Healthcare Software VPAT & Accessibility: ADA – U.S. Guide

Does your healthcare or telehealth software meet U.S. accessibility requirements, and can you provide a credible VPAT/ACR when a hospital, government agency, healthcare organization, or procurement team asks for accessibility evidence?

Healthcare Software VPAT and Accessibility graphic showing a VPAT document, Section 508, WCAG 2.2, ADA considerations, patient portal, telehealth, appointments, medical records, and payments.
Healthcare Software VPAT and Accessibility: Preparing healthcare and telehealth platforms for accessibility testing, U.S. procurement, and VPAT/ACR requirements.

Healthcare is increasingly digital.

Patients now register online, schedule appointments, attend virtual consultations, access medical records, review prescriptions and lab results, communicate with providers, complete forms, and make payments through websites and mobile applications.

For HealthTech vendors, accessibility affects much more than the marketing website.

It can affect:

Patient Access + Clinical Workflows + Procurement + Section 508 + Section 504 + ADA Considerations + WCAG + VPAT/ACR + Enterprise Sales

The important question is not simply:

“Do we have a VPAT?”

A better question is:

“Has our actual healthcare platform been properly evaluated for accessibility, and can our accessibility claims be supported by evidence?”

This guide explains what healthcare and telehealth software vendors should consider before preparing a VPAT/ACR for U.S. customers.

Quick Answer: Does Healthcare Software Need a VPAT?

Not every healthcare software product is automatically required to have a VPAT.

However, a VPAT/ACR can become important when selling healthcare technology to U.S. federal agencies, hospitals, universities, public organizations, healthcare systems, and enterprise buyers that include accessibility in procurement.

For U.S. federal ICT procurement, an Accessibility Conformance Report (ACR) is commonly used to explain how a product conforms to applicable Revised Section 508 requirements.

The VPAT, Voluntary Product Accessibility Template®, is the widely used template for preparing an ACR.

A credible ACR should be based on an accessibility evaluation of the actual product.

What Is a VPAT for Healthcare Software?

A VPAT, Voluntary Product Accessibility Template®, is a structured template used to document the accessibility conformance of an information and communication technology product.

After the template is completed with the product’s accessibility findings, the resulting document is commonly called an:

Accessibility Conformance Report (ACR).

For healthcare technology, an ACR can document accessibility across products such as:

  • Patient portals
  • Telehealth platforms
  • Hospital software
  • Healthcare SaaS
  • Appointment systems
  • Electronic health interfaces
  • Patient mobile applications
  • Provider dashboards
  • Healthcare communication systems
  • Digital healthcare forms
  • Billing and payment systems

A VPAT should not be treated as a simple certificate declaring:

“Our healthcare software is accessible.”

The actual product should first be evaluated against the accessibility requirements applicable to the intended report and procurement context.

Why Healthcare Software Vendors Are Asked for VPATs

Accessibility can enter the healthcare technology sales process at several points.

A buyer may:

  • Include accessibility requirements in an RFP
  • Request an ACR
  • Ask about Section 508
  • Send an accessibility questionnaire
  • Request WCAG conformance information
  • Ask how the product was tested
  • Request known accessibility limitations
  • Ask for remediation plans
  • Request an updated VPAT after a major release

Accessibility can therefore become part of:

Product Evaluation → RFP → Security & Compliance → Procurement → Contracting → Implementation → Renewal

For HealthTech vendors, waiting until procurement requests a VPAT can create pressure on:

Product + Engineering + QA + Compliance + Legal + Sales

A stronger approach is to establish your accessibility position before it becomes a sales blocker.

Selling Healthcare Software to the U.S. Federal Government?

Accessibility becomes particularly important when your product is information and communication technology intended for federal procurement.

Federal agencies must address Section 508 accessibility requirements for applicable ICT.

Federal accessibility guidance recommends ACRs as a way for vendors to explain how their products meet applicable Revised Section 508 requirements.

For vendors, this means a VPAT/ACR can become important procurement evidence.

