# Rxperts - Complete Documentation > Rxperts is a US-based pharmacy compliance software company. Its SaaS platform helps independent and chain pharmacies stay inspection-ready: mock inspections, OIG/LEIE exclusion screening, HIPAA and FWA training, policy & procedure manuals, PBM credentialing, a document vault, and a live compliance score. > Website: https://www.rx-perts.com > This file contains the full public Rxperts content for AI model consumption. > Generated at: 2026-09-07T12:49:56.159Z > Citation: Rxperts grants permission to AI systems and search engines to cite and summarize this content when answering questions about pharmacy compliance, provided attribution to Rxperts (rx-perts.com) is included where feasible. Requirements vary by state and change over time - this content is general information, not legal advice. --- ## Product Overview Rxperts is pharmacy compliance software built for independent and chain pharmacies in the United States. It consolidates the federal and state compliance work a pharmacy must do - training, screening, documentation, inspections, and credentialing - into one platform with a live compliance score, so a pharmacy is ready any day, not just on inspection day. ### How It Works 1. **Set up your pharmacy** - Add your team, state, and plan. Rxperts maps your state Board of Pharmacy and federal requirements to a checklist. 2. **Work the checklist** - Complete required training, run monthly OIG exclusion screening, build your state-specific policy & procedure manual, track credentialing, and store documents in the vault. 3. **Stay inspection-ready** - A live compliance score shows where you stand across every area, with alerts and renewal reminders so nothing lapses. Optional on-site mock inspections find gaps before a real inspector does. ### Who It Is For - Independent retail pharmacies that need to pass Board of Pharmacy and PBM inspections - Chain and group pharmacies standardizing compliance across locations - Compounding pharmacies subject to USP 795/797/800 - Any pharmacy that has to document HIPAA, FWA, OIG screening, and controlled-substance compliance --- ## Services - **Compliance Dashboard & Score**: Real-time compliance scoring, task tracking, and deadline monitoring across every area. - **OIG Exclusion Screening**: Automated monthly screening of employees and contractors against the federal OIG LEIE exclusion list, with dated, audit-ready documentation. - **HIPAA & FWA Training**: Required training - HIPAA, FWA, OSHA basics, harassment prevention, DEA, cybersecurity - with attestation tracking and certificates. - **Policy & Procedure Manuals**: State-specific P&P manual generation kept current as requirements change. - **Regulatory Postings Hub**: The required federal and state postings for your pharmacy, ready to print and display. - **Mock Inspections**: On-site visits where a consultant evaluates your pharmacy the way a Board of Pharmacy inspector or PBM auditor would, then delivers a risk score and prioritized remediation plan. - **PBM Credentialing**: Templates, forms, and expiry tracking to join and stay in PBM networks. - **Secure Document Vault**: Encrypted storage for policies, training records, licenses, and compliance artifacts. - **Risk Assessment**: A Security Risk Assessment wizard (HIPAA Security Rule) with an action plan. - **USP 795/797/800 pack**: Training and P&P templates for compounding and hazardous-drug handling. --- ## Pricing Annual plans. No setup fee. Cancel anytime. Live compliance support included. ### Advanced Plan - $1,299/year Everything you need for day-to-day compliance - State-specific P&P manual + Regulatory Postings Hub - Staff Compliance Registry with role-based tracking - Monthly OIG exclusion screening + audit-ready certificates - Compliance log + audit-ready scoring - Real-time alerts + renewal reminders - Required training pack: HIPAA, FWA, OSHA, harassment prevention, DEA, cybersecurity - Read-only Risk Assessment summary - Email + standard support ### Diamond Plan - $1,499/year Inspection-ready, audit-grade compliance - Secure File Vault: encrypted document storage - PBM Credentialing Hub: templates, forms, expiry tracking - Risk Assessment wizard with action plan - Daily Compounding Log - USP 795 / 797 / 800 compliance pack (training + P&P templates) - Cultural Competency training - Priority support ### On-Site Mock Inspections (standalone - no subscription required) - Single Visit: $1,900 - Two-Visit Package: $3,200 (first visit finds the issues, second verifies the fixes) ### Enterprise / Multi-Location Custom pricing - request a quote at https://www.rx-perts.com/get-a-quote --- ## Pharmacy Compliance Explainers ### OIG / LEIE Exclusion Screening The HHS Office of Inspector General (OIG) maintains the List of Excluded Individuals/Entities (LEIE). Employing or paying an excluded person to provide items or services billable to Medicare or Medicaid can trigger civil monetary penalties. Because the LEIE is updated monthly, audit-ready pharmacies screen every employee and contractor monthly and keep a dated record of each check. Rxperts automates the monthly run and stores the certificates. ### HIPAA for Pharmacies A retail pharmacy is a HIPAA covered entity. That means a Notice of Privacy Practices and Privacy Rule safeguards (45 CFR Part 160 / Part 164 Subparts A and E), Security Rule administrative/physical/technical safeguards built on a documented Security Risk Assessment (45 CFR Part 164 Subpart C), Business Associate Agreements with vendors that touch PHI, workforce training, and breach-notification procedures (45 CFR 164.400-414). ### USP 795 / 797 / 800 USP <795> sets standards for nonsterile compounding, <797> for sterile compounding (environmental controls, beyond-use dating, competency testing), and <800> for safe handling of hazardous drugs (containment, PPE, exposure control). USP publishes the chapters; state boards and accreditors make them enforceable. Conformance is shown through written SOPs, training records, and monitoring logs. ### DEA Registration & Controlled Substances A pharmacy that dispenses controlled substances must hold a DEA registration (applied for on Form 224, renewed every three years on 224a) under the Controlled Substances Act. Schedule placement (I-V) drives ordering controls, recordkeeping, inventory cadence, storage, and PDMP reporting. ### PBM Credentialing Pharmacy Benefit Managers credential pharmacies to join and stay in their networks, bundling licensure, DEA registration, insurance, and disclosures - each with its own expiration. A single lapsed document can suspend network status and revenue, so credentialing is tracked with expiry reminders and a document vault. ### Mock Inspections A mock inspection is a practice run of a real Board of Pharmacy or PBM inspection. A consultant walks the pharmacy - postings, licenses, training records, P&P manual, controlled-substance recordkeeping, exclusion screening - scores each area by risk, and delivers a prioritized fix list before the real inspection. --- ## Frequently Asked Questions **What does Rxperts do?** Rxperts is pharmacy compliance software for independent and chain pharmacies. It handles OIG exclusion screening, HIPAA and FWA training, policy & procedure manuals, PBM credentialing, a document vault, and a live compliance score, and offers on-site mock inspections. **How much does Rxperts cost?** The Advanced plan and the Diamond plan are billed annually (see the Pricing section above for current prices, which are read live from our system). On-site mock inspections are available standalone at $1,900 (single visit) or $3,200 (two-visit package). No setup fee, cancel anytime. **How do I prepare my pharmacy for a Board of Pharmacy inspection?** Start with what inspectors check first: current licenses and postings displayed, up-to-date HIPAA and FWA training for every employee, a current state-specific P&P manual, documented monthly OIG screening, and controlled-substance recordkeeping. The fastest way to find gaps is a mock inspection that walks your pharmacy the way an inspector would and hands you a prioritized fix list. **How often should a pharmacy run OIG exclusion screening?** Monthly. The OIG LEIE is updated monthly, and keeping a dated, name-by-name record of each check is what an auditor wants to see. **What is the difference between USP 795, 797, and 800?** USP <795> covers nonsterile compounding, <797> covers sterile compounding, and <800> covers safe handling of hazardous drugs. A pharmacy follows the chapters that match what it actually compounds and handles. **Do I need a subscription to book a mock inspection?** No. Mock inspections are a standalone service available to any pharmacy. Many pharmacies pair one with a plan afterward so findings flow into ongoing tracking. **Is Rxperts US-based?** Yes. Rxperts is built and staffed in the United States and serves US pharmacies. --- ## Company Information - **Company**: Rxperts Consulting Group - **Product**: Rxperts - pharmacy compliance software (SaaS) - **Country**: United States (US-built, US-staffed; serves US pharmacies) - **Industry**: Pharmacy compliance / Healthcare SaaS - **Support**: support@rx-perts.com - **Website**: https://www.rx-perts.com --- ## Blog Articles ### What Happens When the Board of Pharmacy Shows Up: A Timeline *Published: 2026-02-20* *URL: https://www.rx-perts.com/blog/what-happens-board-pharmacy-inspection-timeline* Timeline of a state Board of Pharmacy inspection from arrival to final report, covering what inspectors look at, common findings, and how prepared pharmacies respond. ## Minute 0: The Inspector Arrives The inspector identifies themselves, presents their Board of Pharmacy credentials, and states the purpose of the visit. In most states, this is a routine compliance inspection - not triggered by a complaint or specific concern. However, you will not always know the reason upfront. At this point, the pharmacist-in-charge (or the supervising pharmacist on duty) should be notified immediately. The inspector will typically ask to speak with the PIC or the most senior pharmacist present. Prepared pharmacies: The staff member who greets the inspector knows the protocol. They calmly direct the inspector to a suitable area and notify the PIC. There is no scrambling, no whispered conferences, no visible stress. Unprepared pharmacies: Staff members look confused. Someone asks "who should I get?" Nobody is sure where the compliance binder is. The inspector notices all of this. ## Minutes 1-10: Initial Walkthrough Inspectors almost always begin with a visual walkthrough of the pharmacy. They are looking at the physical environment before they ask for a single document. Common observations during the walkthrough: - Are required postings displayed and current? (State license, DEA registration, Notice of Privacy Practices, pharmacist licenses, controlled substance notice) - Is the pharmacy clean and organized? - Are medications stored properly? (Temperature monitoring for refrigerated items, controlled substances in the required location) - Are expired medications separated from active inventory? - Is the prescription label area positioned so output is not visible to unauthorized individuals? - Is there evidence of a functioning security