Compliance
/
Payments and PCI

Run program payments without building a separate payment operation.

For Connect program payments, DrWell holds the payment account and payment infrastructure described on this page. Your practice does not need to apply for a separate program-payment account or have staff handle patient card numbers.

No separate program-payment account to open
Staff does not handle card numbers in Connect
Failed-payment recovery built in
Program payment activity stays tied to the order
Merchant account
PCI paperwork
Underwriting
Card storage
Program payments
Handled by Connect
LegitScript Enterprise Certification Partner, Healthcare
DrWell handles the program payment account.
In payment terms, DrWell is the merchant of record for Connect program payments. DrWell holds the payment account and the pharmacy-related classification described on this page, while your practice name can appear on the patient's statement.
What you avoid

What your practice avoids by not opening a separate program-payment account

Six things that stay off your plate when the program-payment account is not in your practice's name.

01
No payment account to apply for

Your practice does not apply for or maintain the payment account DrWell uses for Connect program transactions.

02
No high-risk underwriting to sit through

DrWell is the merchant of record for Connect program payments, so your practice is not the business being underwritten for a high-risk account.

03
No rate priced on your volume alone

Rates in this category follow volume. A practice that opens its own high-risk account is priced on that one practice's volume, while Connect program payments run on DrWell's published platform service fee.

04
No account-level reserve in your name

There is no account-level reserve on a merchant account opened in your practice's name for Connect program payments. Refunds, disputes and applicable fees can still affect payouts.

05
Less card handling for staff

Patient card data follows the Connect payment flow rather than being entered or stored by your staff.

06
Payment activity tied to the order

Program payment activity stays connected to the patient's program order instead of arriving on a separate statement weeks later.

How it actually works

DrWell takes the program payment. Your practice runs the care program.

Merchant of record means the business responsible to the card network for the transaction. For Connect program payments, that is DrWell. Your practice continues to own the patient relationship and the clinical program.

DrWell holds the program-payment account.
Your practice does not open a sub-account under DrWell.
Your practice name can appear on the patient's statement, and Connect ties the payment to the patient's program order.
Plain English

Your practice uses DrWell's program-payment infrastructure. Rather than opening a separate payment account for Connect program transactions. This applies to program payments processed through Connect. Payments your practice accepts through its own terminal or checkout remain under your own payment account and responsibilities.

What your practice does not do for program payments
Apply for a separate program-payment account
Maintain that payment account with the bank
Carry an account-level reserve in your practice's name
Enter a patient's card number for a program payment
Store a card number in your own systems
Complete the card-security paperwork for program payments

Cards you take at the front desk on your own account for visits, injectables, lasers and retail remain yours, and so does the security paperwork for those.

Patient
Pays for the program
Statement shows
Your practice name
DrWell
Takes the program payment
Merchant of record: DrWell
Practice
Receives the payout
No account application, no bank approval
The PCI question

Your staff doesn't need to handle the card number

PCI is the card industry's security standard. For Connect program payments, the practical point is simple: patients enter their own card information into payment-company fields, not into your practice systems.

01
The patient enters the card

Patients add and update their own card in the patient portal. Nobody at your front desk is taking a card number over the phone and typing it somewhere.

02
Card data goes to the payment provider

The field the patient types into is run by the payment company. The number goes directly to them rather than into your systems or DrWell's.

03
Connect receives a token, not the card number

What comes back is a stand-in token. It works only for that patient on DrWell's account, so it is of no use to anyone else who obtained it.

04
Security responsibilities follow the payment

Program-payment security responsibilities sit with the payment infrastructure DrWell operates, including the audit and the sign-off.

Patient enters the card
•••• •••• •••• ••••
Payment company field
Payment provider
Holds the card number
Connect receives
Token
Never reaches your practice systems
Never reaches DrWell systems

Technical detail: PCI DSS v4.0.1 is the current card-security standard, and its newest requirements took effect on 31 March 2025. Your staff does not need to understand the version number to use Connect. Source: PCI Security Standards Council.

Payment classification

The payment classification is already built into the program

Medication-related program payments can be treated differently from ordinary medical-service transactions. DrWell operates the program-payment setup using the pharmacy-related classification identified on this page.

01
Filed under the pharmacy category

MCC 5912 is the payment industry's category for pharmacies and drug stores. It is supporting infrastructure behind Connect, not something your staff has to manage.

02
Card network oversight

Both card networks run additional oversight on this category and hold the payment account holder responsible for how the business is classified and monitored. For Connect program payments that is DrWell.

