Electronic Prescribing of Controlled Substances
The rules do not ask whether an application is convenient. They ask whether the person who signed was proven to be that person, whether two independent factors were used at the moment of signing, and whether the record shows any later change.

The rule in short
An electronic controlled substance prescription is lawful only where the practitioner has been identity proofed, holds a credential issued to that individual, and signs using two of three authentication factors. The application must meet defined processing, transmission and audit requirements, and the receiving pharmacy application must meet its own. Records must be archived in the form received, and an audit trail must capture events that could indicate a security problem.
Electronic prescribing of controlled substances is permitted, but only through a system built to a specification. The regulations do not describe a preferred workflow; they describe a chain of assurances, each of which must hold. Break any link and the resulting document is not a valid prescription, however ordinary it looks in the pharmacy's queue.
Proving who the practitioner is
The chain starts before a single prescription is written. An individual practitioner must be identity proofed by a credential service provider or certification authority that meets defined federal standards, at an assurance level appropriate to the credential being issued.
Institutional practitioners take a different route. The institution may conduct identity proofing through its credentialing office, which already holds documentation on the practitioner, and may then act as the credential issuer for its own practitioners. The obligation to separate duties applies: the person who conducts the proofing may not be the person who issues the credential in the application.
Whichever route is used, the result is a credential bound to one named individual. The practitioner must protect it and must notify the issuer promptly if it is lost, stolen or compromised. A shared credential defeats the entire structure, because the only thing the signature proves is that the credential was used.
A second control sits alongside the credential. Before a practitioner can sign in a given application, someone must grant that authority inside it, and the rules require the access control entry to be signed by two people, at least one of whom holds a registration at the location. That requirement exists so that no single person can quietly add a signer, and the entry itself becomes part of the record an audit examines.
The two factors at the moment of signing
To sign a controlled substance prescription, the application must require authentication using two of three factors: something only the practitioner knows, such as a password or a challenge response; something the practitioner is, meaning biometric data such as a fingerprint or an iris scan; and something the practitioner has, meaning a device separate from the computer being used.
Where one factor is a hard token, it must be separate from the computer it is gaining access to and must meet at least the criteria of the federal cryptographic module standard at security level one. A token embedded in the same machine does not satisfy the separation requirement, which is the point of the factor.
Where one factor is a biometric, the biometric subsystem must meet the additional requirements set out for accuracy, storage and transmission, including a false match rate ceiling and protection against the substitution of a stored template.
The authentication must happen at signing. An application that authenticates once at login and then signs an indefinite number of prescriptions on that authentication does not comply, because the assurance being purchased is that the named practitioner was present for this document.
| Stage | Who carries the obligation | What must be established |
|---|---|---|
| Identity proofing | Credential provider, certification authority or institution | That the named practitioner is who they claim to be, at the required assurance level |
| Access control setting | The registrant or institution | That signing authority was granted by two people, one of whom holds a registration |
| Signing | The individual practitioner | Two independent authentication factors, applied to this prescription |
| Transmission | The prescribing application | That the content was not altered in transit and no intermediary converted the format improperly |
| Receipt and archive | The pharmacy and its application | That the record is stored in the form received, with the digital signature retained |
What the applications themselves must do
Both ends of the transaction run on software that must meet its own requirements, verified by a third party audit or certification before the application is used for controlled substances.
The prescribing application must present the required content for review, must not permit the prescription to be signed by anyone other than the practitioner whose credential is being used, must apply the digital signature or transmit the record with the signing indication intact, and must maintain an internal audit trail. It must also be capable of limiting a practitioner's signing authority to the schedules the practitioner's registration covers.
The pharmacy application must be able to receive, process and archive the prescription. Where a prescription is received in a form that has been converted by an intermediary, the pharmacy application must be able to record that fact. The pharmacy must retain the record electronically in the form it was received, and the archived record must include the digital signature where one was applied.
A printout of an electronic prescription is a copy, not an original, and dispensing against a printout while the electronic version also sits in the queue is how duplicate fills happen. Where a prescription is printed because transmission failed, the printed document must show that it was originally transmitted electronically and identify the intended pharmacy. A pharmacy that receives such a printout should confirm the electronic version was not delivered before dispensing.
The audit trail and what it is for
Both applications must maintain an internal audit trail that records defined auditable events, and must run a daily internal audit that generates a report identifying any event indicating a possible security problem.
The events that must be captured include attempted or successful unauthorized access, attempted or successful unauthorized modification or destruction of any record or of the audit trail itself, interference with the application's operation, and any attempted or successful interference with transmission. Where the audit identifies a possible security incident, the registrant or application provider must determine whether the incident is reportable and, if so, report it.
