Medical practice website checklist: 60 checks for speed, accessibility, privacy and bookings
A good medical practice website loads fast on a phone, works for patients with disabilities, keeps patient information away from ad and analytics tools, and makes booking, calling and checking insurance obvious from every page. This checklist turns that into 60 specific checks across eight areas, with the standards behind them: Google's Core Web Vitals, WCAG 2.2, HHS guidance on tracking technologies, and the HHS Section 504 web accessibility rule for practices that receive HHS funding.
- Aim for Google's "good" Core Web Vitals: LCP within 2.5 s, INP of 200 ms or less, CLS of 0.1 or less, measured on real mobile visits.
- Use WCAG 2.2 Level AA as your accessibility target. HHS's Section 504 rule requires WCAG 2.1 AA for recipients of HHS funding, now due May 11, 2027 (15+ employees) or May 10, 2028 (fewer than 15).
- Forms, booking and portals must be HIPAA-safe: vendors under a BAA and no third-party pixels on those pages.
- Every page needs a visible way to call, book and check insurance.
- Review the site twice a year and whenever you add a vendor, provider, service or location.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Above the fold on a phone (checks 1–7)
Most practice website visits are on phones. Open your home page and a service page on a phone and check what someone sees before they scroll.
- Practice name, specialty and city are clear within the first screen.
- A tap-to-call phone number is visible without scrolling.
- A "Book appointment" button goes straight to booking, not to a contact page.
- Hours and "accepting new patients" status are easy to find.
- No pop-up covers the content on load.
- Real photos of the team or office, not stock images of models in scrubs.
- The headline says what you do for whom ("Family and pediatric dentistry in North Dallas"), not a slogan.
Speed and Core Web Vitals (checks 8–15)
Google's Core Web Vitals measure loading, responsiveness and visual stability on real visits. The "good" thresholds, at the 75th percentile of page loads:
| Metric | Measures | Good |
|---|---|---|
| Largest Contentful Paint (LCP) | How quickly the main content appears | 2.5 seconds or less |
| Interaction to Next Paint (INP) | How quickly the page responds to taps and clicks (replaced First Input Delay in 2024) | 200 milliseconds or less |
| Cumulative Layout Shift (CLS) | How much the layout jumps while loading | 0.1 or less |
- Check the Core Web Vitals report in Search Console, mobile first.
- Hero images compressed, correctly sized and in a modern format.
- Images below the first screen load lazily.
- Remove unused plugins, sliders and old tracking scripts. Each third-party script slows the page.
- Chat widgets and booking embeds load after the main content.
- Fonts limited to a couple of families and weights.
- Space reserved for images, embeds and banners so the layout doesn't jump.
- Hosting with caching and a content delivery network; check server response time.
Accessibility: WCAG 2.2 AA (checks 16–28)
Two federal frameworks matter for practices. The Department of Justice's 2022 web guidance says the ADA applies to the web content of businesses open to the public and points to WCAG as helpful technical guidance. And HHS's Section 504 rule, published in May 2024, requires recipients of HHS financial assistance to make web content and mobile apps meet WCAG 2.1 Level AA. In May 2026, HHS extended the compliance dates by a year: May 11, 2027 for recipients with 15 or more employees and May 10, 2028 for those with fewer. Whether your practice is a recipient depends on the programs you take part in, so ask counsel.
WCAG 2.2, the W3C's current version, includes everything in 2.1 Level AA plus new criteria, so it is the sensible target for a new or rebuilt site.
- Text alternatives for meaningful images; decorative images marked as such.
- Color contrast of at least 4.5:1 for normal text and 3:1 for large text.
- Everything works with a keyboard alone, including menus, booking and forms.
- A visible focus indicator that isn't hidden behind sticky headers or chat widgets (WCAG 2.2 "focus not obscured").
- Tap targets at least 24 by 24 CSS pixels, or with enough spacing (WCAG 2.2 "target size minimum").
- No action that requires dragging without an alternative (WCAG 2.2 "dragging movements").
- Help options, such as phone and contact links, in the same place on every page (WCAG 2.2 "consistent help").
- Forms don't ask for the same information twice in one process (WCAG 2.2 "redundant entry").
- Patient portal and account logins don't rely on memory puzzles or cognitive tests without an alternative (WCAG 2.2 "accessible authentication").
- Form fields have visible labels; errors are explained in text, not just color.
- Videos have captions; audio has transcripts.
- Headings in a logical order, one H1 per page, meaningful link text.
- An accessibility statement with a phone and email to request help or alternative formats.
Automated scanners catch only part of these issues. Test with a keyboard and a screen reader as well. Our ADA and WCAG guide for healthcare websites covers the legal background in more depth.
HIPAA-safe forms, booking and tracking (checks 29–38)
The HHS Office for Civil Rights has said HIPAA applies when tracking technologies on a regulated entity's website collect protected health information. A 2024 court ruling narrowed part of that guidance for unauthenticated public pages, but portals, booking flows and forms remain high-risk. State laws add obligations too: Washington's My Health My Data Act, for example, covers consumer health data and requires a consumer health data privacy policy linked from the home page for businesses it covers.
- A current inventory of every script and tag on the site, and who owns each one.
- No ad pixels or third-party analytics on patient portal, booking, intake and contact form pages, or their thank-you pages.
- Form, scheduling, chat and hosting vendors that handle PHI have signed Business Associate Agreements.
- Form submissions are encrypted and stored in the vendor's secure system, not sent as plain email.
