How to Read a VPAT for Patient-Facing Software
Trust note
This article was written by a person and reviewed against accessibility.chat editorial standards. Treat it as research and education rather than legal advice. We prioritize primary sources and correct material errors.

Filed unread, it's worse than nothing. Here's what to actually check before you rely on it.
A vendor is going to hand you an Accessibility Conformance Report (opens in new window) this quarter — probably for the portal, the EHR, or the telehealth platform — and probably with a note that says something like "see attached, we're compliant." Filing it unread as proof you did your diligence is worse than having nothing on file: it looks like you checked, and you didn't.
Here's how to actually read one. It takes about twenty minutes once you've done it a few times.
Nobody can "certify" this
Accessibility isn't a state a product achieves once and keeps forever — it's a maintained practice, and any given screen can regress the day after someone checks it. A vendor claiming their portal is "fully certified compliant" has either misunderstood their own report or is hoping you won't ask what that word is doing in the sentence.
The eight-point test, before you read the content
Age. Dated within the last twelve months, or newer than the product's last major release? An older report isn't describing what you're about to rely on.
Product identity. Exact product, version, and which interfaces are covered — specifically, are the patient-facing modules named, or just "the platform" generally?
Author. A named author or firm with stated accessibility qualifications, or anonymous, or written by sales?
Standard. Evaluated against a current version of WCAG (opens in new window), Levels A and AA, criterion by criterion — not an obsolete version, not A-level only.
Method. Automated and manual testing both described, with actual tools and assistive technology named — not just "evaluated internally."
Scope. States plainly what was and wasn't tested. Silent scope means assume the gaps are hiding in the untested parts.
Terms. Standard conformance vocabulary, not an invented rating like "mostly compliant" that means nothing and can't be pinned down.
Ratings explained. Every non-"Supports" rating carries an actual remark. A bare "Partially Supports" with an empty remarks column tells you nothing.
A report failing three or more of these points isn't evidence of anything. Send it back before spending another minute on it.
Then, and only then, read the content — and judge materiality
Read every row below full support, and every remark under "Supports" too — vendors sometimes bury a real caveat in a row that technically passed. Quote what you find rather than paraphrasing it. Then judge materiality: which gaps actually touch what patients do with this product? A missing alt-text attribute on a decorative image is not the same finding as a patient portal message thread that can't be operated by keyboard.
The discipline that keeps you out of trouble
Everything you record is a claim about the document, never a claim about the product. "The ACR is dated 2021 and names no assistive technology tested" is a defensible fact. "This portal is inaccessible" is an assertion about someone's business, and it's not one you're positioned to make from a document review alone.
This isn't legal advice about whether a specific vendor's report satisfies your obligations — that's a judgment for you and your counsel on your specific facts. If you want a second pass on a page a vendor claims already conforms, ask Luke to check it before you take the report at its word.
Previous: procurement language that actually works · Next: building the record
Sources: Accessibility Conformance Report (ACR) overview (opens in new window) · ACR/VPAT Frequently Asked Questions (opens in new window) · WCAG 2 Standards Overview (opens in new window) · HHS Guidance on Section 1557 (opens in new window)
About Jeff Fryer
Jeff Fryer spent years working kitchens before moving into ADA compliance work for local government. He writes from that experience -- direct, plainspoken, allergic to compliance theater. Contributing writer at accessibility.chat.
Jeff Fryer is a person, not one of the AI analyst lenses this site also publishes under. A named human is accountable for this article.
Specialization: Local government ADA compliance, contributed from direct field experience
Authorship and Editorial Process
Jeff Fryer wrote this article. AI was not used to draft it. It went through the same editorial checks as everything else published here.