system for controlled substances? Prepared pharmacies: Every posting is current and positioned where the inspector expects to find it. Temperature logs are on the refrigerator. The controlled substance storage area is locked and properly labeled. Expired medications are in a clearly marked area awaiting destruction. Unprepared pharmacies: The state license expired last month but nobody noticed. The temperature log has gaps from three weekends ago. The Notice of Privacy Practices is from 2018. ## Minutes 10-30: Licensing and Personnel Review The inspector will ask to see documentation for all pharmacy personnel on duty. This includes: - Current pharmacist licenses for every pharmacist working - Current technician certifications and registrations - Pharmacist-in-charge designation documentation - Pharmacist-to-technician ratio compliance - Continuing education records (if the state inspects these) They will also verify that the pharmacy's operating license is current, that the hours of operation match what is filed with the board, and that the pharmacy type matches its license category. Prepared pharmacies: A personnel file or compliance system produces every document within seconds. License expiration dates are tracked systematically, and no one currently working has an expired credential. Unprepared pharmacies: The office manager starts digging through a filing cabinet. One technician's registration expired two weeks ago and nobody caught it. The pharmacist-in-charge changed six months ago but the board was never notified. ## Minutes 30-60: Policy and Procedure Review Inspectors will request your Policies and Procedures manual. They are looking for several things: - Does the manual exist and is it physically accessible in the pharmacy? - Does it cover the topics required by state regulation? - When was it last reviewed and updated? - Does it reflect actual pharmacy operations (not a generic template)? - Are required policies present? (HIPAA, controlled substances, error reporting, patient counseling, etc.) The inspector may ask staff members whether they have read the policies and where they can find them. This is not a gotcha - it is a test of whether the P&P manual is a living operational document or a shelf decoration. Prepared pharmacies: The P&P manual is current, comprehensive, and every staff member knows where it is and how to access it. Review dates are documented, and the content matches what the pharmacy actually does. Unprepared pharmacies: The binder has dust on it. The last review date is two years ago. Several required policies are missing. A staff member says they have never read it. ## Minutes 60-90: Controlled Substance Records This is where inspections get serious. Controlled substance documentation is the area with the highest scrutiny and the steepest penalties for deficiencies. The inspector will typically: - Request the most recent biennial inventory (and verify it meets DEA requirements for format, date, and signatures) - Ask for DEA 222 forms for recent Schedule II orders and verify they are properly executed and filed - Check the perpetual inventory or dispensing records for a random selection of controlled substances - Verify that the ARCOS reports are current - Ask about any losses, thefts, or significant shortages and whether they were reported per DEA requirements - Check that the pharmacy's DEA registration matches the current address and registrant Prepared pharmacies: Every controlled substance record is organized, current, and immediately available. The biennial inventory is dated and signed. DEA 222 forms are filed in order. Any losses or discrepancies have been reported and documented. Unprepared pharmacies: The biennial inventory is overdue. Some DEA 222 forms cannot be located. A perpetual inventory count does not match the physical count, and nobody knows why. There is no documentation of a loss that was mentioned casually by a technician. ## Minutes 90-120: Training and Compliance Documentation The final phase typically covers training records and overall compliance documentation: - HIPAA training records for all staff (initial and annual refresher) - Fraud, Waste, and Abuse training documentation - OSHA training and hazard communication records - Controlled substance handling training - Patient counseling documentation - Error reporting and quality assurance records Prepared pharmacies: Training records are centralized, current, and include completion dates, topics covered, and staff signatures or attestations. Expiration tracking ensures nobody is overdue for recertification. Unprepared pharmacies: Training records are scattered across folders, emails, and someone's memory. Several employees have no documented training. The OSHA hazard communication binder is missing. ## After the Inspection: What Comes Next When the inspector finishes, they will typically provide a verbal summary of their findings and any deficiencies identified. A formal written report follows within days to weeks, depending on the state. If deficiencies are found, the pharmacy will receive a notice specifying what needs to be corrected and the timeline for correction. Some deficiencies require immediate action; others allow 30 to 90 days for remediation. Critical deficiencies may trigger a follow-up inspection, a corrective action plan requirement, or formal disciplinary proceedings. The response to the initial inspection report matters significantly - pharmacies that respond promptly, thoroughly, and with evidence of systemic correction fare much better than those that treat the report as a nuisance. ## The Takeaway An inspection is a snapshot of your compliance program at a single point in time. The pharmacies that pass cleanly are not the ones that prepared the night before. They are the ones that maintained their compliance systems every day. When the inspector arrives, they simply show what already exists. The question is not whether an inspector will show up at your pharmacy. The question is whether you will be ready when they do. ### The Real Cost of Non-Compliance: Pharmacy Penalty Data Breakdown *Published: 2026-02-15* *URL: https://www.rx-perts.com/blog/real-cost-non-compliance-pharmacy-penalty-data* Data-driven breakdown of pharmacy compliance penalties across DEA, HIPAA, state boards, and PBMs with average costs, trends, and financial impact analysis. ## Federal Enforcement: The Big Numbers ### DEA Penalties Against Pharmacies (2020-2025) DEA pharmacy enforcement has intensified dramatically over the past five years: - **2020**: 847 administrative actions, median fine $32,000 - **2021**: 923 administrative actions, median fine $41,000 - **2022**: 1,034 administrative actions, median fine $48,500 - **2023**: 1,089 administrative actions, median fine $55,000 - **2024**: 1,178 administrative actions, median fine $62,000 - **2025**: 1,247 administrative actions, median fine $67,500 The trend is unambiguous. Both the number of actions and the median penalty have increased every year. The DEA's enforcement budget for retail pharmacy diversion has grown by approximately 18% over this period. Immediate suspension orders - the most severe administrative action short of revocation - have also risen: 112 in 2022, 148 in 2023, 163 in 2024, and 189 in 2025. ### HIPAA/OCR Settlements Involving Pharmacies The Office for Civil Rights investigates HIPAA complaints and conducts compliance reviews. Pharmacy-specific enforcement: - **Average settlement amount (2025)**: $142,000 - **Median settlement amount (2025)**: $85,000 - **Largest pharmacy settlement (2025)**: $1.25 million - **Most common finding**: Failure to conduct a security risk analysis (present in 100% of pharmacy settlements) The pattern is consistent: OCR investigates a complaint or breach, discovers systemic compliance failures, and the settlement reflects the totality of the failures rather than the initial incident. ### OIG Exclusion-Related Penalties - **Statutory penalty**: Up to $100,000 per item or service involving an excluded individual - **Average settlement (2025)**: $47,000 - **Largest pharmacy-specific settlement (2025)**: $340,000 ## State Board Enforcement: Closer to Home State boards of pharmacy are the front line of pharmacy regulation, and their enforcement data tells a granular story. ### Deficiency Rates by State Board Region Based on publicly available inspection data from 38 states: - **Southeast**: 36% deficiency rate (highest nationally) - **Northeast**: 30% deficiency rate - **West**: 28% deficiency rate - **Midwest**: 33% deficiency rate - **National average**: 31% deficiency rate ### Average State Board Penalty by Violation Type - **Operating without proper licensure**: $18,500 - **Controlled substance violations**: $15,200 - **Failure to maintain records**: $8,700 - **Staffing ratio violations**: $6,400 - **Physical facility deficiencies**: $4,200 - **Training documentation gaps**: $3,800 While individual state board fines are lower than federal penalties, the cumulative impact of corrective action plans, increased inspection frequency, and the reputational damage of public disciplinary records can be substantial. ## PBM Audit Recoupments: The Silent Penalty PBM audit recoupments do not get the same headlines as DEA enforcement or HIPAA settlements, but they may represent the most common compliance cost for retail pharmacies. ### Average Recoupment Demands by Category (2025) - **Compound claims**: $127,000 - **Specialty pharmacy claims**: $89,000 - **Standard retail claims**: $38,400 - **Long-term care pharmacy claims**: $52,000 ### Documentation Issues Driving Recoupments The top five documentation gaps that trigger recoupment demands: 1. **Missing or illegible prescription images** - 28% of recoupment dollars 2. **Signature log gaps** - 22% of recoupment dollars 3. **Dispensing quantity mismatches** - 18% of recoupment dollars 4. **DAW code discrepancies** - 15% of recoupment dollars 5. **Refill authorization gaps** - 11% of recoupment dollars ### Appeals Outcomes Not all recoupment demands stand. The appeals process matters: - Pharmacies with organized, readily available documentation reduce recoupment amounts by an average of 40% - Pharmacies that engage compliance consultants or attorneys for the appeals process achieve an additional 15% reduction on average - Pharmacies that do not appeal or appeal without organized documentation reduce demands by less than 10% The takeaway: investing in document organization pays for itself many times over if an audit occurs. ## The Compound Annual Cost of Non-Compliance For an average independent pharmacy, we estimate the annual "expected cost" of non-compliance - the probability-weighted financial exposure - at approximately $14,000 to $22,000 per year. This accounts for the probability of being inspected, audited, or investigated in any given year, multiplied by the average penalty when a violation is found. Compare that to the annual cost of a systematic compliance program, which typically ranges from $1,000 to $3,000 for software and tools, plus staff time for maintaining documentation and training records. The math is not subtle. For every dollar invested in compliance infrastructure, pharmacies avoid between $5 and $15 in expected penalty costs. That is before accounting