific person and the scope of the authorization (health information, collecting records, or both). We describe a template and the rules for properly collecting such an authorization -- including what happens after the patient's death -- in the article on authorization for a close person to access medical records.

Step 5: Additional consents -- marketing, newsletter, reminder SMS

The last element is consents that have nothing to do with treatment, yet most often end up on the same sheet as medical consent. Consent to send a newsletter, to reminder SMS messages about the next appointment, or to marketing communication has a completely different legal basis than consent to a procedure -- and must be clearly separated from it.

This is one of the most recurring mistakes at small practices: a single "I agree" checkbox at the bottom of the form, implicitly meant to cover the procedure, SMS messages, and the newsletter all at once. Such a construction doesn't meet the requirement of informed, specific consent for each processing purpose separately -- and in a GDPR inspection, it's the first thing that gets challenged.

What the patient must sign, and what they shouldn't

The table below sorts out which documents require the patient's signature and which -- like the information notice -- by definition don't, because they aren't consent.

Document When to collect it Why
GDPR information noticeBefore collecting any dataData controller's information obligation -- does not require a signature
Intake interview and patient recordRight after the notice, at the start of the visitFoundation of medical records and further therapy
Consent to the procedure (basic or extended)Before starting the interventionFormal basis for performing the procedure, proof the patient was informed of the risk
Authorization for a close personSeparately, when the patient wants to authorize someoneWithout it the practice cannot share information or records with family
Additional consents (marketing, SMS, newsletter)Separately from medical consentDifferent legal basis and different data processing purpose

How long this takes in practice

With a well-organized system -- ready templates, a clear order, and one place where all the forms are kept -- the complete set of first-visit documents takes about 5 minutes and doesn't throw the visit off rhythm. The receptionist knows exactly what to hand over for completion, the therapist knows what to check before starting the procedure, and the patient doesn't feel like they're filling out a stack of incomprehensible papers.

Without such a system it looks quite different: the therapist searches for the right form among several versions, the patient signs something in a hurry right before the procedure, and some documents -- most often the authorization and the additional consents -- never make it into the file at all. That's not only frustrating for a patient waiting for treatment, but a real risk for the practice at the next inspection.

[SP] Example -- Solo practice: After an incident during a KIF inspection, Aneta prepares one complete set of documents in a folder at reception -- in order: notice, patient record, procedure consent, authorization, additional consents. Every new patient gets the same set in the same order, so the first visit takes the same amount of time regardless of who is seeing them.

[GR] Example -- Group practice: At a practice with several therapists and a separate reception desk, the risk is different -- each therapist had their own, slightly different set of documents. They standardize this with one "first-visit package" assigned to the reception desk, so the order and completeness of the documents don't depend on which therapist happens to be seeing the patient.

A printable first-visit package

The most practical solution is to combine all five elements into one physical (or digital) set -- an envelope or folder with ready-made forms in the order described above -- so that at every first visit, reception reaches for one complete set instead of assembling it from memory each time. This eliminates the situation where, under time pressure, exactly the document that seems "least urgent" gets skipped -- most often the authorization or the additional consents.

Frequently asked questions

Does the patient need to sign the GDPR information notice?

No. The information notice fulfils the data controller's information obligation, not a request for consent -- it's enough that the patient had a real opportunity to read it, e.g. at reception or on the registration form. Adding a signature line under the notice is a common mistake that confuses it with a consent document.

In what order should documents be collected at the first visit?

First the GDPR information notice -- before collecting any data. Then the intake interview and patient record, followed by consent to the procedure (basic or extended, depending on the technique), and finally, as separate actions, the authorization for a close person and additional consents such as marketing or reminder SMS.

They shouldn't. Consent to a procedure has a different legal basis than marketing or communication consent -- combining them into one document is one of the most common mistakes at small practices, and the first thing a GDPR inspection challenges.

Is there one ready-made "first-visit package" file to download?

Not as a single file -- the individual elements (patient record, procedure consent) come from the TARCZA package, and the GDPR information notice from the PREMIUM package. This article shows how to combine the existing documents from both packages into one coherent first-visit flow, ready to print and use at reception.

CTA: Want the complete set of first-visit documents in one place, without searching for and combining different templates? The TARCZA package includes the patient record and procedure consents, and the PREMIUM package includes full GDPR documentation, including the information notice. See FizjoReady packages →

Related articles:
- GDPR Information Notice for Patients -- What It Must Include and Where to Post It
- How to correctly keep a patient record in physiotherapy?
- Patient consent to a physiotherapy procedure -- template
- Extended informed consent -- when regular procedure consent isn't enough
- Authorization for a Close Person to Access Medical Records -- Template and Rules

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.