You sold a dental practice on a booking system, automated reminders and review requests. Then the office manager logs in and sees a menu that talks about Contacts, Opportunities and Memberships, a bright blue interface that feels nothing like their calm, clinical brand, and a dozen modules nobody at the front desk will ever open. The software works. It just does not feel like it was made for a practice.
This guide covers how to set up HighLevel for dental and medical practices so it fits the way a practice works and looks like your agency’s platform. It covers the compliance question you must answer first, the menu wording and colors that suit healthcare, how to keep patient data off your screen during calls, a step-by-step setup with HighLevel’s menu paths, a first-week rollout for the front desk, and the limits of what branding can do. GHL Dashboard Builder is an independent design service and is not affiliated with HighLevel; where our product helps, we say so and say what it does not do. Nothing here is legal advice.
What does a dental or medical practice need from HighLevel?
A practice needs fewer things than HighLevel offers, presented in words its staff already use. The core is appointments, patient messages, reminders, reviews and new-patient intake. Everything else is optional, and every unused menu item is something a receptionist has to learn to ignore.
Think about who uses the account each day. In most practices it is not the dentist or the doctor. It is the front desk, a treatment coordinator or an office manager, often switching between HighLevel and the practice management software that holds the clinical record. They need to see today’s appointments, answer messages, confirm tomorrow’s patients and send review requests after visits. They do not need to understand what a pipeline is.
Here is how the main HighLevel modules map to a practice’s daily work.
| HighLevel module | What a practice uses it for | Typical user |
|---|---|---|
| Calendars | New-patient bookings, hygiene and follow-up appointments | Front desk |
| Conversations | Replies to texts, emails, web chat and social messages in one inbox | Front desk |
| Contacts | The list of patients and prospective patients | Front desk, office manager |
| Opportunities | Treatment plans that are presented but not yet accepted | Treatment coordinator |
| Automation (workflows) | Booking confirmations, reminders, recall and no-show follow-up | Agency, office manager |
| Reputation | Review requests after visits and replies to reviews | Office manager |
| Sites and forms | The practice’s landing pages and new-patient forms | Agency |
| Reporting | Bookings, sources and campaign results | Owner, agency |
HighLevel itself publishes material aimed at this market, including an operations playbook for dental practices in its help center, so the building blocks are there. The gap is presentation: the same modules appear with the same generic names whether the client is a dental group or a roofing company.
Two terms will come up often in this guide. Protected health information (PHI) is health information that identifies a patient, as defined by the U.S. HIPAA rules; ePHI is the electronic version. A business associate agreement (BAA) is the contract HIPAA requires between a healthcare provider and a vendor that handles PHI on its behalf.
Is HighLevel HIPAA compliant for dental and medical practices?
Not by default. HighLevel’s help center states that accounts are not HIPAA compliant out of the box and offers an optional add-on that makes HIPAA-covered use possible. Whether a practice needs it depends on whether PHI will be stored or sent through HighLevel, and for most clinical practices in the U.S. the honest answer is yes.
According to HighLevel’s article on HIPAA compliance, the add-on is account-wide and enables encryption of ePHI, a business associate agreement, audit logging and enforced multi-factor authentication. At the time of writing it costs US$297 per month and cannot be disabled once purchased. HighLevel sends the BAA for signature after purchase and turns HIPAA mode on once it is returned; the same article puts the whole process at about 48 to 72 hours.
Why the BAA matters: the U.S. Department of Health and Human Services explains in its guidance on HIPAA and cloud computing that a cloud provider which creates, receives, maintains or transmits ePHI for a covered entity is a business associate, and that a business associate agreement is required. That reasoning applies to the software and may apply to you. An agency that manages a practice’s account, reads its conversations or builds workflows that touch patient records may also be handling PHI on the practice’s behalf. Ask a healthcare compliance adviser whether you need your own BAA with each practice.
The chart below puts the add-on next to HighLevel’s main plans, so you can see the monthly cost of serving practices that need it.
Source: gohighlevel.com/pricing and HighLevel Help Center, HIPAA Compliance With HighLevel, checked October 2026. Prices can change.
Confirm current plan prices on HighLevel’s pricing page before you quote a practice. Because the add-on applies across your account, many agencies price it into their healthcare offer as a fixed cost rather than charging each practice separately.
What branding does and does not change
It is worth being blunt about this, because agencies sometimes blur the two in sales conversations.
| Question | Handled by branding | Handled by compliance |
|---|---|---|
| Does the menu say Patients? | Yes | No |
| Are the colors calm and on-brand? | Yes | No |
| Is ePHI encrypted? | No | HighLevel’s HIPAA add-on |
| Is there a signed BAA? | No | Between the parties, with HighLevel’s add-on |
| Who can see which patient records? | No | User roles and permissions, practice policy |
| Are patient names hidden on a screen share? | Visual blur only | Practice and agency policy |
| Are messages to patients appropriate? | No | Practice policy and HIPAA guidance |
A theme is a layer of paint and signposting. It can make the right thing easier to find, and it can hide private data on your own screen, but it is never a compliance control.
How should the HighLevel menu read for a practice?
Use the words the front desk already uses: Patients, not Contacts; Treatments or Treatment Plans, not Opportunities; Appointments, if Calendars confuses anyone. Then hide the modules the practice does not use. A shorter menu in familiar words is the single change that most reduces training time.
HighLevel does not offer a setting to rename its main menu items. Agencies do it with custom JavaScript added at agency level, which our complete guide to white-labeling HighLevel explains in detail, along with what HighLevel’s built-in white-label settings cover.
Here is a menu map that works for most dental and medical practices. Treat it as a starting point and ask the office manager what they call each thing.
| HighLevel calls it | Suggested label | Show or hide | Why |
|---|---|---|---|
| Contacts | Patients | Show | The word every practice uses |
| Opportunities | Treatments | Show | Accepted and pending treatment plans |
| Calendars | Calendars or Appointments | Show | Keep the original if staff already know it |
| Conversations | Conversations or Messages | Show | The front desk inbox |
| Reputation | Reviews | Show | Review requests after visits |
| Memberships | Hide | Courses and communities are rarely used by practices | |
| Launchpad | Hide after setup | Useful during onboarding, clutter afterwards | |
| App Marketplace | Hide | Agency territory, not front desk | |
| AI Studio and other beta tools | Hide until tested | Check how they handle patient data first |
The last row deserves a moment. Before you show a practice any AI feature that reads conversations or contact records, find out from HighLevel which features are covered by its HIPAA arrangement. If you cannot get a clear answer, hide the item for healthcare sub-accounts and revisit later.
Our Clinic template applies this pattern by default. Of HighLevel’s 19 menu items, it renames two, hides four and keeps the rest in their usual places so nothing moves unexpectedly for staff who have used HighLevel before.
Source: GHL Dashboard Builder Clinic template, October 2026
Which colors and design suit a healthcare dashboard?
Choose calm, light colors with one strong brand color, and check that every piece of text on that color is easy to read. Healthcare brands lean on teals, blues and soft greens because they read as clean and trustworthy. The trap is that many of those shades are too light to carry white text.
The W3C’s accessibility guidance sets a minimum contrast ratio of 4.5 to 1 for normal text. Practices see older patients and employ staff of every age, and many front desks work under bright overhead lights on modest monitors, so contrast is a practical concern as well as an accessibility one.
We measured the contrast of four color pairs from our own Clinic template with the WCAG formula. The deep teal used for buttons passes comfortably with white text. The bright accent teal, which looks lovely in a mock-up, does not.
Source: Calculated with the WCAG 2.2 contrast formula from the Clinic template's colors, October 2026. Minimum for normal text: 4.5 to 1.
The lesson is not to avoid bright teal. Use it for accents, icons and thin lines, and use a darker shade wherever text sits on top of it. The same applies to the practice’s own logo color: if their brand green is pale, darken it for buttons and keep the original for the logo.
Design choices that work for practices
- A light sidebar. A white or very pale sidebar with a tinted active item feels clinical and calm, and it keeps the dashboard from looking like a developer tool.
- Generous spacing. Front-desk staff scan the screen while talking on the phone. More space between items reduces misclicks.
- Rounded, soft cards. Friendlier than sharp corners, and consistent with most practice websites.
- One accent color. Use the brand color for the primary button and the active menu item only. If everything is teal, nothing stands out.
- A welcome line. A greeting with the user’s name, the date and quick links to today’s calendar and messages gives the dashboard a clear starting point each morning.
A group practice with a strong existing brand may want its own colors rather than a template’s. That is fine; the contrast rule still applies.
