Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

Medicare Consent to Release form: Free template

Avatar photo Maja Popovska
Last Updated: August 14, 2026
Key takeaways

Key takeaways

The Medicare Consent to Release (CTR) form lets a beneficiary authorize CMS to share claim and entitlement data with a named third party.

Since January 1, 2020, the form requires the Medicare beneficiary identifier (MBI) rather than the legacy Health Insurance Claim Number (HICN). Submit the HICN and CMS rejects the form.

Five fields decide whether CMS accepts the form: beneficiary details, the MBI, the representative, the scope of release, and the expiration date.

A CTR and a HIPAA authorization are not interchangeable, so third-party access to a full record usually needs both.

Practice management software like Pabau collects consent by e-signature and flags each authorization before it expires, so access never lapses mid-case.

This is the CMS form that authorizes release of Medicare claim and entitlement records to a named representative. It covers beneficiary details, representative details, the scope of release, and the expiration date.

Download template

The Medicare Consent to Release (CTR) form authorizes CMS to release a beneficiary’s claim and entitlement records to a named third party. Attorneys, billing firms, and other providers all rely on it. Two details decide whether CMS accepts the form. One is the identifier you enter, and the other is how tightly you define the scope.

The form itself is short. The trouble comes after signing, when nobody tracks the expiration date and access quietly lapses in the middle of a case. Below are the five fields CMS checks, where the beneficiary’s MBI lives, and how to revoke consent.

The CTR form comes from the Centers for Medicare & Medicaid Services (CMS). It authorizes CMS to share Medicare claim data, entitlement information, and beneficiary records with a designated third party. That party is usually an attorney, a billing administrator, or an authorized representative. It belongs with the rest of your HIPAA paperwork, though it is a CMS instrument rather than a HIPAA one.

The form does three things.

  • Records the beneficiary’s consent to disclosure.
  • Defines exactly what information CMS will release.
  • Sets the date the authorization expires.

Medicare-participating practices, law firms, and billing clearinghouses use it regularly. They need the beneficiary’s claim history for legal settlements, workers’ compensation cases, and billing disputes.

When is the CTR form required?

Four situations make the form mandatory. Each one involves somebody other than the beneficiary asking CMS for Medicare data. It joins the stack of forms your practice collects, except this one is filed with CMS rather than the chart.

  • Legal representation. Attorneys handling personal injury, workers’ compensation, or liability claims need the beneficiary’s Medicare records as evidence. A signed CTR is how they get them. Settlements often turn on care billed by chiropractic practices.
  • Billing and claims management. Third-party billing firms and in-house billing staff may need authorization to discuss specific claim details with CMS. The same teams often prepare a medical necessity letter when a claim is denied.
  • Healthcare provider access. A beneficiary may want another provider to receive their Medicare data. That happens when a physical therapy practice picks up post-surgical rehab and needs the claim history.
  • Insurance carriers and Medicare Secondary Payer (MSP) inquiries. Other insurers investigating coordination of benefits need signed authorization before CMS will release beneficiary records.

What information does the form release?

The scope section decides how much CMS hands over. The beneficiary and the authorized representative choose one of four categories.

  • All claims and entitlement information. The broadest option. CMS releases every claim submitted for the beneficiary, plus entitlement and enrollment history.
  • Claims for a specific date range. Authorization limited to claims submitted between two dates, useful for case-specific litigation or billing audits.
  • Claims for specific conditions or procedures. Scoped to a particular diagnosis code or procedure code relevant to the legal or billing matter.
  • Entitlement information only. Authorization to release enrollment dates, plan changes, and beneficiary status without any claims data.

Narrowing the scope limits disclosure to what the stated purpose requires. CMS will not release anything outside the box you checked. Recording the chosen scope in your compliance software lets billing staff see what they may request without rereading the form.

How to fill out the form step by step

Five fields carry the weight here. An error in any of them sends the request back unprocessed.

