GoHighLevel · Solution guide
GoHighLevel Setup Agency for Med Spas: Snapshot, HIPAA and Cost
Quick answer
A GoHighLevel setup for a med spa is a scoped build of lead capture, consultation booking, reminders, no-show recovery, membership and reactivation workflows, review requests, A2P 10DLC registration and, where counsel says it applies, the $297 a month HIPAA add-on with a signed BAA. aibrevo's published price for a single-business CRM setup is $500 to $4,000, separate from HighLevel's own subscription.
Key takeaways
- HighLevel's HIPAA add-on costs $297 a month, must be bought at agency level, then switched on manually for each sub-account after the BAA is signed, and cannot be cancelled, refunded or downgraded once enabled (HighLevel support article, updated 11 June 2026). Decide on it before any client data goes in.
- Of five common med spa platforms checked on 30 September 2026, none showed a first-party GoHighLevel app in our research. Boulevard and Zenoti publish Zapier apps, Aesthetic Record's Zapier app has two triggers (New Patient, New Invoice), and Mangomint and Vagaro rely on webhooks or API access you request from the vendor.
- A2P 10DLC registration costs $22.50 one-time for a low-volume standard brand, $15 per extra campaign and $10 a month for a standard campaign, with Fast Track approval targeted within 3 business days (HighLevel fee article, modified 24 September 2026). Snapshots never carry it across.
- aibrevo's published price for a complete single-business CRM setup is $500 to $4,000, and $4,000 to $12,000 for a multi-location rollout (aibrevo pricing page). An illustrative HIPAA-ready single-location account then runs about $429 a month in HighLevel fees before carrier charges.
- The CTIA 2023 Messaging Principles treat appointment reminders as informational and offers as promotional, which needs written agreement first; the FTC's Consumer Reviews and Testimonials Rule has been in force since 21 October 2024. Consent capture and review-request design are setup decisions, not afterthoughts.
A GoHighLevel setup for med spas is not a template import. It is a build that has to answer three med spa questions before any workflow goes live: whether the practice needs HighLevel’s $297 a month HIPAA add-on (which cannot be cancelled once enabled), how appointment and treatment data will get out of Boulevard, Mangomint, Zenoti, Vagaro or Aesthetic Record, and how the practice will capture consent for reminders versus promotions. This page is for owners and practice managers who have already decided GoHighLevel is worth using and now want to know what a proper setup includes, what it costs, how long it takes and how to pick who does it.
If you are still deciding whether GoHighLevel fits a med spa at all, start with our GoHighLevel for med spas fit and pricing guide, which compares it with booking platforms and walks through the HIPAA add-on in depth. This page picks up where that one stops: the hire and build decision.
What does a GoHighLevel setup for a med spa include?
A complete med spa build includes lead capture, consultation booking, reminders, no-show recovery, treatment-based tagging, membership and package renewal triggers, reactivation, review requests, pipeline reporting, A2P 10DLC registration and email authentication, plus HIPAA configuration and a booking-platform connection when needed.
The table below is the deliverables list we would expect in any written scope for a single-location med spa, whoever builds it. “Standard” means it belongs in a complete build for one business; “scoped” means it depends on the practice and should be priced and named separately.
