Skip to content

PCI DSS vs HIPAA

By Sam Rivera, Founder, SentinelPanda · August 5, 2026 · 3 min read · PCI DSS

A clinic that takes card payments is subject to both — a prescriptive card-brand contract and a flexible federal statute, over two different data types, at the same time.

Contract versus statute

PCI DSS is not law. It is a standard maintained by the PCI Security Standards Council and made binding through your contracts with acquirers and processors. Enforcement is commercial: fines are levied by card brands and passed down, and in a bad case your ability to accept cards is at risk.

HIPAA is federal law — the Privacy, Security, and Breach Notification Rules, as amended by HITECH and the 2013 Omnibus Rule. It is enforced by the HHS Office for Civil Rights, with civil monetary penalties tiered by culpability and state attorneys general holding concurrent enforcement authority. The failure modes are legal and regulatory rather than commercial.

Prescription versus flexibility

This is the sharpest practical difference. PCI DSS names controls. HIPAA's Security Rule was written to be technology-neutral and scalable across a solo practice and a national health system, so it splits implementation specifications into "required" and "addressable".

"Addressable" is the single most misunderstood word in HIPAA. It does not mean optional. It means you implement it, or you document a reasoned assessment of why it is not reasonable and appropriate for you and implement an equivalent alternative. A blank where an addressable specification should be is a finding, not a choice — and encryption of ePHI is the specification most often wrongly treated as optional.

What you can show a third party

  • PCI DSS: an Attestation of Compliance, self-signed or QSA-signed. Concrete, and your acquirer expects it annually.
  • HIPAA: nothing official. There is no government HIPAA certification, and any vendor selling you one is selling their own opinion. What exists in the market are proxies — HITRUST certification, SOC 2 reports mapped to HIPAA, or independent risk assessments.
  • Business associates sit under HIPAA by contract via a BAA, which is the closest structural analogue to how PCI obligations flow downstream to service providers.

When both apply

Any healthcare provider taking card payments is in both regimes simultaneously — and critically, over two distinct data sets. A payment card number is not PHI, and a diagnosis code is not cardholder data. The temptation is to build one "sensitive data" control set covering everything, which usually over-controls the low-risk systems and under-controls the CDE.

The better pattern is a shared control baseline — access control, encryption, logging, incident response, workforce training — with two clearly-scoped overlays: the CDE where PCI's specific mechanics apply, and the ePHI systems where HIPAA's risk analysis and BAA obligations bite. Scope reduction helps both: outsourcing payments to a validated provider shrinks the PCI overlay dramatically without touching your HIPAA posture.

Keeping two scopes, two evidence sets, and two renewal calendars coherent is exactly the kind of cross-framework bookkeeping SentinelPanda tracks in one workspace.

HIPAA Security Rule safeguards PCI DSS CDE scoping HIPAA business associate agreements

Run your compliance program in one workspace.