Prerequisites
- The PC’s operating account open
- Your practice brand decided, for the descriptor
- Your expected card volume and mix
Choose a processor
Test the multi-entity case before signing. Can each location settle to its own PC’s account? A processor that settles everything to one configured account will settle your Colorado PC’s patient payments into whichever account was set up first, which is a commingling problem, not a configuration preference.
Pricing: interchange-plus vs blended
At meaningful volume, ask for interchange-plus. The published interchange rates are the same for every merchant; what you’re negotiating is the markup, and you can only negotiate what you can see.
Card-present vs card-not-present
Encourage in-office payment at check-out where you can. It costs less and disputes less.
Steps
1
Set the statement descriptor to the practice brand
This is the single highest-value configuration on this page. Patients recognize “Meridian Dermatology,” not “Meridian Health Partners LLC” or “Priya Shah MD PC.” Descriptor mismatch is the leading cause of healthcare chargebacks, and the MSO-PC structure makes it worse by design because the legal entity name and the brand differ.Set the descriptor to the brand, include a phone number if your processor supports it, and check what actually appears on a test transaction rather than what the configuration screen says.
2
Point settlement at the PC's operating account
Patient payments are the practice’s revenue. Per entity, per location. See Structure accounts across your entities.
3
Decide on surcharging, carefully
Passing the processing fee to patients is permitted in some states and restricted in others, and card network rules impose their own requirements including advance disclosure, signage, receipt disclosure, and caps.Verify both state law and network rules before implementing, and note that debit card surcharging is generally treated differently from credit. Also weigh the patient-relations cost: a surcharge on a medical bill lands differently than one on a retail purchase.
4
Understand your PCI scope
PCI DSS scope depends on how card data flows. To keep it minimal:
- Use point-to-point encrypted terminals so card data never touches your systems
- Use hosted payment pages or iframes for online payments, so card data goes to the processor directly
- Tokenize cards on file — store the token, never the number
- Never write card numbers on paper forms or store them in the EHR
5
Set up card-on-file compliantly
Requires:
- Written authorization from the patient, specifying what may be charged and when
- Tokenization — store the processor’s token, never the card number
- Notification before charging, per your policy — this dramatically reduces disputes
- A clear way for the patient to revoke
6
Configure receipts to send immediately
Email or text, automatically. A patient with a receipt disputes far less than one without.
7
Set up reconciliation
Card deposits arrive net of fees, in batches that don’t align to individual payments.Record gross revenue and fee expense separately. Netting them understates both revenue and expense, and it makes your effective processing rate invisible. See Reconcile payments daily.
Payer virtual credit cards
If a payer sends single-use card numbers instead of EFT, you are paying 2–3% on money that should arrive free. Complete their EFT enrollment and ask in writing to opt out of the card program. See Paper checks and virtual credit cards.Verify it worked
- Descriptor tested on a real transaction and shows the practice brand
- Settlement points at the correct PC’s account, per entity
- Interchange-plus pricing at meaningful volume
- Surcharging decision verified against state law and network rules
- PCI scope minimized; SAQ completed
- Card-on-file authorization form in use
- Cards tokenized, never stored
- Receipts sending automatically
- Gross revenue and fees recorded separately
- Dispute rate monitored against processor thresholds