| Deliverable | What it does for a med spa | In a standard build? |
|---|---|---|
| Lead capture forms and ad integrations | Pulls Botox, filler, laser and body-contouring inquiries from the website and paid social into one inbox, tagged by treatment | Standard |
| Missed-call text-back | Texts a caller within seconds when the front desk is with a client | Standard |
| Consultation calendar with deposit | Books consultations and collects a no-show deposit or card on file through a payment link | Standard (deposit rules set by the practice) |
| Reminder sequence | Confirmation, day-before and same-day reminders written in generic wording | Standard |
| No-show and cancellation recovery | Tags a no-show and runs a short rebooking sequence that stops when the client rebooks | Standard |
| Treatment tags and custom fields | Stores last treatment type and date so a neurotoxin client and a laser package client get different follow-up | Standard |
| Membership and package renewal triggers | Fires reminders from a renewal date or remaining-sessions field, not a flat calendar blast | Standard |
| Reactivation campaign | Reaches lapsed clients who agreed to promotional texts or emails | Standard (needs consent data) |
| Review requests | Asks every completed client for a review, with a private feedback path | Standard |
| Pipeline and reporting | Shows inquiry to consultation to treatment conversion by source | Standard |
| A2P 10DLC and sending-domain setup | Makes texts deliverable and email authenticated | Standard |
| HIPAA add-on, BAA and per-location activation | Encrypts stored health data and signs a Business Associate Agreement | Scoped (after counsel’s opinion) |
| Booking-platform sync | Moves appointment, completion and membership events in from Boulevard, Zenoti and others | Scoped (method depends on vendor and plan) |
| Data migration and cleanup | Imports the existing client list with consent flags and treatment history | Scoped (by record count and quality) |
| Conversation AI for after-hours FAQs | Answers hours, pricing ranges and booking questions by text | Scoped |
Two items deserve a sentence each. Deposits are a business policy, not a software setting, so the practice decides the amount and refund rules and the build only enforces them. Conversation AI is useful for “what are your hours” and “do you do lip filler”, and not for anything that sounds like a clinical question; route those to a person.
The individual workflows (speed to lead, no-show recovery, membership countdowns) are explained step by step in our med spa automation guide. The generic, industry-neutral version of this checklist is on the GoHighLevel setup agency page.
Snapshot or done-for-you setup: which does a med spa need?
A med spa needs a done-for-you or done-with-you setup when HIPAA, a booking-platform sync or a client-list migration is involved, and can start from a GoHighLevel med spa snapshot when it is a single cash-pay location with simple follow-up and someone on staff to adapt it.
A snapshot is HighLevel’s mechanism for copying an account’s structure into another account. It saves real build time on workflows, pipelines, forms, calendars and email and text templates. It does not carry contacts, integration credentials, A2P 10DLC registration, billing, users, phone numbers, conversation history or domain settings, as our snapshots explainer covers. For a med spa there is one more gap: a snapshot cannot turn on HIPAA for a sub-account. HighLevel’s support article says that step is done manually per location after the BAA is signed.
| Med spa snapshot | Done-for-you setup | |
|---|---|---|
| What you get | A prebuilt structure written for a generic med spa | A build mapped to your treatments, prices, policies and booking platform |
| Typical cost | Low one-time price or included with a service | aibrevo publishes $500 to $4,000 for a single-business CRM setup |
| A2P 10DLC registration | Not included; you register each sub-account | Included in scope |
| HIPAA add-on and per-location activation | Not included | Included when counsel says it applies |
| Booking-platform connection | Not included; credentials never transfer | Included, method depends on vendor |
| Your client list and consent flags | Not included | Cleaned and imported |
| Copy and offers | Someone else’s wording and prices | Written for your services and state rules |
| Who fixes it when a workflow misfires | You | Named in the support terms |
| Best fit | One location, cash-pay, simple follow-up, a hands-on owner | HIPAA, several locations, a sync, or a large list |
Marketplace snapshots also carry assumptions that can be risky in aesthetics: promotional language inside reminders, offers that do not match your state’s rules on medical advertising, or review requests that only go to happy clients. If you buy one, import it into a test sub-account, read every workflow, replace every placeholder and custom value, and only then connect real numbers.
A done-for-you GoHighLevel build for med spas is not automatically better. It costs more, and a vague scope from a builder is worse than a well-understood snapshot. The deciding factor is how much of the work sits outside the snapshot: registration, HIPAA, integration and data.
How much does GoHighLevel setup cost for a med spa?
A med spa’s GoHighLevel build costs a one-time build fee plus HighLevel’s monthly fees. aibrevo publishes $500 to $4,000 for a single-business setup and $4,000 to $12,000 for multi-location; HighLevel charges $97 to $497 a month, $297 for HIPAA, and metered usage.
Those are four separate budgets. Keep them apart when comparing quotes, because a low setup fee sometimes hides an expensive monthly management retainer, and a “free setup” usually means only the generic configuration.
