Start Free Trial
Home/Regulations/DEA Controlled Substance Act (Pharmacy) — Regulatory Reference
Regulatory Reference
Pharmacy Federal (US) critical

DEA Controlled Substance Act (Pharmacy) — Regulatory Reference

Dispensing recordkeeping for Schedule I-V substances — critical sensitivity floor; AI agents gated by need-to-know with tamper-evident audit.

Key Provisions
  • 21 CFR Part 1304 — records and reports
  • 21 CFR Part 1311 — EPCS requirements
  • Closed-system distribution and tamper-evident recordkeeping
  • ARCOS reporting for distributors and manufacturers
How AutoPIL Enforces It
  • Schedule II–V dispensing data classified at CRITICAL sensitivity
  • AI agents in pharmacy support roles restricted by per-role sensitivity ceilings
  • Hash-linked audit chain mirrors closed-system tamper-evidence expectations
Audit LogPolicy EngineSensitivity LabelsAgent RegistryKey Scoping
AutoPIL Policy IDs
PHM-DEA-1304-001Dispensing Record Sensitivity
PHM-DEA-1311-001EPCS Audit Trail
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does the DEA Controlled Substances Act require for AI agents handling dispensing records?
Under 21 CFR Part 1304, pharmacies must maintain complete and accurate records of Schedule I–V controlled substance dispensing. When AI agents assist with clinical decision support, refill authorization, or pharmacy operations, any agent that queries or processes dispensing data is subject to these recordkeeping requirements. The DEA expects a closed-system, tamper-evident record of who accessed what and when. AI deployments must ensure agents operate under documented, enforceable need-to-know restrictions, and that every access decision is logged in a way that cannot be altered — mirroring the tamper-evidence expectations built into the CSA's closed-system distribution framework.
When does the DEA CSA apply to pharmacy AI deployments?
The DEA Controlled Substances Act applies any time an AI agent touches Schedule I–V dispensing data — including prescription history retrieval, refill eligibility checks, drug utilization review, or EPCS (Electronic Prescriptions for Controlled Substances) workflows governed by 21 CFR Part 1311. If an agent can read, process, or return controlled substance records as part of its task execution, the CSA's recordkeeping and access controls apply. This includes LLM-based clinical assistants, pharmacy benefit management bots, and automated prior authorization agents that query dispensing databases to complete their tasks.
What is the EPCS audit trail requirement under 21 CFR Part 1311 and how does it affect AI systems?
21 CFR Part 1311 governs Electronic Prescriptions for Controlled Substances and mandates a complete, tamper-evident audit trail for every step in the EPCS workflow — from prescriber authentication through pharmacy dispensing. For AI systems, this means any agent involved in processing, routing, or reviewing an EPCS must be traceable: which agent accessed the record, under what authorization, and what action was taken. The audit trail must demonstrate integrity — records cannot be modified after the fact. This requirement effectively mandates hash-linked or cryptographically secured logging for any automated system that participates in controlled substance prescribing or dispensing.
How does AutoPIL help pharmacies meet DEA CSA compliance for AI agents?
AutoPIL classifies Schedule II–V dispensing data at CRITICAL sensitivity and enforces per-agent access policies before any controlled substance data enters an agent's context window. Every access decision — allowed or denied — is written to a hash-linked audit chain that satisfies the tamper-evident recordkeeping expectations of 21 CFR Parts 1304 and 1311. AutoPIL's agent registry gates access by role and registration status, so unregistered or out-of-scope agents are denied before retrieval occurs. Policy IDs PHM-DEA-1304-001 and PHM-DEA-1311-001 are pre-built for dispensing record sensitivity and EPCS audit trail requirements respectively.
What are the enforcement risks for pharmacies that deploy AI without adequate DEA CSA controls?
DEA enforcement under the CSA can include civil monetary penalties, loss of DEA registration (which ends the ability to dispense controlled substances), and in cases of willful violation, criminal referral. Recordkeeping violations under 21 CFR Part 1304 — including incomplete or tampered logs — are a common basis for DEA inspection findings. For pharmacies deploying AI, the risk is that an agent accesses or returns Schedule II–V data without a traceable, auditable justification, creating a gap that inspectors can characterize as a recordkeeping failure. Inadequate access controls that allow unauthorized agents to query dispensing history compound this exposure.
Covered Industries

The DEA Controlled Substances Act applies to any organization that dispenses, distributes, or maintains records for Schedule I–V controlled substances — primarily retail and specialty pharmacies, hospital pharmacy operations, and the software platforms that automate their workflows. As AI agents take on roles in prescription processing, refill authorization, and drug utilization review, the CSA's tamper-evident recordkeeping and closed-system access requirements extend directly to those agents.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries