Clinics, med spas, chiropractors and therapists ask the same question before moving patients into GoHighLevel: is it HIPAA compliant? Out of the box, no. With HighLevel's HIPAA add-on and a signed Business Associate Agreement (BAA), it can be part of a HIPAA-compliant setup, as long as you configure it properly and handle the parts the add-on doesn't cover. This guide explains what the add-on does, what it costs, how to turn it on, and the mistakes that still put practices at risk.
1. The short answer
GoHighLevel is not HIPAA compliant by default. HighLevel sells an optional HIPAA compliance add-on that provides a BAA, encryption of the data that can hold protected health information (PHI), enforced multi-factor authentication and audit logs. With the add-on enabled on the right sub-accounts, the GoHighLevel platform can be used for PHI. Your practice (or agency) is still responsible for everything around it: policies, training, user access, what you send in messages, and any other tools connected to GoHighLevel.
2. Who needs to care about HIPAA
- Covered entities: US healthcare providers that bill insurance electronically, health plans and clearinghouses. This includes most dental, chiropractic, physio, medical and mental health practices.
- Business associates: companies that handle PHI for a covered entity. If your agency builds and manages GoHighLevel for clinics, you're one, and HighLevel is your subcontractor.
- Cash-pay clinics such as some med spas may not be covered entities, but state health privacy laws can still apply. Ask your lawyer; treating patient data as PHI is the safer default.
Remember that the fact someone is your patient is itself PHI. A contact record with a name, phone number and an appointment at a clinic counts, not just medical notes.
3. What the GoHighLevel HIPAA add-on includes
| Item | Details |
|---|---|
| Business Associate Agreement | Signed inside the app after purchase |
| Encryption | AES-256 for data that can hold PHI: contacts, notes, custom fields, SMS/MMS, voice recordings, email bodies and attachments, form and survey submissions, calendars and invoices |
| Access security | Enforced multi-factor authentication and role-based permissions |
| Audit logs | Records of user activity, needed for HIPAA's audit controls |
| Compliance documents | Viewed, signed and downloaded in the app |
4. What it costs, and the catch
- $297 per month or $2,970 per year, on top of your normal HighLevel subscription.
- Available on every agency plan and bought once for the whole agency.
- It can't be cancelled, refunded or downgraded once enabled. The per-sub-account HIPAA setting can't be switched off either.
For a single practice that's a real ongoing cost, so decide before you buy. For an agency with several healthcare clients, it's usually built into the monthly price of those accounts.
5. How to turn HIPAA on in GoHighLevel
- In Agency view, buy the HIPAA add-on (monthly or annual).
- Go to Settings → Compliance and sign the Business Associate Agreement.
- Wait for activation. HighLevel says this takes 48–72 hours.
- Go to Sub-Accounts → the clinic's sub-account → Advanced Settings and switch on the HIPAA setting. Do this for every sub-account that will hold PHI; it isn't automatic.
- Review user roles in each sub-account so staff only see what they need, and check every user has MFA working.
Moving a HIPAA-enabled sub-account to another agency only works if that agency also has the HIPAA add-on.
6. What the add-on doesn't cover
- Other tools you connect. The BAA covers HighLevel's platform. Zapier, Make, n8n, a booking tool, an AI service or your own server receiving webhooks each need their own BAA, or must never receive PHI. A self-hosted n8n on servers you control is one way to keep integrations in scope.
- Your own HIPAA programme: a risk assessment, written policies, staff training, a privacy officer and breach procedures.
- Agency obligations: agencies need their own BAA with each clinic client before handling their PHI.
- Message content. Encryption protects data stored in GoHighLevel, but a text message still travels over the phone network and sits on the patient's phone.
- Devices and logins. Shared logins, unlocked phones and staff exporting contact lists to spreadsheets are still risks.
For AI features such as Conversation AI and Voice AI, confirm with HighLevel which are covered by the BAA before letting them handle PHI.
7. Texting and emailing patients safely
- Keep messages minimal: "Reminder: your appointment with Bright Smile Dental is Tuesday at 10am. Reply C to confirm." Leave out diagnoses, treatment details and test results.
- Don't put PHI in email subject lines or SMS previews.
- Send detail through a secure route, such as a patient portal, rather than in a text.
- Get consent: record patients' permission to be contacted by text and email, and their preferences.
- Marketing is different from care. Appointment reminders and recalls are normally fine; promotional campaigns to patients using their health information need more care and may need written authorisation.
- US texting rules still apply: register your numbers through A2P 10DLC.
8. Keep clinical records in your clinical software
Even with HIPAA enabled, GoHighLevel isn't an electronic health record. The setup that works best keeps clinical notes, charts and treatment details in your practice software (Dentrix, Cliniko, Jane, an EHR) and uses GoHighLevel for the patient journey: enquiries, booking, reminders, recalls and reviews. Sync only the fields GoHighLevel needs, such as appointment dates and recall due dates. See how this works in automated patient recall and the dental clinic case study.
9. Outside the US
HIPAA is a US law. In the UK and EU, health data is "special category" data under GDPR, with its own rules on lawful basis, security and processors; see GoHighLevel and GDPR. Australian clinics fall under the Privacy Act and, for SMS marketing, the Spam Act.
10. HIPAA checklist for GoHighLevel
- HIPAA add-on bought and BAA signed.
- HIPAA switched on in every sub-account that holds patient data.
- MFA working and user roles limited to what each person needs.
- Every connected tool either has a BAA or receives no PHI.
- Message templates reviewed: no diagnoses or treatment details.
- Consent to text and email recorded on each patient.
- Clinical notes kept in the practice software, not the CRM.
- Agency and clinic BAA in place if an agency manages the account.
- Risk assessment and staff training documented.
This is general information, not legal advice. Your compliance adviser has the final say on what your practice needs.
Need a HIPAA-ready GoHighLevel setup?
I'm Arslan Mumtaz, a software engineer who builds GoHighLevel systems for clinics and the agencies that serve them, including chiropractic, med spa and dental builds, with integrations kept inside your compliance boundary. See pricing, or start with a $97 audit.