Healthcare & health services

Healthcare web design where intake is treated like intake

Your site is where care starts: an appointment request, a question about a symptom, a form somebody fills out at 11pm. Most agency builds treat all of that like a generic contact form on a generic template.

100Lighthouse a11y · BP · SEOSalyers Construction
WCAG 2.1 AAConformance targetThe standard HHS Section 504 and DOJ Title II both name
14Sites on our accessibility systemOur accessibility system, running in production

Where the line sits

We build the technical safeguards the HIPAA Security Rule calls for, we build to WCAG 2.1 AA, and we tell you plainly where the line sits. If protected health information is going to touch the build, the engagement needs a signed Business Associate Agreement and HIPAA-eligible hosting, scoped per project before any PHI is involved. We build the mechanisms; your counsel signs off on the policy.

The problem

Where a template lets you down.

Four places a standard agency build quietly puts a practice on the wrong side of a rule.

Intake gets built like a contact form

Scheduling, symptom questions, and patient callbacks carry details a marketing form was never designed to hold. Most builds validate an email address and call it done, with no access control, no audit trail, and no honest conversation about what the form should refuse to collect.

Healthcare has its own accessibility deadline

HHS extended the Section 504 web and mobile deadline for federally funded healthcare recipients with 15 or more employees to May 11, 2027, and the standard it names is WCAG 2.1 Level AA. Meanwhile WebAIM found 95.9% of the top million home pages had detectable WCAG failures in 2026, averaging 56.1 errors per page.

Marketing tags on patient-facing pages

An analytics tag or ad pixel that fires on a page about a condition is a very different object than one on a pricing page. Roughly 1,500 CIPA suits were filed in the 18 months to August 2025, and the live question in 2026 cases is narrow: did tracking fire before the visitor acted on the consent banner.

Vendors who answer "HIPAA compliant" and stop talking

It is the easiest thing in the world for an agency to say and the hardest thing to stand behind, because HIPAA compliance is a determination about an organization and its agreements, not a badge on a website. A vendor who will not name the gate is a vendor who has not thought about it.

What we build

Built to the Security Rule.

Mechanisms that are shipped and running, plus a plainly stated line about where a standard build stops.

Access control that holds up

Mandatory TOTP multi-factor authentication enforced at the middleware layer, and a 5-tier role-based access model with 13 permission keys where an account can never grant a permission it does not itself hold. Shipped and running in the multi-tenant portal work we do, not a diagram.

Audit logs you cannot quietly edit

Append-only audit logging where UPDATE and DELETE are blocked at the database even for the service role, plus threat detection for brute-force attempts and privilege escalation. An audit trail that can be rewritten is not an audit trail.

Session and tenant isolation by default

30-minute idle logout, durable per-IP and per-account login lockouts, row-level security on every tenant table, encryption in transit, and sanitize-on-write so nothing untrusted lands in storage in the first place.

Built to WCAG 2.1 AA, the standard the rules name

Skip links, real ARIA patterns, focus traps, heading order enforced at the data layer, and reduced-motion honored throughout. We routinely score 100 on Lighthouse accessibility across whole sites, and we publish a WCAG 2.1 AA accessibility statement you can stand behind rather than a badge you cannot.

Standard on every build

Included, with no line item.

These are not upgrades. They are what leaving the studio looks like.

  • You own the code
  • Loads fast on a phone
  • WCAG 2.1 AA with a public statement
  • Handoff docs so your team ships without us

Before you ask

What healthcare buyers ask first.

Are you a HIPAA compliant web design agency?
No vendor should answer that question with a bare yes, ours included. HIPAA compliance is a legal determination about an organization and the agreements it has signed, not a property a website can have. Here is the concrete version: we build the technical safeguards the HIPAA Security Rule calls for, including mandatory MFA, role-based access control, append-only audit logging, row-level security, idle logout, and account lockouts. And here is the gate, stated plainly: a HIPAA engagement requires a signed Business Associate Agreement and HIPAA-eligible hosting, and that is scoped per project before any protected health information is involved. We build the mechanisms; your counsel and compliance officer sign off on the policy.
Can our website take appointment requests or patient intake?
It depends on what the form collects, and that is a scoping conversation we have before anything is built. A marketing site with a general contact form that deliberately does not collect clinical detail is a standard build. An intake flow that handles protected health information is a different engagement: it needs a signed Business Associate Agreement and HIPAA-eligible hosting in place first. We would rather narrow the form than pretend a standard build can carry PHI.
Does healthcare have an accessibility deadline of its own?
Yes, and it is close. HHS extended the Section 504 web and mobile accessibility deadline for federally funded healthcare recipients with 15 or more employees to May 11, 2027, and the DOJ's ADA Title II deadline for public entities serving 50,000 or more people moved to April 26, 2027. Both rules name WCAG 2.1 Level AA specifically, not WCAG 2.2 and not WCAG 3.0. That is the standard we build to, and we ship a public accessibility statement with every site.
What about analytics and ad pixels on patient-facing pages?
They stay off until a visitor opts in, and we mean that literally: our consent components return null before consent, so the script tag is never rendered and no request goes out. Global Privacy Control is honored as a binding opt-out. This matters more in healthcare than anywhere else, because roughly 1,500 CIPA lawsuits were filed in the 18 months to August 2025, and the question courts are now asking is simply whether tracking fired before the user acted on the banner.
Do you have a healthcare case study we can look at?
Not a published one. The health platform in our portfolio is a pre-sales build and stays unnamed until that client decides otherwise, so we are not going to dress it up as a reference. What we can show you is the shipped evidence behind every claim on this page: Lighthouse 100 on accessibility, best-practices, and SEO on Salyers Construction; a lead flow validated on both the browser and the server on America Premier; a security audit across a 492-URL site that returned 43 findings with 0 critical and 0 high; and row-level security, MFA, and append-only audit logging running in production portal work. Judge us on those.

Tell us what your site actually needs to do: schedule, intake, answer questions, or just make the case. We will scope it honestly, name anything that needs a Business Associate Agreement before we write a line of code, and reply within one business day.

Tell us what the site needs to do.

Six questions, no call required. You get a written scope, a fixed price, and a timeline from the person who will build it.

Start the briefOr compare the six industries