Key Takeaways
- Treat agency selection as a risk-adjusted admissions decision, because the wrong partner exposes the organization to Section 504, HIPAA Security Rule, and online tracking liabilities that reach every vendor touching ePHI.
- Evaluate candidates against four documented pillars: WCAG 2.1 AA accessibility, HIPAA-grade security posture, health-literacy content, and peer-reviewed trust design, each backed by artifacts rather than adjectives.
- Require the agency to name its Section 504 compliance deadline, WCAG 2.1 AA testing methodology, and handling of the rule’s five exceptions, since vague accessibility claims signal remediation costs later 1.
- Verify HIPAA security posture through live data-flow documentation, a named subprocessor list with signed BAAs, and incident-reporting SLAs that meet HHS cloud computing guidance 4, 7.
- Demand a per-script, per-page classification against the HHS tracking bulletin and a written position on the June 2024 partial vacatur, because pixels and session replay carry disclosure risk 5.
- Test health literacy competence with keyboard-only walkthroughs, HTML-first content delivery, and evidence of iterative user testing with real audiences rather than internal stakeholders 9, 10.
- Map every design decision to credibility, impartiality, privacy, and familiarity, the four peer-reviewed factors that actually predict patient trust on health websites 12.
- For multi-facility portfolios, consolidate under one governed design system to compress repeating costs across accessibility remediation, risk analysis, BAA review, and script classification 2, 4, 5, 7.
Why Agency Selection Is a Risk-Adjusted Admissions Decision
A treatment center’s website is where the admissions funnel meets federal accessibility law, the HIPAA Security Rule, and the peer-reviewed literature on patient trust. Picking the wrong design partner does not just produce a slower site or a weaker call-to-action. It exposes the organization to Section 504 obligations that now require WCAG 2.1 Level AA conformance for web content and mobile apps 1, and to Security Rule risk analysis expectations that reach any vendor touching electronic protected health information 4, 6.
The economics track the risk. Every accessibility defect that reaches production becomes remediation labor. Every tracking script installed without a defensible analysis becomes a potential disclosure question under the HHS bulletin on online tracking technologies 5. Every intake form built on infrastructure without a business associate agreement becomes a security-incident reporting problem 7. These are not hypothetical line items; they are the variables a CFO or private-equity sponsor will ask about the first time an OCR complaint or a plaintiff’s demand letter arrives.
Reframing the vendor choice this way changes the question a CMO brings to procurement. The right healthcare website design agency is the one that can document accessibility conformance, a risk-based security posture, health-literacy-grade content, and design decisions grounded in the four peer-reviewed trust factors 12. What follows is the framework for evaluating that documentation.
The Four-Pillar Vetting Framework
Four pillars separate a defensible healthcare website design agency from a creative shop with a healthcare page on its site. Each maps to a primary source a treatment center’s legal and clinical teams already recognize.
- Accessibility conformance under Section 504, measured against WCAG 2.1 Level AA 1.
- Security posture anchored in a documented, ongoing risk analysis of forms, hosting, and third-party scripts 4, with a clear position on the HHS online tracking bulletin 5.
- Health-literacy-grade content and navigation built on plain language, HTML-first structure, and iterative user testing 9, 10.
- Trust design grounded in the peer-reviewed factors that actually predict patient confidence: credibility, impartiality, privacy, and familiarity 12.
The rest of this article works through each pillar as a set of RFP questions, portfolio checks, and procurement artifacts the CMO can hand to legal, IT, and admissions leadership.
Pillar One: Accessibility Conformance Under Section 504
What HHS Actually Requires of Healthcare Digital Experiences
Section 504’s 2024 final rule sets a specific technical target for federally funded healthcare programs: web content and mobile apps must conform to WCAG 2.1 Level AA 1. That includes text, images, audio, video, controls, animations, and conventional electronic documents delivered through the site 2. A treatment center receiving federal funds does not get to negotiate the standard down to a lower conformance level based on aesthetics, brand guidelines, or budget cycles.
