The difference is that PCI DSS is an industry developed and maintained standard. HIPAA is a piece of legislation that created rules around privacy and security (and a lot of other things). There are some standards outlined in the rule. But there is no agency in place to perform validation or audits, and as such being "compliant" doesn't mean much outside of how much you trust the entity. But the penalties are very real, and very severe. Working for a small healthcare IT software company, we take HIPAA very seriously.
Comments
The difference is that PCI DSS is an industry developed and maintained standard. HIPAA is a piece of legislation that created rules around privacy and security (and a lot of other things). There are some standards outlined in the rule. But there is no agency in place to perform validation or audits, and as such being "compliant" doesn't mean much outside of how much you trust the entity. But the penalties are very real, and very severe. Working for a small healthcare IT software company, we take HIPAA very seriously.