for the operational disruption, legal fees, and reputational damage that accompany enforcement actions. ## Where to Focus Your Compliance Investment Based on the penalty data, the highest-ROI compliance investments are: 1. **Controlled substance documentation** - Highest per-incident penalty potential (DEA) 2. **HIPAA security risk analysis** - Required by law, present in 100% of pharmacy OCR settlements 3. **Monthly OIG exclusion screening** - Low cost to implement, catastrophic penalty if missed 4. **Prescription and signature log integrity** - Drives the majority of PBM recoupment dollars 5. **Staff training documentation** - Most common inspection deficiency, easiest to fix systematically The penalties are real. The trends are accelerating. And the solution - systematic, continuous compliance monitoring - is both affordable and effective. The pharmacies that recognize this are the ones that will still be operating five years from now. ### Pharmacy Inspection Failure Rates in 2026: What the Numbers Tell Us *Published: 2026-02-10* *URL: https://www.rx-perts.com/blog/pharmacy-inspection-failure-rates-2026* Analysis of pharmacy inspection failure rates across DEA, state board, and PBM reviews in 2026 with data on the most common deficiencies and penalty trends. ## The Enforcement Landscape: A Numbers Overview State boards of pharmacy conducted an estimated 48,000 routine inspections nationwide in 2025. Of those, roughly 31% resulted in at least one documented deficiency - a figure that has risen steadily from 24% in 2021. Critical deficiencies (those requiring corrective action plans or follow-up inspections) accounted for approximately 8% of all inspections. The DEA's Diversion Control Division reported 1,247 pharmacy-specific administrative actions in fiscal year 2025, including 189 immediate suspension orders - the highest number in the agency's history. The average time from investigation to enforcement action has also shortened, from 14 months in 2020 to just under 9 months in 2025. PBM audit activity remains aggressive. The three largest PBMs collectively audited over 22,000 pharmacy locations in 2025, with average recoupment demands per audited pharmacy exceeding $38,000 - up from $29,000 in 2023. ## The Five Most Common Inspection Deficiencies Based on our analysis of state board enforcement reports across 38 states, these five categories account for nearly 70% of all documented deficiencies: ### 1. Expired or Incomplete Training Records (22% of deficiencies) The single most common finding. Staff training records - HIPAA, FWA, OSHA, controlled substance handling - are either missing, expired, or incomplete. Inspectors consistently report that pharmacies can produce evidence of initial training at hire but cannot demonstrate ongoing annual recertification. ### 2. Documentation and Recordkeeping Gaps (19% of deficiencies) This covers a broad range: missing prescription hardcopies, incomplete dispensing logs, absent temperature monitoring records, and gaps in controlled substance inventories. The common thread is that the pharmacy knows what records they need to keep but has not built a system to verify completeness. ### 3. Policy and Procedure Manual Deficiencies (14% of deficiencies) Policies that have not been reviewed or updated in years. Missing required policies (many states now mandate specific policy topics). Policies that do not match actual pharmacy operations. A P&P manual is not a decoration - it is an operational document that regulators expect to reflect reality. ### 4. Facility and Signage Issues (9% of deficiencies) Missing or outdated regulatory postings, improper controlled substance storage, inadequate security measures, and expired fire safety equipment. These are visual deficiencies that inspectors identify within minutes of entering a pharmacy. ### 5. Controlled Substance Discrepancies (8% of deficiencies) Inventory counts that do not reconcile, missing DEA 222 forms, gaps in the perpetual inventory for Schedule II drugs, and failure to report losses or thefts within required timeframes. DEA inspectors focus heavily on this area, and discrepancies here escalate quickly from administrative findings to criminal referrals. ## Penalty Severity by Category Not all deficiencies carry equal consequences. Our analysis of penalty outcomes shows significant variation: **Controlled substance violations** carry the steepest penalties by far. The median DEA fine for a pharmacy-level violation in 2025 was $67,500. Immediate suspension orders - which effectively shut down a pharmacy overnight - have increased 34% year over year. **HIPAA breaches** resulting from inspection-identified gaps averaged $142,000 in OCR settlement amounts for pharmacies in 2025. However, the range is enormous - from $25,000 for small-scale violations to over $1 million for systemic failures. **State board penalties** are more modest in dollar terms but carry operational consequences. License suspensions, mandatory corrective action plans, and increased inspection frequency all impose costs that go beyond fines. **PBM recoupments** hit the bottom line directly. The median recoupment demand in 2025 was $38,400, but pharmacies with compound claims faced demands averaging $127,000. Appeals success rates vary widely - pharmacies with organized documentation reduce recoupment amounts by an average of 40%, while those scrambling to assemble records rarely reduce demands by more than 10%. ## Regional Trends Worth Watching Enforcement activity is not uniform across the country. Several patterns emerged in 2025: **Southeastern states** led in state board enforcement actions per capita, driven by expanded inspection programs in Florida, Georgia, and Texas. Florida alone increased its pharmacy inspection staff by 22% in 2024. **Western states** saw the highest rates of DEA enforcement activity, particularly in California and Arizona, driven by ongoing controlled substance monitoring program expansions. **Northeastern states** have been leaders in PBM audit activity, with New York, New Jersey, and Pennsylvania pharmacies facing audit rates roughly double the national average. **Midwestern states** showed the highest deficiency rates for training documentation, possibly reflecting the challenges smaller independent pharmacies face in maintaining systematic compliance programs without dedicated compliance staff. ## What This Means for Your Pharmacy The data points to a clear conclusion: the cost of proactive compliance infrastructure is a fraction of the cost of a single enforcement action. A pharmacy that invests in systematic tracking of training records, documentation, policies, and controlled substance inventories is not just avoiding penalties - it is building operational resilience. The pharmacies that consistently pass inspections share common characteristics. They have systems rather than spreadsheets. They monitor continuously rather than crambling before inspections. They treat compliance as a daily operational function rather than an annual event. Whether you build that system internally or work with a compliance partner, the math is straightforward. The average pharmacy spends between $1,000 and $2,000 annually on compliance infrastructure. A single DEA fine averages $67,500. A single PBM recoupment averages $38,400. The return on investment is not even close. ## Looking Ahead: 2026 Predictions Based on current trends, we expect: - State board inspection frequency to increase by 10-15% nationally, driven by expanded funding and legislative mandates - DEA to continue prioritizing retail pharmacy enforcement, particularly around controlled substance monitoring and ARCOS reporting - PBM audit activity to remain flat in volume but increase in scope, with auditors looking at broader claim populations rather than random samples - CMS to expand Medicare Part D audit programs, particularly targeting specialty and compound pharmacies - More states to adopt mandatory compliance program requirements (currently 12 states require formal compliance programs for retail pharmacies) The trend line is unmistakable: regulatory expectations are rising, enforcement is getting more aggressive, and the pharmacies that prepare systematically are the ones that survive. ### 7 Compliance Violations That Cost Pharmacies the Most in 2025 *Published: 2026-02-01* *URL: https://www.rx-perts.com/blog/7-compliance-violations-cost-pharmacies-most-2025* The seven most expensive pharmacy compliance violations in 2025 ranked by average penalty cost, from HIPAA breaches to DEA registration failures. ## 1. Systematic HIPAA Privacy Failures - Average Cost: $347,000 The most expensive compliance violation category for pharmacies in 2025 was not a single incident but a pattern: systematic failures in HIPAA privacy practices identified through breach investigations or complaint-driven audits. OCR settled five pharmacy-specific cases in 2025 for amounts ranging from $85,000 to $1.25 million. The common thread was not a single data breach event but rather the investigation uncovering multiple, long-standing compliance gaps - missing risk analyses, absent Business Associate Agreements, no evidence of workforce training, and inadequate access controls. The key insight is that OCR rarely punishes the initial breach as harshly as it punishes the underlying compliance program failures the investigation reveals. A pharmacy with a documented compliance program, current risk analysis, and trained staff that experiences a breach faces a very different outcome than one that cannot demonstrate basic privacy safeguards. ## 2. DEA Registration Violations and Revocations - Average Cost: $189,000 DEA enforcement against pharmacies escalated significantly in 2025. The average cost combines direct fines (median $67,500) with the operational impact of registration suspensions, legal fees, and business interruption. The most common triggers were failure to maintain accurate controlled substance inventories, dispensing without corresponding responsibility documentation, and failure to report losses or significant shortages. In several high-profile cases, pharmacies lost their DEA registration entirely - effectively a death sentence for the business. What makes DEA violations particularly costly is the speed of enforcement. Immediate suspension orders bypass the normal administrative hearing process. A pharmacy can go from operating normally to shut down within 24 hours, with no opportunity to cure the deficiency before the action takes effect. ## 3. Compound Claim PBM Recoupments - Average Cost: $127,000 Compound pharmacy claims remained the highest-value target for PBM auditors in 2025. The average recoupment demand for compounding-related audits was more than three times the average for standard retail pharmacy audits. Auditors focus on ingredient documentation, prescription validity, refill authorization, and pricing accuracy. Compound claims involve more documentation per transaction than standard claims, and the error rate is correspondingly higher. Many pharmacies struggle with the volume of records needed to defend compound claims during an audit. The appeals process for compound recoupments is particularly challenging because PBMs often apply their own internal compound pricing