WCAG 2.1 Level AA is the technical standard that federal agencies expect medical websites to meet, and patient portals, appointment schedulers, and intake forms carry the highest risk when they fall short. Your first move should be practical: run an automated accessibility scan today, then schedule manual testing on the pages patients actually use to book care.
TL;DR:
- Automated scans should be followed by manual testing of high-risk pages, especially the patient portal, scheduling tools, and intake forms.
- Key fixes include removing keyboard traps, unlabeled fields, and replacing scanned PDFs with accessible, tagged versions.
- Most accessibility issues stem from portal navigation barriers, uncaptioned videos, and PDFs that lack readable text layers, affecting user access directly.
- Vendors must provide a WCAG 2.1 AA conformance statement and recent testing reports before contract renewal, with responsibility remaining on the clinic.
- Continuous monitoring and regular manual tests are crucial because new content and site updates can reintroduce accessibility violations.
Table of Contents
- Which US laws set the accessibility bar for healthcare sites
- Where medical sites fail patients first
- A testing workflow that actually catches problems
- What to fix first, and who should do it
- Who is responsible when a vendor built the tool
- Keeping accessibility current instead of a one-time project
- What we see clinics get wrong
- How AdJet helps clinics fix these gaps
- Sources
- FAQ
Which US laws set the accessibility bar for healthcare sites
Three federal actions shape what your clinic’s website needs to do. The Department of Justice’s Title II rule now incorporates WCAG 2.1 Level AA directly into ADA regulations for public entities, spelling out technical expectations rather than leaving them open to interpretation. HHS guidance extends similar expectations to health programs through Section 504 and Section 1557, naming patient portals, telehealth, and forms as covered content.
The standard itself, WCAG 2.1 AA, organizes requirements around four principles: content must be perceivable, operable, understandable, and robust. That structure is why agencies keep citing it. It gives auditors and developers a shared checklist instead of a vague standard of “accessible enough.”
- Perceivable: text alternatives for images, captions for video, sufficient color contrast.
- Operable: full keyboard navigation, no time limits that lock out slower users.
- Understandable: clear labels, consistent navigation, error messages that explain the fix.
- Robust: code that works with screen readers and other assistive technology.
HHS extended its compliance deadlines in 2026: recipients with 15 or more employees now have until May 11, 2027, and smaller recipients have until May 10, 2028. The extra runway is useful, but it is not a reason to wait.
Where medical sites fail patients first
Patient portals are the most common failure point. Keyboard traps that prevent tab navigation, unlabeled login fields, and session timeouts with no warning all block access for patients using screen readers or switch devices. These are not cosmetic bugs. They stop someone from refilling a prescription or checking a lab result.
PDFs and video content cause a second wave of problems. A scanned intake form saved as an image has no readable text for assistive technology, and a telehealth explainer video with no captions excludes patients who are deaf or hard of hearing. Common audits of medical sites consistently flag intake forms, portal logins, untagged PDFs, and missing captions as the top recurring issues.
- Patient portals: keyboard traps, unlabeled fields, unclear error states.
- Scheduling tools: date pickers that only work with a mouse.
- Intake forms: missing labels, no instructions for required fields.
- PDFs: scanned images with no underlying text layer.
- Telehealth video: no captions or transcripts.
A DOJ-referenced principle worth remembering: automated scanners catch many programmatic errors but miss contextual and interactive problems, which is why manual testing matters as much as the tool you run first.
A testing workflow that actually catches problems
Automated scanners are a fast starting point, not a finish line. They flag missing alt text, contrast failures, and broken heading structure quickly, but they cannot tell you whether a screen reader user can actually complete a booking flow.
- Run a site-wide automated scan to catch structural and code-level issues.
- Test high-risk pages by keyboard only, tabbing through every interactive element.
- Run a full screen reader pass with NVDA or VoiceOver on the portal, scheduler, and intake forms.
- Check every patient-facing PDF for proper tagging and a readable text layer.
- Confirm video content has accurate captions and, where relevant, a transcript.
- Document every finding with a screenshot, the page URL, and the specific WCAG criterion it violates.
Pro Tip: Test your appointment scheduler with your keyboard alone before you touch anything else. If you cannot book a visit without a mouse, neither can a patient using a switch device or a screen reader.
Sequencing matters here. Fix findings from the automated scan first since they are usually quick wins, then move into manual testing on the pages tied directly to care access, and only after that turn to vendor-supplied tools that may need a separate conversation with the provider.

What to fix first, and who should do it
Not every finding deserves the same urgency. Split your list into two tiers and work through them in order.
Priority 1, unblock access to care:
- Fix any keyboard trap or broken login flow on the patient portal.
- Repair the appointment scheduler so it works without a mouse.
- Replace scanned PDFs of intake forms with tagged, text-based versions.
Priority 2, sitewide structural fixes:
- Correct heading order so screen readers can navigate the page logically.
- Add descriptive alt text to every meaningful image.
- Raise color contrast on buttons and body text to meet WCAG AA thresholds.
