A US healthcare website sits under two separate legal tracks, and only one of them has a date on it. Title III of the ADA lists the "professional office of a health care provider, hospital" among places of public accommodation (42 U.S.C. § 12181(7)(F)). No federal regulation sets a technical standard for those private entities, and the Justice Department says so itself (ADA.gov), which means the obligation is live today with no deadline to count down to.
Section 504 of the Rehabilitation Act is the track with a date. HHS adopted WCAG 2.1 Level AA as the technical standard for the web content and mobile apps of anyone receiving its financial assistance, then in May 2026 pushed the compliance dates back a year: 11 May 2027 for recipients with fifteen or more employees, 10 May 2028 for those with fewer (91 FR 25496).
If you bill Medicare or Medicaid, both tracks reach you. The working target is WCAG 2.1 AA across every page a patient uses to get care, including the ones behind a login.
Does the ADA apply to a hospital or medical practice website?
Yes, and the statute names healthcare directly. Subparagraph (F) of the public accommodation definition puts the "professional office of a health care provider, hospital" in the same list as a pharmacy and an insurance office (42 U.S.C. § 12181(7)(F)). Retailers spend years litigating whether a website is a place of public accommodation. A clinic with a waiting room never gets to have that argument.
What Title III withholds is a version number. DOJ's web guidance says its reading of the ADA covers services offered online, then says in the same document that it "does not have a regulation setting out detailed standards" for private businesses. The working standard therefore comes from settlements and from the rules that do name one. Our ADA overview goes through how that gap gets filled.
One more clause earns its keep here. Title III makes it discriminatory to deny someone the benefit of your services "directly, or through contractual, licensing, or other arrangements" (42 U.S.C. § 12182(b)(1)(A)(i)). Almost no provider writes their own patient portal. That clause is why the vendor's code is still your patient's experience of your practice.
What changed with the HHS Section 504 web rule in 2026?
The dates moved. Nothing else did.
HHS published its rewritten Section 504 regulations in May 2024, adopting the WCAG 2.1 Level AA success criteria as the technical standard for recipients' web content and mobile apps (89 FR 40066; 45 CFR 84.82 through 84.89). The original dates were 11 May 2026 and 10 May 2027. The interim final rule of 11 May 2026 extends both by exactly one year, and says plainly that it touches only the compliance dates at 45 CFR 84.84(b).
HHS gave two reasons: that the dates were unlikely to be met by many recipients, and "the potential for copious and costly litigation if the implementation dates are not pushed back." The same rule warns against reading the delay as a reprieve:
Regardless of the compliance dates, recipients have an ongoing obligation to ensure that their programs and activities offered using web content and mobile apps are accessible to individuals with disabilities in accordance with their other obligations under section 504.
The reasonable-modification duty at 45 CFR 84.68(b)(7) did not move. Neither did Title III. And when a commenter argued the rule imposed cost without benefit, HHS answered in a footnote worth quoting to anyone who thinks this is paperwork: "Particularly in the area of telehealth, if a person with a disability is not able to access a recipient's web content or mobile app because it was not designed accessibly, that person is denied health care by a recipient of Federal dollars."
DOJ made the same move a month earlier on the ADA Title II rule that covers public hospitals and county health departments (91 FR 20902), which we wrote up in the Title II deadline extension.
Here is the opinion I will defend: an extension is a scheduling change, not a permission slip. Teams that treat 2027 as the start date will do the same work under the same pressure, minus a budget cycle. HHS also says it may propose changes to the substance of the rule during the extension, so the delay buys time without buying certainty.
Does Section 1557 set a separate deadline?
It sets a separate obligation with no deadline attached, which catches people out.
Section 1557 of the Affordable Care Act reaches health programs through 45 CFR part 92. Paragraph (a) of § 92.204 requires a covered entity to ensure its health programs provided through information and communication technology are accessible, subject only to undue burden or fundamental alteration. That paragraph took effect on 5 July 2024 and appears nowhere in the rule's table of delayed provisions (89 FR 37522). It names no WCAG version, so there is no date to extend. It applies now.
