Skip to main content

Health systems must secure patient-facing payments with latest tech, expert advises

And to deliver a seamless patient experience, providers should take a holistic approach to payment processes, considering touchpoints including in-person locations, phone services, online platforms and mobile apps, says TrustCommerce at HIMSS25.
John Welch, chief product officer at TrustCommerce
John Welch, chief product officer at TrustCommerce
Photo: John Welch

Times are changing, and patients now expect the same seamless integrated payment experience with their healthcare provider that they get with other industries, such as retail.

Healthcare providers need to adapt and implement secure new payment technologies across all their patient-facing environments, said John Welch, chief product officer at TrustCommerce, a payments technology company (Booth 2648 at HIMSS25).

Consistency and convenience

"Implementing omnichannel payment systems allows patients to pay how they want, when they want – whether in person at point-of-service locations, through patient portals, via mobile devices, or over the phone with call center agents," he explained. "This comprehensive approach ensures consistency and convenience while meeting patients where they are in their healthcare journey.

"To enhance security and reduce compliance burdens, providers should strongly consider deploying validated point-to-point encrypted (vP2PE) devices across their in-person environments," he continued. "These solutions, along with hosted payment pages and tokenization technology, significantly decrease risk by helping keep sensitive payment data out of healthcare provider environments while also helping descope their systems from PCI DSS requirements."

Additionally, healthcare organizations can benefit from centralizing their payment processing with one vendor, he suggested.

"One significant benefit of consolidating payment vendors is unified reporting across all payment channels, providing a comprehensive view of transaction data," Welch contended. "This enhances efficiency by reducing manual overhead, streamlining reconciliation processes and offering valuable insights for strategic decision-making."

Reducing compliance burden

Welch has been offering advice to CIOs and other hospital and health system IT leaders on payment technologies. This is something he is sharing around HIMSS25.

"Healthcare leaders have numerous opportunities to enhance efficiency, streamline processes and improve patient collections – all while securing payment data and reducing their PCI DSS compliance burden," he explained. "To maximize efficiency and deliver a seamless patient experience, providers should take a holistic approach to their payment processes, considering all touchpoints, including in-person locations, phone services, online platforms and mobile apps.

"This comprehensive strategy ensures consistency across channels while identifying opportunities for process optimization that can significantly impact both operational costs and patient satisfaction metrics," he continued.

Security vulnerabilities

On another front, Welch recommends conducting a thorough assessment of one's current payment infrastructure to identify security vulnerabilities, compliance gaps and friction points in the patient payment journey.

"Many healthcare organizations are operating with legacy systems or disconnected systems that create unnecessary complexity and increase risk exposure," he said. "By mapping the entire payment ecosystem and evaluating each component against best practices for security and user experience, leaders can develop a strategic roadmap for technology investments that deliver measurable improvements in key performance indicators while addressing emerging threats.

"Focus particularly on implementations that can provide quick wins in both patient satisfaction and staff efficiency, such as self-service payment options and automated reconciliation tools that reduce manual workloads while improving accuracy," he concluded.

Follow Bill's HIT coverage on LinkedIn: Bill Siwicki
Email him: bsiwicki@himss.org
Healthcare IT News is a HIMSS Media publication.

WATCH NOW: Why you can't just dump AI on a CIO or CTO to make a chief AI officer