---
kind: "section"
citation: "21 C.F.R. § 1311.115"
title: "21"
number: "1311.115"
heading: "Additional requirements for two-factor authentication."
url: "https://uscodex.org/cfr/21/1311.115"
---

# §1311.115. Additional requirements for two-factor authentication.

- (a) To sign a controlled substance prescription, the electronic prescription application must require the practitioner to authenticate to the application using an authentication protocol that uses two of the following three factors:
  - (1) **Something only the practitioner knows, such as a password or response to a challenge question.**
  - (2) **Something the practitioner is, biometric data such as a fingerprint or iris scan.**
  - (3) Something the practitioner has, a device (hard token) separate from the computer to which the practitioner is gaining access.
- (b) If one factor is a hard token, it must be separate from the computer to which it is gaining access and must meet at least the criteria of FIPS 140-2 Security Level 1, as incorporated by reference in [§ 1311.08](/cfr/21/1311.08.md), for cryptographic modules or one-time-password devices.
- (c) If one factor is a biometric, the biometric subsystem must comply with the requirements of [§ 1311.116](/cfr/21/1311.116.md).

## Notes

### Source

Source: 75 FR 16310, Mar. 31, 2010, unless otherwise noted.

### Authority

Authority: 21 U.S.C. 821, 828, 829, 871(b), 958(e), 965, unless otherwise noted.

### Source

Source: 70 FR 16915, Apr. 1, 2005, unless otherwise noted.
