Every clinician who wants to electronically prescribe controlled substances runs into the same wall eventually: EPCS — Electronic Prescribing of Controlled Substances — is not a checkbox inside an EHR. It is a federally regulated identity and authentication process governed by DEA rules at 21 CFR Part 1311, and getting it wrong (or getting stuck halfway through) is one of the most common reasons an otherwise EHR-ready practice still can’t send a controlled-substance prescription electronically. This piece walks through what identity proofing actually requires, how the DEA’s two-factor authentication rule works at the point of prescribing, and where practices typically get stuck.
What EPCS Identity Proofing Actually Verifies
Before a prescriber can be issued the credential that lets them sign controlled-substance prescriptions electronically, someone has to independently confirm three things: the person is who they claim to be, they hold a valid state license to practice, and their DEA registration is active and matches. This is not a form the practice fills out internally — it has to be performed by an identity-proofing entity that meets a specific federal bar. Under the DEA’s rule, that means a credential service provider approved by the General Services Administration at a minimum of NIST Identity Assurance Level 3 (IAL3), or a certification authority cross-certified with the Federal Bridge at a basic assurance level or higher. In practice, most EHR and e-prescribing vendors route this step through a small number of GSA-approved identity-proofing services, and the credential itself has to be delivered through two separate channels — for example, one confirmation by email and a second by phone — before it becomes active.
This is the step that trips up the most prescribers, not because it’s conceptually hard, but because it requires the prescriber personally, in a specific window, with specific documents on hand (a government-issued photo ID and confirmation of current license and DEA registration). If a practice tries to batch-onboard a dozen prescribers the week before a system go-live without warning anyone what they’ll need in hand, identity proofing is where the timeline breaks.
Two-Factor Authentication: Two From Three, Every Time
Identity proofing only gets a prescriber the credential. Using it is a separate, ongoing requirement. Under 21 CFR Part 1311, every single controlled-substance prescription has to be authenticated at the moment it is signed — not once per login session — using two of the following three distinct categories:
- Something you know — a password or a response to a security challenge.
- Something you have — a hard token, smart card, cryptographic key, or one-time-password device or app, kept separate from the computer running the prescribing software.
- Something you are — a biometric factor such as a fingerprint, facial scan, or iris scan.
The rule is specific about what qualifies within each category, which is the part most practices don’t discover until a vendor demo goes sideways.
| Factor category | What qualifies | Technical bar |
|---|---|---|
| Something you know | Password, PIN, challenge question | No specific federal crypto standard, but must be unique to the prescriber |
| Something you have | Hard token, smart card, OTP device or mobile authenticator app | Must meet FIPS 140-2 Security Level 1 for its cryptographic module, and a hard token must be a separate physical device from the prescribing workstation |
| Something you are | Fingerprint, facial recognition, iris scan, voice pattern | False match rate of 0.001 or lower, biometric subsystem tested by a DEA-approved laboratory (21 CFR 1311.116) |
Two of these three, applied at the moment of signing, satisfy the rule. A password plus an authenticator-app code is the combination most practices land on, largely because it’s the one that doesn’t require issuing physical hardware to every prescriber. Biometrics are used more often in larger health systems where a fingerprint reader is already built into shared workstations.
Where Practices Actually Get Stuck
In our experience routing Arizona practices to EHR and e-prescribing vendors, three patterns show up repeatedly:
- Identity proofing is scheduled too late. Because it has to be done individually, per prescriber, with documents in hand, cramming it into the week before go-live guarantees a delay for at least one person on staff.
- The “something you have” factor gets under-planned. A hard token that isn’t separate from the prescribing computer, or an authenticator app that hasn’t been verified against the vendor’s FIPS 140-2 requirement, both fail audit later even though they looked fine at setup.
- Locum and part-time prescribers fall through the cracks. Credentials are tied to the individual, not the practice, so a covering physician who was never independently identity-proofed simply cannot e-prescribe controlled substances at that site, no matter how the EHR is configured.
None of this is exotic — it’s procedural, and every EHR and e-prescribing vendor active in this space has already solved it. The friction is almost always coordination: knowing which vendor’s identity-proofing partner to use, what documents to have ready, and how the DEA registration and state license need to line up before the appointment, not after.
A Neutral Starting Point, Not a Vendor Pitch
AzHeC does not sell e-prescribing software, and it does not perform identity proofing itself. What it does is connect Arizona medical practices to the qualified EHR, e-prescribing, and health-IT vendors that can actually walk a prescriber through this process correctly the first time — the same convening role Arizona Health-e Connection played for the state’s health information exchange and e-prescribing initiatives for years before merging into the state’s current HIE infrastructure. For a practice trying to figure out which vendor’s EPCS onboarding process will actually get every prescriber authenticated and signing on schedule, that neutral vantage point is the useful part — not another product to evaluate, but a shorter path to the ones that already work.
The Bottom Line
EPCS identity proofing is a one-time, per-prescriber verification against a federal standard; two-factor authentication is a per-prescription requirement drawn from two of three defined categories. Neither is optional, and neither is something a practice can shortcut by configuring settings inside an EHR. Practices that plan the identity-proofing appointments early, choose a “something you have” factor that actually meets the FIPS 140-2 bar, and account for every prescriber who touches a controlled-substance pad — including locums — are the ones that go live on schedule.