HomeFrameworksHealthcare & Human ServicesDEA EPCS

Framework  Healthcare & Human Services

DEA EPCS

The DEA's Electronic Prescriptions for Controlled Substances rule, 21 CFR Part 1311, sets the conditions under which practitioners may sign and transmit controlled substance prescriptions electronically and pharmacies may receive and store them.

The rule places requirements on three parties: the software applications (which must pass a third-party audit or certification), the prescribers (identity proofing, two-factor authentication credentials, and logical access controls that require two people to grant signing rights), and the pharmacies (application requirements, record retention, and audit logs).

Many states now mandate electronic prescribing of controlled substances, and Medicare Part D requires it, which makes EPCS effectively universal.

In writing, an application provider needs the audit or certification report showing the application meets Part 1311 and must make it available to users, repeated at least every two years or whenever relevant functionality changes.

A prescribing practice or pharmacy needs its identity proofing and credentialing records, the access control setup records signed by the two authorizing individuals, procedures for reporting lost credentials and security incidents to DEA, and retained audit trails and daily incident reports.

AI-compiled
Share
Sponsored
DEA
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with DEA EPCS
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Electronic prescribing application providers and pharmacy application providers; DEA-registered practitioners who prescribe controlled substances electronically; pharmacies that receive electronic controlled substance prescriptions. State e-prescribing mandates and the Medicare Part D EPCS requirement drive adoption.

What the assessor asks to see

An auditor or DEA investigator asks for the application's current audit or certification report and the changes since it was issued, identity proofing and credential issuance records, the two-person access control authorization records, two-factor authentication configuration, audit trail and daily internal audit reports, procedures and records for reporting lost credentials and security incidents to DEA within one business day, prescription transmission and archive records, and the pharmacy's record retention and backup practices.

Where the requirement sits: 21 CFR 1311

Assessors

Who assesses DEA EPCS

For applications, either a third-party audit by a person qualified to perform SysTrust, WebTrust, or SAS 70 style engagements (now SOC) or by a Certified Information Systems Auditor who performs compliance audits as a regular business, or certification by an organization DEA has approved.

Practitioners and pharmacies are not separately certified but are subject to DEA inspection and enforcement. Accredited by DEA approves certifying organizations for the certification route (verify the current list with DEA; no public registry is maintained on the DEA site). Auditors under the audit route are qualified by their professional credentials rather than DEA approval.

No firm has claimed a DEA EPCS assessor listing yet. Claim yours →

Consultants

Who helps with DEA EPCS

EHR and e-prescribing vendors handle most implementation; certification and audit firms serve the vendors. For practices, the work is mostly enrollment through the vendor's identity proofing partner and setting up two-factor credentials and access controls.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a DEA EPCS consultant listing yet. Claim yours →

Software

Tools for DEA EPCS

Tools that name this framework in their own material.

No firm has claimed a DEA EPCS tool listing yet. Claim yours →

Related reading

  1. Electronic Prescribing of Controlled Substances ComplianceSets out the three duties 21 CFR Part 1311 puts on a pharmacy: verifying the identity-proofed credential, two-factor signing, and the internal audit trail.Health Law Alliance

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for DEA EPCS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with DEA EPCS

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.