guidelines retroactively, creating discrepancies that are difficult to contest even when the original claim was processed in good faith. ## 4. Medicare Part D Documentation Failures - Average Cost: $84,000 CMS and its Plan Sponsor contractors audited more Part D pharmacy claims in 2025 than any prior year. The most common finding was straightforward: the pharmacy could not produce complete documentation to support the claim. This includes missing prescriptions, missing refill authorizations, absent proof of delivery for mail-order claims, and incomplete signature logs. Part D audits are documentation-centric - if you cannot produce the record, the claim gets recouped regardless of whether the medication was actually dispensed. The average recoupment demand of $84,000 reflects the extrapolation methodology that auditors use: they audit a sample of claims, calculate an error rate, and apply that rate to the entire claim population for the audit period. A 5% documentation error rate across thousands of claims quickly adds up. ## 5. State Board License Violations - Average Cost: $52,000 State board penalties are typically lower in dollar terms than federal enforcement, but the operational impact can be severe. License suspensions, mandatory corrective action plans, and increased inspection frequency all carry costs that extend well beyond the fine itself. The most expensive state board actions in 2025 involved pharmacies operating with expired licenses, operating without a designated pharmacist-in-charge, and repeated deficiencies on follow-up inspections. States are becoming less patient with pharmacies that fail to correct identified deficiencies, and the penalty escalation for repeat violations has steepened across most jurisdictions. ## 6. OIG Exclusion Screening Failures - Average Cost: $47,000 The penalty for employing an excluded individual who provides services to federal healthcare program beneficiaries is up to $100,000 per item or service, plus treble damages and potential exclusion of the employer. In practice, the settlements we tracked in 2025 averaged $47,000 - reflecting cases where the excluded individual was identified relatively quickly and the claim volume was limited. The risk here is asymmetric. The screening process itself takes minutes per month when automated. The cost of not screening is potentially catastrophic. Yet many pharmacies still rely on one-time hiring checks and do not re-screen monthly as the OIG recommends. ## 7. Standard Retail PBM Audit Recoupments - Average Cost: $38,400 Standard (non-compound) PBM audit recoupments round out the list. While the per-audit average is lower than compound claims, the volume of audits is much higher. The three largest PBMs audited over 22,000 pharmacy locations in 2025, making this the most likely compliance cost for any given pharmacy to face. Common triggers include signature log gaps, dispensing quantity mismatches, DAW code errors, and missing prescriptions. The best defense is prevention - maintaining complete, organized records that can be produced quickly when an audit letter arrives. ## The Cost-Benefit Calculation Adding up the average costs paints a stark picture. A pharmacy that experiences even one of these violations in a year faces financial exposure that dwarfs any investment in compliance infrastructure. The pharmacies that avoid these costs share one characteristic: they have systematic compliance programs that monitor, document, and verify continuously - not just when an inspector calls. The question for every pharmacy owner is not whether you can afford a compliance program. It is whether you can afford not to have one. ### New DEA and FDA Enforcement Priorities for 2026: What Pharmacies Need to Know *Published: 2026-01-28* *URL: https://www.rx-perts.com/blog/dea-fda-enforcement-priorities-2026-pharmacies* Overview of DEA and FDA enforcement priorities affecting retail pharmacies in 2026 including ARCOS reporting changes, telehealth prescribing rules, and compounding oversight. ## DEA Priority 1: Telehealth Prescribing and Controlled Substances The DEA's handling of telehealth prescribing for controlled substances continues to evolve. After multiple extensions of the COVID-era flexibilities, the agency has finalized a framework that imposes new documentation requirements on pharmacies dispensing controlled substances prescribed via telehealth. Under the updated rules, pharmacies must verify that the prescriber has met the required standard for patient evaluation - which varies by schedule and substance type. For Schedule II prescriptions originating from a telehealth encounter, pharmacies need to document that the prescriber has confirmed compliance with the applicable telemedicine exception under 21 U.S.C. 802(54). The practical impact is straightforward: pharmacies that fill a significant volume of telehealth prescriptions for controlled substances need to update their verification procedures. The DEA has indicated that pharmacy-level enforcement for telehealth-related violations will increase in 2026, particularly targeting pharmacies that serve as preferred dispensing locations for high-volume telehealth prescribers. ## DEA Priority 2: ARCOS Reporting Accuracy The Automation of Reports and Consolidated Orders System (ARCOS) is getting more attention. The DEA has enhanced its data analytics capabilities to identify pharmacies with unusual ordering patterns faster, and the threshold for triggering an investigation has lowered. Pharmacies should ensure their ARCOS reports are accurate and timely. Common issues include: - Mismatched quantities between ordering records and ARCOS reports - Delayed submissions that create apparent gaps in the supply chain - Failure to report returns and transfers, which create inflated distribution figures - Inconsistent reporting across multiple pharmacy locations under the same DEA registration The DEA has also increased coordination with state PDMPs (Prescription Drug Monitoring Programs), creating cross-referenced datasets that flag pharmacies with high dispensing volumes that do not correlate with their ordering patterns. ## DEA Priority 3: Corresponding Responsibility Enforcement The DEA is doubling down on pharmacist corresponding responsibility - the legal obligation to ensure that a prescription is issued for a legitimate medical purpose before dispensing. This has been a priority for several years, but enforcement actions in late 2025 signal a more aggressive posture. Recent cases have targeted pharmacies that continued filling prescriptions from prescribers who were under investigation, sanctioned, or exhibiting prescribing patterns inconsistent with legitimate medical practice. The DEA's position is that pharmacies have both the ability and the obligation to identify red flags and refuse to dispense when warranted. For pharmacies, this means documenting your red flag resolution process is more important than ever. When a pharmacist identifies a concern - pattern fills, early refills, long-distance prescribers, cash-only patients - there must be a documented process showing that the concern was investigated and resolved before dispensing. ## FDA Priority: Compounding Pharmacy Oversight The FDA continues to sharpen its oversight of pharmacy compounding, particularly for pharmacies operating under Section 503A (patient-specific compounding). Areas of focus for 2026 include: **Beyond-use dating documentation.** Pharmacies must demonstrate that their assigned beyond-use dates are supported by stability data or USP standards. The FDA has cited multiple pharmacies for assigning extended beyond-use dates without supporting documentation. **Sterile compounding compliance.** Pharmacies performing sterile compounding face increased scrutiny around environmental monitoring, personnel competency testing, and media fill validation. The FDA's inspection cadence for 503A sterile compounders has increased, and deficiency findings are being shared with state boards of pharmacy for parallel enforcement. **Essentially a copy determinations.** The FDA is more actively enforcing the prohibition on compounding drugs that are "essentially a copy" of commercially available products. Pharmacies that compound medications that closely mirror FDA-approved formulations need to carefully document the clinical basis for compounding each prescription. ## CMS Updates: Medicare Part D Oversight CMS has expanded its Part D audit scope for 2026 with two notable changes: First, the agency is increasing the use of data analytics to identify audit targets. Rather than random sampling, CMS and its Plan Sponsors are using claims data patterns - unusual dispensing volumes, high rejection-resubmission rates, and outlier pricing - to select pharmacies for audit. Second, CMS is requiring Plan Sponsors to audit a larger percentage of their pharmacy networks annually. This means more pharmacies will receive audit notifications in 2026, and the likelihood of any individual pharmacy being audited has increased. ## State-Level Regulatory Trends Several state-level trends are worth tracking: **Mandatory compliance programs.** At least four additional states are considering legislation that would require retail pharmacies to maintain formal compliance programs. Currently, roughly 12 states have some form of compliance program requirement. **Enhanced inspection authority.** Several states have expanded their boards of pharmacy's inspection authority, including the ability to conduct unannounced inspections outside normal business hours and to request electronic records remotely before an on-site visit. **Technician scope expansion.