Industry guide

PCI DSS for healthcare

Healthcare takes card payments everywhere — front desks, pharmacies, cafeterias, online bill-pay — usually on networks nobody segmented. Add HIPAA in the mix and you get two compliance programs that overlap but don’t substitute for each other.

The front-desk sprawl

Every registration desk with a card terminal is in scope unless segmented. Healthcare’s first PCI win is almost always the same: P2PE terminals plus network segmentation, collapsing dozens of locations into a manageable scope.

HIPAA ≠ PCI DSS

They overlap (encryption, access control, logging) but neither satisfies the other. A HIPAA risk analysis doesn’t produce a PCI ROC, and a PCI QSA isn’t auditing HIPAA. Plan them as parallel tracks with shared evidence where the controls genuinely coincide — and consider a QSA company that also does HIPAA assessments (several in our directory do).

Patient portals and IVR payments

Online bill-pay and phone-payment (IVR) systems are where healthcare card data actually concentrates — and where breaches happen. Scope them carefully: hosted/redirected payment pages keep the portal out of the cardholder data environment; homegrown payment code puts it squarely in.

Business associates and service providers

Your payment processor’s and portal vendor’s PCI compliance is your problem to verify — collect their AoCs annually. Their lapsed attestation becomes your finding.

Questions

We’re HIPAA compliant — are we PCI compliant?

No. Different standard, different validator, different attestation. Some controls overlap, but you need the PCI validation separately.

Do small practices need a QSA?

Rarely — most practices are Level 4 merchants validating with a SAQ. But P2PE terminals and a segmented network are still the right moves; they make the SAQ honest and short.

Get quotes from QSAs that know your industry

Tell us your environment once — we’ll match QSA companies with experience in it. Free, two minutes.

Get a free quote

← All QSA companies  ·  Cost guide