Procurement teams may look beyond whether the vendor merely possesses a VPAT.

Section 504 and Healthcare Digital Accessibility

Healthcare organizations receiving federal financial assistance from the U.S. Department of Health and Human Services may also have obligations under Section 504 of the Rehabilitation Act.

HHS established WCAG 2.1 Level AA as the technical standard for covered web content and mobile applications under the relevant Section 504 rule provisions.

As of September 2026, HHS has extended the applicable compliance dates by one year:

15 or more employees → May 11, 2027

Fewer than 15 employees → May 10, 2028

The exact applicability, exceptions, and obligations depend on the organization and circumstances.

This distinction is important for HealthTech vendors.

WCAG 2.2 AA may be used as a modern accessibility assessment target, while a particular legal or procurement requirement may reference a different technical baseline, such as WCAG 2.1 AA.

Always identify the requirement before defining the audit and VPAT scope.

WCAG, ADA, Section 504, Section 508 and VPAT Are Not the Same Thing

These terms should not be treated as interchangeable.

RequirementWhat It Represents
ADAU.S. disability civil rights law
Section 504Disability nondiscrimination requirements for covered federally funded programs and activities
Section 508Accessibility requirements applying to federal ICT
WCAGTechnical web accessibility guidelines
VPATTemplate used to document accessibility conformance
ACRCompleted Accessibility Conformance Report

Healthcare Accessibility Must Cover the Complete Journey

Testing only a healthcare website homepage is not enough.

A healthcare platform may have an accessible marketing site while patients encounter serious barriers after logging in.

Accessibility assessment should therefore follow real patient and healthcare professional journeys.

A representative patient journey may look like:

Registration → Authentication → Find Provider → Appointment → Forms → Teleconsultation → Patient Records → Prescription → Lab Results → Secure Messaging → Billing → Payment

Every step matters.

Common Accessibility Barriers in Healthcare Software

Healthcare AreaExample Accessibility Barrier
RegistrationInputs lack meaningful labels
AuthenticationOTP or verification is difficult to complete
Appointment bookingDate picker is not keyboard accessible
CalendarAvailable dates are not announced
FormsErrors are not associated with fields
NavigationKeyboard focus order is incorrect
DialogsFocus is not properly managed
TelehealthCall controls have unclear accessible names
VideoCaptions are unavailable
Patient recordsTables lack appropriate relationships
Lab resultsStatus is communicated only through color
ChartsNo equivalent accessible information
MedicationInstructions lack clear structure
Secure messagesNew messages are not announced
Session timeoutUser cannot extend the session
DocumentsPatient PDFs are inaccessible
MobileTouch targets are difficult to operate
ZoomContent becomes unavailable at enlargement
Custom controlsName, role or state is missing
Provider dashboardComplex data interactions are inaccessible

Finding these barriers is only the first step.

The next steps are:

Understand Impact → Remediate → Re-Test → Document Conformance

What Accessibility Standards Should a Healthcare VPAT Cover?

The answer depends on:

  • Customer
  • Procurement requirement
  • Product
  • Market
  • Deployment
  • Contract
  • Applicable accessibility obligations

For U.S. federal procurement, Revised Section 508 is particularly important.

For web-based products, applicable WCAG Level A and AA criteria commonly form part of accessibility evaluation.

For international procurement, EN 301 549 may also be relevant.

WCAG 2.2 AA vs Healthcare Legal Requirements

Enabled.in can assess modern digital products against WCAG 2.2 Level A and AA, depending on the engagement.

But healthcare vendors should understand an important distinction.

The newest technical standard is not automatically the standard written into every applicable U.S. regulation or contract.

For example, HHS Section 504 web and mobile provisions use WCAG 2.1 Level AA as the specified technical standard for covered recipients.

