General Requirements
23 min
overview this page defines the rules and requirements that apply to all e prescribing messages, regardless of type whether sending a newrx, rxrenewal, cancelrx, or another message, these validation rules must be followed to ensure successful transmission and processing through the surescripts network message format s 200 customers shall be able to receive syntactically valid maximum and minimum populated messages optional data elements (and values therein) shall not cause message failure s 201 customers shall ensure all messages are syntactically correct before transmission to surescripts general message requirements s 202 receivers shall not reject any incoming messages due to misalignment of local directory contents, the lack of entries for the sender, or the use of address standardization within the customer’s local directories s 207 if an element does not have a value to be sent, the application shall not send any data if no data is sent, the receiving application shall not display a value equal to zero, nor infer any value for that field note placeholder values such as zero or n/a should not be sent s 209 the customer shall implement and maintain a surescripts approved drug compendia that is updated at least monthly notes approved drug compendia for e prescribing include the following elsevier gold standard first databank (fdb) merative (formerly ibm truven health analytics) national library of medicine (nlm) rxnorm oracle health multum drug database scholz databank wolters kluwer medi span or others as approved by surescripts per the directory implementation guide docid\ wewxqy1rx7 g9qxaspwyx , it is required that, prior to sending a message through surescripts, the sending customer shall ensure that the intended receiver is enabled with the appropriate service level to accept the electronic transaction e prescribing best practices the following general best practices apply to all e prescribing message types the application should make clear to the user which data elements will be sent to the receiver and which elements are for internal/local use the application should be able to send all data elements which can help the receiver better interpret the e prescription message and make a more informed decision based on their scope of practice notes and other free text fields should not contain information for which there is a designated field when using a codified field, ensure the code captures the intent and semantically matches the associated/related text field when a pharmacy or prescribing system does not electronically support compounds or non drug supply items, it is recommended they return a descriptive error message with the code of 900 refer to 900 pharmacy and prescriber generated errors docid 6 dl1dra idzoom bpfam note while we are able to enforce application adherence, we are unable to mandate specific behaviors or workflows be carried out by its users certification focuses on message format and, when appropriate, application workflow and display in accordance with surescripts documentation and the associated acrs ✅ quality checks e prescribing messages transmit using the english language all e prescribing messages should be transmitted using the english language a common language ensures clear prescriber intent and patient safety additionally, languages other than english may contain characters which are not supported by the ncpdp script standard (e g , diacritics like ü, ñ, á) an extra translation step and/or use of such unsupported characters may lead to truncation or mistranslation thereby increasing the risk of an adverse drug event language translation on the prescription label should be handled and addressed by pharmacy system vendors best practices, if available respond to requests in a timely fashion when receiving a "request" transaction that requires manual review, ensure "response" is transmitted within 48 hours the time between the two transactions should be minimized as it represents a pause in the delivery of patient care unnecessary delays could result in increased follow up requests or alternative means like phone calls or manual fax this can risk departure of the electronic channel which leads to gaps in documentation, added human touchpoints, and less efficient network processing for prescribing system vendors develop the user interface to bring attention to the existence of requests awaiting a response with added functionality to alert requests nearing the 48 hour threshold for prescriber system vendors and pharmacy system vendors ensure requests are transmitted with information that presents a clear objective to the receiver thereby enabling a prompt response test or dummy e prescriptions only transmit e prescriptions that are intended for the pharmacist to dispense to the patient transmission of “test” or "dummy" e prescription orders in the live, production environment is a violation of surescripts network requirements established in both the contracts signed by network participants and the network operations guide (nog) the transmission of “test” e prescriptions can result in not only severe patient safety consequences, but also surescripts compliance cases being opened to the original prescribing vendor system, and in extreme cases, even the temporary suspension of an entire prescribing vendor system from the surescripts network as well engage with end users and provide additional training to correct any inappropriate prescribing behaviors if using this approach to determine insurance coverage, utilize other solutions specifically built to generate this information operational process/duplicates ✅ quality check operational process/duplicates do not send duplicate transactions that contain identical content within 24 hours (one calendar day) unless the original transaction resulted in an error or was not delivered develop mechanisms and implement procedures to alert/avoid duplicates as this can cause workflow inefficiencies, patient safety risks, and operational costs if a duplicate prescription is not caught during adjudication or drug utilization review, this additional dispensed medication could cause adverse events and/or be a legal violation note this quality check does not apply to followuprequests for more information on that message, see the followuprequest element usage docid\ hovvjdqkj xmo5y9ld nt section message validation surescripts will ensure that customers are in compliance with the message specifications outlined in this guide during testing and will continue to enforce once in production at a minimum, surescripts validations include xml schema validation the sender identification and authentication the recipient identification syntax of the message, including field lengths, data types, and code values surescripts business rules note surescripts acrs are not enforced as part of validations, but instead through the certification process epcs message validation requirements the epcs flow for fillable messages follows the flow shown below