Electronic Prescriptions for Controlled Substances (EPCS) Explained

EPCS (Electronic Prescriptions for Controlled Substances) refers to the DEA requirements that govern how controlled substance prescriptions may be issued, signed, and transmitted electronically (21 CFR Part 1311).

EPCS exists because controlled substance prescriptions are a fraud and diversion target. Paper prescriptions can be forged, altered, and stolen. Electronic prescribing removes those risks - but only if the systems issuing them can prove the prescriber is who they claim to be.

If your organization prescribes controlled substances, operates an EHR or e-prescribing platform, or supports healthcare providers who do, EPCS requirements apply to your systems and your identity controls.

What It Is

EPCS is not a general privacy or security framework. It is a specific set of technical and procedural requirements covering:

  • Who is allowed to sign a controlled substance prescription
  • How that person's identity is verified
  • How they authenticate when signing
  • Which software may be used
  • What records must be kept - and for how long

Unlike HIPAA, which asks for "reasonable and appropriate" safeguards, EPCS is prescriptive. Specific controls are named.

HIPAA protects the data. EPCS proves the prescriber.

One scoping note: the DEA rules do not force anyone to prescribe electronically - they set the conditions for doing it. The mandates come from elsewhere. The SUPPORT Act (§2003, P.L. 115-271) requires electronic prescribing of Schedule II-V controlled substances covered under Medicare Part D, and state law adds its own layer - Florida's is covered below.

Who It Applies To

Prescribers and practices: physicians, NPs, PAs, and other DEA-registered practitioners; medical practices and clinics; behavioral health and addiction treatment providers; opioid treatment programs; hospitals and health systems.

Pharmacies: retail, hospital, and mail-order pharmacies receiving electronic controlled substance prescriptions.

Technology and service providers: EHR and e-prescribing platform vendors; health IT and integration providers; cloud and hosting providers supporting prescribing systems; MSPs and IT providers supporting practices that prescribe.

The mandate layer, for context:

  • Medicare Part D: CMS measures compliance annually under its EPCS Program. A prescriber is compliant at a 70 percent or higher e-prescribing rate for qualifying Part D controlled substance prescriptions, with automatic exceptions for prescribers issuing 100 or fewer qualifying prescriptions a year and for declared emergencies. Waivers are available; non-compliance draws CMS notices.
  • Florida: F.S. 456.42 requires prescribers who maintain an electronic health record system to e-prescribe medicinal drugs generally - not just controlled substances - with enumerated exceptions such as technical infeasibility, hardship waivers, and hospice or nursing home settings. Florida's mandate is broader than EPCS and conditioned on EHR use.
  • Other states: mandates vary in scope and exceptions. Verify the rules in each state where your prescribers practice before relying on a general claim.

What Information Is Regulated

EPCS scope covers the systems and records that establish who signed what:

  • Prescriber identity and credentialing records
  • DEA registration information
  • Authentication credentials and hard tokens
  • Controlled substance prescription records
  • Prescription transmission logs and audit trails
  • The EHR or e-prescribing application itself
  • Any system with administrative access to prescribing functions

Records required under the DEA rules must be retained electronically for two years from creation or receipt (21 CFR 1311.305).

Relation to Other Frameworks

EPCS sits inside the broader healthcare compliance stack:

  • HIPAA and HITECH protect the confidentiality and security of health information generally.
  • ONC Health IT Certification certifies that the software supports required capabilities.
  • 42 CFR Part 2 adds stricter consent and disclosure rules where substance use disorder treatment is involved.
  • State prescribing laws and PDMP requirements layer additional obligations on top.

A practice can be HIPAA compliant and still fail EPCS, because EPCS asks a different question: can you prove the person who signed this prescription was actually the prescriber?

IT Requirements

The controls are named in 21 CFR Part 1311, Subpart C.

Identity proofing of prescribers: identity must be verified before signing authority is granted - and the rule specifies how. Individual practitioners must be identity-proofed by a federally approved credential service provider or a certification authority cross-certified with the Federal Bridge, at NIST SP 800-63-1 Assurance Level 3 or above (§1311.105). Institutional practitioners may conduct identity proofing in-house through their credentialing office, verifying government-issued photo ID, state licensure, and DEA registration (§1311.110).

Two-factor authentication for signing: signing requires two of three factors (§1311.115): something you know (password or PIN), something you have (a hard token - a FIPS 140-2 validated cryptographic or one-time-password device that is separate from the computer being used to sign; a separate mobile device can serve this role if it meets those criteria), or something you are (biometric). The two factors must be presented at the point of signing, not just at login - completing the two-factor protocol while the prescription is displayed is what legally constitutes signing it (§1311.140).

Approved software: the e-prescribing application must pass a third-party audit or DEA-approved certification before initial use, and again whenever functionality is altered or every two years, whichever comes first (§1311.300). Auditors must be qualified - CISAs or persons qualified for SysTrust/WebTrust-type engagements performing compliance audits as a regular business activity. If an application fails its audit, it may not be used: the provider must notify the DEA within one business day and users within five business days. Not every EHR with an e-prescribing module qualifies.

