Binoy Koonammavu
PCI ASV scanning for US healthcare providers is a compliance requirement that applies the moment your practice accepts a credit or debit card, whether that’s at a front-desk terminal, over the phone, or through an online patient portal. It doesn’t matter if you run a solo family practice, a multi-location dental group, or a regional speciality clinic: if card data touches an internet-facing system, PCI DSS applies, and quarterly ASV scanning is not optional.
Many healthcare organisations focus their compliance energy almost entirely on HIPAA, which makes sense given the stakes involved in protecting patient health information. But HIPAA and PCI DSS are separate frameworks built to protect different types of sensitive data. A practice that has invested heavily in HIPAA compliance can still be dangerously out of scope on the payment security side, and the penalties for PCI non-compliance are real: fines from card brands, increased processing costs, and loss of card acceptance privileges.
This guide gives US healthcare providers, from solo practitioners to multi-site medical groups, a clear picture of what PCI ASV scanning requires, how it intersects with your existing HIPAA obligations, what’s actually in scope, and what to do to pass your first scan.
PCI DSS (Payment Card Industry Data Security Standard): The security requirements established by the PCI Security Standards Council for any organisation that stores, processes, or transmits payment card data.
ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council to run the external vulnerability scans PCI DSS Requirement 11 mandates.
ASV scan: A quarterly external scan of internet-facing systems, payment pages, patient portals, and public IP addresses that checks for exploitable vulnerabilities before an attacker finds them.
Cardholder Data Environment (CDE): The systems, people, and processes that store, process, or transmit payment card data, plus anything connected to or capable of impacting the security of those systems.
HIPAA (Health Insurance Portability and Accountability Act): US federal legislation, administered by the HHS Office for Civil Rights, that protects patient health information (PHI), a distinct category from cardholder data.
Any medical practice that accepts payment cards through a front-desk terminal, an online billing system, or a patient portal is subject to PCI DSS, including quarterly external ASV scanning, regardless of practice size or speciality.
PCI DSS wasn’t built specifically for healthcare, but healthcare organisations fall within its scope as soon as they process a card transaction. A paediatric clinic processing a handful of card payments per week carries the same baseline obligations as a large hospital system. What changes with size is the validation level required, not whether ASV scanning applies at all.
For most independent medical practices and small clinic groups, that means PCI Merchant Level 4: the lightest documentation tier, but one that still mandates quarterly ASV scans and an annual Self-Assessment Questionnaire. Your acquiring bank or payment processor can confirm your merchant level. For a full breakdown of what qualifies, see “PCI ASV scan requirements“.
If your practice uses a third-party processor that handles all card data on your behalf, your CDE scope may be reduced, but it’s rarely eliminated. Your website and any connected internet-facing infrastructure can still fall within scope, which is worth confirming with a quick scoping check before assuming you’re covered.
Get a free scoping review before your next quarterly deadline.
PCI ASV scanning for US healthcare providers is required under PCI DSS Requirement 11 for any practice with internet-facing payment systems; the obligation exists independently of HIPAA, and non-compliance carries direct financial and operational consequences through your card processing agreement.
Card brands including Visa, Mastercard, and American Express hold acquiring banks accountable for merchant non-compliance, and those costs are routinely passed down to the practice. In the event of a breach, a non-compliant practice can face forensic investigation costs, card-replacement fees charged back by the card brands, and civil liability costs that can be existential for a small practice. Scanning quarterly and keeping documentation current is the most direct way to stay ahead of that exposure. If you’re preparing for your first scan, here’s how to prepare.
HIPAA and PCI DSS address different categories of sensitive data, protected health information and cardholder data, respectively and compliance with one framework does not satisfy, replace, or reduce your obligations under the other.
This is one of the most persistent misconceptions in healthcare payments. Practices that have built robust HIPAA programmes sometimes assume those investments carry over to PCI compliance. There’s real overlap in underlying controls, encryption, access management, and audit logging that are valued by both frameworks, but the enforcement structures are entirely different. HIPAA is enforced by the HHS Office for Civil Rights; PCI DSS is a contractual standard enforced through card brand rules and your merchant agreement. A practice can pass a clean HIPAA audit and still be in breach of its card brand agreement for skipping a quarterly ASV scan.
Where the two frameworks do align is in the controls you’ve likely already built for HIPAA role-based access, patch management, and incident response planning. Adapting that documentation for PCI purposes, rather than starting from zero, is usually the fastest path to closing the gap. Maintaining two distinct compliance programmes, each with its own defined scope, is more reliable than assuming one umbrella programme covers both.
Any internet-facing system that stores, processes, or transmits card data is in scope, most commonly the patient payment portal, card-on-file or recurring billing systems, virtual terminals for phone payments, and the public IPs those systems sit behind.
Online patient payment portals have become standard infrastructure; they reduce administrative burden and meet patient expectations for digital convenience, but they also introduce real PCI scope complexity. If your portal is hosted on servers you control, that infrastructure is firmly within your CDE and your quarterly ASV scans. If you use a redirect or iframe-based payment form from a third-party provider, your scope may be reduced, but your web server’s ability to serve that page securely still places it within the ASV scan scope. PCI DSS guidance is clear: any internet-facing system capable of impacting the security of cardholder data must be scanned.
The safest architecture keeps the payment step isolated from the medical-record view rather than blended into the same page or database; a portal that shows appointment history and accepts a card payment is handling two regulated data types at once. Working with a PCI-certified gateway or portal vendor reduces your compliance burden considerably; your ASV scans will still need to cover your own internet-facing infrastructure, but a well-architected portal using tokenisation and strong TLS configurations produces cleaner scan results with less remediation effort. To confirm exactly what a scan will cover, see what’s included in a PCI ASV scan.
Small and mid-sized healthcare practices are disproportionately exposed because they often lack dedicated IT or compliance staff, yet they face the same external threat landscape and enforcement consequences as larger organizations.
The threat environment doesn’t scale down for smaller targets. Cybercriminals target small medical and dental practices precisely because they’re more likely to have unpatched systems, misconfigured networks, and limited security monitoring, and payment card data has immediate monetisable value on criminal markets. An ASV scan examines internet-facing systems for exactly the vulnerabilities attackers look for: open ports, outdated software, weak SSL/TLS configurations, and unpatched known vulnerabilities.
For a small clinic, an external vulnerability scan is less technically daunting than it sounds. It doesn’t require on-site access or agent installation; it’s conducted remotely against your external IP addresses and internet-facing systems, and the output is a structured report with clear remediation guidance. In small healthcare environments, scans commonly surface expired SSL certificates, outdated web server software, exposed admin interfaces, and vulnerabilities in third-party payment page integrations, most of which are straightforward to fix once identified. If a scan does come back with findings, here’s how to resolve a failed scan before your next quarterly deadline.
Pricing scales with your scope, not your practice size.
Dental practices face identical PCI DSS requirements as any other healthcare provider that accepts cards, but they're statistically among the least prepared, which makes proactive ASV scanning especially important.
Dentistry is a high-card-payment specialty, patients regularly pay out-of-pocket or cover insurance gaps with a card, and average transaction values are high enough that card acceptance is essential to practice operations. Yet independent and small group dental practices frequently operate without dedicated IT staff and have historically focused compliance energy on HIPAA rather than PCI. That combination of high card volume and low PCI readiness creates a gap that’s both common and consequential.
For a single-location dental office, compliance doesn’t need to be an overwhelming project. Start by mapping your card data flows, where cardholder data enters, moves through, and exits your environment. From there, a Level 4 Self-Assessment Questionnaire and quarterly ASV scans form the core of your programme. Choosing a vendor who understands the SMB healthcare environment, offers straightforward onboarding, and reports in plain language see how to choose an ASV vendor makes the quarterly cadence manageable rather than disruptive.
Cost scales with the number of IPs and domains in scope rather than practice size, so a small clinic with one payment portal and one public IP typically pays toward the lower end of the market range.
Practices sometimes over-scope by assuming every internal system needs scanning; narrowing the cardholder data environment first, isolating the payment portal, and segmenting the network usually reduces both cost and ongoing compliance workload. See current ASV scan pricing for a full breakdown by scope size. The cost of quarterly scanning is minimised set against the fines, breach costs, and reputational damage that non-compliance can produce.
Consequences run through the payment side, not the health side, processors can levy monthly fines, raise transaction fees, or suspend card acceptance, and a breach involving unscanned systems adds liability exposure on top of any separate HIPAA breach obligations.
A failed scan isn’t an automatic penalty; ASVs generally allow rescans once vulnerabilities are remediated, but the 90-day compliance clock under PCI DSS v4.0 keeps running regardless. A breach that exposes both cardholder data and PHI in the same incident can trigger PCI-related fines and HIPAA breach notification requirements simultaneously, which is where the stakes compound specifically for healthcare. Staying current on the latest scanning standard also matters: see what changed with PCI DSS v4.0 if your practice hasn’t reviewed its scan configuration recently.
PCI ASV scanning for US healthcare providers is a baseline compliance requirement, not an optional line item; it applies the moment your practice accepts a payment card, independently of your HIPAA programme. Whether you run a busy dental office, a multi-provider medical clinic, or a growing speciality practice, your internet-facing systems must be scanned quarterly by a PCI SSC-approved vendor, and your patient payment portal deserves particular attention as a scope area that’s often underestimated. The distinction between HIPAA and PCI DSS isn’t academic; it’s a compliance gap that leaves real practices exposed to real, avoidable consequences.
The good news: PCI compliance for healthcare SMBs is genuinely achievable. With the right scanning partner, the quarterly ASV process is straightforward, affordable, and gives you ongoing visibility into your external security posture. Start with clarity on your scope, work with a PCI SSC-approved vendor who understands healthcare environments, and make quarterly scanning a routine part of your compliance calendar.
Built for practices with limited IT resources, plain-language reporting, straightforward onboarding.
PCI ASV scanning is a mandatory external vulnerability assessment run by a PCI SSC-approved vendor. Healthcare providers that accept cards need it because it verifies internet-facing systems can't be exploited to reach cardholder data, skipping it puts a practice out of PCI DSS compliance.
At minimum once every 90 days; effectively quarterly, per PCI DSS Requirement 11. Scans must be run by a PCI SSC-approved vendor, and passing results should be kept as compliance documentation.
No. HIPAA protects patient health information; PCI DSS protects cardholder data. These are separate obligations enforced by different bodies, a fully HIPAA-compliant practice can still be non-compliant with PCI DSS.
The provider must remediate the flagged vulnerabilities and resubmit for a passing scan. Continued failure means sustained non-compliance, which can bring card brand fines, higher transaction fees, and liability exposure after a breach.
Size doesn't exempt a practice. If card data touches an internet-facing system, quarterly ASV scanning applies, whether that's a single-provider office or a large network.
No, the scan must be run by a PCI SSC-certified Approved Scanning Vendor. A general IT provider can help with remediation, but the scan itself has to come from a certified ASV.
The vendor may hold PCI responsibility for their own platform, but your practice is still responsible for confirming that, obtaining evidence (an AOC or SAQ), and scanning anything under your own domain or IPs that touches card data.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.