21 CFR 1311.215
§ 1311.215 Internal audit trail.
United States · 21 CFR — Food and Drugs · Status: effective
Cite this
- Citation
- 21 CFR 1311.215, § 1311.215 Internal audit trail, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/92094
- Permanent ID
ys:prov:92094@1- SHA-256
68dd8e0b4d7e50f262cc06f9cadcf7805c5acbd325ed9449fd8bbb0f3f9cf46a
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) The pharmacy application provider must establish and implement a list of auditable events. The auditable events must, at a minimum, include the following:
(1) Attempted unauthorized access to the pharmacy application, or successful unauthorized access to the pharmacy application where the determination of such is feasible.
(2) Attempted or successful unauthorized modification or destruction of any information or records required by this part, or successful unauthorized modification or destruction of any information or records required by this part where the determination of such is feasible.
(3) Interference with application operations of the pharmacy application.
(4) Any setting of or change to logical access controls related to the dispensing of controlled substance prescriptions.
(5) Attempted or successful interference with audit trail functions.
(6) For application service providers, attempted or successful annotation, alteration, or destruction of controlled substance prescriptions or logical access controls related to controlled substance prescriptions by any agent or employee of the application service provider.
(b) The pharmacy application must analyze the audit trail at least once every calendar day and generate an incident report that identifies each auditable event.
(c) The pharmacy must determine whether any identified auditable event represents a security incident that compromised or could have compromised the integrity of the prescription records. Any such incidents must be reported to the pharmacy application service provider, if applicable, and the Administration within one business day.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.