CBT generates paper. Thought records, behavioral activation logs, exposure hierarchies, homework tracking sheets, PHQ-9 scores — a client working through a 16-session CBT protocol will produce fifteen or twenty separate worksheets. Without a system, those worksheets scatter: some in a folder, some emailed back, some photographed on a phone, some never collected at all.

The short answer: organize CBT worksheets by client, not by worksheet type. Use a consistent file naming convention. Store everything in a HIPAA-compliant system. Link each worksheet to the corresponding session note. Done right, this takes five minutes to set up and thirty seconds per session to maintain.


Why CBT worksheets need a documentation system

Direct answer: completed worksheets are Protected Health Information (PHI). They require the same storage security as session notes — and they’re clinically more useful when they’re organized, not just stored.

Three things go wrong without a system:

Worksheets disappear. A thought record from session three — where did it go? Did the client take it home? Is it in a pile somewhere? Can you find it before session eight when you need to show the client their progress?

There’s no link to the session. A behavioral experiment completed between sessions four and five should be connected to the session note from session five. If they live in separate places — a folder and a note — the connection is lost.

Progress can’t be tracked. CBT is measurable. If PHQ-9 scores from intake, session six, and session twelve are in three different places, tracking the trajectory requires hunting. If thought record believability scores aren’t logged anywhere, you’re relying on memory.


Which CBT worksheets to keep

Not all worksheets carry equal documentation weight.

Always keep

Worksheet typeWhy it matters
Thought recordsCore cognitive work; believability scores track treatment response
Behavioral activation logsBehavioral evidence for the mood-activity link
Behavioral experiment formsPrediction + outcome = data for the next session
Exposure hierarchyChanges as treatment progresses; version history matters
PHQ-9, GAD-7, PCL-5, Y-BOCSQuantitative progress tracking from baseline
Homework tracking logsCompletion rate is a clinical signal

Keep situationally

  • Psychoeducation worksheets the client filled in (not blank handouts)
  • Consent forms for specific techniques (EMDR, exposure, imagery rescripting)
  • Materials the client brought in — journals, drawings, notes from between sessions

Not necessary to keep

  • Blank worksheet copies you handed out but the client did not complete
  • Generic handouts with no client-identifying information

HIPAA compliance: where you can and cannot store worksheets

Direct answer: completed CBT worksheets are PHI. They must be stored in a HIPAA-compliant system — which means either a platform with a signed Business Associate Agreement (BAA) or an encrypted local storage solution.

Storage options compared

Storage optionHIPAA statusNotes
EHR with built-in document storage✅ CompliantSimplePractice, TherapyNotes, Jane App — BAA included
Google Workspace (Business/Enterprise) + BAA✅ Compliant with BAAGoogle signs BAA for paid accounts; personal Gmail does not qualify
Encrypted local storage (VeraCrypt, FileVault)✅ CompliantRequires encrypted backup; local access only
ShareFile / Kiteworks✅ CompliantHIPAA-compliant file sharing with BAA
Personal Google Drive❌ Not compliantNo BAA available for personal accounts
Standard Dropbox (personal)❌ Not compliantNo BAA on personal plans
Standard email (Gmail, Outlook personal)❌ Not compliantNot encrypted; no BAA
Text message / WhatsApp❌ Not compliantUnencrypted; no BAA
Notion (free or personal)❌ Not compliantNo BAA available

The BAA question

A Business Associate Agreement is a contract between you (the covered entity) and a technology vendor (the business associate) confirming the vendor will protect PHI. Without a BAA, using that platform for any client data is a HIPAA violation — regardless of how “secure” the platform claims to be.

Before storing any worksheet in a cloud service, confirm: does this vendor sign a BAA? If you can’t find that information in under two minutes, assume the answer is no.


Folder structure: organizing by client

Direct answer: one folder per client, named with a pseudonym or initials plus start year. Subfolders by material type. Never organize by worksheet type across clients — that creates a compliance exposure if the folder is ever opened accidentally.

📁 Clients/
  📁 MT-2024/                      ← initials + year started
    📁 01-session-notes/
    📁 02-thought-records/
    📁 03-behavioral-experiments/
    📁 04-exposure-hierarchy/
    📁 05-standardized-measures/    ← PHQ-9, GAD-7, etc.
    📁 06-homework-logs/
    📁 07-other/
  📁 JK-2025/
    📁 01-session-notes/
    ...

Keep a separate, secure index: “MT-2024 → Michael T., DOB 1988, started March 2024.” This index is itself PHI and needs the same protection as the client folders.

Why initials plus year, not full name

Reduces exposure if a file manager window is accidentally visible. Your secure index holds the actual mapping.


File naming: a consistent system

Direct answer: start every filename with the date in YYYY-MM-DD format, then worksheet type, then client initials. This automatically sorts files chronologically in any file manager — no manual sorting needed.

Naming format

YYYY-MM-DD_worksheet-type_initials.extension

Examples

WorksheetFilename
Thought record, November 142025-11-14_thought-record_MT.pdf
PHQ-9 at session 12025-09-03_PHQ9-session1_MT.pdf
Behavioral experiment2025-11-21_behavioral-experiment_MT.pdf
Exposure hierarchy, version 32025-10-15_exposure-hierarchy-v3_MT.pdf
Homework log, session 82025-11-07_homework-log-s8_MT.pdf

Version numbers matter for the exposure hierarchy — it changes as the client progresses, and seeing earlier versions helps you understand the trajectory.