  1. Beneficiary information. Enter the beneficiary’s full legal name exactly as it appears on their Medicare card. Include the date of birth in MM/DD/YYYY format and the complete mailing address. These details tell CMS whose records to release.
  2. Medicare beneficiary identifier (MBI). Locate the beneficiary’s MBI on their physical or digital Medicare card. The MBI replaced the legacy Health Insurance Claim Number (HICN) on all CMS forms as of January 1, 2020. Submit the HICN and CMS rejects the form.
  3. Authorized representative information. Enter the name, title, and contact details of the person or organization authorized to receive the data. Include the street address, phone number, and email. For an attorney or law firm, add the state bar license number.
  4. Scope of release. Check the box that matches the beneficiary’s intended scope. For a date range or a specific condition, write the exact dates or condition codes. An ambiguous scope gets the request rejected.
  5. Authorization expiration date. Enter the date the authorization ends, in MM/DD/YYYY format. CMS will not process a release request after that date without a new form. Most run one to two years, and the beneficiary decides.

Both the beneficiary and the authorized representative sign and date the form. The beneficiary’s signature must be wet ink or captured by an e-signature platform that logs date, time, and identity. Mail or fax the signed form to the CMS address printed on it.

Understanding the Medicare beneficiary identifier (MBI)

The MBI identifies every Medicare beneficiary. CMS ran a transition period that ended December 31, 2019, and the MBI has been required on CMS forms since January 1, 2020. A form carrying the old HICN comes back unprocessed. That delay can cost a legal deadline or hold up billing reconciliation.

The MBI is printed on the Medicare card directly below the beneficiary’s name. It is an 11-character alphanumeric code combining numbers and uppercase letters, such as 1EG4-TE5-MK73. CMS guidance sets out the character positions, so staff can catch a mistyped entry before the form goes out. Beneficiaries who cannot find the card can log into MyMedicare.gov, call 1-800-MEDICARE, or contact the Social Security Administration at 1-800-772-1213.

Pro Tip

Keep a one-line rule taped to your CMS forms folder. The MBI is the 11-character code printed under the beneficiary’s name, and it has been mandatory since January 1, 2020. If someone copies a longer number from an old record, it is a HICN and the form will come back.

How long is the authorization valid?

The authorization lasts until the date the beneficiary writes on the form. CMS sets no maximum or minimum. Common durations look like this.

  • One to two years for ongoing billing or claims verification.
  • Six months for a time-limited legal matter, such as a settlement.
  • Open-ended for standing authorization, though CMS may ask for periodic renewal.

Once the date passes, CMS rejects any new request. Extending access means a fresh CTR, signed again. Compliance tracking in practice management software like Pabau can warn staff weeks before an authorization lapses.

HIPAA compliance in Pabau
Pabau’s compliance tools store every signed authorization with its expiration date, so nobody discovers a lapsed CTR mid-case.

The beneficiary can cancel the authorization at any time, but it has to be in writing. CMS needs a signed revocation letter or revocation form. The letter carries the beneficiary’s full name, MBI, and date of birth, plus a clear statement revoking consent from a stated date.

Send it by mail, fax, or through the Medicare Secondary Payer Recovery Portal (MSPRP). CMS processes revocations in roughly five to 10 business days. After the effective date, the original signed form stops working, and CMS releases nothing further to that representative.

CTR form vs. Proof of Representation form

These two forms serve distinct purposes and are often confused. Both are required when an attorney represents a Medicare beneficiary in a legal matter.

Form Purpose Who receives it Data released
Consent to Release (CTR) Authorizes CMS to release beneficiary Medicare data to a third party CMS Medicare claims, entitlement records
Proof of Representation (POR) Establishes the attorney’s legal authority to represent the beneficiary CMS Attorney authorization, case reference

Practical rule. If an attorney is involved, send both forms to CMS together. The CTR authorizes the data release. The POR proves the attorney has standing to ask for it. Send one without the other and the request stalls.

CTR vs. HIPAA authorization: Key differences

These two authorizations get conflated constantly, and they answer to different rules.

Instrument Regulates Who controls it Scope
CMS CTR CMS release of Medicare data only CMS federal program rules Medicare claims and entitlement records
HIPAA authorization Provider disclosure of any protected health information HIPAA privacy rules (45 CFR § 164.508) All patient medical records (clinical notes, diagnoses, medications)

A third party who needs the full medical history usually requires both forms. The CTR covers Medicare claims, and the HIPAA authorization covers the clinical records your practice holds. Collect them in one sitting and apply the same data protection rules to each.