- Forms collect only what's needed to book or respond. No "describe your symptoms" box unless it's handled securely.
- URLs and page titles don't carry names, conditions or appointment reasons.
- Chat tools are covered by a BAA or configured to discourage health details.
- Call tracking vendors sign a BAA, or call recording is off.
- Privacy policy and HIPAA Notice of Privacy Practices are linked in the footer; state-required privacy notices are in place.
- Cookie or consent banner where state law or your vendors require it.
Details and a step-by-step audit are in our HIPAA-safe website tracking guide.
Booking and conversion (checks 39–47)
- Online booking where possible, showing real availability.
- Booking takes as few steps as possible, and works on a phone without zooming.
- Click-to-call on every page, with the number matching your Business Profile.
- A "Request a callback" option for people who can't talk now.
- New-patient information in one place: what to bring, forms, parking, what the first visit involves.
- Cost policy explained in plain words: insurance, self-pay, financing options, deposits and cancellation.
- Reviews and testimonials shown with patient permission, without editing that changes their meaning.
- Each service and location page ends with a clear next step.
- Missed-call and form response times measured; someone owns follow-up.
Content patients and search engines need (checks 48–55)
- A page for each main service, answering the main question in its first two sentences.
- A page for each location with address, map, hours, parking and the providers who work there.
- Provider bios with credentials, board certifications, training, languages and photos.
- An insurance page listing in-network plans with a "last checked" date. See our insurance page guide.
- Health content written or reviewed by named clinicians, with review dates and sources.
- FAQ sections answering the questions your front desk hears every week.
- No claims your state board or the FTC would see as misleading: guarantees, unsupported "best" claims, unauthorized before-and-after images.
- Structured data for the practice, locations and providers. See our healthcare SEO checklist.
Security, ownership and maintenance (checks 56–60)
- HTTPS everywhere, with automatic renewal of certificates.
- The practice owns the domain, hosting account and analytics accounts, with vendors added as users.
- Content management system, themes and plugins updated; unused ones removed.
- Backups taken automatically and restored at least once to prove they work.
- A written review every six months covering speed, accessibility, tags and content accuracy.
Ichelon Consulting US builds and maintains practice websites through our healthcare website design service, with accessibility and HIPAA-aware tracking built in, and connects them to SEO and local SEO. For a quick outside view, request a free practice visibility audit, or read how we work. More guides are in the US guides library.
Sources
- web.dev: Web Vitals and Core Web Vitals thresholds
- W3C: Web Content Accessibility Guidelines (WCAG) 2.2
- US Department of Justice: Guidance on web accessibility and the ADA (March 2022)
- HHS: Office for Civil Rights extends web and mobile accessibility compliance deadline (May 2026)
- Federal Register: Section 504 final rule (May 9, 2024)
- HHS: Use of online tracking technologies by HIPAA covered entities and business associates
- Washington Attorney General: My Health My Data Act
Related pages from the US team
Healthcare website design USA
How we build practice websites: fast, accessible and HIPAA-aware.
ADA and WCAG for healthcare websites
The accessibility rules in depth.
HIPAA-safe website tracking
Pixels, analytics and BAAs on practice websites.
Insurance accepted pages
How to build an insurance page patients trust.
Healthcare SEO checklist 2026
Indexing, content, E-E-A-T, local SEO and schema.
Free practice visibility audit
Have the US team review your site and local presence.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
What should a medical practice website include?
At minimum: a page for each service and location, provider bios with credentials, insurance accepted, hours and directions, online booking or a clear booking path, a click-to-call phone number, patient forms through a secure HIPAA-compliant tool, a privacy policy and notice of privacy practices, and an accessibility statement.
Do medical websites have to be ADA compliant?
The Department of Justice has said the ADA applies to the web content of businesses open to the public, including healthcare providers, and points to WCAG as helpful guidance. Separately, HHS's Section 504 rule requires recipients of HHS financial assistance to meet WCAG 2.1 Level AA, with compliance dates of May 11, 2027 for those with 15 or more employees and May 10, 2028 for smaller recipients.
What is WCAG 2.2 and what changed from 2.1?
WCAG 2.2 is the W3C's current web accessibility standard. It adds criteria including focus not obscured, dragging movements, minimum target size, consistent help, redundant entry and accessible authentication, and removes the parsing criterion. Meeting 2.2 Level AA also covers the 2.1 Level AA criteria that the HHS rule references.
Can we use a contact form on a medical website?
Yes, if it is built for health information. Use a form vendor that signs a Business Associate Agreement, encrypt submissions, don't send contents by ordinary email, collect only what you need, and keep analytics and ad tags off the form and its thank-you page.
How fast should a medical practice website be?
Use Google's Core Web Vitals as the benchmark: Largest Contentful Paint within 2.5 seconds, Interaction to Next Paint of 200 milliseconds or less, and Cumulative Layout Shift of 0.1 or less, at the 75th percentile of real visits, measured separately for mobile and desktop.
Should we list insurance plans on our website?
Yes. Patients often check insurance before calling. List plans you are in-network with, the date the list was last checked, and what to do if a plan isn't listed. Keep it current, because out-of-date lists cause frustration and complaints.
How often should a practice website be reviewed?
Run a full review at least twice a year, and a quick check whenever you add a provider, service, location, form, booking tool or marketing tag. Accessibility and tracking problems often come back after small updates.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Planning a new website or fixing the one you have?
A 30-minute benchmarking call with the US team. We'll run the key checks on your site and tell you which fixes will matter most to patients and to search.