PCI DSS Assessment of National Healthcare Agency

Enabling the compliant and secure storage of credit card information.
Situation

Our client was instructed by NSW Treasury to conduct a Payment Card Industry Data Security Standard (PCI DSS) assessment across their organisation in just 10 weeks. 

The PCI DSS assessment process was a race against time, as the National Healthcare Agency needed to thoroughly evaluate each entity, merchant facility, and merchant terminal to identify any potential security vulnerabilities or areas of non-compliance. 

Challenge

The organisation process, manage, and store credit card payment information in different ways across their 22 entities, 300 merchant facilities, and 647 merchant terminals. 

The task at hand involved extensive coordination, collaboration, and meticulous attention to detail. It required assessing the existing processes, policies, and infrastructure within each entity, merchant facility, and merchant terminal to determine the level of adherence to PCI DSS guidelines. Any variations or deviations from the standard needed to be identified, documented, and reported. 

Solution

The PCI SAQ-D is a comprehensive survey spanning over 30 pages, designed to evaluate and certify the security measures implemented by an organisation in handling electronic card data processes, storage, and transmission. To carry out this independent assessment of PCI DSS compliance, the Terra Firma team engaged in a combination of on-site visits and virtual meetings with relevant stakeholders. 

Our Approach

During these meetings, the team began by providing attendees with a comprehensive overview of PCI DSS, emphasising the significance of compliance for the National Healthcare Agency, and establishing trusted relationships with key stakeholders. This served as a foundation for the subsequent discussions aimed at understanding and documenting the organisation’s existing business processes. 

In a non-critical manner, the Terra Firma team worked with stakeholders to investigate and identify areas of both compliance and non-compliance with PCI DSS requirements. Through an inclusive approach, they conducted the necessary 22 PCI SAQ-D surveys, addressing each specific requirement thoroughly. 

Outcomes

The Terra Firma team completed the PCI DSS assessment and associated 22 PCI SAQ-D reports on time. Through our neutral and collaborative approach combined with on-site and virtual interactions, the Terra Firma team executed this assessment process diligently. Our consultants promoted a comprehensive understanding of PCI DSS compliance, paving the way for enhanced security measures and trusted relationships within the organisation. 

In addition, Terra Firma provided senior management with a never-before-seen level of detailed credit card business process maps for each health entity and a prioritised (short, medium, and long-term) list of remediation activities. We enabled senior management to gain a holistic understanding of their PCI obligations and the next steps required to remediate while managing the storage and processing of credit card information in a compliant and secure manner. 

More case studies

Future Ready Government: Building Digital Foundations for Tomorrow’s Communities

Future Ready Government: Building Digital Foundations for Tomorrow’s Communities

With climate resilience and digital transformation in mind, one council envisioned a smarter, more connected future for its community.
Faced with increasing demands for transparency, service excellence and climate resilience, a metropolitan council in Victoria embarked on a bold journey to modernise its digital landscape. With a newly appointed CEO championing customer-centricity and a community eager for smarter, greener services, the council partnered with Terra Firma to craft a future-ready ICT Strategy. The result? A transformative roadmap that empowers the council to deliver responsive, data-driven and sustainable services for years to come.

read more
Transforming Accessibility: A Digital Evolution in the Non-Profit Sector

Transforming Accessibility: A Digital Evolution in the Non-Profit Sector

What if every call for help could be answered faster, smarter, and more compassionately – no matter where it came from?
In 2016, a national not-for-profit organisation unified its national operations, bringing together previously separate territories under one domain. But behind the scenes, its contact centres remained fragmented – each using bespoke, disconnected systems that made it difficult to share information, respond quickly, or provide consistent support.
By 2021, the need for change was clear. The organisation set out to transform how it connected with people in need, whether they were seeking financial assistance, crisis support, housing or simply someone to talk to.

read more
Innovation in Action: A Council’s Digital Leap

Innovation in Action: A Council’s Digital Leap

In a world of accelerating change, one council chose to lead with purpose – through innovation, sustainability, and capability.
Faced with the dual pressures of climate resilience and digital disruption, a local government recognised the need to evolve. The goal was clear: cultivate innovation, sustainability, and capability across council. Terra Firma partnered with the council to co-create a transformative digital strategy, one that would empower staff, engage the community and build a dynamic ecosystem for future solutions.

read more
Securing the Frontline: Strategic Enablement for Public Confidence in Health Services

Securing the Frontline: Strategic Enablement for Public Confidence in Health Services

What happens when a public health crisis demands a 1,500-person response team in days – not weeks?
In times of crisis, trust in public systems becomes paramount. During the height of the COVID-19 pandemic, a Government Department faced an urgent challenge: rapidly mobilise a contact and trace centre to protect public health. Terra Firma was engaged to help deliver a secure, scalable solution that would not only support the workforce behind the scenes but also reinforce public trust in the government’s ability to respond swiftly, transparently and effectively.

read more
Secret Link