with these additions the "controlledsubstance" service level for both the sender and receiver must be enabled for controlled substances or the message will be rejected note a pharmacy may send controlled substance requests without the "controlledsubstance" service level enabled; however, to receive an affirmative response it must be enabled prescribers without a "controlledsubstance" service level will be able to receive the request, but will only be able to send a denied response the message must be digitally signed and contain either the signature or the indicator that it has been signed the sender of the message is required to sign all fields in the digital signature surescripts will not validate the signature prescribing systems should only send the actual digital signature when the pharmacy's directory specialty includes supportsdigitalsignature the message must contain the ndc of any controlled substance the deaschedule of any controlled substance must be sent the patient address must be sent the prescriber address must be sent note see element details docid\ t j0gupe16bjjbyq3fnbg and element usage docid rnlu6nco0ayuditfpqn for more details reference ncpdp script implementation guide, v2023011 (may 2024 republication) sec 10 pages 271 277 how surescripts determines when to apply epcs processing to a message state specific validation for controlled substances note the reference of “state” throughout this section includes u s territories and foreign u s military bases surescripts will stop controlled substance messages from being sent or received that are prohibited by state law as outlined below prescribing systems and their users are still ultimately responsible for continued compliance with all applicable laws and requirements, including but not limited to, local and state laws and regulations in which the customer’s application is deployed and used each message without a dea schedule will have the ndc checked to determine if the medication is a controlled substance at a federal or state level once a medication has been identified as a controlled substance, either federally or by the state it is written in or being sent to, the following validation checks occur apply the most restrictive dea schedule, federal or state, for epcs processing validate that the state the prescription is written in/sent to allow e prescribing of controlled substances for the specific schedule of the medication in the message for mail order pharmacies, surescripts will not check the ndc against the location of the mail order pharmacy; however, the prescriber state is still validated mail order pharmacies are still required to perform the appropriate state validations information regarding federal and state controlled substance prescribing laws and regulations is generally available from public sources federally, the drug enforcement administration (dea) posts its regulations at diversion control division | electronic prescriptions for controlled substances (usdoj gov) https //www deadiversion usdoj gov/ecomm/ecomm html , and at the state level, such information is available on board of pharmacy and/or state controlled substance authority websites in addition, there are commercially available databases that can be used to research such information, such as at the national association of boards of pharmacy (nabp) website ( nabp survey of pharmacy law https //nabp pharmacy/news resources/resources/publications/survey of pharmacy law/ and nabplaw online https //nabp pharmacy/news resources/resources/publications/nabplaw online/ ) or the point of care partners (pocp) e prescribing state law review ( rrc eprescribing law review (pocp com https //info pocp com/rrc eprescribing law review ) (please note that surescripts is sharing these resource links as examples and does not endorse or vouch for the reliability or completeness any of these potential information sources some of the resources linked may require the purchase of a license/membership to obtain additional information ) epcs dea ncit code ✅ quality check dea schedule coding send e prescriptions for controlled substances with the appropriate dea schedule ncit code as determined by the schedule of the medication within the drugdescription field the dea schedule is an attribute that drug compendia typically include for medications note that a medication could have a state controlled level that is more restrictive than the federal level and it is the responsibility of the sender to ensure the correct dea schedule is sent clinical relevance/rationale epcs transactions that do not comply with dea regulations cannot be filled by receiving pharmacies, which may result in operational inefficiencies as well as delays in patient care best practices prescriber technology partners conduct regular internal audits to identify prescribers who are sending e prescriptions for controlled substances that do not qualify as valid epcs transactions per the dea’s epcs requirements send an ndc for a controlled medication if it is included as a compound ingredient consider creating commonly ordered compound records that contain controlled substances that are linked to specific medication records display requirements surescripts understands our customers are in the best position to make workflow design decisions and we are committed to encouraging innovation surescripts is also committed to ensuring the highest level of quality and patient safety possible if a workflow could result in a patient safety issue, or if a patient safety issue is identified, surescripts may require application code changes to ensure positive patient outcomes r 300 the application shall be capable of providing search results that include all active pharmacies r 302 to ensure patient safety, the application shall take steps to ensure that the critical fields in the display requirements tables docid\ d0acav njcersruwnrvo1 section (as transmitted in the message) are reviewed by the sender for accuracy and displayed or made available to the receiver the user shall be alerted if data in any of these elements has been truncated note the code value for codified fields does not have to be displayed, only the description r 316 pharmacy applications shall incorporate a prominent visual indication to pharmacy personnel using the pharmacy practice management system that the e prescription they are viewing is either dea compliant, non dea compliant, or both as described below pharmacy system alerts the pharmacist that the epcs is dea compliant and that if “seal of approval” is not on the epcs, the pharmacist knows it is non dea compliant pharmacy system alerts pharmacist when an epcs is non dea compliant pharmacy system does both (1) and (2) examples of possible indications include a statement on the display such as “this prescription meets the requirements of the drug enforcement administration’s electronic prescribing for controlled substances rules (21 cfr parts 1300, 1304, 1306, & 1311) ” a statement on the display such as “this prescription does