WCAG 2.1, Level AA conformance
The requirements
The Web Content Accessibility Guidelines are the international standard for web and mobile accessibility, developed by the World Wide Web Consortium (W3C). The guidelines are built on four core principles — known by the acronym POUR:
- Perceivable: Information and UI components must be presentable to users in ways they can perceive (captions, alt text, sufficient color contrast)
- Operable : All functionality must be accessible via keyboard; no time traps; no seizure-inducing content
- Understandable : Content must be readable, predictable, and include input assistance
- Robust : Content must be reliably interpreted by assistive technologies including screen readers
Both ADA Title II and Section 504 adopt WCAG version 2.1, level AA as the conformance benchmark. Level AA is the middle tier of WCAG conformance — more rigorous than Level A, and the standard referenced by most accessibility regulations worldwide. There are roughly 50 criteria that must be met for conformance.
What content must be accessible
The rule applies broadly to web content and mobile apps that an organization or public entity provides or makes available, directly or through a contractor, licensor, or other third party. This includes:
- Public-facing websites and microsites
- Patient portals and EHR patient interfaces
- Online scheduling, registration, and intake forms
- Telehealth platforms
- Online billing and payment systems
- Mobile applications
- Patient education videos and multimedia content
- Self-service kiosks (hardware accessibility governed by a parallel standard)
Note: A contractual relationship with a vendor does not transfer your liability. For example, if your electronic health record is fulfilled through a vendor and the patient portal is inaccessible, your organization is still the responsible party. Call-center customer service is no longer an acceptable substitute for inaccessible digital services under this rule.
Exceptions
There are five limited exceptions that do not need to meet WCAG 2.1:
- Archived web content: Content stored for reference that is no longer actively used
- Preexisting conventional electronic documents: PDFs and Office files published before your compliance deadline, provided they are not used to apply for, access, or participate in programs
- Content posted by a third party: Content not controlled by the recipient
- Individualized, password-protected documents: Documents shared with specific individuals that are not widely distributed
- Fundamental alteration or undue burden: Where compliance would fundamentally alter the program or impose an undue burden (must be documented in writing by the head of the entity)
Note: These exceptions are narrow. If any exempt content enters an active workflow (e.g., an archived PDF that gets updated as current patient instructions), it must be remediated or replaced with an accessible version.