The rule also carves out five exceptions, including archived web content and certain preexisting conventional electronic documents 1. Any agency proposing to lean on those exceptions to reduce scope should be able to name which category applies, cite the rule’s language, and document the decision. Vague reassurance that “most of the site is covered” is not the same as a written exception analysis.
The practical vetting move: ask the agency which recipient-size compliance deadline applies to the organization, what its documented WCAG 2.1 AA testing methodology looks like, and how it handles the five statutory exceptions when scoping content migration. A vendor that cannot answer those three questions in specifics has not built a healthcare practice around this rule.
RFP Questions That Separate Conformance From Marketing Copy
An agency page that says “ADA compliant” or “accessibility ready” tells the procurement team nothing. The RFP should force written answers to questions a defense attorney or OCR investigator would ask later.
Ask the vendor to name its target conformance level in exact terms: WCAG 2.1 Level AA, per Section 504’s final rule 3. Ask for the automated tools it uses, the manual testing protocol it runs against those tools, and how many hours of manual testing are budgeted per template. Ask which team members hold accessibility credentials, and whether testing is performed in-house or outsourced.
Ask for a sample Voluntary Product Accessibility Template or accessibility conformance report from a recent healthcare engagement, with client details redacted. Ask how the agency tests with assistive technology, including screen readers and keyboard-only navigation 10. Ask what the remediation SLA looks like when a defect is found post-launch, and who pays for fixes attributable to the agency’s build.
For content migration, ask how the vendor handles legacy PDFs, embedded video captions, and image alt text at scale. These are the categories where WCAG 2.1 AA failures cluster and where the Section 504 exceptions are most often misread 1.
An agency that answers each of these in writing, with artifacts, is operating a conformance practice. An agency that answers with adjectives is selling a redesign.
Pillar Two: HIPAA Security Posture, Hosting, and the Tracking Bulletin
Risk Analysis as the Agency’s Operating Discipline
HHS treats risk analysis as the first step in identifying and implementing safeguards for electronic protected health information, and the process must be documented and updated as new technologies or business changes are introduced 4. A treatment center’s design agency does not sign the risk analysis, but its choices populate it: which forms collect what fields, where those fields transit, which subprocessors touch the data, and which scripts fire on which pages.
The Security Rule reaches covered entities and their business associates 6. A web vendor building an intake form, a chat widget, or a scheduling module for a treatment center is operating inside that perimeter the moment PHI can flow through the code it ships.
The vetting question is whether the agency treats risk analysis as a live operating discipline or as a client problem. Ask for the agency’s internal data-flow documentation from a recent build. Ask which threats and vulnerabilities it identifies at the form layer, the hosting layer, and the third-party script layer, and how it revises that documentation when a marketing team adds a new tag. A vendor that cannot produce artifacts here is one that will hand the risk analysis burden back to the CMO and legal team after launch.
Pixels, Session Replay, and the June 2024 Partial Vacatur
The HHS bulletin on online tracking technologies defines tracking as scripts or code used to gather information about users or their actions, and it warns that tracking technology vendors may themselves be business associates. Disclosures of PHI for marketing purposes without HIPAA-compliant authorization are impermissible under the guidance 5. Consent banners and privacy policies do not cure that; a checkbox does not authorize a PHI disclosure that the underlying script was never allowed to make.
On June 20, 2024, a federal court vacated part of that guidance as applied to certain unauthenticated public webpages 5. That partial vacatur is the reason the correct answer to “can we run Meta Pixel on the treatment page” is neither a flat yes nor a flat no. The bulletin’s framework for authenticated pages, patient portals, and pages where identifiable health information is collected still stands. What changed is the treatment of some general public marketing pages that do not authenticate the visitor or collect identifiable health information.
An agency that cannot explain the pre- and post-vacatur posture in specifics should not be the vendor writing the tag manager configuration for an addiction treatment site. The right RFP moves are concrete:
- Ask which pages are classified as authenticated versus unauthenticated in the vendor’s proposed architecture.
- Ask how the vendor evaluates each script against the bulletin’s definition of tracking technologies.
- Ask which vendors it treats as business associates and can produce signed BAAs for, and which it refuses to deploy on regulated pages.