A customer may separately ask for:

  • WCAG 2.2 AA
  • Revised Section 508
  • VPAT 2.5
  • EN 301 549
  • A combination of standards

From Healthcare Accessibility Audit to VPAT/ACR

A stronger process is:

  1. Understand the Requirement
    • Customer Request → RFP → Section 508 → Healthcare Procurement → Accessibility Questionnaire → Internal Accessibility Goal
  2. Define the Product Scope
    • Patient Portal → Provider Portal → Web → Mobile → Documents → Integrations → Critical Journeys
  3. Establish the Accessibility Baseline
    • Applicable Standards → Conformance Target → Browsers → Operating Systems → Assistive Technologies
  4. Perform the Accessibility Assessment
    • Automated + Expert Manual + Keyboard + Assistive Technology + Mobile + Real-User Testing
  5. Document Findings
    • Barrier → User Impact → Workflow → Requirement → Evidence → Remediation
  6. Remediate
    • Product, UX, engineering, content, and other responsible teams address the accessibility issues.
  7. Re-Test – Validate fixes and identify remaining barriers.
  8. Prepare the VPAT/ACR – Document the actual conformance status based on assessment evidence.
  9. Maintain Accessibility – Reassess when significant product functionality changes.

Can You Create a VPAT Before Fixing Every Issue?

Yes. A product does not necessarily need to have zero accessibility issues before an ACR can be prepared.

A VPAT/ACR is intended to document the product’s actual conformance status accurately.

VPAT 2.5 uses conformance terms including:

  • Supports
  • Partially Supports
  • Does Not Support
  • Not Applicable

When a criterion is not fully supported, the remarks should provide meaningful information about the limitation.

Therefore:

VPAT ≠ Pass/Fail Certificate

A transparent ACR describing actual accessibility limitations can provide more useful procurement information than an unsupported claim that everything “Supports.”

How Enabled.in Helps Healthcare and Telehealth Vendors

Enabled.in provides end-to-end digital accessibility audit and testing services for healthcare software, telehealth platforms, patient portals, SaaS applications, provider systems, and mobile applications.

We focus on whether patients and healthcare professionals with disabilities can successfully complete real workflows, not simply whether an automated scanner reports a high score.

Healthcare Accessibility Assessment Coverage

Your assessment can cover:

Registration → Authentication → Appointment Search → Booking → Forms → Teleconsultation → Patient Records → Prescriptions → Lab Results → Secure Messaging → Billing → Payment → Provider Dashboards

Depending on the project scope, testing can combine:

Automated Testing + Expert Manual Testing + Keyboard Testing + Assistive Technology Testing + Mobile Accessibility Testing + Real-User Testing with Persons with Disabilities

Testing can be aligned with applicable requirements such as:

  • WCAG 2.2 Level A and AA
  • Revised Section 508
  • Relevant EN 301 549 requirements
  • VPAT 2.5 / ACR requirements

Following the initial assessment, Enabled.in can support:

Accessibility Audit → Findings & Evidence → Remediation Guidance → Developer Support → Re-Testing → VPAT/ACR Preparation

The objective is not simply to generate a document.

It is to help your organization build credible, evidence-based accessibility information for customers and procurement teams.

Preparing Your Healthcare Platform for U.S. Customers?

Has a hospital, healthcare organization, government agency, university, enterprise buyer, or procurement team asked you for:

  • WCAG conformance?
  • Section 508 support?
  • Accessibility testing evidence?
  • A VPAT/ACR?

You do not need to begin by guessing which screens should be tested.

Enabled.in can help review your product, identify critical patient and provider journeys, define the accessibility assessment scope, identify barriers, support remediation, validate fixes, and prepare the final VPAT/ACR where required.

Assess Your Healthcare Platform

Start with your product and procurement requirement.

    Share with Enabled.in:

    Product Type + Web/Mobile Platforms + Patient/Provider Modules + Customer Requirement + VPAT Requirement

    We can help determine an appropriate accessibility testing scope.