Paragraph (b) then routes websites and mobile apps to "the requirements of section 504 of the Rehabilitation Act, as interpreted consistent with title II of the ADA." That cross-reference is what the 2026 extension reaches. The technical WCAG 2.1 AA target slid to 2027. The general duty to keep your portal usable stayed where it was.
The same rule also widened who counts as a recipient. HHS revised its longstanding position so that Medicare Part B payments meet the definition of federal financial assistance, and providers whose only federal funding was Part B had to comply with Section 504 and Section 1557 by 6 May 2025. A three-physician practice billing Part B and nothing else sits inside Section 504 today. Plenty of them still think Title III is their only exposure.
| Track | Standard named | Date |
|---|---|---|
| ADA Title III (private providers) | none in regulation | in force, no deadline |
| Section 1557, 45 CFR § 92.204(a) | none | in force since 5 July 2024 |
| Section 504, 45 CFR § 84.84(b) | WCAG 2.1 AA | 11 May 2027 / 10 May 2028 |
| ADA Title II (public hospitals) | WCAG 2.1 AA | extended one year by DOJ |
Which parts of a patient portal actually fail?
The parts no scanner has ever seen, because they need credentials.
Start with the public site, where the failures are dull and measurable. WebAIM's February 2026 report sampled 26,648 home pages in its Health & Fitness category and found 54.4 detected errors per page, about 3% below the million-page average (WebAIM Million). Across all million home pages, low contrast text appeared on 83.9%, missing image alt text on 53.1%, and missing form input labels on 51%. That list maps cleanly onto the "Find a doctor" filter panel and the appointment request form.
Then sign in, and a different class of problem starts. Portal flows I check by hand before trusting any report:
- The multi-factor code field. Blocking paste fails WCAG 2.2's 3.3.8 Accessible Authentication, which prohibits a cognitive function test at any step of signing in (W3C).
- Lab results rendered as a table with no header cells, so a screen reader reads "3.4" with no idea which analyte it belongs to.
- A session-timeout dialog that appears without moving focus, then logs the patient out mid-form.
- Visit summaries and after-visit instructions delivered as untagged PDFs, which are pictures of text as far as assistive technology is concerned.
- Symptom checkers and intake forms that re-ask for the medication list already on file, which is what 3.3.7 Redundant Entry is about.
A home-page scan reports none of this. That gap is the subject of why homepage scans miss risk, and healthcare has it worse than most: the public site is marketing, the portal is the actual service.
Which WCAG version should a healthcare site target?
Build to WCAG 2.2 AA and you satisfy the 2.1 AA that Section 504 names, since W3C states that content conforming to WCAG 2.2 also conforms to 2.1 and 2.0 (W3C). Stop at 2.1 and you meet the regulation while missing the criteria that land hardest on portals, including the paste-blocking rule above. Why no US regulation names a version for private practices is covered in does the ADA require WCAG.
Federal agencies and their vendors answer to a third standard, WCAG 2.0 AA under Section 508, which is what a health system selling software to the VA gets asked for in procurement.
What should a healthcare team do first?
Inventory before you scan. Write down every digital path a patient takes to reach care: appointment booking, the portal login, results, messaging, bill pay, telehealth waiting room, the forms you email before a first visit. Most organizations find one they had forgotten, usually a legacy scheduling tool on a subdomain.
Scan those paths instead of the home page. Fix in this order: labels on every form control, keyboard operability through login and booking, contrast, then table headers on anything clinical. Our WCAG checklist covers the criteria in order.
Ask your portal vendor for a current accessibility conformance report and read the "Supports" rows with suspicion, because nobody audits that document before it reaches you. Their gaps land on you.
Be straight about what tooling does. Deque's study of more than 2,000 audits put automated detection at roughly 57% of issues by volume (Deque); counted by success criteria the figure is closer to 30%. Full conformance needs human review. We went into that split in how much automated tools catch.