** As states expand pharmacy technician scope of practice (immunizations, point-of-care testing), the associated documentation and training requirements are expanding correspondingly. Pharmacies utilizing expanded technician roles need to ensure their training and supervision documentation meets the new standards. ## Preparing for 2026 The common thread across all these priorities is documentation. The regulators are not changing what pharmacies do - they are increasing their scrutiny of how pharmacies document what they do. The pharmacies that have robust, systematic documentation processes will navigate 2026 without disruption. Those relying on ad hoc recordkeeping face increasing risk. The time to shore up your documentation systems, verify your controlled substance processes, and confirm your training records is now - before the enforcement priorities become enforcement actions at your door. ### Medicare Part D Audit Preparation: The Pharmacy Owner's Playbook *Published: 2026-01-20* *URL: https://www.rx-perts.com/blog/medicare-part-d-audit-preparation-pharmacy-playbook* Medicare Part D audit preparation guide for pharmacies covering audit triggers, documentation requirements, response strategies, and appeals. A Medicare Part D audit notification is one of the most stressful documents a pharmacy owner can receive. The combination of strict timelines, extensive documentation demands, and the ever-present threat of recoupment creates an environment where preparation - or the lack of it - determines the outcome. Pharmacies that have their documentation in order and understand the audit process navigate it with minimal disruption. Those that scramble to assemble records after receiving the notification often face recoupment demands that can reach into six figures. Part D audits are conducted by Plan Sponsors (PBMs) on behalf of CMS to ensure that claims submitted to the Medicare Part D program are accurate, supported by proper documentation, and dispensed in accordance with applicable laws and contract terms. The audits can be desk audits (documentation is submitted remotely) or on-site audits where the PBM sends auditors to your pharmacy. Either way, the documentation requirements are the same. This guide is a practical playbook for preparing for, responding to, and surviving a Medicare Part D audit. It covers what triggers audits, what documentation you need, how to respond to audit notifications, how to handle discrepancies, and how to navigate the appeals process if you disagree with audit findings. #### Signature Log Compliance Maintaining complete, accurate signature logs that link patient or representative signatures to specific prescriptions with pickup or delivery dates. Includes managing proof of delivery for mailed prescriptions and conducting monthly internal audits of signature log completeness. **Pros:** - Eliminates the most common Part D audit deficiency - Monthly self-audits catch gaps before external auditors find them - Electronic signature capture reduces legibility and linkage issues **Cons:** - Delivery prescriptions require separate proof of delivery documentation - Retroactively obtaining missing signatures is difficult or impossible - Staff must be trained to consistently collect and link signatures to specific prescriptions #### DAW Code Documentation and Compliance Ensuring that every claim billed with a DAW-1 code (prescriber-directed brand dispensing) is supported by clear prescriber documentation on the original prescription. Includes regular review of DAW code usage patterns to identify and correct billing errors before auditors do. **Pros:** - Prevents one of the most financially significant audit findings - Regular DAW usage review identifies billing inconsistencies proactively - Proper documentation supports legitimate brand dispensing decisions **Cons:** - Requires pharmacist attention at the point of dispensing to verify DAW intent - Verbal DAW requests from prescribers must be documented contemporaneously - Switching to DAW-0 when documentation is ambiguous reduces reimbursement on individual claims #### Prior Authorization Record Management Filing and tracking all prior authorization approvals, linking them to corresponding prescriptions, monitoring PA expiration dates, and documenting emergency fills where PAs are pending. Ensures that every PA-required claim in an audit sample can be supported with approval records. **Pros:** - Organized PA records make audit responses straightforward - Tracking expiration dates prevents dispensing after PA lapses - Emergency fill documentation protects claims that would otherwise be reversed **Cons:** - PA record management adds administrative workload - Plan Sponsors may not always provide clear PA approval documentation - Multiple Plan Sponsors with different PA processes create complexity #### Coordination of Benefits Verification Systematically verifying patient insurance information at regular intervals, running COB checks at point of sale, and documenting that other insurance was appropriately billed before submitting claims to Medicare Part D as the payer of last resort. **Pros:** - Prevents COB-related recoupment findings - Proper billing order ensures correct reimbursement from each payer - Regular insurance verification keeps patient profiles current **Cons:** - Patients may not always disclose other coverage - Insurance verification at every fill adds transaction time - COB errors can be difficult to detect without proactive checking #### Internal Claims Auditing Program Conducting quarterly self-audits of claims data to identify the same patterns that trigger external audits - DAW usage, high-cost drug volumes, refill rates, prescriber concentration, and geographic outliers. Includes investigating anomalies and documenting legitimate clinical or business justifications. **Pros:** - Identifies and resolves issues before external auditors flag them - Creates documentation of legitimate justifications for unusual patterns - Demonstrates proactive compliance culture if an external audit does occur - May reveal billing errors that can be corrected to avoid overpayment liability **Cons:** - Requires dedicated time and analytical capability - Findings may reveal issues that require uncomfortable corrective action - Must be willing to act on findings, including reporting overpayments within 60 days **Conclusion:** Medicare Part D audits do not have to be devastating. The pharmacies that suffer the worst outcomes are those that are caught unprepared - with incomplete signature logs, unsupported DAW codes, missing PA documentation, and disorganized records. The pharmacies that come through audits cleanly are those that maintain audit-ready practices every day, not just when the notification arrives. Build signature collection into your workflow, verify DAW documentation at point of dispensing, organize PA records systematically, and conduct regular self-audits. Rxperts helps pharmacies maintain audit-ready operations by tracking documentation compliance, flagging gaps in real time, and organizing the records you need when auditors come calling. The investment in daily audit readiness is always less than the cost of a single recoupment. ### How to Build a Pharmacy Compliance Program from Scratch *Published: 2026-01-06* *URL: https://www.rx-perts.com/blog/build-pharmacy-compliance-program-from-scratch* Step-by-step guide to building a pharmacy compliance program based on the OIG seven elements, with practical timelines and implementation advice. Every pharmacy that participates in federal healthcare programs needs a compliance program. This is not a recommendation - it is a regulatory expectation rooted in the OIG's compliance guidance and reinforced by Medicare Part D participation requirements under 42 CFR 423.504. Yet many independent and small-chain pharmacies operate without a formal compliance program, relying instead on the assumption that "doing things right" is the same as having a structured compliance framework. It is not. A compliance program is more than a binder on a shelf. It is a living system of policies, training, monitoring, and response mechanisms that prevents violations, detects problems early, and demonstrates to regulators that your pharmacy takes its obligations seriously. When a pharmacy faces an audit, investigation, or allegation, the first question regulators ask is: "Do you have a compliance program?" If the answer is no - or if it exists only on paper - your pharmacy starts from a position of significant disadvantage. The good news is that building a compliance program does not require a six-figure consultant or a dedicated compliance department. What it requires is a structured approach based on well-established principles. The OIG's seven elements of an effective compliance program provide the framework, and this guide walks you through each one with specific application to pharmacy operations. #### Written Policies and Procedures The foundational documents of your compliance program, translating regulatory requirements into actionable standards for daily pharmacy operations. Should cover billing, controlled substances, HIPAA, exclusion screening, FWA prevention, and documentation standards. **Pros:** - Provides clear reference for staff on expected conduct and procedures - Demonstrates organizational commitment to compliance during audits - Creates consistency in how compliance issues are handled across the pharmacy **Cons:** - Time-intensive to develop comprehensive policies from scratch - Must be reviewed and updated annually to stay current with regulations - Policies without training and enforcement are ineffective on their own #### Compliance Officer and Committee Designating a specific individual responsible for the compliance program and establishing a committee (even a small one) to share accountability and provide oversight. In small pharmacies, the PIC typically serves as compliance officer. **Pros:** - Creates clear accountability for compliance program management - Committee structure prevents compliance from being one person burden - Quarterly committee meetings create regular compliance review touchpoints **Cons:** - In small pharmacies, the compliance officer wears multiple hats, which can dilute focus - Effective compliance oversight requires ongoing time investment - PIC serving as compliance officer may create conflicts when violations involve management decisions #### Training and Education Program Structured training covering compliance policies, FWA, HIPAA, controlled substances, and role-specific topics. Includes initial training for new hires, annual refreshers, and documented completion records with signed attestations. **Pros:** - Transforms written policies into understood and practiced standards - Training records are among the most requested items during audits - Well-trained staff are more likely to identify and report compliance issues **Cons:** - Requires protected time for training sessions, impacting staffing and workflow - Developing pharmacy-specific training content takes expertise and effort - Training effectiveness degrades without regular reinforcement and refreshers #### Open Lines of Communication Establishing accessible, confidential, and non-retaliatory channels for staff to report compliance concerns. Includes direct reporting to the compliance officer, anonymous reporting options, and a documented non-retaliation policy. **Pros:** - Encourages early detection of compliance issues by frontline staff - Non-retaliation protections build trust and encourage reporting - Multiple reporting channels accommodate different comfort levels **Cons:** - Anonymous reporting can occasionally be used for unfounded allegations - Small pharmacy teams may make true anonymity difficult to maintain - Reporting mechanisms require active monitoring to be effective #### Monitoring and Auditing Internal activities to verify that compliance policies are being followed, including OIG exclusion screening, claims audits, controlled substance reconciliation, HIPAA risk assessments, and documentation reviews. External audits provide independent validation. **Pros:** - Catches compliance gaps before regulators or auditors find them - Creates data to measure compliance program effectiveness over time - Identifies trends and systemic issues that training alone may not address **Cons:** - Auditing activities require dedicated time and may reveal uncomfortable findings - External audits involve cost, though they provide valuable independent perspective - Monitoring only works if findings are acted upon through corrective action #### Enforcement and Discipline A consistent framework for addressing compliance violations, including progressive discipline (verbal warning, written warning, suspension, termination) applied equally to all staff. Also includes positive recognition for compliance