What It Is

EPCS is not a general privacy or security framework. It is a specific set of technical and procedural requirements covering:

  • Who is allowed to sign a controlled substance prescription
  • How that person's identity is verified
  • How they authenticate when signing
  • Which software may be used
  • What records must be kept - and for how long

Unlike HIPAA, which asks for "reasonable and appropriate" safeguards, EPCS is prescriptive. Specific controls are named.

HIPAA protects the data. EPCS proves the prescriber.

One scoping note: the DEA rules do not force anyone to prescribe electronically - they set the conditions for doing it. The mandates come from elsewhere. The SUPPORT Act (§2003, P.L. 115-271) requires electronic prescribing of Schedule II-V controlled substances covered under Medicare Part D, and state law adds its own layer - Florida's is covered below.

What Information Is Regulated

EPCS scope covers the systems and records that establish who signed what:

  • Prescriber identity and credentialing records
  • DEA registration information
  • Authentication credentials and hard tokens
  • Controlled substance prescription records
  • Prescription transmission logs and audit trails
  • The EHR or e-prescribing application itself
  • Any system with administrative access to prescribing functions

Records required under the DEA rules must be retained electronically for two years from creation or receipt (21 CFR 1311.305).

IT Requirements

The controls are named in 21 CFR Part 1311, Subpart C.

Identity proofing of prescribers: identity must be verified before signing authority is granted - and the rule specifies how. Individual practitioners must be identity-proofed by a federally approved credential service provider or a certification authority cross-certified with the Federal Bridge, at NIST SP 800-63-1 Assurance Level 3 or above (§1311.105). Institutional practitioners may conduct identity proofing in-house through their credentialing office, verifying government-issued photo ID, state licensure, and DEA registration (§1311.110).

Two-factor authentication for signing: signing requires two of three factors (§1311.115): something you know (password or PIN), something you have (a hard token - a FIPS 140-2 validated cryptographic or one-time-password device that is separate from the computer being used to sign; a separate mobile device can serve this role if it meets those criteria), or something you are (biometric). The two factors must be presented at the point of signing, not just at login - completing the two-factor protocol while the prescription is displayed is what legally constitutes signing it (§1311.140).

Approved software: the e-prescribing application must pass a third-party audit or DEA-approved certification before initial use, and again whenever functionality is altered or every two years, whichever comes first (§1311.300). Auditors must be qualified - CISAs or persons qualified for SysTrust/WebTrust-type engagements performing compliance audits as a regular business activity. If an application fails its audit, it may not be used: the provider must notify the DEA within one business day and users within five business days. Not every EHR with an e-prescribing module qualifies.

Logical access controls and separation of duties: granting or revoking EPCS signing authority requires at least two individuals - one entering the permission data, a second authenticating to execute it (§§1311.125-130). One administrator cannot unilaterally grant themselves or others prescribing rights.

Audit trails and reporting: systems must log auditable events, retain those logs, and produce reviewable reports for certain events.

Credential and token management: tokens and credentials must be issued to and controlled by the individual prescriber, never shared, and revoked promptly on role change or departure (§1311.115(c)).

How It Fits Into Cyber Risk Management

EPCS controls are identity and access management with a federal rulebook. The same disciplines a cyber risk program builds everywhere - identity proofing, MFA, least privilege, separation of duties, log review, timely deprovisioning - are here as named legal requirements.

A practice that runs EPCS well usually runs security well. The reverse is also true, and it shows up in audits.

How We Help With EPCS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment verifies your EPCS controls against 21 CFR Part 1311 by name - identity proofing records, two-factor signing, access authorization, audit cadence, and token management.

How to Prepare

  1. Confirm your e-prescribing software qualifies

    Verify the application has passed its DEA-required third-party audit or certification, that the two-year recertification cycle is current, and that vendor documentation proves it (§1311.300).

  2. Document identity proofing for every prescriber

    Every prescriber with signing authority needs a documented identity-proofing record - through an approved credential service provider for individual practitioners, or through institutional credentialing for hospital and health system prescribers (§§1311.105-110).

  3. Validate two-factor authentication

    Confirm both factors are required at signing, the possession factor is a FIPS 140-2 validated hard token separate from the signing computer, tokens are individually issued, and nothing is shared (§§1311.115, 1311.140).

  4. Review access granting and revocation

    Verify the two-individual rule is enforced for granting signing authority, and that access is revoked promptly on role change or departure (§§1311.125-130).

  5. Enable and review audit logs

    Confirm auditable events are logged, retained for at least the two-year record requirement, and reviewed on a documented cadence (§§1311.300-305).

  6. Train prescribers and staff

    Users should understand why EPCS controls exist, how to use authentication correctly, how to report suspicious activity, and their responsibility in protecting prescribing systems.

Official source

Official source: DEA Diversion Control Division, DOJ

Secondary source: eCFR - 21 CFR Part 1311

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25