Guide Industry: Healthcare Accessibility

HHS Section 504 Web Accessibility Deadline: May 11, 2027

HHS-funded hospitals, clinics and health centers face revised web accessibility deadlines in May 2027 and May 2028. Who is covered, what WCAG 2.1 AA asks of websites and patient portals, and how to plan the work.

0reads
HHS Section 504 web accessibility illustration with a patient portal, stethoscope and calendar marking May 11, 2027.

A patient finds the right specialist, chooses an appointment and reaches the registration form. Then the date picker stops responding to the keyboard. Another patient signs into the portal but cannot tell which field contains an error.

For the organization, these may look like software defects. For the patient, they can prevent access to care.

HHS-funded recipients with 15 or more employees must meet the revised web and mobile accessibility requirements by May 11, 2027. Recipients with fewer than 15 employees have until May 10, 2028.

HHS announced the one-year extension on May 7, 2026. The required technical standard remains WCAG 2.1 Level AA. Read the HHS announcement.

For hospitals, clinics and health centers, preparation should follow the patient’s experience across the website, scheduling system, portal and mobile app. That is where the requirements become concrete development work.

Who counts as a recipient?

The HHS rule applies to programs and activities receiving federal financial assistance from the Department of Health and Human Services.

A recipient can be a public or private organization receiving assistance directly from HHS or through another recipient. The definition excludes the ultimate beneficiary—the patient receiving the service is not the funding recipient simply because their care is supported. Federal assistance can include grants, loans and other qualifying arrangements. The regulation defines recipients and financial assistance.

Organizations potentially covered include:

  • Hospitals and health systems.
  • Community health centers and federally qualified health centers.
  • Physician practices and outpatient clinics.
  • Nursing homes and other participating care providers.
  • Behavioral health and substance-use treatment programs.
  • HHS-funded research institutions and health-professions schools.

HHS identifies Medicare, Medicaid and other departmental programs as sources of assistance that can bring providers within scope. A clinic does not have to receive a separate website-development grant for accessibility obligations to apply. HHS explains the covered providers and funding programs.

Start by having finance and compliance identify the recipient entity and relevant funding relationships. Then map the websites, apps and services belonging to its covered operations.

The 15-employee threshold determines the date, not coverage

A small practice should not read “15 or more employees” as an exemption.

Recipient sizeRevised web and mobile compliance deadline
15 or more employeesMay 11, 2027
Fewer than 15 employeesMay 10, 2028

Both groups are addressed in the HHS deadline extension.

A qualifying Medicaid-funded clinic with eight employees can still be covered; it receives the later deadline. For a multisite organization, establish the relevant recipient and employee count rather than assuming each location can use its own headcount.

The extension also leaves existing Section 504 obligations in place. Patients continue to have rights to effective communication, reasonable modifications and equal access during the transition. HHS’s extension analysis distinguishes those duties from the postponed technical compliance dates.

Why the DOJ extension does not set your HHS deadline

The DOJ’s ADA Title II rule and HHS’s Section 504 rule are separate requirements.

Title II concerns state and local public entities. This Section 504 rule concerns recipients of HHS financial assistance. A private clinic may fall under the HHS rule, while a public hospital may have obligations under both.

RuleBasis for the revised deadlineCompliance dates
HHS Section 504Recipient employee countMay 11, 2027, or May 10, 2028
DOJ ADA Title IIDefined government population and entity classificationApril 26, 2027, or April 26, 2028

The dates come from the separate HHS announcement and DOJ guidance.

DOJ’s April 2026 action did not automatically change HHS’s schedule. HHS issued its own extension in May.

If both rules apply, track both. A public hospital subject to the earlier April 2027 deadline cannot treat May 11 as its only accessibility milestone.

What needs to meet WCAG 2.1 AA?

The rule covers web content and mobile apps a recipient provides or makes available, including through contractual, licensing or other arrangements. It requires the applicable Level A and Level AA criteria and conformance requirements of WCAG 2.1, subject to the rule’s exceptions and limitations. See 45 CFR § 84.84.

Translate that scope into an inventory of patient-facing services:

Patient taskSystems and content to examine
Find careProvider directories, location pages and service information
Book a visitScheduling tools, calendars and registration forms
Prepare for treatmentInstructions, documents and educational videos
Manage carePortal login, messaging and prescription-request workflows
Attend remotelyWeb and mobile telehealth interfaces
Understand chargesBilling pages, payment tools and financial-assistance applications

Use this inventory to define testing. A website audit that stops when the patient leaves the main domain may miss the scheduling or payment system where access breaks down.

A purchased patient portal remains part of the work

Buying a portal transfers development tasks to a supplier. The recipient’s responsibility for the service it makes available remains relevant under the rule.

A useful vendor review asks for evidence about the product version and workflows your organization actually uses.

Request a current Accessibility Conformance Report, often prepared using a Voluntary Product Accessibility Template, or VPAT. Review known limitations, testing methods and the supplier’s remediation commitments.