One-time costs
| Item | Price | Source |
|---|---|---|
| aibrevo CRM setup, one business | $500 to $4,000 | aibrevo pricing |
| aibrevo multi-location rollout | $4,000 to $12,000 | aibrevo pricing |
| HighLevel Basic Account Setup (generic) | $299 | HighLevel marketplace listing, checked 20 September 2026 |
| HighLevel Advanced Account Setup (done with you) | $1,000 | HighLevel marketplace listing, checked 20 September 2026 |
| A2P 10DLC brand and vetting, low-volume standard | $22.50 (includes $3 Fast Track) | HighLevel A2P fee article, modified 24 September 2026 |
| Each additional A2P campaign | $15 | Same |
Where a med spa lands inside aibrevo’s $500 to $4,000 range depends mostly on four things: whether HIPAA is in scope, which booking platform has to be connected and by what method, how many treatment lines and membership types need their own branches, and how many client records need cleaning. A single cash-pay location with no sync sits near the bottom. A HIPAA practice with a Boulevard or Zenoti sync and a few thousand lapsed clients sits near the top. More than one location moves into the multi-location band. The implementation cost guide explains how scope translates to price across GoHighLevel projects generally.
Monthly costs
HighLevel’s pricing page (checked 30 September 2026) lists Starter at $97, Unlimited at $297 and Agency Pro at $497 a month, with a 14-day trial, and lists HIPAA compliance as a $297 a month add-on. Usage is billed separately; HighLevel’s phone pricing guide (modified 1 September 2026) lists SMS at $0.00747 per segment, a local number at $1.15 a month and email at $0.675 per 1,000 sends, with carrier fees on top.
An illustrative monthly worked example. Take a single-location, HIPAA-ready med spa on Starter that sends 3,000 SMS segments and 2,000 emails a month from one local number on one standard campaign. These volumes are assumptions for illustration, not client data.
- Plan: $97
- HIPAA add-on: $297
- A2P standard campaign fee: $10
- One local number: $1.15
- SMS: 3,000 × $0.00747 = $22.41
- Email: 2,000 ÷ 1,000 × $0.675 = $1.35
- Total: $97 + $297 + $10 + $1.15 + $22.41 + $1.35 = $428.91 a month, before carrier pass-through fees and any voice minutes.
The point of the arithmetic is the shape, not the total. For a HIPAA-ready account, the add-on is about 69% of the HighLevel bill and usage is a rounding error. For a cash-pay practice whose counsel says HIPAA does not apply, the same account costs about $132 a month. That is why the HIPAA decision comes first in any sensible med spa CRM setup, and why it should be made by a lawyer rather than a builder.
What does a med spa CRM setup timeline look like, week by week?
A single-location med spa CRM setup commonly takes three to five weeks of elapsed time. Build effort is a minority of that; the rest is waiting on counsel, carrier registration, booking-vendor API or webhook requests, and the practice’s own decisions on deposits, consent wording and offers.
HighLevel’s A2P fee article says the bundled registration includes Fast Track processing “to expedite approval within 3 business days”. That is the best case with a clean submission. Rejections, usually from opt-in wording that does not match the website or a legal name that does not match the tax record, restart the clock; our A2P 10DLC rejection guide covers the fixes.
| Week | Work | Waiting on | Output |
|---|---|---|---|
| 1 | Discovery: treatments, lead sources, deposit and cancellation policy, membership types, booking platform, current consent wording | Counsel’s HIPAA opinion; booking-vendor API or webhook request | Written scope and message classification |
| 1 to 2 | Account, users, MFA, HIPAA add-on and BAA if applicable, per-location activation, sending domain | DNS changes | Account ready for data |
| 2 | A2P 10DLC brand and campaign submission with matching opt-in language on every form | Carrier and registry approval (Fast Track targets 3 business days) | Texting enabled |
| 2 to 3 | Booking-platform connection and field ownership map; data export and cleanup | Vendor enabling webhooks or API access | Test events flowing in; clean import file |
| 3 to 4 | Workflow build: lead response, consultation booking, reminders, no-show recovery, reviews, renewals | Practice sign-off on message copy | Workflows in draft |
| 4 | Testing with dummy contacts through every branch; staff walkthrough | Front desk availability | Test log |
| 4 to 5 | Staged go-live, one workflow at a time; reactivation last | Consent data verified | Live account with named owner |
Two med spa specifics lengthen this. Vagaro says its API and webhook access is enabled through its enterprise sales team, and Mangomint says its team configures webhooks from endpoint URLs you supply, so those requests belong in week one. And the reactivation campaign should launch last, because it is the workflow most likely to text someone who never agreed to promotions.
