A violence and homicide risk assessment is the clinical record of how a clinician evaluated a client's risk of harm to others: the threat and its context, target identifiability, intent and access to means, risk and protective factors, a formulation, and the protective actions taken or reasonably ruled out. Clinicians document one when a client threatens an identifiable person or homicidal ideation emerges. Most run 300 to 800 words.
Therapists, psychologists, counselors, clinical social workers, psychiatric prescribers, forensic and emergency clinicians
Treating team, supervisors, crisis and emergency services, auditors, licensing boards, attorneys and courts
300 to 800 words · 15 to 30 minutes by hand (clinical team estimate)
Risk assessment documentation (compare: suicide risk assessment, safety plan, crisis note, mandated report)
When a client threatens an identifiable person, when homicidal ideation or other violence indicators emerge, and at intake, discharge, and forensic evaluations
No mandated note format; the duty to protect it evidences is state law that varies from mandatory to none, so the documented analysis carries the weight
A violence and homicide risk assessment is the clinical record of how a clinician evaluated a client's risk of harm to another person: the threat or indicator that triggered the evaluation, the inquiry into intent, target, and access, the risk and protective factors weighed, the risk formulation, and the protective decisions made, including a reasoned decision that no protective disclosure was indicated. No professional body, statute, or payer has ever standardized this note as a document format. What has been standardized are two separate things the note draws on: the assessment instruments, such as the structured professional judgment tool now in its third version, the Historical, Clinical, Risk Management-20 (HCR-20 V3), and actuarial scales such as the Violence Risk Appraisal Guide (VRAG); and the legal duty the note evidences, which descends from Tarasoff v. Regents of the University of California (17 Cal.3d 425, 1976), where Justice Tobriner wrote that "The protective privilege ends where the public peril begins" (opinion text). Clinicians and charts also say Tarasoff assessment, duty-to-warn or duty-to-protect note, danger-to-others (DTO) assessment, and HI assessment, charting shorthand for homicidal ideation that parallels SI.
The distinction that carries the most weight is warn versus protect. California reframed the obligation as a duty to protect, discharged by "reasonable efforts to communicate the threat" to both the victim and a law enforcement agency, and the statute's own 2013 amendment text states that it only changed the name of the duty (Civil Code 43.92): warning is one way to discharge the duty, alongside hospitalization, means restriction, and intensified treatment. The duty itself is state law that genuinely varies, from mandatory through permissive to none at all, so the note's job is to show which standard applied and how the clinician's analysis tracked it. The assessment note records that evaluation and reasoning; when a report or warning is actually made, the notification record is its own discipline, covered on the mandated reporting and duty-to-protect documentation page. Risk a client directs at themselves belongs in a suicide risk assessment, which shares the same documentation logic with a different subject and no third-party duty.
Every licensed mental health discipline writes them when the trigger arrives: therapists, psychologists, counselors, and clinical social workers in outpatient practice, psychiatric prescribers, emergency and crisis teams, and forensic clinicians for whom structured violence risk evaluation is routine work. In outpatient care the trigger is usually a statement in session, a disclosure of homicidal ideation, or a collateral warning from a family member, which counts as a treatment communication in California under Ewing v. Goldstein (2004); in emergency and inpatient settings the assessment anchors admission, discharge, and disposition decisions. The epidemiology argues for taking the outpatient case seriously: in the landmark MacArthur follow-up of discharged psychiatric patients, violence was "most frequently targeted at family members and friends" and most often took place at home, with substance use symptoms raising rates sharply (Steadman et al., 1998), which means the identifiable-victim analysis is rarely hypothetical. This page covers the evaluation record; when the encounter itself is an emergent, time-based service, the crisis note carries the billing, a psychiatric diagnostic evaluation carries an intake, and the assessment reasoning lives inside or alongside them.
No statute prescribes these headings. They mirror what a later reader, a supervisor, a licensing board, or a court reconstructing your judgment, will look for: what was said, how identifiable the person at risk was, how the clinician weighed it against the jurisdiction's standard, and what was done or deliberately not done. The through-line is that the formulation and the duty analysis must explain the actions.
Reason for assessment and context. What triggered the evaluation (a statement in session, disclosed homicidal ideation, a collateral report, a referral question) and the clinical context around it: precipitants, symptom course, substance use, current stressors. Pitfall: recording the trigger without the context. A threat statement stripped of its precipitant and course reads more alarming or less alarming than the clinician's actual judgment, and the reader cannot tell which.
