CBT generates paper. Thought records, behavioral activation logs, exposure hierarchies, homework tracking sheets, PHQ-9 scores — a client working through a 16-session CBT protocol will produce fifteen or twenty separate worksheets. Without a system, those worksheets scatter: some in a folder, some emailed back, some photographed on a phone, some never collected at all.
The short answer: organize CBT worksheets by client, not by worksheet type. Use a consistent file naming convention. Store everything in a HIPAA-compliant system. Link each worksheet to the corresponding session note. Done right, this takes five minutes to set up and thirty seconds per session to maintain.
Why CBT worksheets need a documentation system
Direct answer: completed worksheets are Protected Health Information (PHI). They require the same storage security as session notes — and they’re clinically more useful when they’re organized, not just stored.
Three things go wrong without a system:
Worksheets disappear. A thought record from session three — where did it go? Did the client take it home? Is it in a pile somewhere? Can you find it before session eight when you need to show the client their progress?
There’s no link to the session. A behavioral experiment completed between sessions four and five should be connected to the session note from session five. If they live in separate places — a folder and a note — the connection is lost.
Progress can’t be tracked. CBT is measurable. If PHQ-9 scores from intake, session six, and session twelve are in three different places, tracking the trajectory requires hunting. If thought record believability scores aren’t logged anywhere, you’re relying on memory.
Which CBT worksheets to keep
Not all worksheets carry equal documentation weight.
Always keep
| Worksheet type | Why it matters |
|---|---|
| Thought records | Core cognitive work; believability scores track treatment response |
| Behavioral activation logs | Behavioral evidence for the mood-activity link |
| Behavioral experiment forms | Prediction + outcome = data for the next session |
| Exposure hierarchy | Changes as treatment progresses; version history matters |
| PHQ-9, GAD-7, PCL-5, Y-BOCS | Quantitative progress tracking from baseline |
| Homework tracking logs | Completion rate is a clinical signal |
Keep situationally
- Psychoeducation worksheets the client filled in (not blank handouts)
- Consent forms for specific techniques (EMDR, exposure, imagery rescripting)
- Materials the client brought in — journals, drawings, notes from between sessions
Not necessary to keep
- Blank worksheet copies you handed out but the client did not complete
- Generic handouts with no client-identifying information
HIPAA compliance: where you can and cannot store worksheets
Direct answer: completed CBT worksheets are PHI. They must be stored in a HIPAA-compliant system — which means either a platform with a signed Business Associate Agreement (BAA) or an encrypted local storage solution.
Storage options compared
| Storage option | HIPAA status | Notes |
|---|---|---|
| EHR with built-in document storage | ✅ Compliant | SimplePractice, TherapyNotes, Jane App — BAA included |
| Google Workspace (Business/Enterprise) + BAA | ✅ Compliant with BAA | Google signs BAA for paid accounts; personal Gmail does not qualify |
| Encrypted local storage (VeraCrypt, FileVault) | ✅ Compliant | Requires encrypted backup; local access only |
| ShareFile / Kiteworks | ✅ Compliant | HIPAA-compliant file sharing with BAA |
| Personal Google Drive | ❌ Not compliant | No BAA available for personal accounts |
| Standard Dropbox (personal) | ❌ Not compliant | No BAA on personal plans |
| Standard email (Gmail, Outlook personal) | ❌ Not compliant | Not encrypted; no BAA |
| Text message / WhatsApp | ❌ Not compliant | Unencrypted; no BAA |
| Notion (free or personal) | ❌ Not compliant | No BAA available |
The BAA question
A Business Associate Agreement is a contract between you (the covered entity) and a technology vendor (the business associate) confirming the vendor will protect PHI. Without a BAA, using that platform for any client data is a HIPAA violation — regardless of how “secure” the platform claims to be.
Before storing any worksheet in a cloud service, confirm: does this vendor sign a BAA? If you can’t find that information in under two minutes, assume the answer is no.
Folder structure: organizing by client
Direct answer: one folder per client, named with a pseudonym or initials plus start year. Subfolders by material type. Never organize by worksheet type across clients — that creates a compliance exposure if the folder is ever opened accidentally.
Recommended structure
📁 Clients/
📁 MT-2024/ ← initials + year started
📁 01-session-notes/
📁 02-thought-records/
📁 03-behavioral-experiments/
📁 04-exposure-hierarchy/
📁 05-standardized-measures/ ← PHQ-9, GAD-7, etc.
📁 06-homework-logs/
📁 07-other/
📁 JK-2025/
📁 01-session-notes/
...
Keep a separate, secure index: “MT-2024 → Michael T., DOB 1988, started March 2024.” This index is itself PHI and needs the same protection as the client folders.
Why initials plus year, not full name
Reduces exposure if a file manager window is accidentally visible. Your secure index holds the actual mapping.
File naming: a consistent system
Direct answer: start every filename with the date in YYYY-MM-DD format, then worksheet type, then client initials. This automatically sorts files chronologically in any file manager — no manual sorting needed.
Naming format
YYYY-MM-DD_worksheet-type_initials.extension
Examples
| Worksheet | Filename |
|---|---|
| Thought record, November 14 | 2025-11-14_thought-record_MT.pdf |
| PHQ-9 at session 1 | 2025-09-03_PHQ9-session1_MT.pdf |
| Behavioral experiment | 2025-11-21_behavioral-experiment_MT.pdf |
| Exposure hierarchy, version 3 | 2025-10-15_exposure-hierarchy-v3_MT.pdf |
| Homework log, session 8 | 2025-11-07_homework-log-s8_MT.pdf |
Version numbers matter for the exposure hierarchy — it changes as the client progresses, and seeing earlier versions helps you understand the trajectory.