How do you keep patient data off your screen during demos and calls?
Use sample data for every demo, and blur real data whenever you have to show a live practice account. Agencies share screens constantly: sales calls, support sessions, training recordings, quick looks in a team chat. Each one can show patient names, phone numbers and message previews to people who have no reason to see them.
HIPAA’s Privacy Rule expects reasonable safeguards here. HHS describes the minimum necessary requirement as limiting uses and disclosures of PHI to what is needed for the purpose. Its guidance on incidental uses and disclosures allows for some unavoidable exposure only when reasonable safeguards are in place, and gives examples such as positioning computer screens away from public view. A screen share is a public view of a different kind.
A practical routine for any agency serving practices:
- Build a demo sub-account. Fill it with clearly fake patients, appointments and conversations. Use it for every sales call and every training video.
- Never record in a live practice account unless private data is hidden first.
- Close the conversations panel before you share a screen; message previews are the most common leak.
- Share one browser tab, not your whole screen, so notifications and other accounts stay private.
- Check recordings before you send them. A two-minute look is cheaper than a recall.
- Write the routine down and give it to every team member and contractor.
Messages to patients are a separate question
The dashboard is only one place PHI appears. Workflows also send texts and emails to patients. HHS’s FAQ on emailing patients says the Privacy Rule does not prohibit unencrypted email for treatment-related communication but expects safeguards, such as limiting the amount or type of information included. In practice, keep reminders short: a first name, the time and the practice’s name, with no procedure or condition. Let the practice sign off on every template.
Privacy mode is a visual safeguard on your own screen. It does not encrypt anything, change who can access records or replace the routine above; it makes the routine easier to follow.
How do you set up HighLevel for a dental or medical practice, step by step?
Settle compliance, then build the account, then brand it, then test with the people who will use it. The order matters, because some decisions, such as the HIPAA add-on, cannot be undone, and branding is easier to adjust once the account’s structure is final. Menu paths below match HighLevel’s help center at the time of writing; HighLevel moves things occasionally.
Step 1: Decide on compliance
- Ask the practice whether PHI will be stored or sent in HighLevel: appointment reasons, treatment notes, intake form answers, insurance details.
- If yes, review HighLevel’s HIPAA article with the practice and, ideally, their compliance adviser.
- Purchase the add-on, sign and return HighLevel’s BAA, and confirm HIPAA is enabled before any patient data is imported.
- Decide with the practice whether you, as their agency, need a BAA of your own.
Step 2: Build the account
- Create the practice’s sub-account from the agency view.
- Set the time zone and business hours under the sub-account’s Settings, Business Profile.
- Create calendars for each appointment type: new patient, hygiene, consultation, follow-up.
- Build the confirmation and reminder workflows under Automation, triggered by appointment status. Keep message text minimal, as discussed above.
- Connect the practice’s Google Business Profile under Reputation, Settings so review requests point to the right listing. HighLevel’s guide to reviews and review requests covers the review link and widget.
- Add user accounts for each staff member with only the permissions they need.
Step 3: Brand the dashboard
- Complete the identity layer at agency level under Settings, Company: logo, white-label domain and legal links.
- Choose or design the theme: colors, menu wording, hidden items, welcome banner.
- In the agency view, open Settings, Company, Whitelabel and scroll to Custom Code.
- Copy whatever is already in the Custom CSS and Custom JavaScript boxes into a text file as your rollback.
- Paste the new CSS and JavaScript and save. HighLevel shows a warning about third-party scripts; read it and confirm only if you trust the code.
- Open the practice’s sub-account in a new tab and refresh.
Step 4: Test with real users
- Log in as a front-desk user, not as an admin, and walk through a normal morning: today’s calendar, a new message, a booking, a review request.
- Check every dropdown and pop-up for readable text.
- Narrow the browser window to tablet width, since some front desks use tablets at check-in.
- Ask one staff member to find three things without help, and note where they hesitate.
That is 20 steps across four stages. The compliance stage is one of the shortest lists and the one with the most lasting consequences, so do not rush it.
How do you onboard the front desk in the first week?
Train the front desk on four tasks, not on HighLevel. Staff do not need a tour of every module; they need to book, reply, confirm and request a review with confidence. A renamed, trimmed menu makes that training shorter, because every item they see is one they use.
