1,420
Avg Audit Hours
annually
1,260
Median Hours
50th percentile
61/100
Maturity Score
Developing
44d
Avg Remediation
per finding
41%
Automation Rate
evidence automated
Audit Hours Percentile Distribution
Distribution range (hours)
0 hrs2,600 hrs
Common Remediation Bottlenecks
HIPAA + PCI dual-framework evidence76%
Legacy medical payment terminal scope68%
Third-party billing system validation59%
Patient payment portal security testing47%
Common SAQ Types in Healthcare
SAQ-D (Merchant)
28% of orgs
Frequently Asked Questions
How do HIPAA and PCI DSS interact for healthcare organisations?
HIPAA and PCI DSS have overlapping but distinct requirements. Both mandate access controls, audit logging, encryption, and incident response, but with different scopes — HIPAA covers protected health information while PCI covers cardholder data. Healthcare organisations must satisfy both frameworks, and 76% report that producing non-duplicative evidence for dual-framework audits is their primary compliance bottleneck.
Do hospital payment systems require PCI compliance?
Yes. Any healthcare organisation that accepts card payments — co-pays, medical billing, cafeteria, gift shops — must comply with PCI DSS. The applicable SAQ level depends on transaction volume and how card data is handled. Large health systems processing significant card volumes typically require Level 1 ROC assessments.
What are legacy medical payment terminal challenges for PCI?
Many healthcare facilities operate payment terminals procured years or decades ago that may no longer be listed on the PCI SSC's approved device lists. Replacing these terminals in clinical environments requires coordination with biomedical engineering, facilities, and IT teams, and is often subject to capital budgeting cycles — extending remediation timelines significantly.
How does patient payment portal security testing work for PCI?
Patient payment portals that accept card payments must undergo annual penetration testing and quarterly ASV vulnerability scanning per PCI DSS. Healthcare organisations face additional complexity because portal integrations often connect to EHR systems, creating broad application scope. Web application firewall deployment and script integrity monitoring (PCI DSS v4.0 Req 6.4.3) are commonly required findings.
How Does Your Healthcare Programme Compare?
Run the benchmark to get your personalised maturity score and see exactly where you stand versus these healthcare industry benchmarks.
Run Free Benchmark →Based on n=421 healthcare organisations. Updated weekly.