03
LegitScript certification

DrWell is a LegitScript Enterprise Certification Partner for Healthcare, a credential relevant to regulated healthcare businesses. Pharmacy partners are evaluated against Connect's sourcing requirements before they receive orders.

04
Your name on the statement

Your practice name can appear on the patient's statement without a payment account being opened in your practice's name.

Where a program transaction is routed
Program transaction
Pharmacy-related lane
MCC 5912
General medical services lane
Not used
The classification sits behind Connect. Your staff does not manage it.
Failed payments

Failed payments don't have to become a staff chase

When a program payment fails, Connect can retry it automatically and prompt the patient to update their card in the portal, helping keep the order from quietly falling out of the cycle.

Connect retries the charge on an automatic schedule.
Patients update their own card in the portal, so your front desk is not chasing it.
Staff does not collect card details by phone, and payment activity stays connected to the program order.
What it costs you
Platform service fee
2.90%* + $0.20
Program-payment account to open
None
Time you spend in underwriting
None
Account-level reserve in your name
None
Merchant of record
DrWell

* Starting platform service fee, charged per transaction at the time of the sale. The rate depends on your plan. See the pricing page for plan-specific rates. Refunds, disputes and applicable network fees are handled separately, which is covered in the next section.

1
Charge failed
2
Automatic retry
3
Patient updates card
4
Payment succeeds
5
Order continues
Your front desk is not the one chasing the card.
Payout transparency

What can still come out of a payout

The payment account may sit with DrWell, but ordinary transaction adjustments do not disappear. Refunds, disputes and applicable network fees can still affect your payout.

01
Refunds

The refunded amount comes out of your payout. The platform service fee already charged on the original sale is not returned.

02
Chargebacks

A disputed amount can be withheld while the dispute is reviewed, and returned if it resolves in your favor.

03
Refund and dispute fees

The card networks charge a per-item fee on a refund and on a dispute. Those are passed through at cost, with no markup.

04
Ordinary merchant adjustments

Anything a card merchant would normally find withheld from a daily settlement is withheld here the same way, at cost. There is nothing held back beyond that list.

One program order, expanded
Patient charge
Order total
Medication and shipping
Comes off the order
Platform service fee
2.90% + $0.20
Refund or dispute on this order
Attached to this order
Your payout
What is left on this order
Every adjustment is visible against the order it belongs to, not on a separate statement weeks later.

The difference is not that these costs disappear. It is that your practice never had to get approved for the account they come out of, and each one is visible against the order it belongs to instead of arriving on a separate statement weeks later.

One honest caveat

Your other payment systems are still yours

If your practice accepts cards through its own terminal or online checkout for visits, injectables, lasers or retail, those payments remain on your account and so does the security paperwork for them. Connect's payment model applies to program payments processed through Connect, which for most practices is the part that was hard to get approved in the first place.

See how compliance works across the platform
Connect program payments
DrWell payment account
Program medication orders
Card data handled by the payment provider
Security paperwork with DrWell
Front desk and other services
Your payment account
Visits, injectables, lasers, retail
Your own terminal or checkout
Security paperwork stays with you
Questions

Answered plainly

Do I need my own merchant account for Connect program payments?

No. DrWell holds the payment account used for the program payments described on this page, so there is no application for your practice to fill out and no bank approval to pass.

Does Connect make my whole practice PCI compliant?

No. The Connect program-payment card flow described here sits with DrWell. Payments your practice accepts through its own account remain your responsibility.

What does merchant of record mean?

For Connect program payments, DrWell is the business responsible to the card network for the transaction and holds the program-payment account. Your practice does not open a sub-account underneath DrWell.

What does the patient see on their bank statement?

Your practice name, set per practice. That keeps down the calls about an unrecognized charge and the disputes that start over a name the patient has never seen.

Who handles chargebacks?

DrWell, as the business accepting the payment. Two things worth separating: a failed payment is a charge that never went through, and a chargeback is a patient disputing one that did. They are handled differently.

What happens when a card fails?

Connect retries the charge on a schedule and prompts the patient to update their card in the portal, reducing staff follow-up. The order holds rather than falling out of the cycle.

Can I keep my existing payment account?

Yes. It can continue handling the other products and services it was set up for. Program payments run through Connect.

Connect by DrWell

See the payment flow without needing to become a payments expert.

In one walkthrough, see who takes the program payment, where card data goes, how failed payments recover, what can affect a payout, and what stays your practice's responsibility.

Payment account
Card security
Classification
Failed-payment recovery
One Connect dashboard
You run the program. Connect handles the program-payment infrastructure.