● In development · free core, coming to WordPress.org

Consent Ledger

Collect patient intake and consent on your WordPress site and keep a record you can stand behind: the exact wording each person agreed to, when, from what device, e-signed, sealed in a tamper-evident chain you can verify with one click. No data leaves your server.

Get notified when it launches →

A patient intake and consent form: name, date of birth, email, two consent sections to agree to, and a typed signature

A stored form is not a defensible record

Most sites collect consent with a general form plugin. It saves a submission — but it does not prove what the person agreed to, and it does not show whether the record has been edited since. Change the consent wording on your site a year later and the old submissions say nothing about what those people actually saw. Edit a row in the database and nothing flags it.

For a health or wellness practice, a clinic, a gym, or anyone who might one day have to show a consent was genuinely given, that gap is the whole problem. Consent Ledger closes it, and does one thing well.

What makes it different

A general form plugin

  • Stores a submission
  • Loses what wording the person saw when you edit the form
  • No signal if a record is edited or deleted
  • No signature, IP or device on the record
  • Often sends data to a third-party service

Consent Ledger

  • Records a sealed, verifiable consent
  • Pins the exact wording shown, forever, per record
  • One-click check catches any edit, deletion or reorder
  • Typed signature, IP, device and UTC time captured
  • Zero external calls — everything stays on your server
SHA-256every record hash-sealed and chained
0external calls — no third-party service
GPLfree core, your data in your database

How the seal works

Each consent is fingerprinted

When someone submits the form, the plugin takes a SHA-256 hash of the record — the intake answers, the exact consent wording they saw, the signature, the time, the IP and the device.

Records are chained

Each record's hash also folds in the hash of the record before it, like numbered, initialled pages in a ledger. The records form a chain, not a loose pile.

Any change shows

Edit a record, delete one, or reorder them, and its hash no longer matches — and every record after it breaks too. One click verifies the whole ledger and points to exactly where it broke.

See it working

The front-end intake and consent form as a patient sees it
The intake and consent form, as a patient sees it
The admin records ledger showing a green banner: two records verified, the ledger is intact, with per-record seals
The records ledger, with the one-click integrity check

Details that matter

The wording is pinned

The consent text a person saw is stored with their record and hashed. Change the wording on your site later and old records still show what those people actually agreed to — not today's version.

The context is captured

Date and time in UTC, the connecting IP address, the device (user agent), and a typed signature are recorded with each consent. Not a bare "submitted at".

Nothing leaves your server

No third-party service, no external API call, no account. Every record stays in your own WordPress database. That is a deliberate design choice, and a privacy one.

You write the wording

Your intake questions, your consent language. The plugin records what a person agreed to; it does not put words in your mouth. An example form is included and clearly marked to be replaced.

Export any time

The full ledger — every field and every hash — exports to CSV, so your records are portable and never locked in.

It pairs with what you use

Consent Ledger does not do booking or payments. Drop it beside whatever tools you already run; it handles the one thing they leave out.

What it is not — plainly

  • It is not legal advice, and it does not supply consent wording. Only you know what your practice and jurisdiction require.
  • "Defensible" means the record is tamper-evident and complete — not that it is automatically legally sufficient. That depends on your wording and your obligations.
  • It is not, by itself, a HIPAA compliance program. It keeps a better record and stores it only on your server; it does not replace a signed BAA with your host or your own policies.

Not out yet — get the launch note

Consent Ledger is in development and heading to the WordPress.org plugin directory. Leave your email and I'll tell you the day it's available. No newsletter, no spam, just that one note.

Prefer to talk first? Get in touch.