By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: PCI Report on Compliance
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Uncategorized > PCI Report on Compliance
Uncategorized

PCI Report on Compliance

onlinetech
onlinetech
Share
3 Min Read
SHARE

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

More Read

health insurance employer
5 Ways for Healthcare Companies to Provide Employee Insurance
4 Tips For Looking Your Best on a Tight Budget This Fall
Cloud Computing in Healthcare
NCQA ACO Accreditation Overview
Cloud Computing in 2012: Ready for Enterprise?

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

  • Entity’s payment card business description
  • High level network diagram

Description of Scope of Work and Approach Taken

  • How the assessment was made
  • Environment
  • Network segmentation used
  • Details for each sample set tested
  • Any international entities requiring compliance with PCI DSS
  • Wireless networks or applications
  • Version of PCI DSS used to conduct assessment (2.0 is the latest)

Details About Reviewed Environment

  • Network diagrams
  • Cardholder data environment
  • List of hardware and software in the cardholder data environment (CDE)
  • Service providers
  • Third-party applications
  • Individuals interviewed
  • Documentation reviewed
  • Reviews of managed service providers

Contact Information and Reporting Date

Quarterly Scan Results

  • Including the four most recent ASV (approved scanning vendor) scan results

Findings and Observations

  • Requirements and sub-requirements
  • Explain N/A responses
  • Validation of all compensating controls

When it comes to documenting details about your reviewed environment, any of your managed service providers/PCI hosting providers should be able to produce their own attestation of compliance report to inform your company about their controls and security. This can save you the time it takes to review and report on their compliance as it affects your company and cardholder data.

References:
PCI DSS Quick Reference Guide (Version 2.0) (PDF)

TAGGED:compliance
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

Beautiful woman manager communicates with the client in the work
Can We Lower Healthcare Costs Outsourcing to the Philippines?
Health
January 24, 2026
cooling vests healthy workplace
How Cooling Vests Improve Health and Workplace Safety
Health Policy & Law
January 22, 2026
talk therapy
When Emotional Healing Requires Physical Awareness
Addiction Recovery Health
January 21, 2026
Career Mobility in the Modern Nursing
The Growing Importance of Career Mobility in the Modern Nursing Workforce
Career Nursing
January 18, 2026

You Might also Like

Linking ICD-10 and the Future of HCIT

February 28, 2012

Cloud Computing for Healthcare; Compliance, Disaster Recovery & Business Sustainability

September 7, 2011
clinical trial
Uncategorized

Clinical Trials and the Time it Takes to Complete Them

August 31, 2022

New Health IT Events Calendar

October 6, 2011
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Go to mobile version
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?