The Payment Card Industry (PCI) Security Standards Council (SSC) is an industry forum for the ongoing management of security standards for account data protection. The PCI Data Security Standard (DSS) provides an actionable framework for developing a robust payment card security process – including prevention, detection and appropriate reaction to security incidents.
Organizations considered to be a Covered Entity include: health care providers, health plans, and health information clearinghouses that process health care information. A Covered Entity must be able to demonstrate HIPAA compliance. Further, third parties providing business services to Covered Entities must provide reasonable assurances that they will appropriately safeguard ePHI.
Build and Maintain a Secure Network
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
In addition to a wide range of complementary managed data center services, Expedient can assist with the PCI DSS compliance process by providing the following documentation offering written assurances:
Hosting with Expedient doesn’t exclusively make an organization compliant with PCI, however, it does reduce the time and expense associated with many of the requirements.
More information about PCI DSS is available from the SSC.