Threat inquiry. What the client actually communicated, in their own terms: the statement and its context, whether it was conditional or unconditional, when and to whom it was made, and whether it has been repeated or escalated. Pitfall: paraphrase so loose the threshold cannot be reconstructed. "Made threatening statements" supports nothing; record the substance of what was said and the questions you asked about it.
Target and identifiability. Who the concern involves, how identifiable they are (a named person, a reasonably ascertainable person or group), the relationship, and current proximity or contact. Pitfall: skipping the identifiability analysis. Most duty-to-protect standards turn on a reasonably identifiable victim, and a note that never says whether one exists has skipped the pivotal legal fact.
Intent, capability, and access to means. Stated intent as distinct from anger or ideation, capability, and access to lethal means asked about directly, with any restriction steps agreed and verified. Pitfall: conclusions with no conversation shown. "No access to means" reads as unsupported unless the note records what was asked, what was answered, and what was confirmed.
History. Prior violence with recency, severity, and context, legal history, protective orders, and the sources consulted: the client's account, available records, collateral information. Pitfall: history from self-report alone, silently. Note what was and was not available to you; a reviewer treats "no history reported" and "records reviewed, no history found" very differently.
Risk and protective factors. Acute and stable risk factors, and protective factors that are specific and current for this client, not a generic list. Pitfall: boilerplate copied forward unchanged between notes. Reviewers read identical factor lists as evidence the assessment was not individualized, and boilerplate cuts both ways in a courtroom.
Risk formulation. The clinical synthesis: a risk characterization (many settings use low, moderate, or high, for acute and longer-term risk) with the rationale connecting the findings above to it. Any instrument used (HCR-20 V3, VRAG) is an input with its result and date, not the formulation itself. Pitfall: a score or a level standing in for reasoning. Instrument discrimination is modest at the individual level, with a 2025 systematic review reporting median AUCs of 0.68 to 0.71 across four established tools, so the defensible note shows judgment, never prediction language like "client will not act".
Duty analysis, consultation, and decision. Which jurisdiction's standard applies, whether its threshold is met on today's facts, consultation obtained (supervisor, colleague, attorney, risk-management line) with who and when, and the decision reached, expressly including a reasoned decision that no disclosure is indicated. Pitfall: the analysis that only exists when the answer is yes. A decision not to warn that is never documented looks, years later, like a question never asked.
Actions, disposition, and reassessment. Protective actions taken with dates, times, and content (any notification made, hospitalization, means restriction, treatment intensification), the disposition, the dated next contact, and when risk will be reassessed. Pitfall: "will monitor" with no date. Elevated risk documented once and never revisited reads as abandoned, not managed.
Client: [initials] Date: Setting/context: Reason for assessment (statement, ideation, collateral report, referral): Threat inquiry (what was communicated, context, conditional/unconditional, when, to whom, repeated or escalated): Target & identifiability (named/ascertainable, relationship, contact): Intent, capability & access to means (asked directly; steps agreed/verified): History (prior violence, legal history, protective orders; sources consulted): Risk factors (acute / stable): Protective factors (specific to this client, today): Instruments & results (HCR-20 V3, VRAG), with dates, as inputs: Risk formulation (level + rationale connecting findings to decisions): Duty analysis & consultation (standard applied, threshold met or not, who was consulted, decision incl. reasoned decision not to disclose): Actions & disposition (dated/timed notifications, means steps, level of care): Follow-up & reassessment plan (dated next contact, triggers for re-review): Clinician signature/credentials: Date signed:
Free to use and share, no signup. The PDF includes a one-page cheat sheet with section-by-section pitfalls and a pre-sign checklist; the DOCX is the blank template, ready to adapt.
Scenario: adult client in weekly outpatient therapy after a job loss makes an angry statement in session about a former supervisor, and the clinician completes and documents a full risk assessment, consultation, and a reasoned decision that no protective disclosure is indicated. All details are fictional, and the risk content is deliberately generalized: it shows what a defensible note records, not how risk presents.
