MIDSOUTH
CENTRAL FLORIDA
Regulations are popping up at every turn. What does all this mean to you and your practice? Not only must you comply with the Health Insurance Portability and Accountability Act (HIPAA) there are other regulatory agencies peaking over your shoulder.
If you accept credit cards, you are required to be compliant with the PCI (Payment Card Industry) Data Security Standard. You can find out your exact compliance requirements only from your payment brand or acquirer. However, before you take action, you may want to obtain background information and a general understanding of what you will need to do from the information and links here.
Doctor’s offices are full of incredibly sensitive data. People trust you to keep their medical and personal information secure. Part of your job is to realize that there are unscrupulous people out there ready to steal information to make fraudulent insurance claims, create duplicate passports and other ID’s as well as stealing credit card data. Doing your due diligence and creating a safe environment for credit transactions goes hand in hand with your other safety measures.
Major considerations in safe guard your practice are encrypted equipment, trained personnel, written policies and secure storage.
There are many firms who offer PCI insurance as well as system checks on equipment. Be wary of purchasing something without doing due diligence. There have been instances of these “protection” firms being skimmers for data. As always an ounce of protection is worth a pound of cure. PCI website and the BBB are good sources for reputable firms and products: Trustwave is the largest and most well-known.
Another step in the defensive battle is to become PCI Certified. You do this by taking a Self-Assessment Questionnaire (SAQ). There are 4 different options based on the equipment and type of transactions you process. If you would like to have a security professional’s guidance to achieve compliance and complete the SAQ, you are encouraged to do so. Please recognize that, while you are free to use any security professional of your choosing, only those included on PCI SSC’s list of Qualified Security Assessors (QSAs) are recognized as QSAs and are trained by PCI SSC. This list is available at https://www.pcisecuritystandards.org.
The PCI Security Standards Council (SSC) provides a variety of educational resources to further security awareness within the payment card industry. These resources include PCI DSS training for Internal Security Assessors (ISAs) and Standards Training. The PCI SSC website is also a primary source for additional resources, including:
Please refer to www.pcisecuritystandards.org for more information.
There are a variety of fines and policies specified by each of the major card companies. To learn what your specific compliance requirements are, check with your card brand compliance program:
For more business centric information about PCI Regulations, you can download the Getting Started Guide and/or the Quick Reference Guide from
https://www.pcisecuritystandards.org/merchants/how_to_be_compliant.php
Check with your Credit Card professional soon to make sure you are operating a safe processing environment. A Breach means more than fines and time consuming fixes. It means a loss of confidence by your patients.
Safe practices are healthy practices!
Article Published in Medical News December 2011
Written by Bobbi Govanus, Retriever Payment Systems
Bobbi@localCCprocessing.com
The post Does Your Practice Need a Check Up? first appeared on Retriever, Advantage Merchant Services.
MID-SOUTH OFFICE
FLORIDA OFFICE