Hosting Impact of PCI Compliance

PCI security standards apply to Hosting Providers and Merchants that accept payments

SAQ Levels

The PCI security standards have created three levels of security and compliance for merchants that use eCommerce applications (card not present). These three levels correspond to the following self-assessment questionnaires (SAQ):

  • SAQ D 
    Integration Difficulty Level: HIGH
    Compliance Difficulty Level: HIGH
    Build your own user interface and use web services without Client Side Encryption to leverage InstaMed’s payment solutions.

Read more about distinctions and impacts of SAQ levels.

SAQ A Requirements

  1. Do not use vendor-supplied defaults for system passwords and other security parameters
  2. Identify and authenticate access to system components
  3. Restrict physical access to cardholder data

Full details of SAQ A

SAQ D Requirements

  1. Install and maintain a firewall configuration to protect data
  2. Do not use vendor-supplied defaults for system passwords and other security parameters
  3. Protect stored cardholder
  4. Encrypt transmission of cardholder data across open, public networks
  5. Protect all systems against malware and regularly update anti-virus software or programs
  6. Develop and maintain secure systems and applications
  7. Restrict access to cardholder data by business need to know
  8. Identify and authenticate access to system components
  9. Restrict physical access to cardholder data
  10. Track and monitor all access to network resources and cardholder data
  11. Regularly test security systems and processes
  12. Maintain a policy that addresses information security for all personnel

Full details of SAQ D

Build a better healthcare payments experience with InstaMed

Talk With an InstaMed Expert