NextGen Knowledge Center

DEA Provider Requirements

To send Electronic Prescriptions of Controlled Substances (ePCS), a provider must meet the following Drug Enforcement Administration (DEA) requirements:

  • The provider's relationship with user is set up as self.
  • The provider's retail service level is set up for ePCS.
  • A valid DEA number is assigned to the provider.

    If a provider is exempted from the DEA registration, a link to the institutional practitioner’s DEA number must exist.

  • Two-factor authentication credentials are added for the provider.
    • Something you know, for example a password or PIN
    • Something you have, for example a token that generates one-time password or a push notification to registered devices
    • Something you are, for example a biometric test

      NextGen® Enterprise EHR uses the something you know (user password), something you have (token generating a one-time access password or a push notification to registered devices), and something you are (biometric test) authentications for ePCS.

  • The provider is authenticated by two registrars.
  • ePCS prescriber access is granted to the provider.
  • Digital signing certificates are assigned to the provider.