InstaMed touted as first in healthcare to achieve P2PE v2.0 validation
InstaMed, a payment network for healthcare, has met the standards to protect payment card data, as defined in the Payment Card Industry Security Standards Council Point-to-Point Encryption Standard version 2.0, the company announced today.
In doing so, it's now touted as the first to achieve the P2PE v.2.0 Validation in the healthcare industry – and the only single healthcare platform to deliver an end-to-end payment tool validated by PCI Level 1 Service Provider, EMV and HITRUST.
"P2P encrypts the card data at the point of swipe and the keys are ejected from InstaMed: There is no way for an unauthorized person to get these keys," said Tony Hansen, senior security consultant at Providence Health and Services.
[EHRs getting better? Readers rank vendors higher than last year in new survey]
"Even if hacked, that computed or POS never have access to the card data. The data is protected from being breached. Whatever the weakness, that card data is safe," he added. "P2PE 2.0 validation means all standards have been met that will hold a vendor accountable."
Providence Health and Services has used InstaMed's payment network for a number of years.
PCI audited InstaMed against its encryption standards, and PCI Council approved InstaMed's Healthcare Payments P2PE and P2PE 2.0 validated. According to officials, this ensures InstaMed's customers are receiving the highest levels of security and compliance in the collection of card data.
By using InstaMed, providers can also simplify PCI compliance programs to a reduced self-assessment and decrease operating and remediation costs associated with scanning and penetration testing, according to officials.
InstaMed was validated by Coalfire Systems Inc., a PCI P2PE Qualified Security Assessor.
"Very few vendors have gone to get validated," said Hansen. "Because our direction is P2P it really is the drive of the organization. And while looking for vendors, we're only looking for those with P2P validation."
"All vendors want to increase scope to give us the confidence to deploy their solution. But vendors need to get validated," he added. "We'll flock to those vendors because I won't need to get my staff to jump through hoops. And we will know you're serious about helping us get compliant."
Twitter: @JessieFDavis
Email the writer: jessica.davis@himssmedia.com