EPCS Documentation

Electronic Prescriptions for Controlled Substances

Hero EMR lets your practice prescribe controlled substances (DEA Schedule II–V) electronically, end to end, with DEA-compliant two-factor signing on a bound mobile device, built-in PDMP checks, and a tamper-evident audit trail. This guide walks through enrollment, issuing your mobile device token, the signing workflow, and the monitoring tools your administrators get.

DEA two-factor signing Mobile device tokens PDMP via Bamboo Health Tamper-evident audit
Overview

How EPCS works in Hero EMR

EPCS (Electronic Prescriptions for Controlled Substances) is the federally regulated way to send Schedule II–V prescriptions to a pharmacy without paper. The DEA requires two things that ordinary e-prescribing does not: every prescriber must complete identity proofing before they can sign, and every controlled-substance prescription must be signed with two-factor authentication at the moment of signing.

Hero EMR satisfies both with a split-device design. You build the prescription on your computer in the EMR, and you approve and sign it on a separate, pre-registered mobile device using a biometric or device passcode. The phone is “something you have” and the biometric/passcode that unlocks its passkey is “something you are/know” — together they meet the DEA’s two-factor requirement. Signed prescriptions transmit to the pharmacy over the Surescripts network with a cryptographic digital signature attached.

Factor 1 · Have

Your bound phone

A specific mobile device you previously registered for EPCS signing — identified by a stored device fingerprint and a passkey.

Factor 2 · Are / Know

Your biometric or passcode

Face ID, Touch ID, or the device passcode unlocks the passkey on that phone to authorize each signature.

The building blocks

  • Logical access grant — the per-prescriber record that says you are allowed to enter, ready, sign, and transmit controlled substances. It is tied to your DEA number and reviewed on a recurring cadence (annually by default).
  • Bound signing device — the phone you activate to approve signatures. Each prescriber can keep up to two active devices.
  • PDMP check — a real-time look at the patient’s controlled-substance history through Bamboo Health’s PMP Gateway, gating the prescription before it can be signed. See section 07.
  • Tamper-evident audit trail — every enrollment, device, and signing action is hash-chained so the record cannot be quietly altered. See section 08.
Step 1 · Verification

Getting started: identity, license & DEA verification

Before anyone in your practice can sign controlled substances, the DEA requires identity proofing of the prescriber. Hero EMR LLC handles this for your first prescriber so your organization has a verified, signing-capable user to build from.

What Hero EMR LLC verifies

We confirm three things for your first EPCS prescriber and record the outcome against their profile:

  • Identity — identity proofing is completed and the prescriber’s status is marked verified. Access cannot be activated until this is true.
  • Active license — a current, unrestricted clinical license on file.
  • DEA registration — an active DEA registration number, which is attached to the prescriber’s logical access grant.

Seeding your first EPCS user

Once those checks pass, Hero EMR LLC seeds the first EPCS user in your organization. In practice this means:

  1. We confirm the verification checks are complete. Identity proofing must read verified, with the active license and DEA registration recorded.
  2. An authorized DEA registrant completes a second-factor confirmation. The first prescriber confirms their DEA number and a one-time PIN before the grant is created — the same two-person/two-factor discipline that protects every later enrollment.
  3. An active EPCS access grant is created. Your first prescriber receives a full-prescriber grant (enter, alter, ready, sign, and transmit privileges) tied to their DEA number, plus the administrator capability to manage EPCS for the rest of the practice.
What this unlocks. With an active grant and EPCS administrator access, your first user can open Admin > EPCS, issue themselves a mobile device token (section 03), and enroll the rest of your prescribers (section 06). From here, EPCS is self-service for your practice.
Step 2 · Your device

Issue yourself a mobile device token

Your seeded first user signs in to the EMR and opens Admin > EPCS. The EPCS console has four tabs — Enrollments, Monitoring, Security Alerts, and PDMP. Everything in this section happens on the Enrollments tab.

Generate the invite

  1. Find your enrollment row. On the Enrollments tab, locate your own row (filter by your name or by the Active / Waiting Device status). Each row shows the prescriber, DEA number, status, and any active devices.
  2. Click “Issue Invite.” Hero generates a one-time device invite. You’ll see a short-lived token (about 15 minutes by default) plus Copy Token and Copy Link buttons. The link is a deep link of the form heroemr://epcs-device-bind?token=….
  3. Open the invite on your phone. On the device you want to use for signing, open the Hero physician mobile app and follow the invite link (or paste the token). The app routes you to the Bind EPCS Device screen.

