Notes Attachments Now Private by Default, Enhancing Security
TL;DR
HighLevel has updated its notes feature, making all new document attachments private by default to improve security and compliance.

TL;DR
New note attachments are private by default. Existing attachments remain public. No immediate action is required unless you need to secure existing documents.
Who this affects
HighLevel users who attach documents to notes, particularly those concerned with document security or HIPAA compliance.
What changed
- Documents uploaded as attachments through the notes section are now private by default.
- Previously, documents uploaded through notes were public.
- New note attachments are stored in the 'Notes attachments' folder under Documents.
- Users can choose access levels when sharing documents: public, private, OTP-protected, or password-protected.
- Existing documents uploaded through notes remain public.
- Users can generate and share a private link for existing documents.
- HighLevel has not confirmed rollout status, limits, or plan gating.
Where to find it
Within the Notes section when attaching documents. New attachments will be in the 'Notes attachments' folder under Documents.
How agencies will use this
An agency managing sensitive client data can now attach documents directly to contact notes without concern that the attachment is publicly accessible by default. For example, a medical practice using HighLevel can attach a client's health history to their contact record note. This document is now private automatically, helping the practice maintain HIPAA compliance. If specific external access is needed, the agency can generate a secure, password-protected link for that document.
Our take
This is a standard security update. It matters for agencies handling sensitive data, as it reduces the risk of accidental public exposure for new documents. For others, it's a minor change that improves the platform's baseline security. HighLevel has not confirmed who is affected, when it rolled out, or if it replaces any existing functionality.
Source: Official HighLevel announcement


