Healthcare · Section 1557 · Compliance

Healthcare Website Accessibility: Where WCAG, ADA, and Section 1557 Actually Meet

  • Healthcare
  • Section 1557
  • Compliance

A hospital system can spend seven figures locking down HIPAA compliance — encryption, audit logs, business associate agreements, the works — and still lose a patient at the very first click. Not to a data breach. To an intake form a screen reader user can't complete at all.

That's the blind spot. HIPAA protects the data once someone gets in. It says nothing about whether they can get in.

The Compliance Gap Nobody's Budget Covers

Picture a regional hospital system's digital team. They've just finished a grueling HIPAA risk assessment. Every field encrypted, every access log reviewed, every vendor contract updated. Leadership is relieved. The compliance box is checked.

Then a patient with low vision calls the front desk, frustrated, because the "Schedule an Appointment" button on the portal has no visible focus indicator and the date picker won't respond to keyboard navigation. She can't book. She has to call instead — which defeats the entire point of building a portal.

This scenario plays out constantly in healthcare. Teams pour resources into the compliance framework they've heard the most about, while the one that actually governs the patient-facing experience gets ignored entirely.

HIPAA Isn't the Accessibility Law You're Looking For

Here's the part that catches healthcare organizations off guard: HIPAA has nothing to do with accessibility. It governs privacy and security of protected health information. It doesn't mention screen readers, color contrast, or keyboard navigation once.

The law that actually applies is Section 1557 of the Affordable Care Act. It prohibits disability discrimination by covered health programs and entities that receive federal financial assistance — which includes most hospitals and a large share of healthcare providers accepting Medicare or Medicaid. HHS's Section 1557 regulations go further than most civil rights statutes: they specifically reference WCAG 2.1 Level AA as the technical standard for web and mobile app accessibility for covered entities.

That's not a vague "reasonable accommodation" standard. It's a named, versioned technical benchmark.

On top of that, healthcare organizations carry the same general ADA Title III exposure that applies to any public-facing business. So you're often looking at a dual, overlapping obligation — general ADA risk plus a specific, funding-tied Section 1557 requirement — and both point at the exact same practical target: WCAG 2.1 (or current) AA conformance.

In short: if your legal team has only ever discussed HIPAA, your accessibility posture has probably never been evaluated at all.

The Stat: Roughly 1 in 4 U.S. adults live with some type of disability (CDC). For a healthcare organization, that's not an edge case — it's a meaningful share of the exact population most likely to need your site.

Share of U.S. adults living with a disability 1 in 4 U.S. Adults Live With a Disability 26% 74% Adults with a disability Adults without a disability Source: CDC, Disability and Health Data System (about 1 in 4 U.S. adults)

Where Patient Portals Actually Break

Accessibility failures in healthcare aren't abstract. They show up at the highest-stakes moments of a patient's journey — the ones where a broken experience doesn't just annoy someone, it delays their care.

Appointment scheduling widgets, intake forms, and prescription refill flows are all form-heavy, and forms are where accessibility problems concentrate. Three WCAG success criteria come up over and over in healthcare audits:

  • 1.3.1 Info and Relationships (Level A) — form fields, labels, and groupings need to be programmatically associated, not just visually adjacent. A label that "looks" attached to a field but isn't coded that way is invisible to assistive technology.
  • 3.3.2 Labels or Instructions (Level A) — every input needs a clear, associated label or instruction, especially for anything as consequential as symptom descriptions or medication history.
  • 4.1.2 Name, Role, Value (Level A) — custom-built widgets (date pickers, dropdowns, multi-step wizards) need to expose their name, role, and current state to assistive technology, or they're functionally invisible.

A mislabeled field on a retail checkout form costs a sale. A mislabeled field on a patient intake form can mean someone can't describe their symptoms, can't confirm an allergy, or can't complete a referral — and simply gives up or shows up unprepared.

