PCI Self Assessment

PCI Self Assessment

Index

  • Sections
    • Complete Merchant Systems – CMS PCI (Payment Card Industry) Self Assessment
    • What is PCI Compliance?
    • Who can help with the compliance process?
    • Does PCI compliance apply to my clients using the Slyce Payment Plug-in?
    • PCI Username and Password

Complete Merchant Systems – CMS PCI (Payment Card Industry) Self Assessment

Complete Merchant Systems (CMS) began a new security compliance program in November 2017. Anyone who uses credit card processing to accept, transmit, or store payment card information, regardless of size, must complete a PCI Self-Assessment Questionnaire. This applies to everyone regardless of when they signed up with CMS.

This assessment has been put in place to prevent cardholder data breach. According to CMS,  should a financial breach occur without an assessment being completed, a practice may be subject to non-compliance fees, card replacement costs, and forensic audits.

If you do not complete the questionnaire, CMS will charge you $20 a month until the questionnaire is completed (beginning in April 2018).

Free assistance with the questionnaire is available through the company, Security Metrics. CMS has contracted with Security Metrics to provide their customers with questionnaire compliance assistance. Each CMS account is automatically enrolled with Security Metrics.

The Customer Support team at CMS is available to assist with login and password issues when accessing the Security Metrics system, and with getting the merchant account on the correct SAQ questionnaire in the Security Metrics system. CMS Support can be reached at 877-267-4324   or 

support@cmsonline.com

Contact Security Metrics at 801-705-5700   or login to your Security Metrics account at

https://www.securitymetrics.com/pcidss.cms for assistance with the questionnaire.

ICANotes cannot provide you with assistance in completion since the questionnaire applies to issues within your local system, not ICANotes.

See also FAQ’s from CMS below.

What is PCI Compliance?

The Payment Card Industry Data Security Standard (PCI DSS) was established by the major card brands. This standard is to help any business who accepts Visa, MasterCard and Discover credit cards to organize their company in a way to keep all customer private information secure.  This information can include but is not limited to credit card numbers, expiration dates, billing address and security CVC codes. It is a requirement from the card brands for any company who processes, stores, or transmits payment card data to implement the applicable strategies and suggestions outlined in the PCI DSS standards to prevent cardholder data from theft or fraudulent activity. PCI compliance is not a single event, but an ongoing process. This is true regardless of the merchant services provider that is being used by the business. CMS has created an FAQ to learn more, which can be viewed at: https://www.cmsonline.com/PCI_FAQs.html

Who can help with the compliance process?

Under PCI rules, the merchant service provider cannot directly assist the merchant through the compliance process. The concern of the Card Association is that it creates a potential conflict of interest and any support should come from a neutral third party. In an effort to minimize the complications that can arise when becoming PCI compliant, CMS has contracted with Security Metrics to answer any questions or to provide support.

If you find that there is a need for help in becoming PCI Compliant please contact Security Metrics directly. They are there to assist in any way and can be reached at 801-705-5700   .

Does PCI compliance apply to my clients using the Slyce Payment Plug-in?

If you have integrated payments using our Slyce Plug-in (which is PCI compliant), this should make the process very seamless for the customer.  Due to the integration the merchant should be taking the required SAQ A if the business is not accepting payments through any other means or recording credit card information outside of the Slyce Payment Plug-in.  This questionnaire is approximately 20 questions and we have found it can be completed within 10 minutes.

PCI Username and Password

<div id="click_to_dial_wrapper" style="displ
    • Related Articles

    • Risk Assessment Report Export

      The Risk Assessment Report (which is located in Billing/Productivity Report Search Form as shown below) will now export to the Upload Site like all other exported documents from ICANotes. Example of Risk Assessment Report: When the report has ...
    • Complete Assessment Tabs for Prescriber and Non Prescriber

      The Prescriber and Non Prescriber Complete Assessment tabs are shown below. The Demographics are accessible as the first tab. The History of Present Illness tab for Non Prescriber ('New HPI') The History of Present Illness tab for Non Prescriber ...
    • Chem (Chemical) Dependency (6 ASAM Dimensions) Assessment

      This knowledge base article will show you how to create and complete and a Chemical Dependency Assessment. 1. From the patient's Chart Face, choose the Chem Dependency (6 ASAM Dimensions) button. 2. The Dimension 1 tab is for ASAM Dimension 1: ...
    • Custom Form: Suicide Risk Assessment (Adult or Child)

      These new forms are located in the Custom Forms/Assessments button from the Chart Face. The Adult Suicide Risk Assessment is located under Adult Assessments column and the Child Suicide Risk Assessment is located under Child Assessments. Tyler shows ...
    • How to Send an Assessment via Client Portal

      Overview ICANotes+ provides a range of assessments that can be sent to clients either individually or as part of a package. Before sending an assessment, ensure the client's portal is activated. Prerequisites To learn how to activate the client ...