- Ask what the incident-response path looks like if a marketing team member installs an unapproved pixel through Google Tag Manager after launch.
The bulletin also matters for session replay, heatmaps, and chatbot transcripts. Each captures user actions in ways that can implicate PHI depending on page context. A defensible agency has a written classification of every category of script it deploys, mapped to the bulletin’s definition and to whether a BAA is required 5.
Cloud Hosting, CMS, and Form Vendor Evaluation
Hosting and CMS decisions carry the same business-associate weight as tracking scripts. HHS guidance on cloud computing requires a business associate agreement that obligates the business associate to report security incidents involving ePHI to the covered entity whose ePHI it maintains 7. A treatment center’s website vendor should be able to name every subprocessor in the stack that could touch ePHI and produce the BAA chain for each.
Ask the agency to list the CMS, the hosting provider, the CDN, the form processor, the email delivery service, the chat vendor, and the analytics stack it proposes. For each, ask whether a BAA is in place, who signs it, and what the security-incident reporting SLA looks like. Ask how the vendor handles a subprocessor change mid-contract.
A useful maturity lens for these answers is the NIST Privacy Framework, which frames privacy risk management as an enterprise activity spanning data minimization, transparency, and governance rather than a vendor-questionnaire checkbox 8. An agency that speaks that language is one that will not quietly swap a form vendor for a cheaper option that never signed a BAA.
Pillar Three: Health Literacy and Patient-Journey Design
Plain Language, HTML-First Content, and Iterative Testing
AHRQ’s guide for developers and purchasers of health IT is specific about what “designed for comprehension” means. Content should use plain and clear language, present relevant information, sit in formats conducive to reading and comprehension, and be refined through iterative testing and revision with the intended audience 9. The same guide tells purchasers to use HTML over other formats for internet-facing content 9. A treatment center site heavy with PDFs, embedded slide decks, or JavaScript-rendered text that never resolves to HTML fails that test before a copywriter opens a document.
ODPHP’s Health Literacy Online guide adds the structural pieces. Page titles and section headings should be marked up consistently, and every task on the site should be completable with a keyboard alone 10. Those are testable properties. A vendor can be asked to demo a full admissions inquiry using only the Tab, Shift+Tab, and Enter keys, without a mouse.
The vetting move is to ask the agency how it runs iterative user testing with people who match the site’s actual audience, not internal stakeholders. Ask how many rounds are budgeted, at what fidelity, and how findings are logged against specific pages before launch.
Behavioral Health and Addiction Treatment Journey Specifics
The vetting frame narrows here from general healthcare to behavioral health and addiction treatment sites, where the visitor is often in crisis, reading on a phone at 2 a.m., or a family member searching on behalf of someone else. Stigma changes what people will click. Low health literacy changes what they will read. Both change what a competent agency ships.
An agency that has actually built for this audience can point to specific design decisions:
- Level-of-care pages written in plain language rather than clinical taxonomy.
- Insurance verification forms that collect only the fields needed for a VOB.
- Cost and program-length information stated in the same paragraph as the call-to-action.
- Navigation that does not force a visitor through a marketing narrative before reaching a phone number.
These match AHRQ’s guidance on relevant content and comprehension-friendly formats 9 and ODPHP’s guidance on consistent headings and keyboard-completable tasks 10.
Ask candidates to walk a family-member persona through a live client site end-to-end. What they skip, defend, or fail to explain is the portfolio review that matters.
Key Metrics for Selecting a Healthcare Website Design Partner
Discover how evidence-based digital strategies support admissions growth and compliance—delivered by experts with decades of healthcare and behavioral health marketing experience.
Assess Your Site NowPillar Four: Trust Design Grounded in Peer-Reviewed Research
Trust on a healthcare website is not a brand tone. It is a set of design specifications the peer-reviewed literature has already named. The revised model of trust in internet-based health information identifies four factors that shape whether a visitor believes what a site says: personal experiences, credibility and impartiality, privacy, and familiarity. Of those four, credibility and impartiality showed a significant direct relationship with trust 12. That finding is the one a CMO should hand to any agency claiming its designs “build trust.”