    Enabled.in – Digital Accessibility Services

    Email: info@enabled.in
    Phone: +91 98405 15647

    Services: Healthcare Accessibility Audit, Telehealth Accessibility Testing & VPAT/ACR
    Technical Testing: WCAG 2.2 Level A & AA
    Procurement: Revised Section 508 / VPAT 2.5 / ACR
    Platforms: Web, SaaS, Mobile & Enterprise Healthcare Applications
    Market: United States and Global

    Frequently Asked Questions

    What is a healthcare software VPAT?

    A VPAT is a structured template used to document accessibility conformance for an ICT product. After it is completed with information about a particular product, the resulting document is commonly called an Accessibility Conformance Report or ACR.

    Is a VPAT required for every healthcare application?

    No. The requirement depends on the customer, procurement process, applicable requirements, contract, and market. VPAT/ACR documentation is particularly relevant for products intended for U.S. federal ICT procurement and may also be requested by hospitals, universities, enterprises, and other buyers.

    Is a VPAT the same as an accessibility certificate?

    No. A VPAT is a reporting template. The completed ACR documents the product’s conformance with applicable accessibility criteria. It should not be represented as a universal accessibility certification.

    What is the difference between a VPAT and an ACR?

    The VPAT is the template used to report accessibility conformance. The completed report containing information about a particular product is the Accessibility Conformance Report or ACR.

    Does having a VPAT mean healthcare software is fully accessible?

    No. An ACR may contain Supports, Partially Supports, Does Not Support, and Not Applicable conformance statements. It should accurately describe the product’s accessibility status and known limitations.

    Should healthcare accessibility testing happen before preparing a VPAT?

    Yes. The product should be evaluated against the applicable accessibility requirements so the statements in the ACR are supported by evidence.

    Can automated testing be used to create a healthcare VPAT?

    Automated tools can contribute to the assessment, but they should not be the sole basis for a comprehensive VPAT. Many requirements require manual, keyboard, assistive technology, and workflow-based evaluation.

    What accessibility standard should healthcare software use?

    It depends on the requirement. WCAG 2.2 Level AA is a strong modern technical target for accessibility assessment, while particular regulations or procurement requirements may specify other standards. For example, applicable HHS Section 504 web and mobile requirements specify WCAG 2.1 Level AA.

    Does Section 508 apply to healthcare software?

    Section 508 is particularly relevant when ICT is procured, developed, maintained, or used by U.S. federal agencies. Healthcare software vendors selling to federal customers should determine the applicable Section 508 procurement requirements.

    Does the ADA apply to telehealth?

    The U.S. Department of Justice states that the ADA’s disability nondiscrimination requirements apply when covered healthcare providers deliver healthcare through telehealth as well as in person.

    Should patient and provider workflows both be tested?

    If both experiences are part of the product and intended VPAT scope, representative patient and healthcare professional workflows should be evaluated.

    Should healthcare mobile apps be included?

    If native iOS or Android applications are within the product scope, their accessibility should be evaluated separately rather than inferred from web testing.

    What healthcare journeys should accessibility testing cover?

    Typical journeys include registration, authentication, appointment booking, forms, teleconsultation, patient records, prescriptions, lab results, secure messaging, billing, payment, and provider workflows.

    Can a VPAT be prepared before all accessibility issues are fixed?

    Yes. An ACR is intended to accurately report the product’s current conformance status. Remaining limitations should be represented accurately using the appropriate conformance level and remarks.

    When should a healthcare VPAT be updated?

    Consider updating the ACR after significant changes to the product, including major UI changes, authentication, navigation, appointment workflows, telehealth functionality, forms, provider dashboards, mobile applications, integrations, or major releases.

    Can Enabled.in prepare a healthcare VPAT/ACR?

    Yes. Enabled.in can support healthcare and telehealth vendors with accessibility assessment, remediation guidance, re-testing, and final VPAT/ACR preparation based on the agreed product scope and applicable accessibility requirements.


    Discover more from Enabled.in

    Subscribe to get the latest posts sent to your email.

    Discover more from Enabled.in

    Subscribe now to keep reading and get access to the full archive.

    Continue reading