Childcare Management Software: Online Childcare Fee Collection, Online Childcare Enrollment Forms Childcare Management Software
Childcare Center
PCI Compliance
Request EZ-CARE2 Demo CD
  Product Overview
  Managing Your Data
  Fee Processing
  Schedule/Attendance
  Accounting
  Reports & Merging
What’s New!
Features List
References
  Pricing
  Request Info

PCI Compliance Standards for
Childcare & Daycare Centers

What is PCI Compliance?

Due to growing concerns with credit card fraud and widely publicized security breaches involving cardholder data, the credit card industry established new standards called Payment Card Industry Data Security Standards (PCI DSS but often referred to as just PCI compliance).

These requirements cover a wide assortment of practices, technology, and systems and can be very complex to understand, let alone comply with. Primarily they relate to how your organization handles, stores and transmits cardholder data. Here are a few of the most important elements:
  • Never store CVV2 data (the 3-digit code on the back of cards) or magnetic strip data
  • If credit card numbers need to be stored or transmitted, they should generally be encrypted with at least 128-bit encryption.
  • Restrict access to physical and electronic cardholder data with user
    specific passwords and based on business need-to-know.
More complete information on the PCI DSS can be found at www.pcisecuritystandards.org
Does this apply to my center?

Every organization that accepts credit cards is being required to comply with PCI DSS, but the requirements for compliance can vary widely depending on the types of processing you do and the volume of credit card transactions processed. Merchants fall into one of four levels. Most daycare programs fall into the lowest processing volume category (Level 4 with less than 20,000 Visa/MC transactions per year), where the primary requirement is completion of a PCI self-assessment questionnaire and quarterly network scans. Currently there is no PCI mandated date for Level 4 merchant compliance.
Why is PCI compliance important to my organization?

Even though participation in compliance has not been made mandatory for Level 4 merchants, your organization could be assessed substantial fines (as much as $500,000) if cardholder data is breached and your center is not compliant.

Equally important is the simple need to protect your parents and their sensitive data they’ve entrusted your organization with.

How can EZ-CARE2 help?

All of EZ-CARE2’s tools for credit card processing including EZ-EFT, Insta-Charge, Click-to-Pay and WebLink already use PCI compliant methods for encrypting and securely transmitting credit card data, but we've recently released a wide variety of improvements to make it easy for our clients to achieve PCI compliance by eliminating the need to store cardholder data within EZ-CARE2. Our new Transaction Processing Gateway can be used to securely store parents' credit card (or bank account data) in a PCI certified hosting facility. A parent’s record will just contain a “SafeSave™ ID” that uniquely identifies stored account data so that future transactions can be processed (via Insta-Charge, Click-to-Pay and EZ-EFT) without the need to re-enter any data.

Click here to learn more about EZ-CARE2's Payment Processing Tools