ConsentOS: what five-tier consent architecture looks like in practice
Most healthcare organizations treat consent as a single checkbox. A five-tier consent architecture separates identity verification, data use authorization, purpose-specific permissions, downstream sharing controls, and revocation rights into distinct, auditable layers. ConsentOS operationalizes all five tiers so every health data record carries machine-readable consent metadata before any AI model touches it.
Patient consent in healthcare is not a single event. It is a stack of decisions, each with different scope, different expiration, and different downstream consequences. Treating consent as a binary yes/no checkbox is how health systems end up training AI models on data that patients never authorized for that purpose.
ConsentOS exists because that checkbox model is broken. Here is what a five-tier consent architecture looks like when it actually works.
Why consent needs tiers, not checkboxes
A 2023 study in the Journal of the American Medical Informatics Association found that 68% of patients could not accurately describe what they had consented to after signing a standard hospital intake form. The problem is not patient literacy. The problem is that a single signature is being asked to cover identity verification, treatment authorization, research participation, third-party data sharing, and future AI model training simultaneously.
No single consent event can carry that much weight. Each of those decisions has a different risk profile, a different time horizon, and a different set of downstream actors. Collapsing them into one form creates legal exposure for institutions and erodes trust for patients.
This is the core problem why consent governance fails in healthcare data and why a purpose-built architecture is required.
The five tiers of ConsentOS
ConsentOS structures patient consent into five discrete, machine-readable tiers. Each tier is independently granted, tracked, and revocable.
Tier 1: Identity verification consent. The patient confirms who they are and authorizes the organization to link records to their verified identity. This is the foundation layer. Without it, every downstream consent decision is unanchored.
Tier 2: Data use authorization. The patient authorizes specific data types (lab results, imaging, genomic data, behavioral health records) for specific clinical purposes. This is where substance use disorder data and mental health data receive the segmented handling that 42 CFR Part 2 and state privacy laws require.
Tier 3: Purpose-specific permissions. The patient grants or withholds consent for each use case: direct care, quality improvement, research, AI model training, commercial analytics. A patient might consent to research use but block commercial analytics. This tier makes that distinction enforceable.
Tier 4: Downstream sharing controls. The patient specifies whether their data can be shared with third parties, which third parties, and under what conditions. This tier addresses the gap that HIPAA does not cover: the difference between a covered entity's use and a business associate's re-use.
Tier 5: Revocation and expiration. Every consent decision carries a time-bound scope and a revocation mechanism. Patients can withdraw consent at any tier without affecting the other tiers. Revocation propagates to every system that received data under that consent grant.
What are the 5 components of consent?
Traditional medical ethics defines five components of informed consent: disclosure (the provider shares relevant information), comprehension (the patient understands it), voluntariness (no coercion), competence (the patient has decision-making capacity), and authorization (the patient agrees). ConsentOS maps these five components into each of its five tiers, ensuring that every tier independently satisfies all five ethical requirements rather than assuming a single signature covers everything.
What are the 5 steps of the consent process?
The operational consent process follows five steps: (1) present the specific request in plain language, (2) verify the patient understands the scope and consequences, (3) document the patient's decision with a timestamp and context, (4) propagate the decision to all systems that need to enforce it, (5) provide a mechanism for the patient to review and modify their decision at any time. Most health systems execute steps 1 through 3 on paper and skip steps 4 and 5 entirely. ConsentOS automates all five.
What are the five types of consent?
Healthcare consent literature identifies five types: explicit consent (written or verbal affirmative grant), implicit consent (inferred from action, such as presenting for treatment), opt-in consent (active selection required), opt-out consent (assumed unless the patient objects), and broad consent (a general authorization for future unspecified uses). ConsentOS requires explicit consent at every tier. Broad consent and implied consent do not meet the evidentiary standard required for AI training data governance.
What are the 5 components of consent fries?
Planned Parenthood's FRIES framework defines consent through five lenses: Freely given, Reversible, Informed, Enthusiastic, and Specific. While originally developed for a different context, these components map directly to health data consent. ConsentOS enforces all five: consent must be uncoerced (freely given), revocable at any tier (reversible), backed by plain-language disclosure (informed), affirmatively granted rather than passively assumed (enthusiastic), and scoped to a defined purpose and data type (specific).
Key statistics
How ConsentOS fits into the Data Trust Index
Consent is not a standalone concern. It is one of eight dimensions the DTI Engine scores on every health data record: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%). A record with perfect quality scores but no verifiable consent metadata will fail DTI scoring. This is by design.
The chain of custody problem intersects directly with consent: you cannot prove a patient authorized a specific use if you cannot prove which version of the record was in play when consent was granted. ConsentOS and the DTI Engine share a common provenance backbone for this reason.
For organizations navigating pediatric data governance, ConsentOS supports proxy consent with automatic transition workflows when a minor reaches the age of majority.
What this means for AI training data
The HIPAA consent gap for AI training is real. HIPAA was written for treatment, payment, and operations. It was not written for training a machine learning model on 10 million patient records. Without tier-level consent tracking, health systems cannot answer a basic question: did this patient authorize their data for this model's training set?
ConsentOS answers that question at the record level, in real time, with an audit trail.
The DTI Engine scores every health data record 0 to 100 across 8 trust dimensions before your AI model sees it. If your team is evaluating data for training, compliance, or clinical use, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.
Further reading:

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
DTI scores the record, not the patient.
8 dimensions. 0–100. Travels with every record permanently.