- Add visible focus indicators so keyboard users can see where they are on the page.
Smaller fixes like alt text and contrast adjustments are often reasonable for an in-house web person to handle with a checklist and a few hours. Portal remediation and PDF retagging usually call for a developer or accessibility specialist, since they touch code structure and document formats that general staff are not trained to fix. Budgets vary by how much custom code your site runs and how many PDFs need retagging, so ask any specialist for a written estimate tied to a specific page count before you commit.
Pro Tip: Ask any accessibility vendor for a sample remediation report before you hire them. A strong one names the exact WCAG criterion, the page, and the fix, not just a pass or fail score.
Who is responsible when a vendor built the tool
You remain responsible for the patient experience even when a third-party company built your portal or scheduler. Regulators do not distinguish between code you wrote and code you licensed. That makes your vendor contracts a compliance tool, not just a procurement detail.
Before renewing or signing any patient-portal or scheduling contract, ask for:
- A written WCAG 2.1 AA conformance statement, not a verbal assurance.
- A remediation service-level agreement with a defined response window.
- Recent accessibility testing reports you can review yourself.
- Coordination language confirming the vendor’s obligations align with your BAA.
Vendors that cannot produce a conformance statement or recent test results are a signal to negotiate harder or look elsewhere before renewal.
Keeping accessibility current instead of a one-time project
Accessibility is not a project you finish and file away. Sites change constantly. New blog posts, updated forms, a redesigned scheduler, and each change can introduce a new violation.
- Run automated scans weekly to catch regressions early.
- Schedule a manual test quarterly, focused on the same high-risk pages every time.
- Test any new page or feature before it goes live, not after.
HHS OCR’s interim final rule pushed compliance dates out by one year: recipients with 15 or more employees now face a May 11, 2027 deadline. That timeline gives most clinics room to work through Priority 1 and 2 fixes methodically rather than in a rush, provided you start now rather than treating the extension as a reason to delay.
Accessibility work also intersects with HIPAA, but the two are separate obligations. A form can be fully accessible and still mishandle protected health information if it was not built with HIPAA-safe intake in mind, so remediation plans need to cover both angles rather than assuming one solves the other.
What we see clinics get wrong
Most clinics discover accessibility gaps late, usually after a demand letter, not during planning. The second most common pattern: a portal or scheduler built by a third-party vendor that nobody checked for WCAG conformance before launch. We also see clinics treat HIPAA compliance and ADA compliance as the same project when they require different fixes entirely.
Our approach sequences an accessibility audit alongside HIPAA-aware development, so intake forms get fixed once instead of twice. Start with your booking flow. It is where patients give up fastest when something breaks.
— Felix
How AdJet helps clinics fix these gaps
If your scan turned up more issues than your team has time to fix, that is a normal starting point, not a red flag. Some agencies build and remediate clinic websites with accessibility and HIPAA-aware development handled together, not as an afterthought.
- Accessibility audits that map findings to specific WCAG criteria and pages.
- Remediation of patient portals, forms, and PDFs alongside HIPAA-safe development practices.
- Ongoing monitoring so new pages do not reintroduce old problems.
Our Web Design service builds these fixes into new clinic sites from the start, and our landing page plans start at $99 per month for custom builds. If your site needs a full audit and remediation plan, reach out and we will walk you through what a realistic timeline and cost look like for your specific pages.
Sources
- OCR: Nondiscrimination on the Basis of Disability — Section 504 and Section 1557 guidance
- Federal Register: DOJ final rule updating Title II web & mobile accessibility
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
Does ADA compliance apply to medical websites?
Yes. DOJ’s Title II rule and HHS guidance under Section 504 and Section 1557 extend accessibility obligations to healthcare entities’ web content and mobile apps, including patient portals and telehealth tools. The technical benchmark both agencies point to is WCAG 2.1 Level AA.
What does an ADA-compliant medical website look like?
It means every patient-facing tool, the portal, scheduler, intake forms, and PDFs, works with a keyboard alone and with a screen reader like NVDA or VoiceOver. Pages follow a logical heading structure, images carry descriptive alt text, and videos include captions.
What is the best tool for checking ADA compliance on a website?
No single tool covers everything. Automated scanners catch many programmatic errors quickly, but the DOJ’s own guidance recommends pairing them with manual keyboard and screen reader testing, since automated tools miss contextual and interactive problems.
How do I check if my website is ADA accessible?
Start with a site-wide automated scan, then manually test your highest-traffic pages, portal, scheduler, and forms, using only a keyboard and a screen reader. Document every finding against the specific WCAG 2.1 AA criterion it violates so your remediation plan has a clear starting list.
What happens if a medical website is not ADA compliant?
Non-compliance can lead to complaints, investigations, and remediation settlements from HHS OCR or DOJ, though enforcement often begins with a request for corrective action rather than an immediate penalty. The bigger risk day to day is patients who cannot book an appointment or complete an intake form, which is a care access problem before it is a legal one.




