Consent Capture
Plan members record the two data-sharing choices of CMS-0057-F themselves, on the Data sharing page of the member portal (Data sharing in the top navigation, /consent):
- Provider Access: whether the plan shares the member's record with the in-network providers who treat them through Provider Access. Sharing is on unless the member opts out.
- Payer-to-Payer: whether the plan may request the member's records from their previous or concurrent health plans through Payer-to-Payer. Nothing is requested unless the member opts in.
This page describes what members see and do there and what each choice records, so that administrators can configure the feature and support members. The plan's side is configured in Consent Settings, and choices signed by an authorized representative are checked in Consent Reviews. The page appears only on deployments that enable member consent capture; see Capture mode.

What members can do
- See what is on file for each choice, and since when it applies
- Opt out of Provider Access, or turn sharing back on
- Authorize Payer-to-Payer exchange for all information, or for non-sensitive information only where the plan offers it, naming one or more registered previous or concurrent plans; and withdraw the authorization
- Let an authorized representative sign, with a document of authority, where the deployment offers it (see Authorized representatives)
- Review earlier changes and what was answered each time
The two cards
Each choice has its own card. The card says what the choice covers (what a treating provider receives and what is never sent, or what the plan would collect from the other plan), asks the form's question, and shows the choice in force. Its status badge reads:
| Card | Status | Meaning |
|---|---|---|
| Provider Access | Sharing is on | No opt-out is in force. This is the default; the card says In force since your coverage started until the member records a choice. |
| Provider Access | Not sharing | An opt-out is in force. |
| Payer-to-Payer | Not asking | No authorization is in force. The card says No permission on file until the member opts in. |
| Payer-to-Payer | Permission given | An authorization is in force until the end date the plan set, for all information or for non-sensitive information only. |
| Either | Waiting on document check | A representative recorded a choice that shares more of the record, and it waits for review. |
Below the cards, What these two choices do not change reminds the member that apps they connected through the FHIR App Gallery keep working, and that neither choice affects their care, coverage, or payments. The plan's contact details, taken from the consent forms, close the page for members who would rather record a choice by phone or mail.
Provider Access opt-out
On the Provider Access card the member picks OPT OUT: do not share my health information with my providers., or Share my health information with my in-network providers. to turn sharing back on.
A confirmation panel opens. Where representatives are offered, it first asks Who is completing this form? with Member (myself) and Authorized representative.
The member ticks the statement under Signature, draws a signature, and clicks Save this choice.

A member's own choice takes effect when it is saved, and the record it replaces stops being in force. From then on, Provider Access responses leave this member's data out.
Payer-to-Payer authorization
On the Payer-to-Payer card the member picks ALL of my health information, including sensitive/protected information. or, where the plan offers it, Only NON-SENSITIVE information. Do not share my sensitive/protected information.
Under Previous or concurrent health plan the member types the plan's name and picks it from the list. Only plans registered in Consent Settings appear. The member adds their Member ID with that plan, whether that plan was in their own name or under someone else, and whether it is a previous plan or one they have now alongside this one. Add another plan names more.
The member signs and clicks Save this choice.

The authorization runs until the date set in Consent Settings, which the form shows before the member signs. Once it is saved, the card lists the plans the member named:

Picking Only NON-SENSITIVE information shows the member a warning before saving: other plans cannot yet separate specially protected records from the rest, so they hold back the member's whole history and nothing moves today.
To stop, the member picks Withdraw my authorization. Do not request my records from my other health plans., signs, and saves. The plan stops asking from that day; records it already collected stay in the member's file.
Authorized representatives
Representative signing is offered only where the portal runs with MEMBER_CONSENT_REPRESENTATIVES_ENABLED=true, for plans whose staff check documents of authority. Elsewhere the panel does not ask who completes the form, the member always signs themselves, and there is nothing to review.
Where it is offered, picking Authorized representative adds:
| Field | What the representative enters |
|---|---|
| Representative name and relationship to member | For example Sam Lee, son. |
| Basis of authority | Power of Attorney, Legal guardian, or Other with a description. |
| Upload documentation of your authority | The power of attorney, guardianship papers or equivalent: a PDF, JPEG or PNG file of up to 10 MB. |

When the choice applies depends on its direction, and the panel tells the representative which before they save:
| Choice | When it applies |
|---|---|
| Shares less: opting out of Provider Access, withdrawing a Payer-to-Payer authorization | At once. The plan checks the document afterwards. |
| Shares more: turning Provider Access sharing back on, authorizing Payer-to-Payer exchange | After an administrator has checked the document and approved the choice in Consent Reviews. Until then the card shows Waiting on document check and the earlier choice stays in force. |
Earlier changes
Earlier changes to this choice, at the bottom of each card, lists every choice recorded for that switch, newest first, with who signed it and its status. View what was answered shows the answers as they were submitted.

| Tag | Meaning |
|---|---|
| In force | The choice that currently applies. |
| In force, approved | A representative's choice that an administrator approved on that date. |
| No longer in force | A later choice replaced it. |
| Waiting on document check | A representative's choice waiting for review. |
| Not approved | An administrator rejected the representative's choice. The internal note is never shown to the member. |
| Ended | A choice whose dates have passed or not started yet. |
After an administrator approves the representative's choice above, the history reads:

Read-only and unconfigured deployments
Where the plan records these choices through Member Services, the deployment runs in read-only capture mode: the page shows what is on file, the choices cannot be changed, and a note points the member to the contact details.

Until the plan organization and the Payer-to-Payer end date are set in Consent Settings, the page shows the choices on file but saving is blocked with Data sharing is not configured yet; please call Member Services to record your choice.
What a saved choice records
Each save writes one set of FHIR records under the member's own session, all together or not at all:
- the answered form, a
QuestionnaireResponse; - a consent document that indexes it, a
DocumentReference; - the
Consentitself; - a
Provenancerecord of who signed and how; - for a representative, also a
RelatedPersonand a secondDocumentReferencefor the uploaded document.
If anything fails, nothing is saved, the panel stays open, and the member sees Sorry, we can't save it now. Please try again later or contact Member Services.
The Consent is what the APIs read: the Provider Access opt-out is checked by $provider-member-match and by every Provider Access export, and the Payer-to-Payer authorization names the plans the plan may ask. The records, their profiles and how to query them are in the Consent reference.