Most med spas running on HighLevel have the same gap. The CRM handles leads, pipelines and campaigns brilliantly. Then a patient starts treatment, and everything after that — refills, dose adherence, "where's my order?", the reason they either stay or quietly disappear at week nine — happens in text threads, spreadsheets and memory.
A patient portal closes that gap. This guide covers what to set up, in what order, and the decisions that matter before you send the link to a single patient.
What a patient portal actually needs to do
Ignore feature lists for a moment. For a med spa or telehealth clinic selling ongoing treatment, a portal earns its place if it does four things:
- Sells refills without you asking. Reordering has to live inside the routine the patient already has, not behind a phone call to your front desk.
- Makes progress visible. Patients who can see 15 pounds lost or a twelve-week streak stay on plan. Patients who see nothing drift.
- Answers "where is it?" without a human. Order status and tracking, visible to the patient, removes a surprising share of your inbound messages.
- Keeps your CRM as the source of truth. If the portal becomes a second system your team has to check, you have added work, not removed it.
That last point is why the HighLevel connection matters more than any individual feature.
Step 1: Claim your portal and brand it
Sign up and pick your subdomain — yourclinic.hlpatientportal.com — then add your logo and brand colors. The portal your patients see should look like your clinic, not like software you bought.
Two things worth getting right on day one:
- Use a logo file with transparent padding. Wordmarks with tight crops end up cramped in the header. If your logo is light-colored, set the logo background to your primary color so it doesn't vanish on white.
- Set your support email to an address you actually monitor. It appears to patients throughout the portal and on every automated email.
On the Growth plan and above you can point a custom domain at the portal, so patients never see a vendor URL at all.
Step 2: Connect HighLevel
This is a two-click OAuth connection from Settings — choose the HighLevel account, authorize, done. There is no Zapier step and no CSV import.
Once connected, four things start happening automatically:
- Patients sync as contacts. A new portal signup becomes a HighLevel contact; an existing contact links up rather than duplicating.
- Orders land as payments. Revenue from the portal shows on your HighLevel dashboard alongside everything else.
- Custom fields update on the contact. Dose streak, total doses, last weight, last order — the fields your smart lists and segments can filter on.
- Workflow triggers fire on real patient behavior. A missed injection, a broken streak, an order marked shipped, a milestone hit.
That fourth one is where clinics get the most leverage. A "reorder due" trigger firing an SMS three days before supply runs out is a revenue automation you build once.
If you don't run HighLevel, none of this is required — the portal has its own messaging, campaigns and analytics built in. The integration is an accelerant for clinics already invested in the CRM, not a dependency.
Step 3: Add treatments and connect payouts
List what you sell — treatments, packages, supplements — with the variants and strengths patients actually order. A few things to decide here:
- Prescription items get a physician review step before fulfilment, so the order flow reflects how you already practice.
- Supply length per variant drives the reorder prompt. A 28-day supply means the portal knows to surface the buy button at the right moment, without you scheduling anything.
- Stripe Connect sends revenue straight to your own Stripe account. The platform never holds your money.
Step 4: Decide what patients track
Turn on only what fits your program. A GLP-1 clinic wants weight and dose tracking. A hormone therapy clinic wants the symptom diary and dose logging, and should turn weight tracking off entirely — an irrelevant tracker on the home screen makes the whole app feel generic.
The tracking features are per-clinic toggles, so this is a settings decision, not a development request.
Step 5: Invite patients
Share your portal link. Existing patients can claim an account against the email you already have on file, which matters — a patient who has to re-register from scratch often doesn't.
Start with the cohort most likely to reorder: patients currently mid-treatment with a refill due in the next month. They get immediate value from tracking and a reorder button, which means your first week of portal data shows real engagement rather than tumbleweed.
What to measure in the first 30 days
Three numbers tell you whether the portal is working:
- Activation rate. What share of invited patients claimed an account. Below 40% usually means the invite email needs work, not the portal.
- Logging frequency. Patients logging doses or weight at least weekly are the ones who reorder. This is your leading indicator.
- Reorder rate versus your pre-portal baseline. The number that pays for everything else.
A note on HIPAA
If you are handling medical information — and you are — the portal you choose needs to be built for it, not retrofitted. That means records encrypted at rest and in transit, audit logging on every access to patient data, two-factor authentication for staff, and complete isolation between clinics.
It also means being careful about what you bolt on. Analytics and advertising pixels inside a patient-facing portal are a genuine compliance risk, and it is worth confirming your vendor doesn't ship them by default.
Setting up the portal takes an afternoon. Getting the program right — which patients to invite first, which triggers to automate, what to measure — is the part that decides whether it becomes revenue or another tab nobody opens.