HighLevel and HIPAA
Updated 2026-09-19
HighLevel offers a HIPAA compliance add-on that provides a business associate agreement and the account controls that go with it. Without it, an account should not be used to store or message protected health information. The add-on has its own monthly cost, and it covers the platform's side of compliance only, not how your staff actually handle patient data day to day.
What the add-on includes
The HIPAA compliance add-on costs $297 a month, applies across the whole agency account rather than to a single sub-account, and is non-cancellable and non-refundable once purchased, as at September 2026, because encrypted protected health information cannot be un-encrypted after the fact. It includes encryption of protected health information, business associate agreements, audit logging and enforced multi-factor authentication. The agreement is signed inside HighLevel's own document tool at the agency level, and once signed, each sub-account that needs it must still be turned on individually in its own advanced settings.
What it does not do
Purchasing the add-on does not make your practice's own handling of patient data compliant on its own. It governs the platform; your staff's training, your device security, and your own policies for who can see what remain your responsibility. Standard SMS is not encrypted in transit to a phone, which is a general fact about how text messaging works everywhere, not something specific to this platform; keep clinical detail out of a text message even with the add-on enabled.
Who typically needs it
A medical spa, a dental practice, a therapy practice, or any clinic that will hold patient names alongside health details, appointment reasons that reveal a condition, or treatment notes, or that will message patients about their care, needs the add-on before any of that goes into the account. A business using the account for marketing to prospects only, with clinical records kept in a separate system built for that purpose, does not need it.
Which plans it is available on
The add-on can be purchased on any plan tier, from Starter through Agency Pro, as at September 2026; it is not exclusive to the higher plans. Enterprise customers additionally receive HIPAA compliance as part of their custom package.
How the sign-up actually works
The process runs in two steps. First, the agency-level administrator purchases the add-on and signs a business associate agreement inside HighLevel's own document and e-signature tool, found under the compliance settings. Signing that agreement turns on HIPAA controls at the agency level, but it does not automatically extend to every client or business inside the account. Second, each individual sub-account that will hold protected health information has to be switched on for HIPAA separately, in that sub-account's own advanced settings. An agency running several client accounts, only some of which are healthcare businesses, can therefore keep the add-on's protections limited to the accounts that actually need them, once each is turned on individually. Skipping that second step is the most common way a business assumes it is covered when only the agency-level agreement has been signed.
An agency's angle on this
For an agency running client accounts under for agencies, a single healthcare client can justify the account-wide add-on if that client's data is worth protecting properly, but it is worth pricing the $297 a month into that specific client's fee rather than absorbing it across every account, since the charge applies once, agency-wide, and cannot be scaled back down once enabled.
What we have watched go wrong
The two failure modes are opposite. One is buying the add-on for an account that only ever markets to prospects, paying a permanent monthly cost for a control it does not need. The other is skipping it because "we only send appointment reminders," while the reminder itself names the treatment or the condition, which is exactly the kind of message the add-on exists to protect.
Verdict
Required, if you will hold patient names alongside health details or message patients about care in the account. Not required, if the account is marketing-only and clinical records live elsewhere. Not this tool, if your compliance officer needs controls the add-on does not list; check the current help center article, with its date, before committing either way, since this is not legal advice. See security and data for the platform's wider security posture, or medspa and clinics and dentists for how the rest of the account fits those businesses.
Questions people ask
Is HighLevel HIPAA compliant?
HighLevel offers a paid add-on that provides the business associate agreement and platform controls needed to handle protected health information; an account without the add-on turned on should not hold that kind of data.
How much does the HIPAA add-on cost?
$297 a month, applied across the whole agency account, as at September 2026.
Do I need it for appointment reminders?
Only if the reminder or the record behind it reveals health information, such as naming a treatment or condition. A reminder that states only a time and a business name does not necessarily require it, but check your own compliance obligations rather than relying on that distinction alone.
Does it cover texting patients?
The add-on covers the account and its encryption and access controls; standard SMS delivery to a phone is not itself encrypted in transit, which is true of text messaging in general, so avoid clinical detail in a text regardless of the add-on.
Which plan do I need for HIPAA?
The add-on can be purchased on any plan, from Starter up, as at September 2026; it is a separate cost from the plan itself, not a feature unlocked by upgrading.