Most dental offices do, in practice. HIPAA applies to a dentist only if the dentist transmits information electronically in connection with a standard transaction, such as an insurance claim, and nearly every office that bills a plan does. A CRM that stores patient names with appointment or treatment information is then a business associate and needs an agreement, which GoHighLevel provides through its $297 a month HIPAA add on. The bottom line: confirm first whether the office is a covered entity, then put an agreement in place with every vendor that holds patient data.

Is every dentist a covered entity

HHS says covered entities include dentists, but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard. The HIPAA Journal notes that a dentist communicating only by phone and fax may not be covered, that a cash only provider who never bills electronically is technically not a covered entity, and that using a billing service or a support organization that submits claims on the practice's behalf makes the practice covered. State privacy laws can apply either way. Most offices that check eligibility or submit claims electronically are covered, so assume yes unless counsel says otherwise.

What HHS says about vendors

HHS's guidance on cloud computing, as summarized by Mintz and Bricker Graydon, says a cloud service provider that creates, receives, maintains, or transmits electronic protected health information for a covered entity is a business associate, even if it stores only encrypted information and holds no key. The conduit exception is limited to transmission only services with temporary storage. OCR does not endorse, certify, or recommend specific technology, so no vendor is HIPAA certified.

GoHighLevel's help portal says accounts are not HIPAA compliant by default, and that HIPAA Compliance is a paid upgrade, $297 a month as an account wide add on, that must be enabled for the agency and then configured for the sub accounts that need it. Third party guides add that the add on provides a business associate agreement, encryption, audit logging, and multi factor authentication, that the practice also needs its own agreement with the agency, and that GoHighLevel itself recommends avoiding protected health information in SMS and email even with the add on. Whether the AI features are covered by the agreement is a question to put to HighLevel in writing before any patient data reaches them.

What is special about dentistry

DataWhy it matters
X rays, intraoral photos, and cosmetic imagesImages of a patient's mouth are health information. Do not send them by ordinary text or a general chat widget
Treatment plans and estimatesThey relate to care and payment
Parent and child recordsThe parent is the child's personal representative
Appointment lists in the CRMNames with appointments relate to the provision of care

Decision guide

SituationWhat to do
The office submits claims or checks eligibility electronicallyTreat it as covered, buy the add on, and sign the agreements before patient data enters the CRM
A cash only office that never uses electronic billingAsk counsel whether HIPAA applies and what state privacy law requires. Many offices still choose to follow it
The office uses Voice AI, Conversation AI, or the chat widget with patientsGet written confirmation that those features are covered by the agreement
An agency runs the accountConfirm the chain: the practice, the agency, and HighLevel each have the right agreement

Set it up right

  1. List every place patient information would enter GoHighLevel: forms, calls, texts, the chat widget, and the calendar.
  2. Decide with your privacy officer whether the practice is a covered entity. For most offices that bill plans electronically, it is.
  3. Buy the HIPAA add on at the agency level, sign the agreement, and enable HIPAA on the practice's sub account.
  4. Sign a separate agreement between the practice and the agency, if an agency manages the account.
  5. Turn on multi factor authentication and role based access for every user.
  6. Keep images out of text threads, and give patients a secure upload for photos.
  7. Review each integration, since each that touches patient data needs its own agreement.

Worked example

For example, at $297 a month the add on costs $3,564 a year (297 times 12). A practice with 800 visits a month pays about 37 cents a visit (3,564 divided by 9,600 visits a year), small next to the $10,000 to $50,000 OCR penalties against dental practices for review replies.

Mistakes to avoid

How this was handled before

Dental offices used their practice software for reminders and kept marketing tools separate. Once a CRM holds patient names and appointments, HHS's cloud guidance treats the vendor as a business associate, which is why an agreement is the test.

What to measure after launch

Track sub accounts with HIPAA enabled, users with multi factor authentication, integrations reviewed, and agreements on file. Review the integrations list quarterly.

Check before you switch it on

US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. This is general information, not legal advice. Have your privacy officer and counsel confirm your status and your agreements. This is general information, not legal advice.

Questions people ask

Is every dentist covered by HIPAA?

HHS says dentists are covered only if they transmit information electronically in connection with a standard transaction. Most offices that bill plans electronically are.

Does a dental office need a business associate agreement with its CRM?

If the CRM creates, receives, maintains, or transmits electronic protected health information for the practice, HHS's cloud guidance treats the vendor as a business associate.

What does GoHighLevel's HIPAA add on cost?

GoHighLevel's help portal says $297 a month as an account wide add on.

Ready to try it yourself? Start a GoHighLevel account here.

You can also see this in action in our GoHighLevel capabilities demo.