Activate the device

  1. Verify with a passkey on this phone. The bind screen lists the passkeys available on the device and prompts you to “Verify Passkey And Bind This Phone.” Authenticating runs a biometric/passcode check and ties the passkey to this specific device.
  2. Hero records the device fingerprint. The phone’s unique signing fingerprint is hashed and stored against your enrollment, so only this device can approve your future signatures.
  3. Done — the device is active. You’ll see “Device linked — this phone is now approved for EPCS signing,” the invite token is consumed, and your enrollment moves to Active.
Up to two active devices. Each prescriber can keep at most two active signing devices (for example, a phone and a tablet). If you already have two, binding a third is blocked until you retire one. The first device you bind becomes your primary.
Step 3 · Device safety

Report a device lost or stolen

If a signing device is lost, stolen, or being replaced, you cut it off from the same Admin > EPCS → Enrollments tab where you issued it. There are two distinct tools, depending on whether you need an immediate replacement or a controlled wind-down.

“Lost Phone” — immediate, one click

  1. Click “Lost Phone” on the affected enrollment. A dialog titled Replace Lost Phone asks for a reason: lost phone, stolen phone, device upgrade, or other, with an optional note.
  2. Confirm “Revoke Devices + Issue Invite.” Hero immediately revokes every active signing device on that enrollment — the old phone can no longer approve anything — cancels any pending invites, and issues a fresh replacement invite token.
  3. Bind your new device. Copy the new token or link and activate your replacement phone exactly as in section 03.

Use “Lost Phone” the moment a device goes missing. Revocation is instant, and the action is written to the audit trail with the reason you selected.

“Revoke” — controlled, two-person

To remove a prescriber’s EPCS access entirely (for example, on departure or a credential change), use Revoke instead. This follows the same two-person rule as enrollment:

  • One administrator requests the revocation; the enrollment moves to Pending Revoke 2nd.
  • A different administrator completes “Second Sign Revoke” with a passkey, and at least one of the two approvers must verify with an approved EPCS hard-token credential.
  • Only after the second approval is the grant marked Revoked and all active devices disabled. Unlike “Lost Phone,” no replacement invite is issued.
Day to day

What happens when an EPCS request is made

Once you’re enrolled with an active device, signing a controlled substance is a quick split-device approval. Here is the full lifecycle, from order entry to the pharmacy.

  1. You place the controlled-substance order on your computer. Hero detects the DEA schedule (CII–CV) and prepares an EPCS signing request. A snapshot of the prescription is cryptographically fingerprinted at this moment so it cannot be altered after you approve it.
  2. A push notification is sent to your bound phone. Your registered device receives “Controlled prescription approval requested — approve on your phone to continue EPCS signing.” The request is valid for three minutes.
  3. You review the prescription on the phone. The approval screen shows the drug, patient, dosage and directions, refills, the DEA schedule, and a live countdown — everything you need to confirm you’re signing the right order.
  4. You approve with a biometric. Tapping Approve triggers Face ID, Touch ID, or your device passcode. That completes two-factor authentication: the bound phone (have) plus your biometric/passcode-protected passkey (are/know). Tapping Deny cancels the request.
  5. Hero applies the digital signature. On approval, a cryptographic signature is computed over the prescription’s clinical fields and attached, recording which device signed and when. The prescription is now EPCS-verified.
  6. The prescription transmits to the pharmacy. Hero sends the signed prescription over the Surescripts network with the digital-signature block included, and tracks the pharmacy’s response.

Safeguards built into every signature

Separate signing device

The phone that approves must be different from the computer that placed the order. A same-device attempt is blocked and flagged — this defeats single-device phishing.

Three-minute window

If you don’t approve within three minutes, the request expires and you simply start a new one. Nothing is left half-signed.

Tamper detection

If the prescription changes after you approve, the signature no longer matches and Hero requires a fresh approval before it will transmit.

Limited retries

Repeated failed approval attempts close the session automatically and raise a security alert (see rule EPCS-R002 in section 08).

Step 4 · Scale the practice

Register other EPCS users

Once your first prescriber is active, your EPCS administrators enroll the rest of the practice from Admin > EPCS. Granting controlled-substance signing rights is a deliberate, two-person process — no single administrator can hand out EPCS access alone.

Create the enrollment request

  1. Start a new EPCS enrollment. On the Enrollments tab, create a request and select the target prescriber, enter their DEA number, and set the identity proofing status. Hero checks the DEA number against the prescriber’s profile and blocks the request if a conflicting number is already on file.
  2. Choose what they can do. Pick a privilege template — Full Prescriber (enter, alter, ready, sign, transmit), Enter Only (drafting without signing rights), or Custom.
    EnterAlterReadySignTransmit
  3. Record your first approval. Submitting the request automatically counts you as the first approver and moves it to Pending 2nd Approval.

A second administrator approves (the two-person rule)

  1. A different administrator clicks “Second Sign.” The first and second approvers must be distinct people — the initiator cannot also be the second signer.
  2. They verify with a passkey or hard token. At least one of the two approvers must be an already-enrolled EPCS prescriber verifying with an approved EPCS hard-token credential, so a vetted prescriber is always in the loop.
  3. The grant activates. Identity proofing must read verified at this point. On success, Hero creates the active access grant (and adds the DEA identifier if needed), and the enrollment moves to Approved – Waiting Device.

