Payment Card Industry (PCI) Security Standards Council

Payment Card Industry (PCI) Security Standards Council

<p>March 11, 2014</p><p>Dear Centricity Customer,</p><p>We would like to make you aware of developments regarding all versions of the Centricity Patient Portal and its standard Quick Pay eForm.</p><p>Payment Card Industry (PCI) Security Standards Council</p><p>The PCI Security Standards Council is an open global forum, launched in 2006, that is responsible for the development, management, education, and awareness of the PCI Security Standards, including the Data Security Standard (PCI DSS)1. The PCI DSS defines workflow and technology recommendations that reduce the risk of payment card fraud for organizations that collect and store this information. It is recommended that organizations use products that are PCI certified to reduce this risk. </p><p>We have been informed that the Quick Pay eForm, which enables the collection and storage of payment information on the Centricity Patient Portal, is not a PCI certified product. GE Healthcare wants to make our clients aware of the situation and to provide them with instructions to ensure their adherence to PCI recommendations. GE Healthcare has not been made aware of any actual breaches related to the use of this form or any other custom e-form intended for payment information collection. </p><p>Recommended Actions for Organizations Who Do Not Use the Quick Pay eForm</p><p>For organizations that have not collected payment card information by using the Quick Pay eForm or any other custom e-form within the Centricity Patient Portal intended for payment information collection, we recommend that you do not begin collecting such information. </p><p>The PCI Security Standards Council does not enforce their security recommendations. If you are not part of a larger institution that performs annual PCI compliance assessments, it is recommended that you perform annual self-assessments. More information can be found at https://www.pcisecuritystandards.org/merchants/.</p><p>Recommended Actions for Organizations Who Do Use the Quick Pay eForm</p><p>For organizations that are using the Quick Pay eForm within the Centricity Patient Portal, please follow the steps below to align with PCI compliance recommendations:</p><p>1. Stop collection of payment card information </p><p>Disable the Quick Pay eForm, or any other custom e-form intended for the collection of payment card information, from displaying in the Centricity Patient Portal by following the steps below: </p><p>- Log into the Centricity Patient Portal as an Administrator and select the Admin link in the upper right hand corner</p><p>- Navigate to the Pages Tab, find the Quick Pay eForm and delete it by clicking the red X - Navigate to the Webboxes Tab to delete the Webboxes linked to the Quick Pay eForm</p><p>2. Remove collected payment card information</p><p>Delete all payment card information that resides in the Centricity Messaging Center by following the steps below:</p><p>- Log into your Centricity system and navigate to Centricity Clinical Messenger</p><p>- Locate the secure messages that contain payment card information and delete them. You can search for secure messages with the subject, “Quick Payment”. If you are not using system defaults, search for the secure message subject line associated with your Quick Pay eForm. </p><p>- Navigate to the “Deleted Items” folder and delete its contents</p><p>The PCI Security Standards Council does not enforce their security recommendations. If you are not part of a larger institution that performs annual PCI compliance assessments, it is recommended that you perform annual self-assessments. More information can be found at https://www.pcisecuritystandards.org/merchants/</p><p>Contact Information and Product Replacement</p><p>If you need assistance or have any questions, or if you would like to replace functionality provided by the Quick Pay eForm with another PCI compliant offering, please contact Centricity Support Services by calling 1-888-436-8491 or via email at [email protected]. 1 https://www.pcisecuritystandards.org/index.php </p>

View Full Text

Details

  • File Type
    pdf
  • Upload Time
    -
  • Content Languages
    English
  • Upload User
    Anonymous/Not logged-in
  • File Pages
    3 Page
  • File Size
    -

Download

Channel Download Status
Express Download Enable

Copyright

We respect the copyrights and intellectual property rights of all users. All uploaded documents are either original works of the uploader or authorized works of the rightful owners.

  • Not to be reproduced or distributed without explicit permission.
  • Not used for commercial purposes outside of approved use cases.
  • Not used to infringe on the rights of the original creators.
  • If you believe any content infringes your copyright, please contact us immediately.

Support

For help with questions, suggestions, or problems, please contact us