- Industries & Communities
- Banking & Finance
- Licensed Engineers & Surveyors
- Enterprise & Corporate
- Government
- Healthcare
- Manufacturing
- Personal & Professional
Image
EPCS Certification Requirements
September 9, 2026 • Wesley Lutz
Understanding EPCS Certification: Where Digital Certificates Come In
Electronic prescribing of controlled substances (EPCS) lets prescribers send Schedule II through V prescriptions electronically instead of relying on paper. Getting an EPCS certification involves many moving pieces for an eHR or eMR platform. Some of it sits at the platform level, where a solution must pass an audit before it can process controlled-substance prescriptions. Other pieces live much closer to the prescriber, in the credential each practitioner needs before they can sign.
The DEA spells out that credential requirement in 21 CFR Part 1311, its regulation governing electronic prescriptions for controlled substances. Section 1311.105(a) requires each practitioner to obtain a two-factor authentication credential before signing electronically, and there are two main ways to get one.
One path runs through a credential service provider approved to perform identity proofing at a specific NIST assurance level. The other involves a digital certificate issued by a certification authority (CA) cross-certified with the Federal Bridge Certificate Authority (FBCA), the federal government’s trust framework for recognizing outside certificate authorities, at a basic assurance level or above. The latter path covers identity proofing, but it doesn’t handle two-factor authentication on its own.
Where Digital Certificates Fit
A digital certificate has to meet a specific bar: identity proofing at a basic assurance level and cross-certification with the FBCA. IdenTrust is a CA that offers an IGC Basic Assurance certificate, which confirms that the prescriber is who they claim to be and satisfies the identity-proofing half of the DEA’s rule.
The two-factor half still needs to be satisfied separately, through two of three possible factors:
- A password or other challenge response that only the prescriber knows
- A fingerprint or other biometric marker unique to the prescriber
- A hardware token or dedicated device the prescriber carries
IdenTrust built three specific offerings to close that gap.
1. Identity Proofing Only
With identity proofing, IdenTrust verifies who the prescriber is, while the eHR platform’s own login and authentication flow supplies the two-factor piece independently. The certificate itself works the same way it always has. The platform takes on the responsibility for its own two-factor process, including documenting it for an audit.
2. Hardware-Based Authentication
Hardware-based authentication stores the certificate on a physical device, such as a USB token or smart card, that requires a passcode to unlock. Logging into the application supplies one factor, and unlocking the device with its passcode supplies the second. That approach doesn’t require any integration work with IdenTrust, but it does require the platform to capture an audit trail every time the passcode is used, since auditors expect to see that record later.
3. Mobile Authentication
Mobile authentication links the certificate to a mobile app rather than a physical device. In IdenTrust’s case, that app is built on the HID Approve platform. It’s the only approach that requires the platform to integrate directly with IdenTrust, and it comes with a modest one-time setup cost. In exchange, the certificate’s validity is tied directly to app access. If the certificate lapses, the app stops working for the prescriber. This gives the platform built-in proof that every prescriber complies.
No matter which approach you choose, start certificate planning at the beginning of a build cycle, not closer to launch. Most eHR and eMR platforms already work with a DEA-approved auditor by the time they start evaluating certificate options, which makes sense, since the auditor’s requirements should shape the platform’s architecture rather than the other way around. However, auditors who handle EPCS platforms are harder to find, so it’s worth lining one up early.
When One Authentication Method Isn’t Enough
Scale changes the picture for eHR or eMR platforms serving more than one practice. A vendor supporting a single small practice can often get by offering one authentication method. However, a vendor that supports multiple health systems usually needs more.
Mobile authentication works well for a prescriber who can use a phone at the point of care, but some clinical settings restrict mobile devices altogether. Hardware tokens fill that gap.
Plus, a vendor working across a range of practice types typically offers multiple authentication options side by side rather than standardizing on a single option.
Certificates and the Prescriber Side
An eHR or eMR platform’s certification and its prescribers’ certificates run on two different clocks. The platform can clear its audit and still have plenty of work left before an individual prescriber is ready to sign. Once the audit closes, what’s left is getting the right certificate into the right prescriber’s hands.
That sounds simpler than it is. A CA typically issues multiple certificate types, and not every type applies to a given eHR or eMR platform. A prescriber who lands on a CA’s general application page has a harder time knowing which option matches their specific platform.
Some CAs, such as IdenTrust, aim to improve the prescriber’s experience by offering a dedicated page that lists relevant EPCS partners. By clicking on a partner’s logo, you can learn more about the company and its available certificates, which helps to narrow your search.
The Choices That Outlive the Audit
A digital certificate only satisfies one part of the DEA’s rule: proving the prescriber is who they say they are. Closing the two-factor gap and getting that certificate into each prescriber’s hands are separate decisions, and together they shape an eHR or eMR platform more than the certificate itself does. Tie a certificate’s validity to app access, and a lapsed certificate cuts off access automatically instead of leaving compliance staff to check by hand. That design choice is easy to underrate until an audit asks for proof of it.
The same logic also applies to timing. Platforms should work with a DEA-approved auditor early in the process, as compliance requirements should shape the subsequent architectural decisions.