August 12, 2026. HighLevel made note attachments private by default on August 11, citing HIPAA compliance as the driver. It is a real improvement and it is worth reading to the end, because the same release states that every document uploaded through notes before it shipped stays public.
What HighLevel changed on August 11
- New documents uploaded through the notes section are private by default and land in a Notes attachments folder under Documents.
- When sharing, users choose the access level. HighLevel's earlier Labs release defines the four options as a public link for anyone with the link, a private link for authorized HighLevel users, a one time code link verified by a password sent to the contact's email, and a password protected link.
- HighLevel describes the previous behaviour plainly. Documents uploaded through notes were public in nature and could be shared without expiration or additional privacy controls.
- In HighLevel's own words, existing documents previously uploaded through notes will continue to remain public. The change applies only to uploads after release.
The paragraph that matters is about the past
A default that changes going forward stops the exposure growing. It does not reduce the exposure you already have. Those older links were created without expiry, so they do not age out, and nothing in the release generates a list of them. The count in your account is whatever your team uploaded through notes since the day you started, and by default nobody knows the number.
The HIPAA framing is what makes this worth an hour rather than a shrug. The release names the compliance context, and that context applies precisely to the historical files, since an intake form or an identity document from March is exactly the kind of record that framing exists to protect. The fix is manual and retroactive. Open the contact record, find the document, and reshare it as a private, one time code or password protected link.
What it means for operators
If you run client sub accounts, this is a backfill task with a clear priority order, not a policy update to forward. Start with the sub accounts in regulated niches, medical, legal, finance and insurance, then work through anything where note attachments were used for identity documents, signed contracts or intake forms. Sample a handful of old links in a private browser window first. If they open without a login, you have measured the problem rather than assumed it.
Then close the loop on process. Tell your team that documents belong in the Documents panel with a chosen access level, not dropped into a note because it was quicker, and put that line in the onboarding checklist for every new sub account you build in GoHighLevel. Configuration drift like this is the ordinary failure mode of a whitelabelled stack, and it is the reason we treat platform defaults as something to verify per account rather than trust once, which is how we run builds at our AI automation agency.
One limit worth stating. HighLevel says the change applies to uploads after the feature is released, and release timing can differ by account, so confirm the behaviour in your own sub account before assuming new uploads are already private.
Frequently Asked Questions
As of August 11, 2026, documents uploaded through the notes section are private by default and stored in a Notes attachments folder under Documents. When sharing, users pick an access level: public link, private link, one time code link, or password protected link.
No. HighLevel's release states that the update applies only to documents uploaded through notes after the feature is released, and that existing documents previously uploaded through notes will continue to remain public. Older links also had no expiration.
Manually. Open the contact record, find the document in the Documents panel, and reshare it with a private, one time code or password protected link. Prioritise sub accounts in regulated niches and any files containing identity documents, contracts or intake forms.
Because HighLevel names HIPAA compliance as the reason for the change, and that context applies most strongly to records created before the change. A new default protects future uploads while the historical files it was designed to protect are the ones still sitting on public links.