Is GoHighLevel HIPAA Compliant? What the $297 Add-On Actually Does

Disclosure: some links in this article are affiliate links. If you start a GoHighLevel trial through one of them I may earn a commission, at no extra cost to you. Nothing here is legal advice. HIPAA obligations depend on your organisation and how you use the platform, so confirm your own position with your compliance officer or counsel before you act on any of it.

The short answer is no. In HighLevel’s own words, accounts are not HIPAA compliant by default. There is a paid add-on that makes them compliant, it costs $297 a month on top of your plan, and buying it is a one-way door: it cannot be cancelled, refunded or downgraded.

That last sentence is the part almost nobody mentions, and it is the one that should change how you make this decision.

What “not compliant by default” actually means for you

If you are a covered entity or a business associate under HIPAA, and you are putting protected health information into a standard GoHighLevel account, you are storing PHI on a platform with no Business Associate Agreement in place. That is a problem that exists today, not one that starts when someone notices.

And PHI gets into GoHighLevel more easily than people expect. It is not just a field marked “diagnosis”. A patient replying to an appointment reminder with why they are coming in is PHI in your SMS log. A contact note saying which treatment they booked is PHI. A form submission with symptoms is PHI. A call recording is PHI. If your account touches patients at all, assume it is in there.

What the add-on covers

Buying the HIPAA package gets you a signed BAA plus the technical controls, and the coverage is reasonably thorough:

  • Encryption of ePHI across the platform
  • Audit logging
  • Enforced multi-factor authentication
  • Mobile app coverage for Conversations, Calendars and Contacts
  • Every data type that tends to hold PHI: contacts, notes, custom fields, SMS and MMS, voice recordings, email bodies and attachments, form and survey submissions, calendars, and invoices

The BAA itself is now signed inside HighLevel, in the Compliance section under Documents and Contracts, rather than through a separate process. You can view it, set signer details, sign and download it from there.

The real cost

The $297 is in addition to your subscription, not instead of it. So the actual monthly figures are:

Plan Plan cost With HIPAA
Starter $97 $394
Unlimited $297 $594
Agency Pro $497 $794

Before usage charges for SMS, voice, email and AI, which sit on top of all of these. See plans and pricing for the full picture.

It is also worth knowing that the package is purchased agency-wide, covering all your sub-accounts, rather than per sub-account. If you run one clinic alongside twenty non-healthcare clients, you are paying the same $297 as an agency running twenty clinics. This is a live complaint in HighLevel’s own ideas board, where agencies have asked for per-sub-account pricing. It has not changed yet, so price your healthcare work accordingly.

Read this part twice: it is permanent

This is the section I would want to have read before buying.

The add-on cannot be cancelled, refunded or downgraded. Once you buy it, it stays on your agency account.

Enabling it on a sub-account is also irreversible. After the BAA is signed you enable HIPAA per sub-account in Advanced Settings, and once enabled on a given sub-account it cannot be turned off.

The data cannot be un-encrypted. There is no path back to a normal account state.

None of that is unreasonable from a compliance design point of view. You should not be able to casually flip protected data back into an unprotected state, and a vendor that let you would be a worse vendor. But it means this is a decision to make deliberately, with a clear view of which sub-accounts genuinely need it, rather than something to switch on across the board to be safe.

Two practical consequences:

  1. Enable it only on the sub-accounts that hold PHI. Not on your own agency account, not on the plumber, not on the sub-account you use for testing. The purchase covers the agency, the enabling is per account, and the enabling is the part you cannot undo.
  2. Test your build before you enable. Get workflows, forms and calendars working in a normal sub-account, then enable HIPAA on the account you will actually run. Debugging is harder once encryption and enforced MFA are in the way.

Who should buy it, and who should not

Buy it if you handle PHI in GoHighLevel at all and you are a covered entity or business associate. There is no clever configuration that gets you out of needing a BAA, and the alternative is not a cheaper compliant setup, it is non-compliance.

Do not buy it if your healthcare-adjacent work genuinely never touches PHI. A wellness brand selling supplements, a gym, a clinic marketing site that collects nothing but a name and an email for a newsletter. Be honest with yourself about this rather than optimistic, because the line is crossed by a single patient reply.

Think harder if you have one healthcare client and nineteen who are not. $297 a month for one client’s compliance either gets priced into that engagement or it does not make sense. Some agencies keep healthcare work on a separate agency account for exactly this reason.

What to do if PHI is already in a non-compliant account

This is the situation a lot of agencies quietly find themselves in, and the honest answer is that it is a compliance incident to assess rather than a settings change to make.

Practically, the steps that matter: stop new PHI entering the account, work out what is actually in there and how far back, get your compliance officer or counsel involved rather than deciding yourself whether it was reportable, and only then work out the target setup. Buying the add-on today does not retroactively cover data that was stored without a BAA in place.

I am not going to pretend to tell you what your notification obligations are. That genuinely depends on facts about your organisation that I do not have, and it is exactly the kind of question where guessing is expensive.

Frequently asked questions

Is GoHighLevel HIPAA compliant?

Not by default. HighLevel states plainly that accounts are not HIPAA compliant unless you purchase the HIPAA add-on, which includes a signed BAA and the technical controls.

How much does GoHighLevel HIPAA compliance cost?

$297 a month on top of your existing plan, purchased at agency level and covering all sub-accounts.

Does HighLevel sign a BAA?

Yes, with the HIPAA package. The BAA is signed inside the platform, in the Compliance area under Documents and Contracts.

Can I cancel the HIPAA add-on if I lose the client?

No. It cannot be cancelled, refunded or downgraded, and enabled sub-accounts cannot be reverted. Factor that into how you price and contract healthcare work.

Do I have to enable it on every sub-account?

No, and you should not. The purchase is agency-wide but enabling is per sub-account, in Advanced Settings. Enable only the accounts holding PHI, because enabling cannot be undone.

Is the mobile app covered?

Yes. Conversations, Calendars and Contacts on mobile are included in the package coverage.

Can I use a cheaper workaround instead?

Not for PHI. Keeping PHI out of GoHighLevel entirely is a legitimate architecture, and plenty of clinics run marketing in GoHighLevel while patient data lives in their EHR. But there is no configuration of a standard GoHighLevel account that makes storing PHI in it compliant, because the missing piece is the BAA rather than a setting.

The short version

GoHighLevel is not HIPAA compliant out of the box. The add-on is $297 a month on top of your plan, bought once at agency level, enabled per sub-account, and permanent in all three senses: you cannot cancel it, you cannot un-enable a sub-account, and the data cannot be un-encrypted. Decide which sub-accounts genuinely hold PHI, build and test before you enable, and price healthcare work knowing the $297 does not go away when the client does.

More on the platform’s compliance and deliverability side in Compliance, or the cost breakdown in plans and pricing. If you are evaluating the platform, you can start a 14 day trial here, though do not put PHI into a trial account.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top