The difference is that PCI DSS is an industry developed and maintained standard. HIPAA is a piece of legislation that created rules around privacy and security (and a lot of other things). There are some standards outlined in the rule. But there is no agency in place to perform validation or audits, and as such being "compliant" doesn't mean much outside of how much you trust the entity. But the penalties are very real, and very severe. Working for a small healthcare IT software company, we take HIPAA very seriously.
Comments
How does HIPAA compare to PCI? Is it easier or harder or about the same difficulty?
The difference is that PCI DSS is an industry developed and maintained standard. HIPAA is a piece of legislation that created rules around privacy and security (and a lot of other things). There are some standards outlined in the rule. But there is no agency in place to perform validation or audits, and as such being "compliant" doesn't mean much outside of how much you trust the entity. But the penalties are very real, and very severe. Working for a small healthcare IT software company, we take HIPAA very seriously.
HIPAA is easier than PCI. PCI involves not only concrete technical controls, but also a for-profit bureaucracy.
Neither are particularly meaningful from the POV of software security.