---
kind: "section"
citation: "21 C.F.R. § 1304.06"
title: "21"
number: "1304.06"
heading: "Records and reports for electronic prescriptions."
url: "https://uscodex.org/cfr/21/1304.06"
---

# §1304.06. Records and reports for electronic prescriptions.

- (a) As required by [§ 1311.120](/cfr/21/1311.120.md) of this chapter, a practitioner who issues electronic prescriptions for controlled substances must use an electronic prescription application that retains the following information:
  - (1) **The digitally signed record of the information specified in part 1306 of this chapter.**
  - (2) The internal audit trail and any auditable event identified by the internal audit as required by [§ 1311.150](/cfr/21/1311.150.md) of this chapter.
- (b) An institutional practitioner must retain a record of identity proofing and issuance of the two-factor authentication credential, where applicable, as required by [§ 1311.110](/cfr/21/1311.110.md) of this chapter.
- (c) As required by [§ 1311.205](/cfr/21/1311.205.md) of this chapter, a pharmacy that processes electronic prescriptions for controlled substances must use an application that retains the following:
  - (1) All of the information required under [§ 1304.22(c)](/cfr/21/1304.22.md?p=c) and [part 1306](/cfr/21/part1306.md) of this chapter.
  - (2) The digitally signed record of the prescription as received as required by [§ 1311.210](/cfr/21/1311.210.md) of this chapter.
  - (3) The internal audit trail and any auditable event identified by the internal audit as required by [§ 1311.215](/cfr/21/1311.215.md) of this chapter.
- (d) A registrant and application service provider must retain a copy of any security incident report filed with the Administration pursuant to §§ [1311.150](/cfr/21/1311.150.md) and [1311.215](/cfr/21/1311.215.md) of this chapter.
- (e) An electronic prescription or pharmacy application provider must retain third party audit or certification reports as required by [§ 1311.300](/cfr/21/1311.300.md) of this chapter.
- (f) An application provider must retain a copy of any notification to the Administration regarding an adverse audit or certification report filed with the Administration on problems identified by the third-party audit or certification as required by [§ 1311.300](/cfr/21/1311.300.md) of this chapter.
- (g) Unless otherwise specified, records and reports must be retained for two years.

## Notes

### Amendments

[75 FR 16306, Mar. 31, 2010]

### Authority

Authority: 21 U.S.C. 821, 823(j), 827, 831, 871(b), 958(e)-(g), and 965, unless otherwise noted.

### Amendments

[75 FR 16306, Mar. 31, 2010]
