1 Why this page exists
Most compliance vendors describe risk in the space between a testimonial and a logo wall. We sell a product whose entire premise is that a written, dated record beats a confident assurance. It would be incoherent to make an exception for our own marketing.
So this is the disclosure. It is not buried in a footnote, it is linked from the footer of every page, and it is written so that a practice owner can read it in ten minutes and know exactly what they are and are not buying.
Nothing on this page is legal advice. We are not a law firm. Decisions about your obligations belong with your own counsel, and this page is a description of a product, not a substitute for that conversation.
2 What Consential does
Consential installs a consent layer on your website. It holds non-essential third-party tags — analytics, advertising pixels, retargeting tags — so they do not execute until a visitor makes a choice, then releases only the ones that visitor allowed. It writes every decision to an append-only record carrying a timestamp, a hash of the policy text in force at that moment, and the visitor's state, and it signals that decision to platforms you have configured to receive one.
Alongside that it scans your site against WCAG 2.1 AA on a schedule and produces a dated report, and it flags when your published privacy notice has stopped matching what your website actually does.
What you are buying is evidence and control: a smaller set of uncontrolled disclosures, and a document that says what happened and when.
3 What Consential does not do
- It does not provide legal advice or legal representation.
- It does not guarantee compliance with HIPAA, the ADA, WCAG, any state privacy statute, or any other law. Compliance is determined by a regulator or a court, on the facts of your practice. No vendor can confer it.
- It does not conduct a HIPAA risk analysis for your practice.
- It does not review, draft, or certify the legal sufficiency of your privacy policy, your notice of privacy practices, your terms, or your consent language.
- It does not indemnify you against a regulatory action, a demand letter, or a lawsuit, beyond the specific indemnities in section 11 of the Terms of Service.
- It is not, and does not include, an accessibility overlay. We will not ship one at any price.
- It does not make your practice's other obligations go away. Your business associate agreements with other vendors, your training, your policies and your breach response remain yours.
4 Detection is not exhaustive
This is the most important residual risk in the product, so it gets stated first among them.
The consent layer governs what the browser loads on a page where the widget is installed. Several categories of tracking sit outside that reach:
- Server-side tracking. A conversions API or a server-to-server integration sends data from your server, not from the visitor's browser. A browser-side consent layer cannot see it and cannot stop it.
- Tags hardcoded into theme files or injected by a plugin, on pages where the widget is not installed or loads after them.
- Third-party iframes — booking widgets, review embeds, chat, call tracking — which run in their own context under their own rules.
- Anything added after installation. A new plugin, a new campaign tag, or an agency adding a pixel next month can reintroduce exposure. The scheduled scan exists to catch exactly this, but it catches it after it happens, not before.
- Misconfiguration. If a tag is categorised as essential when it is not, the layer will release it, correctly, on your instruction.
Our scan surfaces what it can find. Acting on the finding is yours, and a finding that nobody reads changes nothing.
5 Consent is not a universal defence
A recorded consent is evidence that a visitor was asked and answered. It is not a blanket authorisation.
HIPAA distinguishes consent from a valid authorisation under 45 CFR § 164.508, which has formal content requirements a website banner does not meet. A number of state wiretap and session replay theories turn on whether a party to the communication consented, and in several of them the liability follows the visitor's state rather than yours. Some disclosures are not curable by consent at all.
What the record does is let you show what was asked, what was answered, and when. That is frequently the question in dispute, and it is worth a great deal. It is not the same as immunity.
6 Automated accessibility scanning is partial by nature
Automated rules reliably catch a real but incomplete share of what disabled patients actually encounter. Reading order that is technically valid but clinically nonsensical, a form that is navigable but incomprehensible, a video that needs described audio — none of these is a defect an engine can settle.
A clean scan is not a conformance claim, and our reports never state one. Nothing replaces testing with a human being who uses assistive technology. And a fix does not stay fixed: a theme update can reintroduce any of it, which is why monitoring is a subscription and repair is not.
7 The record cuts both ways
We think you should hear this from us rather than from opposing counsel.
An append-only, timestamped archive of what your website did is powerful evidence. It is powerful in whichever direction the facts run. If your site disclosed something before a visitor agreed, the record will show that too, precisely and with a date, and it is discoverable.
We believe that is still the right trade — the alternative is not innocence, it is an absence of evidence, and the practices that fare worst in these matters are usually the ones who cannot say what happened. But it is a genuine consequence of installing this product and you should take it into account, with counsel, before you do.
8 The legal landscape is unsettled and moving
This product sits on rules that are actively contested. The OCR bulletin on online tracking technologies was vacated in part in American Hospital Association v. Becerra (N.D. Tex., 20 June 2024), which struck the portion addressing the combination of an IP address with a visit to an unauthenticated public webpage. State consumer health data statutes in Washington, Nevada and Connecticut reach further than HIPAA in some respects and are largely untested. Roughly twenty states have comprehensive privacy laws with differing opt-out mechanics, and more arrive each session.
Any characterisation of the law on this website, including our per-state material, is our current reading and not settled law. It may be wrong, and it will change. We date what we publish so you can tell how old a reading is, and we will correct it when it moves.
9 Vendor, continuity, and concentration risk
Consential is a small company and a young product. Reasonable diligence includes asking what happens if we stop operating.
Our answers: your records are exportable at any time, in a machine-readable format, free, under section 13.3 of the Terms — and that right is not conditioned on your account being paid up. Removing the widget removes the consent layer from your site cleanly. The archive is yours and is transferred to you rather than destroyed.
What we cannot offer today: a third-party escrow arrangement, a published recovery-time objective, or a SOC 2 report. If any of those is a procurement requirement for you, we are not yet the right vendor, and we would rather tell you that here than discover it in a questionnaire.
10 Our own maturity, stated plainly
The controls that are actually running are described, and dated, on our Security page, which is deliberately limited to controls in place today rather than controls that are planned. The subprocessors in the path, including where consent records are physically stored, are named in DPA Schedule 2, including the parts of that architecture that are still being moved.
We publish those two pages in that form on purpose. A trust page that describes an intended architecture as though it were running is the specific failure this company exists to argue against.
11 Financial limits on our liability
Our liability is capped. Section 10 of the Terms of Service limits total aggregate liability to the fees paid or owed in the twelve months before the claim, with carve-outs for indemnities, confidentiality, PHI obligations under the BAA, and anything that cannot lawfully be limited.
Read that against the numbers in your own risk register. A subscription of a few thousand dollars a year does not, and is not priced to, underwrite a settlement. Insurance underwrites settlements; this product reduces the probability of one and improves your position if it happens. If you need risk transfer, buy risk transfer, and talk to your broker about whether your existing cyber and professional liability policies respond to a pixel-based claim — many practices discover late that they do not.
12 What to do with this page
Give it to your counsel and to your broker before you buy, not after. Then run the free scan on your own site and read what it finds — it names specific elements on specific pages, it costs nothing, and it will tell you more about your actual exposure than any vendor page including this one.
If something here is unclear, or you think it is wrong, write to Contact. Corrections to this page get made and dated.