We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: PCI Report on Compliance
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Uncategorized > PCI Report on Compliance
Uncategorized

PCI Report on Compliance

onlinetech
onlinetech
Share
3 Min Read
SHARE

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

More Read

How to make sure your favorite health food is as healthy as it sounds [Infographic]
Controlling vs. collaborative IT leadership and what it means to your healthcare organization
NIST Recommendations for Security in the Outsourced Cloud
Mass Digitization Threatens the IT Industry
HIPAA Hosting Q&A with a Certified HIPAA Practitioner & Security Specialist

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

  • Entity’s payment card business description
  • High level network diagram

Description of Scope of Work and Approach Taken

  • How the assessment was made
  • Environment
  • Network segmentation used
  • Details for each sample set tested
  • Any international entities requiring compliance with PCI DSS
  • Wireless networks or applications
  • Version of PCI DSS used to conduct assessment (2.0 is the latest)

Details About Reviewed Environment

  • Network diagrams
  • Cardholder data environment
  • List of hardware and software in the cardholder data environment (CDE)
  • Service providers
  • Third-party applications
  • Individuals interviewed
  • Documentation reviewed
  • Reviews of managed service providers

Contact Information and Reporting Date

Quarterly Scan Results

  • Including the four most recent ASV (approved scanning vendor) scan results

Findings and Observations

  • Requirements and sub-requirements
  • Explain N/A responses
  • Validation of all compensating controls

When it comes to documenting details about your reviewed environment, any of your managed service providers/PCI hosting providers should be able to produce their own attestation of compliance report to inform your company about their controls and security. This can save you the time it takes to review and report on their compliance as it affects your company and cardholder data.

References:
PCI DSS Quick Reference Guide (Version 2.0) (PDF)

TAGGED:compliance
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

Before Sterilization Begins: Why Bioburden Testing Matters -- AI-generated illustration
Before Sterilization Begins: Why Bioburden Testing Matters
Health Infographics
September 11, 2026
Hidden Cybersecurity Roadblocks That Can Complicate FDA Submissions -- AI-generated illustration
Hidden Cybersecurity Roadblocks That Can Complicate FDA Submissions
Infographics Policy & Law Technology
September 11, 2026
Smaller, Lighter, Smarter: How Inflation Is Changing Wellness Packaging -- AI-generated illustration
Smaller, Lighter, Smarter: How Inflation Is Changing Wellness Packaging
Infographics Wellness
September 11, 2026
How Roof Deterioration Affects Indoor Air Quality and the Health of Building Occupants -- AI-generated illustration
How Roof Deterioration Affects Indoor Air Quality and the Health of Building Occupants
Health
September 10, 2026

You Might also Like

Expected Benefits of Cloud Apps for SMBs
Uncategorized

Rethinking the Outsourced Cloud, Part III: Expected Benefits of Cloud Applications

September 29, 2011
Uncategorized

Make America and the Medical Profession Great Again

October 4, 2015
dental x-rays
Dental healthSpecialtiesUncategorized

Everything You Need To Know About Dental X-Rays And 3D Imaging

July 1, 2021
Private vs Public Cloud Security
Uncategorized

Benefits of Private Cloud Computing: Compliant & Cost-Effective

September 16, 2011
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?