Which med spa booking platforms does GoHighLevel connect to?
GoHighLevel connects to the main med spa booking platforms through Zapier, vendor webhooks or APIs rather than first-party marketplace apps. Boulevard and Zenoti publish Zapier apps and APIs, Aesthetic Record has a two-trigger Zapier app, and Mangomint and Vagaro offer webhooks.
We checked each vendor’s own documentation and Zapier listing on 30 September 2026. We did not find a first-party GoHighLevel marketplace app from any of the five; the HighLevel marketplace renders its app list in the browser, so confirm inside your account under Settings, Integrations before you design around this. HighLevel’s official Zapier app is listed as LeadConnector, which is what you search for in Zapier.
| Platform | Connection method | Events available to trigger GoHighLevel workflows | Notes |
|---|---|---|---|
| Boulevard | Zapier app; open API and webhooks | Appointment created, completed, cancelled, rescheduled; client created or updated; order completed | Boulevard’s support centre says Enterprise customers have API access for custom apps |
| Zenoti | Zapier app; API and webhooks | 40 Zapier triggers including appointment completed, guest created, membership changes and invoice closed | Third-party middleware such as Keragon also advertises a Zenoti to GoHighLevel connector (vendor claim) |
| Mangomint | Outbound webhooks set up by Mangomint staff | Appointment created, updated or deleted; sale completed; membership started or cancelled; form submitted | No listed Zapier app or public API found; point the webhook at a HighLevel inbound webhook trigger or a Zapier catch hook |
| Vagaro | APIs and webhooks on request | Appointments, customers, transactions, form responses | Vagaro’s webhook page says to contact its Enterprise Sales Team to enable; third-party connectors exist |
| Aesthetic Record | Zapier app (Settings, Integrations, Zapier) | New Patient, New Invoice | Requires a paid Zapier account; no appointment-completed trigger, so review requests usually key off a new invoice |
Three setup rules follow from that table.
Pick one owner per field. The booking platform should own appointments, treatments, charts and membership billing. GoHighLevel should own lead source, pipeline stage, marketing consent and campaign history. Two systems writing to the same field produce a client who gets a “we miss you” text the day after a filler appointment.
Move events, not charts. Send “appointment completed”, “membership cancelled” and “new client” into GoHighLevel. Do not copy clinical notes or photos into CRM notes. That keeps the HIPAA surface small and the sync cheap.
Check the middleware’s BAA position. If the practice is a covered entity, every tool that carries protected health information between systems is a separate vendor. Ask Zapier or any other connector whether it will sign a Business Associate Agreement on your plan before you route treatment data through it. Our Zapier versus native integrations guide covers the cost and reliability trade-off.
What compliance setup does a med spa need in GoHighLevel?
A med spa needs four compliance layers configured in GoHighLevel: a written HIPAA decision (and, if covered, the add-on, BAA and per-location activation), consent capture that separates reminders from promotions, A2P 10DLC registration, and review and testimonial practices that follow FTC rules. This is general information, not legal advice.
HIPAA and the BAA. HighLevel’s HIPAA support article (updated 11 June 2026) says accounts are not HIPAA compliant by default. The add-on is bought under Settings, Compliance at $297 a month, the BAA is signed in-platform, and HIPAA is then enabled manually for each sub-account under Advanced Settings. It covers contacts, notes, custom fields, SMS and MMS, voice recordings, email bodies and attachments, form submissions, calendars and invoices, and it “cannot be canceled, refunded, removed, or downgraded once enabled”. Whether you need it depends on whether the practice is a covered entity, which under the CMS covered-entity guidance turns on conducting standard electronic transactions such as claims. Many cash-pay med spas may not be; some are affiliated with practices that are. Get it in writing.