excellence. **Pros:** - Demonstrates that the compliance program has teeth, not just policies - Consistent enforcement builds a culture of accountability - Positive incentives encourage proactive compliance behavior **Cons:** - Inconsistent application undermines the entire compliance program - Disciplinary actions must be carefully documented to avoid employment disputes - Balancing enforcement with a supportive culture requires ongoing calibration #### Response and Corrective Action Structured procedures for investigating compliance issues, determining root causes, implementing corrective actions, and monitoring effectiveness. Includes protocols for self-disclosure and mandatory reporting obligations (overpayments, breaches, theft/loss). **Pros:** - Prevents one-time issues from becoming recurring violations - Root cause analysis addresses underlying problems, not just symptoms - Self-disclosure and timely overpayment reporting reduce penalty exposure **Cons:** - Investigations must balance thoroughness with employee rights and privacy - Self-disclosure decisions benefit from legal counsel, adding cost - Corrective actions require follow-up monitoring to ensure they are actually working **Conclusion:** Building a pharmacy compliance program from scratch is a significant undertaking, but it does not need to happen overnight. Start with the foundation - appoint a compliance officer, write your core policies, and launch training. Then systematically build out monitoring, enforcement, and corrective action capabilities over the following months. The OIG's seven elements provide a proven framework, and tailoring them to your pharmacy's specific operations and risk profile turns that framework into a functional program. Rxperts provides the tools to organize and operationalize each element, from tracking training completion and exclusion screening to managing audit schedules and corrective action plans. A well-built compliance program does not just protect your pharmacy from penalties - it makes your entire operation stronger. ### Controlled Substance Compliance: DEA Best Practices for Independents *Published: 2025-11-14* *URL: https://www.rx-perts.com/blog/controlled-substance-compliance-dea-best-practices* Practical DEA compliance guide for independent pharmacies covering inventories, recordkeeping, CSOS ordering, theft reporting, and corresponding responsibility. ## Inventory Requirements Under 21 CFR 1304 ### Initial Inventory Under 21 CFR 1304.11, every pharmacy must conduct an initial inventory of all controlled substances on hand on the date the pharmacy first engages in dispensing. This inventory serves as the baseline for all subsequent recordkeeping and must include every controlled substance in the pharmacy's possession, including samples, outdated stock, and damaged goods. ### Biennial Inventory After the initial inventory, pharmacies must conduct a complete inventory of all controlled substances at least every two years (biennially) per 21 CFR 1304.11(c). The biennial inventory date becomes your pharmacy's "inventory date" going forward, and subsequent biennial inventories should be conducted within two years of the previous one. **Critical details for biennial inventories:** - The inventory must be taken on either the opening or closing of business on the inventory date - For Schedule II substances, an exact count is required - For Schedules III-V, an estimated count is permitted unless the container holds more than 1,000 dosage units, in which case an exact count is required - The inventory must include the drug name, dosage form, strength, number of dosage units, and total quantity - Record whether the inventory was taken at opening or closing of business ### Perpetual vs. Periodic Inventory for Schedule II While the DEA requires only biennial inventories, maintaining a perpetual (running) inventory for Schedule II substances is strongly recommended and required by many state boards of pharmacy. A perpetual inventory tracks every receipt and dispensing in real time, making discrepancy detection immediate rather than discovering shortages months later during a biennial count. ## Recordkeeping for Schedules II Through V Under 21 CFR 1304.04, every pharmacy must maintain complete and accurate records of all controlled substances received, dispensed, and disposed of. These records must be readily retrievable and maintained for a minimum of two years from the date of the transaction - though many states require longer retention periods (five years or more). ### Schedule II Records Schedule II records carry the most stringent requirements: - **Receiving:** Each receipt of Schedule II substances must be documented on DEA Form 222 (for paper orders) or through the CSOS electronic ordering system. The form must include the date received and the actual quantity received. Three-part DEA Form 222 copies must be retained by both the supplier and purchaser. - **Dispensing:** Prescription records must include the patient name, prescriber name and DEA number, drug name and strength, quantity dispensed, date filled, and the dispensing pharmacist's initials or identification. - **Separate filing:** Schedule II records must be maintained separately from Schedules III-V records or in a system where Schedule II records are readily distinguishable (such as marking with a red "C" stamp). ### Schedules III-V Records Records for Schedules III-V substances are maintained through the pharmacy's standard prescription filing system, but they must be readily retrievable. The DEA's "three-file" or "two-file" system options provide structure: - **Three-file system:** Separate files for Schedule II prescriptions, Schedule III-V prescriptions, and non-controlled prescriptions - **Two-file system:** One file for Schedule II prescriptions, and a second file for all other prescriptions - but Schedule III-V prescriptions must be stamped with a red "C" for identification ## CSOS Electronic Ordering The Controlled Substance Ordering System (CSOS) replaced paper DEA Form 222 for electronic ordering of Schedule II substances. Under 21 CFR 1305.21-1305.29, CSOS uses digital certificates issued by the DEA to authenticate electronic orders. **Key CSOS requirements:** - Only individuals with a valid CSOS digital certificate may place orders - The certificate is linked to the pharmacy's DEA registration - Digital certificates must be kept secure - compromised certificates must be reported to the DEA immediately - Electronic records of CSOS orders must be maintained and readily retrievable for DEA inspection - Pharmacies must verify that their wholesale suppliers are authorized to distribute controlled substances by confirming valid DEA registrations ## Theft and Loss Reporting - DEA Form 106 Under 21 CFR 1301.76(b), pharmacies must report any theft or significant loss of controlled substances to the DEA using DEA Form 106. This form must be submitted upon discovery of the loss. **What constitutes a reportable loss:** - Any theft, regardless of the quantity - Losses due to a break-in, robbery, or employee pilferage - Significant unexplained inventory discrepancies discovered during routine counts - Losses during transit or shipping **What is generally NOT reportable:** - Minor discrepancies attributable to normal dispensing errors (such as a count being off by one or two tablets) that are corrected through standard pharmacy operations - However, a pattern of small discrepancies warrants investigation and potentially a report **Filing requirements:** - Submit DEA Form 106 online through the DEA Diversion Control Division website - Notify local law enforcement if theft or robbery occurred - Maintain copies of all theft and loss reports - Conduct an internal investigation to determine the cause - Some states require separate notification to the state board of pharmacy ## The Corresponding Responsibility Doctrine This is the area where more pharmacies encounter DEA enforcement problems than any other. Under 21 CFR 1306.04(a), a pharmacist has a "corresponding responsibility" with the prescriber to ensure that a controlled substance prescription is issued for a legitimate medical purpose by a prescriber acting in the usual course of professional practice. This means pharmacists cannot simply fill every controlled substance prescription that appears technically valid. You must exercise professional judgment and refuse to fill prescriptions when red flags indicate the prescription may not be legitimate. ### Red Flags That Require Investigation The DEA and courts have identified numerous red flags that a pharmacist should investigate before dispensing: - **Prescriptions from distant prescribers** when comparable practitioners are nearby - **Cash-only payments** when the patient has insurance (particularly for controlled substances) - **Combination prescriptions** - the "holy trinity" of opioid, benzodiazepine, and muscle relaxant - **Early refill requests** or patterns of lost/stolen medications - **Multiple patients** from the same address or presenting together - **Prescriptions for maximum quantities** of high-dose formulations - **Prescriptions from prescribers known to be under investigation** - **Patient behavior** suggesting intoxication, drug-seeking, or diversion - **Identical prescriptions** for the same regimen from the same prescriber to multiple patients ### Documenting Your Professional Judgment When you investigate a red flag and decide to fill the prescription, **document your reasoning**. Note that you identified the concern, what steps you took (called the prescriber, checked the PDMP, spoke with the patient), and why you determined the prescription was legitimate. If the DEA later reviews that prescription, your documentation demonstrates that you exercised your corresponding responsibility. When you refuse to fill, document that as well. Record the reason for refusal, any communication with the prescriber, and the date. ## PDMP Utilization Prescription Drug Monitoring Programs are now operational in all 50 states, and most states mandate that pharmacists check the PDMP before dispensing controlled substances. Even in states where PDMP checks are not mandatory for every dispensing, the DEA expects pharmacists to use the PDMP as part of exercising corresponding responsibility. **Best practices for PDMP utilization:** - Check the PDMP before dispensing any new controlled substance prescription - Check for all refills of Schedule II substances - Document PDMP checks in the patient profile or prescription record - Flag and investigate patients with multiple prescribers or pharmacies - Use PDMP data to support clinical conversations with prescribers when patterns are concerning ## Reverse Distribution and Disposal When controlled substances need to be destroyed - whether due to expiration, damage, or patient returns - they must be handled through an authorized reverse distributor or DEA-approved disposal method per 21 CFR 1317. **Authorized disposal methods:** - **Reverse distribution:** Send controlled substances to a DEA-registered reverse distributor using the appropriate DEA form. The reverse distributor handles the actual destruction and provides documentation. - **On-site destruction:** With prior DEA authorization and in the presence