Skip to content

HighLevel Made Note Files Private. Everything Uploaded Before Stays Public

August 12, 2026. HighLevel made note attachments private by default on August 11, citing HIPAA compliance as the driver. It is a real improvement and it is worth reading to the end, because the same release states that every document uploaded through notes before it shipped stays public.

What HighLevel changed on August 11

  1. New documents uploaded through the notes section are private by default and land in a Notes attachments folder under Documents.
  2. When sharing, users choose the access level. HighLevel's earlier Labs release defines the four options as a public link for anyone with the link, a private link for authorized HighLevel users, a one time code link verified by a password sent to the contact's email, and a password protected link.
  3. HighLevel describes the previous behaviour plainly. Documents uploaded through notes were public in nature and could be shared without expiration or additional privacy controls.
  4. In HighLevel's own words, existing documents previously uploaded through notes will continue to remain public. The change applies only to uploads after release.

The paragraph that matters is about the past

A default that changes going forward stops the exposure growing. It does not reduce the exposure you already have. Those older links were created without expiry, so they do not age out, and nothing in the release generates a list of them. The count in your account is whatever your team uploaded through notes since the day you started, and by default nobody knows the number.

The HIPAA framing is what makes this worth an hour rather than a shrug. The release names the compliance context, and that context applies precisely to the historical files, since an intake form or an identity document from March is exactly the kind of record that framing exists to protect. The fix is manual and retroactive. Open the contact record, find the document, and reshare it as a private, one time code or password protected link.

What it means for operators

If you run client sub accounts, this is a backfill task with a clear priority order, not a policy update to forward. Start with the sub accounts in regulated niches, medical, legal, finance and insurance, then work through anything where note attachments were used for identity documents, signed contracts or intake forms. Sample a handful of old links in a private browser window first. If they open without a login, you have measured the problem rather than assumed it.

Then close the loop on process. Tell your team that documents belong in the Documents panel with a chosen access level, not dropped into a note because it was quicker, and put that line in the onboarding checklist for every new sub account you build in GoHighLevel. Configuration drift like this is the ordinary failure mode of a whitelabelled stack, and it is the reason we treat platform defaults as something to verify per account rather than trust once, which is how we run builds at our AI automation agency.

One limit worth stating. HighLevel says the change applies to uploads after the feature is released, and release timing can differ by account, so confirm the behaviour in your own sub account before assuming new uploads are already private.

Running client sub accounts in GoHighLevel? imisofts audits the defaults before they cost you.

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

As of August 11, 2026, documents uploaded through the notes section are private by default and stored in a Notes attachments folder under Documents. When sharing, users pick an access level: public link, private link, one time code link, or password protected link.

No. HighLevel's release states that the update applies only to documents uploaded through notes after the feature is released, and that existing documents previously uploaded through notes will continue to remain public. Older links also had no expiration.

Manually. Open the contact record, find the document in the Documents panel, and reshare it with a private, one time code or password protected link. Prioritise sub accounts in regulated niches and any files containing identity documents, contracts or intake forms.

Because HighLevel names HIPAA compliance as the reason for the change, and that context applies most strongly to records created before the change. A new default protects future uploads while the historical files it was designed to protect are the ones still sitting on public links.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us