The new prescriber binds their device

Finally, an administrator clicks Issue Invite for the new prescriber and shares the short-lived token or deep link. The prescriber activates their own phone exactly as described in section 03, and their enrollment flips to Active. Removing access later uses the two-person Revoke flow from section 04.

Permissions. Managing EPCS enrollments, approvals, device invites, and revocations requires the EPCS oversight permission (the “Manage EPCS oversight workflows” capability) or an administrator role. Hand it out only to the staff who genuinely run EPCS oversight.
Compliance gate

PDMP checks & how Bamboo works

A Prescription Drug Monitoring Program (PDMP) is a state database that tracks dispensed controlled substances. Many states require a prescriber to review it before writing a controlled prescription. Hero connects to PDMPs through Bamboo Health’s PMP Gateway, a clearinghouse that lets one request reach multiple states’ programs and return a consolidated history — so you don’t query each state separately.

What a PDMP check returns

  • Prescription history across the states your practice is approved to query.
  • NarxCare risk scores — numeric indicators for overdose, narcotic, sedative, and stimulant risk that help you triage at a glance.
  • A secure link to the full report, opened in-app, that expires after about 30 minutes.
  • Per-state results — which states returned data, which had none, and which the practice isn’t registered for.

When a check runs and what you see

In the prescribing workflow a status panel shows the result with a clear go / caution / blocked indicator, the risk scores, and the timestamps for when the check was run and reviewed. Checks can be triggered:

  • Manually, with the Run PDMP button.
  • Automatically when you select a controlled medication in order entry (pre-fetched so it’s ready).
  • As a gate before transmitting, and when reviewing a controlled-substance refill.

If a report needs a closer look, you open it with Review report. A check stays “fresh” for a configurable window (24 hours by default), after which the panel prompts you to refresh.

How it connects to EPCS

PDMP is a prerequisite gate for EPCS signing. A controlled-substance prescription can be signed only when a PDMP check has run, returned a usable result, and — where your state or organization policy requires it — the report has been opened and reviewed. Each organization configures its own Bamboo credentials, the states it’s approved to query, and whether the check is advisory or strictly blocking.

State specifics. Some states layer on extra requirements. Kentucky’s KASPER program, for example, requires the prescriber to be registered, additional patient identifiers, and a mandatory report review before the prescription can move forward. Hero handles these state rules as part of the readiness setup your implementation team completes with you.
Oversight

Audit logging & security alerts

Everything EPCS does is recorded, and suspicious patterns surface automatically for your administrators to triage.

A tamper-evident audit trail

Every EPCS event — enrollment requests and approvals, grant creation, device invites and bindings, access checks, verification failures, and revocations — is written to an append-only audit log. Each record carries a cryptographic hash that incorporates the previous record’s hash, forming a chain. Altering any past entry would break every hash after it, so tampering is detectable. Administrators can pull a per-prescriber action report that assembles enrollment, grant approval (including who first- and second-signed), signing, and authentication events into one chronological timeline for compliance reviews.

The eight security-alert rules

Hero continuously evaluates EPCS activity against eight built-in rules. Each fires an in-app alert and, where configured, an email. Severity ranges from MEDIUM to HIGH to CRITICAL.

RuleWhat it detectsSeverity
EPCS-R001Repeated EPCS verification failures of the same type in a short window (e.g. several failed signatures within minutes).HIGHCRIT
EPCS-R002A burst of signing sessions that hit the maximum approval retries — possible brute-forcing of an approval.HIGH
EPCS-R003Multiple second-device policy violations — attempts to approve on the same device that placed the order.HIGH
EPCS-R004Repeated access denials from a passkey/device binding mismatch. Downgraded to MEDIUM when a recent, legitimate device change explains it.MEDCRIT
EPCS-R005The emergency EPCS bypass override was used. Always flagged for immediate review.CRITICAL
EPCS-R006A device-invite redemption lockout was reached — possible attempts to redeem an invite token by force.HIGH
EPCS-R007A burst of mobile authentication requests in a very short window (e.g. 5+ in a minute) — a possible denial-of-service pattern.HIGH
EPCS-R008A prescriber attempted to sign or transmit a controlled substance without an active EPCS access grant.CRITICAL

Delivery & configuration

  • In-app console. Every alert appears under Admin > EPCS > Security Alerts, where administrators can acknowledge, suppress (temporarily), or resolve it with a documented reason.
  • Email. HIGH and CRITICAL alerts can email a destination you choose (a custom address, or all active organization administrators by default), with cooldowns so you aren’t flooded. Patient identifiers are intentionally kept out of alert emails.
  • Per-organization control. Each organization can turn email notifications on or off, set the destination address, and enable or disable each of the eight rules independently.