← All posts

October 10, 2026 · 8 min read

Is GoHighLevel HIPAA Compliant? BAA, $297 Add-On and Setup Guide (2026)

Arslan Mumtaz

By Arslan Mumtaz, software engineer and GoHighLevel & AI automation specialist

Clinics, med spas, chiropractors and therapists ask the same question before moving patients into GoHighLevel: is it HIPAA compliant? Out of the box, no. With HighLevel's HIPAA add-on and a signed Business Associate Agreement (BAA), it can be part of a HIPAA-compliant setup, as long as you configure it properly and handle the parts the add-on doesn't cover. This guide explains what the add-on does, what it costs, how to turn it on, and the mistakes that still put practices at risk.

1. The short answer

GoHighLevel is not HIPAA compliant by default. HighLevel sells an optional HIPAA compliance add-on that provides a BAA, encryption of the data that can hold protected health information (PHI), enforced multi-factor authentication and audit logs. With the add-on enabled on the right sub-accounts, the GoHighLevel platform can be used for PHI. Your practice (or agency) is still responsible for everything around it: policies, training, user access, what you send in messages, and any other tools connected to GoHighLevel.

2. Who needs to care about HIPAA

Remember that the fact someone is your patient is itself PHI. A contact record with a name, phone number and an appointment at a clinic counts, not just medical notes.

3. What the GoHighLevel HIPAA add-on includes

ItemDetails
Business Associate AgreementSigned inside the app after purchase
EncryptionAES-256 for data that can hold PHI: contacts, notes, custom fields, SMS/MMS, voice recordings, email bodies and attachments, form and survey submissions, calendars and invoices
Access securityEnforced multi-factor authentication and role-based permissions
Audit logsRecords of user activity, needed for HIPAA's audit controls
Compliance documentsViewed, signed and downloaded in the app

4. What it costs, and the catch

For a single practice that's a real ongoing cost, so decide before you buy. For an agency with several healthcare clients, it's usually built into the monthly price of those accounts.

5. How to turn HIPAA on in GoHighLevel

  1. In Agency view, buy the HIPAA add-on (monthly or annual).
  2. Go to Settings → Compliance and sign the Business Associate Agreement.
  3. Wait for activation. HighLevel says this takes 48–72 hours.
  4. Go to Sub-Accounts → the clinic's sub-account → Advanced Settings and switch on the HIPAA setting. Do this for every sub-account that will hold PHI; it isn't automatic.
  5. Review user roles in each sub-account so staff only see what they need, and check every user has MFA working.

Moving a HIPAA-enabled sub-account to another agency only works if that agency also has the HIPAA add-on.

6. What the add-on doesn't cover

For AI features such as Conversation AI and Voice AI, confirm with HighLevel which are covered by the BAA before letting them handle PHI.

7. Texting and emailing patients safely

8. Keep clinical records in your clinical software

Even with HIPAA enabled, GoHighLevel isn't an electronic health record. The setup that works best keeps clinical notes, charts and treatment details in your practice software (Dentrix, Cliniko, Jane, an EHR) and uses GoHighLevel for the patient journey: enquiries, booking, reminders, recalls and reviews. Sync only the fields GoHighLevel needs, such as appointment dates and recall due dates. See how this works in automated patient recall and the dental clinic case study.

9. Outside the US

HIPAA is a US law. In the UK and EU, health data is "special category" data under GDPR, with its own rules on lawful basis, security and processors; see GoHighLevel and GDPR. Australian clinics fall under the Privacy Act and, for SMS marketing, the Spam Act.

10. HIPAA checklist for GoHighLevel

  1. HIPAA add-on bought and BAA signed.
  2. HIPAA switched on in every sub-account that holds patient data.
  3. MFA working and user roles limited to what each person needs.
  4. Every connected tool either has a BAA or receives no PHI.
  5. Message templates reviewed: no diagnoses or treatment details.
  6. Consent to text and email recorded on each patient.
  7. Clinical notes kept in the practice software, not the CRM.
  8. Agency and clinic BAA in place if an agency manages the account.
  9. Risk assessment and staff training documented.

This is general information, not legal advice. Your compliance adviser has the final say on what your practice needs.

Need a HIPAA-ready GoHighLevel setup?

I'm Arslan Mumtaz, a software engineer who builds GoHighLevel systems for clinics and the agencies that serve them, including chiropractic, med spa and dental builds, with integrations kept inside your compliance boundary. See pricing, or start with a $97 audit.

Work with me

Still losing leads to voicemail or slow follow-up?

I build speed-to-lead, retention and AI automation systems in GoHighLevel, with custom code where the platform falls short.

More articles