Paper CTR forms create friction. They get misplaced, expiration dates slip past unnoticed, and a revocation notice never reaches the billing staff who need to see it. A static PDF tells you nothing about which authorizations are still live.

Staff training improves accuracy, but it cannot catch a date nobody is watching. Pabau keeps the CTR in the client record itself, beside the intake questionnaire and the multidisciplinary review.

Customizable consent and intake forms
Pabau’s customizable consent forms capture the beneficiary’s signature and file it against the client record, ready to send to CMS.

Pabau’s digital consent forms cover four things paper cannot.

  • E-signature capture. Beneficiaries sign through a secure link, and every signature is timestamped against the client record.
  • Expiration tracking. Pabau flags an authorization before it lapses, so staff collect the renewal in time.
  • Revocation logging. When a beneficiary revokes consent, the date and effective time sit in the record for the audit trail.
  • Scope documentation. Each CTR records its scope in a structured field, so billing staff know exactly what they may request.

Practices that bill Medicare rely on claims data every month. Moving consent collection off paper cuts both the error rate and the audit exposure that comes with it.

Keep every Medicare consent current

Pabau collects consent by e-signature, stores it in the client record, and flags every authorization before it expires. Your team stops chasing paper and never loses data access mid-case.

Pabau practice management dashboard

Conclusion

Treat the CTR as a dated instrument, not a one-off signature. The identifier and the scope box decide whether CMS accepts it today. The expiration date decides whether you still have access in six months.

So the practical move is a single place to see every live authorization, its scope, and its expiry. Digital consent storage gets you that, and it turns renewal into a task somebody owns rather than a surprise. Book a demo to see how Pabau tracks Medicare consent from signature to expiration.

Continue your research

Continue your research

Building a digital consent workflow? Patient portal benefits shows how patients complete and sign forms before they arrive.

Completing certification paperwork for a patient? TLC medical certification form walks through the provider sections and the signature requirements.

Auditing the compliance documents you keep on file? OSHA emergency action plan covers the written plan and the review dates an inspector asks for.

Tightening up clinical documentation? Progress notes cheat sheet gives you a note structure that holds up in an audit.

Frequently asked questions

What is a Medicare Consent to Release form?

It is a CMS authorization that lets a Medicare beneficiary permit the release of their claim and entitlement data. The named third party is usually an attorney, a billing firm, or another provider.

What is the Medicare beneficiary identifier (MBI), and where do I find it?

The MBI is an 11-character alphanumeric code combining numbers and uppercase letters, such as 1EG4-TE5-MK73. It is printed on the Medicare card directly below the beneficiary’s name. The MBI replaced the legacy Health Insurance Claim Number (HICN) on CMS forms as of January 1, 2020. Beneficiaries can also find it on MyMedicare.gov or by calling 1-800-MEDICARE.

How long does the authorization stay valid?

It stays valid until the expiration date the beneficiary writes on the form, and CMS sets no maximum or minimum. Six months suits a time-limited legal matter, while one to two years suits ongoing billing access. After that date, the representative needs a new CTR to keep receiving data.

Does a CTR replace a HIPAA authorization?

No. The CTR only authorizes CMS to release Medicare claims and entitlement data. A HIPAA authorization is a separate document that lets a provider disclose protected health information, including clinical notes, diagnoses, and medications. A third party who needs the full record usually requires both.

How do I revoke consent once the form is signed?

Send CMS a signed revocation letter or revocation form. Include the beneficiary’s full name, MBI, and date of birth, plus a clear statement revoking consent from a stated date. Submit it by mail, fax, or the Medicare Secondary Payer Recovery Portal. CMS processes revocations in roughly five to 10 business days.

How does the CTR differ from Proof of Representation?

The CTR authorizes CMS to release beneficiary data to a named third party. Proof of Representation (POR) establishes an attorney’s legal authority to act for the beneficiary. When an attorney is involved, CMS needs both forms, submitted together.

×