Our scanner will find the unlabeled "Request refill" button and the 3:1 contrast on your appointment confirmation. It will not tell you whether a patient using a screen reader can work out that their INR is out of range. Somebody has to sit down with a screen reader and book a real appointment. In healthcare that hour buys more than any report, and it becomes the evidence behind the accessibility statement you publish, which documents effort rather than certifying an outcome.
FAQ
Does the ADA apply to a private medical practice website?
Yes. Title III names the "professional office of a health care provider, hospital" as a public accommodation (42 U.S.C. § 12181(7)(F)), with no small-practice exemption. There is no federal regulation setting a technical standard for private providers (ADA.gov), so WCAG 2.1 AA or higher is the practical target.
What is the Section 504 healthcare web accessibility deadline now?
11 May 2027 for HHS funding recipients with fifteen or more employees, and 10 May 2028 for those with fewer. HHS extended both by one year in an interim final rule published on 11 May 2026 (91 FR 25496). The standard remains WCAG 2.1 Level AA.
Does the extension mean we can wait until 2027?
No. The rule states that regardless of the compliance dates, recipients have an ongoing obligation to keep programs offered through web content and mobile apps accessible under their other Section 504 duties. Title III and 45 CFR § 92.204(a) both apply now, and neither has a deadline.
Do patient portals have to be ADA compliant if a vendor built them?
The obligation stays with the provider. Title III covers discrimination "directly, or through contractual, licensing, or other arrangements" (42 U.S.C. § 12182(b)(1)(A)(i)), and the Section 504 web requirements apply to content recipients make available through contractual or licensing arrangements too.
Does taking Medicare make my practice subject to Section 504?
In HHS's current interpretation, yes, including practices whose only federal funding is Medicare Part B. HHS revised its position in the 2024 Section 1557 rule and set 6 May 2025 as the date by which those newly covered providers had to comply (89 FR 37522).
Scan your booking flow and patient portal to see the exact selectors that fail, then decide what to fix first: scan your site.
Written by Pavel Charkasau, founder of wcagc.com. I read the HHS interim final rule and both 2024 final rules end to end, so every date here traces to the published text.
Last updated: September 17, 2026
Sources
- ADA.gov, Americans with Disabilities Act, 42 U.S.C. §§ 12181(7)(F) and 12182(b)(1)(A)(i) (accessed September 17, 2026).
- ADA.gov, Guidance on Web Accessibility and the ADA (accessed September 17, 2026).
- U.S. Department of Health and Human Services, Extension of Compliance Dates for Nondiscrimination on the Basis of Disability; Accessibility of Web Content and Mobile Applications of Recipients of Departmental Financial Assistance, interim final rule, 91 FR 25496 (published May 11, 2026; accessed September 17, 2026).
- U.S. Department of Health and Human Services, Nondiscrimination on the Basis of Disability in Programs or Activities Receiving Federal Financial Assistance, final rule, 89 FR 40066 (published May 9, 2024; accessed September 17, 2026).
- U.S. Department of Health and Human Services, Nondiscrimination in Health Programs and Activities, final rule, 89 FR 37522, including 45 CFR § 92.204 and the Medicare Part B interpretation (published May 6, 2024; accessed September 17, 2026).
- U.S. Department of Justice, Extension of Compliance Dates for Nondiscrimination on the Basis of Disability; Accessibility of Web Information and Services of State and Local Government Entities, 91 FR 20902 (published April 20, 2026; accessed September 17, 2026).
- W3C, Web Content Accessibility Guidelines (WCAG) 2.2 (W3C Recommendation, 12 December 2024; accessed September 17, 2026).
- WebAIM, The WebAIM Million: the 2026 report on the accessibility of the top 1,000,000 home pages (published February 2026; accessed September 17, 2026).
- Deque Systems, Automated Testing Study Identifies 57 Percent of Digital Accessibility Issues (accessed September 17, 2026).