US Medical Billing
Patient Billing & Collections

Online Patient Payments

Ask what a patient payment page is and the answer comes back operational: a place a balance gets paid, judged by whether the money arrives and the vendor is compliant. Both true, and neither is the legal description. The page is a patient communication that has been given a payment function, and almost everything practices get wrong about it follows from measuring the transaction instead of the communication.

Updated 14 min read

On this page

Key takeaways

Three identities, and none of them is a checkout

A communication about the cost and payment of care
The nondiscrimination rule enumerates the communications that must carry a notice of availability of language assistance and auxiliary aids, and the list expressly names communications related to the cost and payment of care, including medical billing and collections materials. A separate provision catches communications that request a response, which a payment page plainly does. So the page is a notice-bearing document that accepts money, rather than a payment device that happens to display text.
Information and communication technology
The regulation's definition of that term lists websites, software, mobile applications and electronic documents by name — and separately lists accessible technology among the auxiliary aids a covered entity is obliged to provide. Both halves matter: the page is subject to an accessibility duty, and it is also one of the accommodations that duty is discharged with.
A restriction-triggering event
Where a patient — or someone other than the plan, on the patient's behalf — pays in full for an item or service, the covered entity must agree on request to restrict disclosure of the related information to the health plan, and cannot later terminate that restriction on its own. A payment page is where that fact most often occurs, and usually with nobody watching for it.

One scope caution before any of this applies

The word that repeats, and the fallback that fails it

Read the three relevant duties next to each other and the same requirement appears in each, written by different drafters for different reasons. The web-accessibility rule's minimal-impact test asks whether a person can conduct the same transaction with substantially equivalent timeliness, privacy, independence, and ease of use. The auxiliary-aid duty requires that the aid protect privacy and the independence of the individual. The language-assistance duty requires protection of independent decision-making ability. Three regimes, one test: can the patient complete this alone.

Which makes the universal workaround the aggravating fact

Two adjacent rules are worth knowing because they are where a good-faith practice gets caught. Machine translation is not prohibited — it is conditionally permitted, and requires qualified human review where the text is critical to rights or benefits or meaningful access, where accuracy is essential, or where the language is complex or technical. A balance explanation and a payment agreement are all three. And the duty to make reasonable modifications to a policy has a written-procedure requirement attached: the process for handling a request, and for identifying an alternative that does not fundamentally alter the service, has to exist on paper rather than at the front desk.

And the relief valve is not self-executing

Outsourcing relocates the code and nothing else

Almost every practice's payment page is somebody else's software. That changes who writes it and changes nothing about who owes the duty. The accessibility obligation reaches content provided directly or through contractual, licensing, or other arrangements, and the exception for third-party content is expressly carved back where the third party posts under contract with the covered entity — which is the posture of every hosted portal there is.

The exemption neither party is holding

A one-time payment is a different legal object

The federal electronic-payment rules draw a line that maps cleanly onto the difference between this article and the one next to it. A preauthorized transfer is defined by recurrence at substantially regular intervals — which is what a stored authorization produces, and what carries the writing requirement card on file is built around. A one-time pay-the-balance never engages it.

  • A bank debit initiated on a web page is still an electronic fund transfer, because the definition reaches transfers initiated through a computer. Debit card transactions are covered whether or not an electronic terminal was involved.
  • A credit card transaction falls outside that regulation entirely — and by definition rather than by exclusion, because the regulation's idea of an account is a consumer asset account. Most payment pages take both, which means one page runs two legal regimes side by side and the rules for card disputes come from somewhere else.
  • Most of the regulation binds financial institutions, not the practice. A short enumerated list binds any person, and it is worth knowing which provisions are on it — the compulsory-use prohibition and the preauthorized-transfer requirements are; the error-resolution machinery is not.

Which produces a gap practices do not expect

On making a click count as a signature

Security, and the display that is not a security question

The security rule's technical safeguards are less prescriptive than most practices assume and more consequential than that suggests. Only two implementation specifications are required — a unique identifier for each user, and emergency access. Encryption appears twice and is addressable both times, which means assess it, then either implement it or document why it is not reasonable and implement an equivalent alternative. The rule names no technology, no cipher, no key length and no session behavior anywhere.

But the incentive for encryption sits in a different rule

One more distinction the page makes concrete. The minimum necessary standard does not apply to a disclosure to the individual, so a patient looking at their own balance is not a minimum-necessary question. It continues to govern the staff-facing view of the same data — and it governs the harder case the page creates, which is somebody other than the patient logging in to pay. The guarantor for minors and divorced parents covers who may be shown what, and a portal that grants a guarantor the patient's own view has answered that question without asking it.

