The HHS Web Accessibility Rule: What Healthcare Providers Must Do by May 2027
The HHS Web Accessibility Rule: What Healthcare Providers Must Do by May 2027

Most of the attention on web accessibility law has gone to two places: the wave of private lawsuits against retail and restaurant sites, and the Department of Justice rule that binds state and local government. Healthcare has largely been discussed in terms of HIPAA, which is a different problem entirely.
Meanwhile a rule that reaches a very large share of American healthcare providers has been quietly moving toward its compliance date. It is issued under Section 504 of the Rehabilitation Act, it names a specific technical standard, and it applies to organizations that receive federal financial assistance from the Department of Health and Human Services. If you take Medicare, Medicaid or CHIP, you should assume it is worth checking whether it applies to you.
The date moved in May 2026. That is good news, and it is the reason to act now rather than the reason to file this away.
What the rule actually is
In May 2024, HHS published a final rule under Section 504 titled "Nondiscrimination on the Basis of Disability in Programs or Activities Receiving Federal Financial Assistance." Among other things, it sets an accessibility standard for the web content and mobile applications of entities that receive HHS funding.
This is a regulation with a named standard and a named date. That distinguishes it from the situation facing ordinary private businesses, where there is still no federal web accessibility rule at all and exposure comes from litigation rather than from a compliance deadline.
Who it covers
The rule applies to recipients of federal financial assistance from HHS. In practice that reaches a great deal of the sector: community health centers, Head Start agencies, hospitals and health systems, and providers participating in Medicare and Medicaid.
Whether a particular organization is a covered recipient is a legal question about how it is funded, not a design question, and the answer is not always obvious at the margins. Independent practices in particular should confirm their status rather than assume it in either direction. What is safe to say is that the population of covered organizations is much larger than the population that currently knows about this rule.
The standard is WCAG 2.1 Level AA
The rule requires conformance with the Web Content Accessibility Guidelines 2.1, Level AA.
Note the version. There is a persistent assumption that the current published version of WCAG is automatically the legal requirement, and that is not how any of these rules work. WCAG 2.2 has been the current recommendation since October 2023, but the HHS rule cites 2.1, and so does the DOJ rule for state and local government. Section 508, which governs federal agencies and their vendors, still incorporates WCAG 2.0 Level AA.
The practical consequence is small but worth getting right in writing. Build and test to 2.2 AA, because it is a superset of 2.1 and it is where the standards are going. But when you are stating conformance in a contract, a grant report or an accessibility statement, name the version the rule names. Claiming conformance with the wrong version is a needless way to create a discrepancy someone can point at later.
The dates, after the extension
The original compliance dates were May 2026 and May 2027, staged by size. In May 2026, HHS extended both by one year. The dates that now apply are:
11 May 2027 — recipients with 15 or more employees.
10 May 2028 — recipients with fewer than 15 employees.
This mirrors what happened with the DOJ rule for government websites, which was also extended by a year in April 2026. Two federal accessibility deadlines moving in the same quarter has created a general impression that these requirements are softening. That reading is a mistake. The substantive requirements did not change in either case. What changed is how long you have, and a year disappears quickly once you account for procurement, budget cycles and the fact that remediation work has to be scheduled around clinical operations rather than the other way round.
What counts as web content
The scope is wider than the marketing site, which is where most remediation budgets stop.
It reaches your public website and your mobile applications. It reaches the documents you publish, which for most providers is the expensive category: intake forms, notices, plan documents, financial assistance policies and patient education material, a great many of which are scans or exports that were never structured for a screen reader. And it reaches certain kiosks and self-service technology used to access care or services, which is a category most organizations have never inventoried at all.
Third-party systems deserve particular attention. Patient portals, scheduling widgets, bill-pay tools and symptom checkers are frequently the least accessible things on a healthcare site, and they are typically the things you did not build. Ask each vendor for a current accessibility conformance report. Their answers, and more tellingly their silences, are the fastest way to find out where your real risk sits.
The exceptions, and how narrowly to read them
The rule carries exceptions. Archived web content that is not altered after the compliance date, certain pre-existing electronic documents, content posted by third parties that you do not control, individualized password-protected documents, and certain pre-existing social media posts.
These are narrower than they sound, and they are a poor foundation for a compliance strategy. "Archived" has a specific meaning and does not cover a page simply because nobody has looked at it recently — and the moment you update archived content, the exception stops applying to it. The third-party exception turns on control, which is not the same as authorship: content you commissioned, embedded or configured is generally not somebody else's problem merely because it is served from another domain.
Treat the exceptions as a way to sequence the work, not as a way to avoid it. They tell you what to do last.
Alternative methods are permitted, but read the condition
The rule allows alternative methods of providing access, provided they deliver an equal or greater level of access than conformance would.
That condition is doing the heavy lifting, and it is worth being blunt about a common misreading. An accessibility overlay or toolbar is not an alternative method in this sense. A widget that sits on top of an inaccessible page does not give a screen reader user equal access to it, and no serious accessibility practitioner argues otherwise. A staffed phone line that genuinely completes the same task, on request, without delay, is a much closer fit to what the provision contemplates — and even then it is a supplement to remediation rather than a substitute for it.
What to do in the next ninety days
Four things, in this order, and the first two you can start this week.
Confirm whether you are a covered recipient, and get the answer in writing from whoever handles your funding compliance. Everything else depends on this and it is the one step that is not a web project.
Inventory what you publish. Every site and subdomain, every mobile application, every patient-facing document, and any kiosk or self-service device. Note which documents are scans rather than structured exports, because that is where the cost concentrates.
Write to every third-party vendor in the patient journey and ask for a conformance report. Do this early: vendor timelines are the part of the schedule you do not control.
Then get an accessibility audit against WCAG 2.1 AA, and take the findings to your board or executive team with a remediation plan and a cost. We have written separately about what an audit costs and what you get for it, and the same logic applies here. Two budget cycles is enough time to do this deliberately. One is not.
If a rebuild is the answer
Sometimes it is. If the site is old enough that its templates, its document library and its third-party integrations all fail together, remediating page by page costs more than rebuilding on foundations that are accessible by default — and leaves you doing it again at the next redesign.
If you reach that conclusion, put the standard in the procurement document rather than hoping it is understood. Name WCAG 2.1 AA as the contractual floor, ask bidders for a conformance report on work they have already delivered, and say who pays to fix defects found after launch. Those three clauses separate vendors who do this work from vendors who describe it. Our guide to writing a public-sector website RFP covers the mechanics, most of which transfer directly, and you can send us an RFP when yours is ready.
One closing note. This article describes a regulation in general terms and is not legal advice. Whether the rule applies to your organization, and what conformance requires in your circumstances, is a question for your counsel and your compliance team.
Put this into action with eSEOspace
We help businesses grow with website development that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!
On this page






