Consent Management

Your website is telling ad platforms who's asking about a procedure.

Not your booking system. Not your EHR. Your public website. On a typical practice site, analytics and advertising tags fire the instant a page opens — on the procedure page, on the consultation page, on the form. Nobody agreed to it, because there was nothing to agree to.

Dec 2022HHS/OCR guidance on tracking technologies. Enforcement is ongoing, not theoretical.
0/100Score of the first practice website we ran through our own scanner.
~20US states with their own consumer privacy law layered on top of HIPAA.
6 yearsHow long HIPAA expects documentation to survive. Most banners keep none.

The problem

What happens between the click and the page

A prospective patient searches for a procedure, clicks your ad, and lands on the page you built for exactly that moment. Here is the part nobody sees.

  1. The page starts loading. So does everything attached to it.

    Google Analytics, the Meta Pixel, Google Ads conversion tracking, a tag manager, and often a session recorder or heatmap tool all begin firing before the page finishes painting.

  2. Each tag receives the URL. The URL names the procedure.

    A request to /hair-transplant-consultation is not a neutral page view. It is a statement about why that specific person is on your site.

  3. The identity is already in the browser.

    The advertising cookie was set on a different site weeks ago. Paired with the IP address and the page path, this stops being anonymous traffic and starts being a named person associated with a medical interest.

  4. The form gets watched too.

    Session recorders capture keystrokes in form fields by default. That includes the fields a patient fills in before they ever press submit.

Nothing in that sequence waited for permission. By the time your cookie notice renders — if you have one — the disclosure has already happened.

Why the usual fix isn't one

Most cookie banners announce the problem. They don't stop it.

The banner on a typical practice site was installed to look responsible. Three things it usually isn't doing:

It's a notice, not a gate

Display-only banners tell a visitor that tracking exists. They don't hold the scripts. The tags fired while the banner was still rendering, and the click changes nothing about what already left.

It doesn't know your pages carry health intent

General-purpose consent tools were built for retail and publishing. They treat a treatment page and an About page identically, because in every other industry they are identical.

It leaves no record you can produce

A cookie set in the visitor's own browser is not documentation. If someone asks what a specific visitor was shown and what they chose on a specific date, a browser cookie cannot answer, and the visitor cleared it in March anyway.

And now it costs you data too

The consent signal became the measurement signal

Google Consent Mode v2 is the mechanism a linked Google Ads account uses to interpret consented and non-consented traffic. Google Signals stopped acting as a backstop on 15 June 2026.

Before that date, a missing consent signal degraded your reporting. After it, a missing consent signal means the platform has nothing to model from. This is the rare case where the compliance-correct configuration and the performance-correct configuration are the same configuration — and running neither costs you both.

The honest test

Three questions most practices can't answer

  • What is firing on my site right now?

    Not at launch — right now. Sites drift. A plugin update adds a pixel, a new landing page ships with a stray tag, someone installs a chat widget on a Friday. The list you approved and the list that runs are two different lists, and nothing tells you when they diverge.

  • What did this visitor see, and what did they choose, on this date?

    A defensible answer is a timestamped row with the banner version, the categories offered, and the choice made. Not a screenshot of what the banner looks like today.

  • When a patient withdraws consent, does anything downstream actually change?

    In most setups the pixel stops and the CRM keeps going. The record that started life as a consented lead stays in the nurture sequence, because nothing told the CRM the answer changed.

What Consential does

One gate on the way in. One record on the way out.

Consential is a consent layer built for sites where the page path itself is sensitive. It installs once, runs without anyone on your team touching it, and produces the documentation the banner never did.

Deny by default

Non-essential tags are held before they execute, not asked to behave afterward. Nothing in the analytics or advertising category runs until a visitor makes a choice.

An append-only record

Every choice is written to a log where updates and deletes are revoked at the database permission level, so the history can't be quietly rewritten later — including by us.

Consent Mode v2, signalled correctly

The consent state is passed to Google in the format it expects, so consented traffic measures properly instead of disappearing into a gap.

The choice travels downstream

Consent state syncs to the CRM and to any connected system via signed webhooks, and a hosted preference center lets a patient change or withdraw it later without emailing your front desk.

Two more things per scan cycle

The configuration stays honest on its own

A consent layer is only accurate on the day it's configured. Two checks ride the regular scan cycle so it stays accurate afterward — neither requires anyone to remember anything.

Script drift

Every cycle observes the scripts, pixels and cookies actually loading and compares them against what your consent configuration declares. Banner covers six trackers, scan finds nine, the gap appears in the report.

When no configuration has been supplied it says so, rather than reporting all clear. A false all-clear never gets investigated.

Privacy policy staleness

The same cycle reads your policy page and flags when it hasn't been revised in over a year, when it names vendors no longer on the site, when vendors are on the site but absent from the policy, and when state privacy laws have taken effect since its last revision date.

These are recorded as observations. Whether any of them is a legal problem is your counsel's call, not ours.

What this is, and what it isn't

Consential is consent infrastructure. It is not a law firm, it does not provide legal advice, and installing it does not by itself satisfy HIPAA, any state privacy law, or any other regulation. What it does is make your posture real and documented instead of assumed: tracking held until a choice is made, that choice written down with a timestamp, and a record your attorney can actually work from. Your counsel should review your consent language before it goes live. See the full Risk Disclosure.

Find out what your site is actually doing

The scanner loads your site fresh in a real browser and reports what fires before any consent interaction — named tags, named cookies, with timestamps. It takes about a minute and tells you where you stand before anyone tries to sell you anything.