What to actually check

  1. Establish your own coverage status, in writing, once

    It is the predicate for everything above, and it is not a question to answer from a vendor's marketing page. What the codified text names, and what sits only in a preamble, are different things.
  2. Read the current accessibility standard rather than a summary of it

    The technical standard is not in the nondiscrimination rule at all — it lives in the disability-rights rule and is reached by cross-reference, it is incorporated by reference at a pinned version, and its phase-in is keyed to organizational size. Those dates have already been amended once, which makes any secondhand statement of them unreliable by default.
  3. Test the page the way the rule tests it: alone

    Keyboard only. Screen reader. A language other than English. The question is not whether the payment can be completed with help — it is whether it can be completed independently, privately, and in comparable time.
  4. Write down the exception path

    The reasonable-modification duty carries an express requirement for a written process, including how an alternative that does not fundamentally alter the service is identified. “Call us” is not that document.
  5. Put the notice where the rule puts it

    Billing and collections materials are named carriers of the notice of availability, and there are separate website posting duties for that notice and for the nondiscrimination notice. Three obligations, easily satisfied, routinely missed on the one page that takes money.
  6. Capture the authorization the way you would want to read it later

    What was agreed, by whom, when, and shown in the same electronic form the record uses. On a one-time payment nothing federal requires a stored authorization — but the practice's evidence in a dispute is whatever it captured at that moment, and the dispute will be resolved somewhere it is not present.
  7. Watch for the pay-in-full event

    It is the one restriction a covered entity must agree to and cannot unilaterally end, and a payment page is where it happens. A portal that cannot flag it has quietly made a promise the practice does not know it made.

Common questions

Our portal is a vendor's product. Isn't accessibility their problem?

Not as a matter of who owes the duty. The obligation reaches content provided directly or through contractual, licensing or other arrangements, and the exception for third-party content is expressly carved back where the third party is posting under contract with the covered entity — which describes every hosted payment portal. Outsourcing moves where the code lives and nothing else. It is worth reading the vendor agreement for what it actually promises about conformance, because the practice carries the obligation whether or not the contract allocates the work.

If a patient cannot use the page, can they just call us to pay?

They can, and offering that is right — but it is not compliance and it should not be recorded as such. Three separate rules test the same thing: whether the patient can complete the transaction with substantially equivalent timeliness, privacy, independence and ease of use; whether an auxiliary aid protects privacy and independence; and whether language assistance protects independent decision-making. A phone call fails all three in the same way. It also lands the patient with staff, where a further rule bars relying on people who are not qualified to communicate in their language, bars charging the patient for an interpreter, and bars leaning on an accompanying adult except in narrow circumstances. The call is the fallback. The fix is the page.

Do we need a written authorization for a one-time payment?

Not for the reason people expect. The federal writing requirement attaches to a preauthorized transfer, and that term is defined by recurrence at substantially regular intervals — so a one-time pay-the-balance does not engage it. That is the clean line between this and a stored card. What remains is evidentiary rather than regulatory: if the charge is later disputed, the practice's only asset is what it captured at the moment of payment. And where a click is being relied on as a signature under some other law's writing requirement, the electronic-signature statute expects affirmative consent, a clear and conspicuous statement beforehand, and consent given through the same electronic form the records will use.

A patient disputed an online payment and the money came back. How do we fight it?

Understand first that you were probably not a party to it. For a debit from a bank account, the error-resolution process runs between the patient and their own financial institution — the provision that governs it is not among the handful that bind any person rather than only a financial institution, so the practice is neither in the loop nor notified. The first sign is usually an unexplained reversal in a deposit, already decided. Post it as a reversal rather than working it like a payer takeback, and treat the record of what the patient agreed to at the point of payment as the thing worth improving, because that is the only evidence that would have mattered.

Does our page have to be encrypted?

The technical safeguards rule makes encryption addressable rather than required — assess it, and either implement it or document why it is not reasonable and appropriate and implement an equivalent alternative. Only two specifications in that rule are strictly required, and the rule names no technology, cipher or key length at all. But the practical answer is different from the formal one, and it comes from the breach rule: the notification duty runs only to unsecured protected health information, meaning information not rendered unusable, unreadable or indecipherable by a specified technology or methodology. Encryption is what decides whether an incident is a notification event. Nominally optional, practically the whole question.