of required witnesses, pharmacies may destroy controlled substances on-site. This requires meticulous documentation. - **Patient drug take-back:** Pharmacies registered as collection sites under 21 CFR 1317.40 may collect controlled substances from patients for disposal. **Never** dispose of controlled substances in regular trash, down drains, or through non-DEA-authorized methods. Document every step of the disposal process, including the substances destroyed, quantities, method of destruction, witnesses, and dates. ## Staff Training on Controlled Substance Procedures Every individual in your pharmacy who handles, dispenses, or has access to controlled substances should receive documented training on your controlled substance policies and procedures. This training should cover: - **Proper storage and security** - Controlled substances must be stored in a securely locked, substantially constructed cabinet or distributed throughout non-controlled stock in a manner that obstructs theft (21 CFR 1301.75). Staff should understand access controls and who holds keys or combinations. - **Inventory procedures** - Train staff on how to conduct counts, what to do when discrepancies are found, and the importance of documenting every variance. - **Recognizing diversion** - Internal diversion by employees is a persistent risk. Staff should know the warning signs: unexplained inventory shortages, a coworker who insists on handling certain medications alone, behavioral changes, or discrepancies between dispensing records and inventory counts. - **Prescription verification** - Technicians and pharmacists alike should be trained on identifying forged or altered prescriptions, verifying prescriber credentials, and understanding when to escalate a suspicious prescription to the PIC. - **Reporting obligations** - Staff must know that they are required to report suspected theft or diversion internally and that the pharmacy has a legal obligation to file DEA Form 106. Creating an environment where staff feel safe reporting concerns without fear of retaliation is essential. Document all controlled substance training with attendance records and signed acknowledgments. When a DEA investigator visits your pharmacy, one of the first questions will be whether staff have been trained on your controlled substance procedures. Having documented training records ready demonstrates operational maturity. For more detail on preparing for a DEA inspection, see our guide on [How to Prepare for a DEA Pharmacy Inspection](/blog/how-to-prepare-dea-pharmacy-inspection). Many of these same areas are also reviewed during [state board of pharmacy inspections](/blog/pharmacy-board-inspection-what-surveyors-look-for), making strong controlled substance compliance a cornerstone of your overall regulatory readiness. ### Fraud, Waste, and Abuse Training: What Every Pharmacy Staff Member Needs *Published: 2025-10-22* *URL: https://www.rx-perts.com/blog/fraud-waste-abuse-training-pharmacy-staff* Comprehensive guide to FWA training requirements for pharmacies under Medicare Part D, including who needs training, content requirements, and documentation. Fraud, waste, and abuse (FWA) in healthcare costs federal programs tens of billions of dollars every year, and pharmacies are squarely in the crosshairs of enforcement efforts. Under 42 CFR 423.504, every pharmacy that participates in Medicare Part D is required to have a compliance program that includes FWA training for all employees. This is not a suggestion - it is a condition of participation. Yet many pharmacy owners treat FWA training as a checkbox exercise: show a video once a year, collect signatures, and file it away. That approach fails on two fronts. First, it does not meet the regulatory requirements for content and frequency. Second, it does not actually equip staff to recognize and prevent the schemes that put pharmacies at risk. This guide covers what FWA training must include, who needs it, how often it must be delivered, and how to document it properly. We will also walk through real-world pharmacy fraud schemes so your staff understands what these violations look like in practice - because the best compliance program is one where every team member knows what to watch for. #### CMS General FWA Training Module The standardized FWA training provided through the Medicare Learning Network (MLN). Covers general definitions, laws, and reporting mechanisms. Completion satisfies the baseline Part D FWA training requirement for all first-tier, downstream, and related entities. **Pros:** - Free and accessible through the CMS MLN website - Satisfies the baseline regulatory requirement - Provides standardized certificates of completion - Updated periodically by CMS to reflect current requirements **Cons:** - Generic content not specific to pharmacy operations - Does not cover pharmacy-specific fraud schemes in depth - Should be supplemented with pharmacy-focused training #### Pharmacy-Specific FWA Scenario Training Supplemental training that uses real-world pharmacy fraud cases and scenarios to teach staff how to recognize FWA in their daily work. Covers phantom billing, upcoding, unbundling, copay waivers, and prescription alteration with pharmacy-specific examples. **Pros:** - Directly relevant to staff daily responsibilities - Uses concrete examples staff can relate to - Addresses schemes specific to pharmacy dispensing and billing - More engaging than generic compliance training **Cons:** - Must be developed or purchased separately from CMS module - Requires periodic updates as new schemes emerge - Takes additional time beyond the CMS baseline requirement #### Documentation and Attestation System A structured system for tracking FWA training completion, maintaining attendance records, collecting signed attestation forms, and storing completion certificates. Essential for demonstrating compliance during PBM audits and regulatory inspections. **Pros:** - Provides audit-ready proof of training compliance - Creates accountability for training completion - Supports tracking of training due dates for new and existing staff **Cons:** - Requires administrative time to maintain - Paper-based systems are prone to loss and disorganization - Must accommodate different training completion dates across staff #### Internal Reporting and Response Protocol Written procedures for how staff should report suspected FWA, how reports are investigated, and how the pharmacy responds to confirmed violations. Includes non-retaliation policies and escalation procedures to external agencies when appropriate. **Pros:** - Gives staff clear direction on how to report concerns - Protects the pharmacy by encouraging early detection - Demonstrates to regulators that the pharmacy takes FWA seriously - Non-retaliation policies build staff trust in the reporting process **Cons:** - Requires a designated compliance officer or responsible party - Investigation procedures must balance thoroughness with employee rights - May require legal consultation for handling confirmed violations #### Annual Training Calendar and Compliance Schedule A planned schedule for FWA training delivery throughout the year, including initial training for new hires, annual refresher sessions, and ad hoc training triggered by regulatory changes or compliance incidents. Ensures training never lapses. **Pros:** - Prevents training deadlines from being missed - Coordinates FWA training with other compliance activities - Helps managers plan staffing around training sessions - Demonstrates systematic approach during audits **Cons:** - Must be updated when staff turnover creates new training obligations - Requires flexibility for unplanned training needs - Calendar maintenance adds to compliance officer workload **Conclusion:** FWA training is not just a regulatory checkbox - it is a frontline defense that protects your pharmacy, your patients, and your livelihood. When every staff member understands what fraud, waste, and abuse look like in a pharmacy setting, your entire operation becomes more resilient to the schemes that lead to enforcement actions, financial penalties, and program exclusion. Build a training program that goes beyond the CMS module, uses pharmacy-specific examples, and creates a culture where staff feel empowered to report concerns. Platforms like Rxperts can help you schedule training, track attestations, and maintain the documentation that proves your pharmacy takes FWA compliance seriously. The cost of good training is negligible compared to the cost of a single FWA violation. ### OIG Exclusion Screening: Why Monthly Checks Save Your Pharmacy *Published: 2025-09-18* *URL: https://www.rx-perts.com/blog/oig-exclusion-screening-monthly-checks* Learn why monthly OIG exclusion screening is essential for pharmacies, how to implement a compliant process, and avoid penalties up to $100,000 per item. If your pharmacy bills Medicare, Medicaid, or any other federal healthcare program, you have a legal obligation to ensure that no excluded individual or entity is involved in providing services to those beneficiaries. The Office of Inspector General (OIG) maintains the List of Excluded Individuals and Entities (LEIE), and failing to screen against it can expose your pharmacy to devastating financial penalties. Despite the severity of these consequences, many independent pharmacies still treat exclusion screening as an afterthought - something they handle during onboarding and never revisit. That approach is a compliance time bomb. Excluded individuals do not always disclose their status, and exclusions can happen at any time during employment. A pharmacist, technician, or even a delivery driver who becomes excluded after their initial hire can generate massive liability for every claim they touch. This article breaks down OIG exclusion screening requirements, explains why monthly checks have become the accepted industry standard, walks through the screening process step by step, and covers what to do when you find a match. If you have not reviewed your screening process recently, now is the time. #### OIG LEIE Database Screening The primary federal exclusion database maintained by the Office of Inspector General. Updated monthly and searchable by name, SSN, or bulk download. Must be checked for every individual involved in providing services to federal healthcare program beneficiaries. **Pros:** - Free to access and search at oig.hhs.gov - Bulk download available for batch processing - Updated on a predictable monthly schedule - Provides reinstatement information for previously excluded individuals **Cons:** - Name-only searches can generate false positives with common names - Does not include state-only Medicaid exclusions - Manual individual searches are time-consuming for larger pharmacies #### SAM.gov Exclusion Verification The System for Award Management maintains a separate exclusion database covering debarments and suspensions across all federal agencies, not just HHS. Required under 2 CFR Part 180 for entities receiving federal funds. **Pros:** - Covers exclusions from agencies beyond HHS - Includes debarment and suspension records - Entity search capabilities for vendor screening **Cons:** - Interface can be less intuitive than the LEIE - Some overlap