Here is a first-week plan that fits around a working practice.
| Day | Session (about 20 minutes) | Done when |
|---|---|---|
| 1 | Logging in on the practice’s address, the menu, the welcome screen | Everyone can log in and find Patients and Calendars |
| 2 | Booking, moving and cancelling appointments | Each person books a test appointment |
| 3 | The Conversations inbox: replying, assigning, closing | Each person replies to a test message |
| 4 | Confirmations and reminders: what goes out and when | Staff can explain what a patient receives |
| 5 | Review requests after visits | The office manager sends one to a test contact |
Keep sessions short and in the practice’s own account, with the demo data or with privacy mode on if you are recording. Record each session once, using sample data, so new hires can watch it later.
Three habits make the first month smoother:
- Name one owner at the practice. Usually the office manager. Changes to wording, workflows and users go through that person.
- Agree a channel for questions. One shared thread is better than staff messaging different people at the agency.
- Review after 30 days. Ask which menu items nobody opened and hide them. Ask what they still call things and rename accordingly.
Should every practice in your agency get the same look?
Not necessarily. Agencies that serve practices alongside other industries often want healthcare sub-accounts to look clinical without changing everyone else’s dashboard. Dental groups with several locations may want their own brand while your other clients keep yours.
Agency-level custom code in HighLevel applies across the interface your users see, including sub-account views. To give one practice its own look, the theme has to check which sub-account is open, using its Location ID, and apply the design only there. HighLevel shows the Location ID in the web address when you open a sub-account.
Common situations where a separate look makes sense:
- A premium client. A large dental group pays for a fully branded platform with its own colors and name.
- A pilot. You want to test a new healthcare design on one practice before rolling it out to all of them.
- A mixed agency. Your practices get Patients and teal; your other clients keep Contacts and your agency brand.
- A multi-location group. Each location is a sub-account, and all of them should share the group’s brand rather than yours.
What if the front desk works in another language?
Translate the menu for the people who use it every day. In many practices the staff answering phones and messages speak a language other than English at home, and in some markets the whole team works in it. A menu in their language reduces the small hesitations that add up over a busy day.
In the U.S., a bilingual front desk might prefer a Spanish menu while the practice owner keeps English. Outside the U.S., our market page for the United Arab Emirates is one of several, alongside Saudi Arabia, Egypt, Pakistan and Türkiye, where the Clinic template is among the suggested designs; our guide to white-labeling HighLevel in the United Arab Emirates covers what changes when the dashboard runs right-to-left in Arabic.
Two limits to explain to the practice up front:
- The menu and navigation can be translated by a theme; HighLevel’s own pages follow HighLevel’s language settings. Check the screens staff use most, such as the calendar and conversations, before promising a fully translated system.
- Patient-facing messages are separate. Reminders, review requests and forms are written in the workflow and form builders, in whatever language the practice chooses. Translate them with the practice, not by machine, because wording around health is sensitive.
What can go wrong, and what doesn’t branding solve?
Most problems come from treating branding as more than it is, or from skipping the test with real users. A theme is custom code running in the browser. HighLevel provides the place for it but does not officially support it, so a HighLevel update can occasionally leave part of a screen unstyled until the theme is refreshed.
| Problem | Why it happens | What to do |
|---|---|---|
| A practice believes the branded platform is “HIPAA compliant” | Branding and compliance were presented together | Explain the difference in writing; point to the HIPAA add-on and BAA |
| Staff cannot read button text | A pale brand color with white text | Darken the color for buttons; check 4.5 to 1 |
| Part of a screen loses its styling after an update | HighLevel changed that screen’s structure | Update the theme; keep a rollback copy of the old code |
| Patient names appear in a training video | Recorded in a live account without blur | Use the demo sub-account; review recordings before sharing |
| The renamed menu confuses the agency’s own support team | Support staff look for Contacts and see Patients | Keep a one-page map of renamed items for your team |
| A hidden module is needed after all | It was hidden without asking the practice | Review hidden items after 30 days; un-hiding is one setting |
| Different practices want different looks | Agency-level code reaches every sub-account | Use a theme that can target sub-accounts by Location ID |
What branding will never do
- It will not make HighLevel HIPAA compliant, sign a BAA or encrypt anything.
- It will not change HighLevel’s features, data or permissions.
- It will not change the mobile app, the emails HighLevel sends or patient-facing forms.
- It will not replace the practice’s management software, which normally remains the clinical record.
