GroundRules
← Search the law
Federal regulations · Through 2026-08-25 · Newer source version available

21 CFR 1311.115: Additional requirements for two-factor authentication.

Read at publisher ↗
Where this section sits in the code
  1. Title 21—Food and Drugs
  2. CHAPTER II—DRUG ENFORCEMENT ADMINISTRATION, DEPARTMENT OF JUSTICE
  3. PART 1311—REQUIREMENTS FOR ELECTRONIC ORDERS AND PRESCRIPTIONS
  4. Subpart C—Electronic Prescriptions

(a) To sign a controlled substance prescription, the electronic prescription application must require the practitioner to authenticate to the application using an authentication protocol that uses two of the following three factors:

(1) Something only the practitioner knows, such as a password or response to a challenge question.

(2) Something the practitioner is, biometric data such as a fingerprint or iris scan.

(3) Something the practitioner has, a device (hard token) separate from the computer to which the practitioner is gaining access.

(b) If one factor is a hard token, it must be separate from the computer to which it is gaining access and must meet at least the criteria of FIPS 140-2 Security Level 1, as incorporated by reference in § 1311.08, for cryptographic modules or one-time-password devices.

(c) If one factor is a biometric, the biometric subsystem must comply with the requirements of § 1311.116.

Collected 2026-08-27T02:24:47Z. Source file · JSON

Browse this collection