Consent for texts. The CTIA Messaging Principles and Best Practices (May 2023), which carriers apply to 10DLC traffic, classify appointment reminders as informational messages and say that before promotional messages “the Consumer should agree in writing to receive promotional texts”. They also call for a confirmation message on recurring programs, one opt-in per campaign, and acting on STOP and plain-language opt-outs. In GoHighLevel, that means two separate checkboxes on consultation and booking forms (reminders, and offers), two custom fields that record them, and workflows that check the offers field before any promotion or reactivation text. Some states go further: Florida’s Telephone Solicitation Act (section 501.059) requires prior express written consent for automated sales calls and defines them to include text messages, with damages of $500 per violation, trebled if willful.
A2P 10DLC. Register each sub-account that texts. For a med spa, the campaign description and sample messages should match what you actually send; a “customer care” campaign that then sends laser promotions is a common rejection and filtering cause. HighLevel’s A2P fee article lists the current fees.
Before-and-after photos. Under HIPAA’s de-identification standard (45 CFR 164.514), full-face photographs and comparable images are identifiers, and HHS marketing guidance generally requires written authorization to use protected health information in marketing. Whatever your HIPAA status, keep photos in the charting system, capture photo-use consent there, and do not collect photos through CRM text threads.
Reviews and testimonials. The FTC’s Consumer Reviews and Testimonials Rule, in force since 21 October 2024, bars incentives conditioned on positive sentiment, and the FTC’s guidance says asking for reviews only from customers you think are happy could violate the FTC Act. So the review workflow sends the same request to every completed client, and the private feedback step never decides who gets the public link. Testimonials in ads also fall under the FTC’s Endorsement Guides (16 CFR Part 255), which is a question for your marketing counsel, not your CRM.
Which automations should a med spa launch first?
A med spa should launch missed-call and inquiry response first, then consultation reminders, no-show recovery and review requests, and leave membership renewal and reactivation until consent data and the booking sync are proven. Each one below is written as trigger, action and why.
1. Inquiry and missed-call response
Trigger: a form submission, ad lead or unanswered call. Action: an instant text that names the practice, asks which treatment they are interested in and offers a consultation link; an alert to the front desk. Why first: it needs no booking-platform data, only A2P approval, and it is the easiest to measure. If texts are not arriving, see our missed-call text-back troubleshooting guide.
Live in week 2 or 32. Consultation booking, deposit and reminders
Trigger: a consultation booked. Action: confirmation with deposit or card-on-file link and cancellation policy, then day-before and same-day reminders in generic wording. Why: reminders are informational messages under CTIA's framework, so they sit on the reminder consent, not the promotional one.
Deposit rules set by the practice3. No-show recovery
Trigger: appointment marked no-show in the booking platform or GoHighLevel calendar. Action: a same-day, blame-free rebooking text and one or two follow-ups. Exit: the client rebooks. Why: it recovers a slot that already had demand, and it tests whether the booking sync is sending status changes correctly.
Needs a working status sync4. Review request to every completed client
Trigger: appointment completed (or new invoice, for Aesthetic Record). Action: a neutral request a day later that does not name the treatment. Why: steady reviews, and a design that matches the FTC's position on selective solicitation.
Same request for everyone5. Membership and package renewal
Trigger: a renewal date or remaining-sessions field reaching a threshold. Action: a countdown sequence to the client and a task for staff. Why later: it depends on accurate membership data from the booking platform, which usually needs a week of checking.
After the sync is proven6. Reactivation of lapsed clients
Trigger: last visit older than the typical interval for that treatment, and the promotional-consent field set to yes. Action: one or two relevant offers, spaced out, with STOP honoured. Why last: it is the workflow with the most compliance risk and the one most damaged by bad data.
Promotional consent requiredAmSpa’s 2024 State of the Industry report puts the repeat-patient rate at 73% and average spend at $527 per visit (AmSpa statistics), which is why renewal and reactivation matter in aesthetics even though they launch last. Sequence them after the basics work, not instead of them.