Scanning paper worksheets

Many clients complete worksheets by hand — in session or at home. Here’s a workflow that keeps paper from accumulating.

Five-step scanning workflow

1. Client completes worksheet in session or brings homework back
2. Scan immediately after session — don't let it join the pile
3. Rename file to your naming convention
4. Save to the client's folder
5. Paper original:
   → Return to client if it's their working material
   → Shred securely if you're keeping the digital copy as the record

Mobile scanning apps worth using

AppCostNotes
Adobe ScanFreeOCR, clean output
Microsoft LensFreeOneDrive integration; use business account with BAA
Scanner ProPaidStrong output quality, local save option
Genius ScanFree/paidSimple, reliable

The rule: scan immediately, not “later.” A pile of “scan later” worksheets is a pile of unsecured PHI waiting to be lost.


Tracking homework completion in session notes

Direct answer: track homework completion in your session notes — not just by keeping the worksheet. The session note entry is what makes the worksheet clinically meaningful.

What to document in the session note

HOMEWORK REVIEW — Session [#]
Assigned last session: [describe specific worksheet or task]
Completed: yes / partially / no
If partial or no — what got in the way:
What the client observed or learned:
Clinical note on completion pattern:
Worksheet file: [filename or location]

Why “homework completed” is not enough

“Client completed thought record” tells you nothing useful. Compare:

❌ “Homework completed.”

✅ “Client completed 5 of 7 thought records. Skipped both weekend days — consistent with ‘nothing matters on weekends’ cognition from session 6. Believability of alternative thought dropped from 60/100 to 35/100 across the week. Suggests the cognitive work isn’t yet affecting weekend behavior. Address this session.”

The second note turns the worksheet into clinical data. The first documents compliance, not progress.


Sending worksheets to clients: what’s HIPAA-compliant

Direct answer: standard email and text message are not HIPAA-compliant channels for worksheet delivery. Use a client portal, a HIPAA-compliant file-sharing tool, or a secure messaging platform with a signed BAA.

Options for delivering worksheets to clients

MethodComplianceNotes
EHR client portal✅Built into most major EHRs
ShareFile / Kiteworks (with BAA)✅Purpose-built for secure file sharing
Signal (for messaging + files)✅End-to-end encrypted; no BAA needed
Doxy.me secure messaging✅Designed for telehealth
Personal Gmail❌No BAA; not encrypted
Standard text message❌Not encrypted
WhatsApp❌No healthcare BAA

For receiving completed worksheets from clients — the same standards apply. A client photographing their thought record and texting it to you is a compliance gap.


Frequently asked questions

How long do I need to keep completed CBT worksheets? Under HIPAA, medical records including therapy documentation must be retained for a minimum of 6 years from creation or the date it was last in effect, whichever is later. For clients who were minors during treatment, many states require keeping records until the client reaches age 21 or for a defined number of years after the last service — whichever is longer. Check your state’s specific requirements, as they often exceed the federal minimum.

My client wants copies of their worksheets — how do I share them securely? Use your EHR’s client portal, or a HIPAA-compliant file-sharing link. Do not email worksheets from a personal Gmail account or text them. If a client requests their records, they have a right to them under HIPAA — the delivery method needs to be secure, but their access right is real.

Do I need to keep worksheets the client took home and never returned? If the client took the worksheet home and you never saw the completed version, there’s nothing to retain. Document in your session note that homework was assigned and not returned — that’s the clinical record. You can’t keep what you don’t have.

How do I handle worksheets in telehealth practice? In telehealth, clients complete worksheets at home. Options: send a fillable PDF through your client portal; use a digital worksheet tool; or have clients print, complete, and photograph worksheets to send back through a secure channel. Screen-sharing a blank worksheet during the session and completing it together is also an option — document that the exercise was completed in-session rather than as homework.


Worksheet organization checklist

SETUP (once)
[ ] HIPAA-compliant storage platform confirmed and BAA signed
[ ] Folder structure created: one folder per client, subfolders by type
[ ] File naming convention decided and documented
[ ] Separate client index created (pseudonym → full name + DOB)
[ ] Encrypted backup solution in place

AFTER EACH SESSION
[ ] Any paper worksheets scanned immediately
[ ] Files renamed to naming convention
[ ] Files saved to correct client subfolder
[ ] Homework review documented in session note (with file reference)
[ ] Next homework assignment recorded with success criterion

COMPLIANCE
[ ] No client worksheets in personal cloud storage without BAA
[ ] Delivery method for sending worksheets to clients is HIPAA-compliant
[ ] Retention schedule confirmed for your state/jurisdiction

A worksheet system that works is invisible in practice. You assign homework, the client brings it back, you scan it, rename it, drop it in the folder, and reference it in the session note. Two minutes total. Three months later, you can pull up every thought record from the beginning of treatment and show the client how their thinking has changed — because the system kept it all connected.

Try TheraMemory free for 14 days

Client records, session notes, and worksheet tracking in one HIPAA-ready place — built for the way CBT practice actually works.

Document every session in under 10 minutes.

Try TheraMemory

Read also