Client: D.R., 41 · Date: 07/21/2026 · Setting: Outpatient office, scheduled session · Reason for assessment: Statement about a former supervisor made in session
Context and precipitant: Client is in week 7 of weekly therapy for an adjustment disorder with depressed mood following termination from a nine-year position. Client reports escalating rumination about the termination over the past two weeks, disrupted sleep, and drinking above baseline on several evenings. A wrongful-termination claim was declined by an attorney last week, which client describes as "the door closing."
Threat inquiry: While describing the termination, client made a statement to the effect that the former supervisor should be afraid of what client might do. Asked directly about the statement, client described it as venting, denied wanting to harm the supervisor, and denied telling anyone else anything similar. Client reports recurrent angry thoughts about the supervisor over two weeks, brief and intrusive, without rehearsal or imagery of acting. The statement today was conditional and made in frustration; client withdrew it when asked to elaborate. No prior statements of this kind in treatment.
Target and identifiability: The person referenced is a specific named individual known to the client through the former workplace. Client has had no contact since the termination, has no reason to be at the former workplace, and reports no current proximity. Because the person is reasonably identifiable, the duty threshold analysis below was completed and documented.
Intent, capability, and access: Client denies intent to harm, denies any plan, and denies preparatory or rehearsal behavior. Access to means was reviewed directly with the client. One category of concern was identified, and a specific restriction step was agreed with the client and the client's spouse, with verification arranged and recorded in the plan below. Client engaged in the conversation without resistance.
History: No adult history of violence toward persons. One verbal workplace altercation approximately six years ago without physical contact or disciplinary action, per client report. No arrests, no protective orders, no weapons-related incidents reported. Records available to this practice contain no violence history; no collateral records were available at the time of assessment, which is noted as a limit of today's data.
Risk factors: Acute: humiliation-framed loss with a fresh legal setback, escalating rumination, disrupted sleep, alcohol use above baseline, recurrent angry ideation about a specific person. Stable: none identified; no violence history, no prior psychiatric hospitalization.
Protective factors: Engaged in weekly treatment and disclosed spontaneously in session; married with a supportive spouse who is aware of the job loss; financially stable for the near term; active job search with two interviews scheduled; states the supervisor "is not worth my life" and connects acting on anger with losing their family and the career they are rebuilding; no intoxication in session.
Risk formulation: Conditional angry statement about an identifiable person, without stated intent, plan, preparatory behavior, or history of violence, in the context of an acute loss, rumination, and increased alcohol use. Acute risk of harm to the named individual is judged low to moderate and manageable in outpatient care with the steps below; longer-term risk is low. Rationale: the statement was conditional and withdrawn on direct inquiry, intent and planning are denied with a consistent account, means access is being addressed with verification, protective factors are current and specific, and the client engaged openly in the assessment. Foreseeable destabilizers, contact initiated with the former workplace, an escalation in drinking, or a further legal setback, were named with the client and are covered by the reassessment plan.
Duty analysis, consultation, and decision: This state's duty-to-protect standard requires a serious threat of physical violence against a reasonably identifiable victim. On today's facts the threshold is not met: the person is identifiable, but the statement was conditional and withdrawn, intent is denied, and no plan or preparatory behavior is present. Case reviewed same day with clinical supervisor, J.M., PhD, and the practice's risk-management consultation line; both concurred that no notification is indicated on the present facts. Decision: no protective disclosure at this time; intensify treatment and reassess. If intent, a plan, or an unconditional threat emerges, the duty analysis will be repeated immediately and the discharge options under this state's statute will be followed, with the analysis documented.
Actions, disposition, and follow-up: Sessions increased to twice weekly for two weeks; next appointment 07/24/2026, phone check-in 07/22/2026 at 4:30 pm. Means-restriction step to be verified by spouse call on 07/22/2026, with client's written consent obtained in session. Coping plan for rumination and anger arousal reviewed; client agreed to hold alcohol at or below baseline while symptoms are acute and to review this next session. Client verbalized agreement to contact the practice or crisis services if thoughts of harming anyone intensify.
Reassessment plan: Threat content, intent, means status, and alcohol use reviewed at every contact while active; full reassessment at the next session or immediately upon any change, including contact with the former workplace, an intoxicated presentation, or any new statement about the named individual.
This sample is fictional and for educational purposes. It does not describe a real patient, and it intentionally omits the clinical specifics a real record would contain.
Writing these after every session? BastionGPT drafts complete notes from bullets, dictation, or a transcript.