Scanning paper worksheets
Many clients complete worksheets by hand — in session or at home. Here’s a workflow that keeps paper from accumulating.
Five-step scanning workflow
1. Client completes worksheet in session or brings homework back
2. Scan immediately after session — don't let it join the pile
3. Rename file to your naming convention
4. Save to the client's folder
5. Paper original:
→ Return to client if it's their working material
→ Shred securely if you're keeping the digital copy as the record
Mobile scanning apps worth using
| App | Cost | Notes |
|---|---|---|
| Adobe Scan | Free | OCR, clean output |
| Microsoft Lens | Free | OneDrive integration; use business account with BAA |
| Scanner Pro | Paid | Strong output quality, local save option |
| Genius Scan | Free/paid | Simple, reliable |
The rule: scan immediately, not “later.” A pile of “scan later” worksheets is a pile of unsecured PHI waiting to be lost.
Tracking homework completion in session notes
Direct answer: track homework completion in your session notes — not just by keeping the worksheet. The session note entry is what makes the worksheet clinically meaningful.
What to document in the session note
HOMEWORK REVIEW — Session [#]
Assigned last session: [describe specific worksheet or task]
Completed: yes / partially / no
If partial or no — what got in the way:
What the client observed or learned:
Clinical note on completion pattern:
Worksheet file: [filename or location]
Why “homework completed” is not enough
“Client completed thought record” tells you nothing useful. Compare:
❌ “Homework completed.”
✅ “Client completed 5 of 7 thought records. Skipped both weekend days — consistent with ‘nothing matters on weekends’ cognition from session 6. Believability of alternative thought dropped from 60/100 to 35/100 across the week. Suggests the cognitive work isn’t yet affecting weekend behavior. Address this session.”
The second note turns the worksheet into clinical data. The first documents compliance, not progress.
Sending worksheets to clients: what’s HIPAA-compliant
Direct answer: standard email and text message are not HIPAA-compliant channels for worksheet delivery. Use a client portal, a HIPAA-compliant file-sharing tool, or a secure messaging platform with a signed BAA.
Options for delivering worksheets to clients
| Method | Compliance | Notes |
|---|---|---|
| EHR client portal | ✅ | Built into most major EHRs |
| ShareFile / Kiteworks (with BAA) | ✅ | Purpose-built for secure file sharing |
| Signal (for messaging + files) | ✅ | End-to-end encrypted; no BAA needed |
| Doxy.me secure messaging | ✅ | Designed for telehealth |
| Personal Gmail | ❌ | No BAA; not encrypted |
| Standard text message | ❌ | Not encrypted |
| ❌ | No healthcare BAA |
For receiving completed worksheets from clients — the same standards apply. A client photographing their thought record and texting it to you is a compliance gap.
Frequently asked questions
How long do I need to keep completed CBT worksheets? Under HIPAA, medical records including therapy documentation must be retained for a minimum of 6 years from creation or the date it was last in effect, whichever is later. For clients who were minors during treatment, many states require keeping records until the client reaches age 21 or for a defined number of years after the last service — whichever is longer. Check your state’s specific requirements, as they often exceed the federal minimum.
My client wants copies of their worksheets — how do I share them securely? Use your EHR’s client portal, or a HIPAA-compliant file-sharing link. Do not email worksheets from a personal Gmail account or text them. If a client requests their records, they have a right to them under HIPAA — the delivery method needs to be secure, but their access right is real.
Do I need to keep worksheets the client took home and never returned? If the client took the worksheet home and you never saw the completed version, there’s nothing to retain. Document in your session note that homework was assigned and not returned — that’s the clinical record. You can’t keep what you don’t have.
How do I handle worksheets in telehealth practice? In telehealth, clients complete worksheets at home. Options: send a fillable PDF through your client portal; use a digital worksheet tool; or have clients print, complete, and photograph worksheets to send back through a secure channel. Screen-sharing a blank worksheet during the session and completing it together is also an option — document that the exercise was completed in-session rather than as homework.
Worksheet organization checklist
SETUP (once)
[ ] HIPAA-compliant storage platform confirmed and BAA signed
[ ] Folder structure created: one folder per client, subfolders by type
[ ] File naming convention decided and documented
[ ] Separate client index created (pseudonym → full name + DOB)
[ ] Encrypted backup solution in place
AFTER EACH SESSION
[ ] Any paper worksheets scanned immediately
[ ] Files renamed to naming convention
[ ] Files saved to correct client subfolder
[ ] Homework review documented in session note (with file reference)
[ ] Next homework assignment recorded with success criterion
COMPLIANCE
[ ] No client worksheets in personal cloud storage without BAA
[ ] Delivery method for sending worksheets to clients is HIPAA-compliant
[ ] Retention schedule confirmed for your state/jurisdiction
A worksheet system that works is invisible in practice. You assign homework, the client brings it back, you scan it, rename it, drop it in the folder, and reference it in the session note. Two minutes total. Three months later, you can pull up every thought record from the beginning of treatment and show the client how their thinking has changed — because the system kept it all connected.
Try TheraMemory free for 14 days
Client records, session notes, and worksheet tracking in one HIPAA-ready place — built for the way CBT practice actually works.
Document every session in under 10 minutes.
Try TheraMemory