How do you vet a GoHighLevel expert for med spa work?
Vet a GoHighLevel expert for med spa work on how they handle HIPAA, booking-platform integration, consent and review design, and on the written scope and handoff. A certification badge and a snapshot demo are supporting evidence, not proof.
HighLevel’s Certified Admin credential costs $97 a month or $970 a year, and the certification program includes a HIPAA compliance track. It confirms platform knowledge. It does not confirm that the person has connected your booking platform or configured a per-location HIPAA switch.
Questions to ask
- Will you ask for our counsel’s HIPAA opinion before buying the add-on, and how do you verify HIPAA is on in each sub-account?
- Which of Boulevard, Mangomint, Zenoti, Vagaro or Aesthetic Record have you connected, by what method, and which events did you use?
- Which system will own appointment, treatment, membership and consent fields, and where is that written down?
- How will forms capture separate consent for reminders and promotions, and how do workflows check it?
- What will the A2P campaign description and sample messages say?
- How does the review workflow avoid review gating?
- What is in the written scope, what is out, and what does the test plan cover?
- Who owns the account, logins and any snapshot you build?
- What support is included after launch, and for how long?
Red flags
| Red flag | Why it matters for a med spa |
|---|---|
| “Our snapshot is fully HIPAA compliant” | A snapshot cannot enable HIPAA; the add-on, BAA and per-location switch are account steps, and compliance also depends on the practice’s own policies |
| Buying the HIPAA add-on before any legal opinion | It is permanent and costs $3,564 a year |
| No mention of A2P 10DLC | Texts will be filtered or blocked |
| One opt-in checkbox for everything | Promotional texts need their own written agreement |
| “Only send review links to 5-star clients” | Conflicts with the FTC’s guidance on selective solicitation |
| Before-and-after photos collected by SMS into the CRM | Moves identifiable images into the wrong system |
| Guaranteed bookings or revenue | No builder controls your offer, demand or front desk |
When does a med spa not need a GoHighLevel setup agency?
A med spa does not need a setup agency when it is one cash-pay location with no HIPAA requirement, no booking-platform sync, a small client list and someone on staff who will own the account every week. In that case, DIY with HighLevel’s own setup options is reasonable.
An honest DIY path looks like this:
- Use HighLevel’s 14-day trial to test phone routing and A2P approval before paying for a full month.
- Consider HighLevel’s own generic setup packages (the $299 Basic Account Setup listing, or the $1,000 done-with-you option) if you want someone to configure the basics.
- Build three workflows only: missed-call and inquiry response, consultation reminders and review requests. Watch each for a week before adding the next.
- Keep the booking platform’s own reminders switched off for anything GoHighLevel now sends, so clients do not get two texts.
- Check what your existing medical spa CRM software already does. Booking platforms’ native texting and marketing tools may cover reminders and reviews, and GoHighLevel is overbuilt for a practice that only wants those.
Hire help when the work moves outside that box: HIPAA, a Boulevard or Zenoti sync, several locations sharing templates, or a reactivation list of thousands with messy consent history. Those are where mistakes are expensive and hard to undo. The same logic applies in dentistry; our dental practice setup page covers a comparable HIPAA-first build.
How does aibrevo run a GoHighLevel setup for a med spa?
aibrevo runs each med spa build as a scoped project: a written scope and message classification first, the HIPAA decision and registrations started in week one, the booking-platform connection proven before automations depend on it, and a staged launch with documentation and a named owner.
The steps:
- Discovery call and written scope. Treatments, lead sources, booking platform, deposit and cancellation policies, membership types, locations and current consent wording. You get a deliverables list and a fixed price within our published range.
- Compliance decisions. We ask for your counsel’s view on HIPAA status before any add-on is bought, and we write the reminder versus promotion classification with you.
- Account, registration and domain. Plan, users, MFA, HIPAA and BAA if applicable, per-location activation, A2P 10DLC and sending-domain authentication.
- Booking-platform connection. Zapier, webhooks or API, depending on your vendor and plan, with a field-ownership map.
