It can, with guardrails. A chat box from GoHighLevel or any vendor on a practice website that collects a name and a callback number is a low risk way to catch visitors, but a chat is a place where people type health details, so the chat vendor is likely handling protected health information and needs a business associate agreement. The bottom line: ask for a number first, warn visitors not to type medical details, and confirm the vendor's agreement before the box goes live.
What the tracking technology rulings mean
HHS's Office for Civil Rights issued a bulletin on online tracking technologies in December 2022 and revised it in March 2024. On June 20, 2024, a federal court in the Northern District of Texas, in American Hospital Association v. Becerra, vacated the part of the bulletin that said HIPAA obligations attach when a tracking technology connects an IP address with a visit to an unauthenticated public webpage about health conditions or providers. OCR withdrew its appeal in August 2024. Law firm summaries stress what was not vacated: the parts on user authenticated pages such as patient portals, and on other combinations of individually identifiable health information, and they advise entering business associate agreements with tracking and technology vendors that have access to protected health information. Other federal and state privacy laws may still apply.
A chat box is not a passive pixel. A visitor who types a symptom or a medication into it has just sent health information to whatever service runs the chat, so the vendor question is the main one.
What the box should do
| Feature | Setting |
|---|---|
| First message | Name and phone number only, plus a line: do not type medical details, and call 911 in an emergency |
| Consent | A line that the practice may call or text about the request, tied to the A2P opt in |
| Placement | Public pages such as contact and new patient, and not inside the patient portal |
| Vendor | A signed agreement that covers the chat product |
| Transcripts | Stored in the HIPAA configured account, with access limited by role |
Build it in GoHighLevel
A third party guide describes GoHighLevel's chat widget as a box that collects contact details so the business can reply by text or email. Confirm in your account whether the widget is covered under the HIPAA add on and the agreements.
GoHighLevel's help portal says accounts are not HIPAA compliant by default, and that HIPAA Compliance is a paid upgrade, $297 a month as an account wide add on, that must be enabled for the agency and then configured for the sub accounts that need it. Third party guides add that the add on provides a business associate agreement, encryption, audit logging, and multi factor authentication, that the practice also needs its own agreement with the agency, and that GoHighLevel itself recommends avoiding protected health information in SMS and email even with the add on. Whether the AI features are covered by the agreement is a question to put to HighLevel in writing before any patient data reaches them.
- Confirm in writing with HighLevel that the chat widget is covered by the agreement, before any health information can be typed into it.
- Create the widget with the first message and consent line from the table.
- Limit the form fields to name, phone, and a reason chosen from a short list of administrative reasons.
- Add the script to public pages only, and leave the portal and login pages out.
- Build a workflow that creates a callback task and sends a generic confirmation text.
- Review the chat transcripts weekly for health details that were typed in, and train staff to delete or restrict them.
Worked example
For example, if a practice site gets 3,000 visits a month and 1 percent start a chat, that is 30 chats (3,000 times 0.01). If 20 leave a number, the front desk has 20 callbacks that started as anonymous visitors.
Mistakes to avoid
- No agreement with the chat vendor. A chat collects health details.
- Asking what is wrong. Ask for a number and a reason category.
- Placing the box in the patient portal. Authenticated pages carry more risk.
- Assuming the 2024 ruling ends the issue. Other laws and the remaining guidance apply.
How this was handled before
Practice websites offered a phone number and a contact form. Chat boxes arrived with marketing tools, and OCR's 2022 tracking bulletin brought attention to what those scripts collect. A court has since narrowed that bulletin, and the vendor agreement question remains.
What to measure after launch
Track chats started, numbers captured, callbacks made, and chats with health details typed. If patients keep typing health details, change the first message.
Check before you switch it on
US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. Have counsel review the chat, tracking scripts, and vendor agreements under HIPAA and your state's privacy laws. This is general information, not legal advice.
Questions people ask
Did a court end OCR's tracking guidance?
It vacated only the part on unauthenticated public pages, and OCR withdrew its appeal. Other parts and other laws remain.
Does a chat vendor need a BAA?
If it has access to protected health information, law firm summaries advise entering a business associate agreement.
What should the first chat message say?
Ask for a name and number, warn visitors not to type medical details, and tell them to call 911 in an emergency.
Ready to try it yourself? Start a GoHighLevel account here.
You can also see this in action in our GoHighLevel capabilities demo.
