21 CFR 1311.115
§ 1311.115 Additional requirements for two-factor authentication.
United States · 21 CFR — Food and Drugs · Status: effective
Cite this
- Citation
- 21 CFR 1311.115, § 1311.115 Additional requirements for two-factor authentication, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/92081
- Permanent ID
ys:prov:92081@1- SHA-256
47e18be384f6677d0c073cb4387304fc215e2766c8991fee0870a772c1719e7a
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) To sign a controlled substance prescription, the electronic prescription application must require the practitioner to authenticate to the application using an authentication protocol that uses two of the following three factors:
(1) Something only the practitioner knows, such as a password or response to a challenge question.
(2) Something the practitioner is, biometric data such as a fingerprint or iris scan.
(3) Something the practitioner has, a device (hard token) separate from the computer to which the practitioner is gaining access.
(b) If one factor is a hard token, it must be separate from the computer to which it is gaining access and must meet at least the criteria of FIPS 140-2 Security Level 1, as incorporated by reference in § 1311.08, for cryptographic modules or one-time-password devices.
(c) If one factor is a biometric, the biometric subsystem must comply with the requirements of § 1311.116.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.