EPCS (Electronic Prescriptions for Controlled Substances) refers to the DEA requirements that govern how controlled substance prescriptions may be issued, signed, and transmitted electronically (21 CFR Part 1311).
EPCS exists because controlled substance prescriptions are a fraud and diversion target. Paper prescriptions can be forged, altered, and stolen. Electronic prescribing removes those risks - but only if the systems issuing them can prove the prescriber is who they claim to be.
If your organization prescribes controlled substances, operates an EHR or e-prescribing platform, or supports healthcare providers who do, EPCS requirements apply to your systems and your identity controls.
EPCS is not a general privacy or security framework. It is a specific set of technical and procedural requirements covering:
Unlike HIPAA, which asks for "reasonable and appropriate" safeguards, EPCS is prescriptive. Specific controls are named.
HIPAA protects the data. EPCS proves the prescriber.
One scoping note: the DEA rules do not force anyone to prescribe electronically - they set the conditions for doing it. The mandates come from elsewhere. The SUPPORT Act (§2003, P.L. 115-271) requires electronic prescribing of Schedule II-V controlled substances covered under Medicare Part D, and state law adds its own layer - Florida's is covered below.
Prescribers and practices: physicians, NPs, PAs, and other DEA-registered practitioners; medical practices and clinics; behavioral health and addiction treatment providers; opioid treatment programs; hospitals and health systems.
Pharmacies: retail, hospital, and mail-order pharmacies receiving electronic controlled substance prescriptions.
Technology and service providers: EHR and e-prescribing platform vendors; health IT and integration providers; cloud and hosting providers supporting prescribing systems; MSPs and IT providers supporting practices that prescribe.
The mandate layer, for context:
EPCS scope covers the systems and records that establish who signed what:
Records required under the DEA rules must be retained electronically for two years from creation or receipt (21 CFR 1311.305).
EPCS sits inside the broader healthcare compliance stack:
A practice can be HIPAA compliant and still fail EPCS, because EPCS asks a different question: can you prove the person who signed this prescription was actually the prescriber?
The controls are named in 21 CFR Part 1311, Subpart C.
Identity proofing of prescribers: identity must be verified before signing authority is granted - and the rule specifies how. Individual practitioners must be identity-proofed by a federally approved credential service provider or a certification authority cross-certified with the Federal Bridge, at NIST SP 800-63-1 Assurance Level 3 or above (§1311.105). Institutional practitioners may conduct identity proofing in-house through their credentialing office, verifying government-issued photo ID, state licensure, and DEA registration (§1311.110).
Two-factor authentication for signing: signing requires two of three factors (§1311.115): something you know (password or PIN), something you have (a hard token - a FIPS 140-2 validated cryptographic or one-time-password device that is separate from the computer being used to sign; a separate mobile device can serve this role if it meets those criteria), or something you are (biometric). The two factors must be presented at the point of signing, not just at login - completing the two-factor protocol while the prescription is displayed is what legally constitutes signing it (§1311.140).
Approved software: the e-prescribing application must pass a third-party audit or DEA-approved certification before initial use, and again whenever functionality is altered or every two years, whichever comes first (§1311.300). Auditors must be qualified - CISAs or persons qualified for SysTrust/WebTrust-type engagements performing compliance audits as a regular business activity. If an application fails its audit, it may not be used: the provider must notify the DEA within one business day and users within five business days. Not every EHR with an e-prescribing module qualifies.
Logical access controls and separation of duties: granting or revoking EPCS signing authority requires at least two individuals - one entering the permission data, a second authenticating to execute it (§§1311.125-130). One administrator cannot unilaterally grant themselves or others prescribing rights.
Audit trails and reporting: systems must log auditable events, retain those logs, and produce reviewable reports for certain events.
Credential and token management: tokens and credentials must be issued to and controlled by the individual prescriber, never shared, and revoked promptly on role change or departure (§1311.115(c)).
An application that fails its required audit or certification cannot be used for controlled substance prescribing - full stop, with DEA notification on a one-business-day clock (21 CFR 1311.300). Broader failures can bring DEA enforcement, state licensing consequences, and - where diversion occurs - criminal exposure.