An earlier synthesis of the literature reached a compatible conclusion: trust should focus on information quality, user understanding, website reliability, and the visitor’s experience interacting with the site 11. Neither paper points to hero imagery, stock photography of clinicians, or award badges. Both point to what the content says, how clearly it is written, and whether the site works when a person actually uses it.
Each of the four factors maps to concrete design decisions an agency should be able to defend.
- Credibility and impartiality require clinical authorship attribution, dated content, disclosure of ownership and payor relationships, and level-of-care descriptions that do not read as sales copy.
- Privacy requires a plain-language notice explaining what the intake form collects, where it goes, and which third-party scripts run on the page, aligned with the risk analysis already underway 4.
- Familiarity requires consistent navigation, headings, and interaction patterns across every page and facility, so a family member who lands on a program page and then a location page is not learning a new interface each time.
- Personal experiences require that the site actually work end-to-end on the devices and connections real visitors use.
The vetting move is to ask a candidate agency which of the four factors each proposed design decision addresses, and to reject answers that collapse into “we make it look trustworthy.” A vendor that cannot map its choices back to credibility, impartiality, privacy, and familiarity is designing on instinct, not on evidence.
Grading Portfolio Work Without Getting Distracted by Aesthetics
A portfolio review that stops at screenshots grades the wrong artifact. The aesthetic surface says nothing about whether the site conforms to WCAG 2.1 Level AA, whether the intake form sits behind a signed BAA, or whether a family member in crisis can find a phone number in under fifteen seconds.
Grade the portfolio on properties that can be tested from the outside:
- Run a live client site through a keyboard-only pass: Tab, Shift+Tab, Enter, and nothing else. Check whether headings are marked up consistently and whether skip links resolve where they claim to 10.
- Open the source and confirm content renders as HTML rather than as PDF downloads or JavaScript payloads that never resolve for a screen reader 9.
- Open the network tab and inventory every third-party script firing on a page that discusses a specific level of care, then ask the agency which of those it treats as tracking technologies under the HHS bulletin 5.
Ask the agency to name the credibility, impartiality, privacy, and familiarity decisions behind a live page 12. Aesthetics are the last thing to grade, not the first.
If You Manage a Multi-Facility Portfolio: Consolidation Economics
The audience narrows here to CMOs at PE-backed networks and multi-facility operators running three or more sites. The vetting math changes when accessibility, security, and tracking obligations repeat across every property.
A single agency delivering one governed design system across the portfolio compresses four cost categories the CFO already tracks:
- Per-site WCAG 2.1 AA remediation hours.
- Per-site risk analysis documentation under the Security Rule 4.
- Per-site BAA legal review for hosting and form vendors 7.
- Per-site classification of tracking scripts against the HHS bulletin 5.
Per-facility vendors duplicate each of those line items and rarely reconcile the outputs. When OCR asks how the network evaluates pixels on level-of-care pages, one methodology across ten sites is a defensible answer. Ten methodologies is not.
Recipient size also drives the compliance calendar. Section 504’s final rule applies the two-year window to recipients with 15 or more employees and the three-year window to smaller recipients 2. In a portfolio, that variable is set at the entity level, not the facility level, and it should be resolved before scoping the redesign schedule.
The consolidation questions to ask a candidate agency: what percentage of components are reused across facility templates, how is the risk analysis maintained when a facility launches a local campaign, and who owns the BAA chain when a subprocessor changes. A vendor that treats each facility as a fresh build is one the network will pay to solve the same problem repeatedly.
A Procurement Scorecard the Legal and Clinical Teams Will Sign
The final artifact of a real vetting process is a one-page scorecard that legal, IT, and clinical leadership will initial before contract signature. It converts the four pillars into pass/fail evidence, not adjectives.
- Score accessibility on written WCAG 2.1 Level AA conformance methodology, a redacted conformance report from a healthcare build, and a keyboard-only demo of a live client site 3, 10.
- Score security on a sample data-flow document, a named list of subprocessors with BAAs in place, and the incident-reporting SLA the vendor will sign under cloud computing guidance 4, 7.