Generate a note from bulletsWrite this note knowing the standard it will be held to: not whether the outcome was predicted, but whether a reasonable assessment process ran and is visible on the page. The confidence gap in the field is documented: in a survey reported in the American Psychological Association's duty-to-protect volume, 90 percent of psychologists were confident in their knowledge of their legal responsibilities with dangerous clients, while "as many as 75 percent of the sample were misinformed" about their legal duties (APA, The Duty to Protect), which is exactly why the note should name the standard applied rather than assume it. The note sits in the ordinary record: the client generally holds access rights to it, it is reachable by subpoena, and the separately kept psychotherapy notes category never covers it (see the psychotherapy notes authorization page). Under the information-blocking rules, withholding it from an access request requires the narrow preventing-harm exception, a reasonable belief that release would "substantially reduce a risk of harm" being prevented, judged case by case (45 CFR 171.201), so write facts, reasoning, and actions rather than speculation. After a bad outcome, never revise the original entry; anything learned later goes in a clearly dated late entry or addendum. In telehealth, the prevailing compliance guidance is to analyze the duty under the law of the state where the client is located during the session, which can change the standard mid-caseload. When a threat situation, a warning, or any legal process touches your documentation, consult your attorney or board; state rules vary. If you or a client needs immediate support: call or text 988 (US), 9-8-8 (Canada), or Lifeline 13 11 14 (Australia).
Keep the legal layers straight, because they carry different weight. The duty is LAW that varies by state: a 2022 National Conference of State Legislatures review classifies roughly 29 jurisdictions as imposing a mandatory duty, 19 as permissive, and 3 as recognizing no duty (NCSL), and the details diverge sharply: California discharges the duty by "reasonable efforts to communicate the threat" to both the victim and law enforcement (Civil Code 43.92(b)), Texas recognizes no duty and makes protective disclosure permissive, to medical, mental health, or law enforcement personnel only, never directly to the victim (Health and Safety Code 611.004), Florida's statute reaches psychiatrists specifically and requires the threat be communicated to a law enforcement agency, which then acts (456.059), and New York's SAFE Act pathway is a separate mandatory report to the director of community services, not to the victim (Mental Hygiene Law 9.46). Federal privacy law is PERMISSIVE, never a duty: HIPAA lets a covered entity disclose in good faith to "prevent or lessen a serious and imminent threat", including to the target, and presumes the good faith (45 CFR 164.512(j)). Two consequences are worth documenting awareness of: in California a qualifying report to law enforcement triggers a five-year firearm prohibition for the client (Welfare and Institutions Code 8100(b)(1)), and in Canada the Supreme Court's public safety exception in Smith v. Jones permits disclosure on clarity, seriousness, and imminence grounds while leaving open whether it is ever required ([1999] 1 S.C.R. 455); Australia's APS Code likewise permits disclosure for "an immediate and specified risk of harm to an identifiable person" (A.5.2(c)) alongside the Privacy Act's serious-threat permission (s 16A). The note itself is CONVENTION everywhere, which is why it matters: it is the only evidence you control that the analysis ran and the duty, where one existed, was met. On the payer side there is no violence-note code to defend; the assessment is reviewed inside whatever service carried it, a crisis encounter or an evaluation, and the action side of a report or warning has its own documentation discipline on the mandated reporting and duty-to-protect page, with client-facing stabilization work in a safety plan.
The audit numbers around this document are generic to psychotherapy records, and they are bad enough: a 2020 HHS Office of Inspector General audit of a psychotherapy practice found 111 of 120 sampled claims non-compliant and estimated at least $3.3 million in Medicare overpayments, with treatment-plan documentation deficiencies on 111 claims and notes signed with digital images of signatures on 109 (A-02-19-01012). The legal exposure is sharper here than for any other note type because most clinicians misjudge their own state's rules: the confidence-versus-accuracy gap reported in APA's duty-to-protect volume ran 90 percent confident against roughly 75 percent misinformed (APA). The BastionGPT Clinical Advisory Board sees the same errors most often in violence risk assessment reviews:
BastionGPT is specifically trained, tuned, and clinically tested on violence and homicide risk assessments.
See how clinicians use it day to day on the AI therapy notes page.
Many BastionGPT users report saving more than 90 minutes per day on documentation.
HIPAA-compliant with a signed BAA on every plan. Your data is never used to train models. BastionGPT drafts, you review and sign.
