Consent management for medical practices

Control website tracking before patient data is collected.

Consent management designed for medical practices. Block non-essential tracking, document patient choices, and keep connected systems aligned.

Scan Your Site Free
  • Built for medical practices
  • AWS-hosted
  • Encrypted audit logs
  • WordPress + GHL compatible
samplemedicalpractice.com
  1. Page Load
  2. 2 Tracking Blocked Until Consent
  3. 3 Consent Granted, Safe to Load

Non-essential tracking blocked until a choice is made.

GA4 Google Ads Meta Pixel GTM

The product

Compliance isn't a promise.
It's a paper trail.

Every vendor in this category sells you a feeling. Consential produces a document: what was running on your site, what a patient chose, what changed since last month, and the date each of those was true. It arrives whether or not anyone on your team opens it.

At page load

Consent is enforced

Non-essential trackers stay dark until the visitor chooses. Consent Mode v2 signals go out in the right order.

Continuously

The record is written

Append-only at the database level. Corrections are new entries, never overwrites. Six-year retention.

Every cycle

The site is re-observed

Accessibility scanned against WCAG 2.1 AA. Live scripts compared to what your configuration declares. Policy age checked.

Every month

The evidence is delivered

A dated report with your domain on it, showing what was found, what changed, and what it means. Nobody has to request it.

Compliance Evidence Report

samplemedicalpractice.com · cycle 07 · 2026-07-25
B+WCAG 2.1 AA
Consent events recorded4,182
Non-essential scripts heldGA4 · Ads · Meta · GTM
Undeclared trackers found1 — clarity.ms
Accessibility findings9 open · 14 closed
Privacy policy last revised2024-11-02 · 20 mo
Record integritychain verified

Append-only. Hash-chained daily. Retained six years.

Sample report. Figures are illustrative, not a customer's data.

Consent module

Three controls, one script tag.

Tracking Control

Non-essential scripts stay dark until a visitor takes an affirmative, granular opt-in action across Essential, Analytics, Marketing, and Communications. Google Consent Mode v2 compatible, so GA4, Meta Pixel, Google Ads, and GTM only fire once gatekeeping rules allow it.

Audit Trail

Maintain documented, append-only consent records — nothing is edited or deleted after the fact, only added to.

Preference Center

Patients can view, update, or revoke consent by category anytime, without contacting the practice. Every change appends to the record — patient rights management, handled end to end.

Process

How Consential.io Works

  1. 01

    Configure your practice

    Set domains, scripts, and granular consent categories — Essential, Analytics, Marketing, Communications — plus state-level jurisdiction rules for CCPA, VCDPA, CPA, and CTDPA opt-out rights.

  2. 02

    Install the consent layer

    Add a lightweight, Google Consent Mode v2-compatible snippet to your site. Gatekeeping functionality blocks every non-essential script until a visitor acts.

  3. 03

    Capture visitor choices

    Visitors see a clear banner and take an affirmative, granular opt-in action — accept, decline, or customize by category. Every choice is written to the append-only audit trail.

  4. 04

    Sync preferences downstream

    Approved tracking releases instantly, and HMAC-signed webhooks push the decision to GoHighLevel, your CRM, or any endpoint tied to your practice-scoped API key.

Scale

Designed for practices with 1-5 locations

1 Location

  • Centralized oversight from a single dashboard
  • Support for one primary domain
  • Branded consent banner and preference center
  • Reports for your practice and your team

Most common

2-3 Locations

  • Centralized oversight across locations
  • Support for multiple domains and subdomains
  • Consistent branding across all locations
  • Location-level and rollup reporting

4-5 Locations

  • Centralized oversight with role-based access
  • Support for multiple domains and providers
  • Custom branding per location if needed
  • Advanced reporting and audit exports
Medical practice staff member speaking with a patient by phone at a front-desk workstation

Built for healthcare-sensitive environments

We follow industry best practices to protect patient trust and strengthen your practice's compliance posture.

Built around HHS Office for Civil Rights (OCR) guidance on tracking technologies on covered-entity websites and apps — issued December 2022, with enforcement actions ongoing.

Encryption

Data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Role-Based Access

Granular permissions ensure the right access for the right people.

Consent Records Retained

Append-only audit logs with secure, long-term retention.

Practice-Level Agreements

Business Associate Agreements (BAA) available upon request.

AES-256 encryption TLS 1.2+ in transit AWS HIPAA-eligible infrastructure BAA available 6-year audit retention

Connected systems

WordPress GoHighLevel Google Analytics Google Ads Meta Webhooks API

Pricing

Billed per practice, not per visitor.

Consential.io runs on AWS HIPAA-eligible infrastructure, with audit logs retained six years to meet the HIPAA minimum. First rolling out across EFFVIT's own VMMG hair restoration and aesthetics client fleet.

Consent

$199/mo

One practice, one domain.

  • Consent gate, deny by default
  • Append-only audit log, six years
  • Google Consent Mode v2
  • State-aware notices
  • Patient preference center
  • CRM sync and signed webhooks
See pricing

Most popular

Consent + Disabilities

$299/mo

Both compliance surfaces, one install.

  • Everything in Consent
  • Scheduled WCAG 2.1 AA scans
  • Conversion-path-first discovery
  • Platform-aware remediation guidance
  • Timestamped evidence report each cycle
See pricing

Multi-location

Custom

Groups, networks, and several domains.

  • Multi-location rollup
  • White-label option
  • Full API access, practice-scoped keys
  • Dedicated support

Important: Consential provides technical consent management infrastructure for healthcare websites. It is not legal advice, does not guarantee regulatory compliance, and does not replace a comprehensive HIPAA compliance program. Your attorney should review all consent language before deployment. See our full Risk Disclosure for details.

FAQ

Questions practices ask before switching.

Do you sign a BAA?

Yes. Consential.io is built for HIPAA-covered practices, and a Business Associate Agreement is available at the practice level before you go live.

How is this different from a cookie banner plugin?

A cookie plugin styles a banner. Consential gates the scripts themselves — GA4, Meta Pixel, Google Ads, and GTM stay dark until a visitor takes an affirmative, granular action, and every decision writes to a database-level, append-only audit trail that can't be edited or deleted after the fact.

Does this work with GoHighLevel or other CRMs?

GoHighLevel is a first-class integration on the Professional tier. Every other CRM, ad platform, or internal tool connects through universal, HMAC-signed webhooks and a practice-scoped API key.

Does it detect state privacy laws automatically?

Yes. The consent layer detects visitor jurisdiction and applies the relevant opt-out framework — CCPA, VCDPA, CPA, or CTDPA — alongside your HIPAA-driven tracking controls. See how state privacy detection works.

What happens to data if I cancel?

Consent records are retained for the HIPAA minimum of six years, exactly as captured — nothing is rewritten or deleted. Your active tracking gate simply turns off.

How long does setup take?

In this phase, EFFVIT installs the consent layer for you — configuring domains, categories, and jurisdiction rules — rather than a self-serve signup. Most single-location practices are live within a few business days of kickoff.

Read all 37 questions

See what's running on your website today.

Run a free live scan and see exactly which trackers fire before a patient consents — in about 15 seconds, no signup. Prefer a hand review? We'll do one too.