1. The Membership Agreement: Your Foundational Document

Everything else in your practice hangs off this contract. It defines what patients pay, what they receive, and—just as important—what they don't receive. A well-drafted membership agreement should nail down:

What Every Membership Agreement Needs

  • Scope of services: A specific, itemized list of what membership includes—same-day access, extended visits, care coordination, an annual executive physical, direct messaging
  • Exclusions: An equally explicit list of what is NOT covered—hospital care, specialist fees, labs, imaging, prescriptions, emergency services
  • Fee terms: Amount, billing frequency, payment methods, late-payment consequences, and how and when fees can change
  • Renewal and termination: Whether the agreement auto-renews, how either party ends it, and how you will hand off care so termination never looks like abandonment
  • Refund terms: What happens to prepaid fees if the patient leaves mid-term, moves away, or dies—vagueness here is a common source of disputes
  • No guarantee of outcomes: Explicit language that membership buys access and service levels, not medical results

The Insurance Trap

The biggest structural risk in a membership agreement is drafting it so broadly that it looks like prepaid health coverage. If your agreement promises to cover whatever care a member may need for a flat fee, a state insurance regulator can argue you're selling insurance without a license. State insurance regulators have in fact scrutinized retainer arrangements on exactly this theory, and some states have responded with explicit statutory frameworks—Washington, for example, has a direct-practice statute (chapter 48.150 RCW) that exempts properly registered direct practices from regulation as insurers. The drafting lesson applies everywhere: define a limited, specific set of non-covered services, avoid open-ended coverage promises, and have counsel confirm how your state regulates concierge medicine and retainer agreements.

2. Medicare Private Contracts (If You've Opted Out)

If you opt out of Medicare—the route most full concierge models take—federal regulations require a written private contract with every Medicare beneficiary you treat. This is not a nice-to-have; it's a federal requirement with prescribed contents, and treating a Medicare beneficiary without a signed contract in place can jeopardize your opt-out status.

Key mechanics to build into your document workflow:

  • The opt-out affidavit must be filed with your Medicare Administrative Contractor, and the opt-out runs in two-year cycles (affidavits filed since mid-2015 renew automatically unless you cancel)
  • Private contracts must be signed before you furnish any service to that beneficiary
  • The contract must contain specific acknowledgments—that you've opted out, that neither the patient nor you will bill Medicare for your services, and that the patient agrees to pay your charges
  • You need a tracking system so no Medicare patient is ever seen without a current contract on file

The required contract contents are covered in more detail in our guide to Medicare compliance for concierge practices.

3. Patient Transition and Notice Letters

If you're converting an existing practice, your notice letters to current patients are legal documents, not marketing. Done wrong, they expose you to patient abandonment claims and board complaints. Your letter file should include:

  • An initial written notice with the effective date, new terms, and the patient's options
  • Follow-up notices (certified mail for some patients and some states)
  • Referral assistance and records-transfer instructions for patients who don't join
  • Documentation of every notice sent and every contact attempt

Thirty days is a common minimum, but many situations call for more, and requirements vary by state. See our full breakdown of the 30-day notice rule and transition requirements.

Planning Your Transition? Use our free calculator to model membership pricing and revenue before you finalize your agreement terms.

4. HIPAA Documents: Privacy Notices, Authorizations, and BAAs

Leaving insurance networks does not take you out of HIPAA's reach, and even practices that fall outside HIPAA's technical definitions face state privacy laws. Your privacy paperwork should include:

The HIPAA Document Set

  • Notice of Privacy Practices (NPP): Explains how you use and disclose patient information, provided to patients with a good-faith effort to obtain written acknowledgment
  • Patient authorizations: Signed forms for uses and disclosures beyond treatment, payment, and operations—including marketing, testimonials, and sharing records with family members
  • Business associate agreements (BAAs): Required with every vendor that touches protected health information—your EHR, billing platform, answering service, email provider, cloud storage, and IT support

The BAA is the most commonly missed item on this list. Concierge practices adopt consumer-grade tools for messaging and scheduling; every one of those vendors needs to either sign a BAA or stay entirely outside the flow of patient information.

5. Informed Consent and Financial Policy Documents

Beyond the membership agreement itself, day-one paperwork should include:

  • General consent to treat: Your baseline informed-consent documentation, plus procedure-specific consents where relevant
  • Financial policy: A plain-language document explaining that membership fees are separate from insurance, what patients may still owe third parties, and how insurance and out-of-network care work alongside membership
  • Insurance acknowledgment: For opted-out or out-of-network physicians, a signed acknowledgment that the patient understands what their insurance will and won't pay—this prevents the most common billing disputes months later

6. Employment Agreements and Restrictive Covenants

In a small practice, one departing employee can walk out with your patient relationships and your operational playbook. Staff documents to have in place before your first hire:

  • Employment or contractor agreements defining duties, compensation, and termination terms—with correct worker classification, since misclassifying employees as contractors carries tax and labor-law consequences
  • Confidentiality and non-solicitation provisions protecting patient lists, pricing, and business information
  • Non-compete provisions, used carefully: Enforceability varies dramatically by state, several states limit or prohibit non-competes for healthcare workers specifically, and the law in this area continues to shift—this is a clause to draft with counsel, not copy from a template

7. Corporate Formation Documents and Entity Choice

Your entity is the legal wrapper around everything else: articles of incorporation or organization, bylaws or an operating agreement, and ownership records. Two reasons this deserves attorney attention rather than an online filing service:

Corporate practice of medicine (CPOM). States such as California and Texas prohibit general business corporations from practicing medicine or employing physicians to do so. In CPOM states, physicians typically must organize as a professional corporation or professional entity owned by licensed physicians, and arrangements with non-physician investors or management companies must be structured carefully. Forming the wrong entity type in a CPOM state can invalidate your structure from the start.

Liability and tax. Entity choice affects how membership revenue is taxed, how you pay yourself, and what stands between practice liabilities and your personal assets. The right answer depends on your state, your ownership plans, and whether partners will join later.

8. Telehealth Consent

If your membership includes virtual visits—and in most concierge models it does—add a telehealth-specific consent covering the limitations of remote evaluation, technology and privacy risks, and what to do in an emergency. Many states require documented telehealth consent, and state licensure rules generally turn on where the patient is located at the time of the visit, which matters when members travel or winter out of state. Build the consent into your onboarding flow rather than treating it as an afterthought.

The Master Checklist

Document Purpose When You Need It
Entity formation documents Legal structure, CPOM compliance, liability protection Before signing anything else
Membership agreement Defines services, fees, exclusions, termination Before enrolling your first member
Medicare opt-out affidavit and private contracts Federal requirement for opted-out physicians Before treating any Medicare beneficiary after opt-out
Patient transition/notice letters Avoids abandonment claims during conversion 60–90 days before conversion
Notice of Privacy Practices and authorizations HIPAA privacy compliance Day one
Business associate agreements Covers every vendor handling patient information Before any vendor touches PHI
Informed consent and financial policy Treatment consent and billing clarity Day one
Employment/contractor agreements Protects patient relationships and business information Before your first hire
Telehealth consent State consent requirements for virtual care Before your first virtual visit

Build Your Practice on Solid Ground

Our team will guide you through every stage of the concierge transition. Get practical guidance on sequencing your legal, financial, and operational setup.

Contact Us About Your Transition

Paperwork First, Patients Second

The physicians who transition smoothly are the ones whose documents were ready before their first member signed. Work through this checklist with counsel, and the legal side of your practice becomes something you set up once—not something you firefight forever.

When you are ready to run the membership side, see MedAlly plans and pricing: run the billing in-house, or have our team run it.