Being clear about these limits in the sales conversation protects you. A practice that knows exactly what it is buying is less likely to be surprised later.
How does GHL Dashboard Builder handle dental and medical practices?
GHL Dashboard Builder is a design service and visual builder that produces the CSS and JavaScript for a branded HighLevel and installs it with two short lines in HighLevel’s Custom Code boxes. For practices, the relevant pieces are the Clinic template, the menu editor, privacy mode, single sub-account targeting and languages. Here is what each does, taken from the product as it stands today.
- The Clinic template. A white sidebar, medical teal, soft cards and a welcome banner that points staff to the day’s appointments and patients. The menu comes with Contacts renamed Patients and Opportunities renamed Treatments, and Launchpad, AI Studio, Memberships and the App Marketplace hidden. You can see it on the Clinic template page and try it in the free builder.
- The menu editor. Rename, reorder and hide any of HighLevel’s 19 menu items and add badges. On the Pro plan you choose your own wording, such as Treatment Plans or Appointments.
- Privacy mode. An eye button in HighLevel’s header that blurs contact names, emails, phone numbers, the conversation list and deal values. It is included from the Starter plan.
- One sub-account or all. Apply the design to every sub-account or only to selected practices.
- Languages. The menu and navigation in 15 languages, with right-to-left layouts for Arabic, Urdu and Hebrew. Included on Pro.
- Hosted install. Instead of pasting pages of code, you paste one CSS line and one JavaScript line. Change the design later and HighLevel picks up the new version.
On data: the builder never connects to your HighLevel account, and the installed code changes styling and menu labels only. It does not read or send your clients’ data anywhere. It is still custom code, so it carries the same caveat as any custom code in HighLevel, and it is not a compliance measure.
The features page lists everything that installs into HighLevel and what is preview only. Current plans and prices are Starter at US$149 one-time for one branded dashboard from a template, Pro at US$349 one-time for a custom design with menu renames, languages and installation by us, and Agency at US$99 per month for new themes when you need them and re-checks after HighLevel releases. If your agency mainly serves healthcare, our page on who the builder is for covers niche agencies in more detail.
An example rollout for a three-chair dental practice
This is an illustrative example, not a customer story. It shows how the pieces in this guide fit together over two weeks for a small practice.
Days 1 and 2: compliance. The agency confirms with the practice that intake answers and appointment reasons will live in HighLevel. The HIPAA add-on is already active on the agency account, so the practice’s sub-account is created inside it. The practice’s adviser reviews the agency’s own agreement.
Days 3 to 5: the account. Calendars for new patients, hygiene and emergencies. A confirmation on booking, a reminder the day before and a review request after the visit, each with short wording the office manager approves. Google Business Profile connected under Reputation.
Day 6: the look. The agency starts from the Clinic template, swaps in the practice’s logo and darkens its brand green for buttons after a contrast check. Contacts reads Patients, Opportunities reads Treatments, Reputation reads Reviews. The design is applied to this sub-account only, because the agency’s other clients are home-service businesses.
Day 7: testing. A front-desk user walks through a normal morning. One dropdown has unreadable text and is fixed. The agency records a short welcome video in its demo sub-account, not the live one.
Week two: training. The five 20-minute sessions from the table above, one per day. At the end of the week the office manager sends the first real review request.
Day 30: review. Nobody at the front desk opened Sites or Reporting. Reporting stays for the owner; Sites is hidden, because the agency manages the website. The front desk asks for Calendars to read Appointments, and it is renamed.
Nothing in this rollout required changing how HighLevel works. What changed is what the front desk sees at eight in the morning: their words, their colors and only the tools they use.
What to do next
- Answer the compliance question first. For each practice, decide whether PHI will be in HighLevel. If so, read HighLevel’s HIPAA article, plan for the add-on and a BAA, and talk to a compliance adviser about your own role.
- Build a demo sub-account with fake patients and use it for every sales call and training video from now on.
- Draft the menu map for your next practice with the office manager: what they call each item, and what to hide.
- Try the Clinic look on HighLevel’s screens in the free builder, with the practice’s colors and logo, and check the contrast of every button.
- Roll out to one practice, run the first-week training plan, and review hidden items and wording after 30 days.
If you would rather have the design done for you, or your healthcare clients need something no template covers, get in touch and tell us about the practices you serve.


