Anyone opening GoHighLevel for the first time is met with an automation builder holding dozens of blocks and the feeling that anything is possible. That is exactly the moment most practices stall: everything can be built, so nothing gets built. This article lists seven concrete automations — the ones that produce a measurable benefit in a medical practice while staying inside the rules of healthcare communication. For each one: what it does, how it is built, and where the line sits.

If you are still deciding whether the platform belongs in your practice at all, the scope of our own work with it is described on the GoHighLevel for medical practices page.

Before the workflows: the foundations

An automation built on messy data amplifies the mess. Three things need sorting before you touch the workflow builder.

Tags. A minimal, stable scheme: contact source (website, phone, referral, campaign), status (new, awaiting callback, booked, active patient, inactive), consent (marketing yes/no). Tags invented along the way become three hundred tags in six months and stop meaning anything.

Custom fields. Date of last appointment, type of service in logistical terms, preferred channel. No field holding clinical information: the CRM is not the medical record.

The pipeline. The real stages of an enquiry in your practice, not the ones from a sales manual: enquiry received, contacted, appointment booked, attended, closed. Five stages are enough.

With those foundations in place, each of the workflows below takes hours to build. Without them, you spend your time patching.

1. Instant acknowledgement of an enquiry

What it does. When an enquiry arrives from the website or the phone, the contact enters the CRM tagged with its source, receives a message within seconds confirming that the request was received, and a task with a due date is created for the front desk.

How it is built. Trigger on form submission (or on a missed call recorded against the practice number), create-or-update contact action, source tag, confirmation SMS or email, opportunity created in the pipeline, internal notification.

The boundary. The message confirms receipt and states a realistic callback window. It promises no treatment, anticipates nothing clinical, and never says "we'll sort it out right away".

This is the highest value-to-effort automation in the entire list: someone who writes in knows they have been heard, and stops shopping around while they wait.

2. Appointment reminders on a cadence

What it does. Confirmation at booking, a reminder 48 to 72 hours out, and a same-day reminder where it helps. On the channel the patient actually uses, with SMS as the safety net.

How it is built. Trigger on appointment created in the calendar, wait steps relative to the appointment date, sends conditioned on the available channel and on the absence of a previous reply.

The boundary. Date, time, place, and the practitioner if relevant. Never the service, and never the department when the department reveals the condition. The wording says "let us know if you can't make it", not "please confirm".

3. Missed-call recovery

What it does. When a call to the practice number goes unanswered, an SMS goes out to the caller automatically and a priority callback task is created.

How it is built. This requires the published number to be handled by the platform or forwarded to it. Trigger on the unanswered call, immediate SMS, contact created if it does not exist, task assigned to the front desk.

The boundary. The message is a service message: "Sorry we missed your call. Write to us here or call back on [number] and we'll get back to you as soon as we can." No promotional content, no questions about symptoms.

One clarification is worth making: this workflow collects and organises, it does not answer. If the goal is for someone to genuinely answer outside opening hours, that is a different problem, and it belongs to the virtual front desk.

4. Review request after the visit

What it does. A few hours after a completed appointment, the patient receives a message with a direct link to the practice's Google listing. One reminder a few days later, then it stops.

How it is built. Trigger on the appointment marked as attended, a wait of some hours, a message carrying the short review link, exit condition on reply or click.

The boundary, and here it is a heavy one. The workflow sends to every patient in the group, with no pre-filtering: review gating — an internal survey that diverts unhappy patients away from the public listing — is against Google's policies and is simply dishonest. No incentives of any kind. No reference to the treatment received. The service built around this is Aurea.

5. Periodic recall

What it does. When a patient passes a time threshold set by the practice — 8 to 12 months for a hygiene appointment, 12 to 18 for a specialist check-up — they receive a message reminding them that they can book.

How it is built. The engine is a date field (last appointment) plus a time condition. The workflow checks the marketing consent tag before any send, and anyone without it leaves the branch having received nothing.

The boundary, the most important of them all. Recall is promotional communication, so it requires valid, documented marketing consent, a generic message, and an opt-out that is always available and honoured immediately. It also runs into advertising rules that vary by country: in Italy, Law 145/2018 as amended by Decree-Law 69/2023 prohibits attention-grabbing or suggestive elements — including discounts, offers and promotions — in healthcare communication. Equivalent restrictions exist in other European jurisdictions in different forms, so the wording has to be checked against the rules of the country where the practice operates before anything is sent. This workflow is the one behind our patient recall service, Recall Pazienti — the Italian name we kept for it.

