yourstate.us
21 CFR 1311.150

§ 1311.150 Additional requirements for internal application audits.

United States · 21 CFR — Food and Drugs · Status: effective

Get this as JSONEmbed this
Cite this
Citation
21 CFR 1311.150, § 1311.150 Additional requirements for internal application audits, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/92089
Permanent ID
ys:prov:92089@1
SHA-256
100b422fb02a949780f003fa56400f81c48ad04d2e6ef69e4a85ddf649d51f79

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) The application provider must establish and implement a list of auditable events. Auditable events must, at a minimum, include the following: (1) Attempted unauthorized access to the electronic prescription application, or successful unauthorized access where the determination of such is feasible. (2) Attempted unauthorized modification or destruction of any information or records required by this part, or successful unauthorized modification or destruction of any information or records required by this part where the determination of such is feasible. (3) Interference with application operations of the prescription application. (4) Any setting of or change to logical access controls related to the issuance of controlled substance prescriptions. (5) Attempted or successful interference with audit trail functions. (6) For application service providers, attempted or successful creation, modification, or destruction of controlled substance prescriptions or logical access controls related to controlled substance prescriptions by any agent or employee of the application service provider. (b) The electronic prescription application must analyze the audit trail at least once every calendar day and generate an incident report that identifies each auditable event. (c) Any person designated to set logical access controls under §§ 1311.125 or 1311.130 must determine whether any identified auditable event represents a security incident that compromised or could have compromised the integrity of the prescription records. Any such incidents must be reported to the electronic prescription application provider and the Administration within one business day.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.