A parent logs in and can see everything on the patient's account. Is that a problem?

It can be, and the portal has usually answered the question without anyone asking it. The minimum necessary standard does not apply to a disclosure to the individual, so a patient viewing their own balance is not the issue. Somebody else viewing it is: the standard applies to that, and who may be treated as standing in the patient's shoes is decided by state law and by the privacy rule's personal-representative provisions, which are service-specific for a minor. A portal that grants a guarantor the patient's own view has made a disclosure decision in its access model rather than in a policy.

Authoritative sources

  • 45 CFR Part 92 — Nondiscrimination in health programs and activities (opens in a new tab)

    Where an entity is covered, its entire operations are the health program or activity. Information and communication technology is defined to include websites, software, mobile applications and electronic documents, and accessible technology is itself listed among the auxiliary aids a covered entity provides. Section 92.204(a) requires health programs and activities provided through such technology to be accessible unless doing so would cause undue financial and administrative burdens or a fundamental alteration, with a floor duty to ensure individuals with disabilities receive the benefits to the maximum extent possible; 92.204(b) is a cross-reference to the section 504 requirements rather than a technical standard. Section 92.205 requires reasonable modifications to policies, practices and procedures, and 92.8(f) requires a written process for handling such requests including identifying a non-altering alternative. Section 92.11 requires a notice of availability of language assistance and auxiliary aids on communications related to the cost and payment of care, including medical billing and collections materials, and separately on the entity's website. Section 92.201 protects independent decision-making ability, conditions the use of machine translation on qualified human review where accuracy is essential or the material is complex, and bars reliance on unqualified staff, charging the individual for an interpreter, and reliance on accompanying adults except in narrow circumstances. Section 92.202 requires auxiliary aids that protect the privacy and independence of the individual.

  • 45 CFR Part 84, Subpart I — Web and mobile accessibility under section 504 (opens in a new tab)

    This is where the technical standard actually lives, incorporated by reference at a pinned version and phased by organizational size — dates that have already been amended once, so the current text is the only reliable source for them. The duty reaches web content and mobile apps provided directly or through contractual, licensing or other arrangements. Its exceptions are cumulative-condition and narrow, and the exception for third-party content is expressly carved back where the third party posts under contract with the recipient. A conforming alternate version is a last resort. The undue-burden defense carries procedure: the burden of proof is on the recipient, the decision must be made by the head of the entity or a designee after considering all resources, and it must be recorded in a written statement of reasons. Partial non-conformance is excused only where the impact is minimal, measured against the ability to conduct the same transactions with substantially equivalent timeliness, privacy, independence and ease of use.

  • 12 CFR Part 1005 (Regulation E) and 15 U.S.C. § 7001 — Electronic payments and electronic records (opens in a new tab)

    An electronic fund transfer includes one initiated through a computer, and debit card transactions are covered whether or not an electronic terminal is involved; credit card transactions fall outside the regulation by definition, because its idea of an account is a consumer asset account. A preauthorized transfer is defined by recurrence at substantially regular intervals, so a one-time payment does not engage the writing requirement that governs a standing authorization. Most of the regulation binds financial institutions; a short enumerated list binds any person, and the error-resolution provisions are not on it — a disputed debit is resolved between the consumer and their own financial institution. The electronic-signature statute converts the form of a record and not its content or timing, applies only where another law imposes a writing requirement, and where it applies requires affirmative consent preceded by a clear and conspicuous statement and demonstrated through the same electronic form the records will use.

  • 45 CFR §§ 164.306, 164.312, 164.402 and 164.404, and 42 U.S.C. § 1320d-8 (opens in a new tab)

    Of the technical safeguards, only unique user identification and emergency access are required implementation specifications; encryption is addressable in both places it appears, which means assessing it and either implementing it or documenting why it is not reasonable and appropriate and implementing an equivalent alternative. The rule names no technology, cipher, key length or session behavior. The breach-notification duty runs only to unsecured protected health information — information not rendered unusable, unreadable or indecipherable through a specified technology or methodology — which is what gives encryption its practical weight; and discovery is constructive, with knowledge imputed from any workforce member other than the person who committed the breach. The statutory carve-out for payment processing is scoped to activities, and its operative branch addresses payment activities performed for a financial institution.

Ready to improve your revenue cycle?

Tell us about your practice and we’ll tell you where we would start.