No statute in the US, Canada, or Australia prescribes a violence risk assessment template, and no professional body has standardized the note as a document format. The obligations are layered instead: the duty to protect that the note evidences is state law that varies from mandatory to none, licensing boards require adequate records everywhere, and the clinical standard of care fills the rest. Most run 300 to 800 words, and the test any format is held to is whether the formulation and the duty analysis explain the actions taken, or the reasoned decision not to act.
No, and the widely repeated claim that they do is false. A 2022 National Conference of State Legislatures review classifies roughly 29 jurisdictions as imposing a mandatory duty, 19 as permissive, and 3 as recognizing no duty, and published counts differ by methodology. Texas is the marquee counterexample: its supreme court declined to adopt Tarasoff in 1999, and its statute makes disclosure permissive, to medical, mental health, or law enforcement personnel only, never directly to the victim (Health and Safety Code 611.004). Read your own state's current statute rather than a national summary, and name the standard you applied in the note.
Warning is one option; protecting is the duty. California's statute is the clearest illustration: it imposes a duty to protect, discharged by "reasonable efforts to communicate the threat" to both the victim and a law enforcement agency, and the 2013 amendment's own text says it only changed the name of the duty (Civil Code 43.92). Depending on the jurisdiction, protective options can include hospitalization, means restriction, intensified treatment, and involving supports, which is why the note documents the protective reasoning, not just whether a phone call was made.
As a decision, not an omission. Record the standard that applies in your jurisdiction, the facts weighed against its threshold (identifiability of the person at risk, the seriousness and conditionality of what was communicated, intent, means, history), the consultation obtained with who, when, and outcome, the conclusion that the threshold was not met, and the specific changes that would reopen the analysis. The sample above shows the pattern. Documented reasoning matters equally in both directions: years later, an undocumented negative decision looks like a question that was never asked.
No regulation reviewed for this page mandates a violence risk instrument in any of the three countries. Structured professional judgment tools such as the HCR-20 V3 organize the factor review, and actuarial scales such as the VRAG estimate group-level recidivism probabilities, but discrimination is modest: a 2025 systematic review found median AUCs of 0.68 to 0.71 across four established instruments, with predictive value hinging on local base rates. Your employer or setting can require a named tool by policy. Either way, record the result as an input with its date, and let the formulation carry the reasoning.
First the duty analysis that led there, then the mechanics: who was contacted, when, by what means, the substance of what was communicated, and any report or reference number law enforcement provided. Your state's discharge formula controls the recipients: California expects efforts to reach both the victim and law enforcement, Florida channels the required notification to a law enforcement agency, which then acts, and New York's separate SAFE Act pathway runs to the director of community services. Enter it the same day, contemporaneously. The notification record itself has a full walkthrough on the mandated reporting and duty-to-protect documentation page.
The violence risk assessment is the evaluation record: the inquiry, the factors, the formulation, and the duty analysis. A mandated report documents a statutory report, child or elder abuse reporting with its own triggers, recipients, and deadlines, and covers the action side when a duty-to-protect notification is made. A safety plan is a client-facing stabilization intervention, not an assessment. A crisis note records an emergent, time-based encounter, which may contain risk assessment reasoning inside it. Risk a client directs at themselves belongs in a suicide risk assessment, the closest sibling of this document.
Generally yes. It lives in the ordinary record, where clients hold access rights under HIPAA and the information-blocking rules, and the separately kept psychotherapy notes category never covers it. Withholding it from an access request requires the preventing-harm exception, which demands a reasonable belief that withholding will "substantially reduce a risk of harm", applied case by case and narrowly (45 CFR 171.201). Write every line knowing the client, their attorney, and a board may read it: facts, reasoning, and actions, without speculation.
Yes. Give it bullets or a dictation from the session, and it drafts a structured assessment with the threat inquiry, identifiability analysis, risk and protective factors, formulation, duty analysis, and actions in the right places for your review. It can also check a finished note before you sign: a formulation with no rationale, a missing identifiability analysis, an undocumented consultation, or actions with no dated follow-up. BastionGPT is HIPAA-compliant with a signed BAA on every plan, and your data is never used to train models.
The compliance claims on this page trace to these authorities, last verified July 2026:
Educational content, not legal or billing advice. Sample notes are fictional. Follow your organization's policies and your board, payer, and jurisdiction requirements.