We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: PCI Report on Compliance
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Uncategorized > PCI Report on Compliance
Uncategorized

PCI Report on Compliance

onlinetech
onlinetech
Share
3 Min Read
SHARE

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

More Read

Interview Podcast: ICD-10 Best Practices with Connie Tohara Vol. 1
Server Hack Leads to HIPAA Violation by Utah Department of Health
2011 SMBs & Disaster Recovery in the Cloud
Lack of Care Coordination Leads to Patient Frustration and Poor Care
Filtering versus Overload : Information and Content in The Digital Age

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

  • Entity’s payment card business description
  • High level network diagram

Description of Scope of Work and Approach Taken

  • How the assessment was made
  • Environment
  • Network segmentation used
  • Details for each sample set tested
  • Any international entities requiring compliance with PCI DSS
  • Wireless networks or applications
  • Version of PCI DSS used to conduct assessment (2.0 is the latest)

Details About Reviewed Environment

  • Network diagrams
  • Cardholder data environment
  • List of hardware and software in the cardholder data environment (CDE)
  • Service providers
  • Third-party applications
  • Individuals interviewed
  • Documentation reviewed
  • Reviews of managed service providers

Contact Information and Reporting Date

Quarterly Scan Results

  • Including the four most recent ASV (approved scanning vendor) scan results

Findings and Observations

  • Requirements and sub-requirements
  • Explain N/A responses
  • Validation of all compensating controls

When it comes to documenting details about your reviewed environment, any of your managed service providers/PCI hosting providers should be able to produce their own attestation of compliance report to inform your company about their controls and security. This can save you the time it takes to review and report on their compliance as it affects your company and cardholder data.

References:
PCI DSS Quick Reference Guide (Version 2.0) (PDF)

TAGGED:compliance
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

How to Choose an On-Demand Medical Interpreting Provider for Your Hospital -- AI-generated illustration
How to Choose an On-Demand Medical Interpreting Provider for Your Hospital
Health care
August 12, 2026
The Chemistry Of Drug Consistency -- AI-generated illustration
The Chemistry Of Drug Consistency
Policy & Law
August 12, 2026
Dental Materials Through The Decades -- AI-generated illustration
Dental Materials Through The Decades
Dental health Infographics Specialties
August 12, 2026
DNP or PhD: What Each Actually Means for Your Nursing Career -- AI-generated illustration
DNP or PhD: What Each Actually Means for Your Nursing Career
Career Nursing
August 12, 2026

You Might also Like

Healthcare Franchise
Health care

Choosing The Right Healthcare Franchise For Your Family

April 14, 2023
Medical device classification and development strategies
Uncategorized

The role of digital therapy in changing the future of healthcare

April 30, 2022
How a Small Incident Turns into a Major Disaster - An IT Disaster Recovery Webinar
Uncategorized

Upcoming Cloud Computing and Disaster Recovery Events

September 20, 2011

Shahid Shah Speaking at NIH Clinical Center on Why Meaningful Use (MU) and EHRs are Insufficient for Evidence Based Medicine (EBM) and Comparative Effectiveness Research (CER)

February 8, 2012
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?