- Score tracking on a per-script classification against the HHS bulletin and a written position on the June 2024 partial vacatur 5.
- Score trust design on decisions mapped to credibility, impartiality, privacy, and familiarity for a specific page 12.
Any candidate that cannot produce artifacts in all four columns is not the healthcare website design agency the admissions team should be routing calls through. Active Marketing built its vetting posture around exactly this scorecard.
Frequently Asked Questions
What accessibility standard should a healthcare website design agency build to?
WCAG 2.1 Level AA, as required by Section 504’s 2024 final rule for federally funded healthcare programs 1. That standard applies to text, images, audio, video, controls, and conventional electronic documents delivered through the site 2. An agency that markets “ADA compliant” without naming WCAG 2.1 AA and its five statutory exceptions is not writing to the actual rule.
When does a website vendor become a HIPAA business associate?
The moment its code, hosting, forms, or scripts create, receive, maintain, or transmit ePHI on behalf of a covered entity 6. HHS treats tracking technology vendors as potential business associates when their scripts collect user information tied to health context 5. Cloud hosts, form processors, and analytics vendors touching ePHI require a signed BAA obligating security-incident reporting 7.
Can we still use tracking pixels and analytics on our treatment center website after the June 2024 partial vacatur?
On some unauthenticated public marketing pages, yes; the June 20, 2024 order vacated part of the bulletin as applied to those pages 5. Authenticated pages, portals, and pages collecting identifiable health information still fall under the bulletin’s framework. The defensible move is a per-script, per-page classification, not a blanket policy either direction.
How should an agency demonstrate health literacy competence during vetting?
Ask for evidence of plain-language content, HTML-first delivery over PDFs, and iterative testing with people who match the site’s audience rather than internal stakeholders 9. Request a live keyboard-only walkthrough of a client site to confirm consistent heading markup and completable tasks 10. Portfolio screenshots do not answer this; a demo does.
What questions separate real WCAG conformance from marketing claims in an RFP response?
Ask for the target conformance level in exact terms, the automated tools used, and the manual testing hours budgeted per template 3. Request a redacted accessibility conformance report from a recent healthcare build and the post-launch remediation SLA. Ask which staff hold accessibility credentials and how the agency handles Section 504’s five exceptions 1.
For a multi-facility behavioral health portfolio, is one agency across all sites better than per-facility vendors?
One agency operating a governed design system consolidates four repeating cost categories: WCAG 2.1 AA remediation, Security Rule risk analysis documentation 4, BAA legal review for hosting and form vendors 7, and per-script tracking classification against the HHS bulletin 5. One methodology across ten sites is defensible to OCR. Ten disconnected methodologies rarely are.
References
- Section 504 of the Rehabilitation Act of 1973 Final Rule – HHS.gov. https://www.hhs.gov/civil-rights/for-individuals/disability/section-504-rehabilitation-act-of-1973/ocr-detailed-504-fact-sheet/index.html
- Section 504 of the Rehabilitation Act of 1973 Final Rule. https://www.hhs.gov/sites/default/files/sec-504-ria-final-rule-2024.pdf
- Section 504 of the Rehabilitation Act of 1973 Part 84 Final Rule. https://www.hhs.gov/civil-rights/for-individuals/disability/section-504-rehabilitation-act-of-1973/part-84-final-rule-fact-sheet/index.html
- Guidance on Risk Analysis. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
- Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
- Summary of the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- Guidance on HIPAA & Cloud Computing. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- NIST Privacy Framework: An Overview. https://www.nist.gov/publications/nist-privacy-framework-overview
- Accessible Health Information Technology (IT) for Populations with Limited Literacy: A Guide for Developers and Purchasers of Health IT. https://digital.ahrq.gov/sites/default/files/docs/page/LiteracyGuide_0.pdf
- Health Literacy Online. https://odphp.health.gov/healthliteracyonline/2016/full/
- Trust between patients and health websites: a review of the literature. https://pmc.ncbi.nlm.nih.gov/articles/PMC3266366/
- A Revised Model of Trust in Internet-Based Health Information. https://pmc.ncbi.nlm.nih.gov/articles/PMC6878106/