7.3 Electronic Prescriptions for Controlled Substances (EPCS) & Security Requirements

Key Takeaways

  • DEA EPCS regulations (21 CFR Part 1311) mandate two-factor authentication (2FA) for prescribers using two of three factors: something you know, something you have, and something you are.
  • Identity proofing (IDP) must be performed by a DEA-approved Credential Service Provider at NIST SP 800-63 Assurance Level 3 (AL3) before issuing EPCS signing credentials.
  • Prescribing and pharmacy e-dispensing software must undergo independent third-party audit or certification to process EPCS orders lawfully.
  • Electronic controlled substance prescription records must be digitally archived by the pharmacy for a minimum retention period of 2 years federally.
  • Computer-generated faxes do not meet EPCS criteria; if an EPCS transmission fails, a replacement paper prescription must explicitly state that the electronic transmission failed.
Last updated: July 2026

Electronic Prescriptions for Controlled Substances (EPCS) represent the modern standard for controlled substance prescribing in the United States. Promulgated by the DEA under 21 CFR Part 1311, EPCS regulations permit practitioners to write and electronically transmit controlled substance prescriptions (Schedules II through V) while eliminating paper prescription forgery, alteration, and stolen prescription pads. However, to maintain legal validity, both prescribing systems and pharmacy dispensing systems must strictly adhere to complex technical, cryptographic, and security standards.

Mandatory Two-Factor Authentication (2FA) for Prescribers

Under 21 CFR § 1311.116, a practitioner is strictly prohibited from signing an electronic controlled substance prescription unless they utilize a compliant Two-Factor Authentication (2FA) protocol. The 2FA requirement mandates the use of two out of three independent credential factors:

  1. Something You Know: Knowledge factor (e.g., a secure password, PIN, or response to a cryptographic challenge).
  2. Something You Have: Hard token factor separate from the computer (e.g., a cryptographic hardware token, USB key, or one-time password [OTP] mobile generator app).
  3. Something You Are: Biometric factor unique to the individual (e.g., fingerprint scan, iris scan, or facial recognition).

Critical Regulatory Rule: Using two instances of the same factor (e.g., two separate passwords) is INVALID. The two factors must belong to distinct categories (e.g., Password + Hardware OTP Token, or Password + Biometric Fingerprint).


Identity Proofing (IDP) Protocols & NIST AL3 Standards

Before a practitioner can be issued EPCS signing credentials or granted logical access to sign EPCS orders, their identity must be conclusively established through formal Identity Proofing (IDP).

Requirements for Identity Proofing

  • Conducting Entity: Must be performed by an independent, DEA-approved Credential Service Provider (CSP) or Certification Authority (CA).
  • Assurance Standard: IDP must meet NIST SP 800-63 Assurance Level 3 (AL3) standards.
  • Verification Methods:
    • In-Person Processing: Practitioner presents government-issued photo identification and state medical license credentials to a qualified CSP agent.
    • Remote Processing: CSP utilizes financial history verification, credit bureau data, identity checks, and hard-copy credential mailing to confirm practitioner identity.

Once IDP is complete, the CSP issues the practitioner their 2FA credential token and digital certificate.


Logical Access Controls & Institutional Management

At the clinical site or institutional level (e.g., hospital EHR systems), access to the EPCS signing functionality is governed by strict Logical Access Controls (21 CFR § 1311.105):

  • Access authorization requires two distinct individuals to activate EPCS privileges for a prescriber.
  • Individual 1: A DEA-registered practitioner (who checks medical license and DEA status).
  • Individual 2: An authorized system administrator (who assigns software access rights).
  • This dual-control requirement prevents a single rouge administrator or practitioner from fraudulently enabling EPCS signing permissions.

Pharmacy E-Dispensing System Requirements & Record Archival

Pharmacies cannot simply receive electronic orders via standard email or fax. A pharmacy application processing EPCS must meet explicit federal criteria under 21 CFR § 1311.205:

Mandatory Pharmacy Application Controls

  1. Third-Party Audit & Certification: The pharmacy e-dispensing software must obtain a formal third-party audit or certification report confirming compliance with DEA 21 CFR Part 1311 rules.
  2. Digital Signature Verification: The system must automatically verify the digital signature binding of the prescriber's EPCS file upon receipt.
  3. Automated Flagging: The software must flag and halt processing if required elements (e.g., DEA number, patient address, digital signature hash) are missing or corrupted.
  4. Transmission Medium: Transmission must be direct electronic-to-electronic. Computer-generated faxes of electronic prescriptions are strictly prohibited as EPCS orders (they fail digital signature verification).
  5. Record Archival & Retention: All electronic controlled substance prescription records, audit trails, and dispensing histories must be digitally archived for a minimum of 2 years federally (many state laws require 5 to 10 years). Archives must be readily retrievable and backed up daily.

EPCS vs. Paper vs. Fax Regulatory Comparison

Regulatory DimensionEPCS (Electronic)Written (Paper)Faxed Prescriptions
Governing DEA Rule21 CFR Part 131121 CFR § 1306.0521 CFR § 1306.11
AuthenticationDual-Factor (2FA) + NIST AL3 IDPManual Wet Ink SignatureManual Wet Ink Signature
Schedules AllowedC-II, C-III, C-IV, C-VC-II, C-III, C-IV, C-VC-III–V (C-II only for LTCF, Hospice, Parenteral Compounding)
System RequirementCertified EPCS Software AuditSecurity Paper (State specific)Direct Fax Machine Transmission
Federal Retention2 Years (Electronic Format)2 Years (Hardcopy Format)2 Years (Hardcopy Format)

Handling EPCS Transmission Failures & Paper Conversions

If a practitioner attempts to transmit an EPCS prescription but the electronic transmission fails (e.g., network outage or system rejection), specific conversion protocols apply under 21 CFR § 1311.102(c):

  1. Paper Replacement Requirement: The practitioner may print a paper prescription, which must be manually signed in wet ink.
  2. Mandatory Annotation: The paper replacement MUST explicitly state that the prescription was originally attempted via EPCS, noting the specific pharmacy destination, date, time, and confirmation of electronic transmission failure.
  3. Pharmacist Verification Protocol: Upon receipt of such a paper prescription, the pharmacist MUST access the pharmacy electronic system to verify that the EPCS order was not received and dispensed previously. If the EPCS was received, the paper copy must be voided. If the EPCS was not received, the pharmacist may dispense the paper copy and void any late-arriving EPCS order.
Loading diagram...
EPCS End-to-End Authentication & E-Dispensing Workflow
Test Your Knowledge

Under 21 CFR § 1311.116, which credential combination satisfies the mandatory Two-Factor Authentication (2FA) requirement for a practitioner signing an EPCS prescription?

A
B
C
D
Test Your Knowledge

What is the minimum federal NIST Identity Proofing (IDP) assurance level required for a Credential Service Provider before issuing EPCS signing credentials to a practitioner?

A
B
C
D
Test Your Knowledge

Under federal EPCS regulations (21 CFR § 1311.205), what is the minimum required retention period for electronic controlled substance prescription records archived by a pharmacy?

A
B
C
D
Test Your Knowledge

An EPCS transmission for a Schedule II drug fails due to a network error. The physician prints a paper hardcopy, signs it in wet ink, annotates that electronic transmission failed, and gives it to the patient. Upon presentation, what must the pharmacist do before dispensing?

A
B
C
D