Patients pay copays, deductibles, and treatment balances by card every day. Each transaction puts card data in your care, even if only for a moment. Good card payment security protects patients, keeps your merchant account in good standing, and reduces the chance of fraud.
How PCI DSS applies to your practice
The Payment Card Industry Data Security Standard, known as PCI DSS, applies to any business that accepts, processes, stores, or transmits card data. That includes dental practices of every size.
In practice, most offices confirm compliance each year through a self-assessment questionnaire from their processor. The right questionnaire depends on how you take payments. So ask your processor which one applies and what it requires.
Also note that PCI DSS is separate from HIPAA. A practice needs to meet both, and one does not satisfy the other.
Choose safer payment equipment
The terminal you use shapes your risk and your paperwork. It is also the easiest place to improve.
Modern terminals that read chip cards and tap payments are safer than swiping alone. In addition, many processors offer point-to-point encryption.
With point-to-point encryption, card data is encrypted inside the terminal. As a result, your computers and network never see the full card number. That can reduce the scope of your PCI DSS requirements, depending on the solution.
Integrated payments that connect to practice management software are convenient. However, confirm how the integration handles card data before you adopt it.
Keep payment systems separate
Card terminals should sit on their own network segment, away from workstations, guest Wi-Fi, and imaging systems. That way, a problem elsewhere does not reach payment traffic.
Also, protect the front desk computers that staff use for billing. For example, keep them patched, run endpoint protection, and limit web browsing to business needs.
Phone payments and cards on file
Many patients pay balances over the phone. That is convenient, but it creates risk.
For that reason, staff should enter card numbers directly into the terminal or a secure payment page, never on paper.
Cards on file also help with treatment plans and recurring payments. Instead of storing card numbers yourself, use your processor’s tokenization feature. The processor keeps the card data, and you keep only a reference token.
Finally, never store the security code on the back of the card. PCI DSS prohibits storing it after a transaction is authorized.
Card payment security checklist
Use this checklist to review your front desk practices.
- Terminals support chip and tap payments.
- Point-to-point encryption is in place if your processor offers it.
- Payment terminals sit on a separate network segment.
- No card numbers are written on paper, sticky notes, or intake forms.
- No card numbers appear in email, texts, or practice management notes.
- Cards on file use processor tokenization.
- Staff inspect terminals for tampering on a regular schedule.
- Each staff member uses an individual login for payment systems.
- The annual self-assessment questionnaire is complete and on file.
Train the front desk
People handle every transaction, so habits matter as much as equipment. Good card payment security starts with a few simple routines.
First, teach staff to keep cards in the patient’s hands whenever possible. Next, show them what a tampered terminal might look like, such as loose parts or unfamiliar attachments.
Also, keep receipts and reports free of full card numbers. Most modern terminals mask them automatically, but check older devices and any reports your practice management software prints.
Scammers sometimes call pretending to be from the processor. They may ask staff to run a test transaction or install software. Therefore, staff should verify any such request by calling the processor at a known number.
Respond quickly to problems
If you suspect card data was exposed, contact your processor right away. Then they will explain the next steps and any investigation requirements. In addition, involve your IT partner to find and close the gap.
Because payment systems may connect to patient data, also review whether any HIPAA duties apply. Your counsel can help sort out the obligations. Afterward, update your procedures so the same gap does not reopen.
How WEBIT helps
WEBIT helps practices segment payment systems, secure front desk workstations, and prepare for the annual self-assessment. Every managed device gets Security Essentials, including Zero Trust EDR, application allowlisting, and DNS filtering.
We also run monthly or quarterly health assessments and review findings with you. See our managed IT services or visit our dental practices page.
Key takeaways
- PCI DSS applies to every practice that accepts cards, separate from HIPAA.
- Point-to-point encryption and tokenization reduce the card data you handle.
- Keep terminals on their own network segment.
- Never write down card numbers or store security codes.
- Train staff to spot tampering and verify processor calls.