The Challenge
The organisation needed to comply with the Payment Card Industry Data Security Standard (PCI DSS) across a vast and diverse network, with 300 merchants and 647 payment terminals, each operating under a different operating framework. The goal was to ensure that every touchpoint involving cardholder data was secure, consistent and compliant, without disrupting critical healthcare operations. This wasn’t just about meeting regulatory requirements; it was about reinforcing the confidence of patients and families in the integrity of public healthcare services.
Our Engagement
Terra Firma deployed a Qualified Security Assessor (PCI QSA) to conduct a comprehensive PCI DSS assessment. The engagement required the development of 22 tailored Self-Assessment Questionnaire (SAQ-D) reports, one for each health entity, within a tight six-week timeframe. The approach was collaborative, engaging directly with stakeholders to understand their unique processes and build trust through transparency and shared goals.
Key Initiatives

Stakeholder Collaboration
Conducted deep-dive sessions with representatives from all 22 entities to understand local practices and build alignment.

Process Mapping
Documented and analysed how cardholder data was handled across payments, refunds, storage, and disposal.

Risk Identification
Assessed vulnerabilities and control gaps across diverse operational environments.

Remediation Roadmaps
Delivered clear, prioritised action plans tailored to each entity’s needs and maturity level.

Compliance Education
Provided guidance and context to help stakeholders understand the importance of PCI DSS and their role in maintaining public trust.
Outcomes
Terra Firma successfully delivered 22 customised SAQ-D reports within six weeks, covering over 300 merchant facilities and 647 terminals. Each report provided a clear and actionable roadmap for remediation, tailored to the operational realities of each health entity. The engagement achieved full stakeholder participation, ensuring that every entity had visibility in its cardholder data practices and a path forward to compliance. This not only improved governance and accountability but also empowered the organisation to take proactive steps in securing sensitive financial data. Additionally, it reinforced public trust in the orgnaisation’s digital infrastructure especially for vulnerable patients and families relying on these services.
Why It Matters
This engagement wasn’t just about meeting a standard, it was about earning and sustaining trust. In an environment where financial data intersects with personal health information, the stakes are high. Terra Firma’s work helped the organisation demonstrate its commitment to protecting sensitive data, reinforcing public confidence in its digital systems.
By making security transparent, collaborative and achievable, Terra Firma helped turn compliance into a catalyst for trust, laying the foundation for safer, more resilient healthcare services.