The audit trail exists to answer a question that arises after the fact: whether the prescription in the record is the prescription that was signed. That is the same question the paper record system answers through separate filing and retention, and both regimes fail in the same way, which is silently.
Where the electronic route meets the rest of the rules
Electronic prescribing changes the medium, not the substance. A prescription signed with two factors is still ineffective unless it was issued for a legitimate medical purpose in the usual course of professional practice, so everything under the validity test for a prescription continues to apply unchanged.
Nor does it relieve the pharmacy of judgment. An electronic prescription arrives already authenticated, which removes the forgery question but leaves every other concern in place, and the flags described under the duty to resolve red flags before dispensing operate the same way whether the prescription arrived on paper or through an interface.
State law adds a further layer that federal law does not preempt. Many states require electronic prescribing for controlled substances subject to stated exceptions, and some require the pharmacy to accept an electronic prescription where one is offered. The federal rules set the floor for how the transaction is secured; the state rules frequently decide whether it must be used at all.
Points to carry away
- Identity proofing precedes everything: the credential is issued to a named practitioner and may not be shared or delegated.
- Signing requires two of three factors, one of which may be a hard token separate from the computer being used.
- A hard token must meet at least the criteria of a recognized federal cryptographic standard for security level one.
- The pharmacy application must receive, process and archive the prescription in the form in which it was transmitted.
- Both the prescribing and pharmacy applications must maintain an internal audit trail that records defined auditable events.
Questions readers ask
Can an office manager set up the credential on the practitioner's behalf?
No. Identity proofing establishes that a specific individual is who they claim to be, and the credential that follows belongs to that individual alone. The rules place the obligation on the practitioner to protect the authentication credential and to notify the credential provider promptly if it is compromised. Institutional practitioners may conduct identity proofing internally through their credentialing office, which is a different route to the same result, but the outcome is still a credential bound to one named person who must be the one to use it.
What happens if the electronic system fails partway through a transmission?
The rules anticipate this. Where a prescription cannot be delivered electronically, the practitioner may print it, but the printed copy must indicate that it was originally transmitted electronically and identify the pharmacy to which it was sent, so the pharmacy does not dispense against both. A prescription that was successfully signed but not delivered has not disappeared; the audit trail on the prescribing side will record the signature. Reissuing without accounting for the first attempt creates the risk of a duplicate dispensing.
Does electronic transmission change the content the prescription must carry?
No. The electronic prescription must contain everything a paper prescription would: the issue date, the patient's full name and address, the drug name, strength, dosage form and quantity, the directions for use, and the practitioner's name, address and registration number. What changes is how the document is authenticated and stored. The signature requirement is met by the digital signing process rather than by ink, and the archive requirement replaces the filing cabinet with an electronic record that must be retained in its received form.
Sources
- 21 CFR § 1311.105 — Obtaining an authentication credentialSets identity proofing and credential issuance for individual practitioners.
- 21 CFR § 1311.115 — Additional requirements for two-factor authenticationStates the three factors, the two-of-three rule and the hard token standard.
- 21 CFR § 1311.116 — Additional requirements for biometricsSets accuracy, liveness and storage requirements where a biometric is used.
- 21 CFR § 1311.120 — Electronic prescription application requirementsLists what the prescribing application must do before it may be used.
- 21 CFR § 1311.200 — Pharmacy responsibilitiesPlaces the duty on the pharmacy to use a compliant application and archive the record.
- 21 CFR § 1311.215 — Internal audit trailRequires the pharmacy application to record auditable events and generate reports.
- DEA Diversion Control Division — Electronic PrescriptionsThe agency's collected guidance and rulemaking materials on electronic prescribing.
Metro Law Advisors is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Pharmacy & Controlled Substances
Registering to Handle Controlled Substances
Federal law requires a separate registration for each principal place of business where controlled substances are manufactured, distributed or dispensed, and a separate registration for each independent group of activities. A practitioner registration depends on state authority to dispense: when the state license ends, the federal authority it rests on ends with it. Registrations expire on assigned cycles and must be modified when the address or the schedules handled change.
The Drug Schedules and What Each One Restricts
Congress set five schedules and gave the Attorney General authority to add, remove or move substances after a scientific and medical evaluation. Each placement rests on findings about abuse potential, accepted medical use and the dependence a substance produces. The schedule then determines the ordering, prescribing, refill, storage and recordkeeping rules that apply, and a change in schedule changes all of them at once.
Refills, Transfers and Partial Fills by Schedule
Schedule II prescriptions may not be refilled and their partial fills run on tight deadlines measured from the prescription or the first fill. Schedules III and IV permit up to five refills within six months of issue, and refill information may be transferred between pharmacies once unless they share a real-time database. Every partial fill and refill generates a record entry, and the total dispensed can never exceed the quantity prescribed.