- Build, test and launch in stages. The six workflows above, tested with dummy contacts, then switched on one at a time.
- Handoff. Written documentation of every workflow, a recorded walkthrough and a named owner on your side.
Alpit Patel founded aibrevo in San Francisco in 2021 and has personally overseen 320+ GoHighLevel implementations through autoesta and HighLevel Automation Team; aibrevo’s own 16-person engineering team, led by CTO Shivam, applies that same approach to every build. You can read more about Alpit’s background and our GoHighLevel implementation service.
Pricing is published: $500 to $4,000 for a complete single-business CRM setup and $4,000 to $12,000 for multi-location, on our pricing page. To scope your practice, book a strategy call or send us a message.
Sources
- HighLevel, Pricing: Starter $97, Unlimited $297, Agency Pro $497 a month, 14-day trial, HIPAA add-on $297 a month. Checked 30 September 2026.
- HighLevel Support, HIPAA Compliance with HighLevel: not compliant by default, purchase and BAA steps, per-sub-account activation, covered data types, permanence. Updated 11 June 2026; checked 30 September 2026.
- HighLevel Support, A2P 10DLC messaging fees: $22.50 low-volume standard brand fee including $3 Fast Track, $64 high-volume, $15 per additional campaign, $10 a month standard campaign, Fast Track approval within 3 business days. Modified 24 September 2026; checked 30 September 2026.
- HighLevel Support, phone system pricing and billing guide: SMS $0.00747 per segment, local number $1.15 a month, email $0.675 per 1,000. Modified 1 September 2026, as cited on aibrevo’s twin pages.
- HighLevel marketplace setup listings ($299 Basic Account Setup, $1,000 Advanced Account Setup) and certifications page (Certified Admin $97 a month or $970 a year; HIPAA track), as recorded on aibrevo’s setup agency page, checked 20 September 2026.
- Snapshot exclusions (contacts, credentials, A2P, billing, users, numbers, domains): HighLevel documentation and community guides as summarised on aibrevo’s setup agency and snapshots pages, 20 September 2026.
- Zapier, Boulevard integrations: 9 triggers and 7 actions. Checked 30 September 2026.
- Boulevard Support, Connect custom and public apps to Boulevard: API access for Enterprise customers. Checked 30 September 2026.
- Zapier, Zenoti integrations (40 triggers, 9 actions) and Zenoti API documentation (webhooks). Checked 30 September 2026.
- Mangomint, Webhooks integration: webhook events and staff-configured setup; no Zapier app or public API found. Checked 30 September 2026.
- Vagaro, APIs and webhooks (enable via Enterprise Sales) and API documentation (event categories). Checked 30 September 2026.
- Aesthetic Record Learning Lab, Zapier integration, and Zapier’s Aesthetic Record EMR plus LeadConnector page: New Patient and New Invoice triggers, paid Zapier account. Checked 30 September 2026.
- Keragon, Zenoti to GoHighLevel: vendor claim of a HIPAA-oriented connector, not independently tested. Checked 30 September 2026.
- CTIA, Messaging Principles and Best Practices, May 2023: sections 5.1 to 5.3 and Exhibit II (informational versus promotional consent, confirmation, opt-out). Checked 30 September 2026.
- Florida Senate, Florida Statutes section 501.059, 2025: text messages included in telephonic sales calls, prior express written consent, $500 damages. Checked 30 September 2026.
- CMS, Are you a covered entity?, and HHS, Marketing guidance, as cited on aibrevo’s twin page, 20 September 2026.
- Cornell LII, 45 CFR 164.514: full-face photographs listed among de-identification identifiers. Checked 30 September 2026.
- FTC, Consumer Reviews and Testimonials Rule: Questions and Answers: effective 21 October 2024, sentiment-conditioned incentives, selective solicitation. Checked 30 September 2026. FTC Endorsement Guides, 16 CFR Part 255.
- AmSpa, Med spa statistics: 2024 repeat-patient rate 73%, $527 average spend per visit, as cited on aibrevo’s twin pages.
- aibrevo, pricing: CRM setup $500 to $4,000; multi-location $4,000 to $12,000.