PCI DSS for Healthcare Kit
Healthcare takes card payments too — and PCI is assessed separately from HIPAA by people who do not care that you have a Security Rule programme. One control set for both, the SAQ decision that vendors keep getting wrong, and the dual clock when an incident touches PHI and cardholder data at once.
What this actually gives you
- 2026 is the first assessment year with no grace argument — PCI DSS v4.0.1 is the only active version and all 51 future-dated requirements have been mandatory since 31 March 2025.
- A patient portal that embeds the gateway’s JavaScript is SAQ A-EP, whatever the vendor deck said. 6.4.3 and 11.6.1 were pulled from SAQ A in January 2025 and replaced with an eligibility criterion.
- Roughly 70% of PCI’s controls are already the HIPAA Security Rule’s — and the HIPAA proposed rule moves toward PCI, not away.
- Your billing company is both a service provider and a business associate. So is the gateway, the EHR payment module and the IVR vendor — collect the AOC, the BAA and the annual verification together.
- When an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences — computed here from a single discovery time.
2026 is the first assessment year with no grace argument. PCI DSS v4.0.1 is the only active version, and all 51 future-dated requirements have been mandatory since 31 March 2025. The transition talk is over; this is the year the assessment is against the full standard.
The SAQ your gateway vendor told you about is probably wrong. In January 2025 the two requirements that fail most — 6.4.3 payment-page script inventory and authorisation, and 11.6.1 weekly tamper detection — were removed from SAQ A and replaced with an eligibility criterion. They apply in full to SAQ A-EP and SAQ D. A patient portal that embeds the gateway's JavaScript is SAQ A-EP, whatever the vendor deck said, and file 03 walks the eligibility criterion honestly rather than assuming the answer you would prefer.
Roughly 70% of PCI's controls are already the HIPAA Security Rule's. Access control, encryption, logging, vulnerability management, secure configuration — you are largely doing the work twice, in two spreadsheets, for two audiences. File 02 crosswalks them so one control set answers both. And the HIPAA proposed rule moves toward PCI, not away: required MFA, encryption, an asset inventory with a network map, 15- and 30-day patching, scans and business-associate verification are all things PCI already asks for.
Your billing company is both a service provider and a business associate. So is your gateway, your EHR's payment module and your IVR vendor. They owe you an AOC under PCI and a BAA under HIPAA, and from the proposed rule an annual verification too. File 04 collects all three in one register, because chasing them separately is how one of them goes missing.
What you get
01 Payment Channel & Scope Mapper (XLSX) — every way a card enters your organisation (portal, IVR, front desk, mail order, lockbox, kiosk, mobile) with the systems and people it touches, resolving to your cardholder data environment and merchant level.
02 PCI-HIPAA Control Crosswalk (XLSX) — the shared control set, with what PCI asks that HIPAA does not and the reverse, so you build once and evidence twice.
03 E-Commerce Requirements & SAQ A Eligibility (XLSX, 3 tabs) — the eligibility criterion worked through properly, plus 6.4.3 and 11.6.1 in full for anyone who lands on A-EP or D.
04 Service Provider & BA Register (XLSX) — AOC, BAA and annual verification tracked together, per vendor, with expiry.
05 Scope-Reduction Plan (DOCX) — the cheapest PCI programme is a small one: what to move off the cardholder data environment, in what order, and what each move actually removes from assessment.
06 Dual-Clock Incident Sheet (XLSX) — when an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences. Computed from a single discovery time.
07 CFO One-Pager (PPTX) — the exposure, the plan and the decision, for the person who signs the assessment budget.
08 Practitioner Guide (PDF) — the standard, the channels, SAQ selection, the crosswalk, scope reduction, service providers, incidents, ninety days, failure patterns and an FAQ.
pci01.json — channels, crosswalk rows and SAQ logic.
Healthcare-specific, on purpose. If you need general PCI coverage across twelve requirement domains with a QSA-ready evidence register, that is the PCI DSS v4.0.1 Readiness Accelerator — a bigger, broader workbook for any merchant. This one assumes patient portals, billing companies, EHR payment modules and a HIPAA programme you already run, and it is priced as the narrower kit it is.
The third leg of the healthcare set: the HIPAA Readiness Accelerator is the whole HIPAA programme, the HIPAA Security Rule 2027 Readiness Kit is the rule change coming, and this is the payment side neither covers.
Pairs with I've Been Breached for the incident, the Vendor Risk Operations Kit and TPRM Program Kit for the provider programme, the MSP & MSSP Assessment Kit if a billing company or MSP holds the environment, and the Cyber Insurance Application Readiness Kit for the underwriter's questions.
SAQ selection and merchant levels are ultimately your acquirer's and the card brands' call, and the files say so — have a QSA confirm the eligibility logic before you rely on it. A practitioner's toolset, not legal advice.
Also available in 2 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Healthcare Provider Risk
The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.
Healthcare Now & Next
The whole HIPAA programme, the Security Rule change coming in 2027, and the payment side neither covers. Three products across the compliance a healthcare organisation is actually assessed on. 19% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee