{"data":{"id":"us/21-cfr-1311.115","jurisdiction":"us","citation":"21 CFR 1311.115","heading":"Additional requirements for two-factor authentication.","body":"(a) To sign a controlled substance prescription, the electronic prescription application must require the practitioner to authenticate to the application using an authentication protocol that uses two of the following three factors:\n(1) Something only the practitioner knows, such as a password or response to a challenge question.\n(2) Something the practitioner is, biometric data such as a fingerprint or iris scan.\n(3) Something the practitioner has, a device (hard token) separate from the computer to which the practitioner is gaining access.\n(b) If one factor is a hard token, it must be separate from the computer to which it is gaining access and must meet at least the criteria of FIPS 140-2 Security Level 1, as incorporated by reference in § 1311.08, for cryptographic modules or one-time-password devices.\n(c) If one factor is a biometric, the biometric subsystem must comply with the requirements of § 1311.116.","path":["Title 21—Food and Drugs","CHAPTER II—DRUG ENFORCEMENT ADMINISTRATION, DEPARTMENT OF JUSTICE","PART 1311—REQUIREMENTS FOR ELECTRONIC ORDERS AND PRESCRIPTIONS","Subpart C—Electronic Prescriptions"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-21.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:47Z","sha256":"798c0e2c2ff20366b5b035e941f4e25f670a2666c841df682523817acf5050f7","source_id":"us-cfr","stale":true,"prev":"us/21-cfr-1311.110","next":"us/21-cfr-1311.116"},"notice":"GroundRules: Original legal text. Not legal advice."}