6. Nurturing for guide downloads

What it does. Someone who leaves an email address to receive an informational resource enters a follow-up sequence: immediate delivery of the material, then a handful of educational emails spread over weeks.

How it is built. Trigger on form submission, file delivery, source tag, email sequence with an automatic exit on a contact request or an unsubscribe.

The boundary. This sequence addresses a professional audience — colleagues, practice owners — and not patients. The distinction is substantive: towards patients the perimeter is far narrower and promotional communication is off the table. Informational content, an unsubscribe link in every message, no promise of results.

7. The once-a-year institutional message

What it does. One message a year, on a birthday or on the anniversary of the first visit, saying simply that the practice is there.

How it is built. Trigger on the recorded date of birth, annual send with a marketing consent check, one message.

The boundary. Good wishes, full stop. No invitation to book, no birthday discount, no implicit nudge towards a treatment. It is the automation with the lowest commercial return and the highest relational value, and it should be left that way: the moment an offer is attached to it, it becomes promotional communication.

The automations not to build

The platform will let you do some things. In a medical practice they should not be done.

  • Sequences carrying offers, discounts or packages aimed at patients. Restricted or outright prohibited by healthcare advertising rules in several countries, however well written they are.
  • Messages containing the treatment or health data. The channel is not secure and the CRM is not the clinical record.
  • Pre-filtering of reviews. Against Google's policies.
  • Bots answering clinical questions. No triage, no advice, ever.
  • Automated persistence. Someone who has not replied to two messages should not be chased with a third and a fourth. Repeated pressure erodes trust and produces deletion requests.

A sensible activation order

Switching them all on at once is the surest way to get none of them working. The order we recommend, by benefit-to-risk ratio:

  1. Instant acknowledgement of an enquiry.
  2. Appointment reminders.
  3. Missed-call recovery.
  4. Review requests.
  5. Periodic recall (only after consent has been put in order).
  6. Professional nurturing.
  7. The institutional message.

Each one should be tested on a small group before going live, and every piece of wording should be approved by the practice owner: the signature under each message is theirs, not the platform's.

How much work this really is

Setting up these seven workflows, with clean data and a connected calendar, is a matter of days rather than hours, and the longest part is not technical: it is deciding thresholds, wording and responsibilities. After that the system runs, with light maintenance whenever hours, services or people change.

Anyone doing it in-house faces a real but manageable learning curve. Anyone who would rather hand it over will find the scope of our work on the GoHighLevel for medical practices page, which also describes the path for practices that want to run the platform themselves.

Before any of this goes live, the data protection groundwork has to be in place — roles, processing agreement, and what must never enter the CRM. That is covered in GoHighLevel and GDPR in a European medical practice.

Frequently asked questions

Do you need technical skills to build these workflows?

Patience and method more than programming: the builder is visual. The real obstacle is the time it takes to understand the logic of triggers and conditions, and the discipline to keep tags and fields tidy.

Can GoHighLevel be connected to the practice management software we already use?

It depends on the software. Some expose APIs or integrate through external connectors, others do not and require double entry or a custom bridge. Check this before you start: it is the point where projects stall most often.

Is automated recall lawful?

It is, when it goes to people with valid, documented marketing consent, with a generic message, no discounts or promotions, and an opt-out that is always available. Outside those conditions, no. The specific advertising restrictions on healthcare communication vary by country and have to be checked locally.

Can reminders be sent over WhatsApp?

Yes, but automated sending goes through the official WhatsApp Business APIs with templates approved in advance and a per-conversation cost. Bulk use from the consumer app risks getting the number blocked.

Which automation should we start with?

Instant acknowledgement of enquiries: it is the simplest, it carries no marketing consent constraint, and it is the one people notice most, because whoever wrote in stops waiting in the dark.

We would rather someone else handled this.

That is the most common case. If you want to work out which of these automations would make sense in your practice, and in what order, request an assessment with no commitment. If you would rather get the wider picture first, there is the free guide.