Sending both emails to the same address is certainly not a secure approach.
You'll need to ask your PCI person whether they will pass you if the credit card digits are supplied to you in separate emails. I've seen many people pass compliance by sending the middle digits to an email address that's stored on another domain on another server separate from the one where your order confirmation emails are sent.
And then of course deleting those emails once you've processed the orders.
In the simplest sense sending the middle digits via email, and leaving the outer digits on the server, is secure. But having 2 emails sent to the same place containing the sum total of all digits is ... dangerous, for the reasons kobra mentioned.
But ... a much safer and secure approach is to use a payment gateway service that processes the card in real time. That also gives the customer immediate access to whatever they've purchased ... which is important if you're selling digital goods. There's the added cost of a monthly fee for live processing, which can be a minor deterrent for some in the early stages of business, or so some say. It's a lot less work to have it done live than to have to process them manually later, especially if the card is declined for some reason ... the gateway would have caught that immediately and the customer would have to sort it out, rather than you having to contact them and work out other arrangements or try other cards etc etc etc.
HTH