Velant is live → Cut healthcare lead response time to under 30 seconds. See how

Definition

What is DEA 1311 (21 CFR Part 1311)?

The DEA regulation governing electronic prescribing of controlled substances, including identity proofing, two-factor authentication, biometric standards, hardware token requirements, and audit logging.

The full definition

21 CFR Part 1311 is the DEA's rulebook for EPCS. It requires: (1) IAL2-level identity proofing of the prescriber (in-person or remote with NIST 800-63-3 controls), (2) AAL2-level two-factor authentication at the point of prescribing, (3) biometrics that meet a false match rate of ≤0.001 if used, (4) FIPS 140-2 Level 1 hardware tokens if used, (5) tamper-evident audit logging of every prescription event, and (6) a third-party DEA audit of any application sending EPCS messages.

Why it matters in practice

DEA 1311 compliance is the gatekeeper for prescribing controlled substances electronically. Any ePrescribe vendor offering EPCS must either pass its own DEA audit or use a Surescripts-certified middleware vendor whose audit covers them. The audit is non-trivial — typically $15-30k and a 4-6 month engagement with a qualified third-party auditor.

Real-world examples

  • Identity proofing a new prescriber via Experian remote IAL2 verification
  • Requiring a YubiKey hardware token plus password to send a Schedule II prescription
  • Logging every EPCS event in a tamper-evident audit trail accessible to DEA

Inside Velant

Velant ePrescribe meets DEA 1311 with IAL2 identity proofing, AAL2 two-factor authentication, and tamper-evident audit logging — included at no additional charge as part of the per-prescriber pricing.

Related terms

See DEA 1311 (21 CFR Part 1311) in action — inside Velant

Book a 20-minute walkthrough and we'll show you the workflow end to end.