Then test the configured service. Branding, optional modules and integrations can change the experience.

For a patient portal, examine whether someone can:

  • Sign in and recover account access.
  • Understand field labels and validation errors.
  • Navigate using a keyboard.
  • Request an appointment or prescription renewal.
  • Read messages and reach available records.
  • Complete a payment and recognize its confirmation.

Give each identified barrier an owner. Your developers may control the surrounding website, while the portal vendor controls authentication and the scheduling interface. Procurement may need to enforce delivery commitments or evaluate alternatives.

Put remediation dates, retesting expectations and accessibility regression handling into vendor discussions early.

Documents and exceptions need a careful review

The rule includes exceptions for qualifying archived content, certain preexisting electronic documents, independently posted third-party content, individualized secured conventional electronic documents, and preexisting social media posts. Each category has conditions. HHS describes the exceptions.

An important healthcare distinction concerns individualized documents. A secured PDF about a particular patient may qualify for an exception. That does not exempt the portal interface, general patient instructions or every document behind a login.

Similarly, an older financial-assistance application still used to access services does not qualify merely because it was uploaded years ago.

Other Section 504 duties continue even where a technical exception applies, including providing effective communication when a patient needs accessible information.

Maintain an exception register recording the content, applicable conditions, reviewer and process for responding to an accessibility request.

A practical implementation plan for May 2027

For teams beginning in autumn 2026, the available time needs to cover assessment, development, vendor delivery and verification.

September–October: establish scope and test critical journeys

Confirm coverage, recipient size and the applicable deadline. Assign a program owner and involve compliance, IT, patient services, communications and procurement.

Inventory systems and identify who can authorize changes. Select representative patient journeys for a baseline assessment.

Combine automated checks with manual evaluation. W3C notes that tools alone cannot determine accessibility; human assessment is essential. W3C’s evaluation guidance provides a starting point.

Prioritize barriers that prevent completion of a task. An inaccessible appointment form deserves prompt attention even if a scanner reports more errors on a less consequential page.

Deliverable: an owned inventory and a prioritized, costed remediation backlog.

November–January: repair components and secure vendor releases

Address shared problems in navigation, forms, dialogs, focus behavior and document templates. Verify each correction in the journeys where that component appears.

Work with vendors against specific acceptance criteria. “An accessible update is coming” needs a release date, a description of the fixes and time for your team to test.

For custom development, create regression checks around problems already found. For purchased systems, obtain a test environment containing the proposed release.

Use synthetic patient records during testing so the team can exercise realistic workflows without exposing actual patient information.

Deliverable: tested fixes and scheduled delivery for outstanding vendor work.

February–March: verify the complete patient experience

Retest across systems, including transitions between the website and outside services.

Include patients with disabilities in usability testing where possible. Record where people become confused, cannot proceed or must seek assistance.

Review patient instructions and frequently used documents alongside interfaces. Train staff who publish content so new uploads do not recreate the backlog.

Confirm how accessibility reports reach the right team and how patients receive timely help while an issue is being resolved.

Deliverable: current test evidence and a working issue-response process.

April–May: close gaps and establish continuing maintenance

Resolve remaining in-scope failures before the applicable deadline. Organizations also subject to an earlier Title II date should schedule this work accordingly.

Review exceptions, vendor commitments and release evidence. Assign responsibility for future testing, new content and supplier updates.

Prioritization sets the order of work. It does not remove lower-priority content from the requirements.

Deliverable: verified results and a maintenance process that continues after launch.

Where enforcement sits—and why funding matters

The HHS Office for Civil Rights, or OCR, enforces Section 504. Its work includes investigating complaints and conducting compliance reviews. HHS explains OCR’s role.

Federal financial assistance can be at risk where noncompliance remains unresolved. The applicable enforcement procedures provide for suspension, termination or refusal of assistance, subject to formal safeguards and efforts to secure voluntary compliance. Funding does not disappear automatically because a scan identifies an error. The compliance procedures are set out in 45 CFR § 80.8.

For healthcare leaders, that makes accessibility a responsibility shared across operations, procurement and technology.

Keep evidence that helps the organization explain its work: assessment scope, findings, verified corrections, vendor correspondence and responses to patient reports. Documentation supports accountability, but the essential outcome is that patients can use the service.

Start with the appointment journey

Pick one common patient task and follow it from beginning to end.

Can someone find a provider, choose a time, complete registration and understand the confirmation using a keyboard or screen reader? Which team owns each step? Which changes depend on a vendor?

Those questions turn the deadline into a practical delivery plan.

Explore Dynamosys’ Healthcare solutions to discuss the website, integration and development work your assessment identifies.

The most useful measure of progress is a patient completing a task that previously stood in their way.

Newsletter

Would you like to join our fabulously insightful newsletter that will help you grow your business?

By joining you agree to receive marketing communications from Dynamosys. You can unsubscribe anytime. We won't share or sell your personal information. Privacy policy