Documents Patients Actually Need to Read

Healthcare generates an enormous volume of PDFs: lab results, discharge instructions, insurance forms, after-visit summaries. Many of these are scanned images with no underlying text layer at all.

An unlabeled scanned PDF is functionally invisible to a screen reader user trying to read their own discharge instructions — the same real remediation work covered in accessible PDF compliance applies directly here, and it's frequently the most-overlooked piece of a healthcare accessibility program.

Telehealth Adds a Whole New Layer

Video visits and pre-recorded patient education content bring Guideline 1.2 (Time-based Media) into play. Pre-recorded patient education videos need captions and, where relevant, audio description. Live video visits need real-time captioning support so deaf and hard-of-hearing patients can actually communicate with their care team — not just tolerate the platform, but use it as intended.

Where to Start (Because You Can't Fix Everything Monday Morning)

Healthcare digital estates are sprawling — marketing sites, patient portals, telehealth platforms, billing systems, mobile apps. Trying to remediate everything simultaneously usually means remediating nothing well.

The practical move: prioritize the highest-stakes patient-facing flows first. Appointment booking, intake forms, portal login/authentication, and prescription/billing are simultaneously the highest-traffic and highest-consequence surfaces for accessibility failures in a healthcare context. Fix those before touching your careers page.

Prioritization framework for healthcare accessibility remediation

Priority Flow Why It's High-Stakes Key WCAG Focus
1 Appointment booking Blocks access to care entirely if unusable 4.1.2, 2.1.1 Keyboard
2 Intake / symptom forms Incomplete or wrong info reaches clinicians 1.3.1, 3.3.2
3 Portal login / authentication Locks patients out of records and messaging 4.1.2, 3.3.1 Error Identification
4 Prescription refills / billing Delayed medication, unresolved balances 1.3.1, 3.3.2
5 Telehealth video visits Excludes deaf/HoH patients from live care 1.2.4 Captions (Live)
6 Discharge / lab result PDFs Patients can't read their own medical info 1.1.1 Non-text Content
7 General marketing pages Lower stakes, still ADA/1557 exposure 1.4.3 Contrast (Minimum)

The Numbers Say This Isn't a Fringe Issue

Skeptical that this is worth prioritizing over the next feature release? The broader web data backs up what healthcare-specific audits keep finding.

WebAIM's annual "WebAIM Million" evaluation of the top 1,000,000 home pages has repeatedly found that the vast majority — in recent years around 95-96% — have detectable WCAG 2 failures, with low-contrast text and missing alt text consistently among the most common issues (WebAIM: The WebAIM Million). Healthcare sites are not a special exception to that trend.

And the legal exposure isn't theoretical either. UsableNet's annual ADA Digital Accessibility Lawsuit Report has tracked several thousand federal ADA website lawsuits filed per year in the U.S. in recent years, with plaintiffs' firms increasingly sending pre-suit demand letters as well as filing suit (UsableNet). Add Section 1557's explicit WCAG 2.1 AA reference on top of general ADA exposure, and healthcare organizations face a more clearly defined technical target — and a correspondingly clearer path to a finding of non-compliance — than most industries.

Globally, the stakes are even bigger than a lawsuit count. The World Health Organization estimates over 1 billion people worldwide, roughly 16% of the global population, live with some form of disability. For an industry whose entire mission is serving people's health needs, excluding a population that size from your digital front door isn't just a compliance risk. It's a mission failure.

Get Your Patient-Facing Properties Actually Audited

HIPAA compliance tells you your patient data is locked down. It tells you nothing about whether the patient trying to reach that data can get through the door.

If your last accessibility conversation was actually a privacy and security conversation, you don't yet know where you stand on Section 1557 and WCAG 2.1 AA — and that's a gap worth closing before a demand letter closes it for you.

Get a healthcare-specific WCAG audit for your patient-facing digital properties — one that walks your appointment scheduling, intake forms, patient portal, and telehealth flows against the actual technical standard regulators reference. Start here.