Industry guide

PCI DSS certification for healthcare

Healthcare takes card payments everywhere — front desks, pharmacies, cafeterias, online bill-pay — usually on networks nobody segmented. Certification here is won in Phase 1 (scoping): collapse the sprawl before the QSA arrives.

Scope the sprawl first

Every registration desk with a card terminal is in the cardholder data environment unless segmented. The standard healthcare play: P2PE terminals plus network segmentation, collapsing dozens of locations into a manageable scope. Do this before the gap assessment, not during fieldwork.

Portals and phone payments

Online bill-pay and IVR phone-payment systems are where healthcare card data concentrates. Hosted or redirected payment pages keep the portal out of scope; homegrown payment code puts it squarely in. Scope these carefully in Phase 1 — they're where breaches happen.

HIPAA is not PCI certification

The programs overlap (encryption, access control, logging) but neither satisfies the other: a HIPAA risk analysis doesn't produce a PCI ROC, and a PCI QSA isn't auditing HIPAA. Run them as parallel tracks with shared evidence where controls genuinely coincide.

Collect your vendors' AoCs

Your payment processor's and portal vendor's PCI compliance is your problem to verify — collect their Attestations of Compliance annually. Their lapsed attestation becomes your finding in Phase 4.

Questions

We're HIPAA compliant — are we PCI certified?

No. Different standard, different validator, different attestation. Some controls overlap, but the PCI validation is separate.

Do small practices need a QSA?

Rarely for validation — most are Level 4 merchants filing a SAQ. But P2PE terminals and a segmented network still make the SAQ honest and short.

Get quotes from QSAs that know your industry

Tell us your environment once — we’ll match QSA companies with experience in it. Free, two minutes.

Get a free quote

← All QSA companies  ·  Cost guide