Guides

Electronic Prescribing of Controlled Substances (EPCS): A Practice Guide

Electronic prescribing of controlled substances follows different rules from ordinary e-prescribing. The Drug Enforcement Administration permits it only when the software has been certified against a specific set of requirements and the prescriber has completed identity proofing and uses two-factor authentication to sign each prescription. Medicare and most states now require it for at least some controlled substance prescriptions. This guide explains what the EHR must provide, what the practice must do, and how to set it up without tripping over the details.

What EPCS is and who requires it

EPCS is the transmission of a prescription for a Schedule II through V controlled substance from the prescriber's software to the pharmacy electronically. The DEA's interim final rule, codified at 21 CFR Part 1311, sets the conditions under which that is lawful. Separately, federal law requires that prescriptions for controlled substances covered under Medicare Part D be transmitted electronically, with limited exceptions, and CMS enforces this through a compliance program. Many states have their own mandates, some broader than the federal one, and several require electronic prescribing of all prescriptions. A practice should confirm the current requirement in each state where its prescribers hold licenses.

What the EHR must have

The DEA rule does not certify software itself; it requires that the application be audited or certified by a qualified third party against the rule's functional requirements, and that the practice retain the audit or certification report. The main requirements the EHR must meet are as follows.

  • Two-factor authentication for signing, using two of three factor types: something the prescriber knows, something the prescriber has, and something the prescriber is. The "has" factor must be a hard token separate from the computer or a cryptographic module meeting a federal standard; a biometric may substitute.
  • Logical access controls that restrict the signing function to prescribers whose DEA registration has been verified, set through a two-person process.
  • A record of the prescription that includes the required contents, the signing timestamp, and an indication that the prescriber signed it, with a digital signature or secure transmission to the pharmacy.
  • An internal audit trail that records every access to and change of controlled substance prescriptions and the access control settings, protected from alteration.
  • Daily internal audit that identifies auditable events, such as attempts to bypass authentication, and a report to the practice for review.
  • A display, at signing, of the prescription information the prescriber is attesting to, and a statement the prescriber affirms.

Most major EHRs meet these requirements through a partnership with an e-prescribing network and an identity provider, and the vendor's certification report is what a practice should request and file.

What the prescriber must do

Before a prescriber can sign electronically, two things must happen. The prescriber's identity must be proofed by an approved credential service provider or certification authority at a defined assurance level; this typically involves submitting government identification and answering knowledge-based questions or completing a video verification. The prescriber must then obtain the two-factor credential, usually an authenticator application on a phone or a hardware token, bound to the proofed identity. The DEA registration and any state controlled substance registration must be current, and the practice's access control process must verify them before granting signing rights.

Logical access controls and the two-person rule

The rule requires that setting or changing which users may sign controlled substance prescriptions be done by two people. One, who must be a registrant or an individual designated by the practice, enters the data; a second, who must be a DEA registrant with EPCS authority, approves it using their two-factor credential. This prevents a single administrator from granting signing rights to an unauthorized user. Practices with only one prescriber still need a second person to enter the request; the prescriber then approves their own access.

Keep a written record of every access control change: who requested it, who approved it, and when. The EHR logs it, but an auditor will ask for the practice's own process documentation as well.

Signing a controlled substance prescription

  1. The prescriber creates the prescription in the EHR with all required elements, including the patient's full name and address, drug, strength, dosage form, quantity, directions, refills where permitted, and the prescriber's DEA number.
  2. Where required, the prescriber reviews the state prescription drug monitoring program report; many EHRs integrate this check into the workflow.
  3. The EHR displays the prescription for review and the attestation statement.
  4. The prescriber completes two-factor authentication: typically the EHR password plus a code or push approval from the authenticator.
  5. The prescription is digitally signed, transmitted through the e-prescribing network, and recorded with the signing timestamp.

Only the prescriber may complete the two-factor step. Delegating the token or the authenticator to staff violates the rule and is treated the same as sharing a signature stamp.

Audits, reports, and incident duties

The rule assigns continuing duties. The practice must review the daily audit report the EHR generates and investigate any auditable event. If a prescriber's token is lost or credential compromised, the prescriber must notify the practice and the credential provider, and the practice must disable the credential within a defined short period. If the practice discovers that a controlled substance prescription was issued without the prescriber's knowledge or the two-factor step was bypassed, it must report the incident to the DEA within one business day. The EHR vendor, for its part, must notify customers of any software problem that could affect these controls. Records of prescriptions, audit trails, and access control changes must be retained for at least two years.

A setup checklist

  • Obtain and file the EHR's third-party EPCS certification or audit report.
  • Verify each prescriber's DEA and state registrations and record them in the EHR profile.
  • Complete identity proofing and credential enrollment for each prescriber.
  • Run the two-person access control process and document it.
  • Configure PDMP integration if available and required in your state.
  • Assign an owner for the daily audit report review and document the review.
  • Write a short policy covering token custody, lost credentials, incident reporting, and the prohibition on delegation.
  • Test with a prescription to a test pharmacy before going live.

EPCS is more procedural than technical for the practice. The EHR carries the cryptography; the practice carries the identity, access, and review obligations. A half day of setup and a standing weekly audit review are what keep it compliant.

Common questions

Is EPCS mandatory?

Federal law requires electronic prescribing of controlled substances covered under Medicare Part D, with limited exceptions, and many states mandate it more broadly. Check the current requirements for each state where your prescribers practice; the DEA rule itself permits EPCS but the mandates come from CMS and the states.

Can a nurse or medical assistant enter the two-factor code for the prescriber?

No. The two-factor authentication must be performed by the prescriber personally. Staff may prepare the prescription for review, but only the prescriber may complete the signing step, and sharing tokens or authenticators violates the DEA rule.

What happens if a prescriber loses their hardware token or phone?

The prescriber must promptly notify the practice and the credential service provider, and the credential must be disabled. Once a replacement credential is bound to the prescriber's proofed identity, signing rights are restored through the access control process.

How long must EPCS records be kept?

The DEA rule requires the practice to retain the prescription records, audit trail data, access control records, and the software certification report for at least two years. State law and general medical record retention rules may require longer.