Logical access controls and separation of duties: granting or revoking EPCS signing authority requires at least two individuals - one entering the permission data, a second authenticating to execute it (§§1311.125-130). One administrator cannot unilaterally grant themselves or others prescribing rights.

Audit trails and reporting: systems must log auditable events, retain those logs, and produce reviewable reports for certain events.

Credential and token management: tokens and credentials must be issued to and controlled by the individual prescriber, never shared, and revoked promptly on role change or departure (§1311.115(c)).

Why It Matters

An application that fails its required audit or certification cannot be used for controlled substance prescribing - full stop, with DEA notification on a one-business-day clock (21 CFR 1311.300). Broader failures can bring DEA enforcement, state licensing consequences, and - where diversion occurs - criminal exposure.

Most failures are operational, not technical: shared credentials or tokens; administrators granting themselves signing rights; identity proofing skipped or undocumented; departed prescribers whose access was never revoked; audit logs enabled but never reviewed.

Every one of those is checkable, and every one is fixable before the DEA or a state board finds it first.

How It Fits Into Cyber Risk Management

EPCS controls are identity and access management with a federal rulebook. The same disciplines a cyber risk program builds everywhere - identity proofing, MFA, least privilege, separation of duties, log review, timely deprovisioning - are here as named legal requirements.

A practice that runs EPCS well usually runs security well. The reverse is also true, and it shows up in audits.

How We Help With EPCS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment verifies your EPCS controls against 21 CFR Part 1311 by name - identity proofing records, two-factor signing, access authorization, audit cadence, and token management.

How to Prepare

  1. 01Confirm your e-prescribing software qualifies

    Verify the application has passed its DEA-required third-party audit or certification, that the two-year recertification cycle is current, and that vendor documentation proves it (§1311.300).

  2. 02Document identity proofing for every prescriber

    Every prescriber with signing authority needs a documented identity-proofing record - through an approved credential service provider for individual practitioners, or through institutional credentialing for hospital and health system prescribers (§§1311.105-110).

  3. 03Validate two-factor authentication

    Confirm both factors are required at signing, the possession factor is a FIPS 140-2 validated hard token separate from the signing computer, tokens are individually issued, and nothing is shared (§§1311.115, 1311.140).

  4. 04Review access granting and revocation

    Verify the two-individual rule is enforced for granting signing authority, and that access is revoked promptly on role change or departure (§§1311.125-130).

  5. 05Enable and review audit logs

    Confirm auditable events are logged, retained for at least the two-year record requirement, and reviewed on a documented cadence (§§1311.300-305).

  6. 06Train prescribers and staff

    Users should understand why EPCS controls exist, how to use authentication correctly, how to report suspicious activity, and their responsibility in protecting prescribing systems.

Frequently Asked Questions

Does EPCS apply to my practice?

If anyone in your organization prescribes controlled substances electronically, yes - the DEA rules govern how that must work. If you prescribe Medicare Part D controlled substances, CMS expects you to e-prescribe them at a 70 percent or higher rate. And in Florida, maintaining an EHR triggers a broader e-prescribing requirement under F.S. 456.42.

What happens if we're not compliant?

The sharpest consequence is losing the ability to e-prescribe: an application that fails its required audit cannot be used, with DEA notification within one business day. Beyond that, failures can bring DEA enforcement, state licensing consequences, and criminal exposure where diversion occurs. Operational gaps - shared tokens, unrevoked access - are what auditors find first.

How long does it take to get EPCS-ready?

For most practices the controls already exist in the software - the work is verification and cleanup: identity-proofing records, token issuance, access reviews, log cadence. That typically fits inside our standard 2 to 4 week assessment, with remediation scheduled by priority afterward.

What does EPCS compliance cost?

It depends on the number of prescribers, systems, and gaps involved. You get a firm quote after the assessment; the conversation costs nothing.

We already have an IT provider. Do we still need this?

EPCS failures are usually process failures your IT provider was never asked to own - identity proofing documentation, the two-individual access rule, token lifecycle, audit review cadence. We verify those against the regulation itself and work co-managed with your existing provider on fixes.

What's the difference between EPCS and HIPAA?

HIPAA protects the data; EPCS proves the prescriber. HIPAA asks for reasonable and appropriate safeguards and lets you decide how. EPCS names its controls: approved software, formal identity proofing, a FIPS-validated hard token at signing, two-person access authorization, and two-year record retention.

Can we handle EPCS ourselves?

Much of it, yes - the rule is prescriptive enough to be a checklist. The failure mode is assuming the EHR vendor handled everything. The vendor certifies the software; identity proofing, token management, access control, and log review are on your side of the line. Our DIY-with-support tier backs your team on exactly those items.

Where do we start?

Start with the two questions auditors ask: is your software's certification current, and can you produce identity-proofing and access records for every prescriber? Our Cyber Risk & Compliance Gap Assessment answers both and checks the rest of the Part 1311 controls by name. No pressure. No jargon. Just clear insights and your best next steps.

Official source

Official source: DEA Diversion Control Division, DOJ

Secondary source: eCFR - 21 CFR Part 1311

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25