Yes. A text with a link to a form in GoHighLevel works, as long as the text carries no health information, the form sits in the practice's HIPAA configured account, and the patient's preference for texting is documented. The bottom line: the link is the easy part, and the practice's privacy officer should decide in advance what the form collects, where it is stored, and who can see it.

What HIPAA allows

HHS's Omnibus Rule commentary, as quoted by the Holland and Hart health law blog, says covered entities may send unencrypted messages if they have advised the individual of the risk and the individual still prefers that channel, and then are not responsible for unauthorized access in transit. Practices therefore warn patients, document the preference, and keep the message itself generic. A text that says your new patient forms are ready, with a link, tells a lock screen almost nothing. The form behind it is where health information is entered, which is why it belongs in the protected account and not in a general web form tool.

GoHighLevel's help portal says accounts are not HIPAA compliant by default, and that HIPAA Compliance is a paid upgrade, $297 a month as an account wide add on, that must be enabled for the agency and then configured for the sub accounts that need it. Third party guides add that the add on provides a business associate agreement, encryption, audit logging, and multi factor authentication, that the practice also needs its own agreement with the agency, and that GoHighLevel itself recommends avoiding protected health information in SMS and email even with the add on. Whether the AI features are covered by the agreement is a question to put to HighLevel in writing before any patient data reaches them.

What the form does

GoHighLevel's help page on conditional logic in forms and surveys describes rules that redirect, show a message, disqualify, or show and hide fields, evaluated from the top down. For a clinic that means one form can show pediatric questions only when the patient is under 18, show an insurance section only when the patient says they have coverage, and show a self pay notice when they do not.

SectionShown when
Demographics and contactAlways
Guardian detailsPatient is under 18
Insurance details or uploadPatient has coverage
Self pay and financial policy noticePatient has no coverage
Medical historyAlways, in short sections
Privacy notice acknowledgment and consent to textsAlways

Text, email, and portal compared

ChannelStrengthWeakness
Text linkOpened on the phone the patient already hasUnencrypted, and the phone may be shared
Email linkHolds more explanationOften unread, and also unencrypted
Patient portalSecure, and tied to a loginNew patients do not yet have an account

Before online forms, a new patient got a mailed packet or a clipboard at check in, and front desk staff typed the answers into the chart. The text link removes the clipboard, and the privacy rules decide how much it asks.

Build it in GoHighLevel

  1. Build the new patient form with the sections in the table, using conditional logic to show and hide them.
  2. Add a required acknowledgment of the Notice of Privacy Practices, and a separate consent line for text messages that states the risk of unencrypted texting.
  3. Build a workflow with the Customer Booked Appointment trigger for new patient visits that sends the link by text only if the contact has the tag Text consent, and by email otherwise.
  4. Write the text: your forms for your visit with the practice name are ready at this link, and reply STOP to stop messages.
  5. Add a Goal Event that waits for the form, and a reminder 48 hours before the visit if it is not submitted.
  6. Create a task for the front desk to review submitted forms before the visit, and to hand a paper copy to patients who did not complete them.

Worked example

For example, a clinic that sees 100 new patients a month and gets 60 forms completed before the visit saves 60 clipboards at check in. If each saves 8 minutes of front desk typing, that is 480 minutes a month (60 times 8), or 8 hours.

Mistakes to avoid

How this was handled before

Practices mailed a packet or handed a clipboard at check in, and front desk staff typed the answers into the chart. Patient portals moved forms online for existing patients, and a text link extends that to new patients who have no account yet.

What to measure after launch

Track forms sent, forms completed before the visit, reminders needed, and check in time. If few patients complete forms, shorten the form.

Check before you switch it on

US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. Have your privacy officer approve the form fields, the consent wording, and the storage location. This is general information, not legal advice.

Questions people ask

Can a practice text patients without encryption?

HHS commentary says covered entities may do so if the patient was warned of the risk and still prefers it. Document the preference.

What should the text say?

Only that forms are ready, with a link and a STOP line. No health details.

What can conditional logic do?

GoHighLevel's help page lists redirect, message, disqualify, and show or hide field actions.

Ready to try it yourself? Start a GoHighLevel account here.

You can also see this in action in our GoHighLevel capabilities demo.