Most failures are operational, not technical: shared credentials or tokens; administrators granting themselves signing rights; identity proofing skipped or undocumented; departed prescribers whose access was never revoked; audit logs enabled but never reviewed.
Every one of those is checkable, and every one is fixable before the DEA or a state board finds it first.
EPCS controls are identity and access management with a federal rulebook. The same disciplines a cyber risk program builds everywhere - identity proofing, MFA, least privilege, separation of duties, log review, timely deprovisioning - are here as named legal requirements.
A practice that runs EPCS well usually runs security well. The reverse is also true, and it shows up in audits.
EPCS is the one healthcare requirement where "reasonable effort" isn't the standard. Most healthcare regulations ask whether safeguards were appropriate to the risk.
EPCS names specific controls and expects them to be in place. The rule even defines the act of signing: two factors, presented while the prescription is on screen.
That precision cuts both ways - compliance is unambiguous, and so is non-compliance.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment verifies your EPCS controls against 21 CFR Part 1311 by name - identity proofing records, two-factor signing, access authorization, audit cadence, and token management.
Verify the application has passed its DEA-required third-party audit or certification, that the two-year recertification cycle is current, and that vendor documentation proves it (§1311.300).
Every prescriber with signing authority needs a documented identity-proofing record - through an approved credential service provider for individual practitioners, or through institutional credentialing for hospital and health system prescribers (§§1311.105-110).
Confirm both factors are required at signing, the possession factor is a FIPS 140-2 validated hard token separate from the signing computer, tokens are individually issued, and nothing is shared (§§1311.115, 1311.140).
Verify the two-individual rule is enforced for granting signing authority, and that access is revoked promptly on role change or departure (§§1311.125-130).
Confirm auditable events are logged, retained for at least the two-year record requirement, and reviewed on a documented cadence (§§1311.300-305).
Users should understand why EPCS controls exist, how to use authentication correctly, how to report suspicious activity, and their responsibility in protecting prescribing systems.
If anyone in your organization prescribes controlled substances electronically, yes - the DEA rules govern how that must work. If you prescribe Medicare Part D controlled substances, CMS expects you to e-prescribe them at a 70 percent or higher rate. And in Florida, maintaining an EHR triggers a broader e-prescribing requirement under F.S. 456.42.
The sharpest consequence is losing the ability to e-prescribe: an application that fails its required audit cannot be used, with DEA notification within one business day. Beyond that, failures can bring DEA enforcement, state licensing consequences, and criminal exposure where diversion occurs. Operational gaps - shared tokens, unrevoked access - are what auditors find first.
For most practices the controls already exist in the software - the work is verification and cleanup: identity-proofing records, token issuance, access reviews, log cadence. That typically fits inside our standard 2 to 4 week assessment, with remediation scheduled by priority afterward.
It depends on the number of prescribers, systems, and gaps involved. You get a firm quote after the assessment; the conversation costs nothing.
EPCS failures are usually process failures your IT provider was never asked to own - identity proofing documentation, the two-individual access rule, token lifecycle, audit review cadence. We verify those against the regulation itself and work co-managed with your existing provider on fixes.
HIPAA protects the data; EPCS proves the prescriber. HIPAA asks for reasonable and appropriate safeguards and lets you decide how. EPCS names its controls: approved software, formal identity proofing, a FIPS-validated hard token at signing, two-person access authorization, and two-year record retention.
Much of it, yes - the rule is prescriptive enough to be a checklist. The failure mode is assuming the EHR vendor handled everything. The vendor certifies the software; identity proofing, token management, access control, and log review are on your side of the line. Our DIY-with-support tier backs your team on exactly those items.
Start with the two questions auditors ask: is your software's certification current, and can you produce identity-proofing and access records for every prescriber? Our Cyber Risk & Compliance Gap Assessment answers both and checks the rest of the Part 1311 controls by name. No pressure. No jargon. Just clear insights and your best next steps.
Official source: DEA Diversion Control Division, DOJ
Secondary source: eCFR - 21 CFR Part 1311
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25