yourstate.us
21 CFR 1304.06

§ 1304.06 Records and reports for electronic prescriptions.

United States · 21 CFR — Food and Drugs · Status: effective

Get this as JSONEmbed this
Cite this
Citation
21 CFR 1304.06, § 1304.06 Records and reports for electronic prescriptions, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/91895
Permanent ID
ys:prov:91895@1
SHA-256
0fa65fee4610e7ea955bef0a658c0e4ab98016da878d9bfca76394ac19b888bd

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) As required by § 1311.120 of this chapter, a practitioner who issues electronic prescriptions for controlled substances must use an electronic prescription application that retains the following information: (1) The digitally signed record of the information specified in part 1306 of this chapter. (2) The internal audit trail and any auditable event identified by the internal audit as required by § 1311.150 of this chapter. (b) An institutional practitioner must retain a record of identity proofing and issuance of the two-factor authentication credential, where applicable, as required by § 1311.110 of this chapter. (c) As required by § 1311.205 of this chapter, a pharmacy that processes electronic prescriptions for controlled substances must use an application that retains the following: (1) All of the information required under § 1304.22(c) and part 1306 of this chapter. (2) The digitally signed record of the prescription as received as required by § 1311.210 of this chapter. (3) The internal audit trail and any auditable event identified by the internal audit as required by § 1311.215 of this chapter. (d) A registrant and application service provider must retain a copy of any security incident report filed with the Administration pursuant to §§ 1311.150 and 1311.215 of this chapter. (e) An electronic prescription or pharmacy application provider must retain third party audit or certification reports as required by § 1311.300 of this chapter. (f) An application provider must retain a copy of any notification to the Administration regarding an adverse audit or certification report filed with the Administration on problems identified by the third-party audit or certification as required by § 1311.300 of this chapter. (g) Unless otherwise specified, records and reports must be retained for two years.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.