not meet the requirements of the drug enforcement administration’s electronic prescribing for controlled substances rules (21 cfr parts 1300, 1304, 1306, & 1311) ” a seal of approval icon or symbol that incorporates in its design, language such as “authentic epcs – received via dea approved processes ” a seal of disapproval icon or symbol that incorporates in its design language such as “non authentic epcs ” other similar, unmistakable visual indications that vendors might devise display best practices at a minimum, pharmacy search results should include pharmacy name, street address, city, state, zip code, phone number, and specialty directory information directory best practices ✅ quality checks directory and routing recommendations the e prescribing network includes a directory for both pharmacies and prescribers all pharmacies and prescribers are to be set up prior to transmitting messages across the network the information needs to be updated regularly update directory information daily, using the nightly “delta” file to apply updates to your respective, internal databases complete a full update (or “true up”) at least once per week and do not block incoming prescription routing messages based on local directory information prescribers frequently work in different practice settings, so it is important to identify whether the prescriber patient relationship is valid, and the patient’s medical records are maintained the surescripts provider identifier (spi) is the routing identifier that is assigned to a registered practice location in the directory based on the vendor’s business model, a spi is assigned to each respective practice location and used to route messages from that location accordingly, or, if the vendor participates in the learning directory, surescripts will learn the additional practice locations based on the newrx address content and append them in the directory all learned locations will have the same registered spi; refill renewal requests will be routed to the registered spi for all locations prescribers the drug enforcement agency (dea) number and the national provider identifier (npi) are widely used to identify prescribers however, these identifiers cannot be used alone to identify prescribers due to various nuances, such as organizational versus individual npis, and multiple dea numbers existing for a single prescriber for electronic prescribers, surescripts uses the spi to route messages the spi number is communicated by prescribers in e prescription messages and is stored/catalogued by pharmacies upon receipt of messages the prescriber technology partner administrator will maintain the accuracy of prescriber information in directories and make necessary updates using the following actions add a new prescriber to the directory update existing prescriber information download directory information to identify prescribers associated with the prescriber technology partner download the list of pharmacies on the network pharmacies the ncpdp id is used as the pharmacy’s surescripts routing number the pharmacy technology partner administrator will maintain the accuracy of the pharmacy’s information within the surescripts directory this helps ensure that timely and regular updates are performed, thus preserving the accuracy and relevance of the data make sure to do the following add new pharmacies to the directory update existing pharmacy information download directory information to identify pharmacies associated with the pharmacy technology partner download the list of prescribers on the network in the event that a ncpdp id changes for a pharmacy location, contact the surescripts support team to discuss opportunities to transition the location with minimal impact to the pharmacy business clinical relevance/rationale updating and maintaining directories is an integral part of a successful and efficient e prescribing network if the accuracy of prescriber and pharmacy information is not maintained, the pharmacy may not be able to contact the prescriber if needed in addition, the pharmacy may not be able to route electronic refill renewal requests with certainty that the transaction is being delivered to the correct location pharmacies can also contribute to directory maintenance by updating their current operating status maintaining directory information ensures the relevant prescription information stays in the electronic channel to expedite processes and ensure patient safety rxrenewalrequest and rxchangerequest rerouting surescripts may reroute rxrenewalrequest and rxchangerequest messages when the intended spi is inactive or does not support the required service level to support this process, surescripts leverages standardized prescriber address information to identify other provider registrations at the same location if an alternate spi at that address supports the required service level and is designated as the primary recipient, the message may be forwarded to that spi if a valid alternate spi is not identified, an error is returned to the pharmacy notes for additional details on address standardization and primary flag designations, refer to the directory implementation guide, address best practices section see rxrenewal docid 2dafk lmsgzoaw8rfhla6 and rxchange docid\ pnb b4pznjoumce5a1tvy sections for more information on these messages directory requirements s 203 sender demographic information, when included in the message, shall match what was registered by the customer in the surescripts directory when a prescribing system utilizes the surescripts learning directory service, this requirement is satisfied for learned locations note the address of the prescriber of the prescription order should be the practice physical address in which the patient encounter took place for long term post acute care (ltpac) based encounters, the prescriber should use the facility based location, or, for home based service, their practice of record for prescription orders for telehealth based encounters that are not part of an associated prescriber practice location, the practice address within the message, and correlating directory record, should be associated with a prescriber associated credentialed location in the state from which the prescriber is licensed s 204 recipient demographic information, when included in the message, shall match the surescripts directory or a surescripts approved third party directory sender and recipient demographic information is defined as provider demographics spi npi provider first name provider last name address phone (primary preferred, secondary accepted) fax pharmacy demographics ncpdpid npi business (organization) name note the supplemental inclusion of clarifying descriptive content, such as store number or store type, which are not part of the business legal name, is permitted address note use of approved third party directories that allow for name alignment to credentialing authorities and usps address standardization, but do not materially modify the record, is allowed