Healthcare Accessibility

Healthcare organizations that receive federal financial assistance from HHS must make their websites, web content, and mobile apps conform to WCAG 2.1 AA under the new Section 504 rule. The process is an audit, remediation, validation, and documentation cycle that applies to hospitals, nursing homes, Medicaid and CHIP providers, Medicare participants, and marketplace insurers.

The deadline for organizations with 15 or more employees is May 11, 2026. Organizations with fewer than 15 employees have until May 10, 2027. Here is the full breakdown of what this means for healthcare organizations and how to move from where you are now to WCAG conformance.

Healthcare Accessibility: Process Overview
Stage What It Covers
Section 504 Requirement WCAG 2.1 AA conformance for websites, web content (including documents), and mobile apps
Accessibility Audit Manual evaluation of every applicable WCAG success criterion by a technical accessibility expert
Remediation Development work to fix the issues the audit identified, prioritized by severity and user impact
Validation Confirming each fix was implemented correctly and no new issues were introduced
VPAT / ACR Standardized documentation reporting your product or service’s WCAG conformance status to procurement officers and compliance teams

Section 504 and the New HHS Rule

Section 504 of the Rehabilitation Act prohibits discrimination on the basis of disability in programs and activities that receive federal financial assistance. In 2024, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a final rule that updates, modernizes, and clarifies Section 504 for entities it regulates. One of the most significant additions is a specific digital accessibility requirement: WCAG 2.1 AA conformance for websites, web content, and mobile apps.

The rule applies to any entity receiving federal financial assistance from HHS. This includes:

  • Health care providers participating in CHIP and Medicaid programs
  • Hospitals and nursing homes (recipients under Medicare Part A)
  • Medical, preventative, and mental health services covered under Medicare Part B
  • Medicare Advantage Plans such as HMOs and PPOs (recipients under Medicare Part C)
  • Prescription Drug Plan sponsors and Medicare Advantage Drug Plans (recipients under Medicare Part D)
  • Human and social service agencies
  • Insurers participating in the Marketplaces and receiving premium tax credits

The digital accessibility requirements mirror those in the ADA Title II web accessibility rule, which also adopted WCAG 2.1 AA as the technical standard. Organizations covered by both rules can use the same conformance project and documentation to address requirements under each.

Five content exceptions exist: archived web content, preexisting conventional electronic documents (unless currently used for program access), third-party content not posted under a contractual arrangement, individualized password-protected documents, and preexisting social media posts. Even with these exceptions, the scope of what must conform is broad.

The rule also allows for noncompliance that has a minimal impact on access. If remaining issues do not affect the ability of individuals with disabilities to access the same information, engage in the same interactions, and conduct the same transactions as individuals without disabilities, the organization may still be deemed in compliance. This is a narrow exception and should not be treated as a primary strategy.

WCAG Conformance for Healthcare

The Web Content Accessibility Guidelines (WCAG) are the technical standard for digital accessibility. For healthcare organizations under the new HHS rule, WCAG 2.1 AA is the required conformance target. It addresses the full range of accessibility requirements across visual, auditory, motor, and cognitive dimensions.

WCAG is organized around four principles: perceivable, operable, understandable, and robust. Within those principles are success criteria, which are specific, testable requirements your digital asset either passes or does not pass. Meeting all applicable criteria at the AA level means your website, web content, or mobile app is conformant.

Healthcare digital assets present specific considerations. Patient portals, appointment scheduling systems, telehealth platforms, lab results interfaces, and billing systems all fall within scope. Electronic documents such as intake forms, discharge instructions, and explanation of benefits documents must also conform unless they qualify under one of the five content exceptions. For organizations using platforms like Shopify for any e-commerce or patient-facing storefront functionality, those interfaces need evaluation as well.

Automated scans such as WAVE or Axe can flag a fraction of WCAG issues. Many success criteria require human judgment, including evaluations of screen reader experience, keyboard navigation, meaningful alternative text, and proper content structure. A passing scan result does not indicate conformance. Only a manual accessibility audit can determine whether your digital assets meet the standard the rule requires.

Accessibility Audit

An accessibility audit is a thorough evaluation of your digital asset conducted by a technical accessibility expert. The audit identifies every instance of nonconformance with WCAG success criteria and produces a detailed report that becomes the foundation for remediation.

For healthcare organizations, scope includes the primary patient-facing and staff-facing digital experiences. Patient portals, appointment scheduling flows, telehealth interfaces, billing and payment screens, and any publicly available web content all need evaluation. Organizations with mobile apps must include those as well.

A manual audit uses multiple evaluation methodologies: screen reader testing with NVDA, JAWS, or VoiceOver, keyboard-only navigation, visual inspection, code inspection, browser zoom testing at 200% and 400%, color contrast analysis, and an automated scan as a secondary check. Accessible.org audits are always fully manually conducted. We never copy and paste scan results into audit reports. Every issue in the report is identified and verified by a human auditor.

The audit report documents each issue with specific details:

  • Issue description explaining what fails
  • URL or screen location
  • Specific element location
  • Testing environment used
  • Applicable WCAG success criterion
  • Remediation recommendations
  • Screenshots or video clips for visual context

Audit scope and cost are driven by the number of unique pages or screens evaluated and the complexity of interactive elements. Pages or screens that are similar in structure and functionality are typically not duplicated in scope. For healthcare organizations with multiple digital assets, such as a public website, a patient portal, and a mobile app, each may require a separate audit or a combined scope depending on how distinct the interfaces are.

Remediation

Remediation is the development phase where your team fixes the issues the audit identified. Issues are typically organized by severity and user impact so the highest-risk items are addressed first.

Healthcare teams can distribute remediation across sprints. The audit report maps directly to this workflow. Each issue is a discrete task with a clear acceptance criterion tied to a specific WCAG success criterion.

Teams using the Accessibility Tracker platform can import audit issues directly and work through their remediation workflow with built-in prioritization formulas and progress reporting. Developers can track issue status, assign items to team members, and move each issue through predefined status labels: Not Started, In Progress, Completed, On Hold, Needs Work, Validated, or Discarded.

Remediation timelines vary by the scope of digital assets and team capacity. A focused effort on a mid-complexity healthcare website or portal typically runs four to eight weeks. Organizations with multiple digital assets, complex interactive components, or large backlogs of existing issues should plan for longer timelines. Given the May 2026 and May 2027 deadlines, starting the audit as early as possible gives your team adequate time to complete the full cycle.

Validation

Validation confirms that the fixes made during remediation were implemented correctly and that no new issues were introduced.

The original auditor re-tests each remediated issue against its WCAG success criterion using the same evaluation methodologies from the audit. Issues that pass are marked resolved. Issues that need adjustment are returned to development with updated notes. This cycle continues until all issues are resolved or the organization has addressed all feasible fixes.

Accessible.org recommends a 20-25% incremental approach to validation. Work through a batch of fixes, validate that batch, confirm the team is on the right track, then continue with the next. This prevents a misunderstanding about implementation from carrying through dozens of issues before anyone catches it.

Validation is not optional. Development teams can introduce new issues during remediation, particularly when fixing one component affects others. Skipping validation means operating with unverified conformance, which is a risk no healthcare organization should take given the regulatory deadlines.

VPAT and ACR

A VPAT (Voluntary Product Accessibility Template) is a standardized template published by the IT Industry Council (ITI). When completed, it becomes an Accessibility Conformance Report (ACR). The ACR documents the conformance status of your digital asset against WCAG 2.1 AA, criterion by criterion.

Healthcare organizations that provide products or services procured by other entities, especially in government contexts, need an ACR. Even outside procurement, an ACR serves as formal documentation of your accessibility status for compliance records. Hospitals, health systems, and insurers increasingly use ACRs as evidence of their conformance efforts under Section 504.

An ACR can only be completed after a thorough audit. It maps the audit findings to each WCAG success criterion and rates conformance as Supports, Partially Supports, Does Not Support, or Not Applicable. Accessible.org uses a pause-and-fix approach where clients can remediate issues after the audit but before ACR issuance. This means your documentation reflects your remediated state rather than the pre-fix baseline.

Most healthcare organizations use the WCAG edition of the VPAT. The Section 508 edition is required when selling to U.S. federal agencies. The EU edition aligns with EN 301 549 standards for organizations subject to the European Accessibility Act (EAA). The INT edition combines all three for products and services marketed globally. Accessible.org clients usually select WCAG 2.1 AA because it maps directly to the HHS rule requirement and covers the needs of most buyers.

If your organization also needs to demonstrate conformance under the ADA or the EAA, the same audit and VPAT process applies. WCAG 2.1 AA is the common standard across these regulations, so one thorough audit and a well-documented ACR can serve multiple compliance needs.

Frequently Asked Questions

Does the new HHS rule apply to all healthcare organizations?

No. It applies specifically to entities receiving federal financial assistance from HHS. This includes Medicaid and CHIP providers, Medicare participants across Parts A through D, human and social service agencies, and marketplace insurers receiving premium tax credits. Private practices that do not receive HHS funding are not covered under Section 504, though they may still have obligations under the ADA.

Can an automated scan satisfy the conformance requirement?

No. Automated scans can only detect a limited portion of WCAG 2.1 AA success criteria. The rule requires full conformance, which can only be verified through a manual audit. Scans are useful as a secondary check within the audit process, but they cannot serve as the evaluation itself.

What is the difference between a VPAT/ACR and certification?

A VPAT/ACR documents the current conformance status of a digital asset, including areas of nonconformance. It does not require full conformance. Certification is issued only when a digital asset fully conforms with the technical standard across the entire defined scope. Both require a manual audit as their foundation.

What if we cannot meet full WCAG 2.1 AA conformance by the deadline?

The rule includes a provision for noncompliance that has a minimal impact on access. If remaining nonconformance does not affect the ability of individuals with disabilities to access the same information, engage in the same interactions, and conduct the same transactions, the organization may still be deemed in compliance. This is a narrow exception. Organizations should also be aware of the fundamental alteration and undue burden defenses, which require documented evidence and a written statement from the head of the organization.

How long does the full audit-to-conformance process take?

The audit itself typically takes one to two weeks depending on scope. The full process from audit through remediation and validation usually takes two to four months, depending on the number of digital assets, how quickly your team implements fixes, and the volume of issues identified.

Summary

The HHS Section 504 rule creates a clear requirement for healthcare organizations: WCAG 2.1 AA conformance for websites, web content, and mobile apps by May 2026 or May 2027. The process to get there follows a defined, repeatable sequence. Starting with a clear picture of where your digital assets stand is the most direct path forward.

Contact Accessible.org to get started with an audit.

Sign up for Accessibility Tracker

Track your accessibility issues, manage remediation, and generate VPATs from audit data. Sign up at AccessibilityTracker.com.

Sign up for Accessibility Tracker

New platform has real AI. Tracking and fixing accessibility issues is now much easier.

Kris Rivenburgh, Founder of Accessible.org holding his new Published Book.

Kris Rivenburgh

I've helped thousands of people around the world with accessibility and compliance. You can learn everything in 1 hour with my book (on Amazon).