Research

The audit trail behind an electronic prescription

For a controlled substance prescribed electronically, the record is not the prescription. It is a digitally signed copy, an internal audit trail, an identity-proofing record, and a set of third-party audit reports.

By Nora Castellan, Standards Editor

Where this applies, stated first

This is a controlled substances rule. It governs practitioners who issue electronic prescriptions for controlled substances, and pharmacies that process them.

Most peptides sold in this market are not controlled substances. A seller handling only non-controlled products is not the party this section governs, and its silence on these points is not a finding about it.

The reason to read it anyway is that it shows what a regulator considers an adequate electronic record when it bothers to specify one. That is a useful yardstick for a market full of electronic paperwork nobody has defined.

The prescription is not the record

A paper prescription is a document, and the record is the document. An electronic one works differently.

The section requires that a practitioner issuing electronic prescriptions for controlled substances use an application that retains two things.

The digitally signed record of the prescription information required by the prescribing rules. And the internal audit trail, together with any auditable event the internal audit identifies.

So the retained object is a signed copy plus a log of what the system did. Not a rendering, and not a printout.

The pharmacy side keeps three things

A pharmacy that processes electronic prescriptions for controlled substances has a parallel obligation, and it retains one more item than the prescriber.

All of the information required under the dispenser records provision and the prescribing rules.

The digitally signed record of the prescription as received.

And the internal audit trail, plus any auditable event the internal audit identifies.

The phrase "as received" is doing work in the second item. What is kept is the prescription in the state it arrived, which is what makes a later comparison possible.

The record about who the prescriber is

One requirement is about identity rather than about any prescription.

An institutional practitioner must retain a record of identity proofing, and of the issuance of the two-factor authentication credential, where applicable.

That is a record that a specific human being was verified and given a credential. It exists before any prescription and outlasts each one.

It is also the record that makes a digital signature mean something. A signature is only as good as the process that established who holds the key.

Security incidents, and the audits of the audits

Three more retention duties cover the systems themselves rather than the prescriptions passing through them.

A registrant and an application service provider must retain a copy of any security incident report filed with the Administration under the relevant provisions.

An electronic prescription or pharmacy application provider must retain third party audit or certification reports.

And an application provider must retain a copy of any notification to the Administration about problems identified by a third-party audit or certification — specifically, an adverse audit or certification report.

That last one is the most striking. A bad audit result is not merely reported; the report of it is a record the provider has to keep.

Two years, unless something says otherwise

The retention period is short compared with most of the record rules in this area.

The section closes with a single sentence: "Unless otherwise specified, records and reports must be retained for two years."

That is the default for this section. Other rules elsewhere set longer periods for other records, and the phrase unless otherwise specified is what lets them.

Two years is worth holding next to the ten-year retention that applies to human tissue records. Different rulebooks price the same kind of question very differently.

What the dispenser record itself contains

The section cross-references the dispenser records provision, which is worth reading on its own because it defines the minimum content of a dispensing record.

A registrant dispensing controlled substances keeps the same information required of manufacturers for finished forms. The name of the substance, and each finished form with the number of units or volume in each commercial container. The quantity imported directly, the quantity distributed in bulk to other persons, and the quantity disposed of in any other manner.

On top of that, the record must show the number of units or volume dispensed. It must show the name and address of the person it was dispensed to, and the date of dispensing. And it must show the written or typewritten name or initials of the individual who dispensed or administered the substance.

Five fields, and one of them is a person. The record names the individual who handed it over, not only the business.

What this section does not contain

Most of this section is a set of pointers into a different part of the regulations, the one governing electronic prescription applications and their requirements.

That part sets out what identity proofing involves, what the internal audit has to check, what counts as an auditable event, and what the third-party audit or certification process is.

None of that was read for this article, and nothing here describes those requirements. What is described is the retention obligation this section imposes, which is a separate question from what the underlying processes require.

A reader who wants the mechanics of identity proofing or auditable events will need the other part, and should not take this one as a summary of it.

The transferable idea

The pattern here is worth carrying to any electronic paperwork a reader is asked to trust.

A signed record, retained in the state it was created or received. A log of system events sitting alongside it. A separate record establishing who was verified as the signer.

And an independent audit of the system, with a duty to retain the adverse results rather than only the clean ones.

Where a market produces electronic records without those four elements, it is not producing what a regulator asked for when it wrote the requirement down. That is an observation about the shape of a record, not about anyone in particular.

Key takeaways

Frequently asked questions

What has to be retained for an electronic controlled-substance prescription?

On the prescriber side, the digitally signed record of the prescription information and the internal audit trail with any auditable event the audit identifies. On the pharmacy side, the dispenser record information and the prescribing rules' information, the digitally signed record of the prescription as received, and the internal audit trail with any auditable events.

How long are these records kept?

The section states that unless otherwise specified, records and reports must be retained for two years. Other provisions can set longer periods, which is what the qualifier allows for.

Does anything record who the prescriber is?

Yes. An institutional practitioner must retain a record of identity proofing and of the issuance of the two-factor authentication credential, where applicable. That record establishes who was verified and given the credential, which is what gives a digital signature its meaning.

Are audit failures recorded?

Yes. An application provider must retain a copy of any notification to the Administration regarding an adverse audit or certification report, filed on problems identified by the third-party audit or certification. Providers must also retain the third party audit or certification reports themselves, and registrants and application service providers must retain copies of security incident reports filed.

Does this apply to a peptide seller?

Only where controlled substances are involved. Most peptides sold in this market are not controlled substances, so most sellers are outside this section entirely. The value of reading it is as a yardstick for what a regulator considers an adequate electronic record, not as a standard to measure a non-controlled seller against.

Sources

Each document below is named as it names itself, with the date printed on that document rather than the day it was read.

  1. 21 CFR 1304.06, Records and reports for electronic prescriptionsElectronic Code of Federal Regulations, title 21, March 2010
  2. 21 CFR 1304.22, Records for manufacturers, distributors, dispensers, researchers, importers, exporters, registrants that reverse distribute, and collectorsElectronic Code of Federal Regulations, title 21, August 2026