← Back to blog

July 5, 2026

Section 504 and Healthcare Websites: What the HHS Web Rule Requires

Hospitals and health systems that receive HHS funding face a second web accessibility rule beyond the ADA. Section 504 adopts WCAG 2.1 AA with deadlines in 2027 and 2028 - here's who's covered and what to do now.

D
Daruma Tech

Most conversations about website accessibility law focus on the ADA. But for hospitals, health systems, community health centers, and state health agencies, there is a second rule that matters just as much — and it has its own deadlines: Section 504 of the Rehabilitation Act, as updated by a 2024 HHS final rule.

If your organization receives federal financial assistance from the Department of Health and Human Services — and most healthcare providers do — this rule applies to you. Here is what it requires and when.

Two rules, one standard

In May 2024, HHS finalized an updated rule under Section 504 that, for the first time, sets a concrete technical standard for the accessibility of websites and mobile apps operated by recipients of HHS funding. That standard is the same one the DOJ adopted for governments: WCAG 2.1 Level AA.

This means many healthcare organizations are now covered by two rules pointing at the same target:

  • Section 504 (HHS) — because they receive federal health funding.
  • ADA Title II (DOJ) — if they are also a public entity, such as a county hospital or a public university medical center.

The practical takeaway is reassuring: because both rules adopt WCAG 2.1 AA, meeting one standard satisfies the technical requirement of both. You do not have to build to two different specifications.

Who is covered

Section 504 reaches any program or activity that receives federal financial assistance from HHS. In healthcare, that typically includes:

  • Hospitals and health systems that participate in Medicare and Medicaid
  • Federally Qualified Health Centers (FQHCs) and community health centers
  • State Medicaid agencies and state and local health departments
  • Many clinics, physician groups, and long-term care facilities that accept federal reimbursement

If federal health dollars flow to your organization, assume the rule applies and confirm the specifics rather than assuming you are exempt.

The deadlines

Following the rule's compliance timeline, covered entities must bring their web content and mobile apps into conformance with WCAG 2.1 AA on a schedule tied to organization size:

  • May 2027 — larger recipients.
  • May 2028 — smaller recipients.

These are conformance deadlines, not aspirational targets. And as with Title II, the realistic lead time to reach conformance across a real healthcare website — plus its patient portals, forms, and document libraries — is measured in many months. Working backward from a 2027 date means scoping the work well before then.

Note the framing carefully: this rule is not "already in force" today as a web-conformance mandate. The obligation to meet WCAG 2.1 AA phases in at these dates. That is exactly why now is the window to plan, not to panic — and not to wait.

Why healthcare sites are especially exposed

Healthcare websites tend to carry more accessibility risk than the average site because of what they contain:

  • Patient portals and appointment scheduling — complex, interactive, and often built on third-party platforms that were not designed with keyboard and screen-reader users in mind.
  • Forms — intake, insurance, consent, and registration forms are among the most common failure points, and among the most consequential when a patient cannot complete one.
  • Posted documents — visit summaries, price transparency files, notices, and policies, frequently published as inaccessible PDFs.
  • Provider directories and location finders — dynamic content that often breaks for assistive technology.

When a patient cannot book an appointment, read a test result, or complete an intake form because the page does not work with their assistive technology, that is precisely the kind of barrier Section 504 is meant to prevent.

What conformance looks like in practice

The WCAG 2.1 AA requirements are the same across every covered organization. In plain terms, across your website, portal, and documents:

  1. Images that convey information have text alternatives.
  2. Text meets minimum color-contrast ratios.
  3. Every form field has a programmatic label.
  4. Everything works with a keyboard alone, with a visible focus indicator.
  5. Links and buttons have clear, descriptive names.
  6. Video is captioned and audio is transcribed.
  7. Posted PDFs and documents meet the same standard.

A realistic path for health systems

  1. Inventory and scan the full digital footprint — main site, sub-sites, portal-facing pages, and the document library.
  2. Prioritize patient-critical journeys first: scheduling, intake, results, billing.
  3. Coordinate with your portal and EHR vendors, since some fixes live in third-party systems and require lead time to negotiate.
  4. Work the document backlog in parallel.
  5. Monitor continuously so new clinical and administrative content does not reintroduce barriers.
  6. Document the program — ongoing, demonstrable remediation is your best evidence of good-faith compliance.

Start by knowing where you stand

The first step is not a policy or a vendor contract — it is an accurate measurement of your current gap across every page, portal surface, and document. You cannot plan a remediation you have not scoped, and the runway to 2027 is shorter than it looks.

Sources: U.S. Department of Health and Human Services, Final Rule on Nondiscrimination on the Basis of Disability in Programs and Activities Receiving Federal Financial Assistance (Section 504 of the Rehabilitation Act), May 2024; Web Content Accessibility Guidelines (WCAG) 2.1. This article is informational and is not legal advice. Confirm your organization's coverage and applicable compliance date before relying on this summary.

Start your compliance program today.

Free scan and Document Remediation widget — no credit card required.

Get your complimentary scan