HighLevel logo
HighLevel
Create
Roadmap
Feedback
HIPAA Compliance
12
Changelog
Log in to your HighLevel account to give feedback

    Boards

  • Ad Reporting and Attribution

  • APIs

  • App Marketplace

  • Ad Manager

  • Automations

  • AI Employee

  • Voice AI

  • Conversation AI

  • Content AI

  • Blog

  • Bulk Actions

  • Calendar

  • Call Tracking

  • Client Portal

  • Communities

  • Company Object

  • Conversations

  • Certificates

  • Contacts

  • Custom Objects

  • CRM

  • Dashboard

  • Documents & Contracts

  • Domains

  • E-commerce Stores

  • Email Builder

  • Eliza

  • FB/ IG Messenger

  • Forms

  • Funnels

  • Google My Business

  • HL Affiliate Portal

  • Integrations

  • Invoicing

  • Phone System

  • LC Email System

  • Courses

  • Mobile App

  • Media Library

  • Agency Onboarding

  • Opportunities & Pipelines

  • Payments

  • Prospecting Tool

  • Reporting

  • Reputation Management

  • SaaS Mode

  • Smartlists

  • Snapshots

  • Social Planner

  • Sub-account Affiliate Manager

  • Surveys

  • Tasks

  • Template Library

  • Users & Permissions

  • Website

  • Whatsapp

  • Widgets

  • Wordpress

  • Listings

  • Chat Widget

  • Language - Internationalization

  • Payment Links

  • QR Codes

  • Quizzes

  • Reviews AI

  • POS and Mobile Payments

  • Reselling

  • Location Launchpad

  • HIPAA Compliance

  • Priority support

  • Go Kollab

  • SEO

  • Marketplace new app request

  • RCS Messaging

Powered by Canny

HIPAA Compliance

posts
Exposed media uploads
The media upload of files is publicly available. Even though the link is not necessarily easy to guess, the data is still publicly available and presents a flaw on data protection. Enabling HIPAA compliance does not make any difference, the media items have no request for authentication when visiting a link to the uploaded file. All form fields should be treated as sensitive data, including file uploads. This is a security risk for anyone using the file upload form field to collect personal data in some way.
9
·

under review

Powered by Canny