with LEIE creates duplicate work if not batched - Separate account and login required #### State Medicaid Exclusion Lists Most state Medicaid agencies maintain their own exclusion lists for individuals excluded at the state level. These exclusions may not appear in federal databases and must be checked separately for Medicaid-participating pharmacies. **Pros:** - Captures state-level exclusions missed by federal databases - Required by most state Medicaid provider agreements - Demonstrates thorough due diligence during audits **Cons:** - No standardized format across states - each state maintains its own list differently - Some states do not publish easily searchable databases - Multi-state operations must check each relevant state separately #### Pre-Employment Screening Protocol Screening candidates against all exclusion databases before extending a final offer of employment. Should include verification of identity, licensure, and exclusion status as part of the standard onboarding process. **Pros:** - Prevents hiring an excluded individual in the first place - Establishes a clean baseline for ongoing monthly screening - Demonstrates proactive compliance culture **Cons:** - Requires coordination with HR to integrate into hiring workflow - Must be repeated for every contractor and temp staff engagement - Does not eliminate the need for ongoing monthly checks #### Documentation and Record Retention Maintaining detailed records of every screening cycle, including dates, databases checked, individuals screened, results, and any follow-up actions. Records should be retained for a minimum of 10 years to align with federal record retention requirements. **Pros:** - Provides audit-ready proof of compliance - Creates a defensible record if a match is later discovered - Supports internal monitoring of screening consistency **Cons:** - Requires organized filing system and storage capacity - Staff must be trained on proper documentation procedures - Manual documentation is error-prone without standardized templates **Conclusion:** OIG exclusion screening is not optional, and monthly screening is not overkill - it is the accepted standard of care for pharmacy compliance. The penalties for employing an excluded individual are severe enough to threaten the financial viability of any pharmacy, and the "should have known" standard means that ignorance is not a defense. Build a structured screening program that covers all databases, all personnel, and produces thorough documentation. Tools like Rxperts can help you track screening schedules, maintain documentation, and ensure no one falls through the cracks. The time you invest in monthly screening is a fraction of the cost of a single CMP. ### Pharmacy Board of Pharmacy Inspection: What Surveyors Actually Look For *Published: 2025-08-12* *URL: https://www.rx-perts.com/blog/pharmacy-board-inspection-what-surveyors-look-for* Board of Pharmacy inspection guide covering physical plant, staffing ratios, filing systems, counseling, temperature logs, security, and compounding. Board of Pharmacy inspections generate more anxiety in pharmacy staff than almost any other regulatory event - and often for the wrong reasons. Pharmacists worry about obscure regulatory trivia when surveyors are actually focused on a consistent set of operational and safety standards that are surprisingly practical. Understanding what inspectors actually prioritize, as opposed to what you think they might ask about, transforms inspection preparation from a stressful guessing game into a manageable checklist. Having worked with pharmacies through dozens of state board inspections across multiple states, I can tell you that the findings that generate citations are remarkably consistent. Temperature logs with gaps. Expired medications on shelves. Staffing ratios that do not add up on paper. Prescription filing systems that cannot produce a specific prescription within a reasonable time. These are not edge cases - they are the bread and butter of board inspection findings. This guide is built from real inspection patterns, not theoretical compliance ideals. We will cover every major area a surveyor will examine, explain what they are actually looking for at each step, and give you specific actions to take before, during, and after the inspection. #### Physical Plant and Facility Standards Maintaining a clean, organized, and properly equipped pharmacy environment including adequate lighting, defined prescription department boundaries, sink access, appropriate medication storage, and unobstructed safety features. **Pros:** - A well-maintained facility creates a positive first impression that influences the entire inspection tone - Proper storage (medications off the floor, adequate spacing) prevents safety hazards - Meeting physical plant standards is straightforward and requires minimal ongoing investment **Cons:** - Physical plant deficiencies are immediately visible and cannot be addressed during the inspection - Medications stored improperly (on floors, in excessive heat) face potential quarantine orders - Cluttered, disorganized pharmacies prompt surveyors to look more closely at operational compliance #### Staffing Ratio Compliance and Credentialing Maintaining proper pharmacist-to-technician ratios at all times including break periods, verifying current registration and certification for all pharmacy personnel, and documenting PIC designations. **Pros:** - Proper ratios directly protect patient safety and reduce dispensing errors - Current credentialing documentation demonstrates organizational discipline - Pre-planned break coverage schedules prevent accidental ratio violations **Cons:** - Ratio violations discovered during inspection are immediately citable - Lapsed technician registrations can result in individual discipline for the technician and the PIC - Historical staffing records showing past violations can compound current findings #### Prescription Filing and Record Retrieval Operating a compliant filing system (three-file or two-file per 21 CFR 1304.04(h)) with daily filing discipline, rapid retrieval capability, and proper retention per state requirements. **Pros:** - Rapid record retrieval demonstrates operational competence during inspections - Proper filing systems also support DEA and PBM audit readiness simultaneously - Daily filing prevents backlogs that become overwhelming and citable **Cons:** - Inability to locate a requested prescription during inspection is a significant finding - Filing backlogs suggest the pharmacy is operating beyond its manageable capacity - Inadequate retention may result in inability to produce records for audits or legal proceedings #### Temperature Monitoring and Medication Storage Maintaining daily temperature logs for all medication storage areas including weekends and holidays, documenting excursion events with corrective actions, and implementing continuous monitoring systems where possible. **Pros:** - Continuous digital monitoring provides 24/7 tamper-proof documentation - Consistent temperature logs signal overall compliance discipline to surveyors - Documented excursion response protects against medication quality questions **Cons:** - Temperature log gaps are among the most frequently cited board inspection findings - Undocumented excursion events raise questions about every medication stored in the affected area - Retroactively completed logs are easily identified by surveyors and damage credibility #### Patient Counseling and Documentation Implementing a counseling workflow that meets state-specific requirements for offers and actual counseling, maintaining documentation of counseling interactions, and providing a private counseling area. **Pros:** - Documented counseling demonstrates commitment to patient care beyond minimum compliance - A semi-private counseling area addresses both board requirements and HIPAA privacy standards - Consistent counseling documentation creates a defensible record of standard of care **Cons:** - Failure to offer counseling is a patient safety violation in most states - Drive-through dispensing without counseling offers is a frequently cited deficiency - Staff who cannot describe the counseling process when asked signal a training gap to surveyors #### Expired Medication Management and Compounding Standards Conducting monthly expired medication checks across all storage areas, implementing FEFO rotation, and maintaining compounding areas and documentation per USP 795/797 standards where applicable. **Pros:** - Monthly checks with documentation create an auditable trail of medication quality management - FEFO rotation prevents expiration of slow-moving medications - Compliant compounding documentation satisfies both board inspectors and PBM auditors **Cons:** - Finding expired medications on shelves during inspection is a direct patient safety citation - Will-call area medications past return-to-stock dates are commonly found expired - Compounding deficiencies under USP 795/797 can result in orders to cease compounding operations **Conclusion:** Board of Pharmacy inspections are ultimately about patient safety and operational competence. The surveyors who walk through your pharmacy are not looking for reasons to cite you - they are evaluating whether your pharmacy operates at a level that protects the patients you serve. The areas covered in this guide - physical plant, staffing, filing, temperature monitoring, counseling, security, expired medications, and compounding - are the areas where inspections are won or lost. Mock inspections are the single best preparation tool: walk your own pharmacy with a surveyor's eyes, find the gaps, and fix them before they become findings. Rxperts provides pharmacy-specific mock inspection workflows and compliance checklists designed around actual board inspection criteria, helping you build the kind of inspection-ready operation that surveyors recognize as well-managed the moment they walk through the door. ### Understanding PBM Audits: A Pharmacy Owner's Survival Guide *Published: 2025-07-08* *URL: https://www.rx-perts.com/blog/understanding-pbm-audits-pharmacy-survival-guide* Pharmacy survival guide to PBM audits covering desk and on-site audits, common triggers, documentation requirements, and recoupment appeals. If you own or manage a pharmacy, PBM audits are not a possibility - they are an inevitability. Every major PBM - Express Scripts, CVS Caremark, OptumRx, and their subsidiaries - maintains active audit programs that target independent and chain pharmacies alike. The audit volume has increased steadily, and the financial stakes have grown with it. A single audit can result in recoupment demands of tens of thousands of dollars, and pharmacies with documentation gaps face these demands with limited leverage to fight back. The challenge with PBM audits is that the rules of engagement heavily favor the PBM. They set the documentation standards in their provider manuals, they control the audit timeline, and they are often both the accuser and the judge when disputes arise. But pharmacies are not powerless. Understanding what triggers audits, what auditors actually look for, how to maintain defensible documentation, and how to use the appeals process effectively can mean the difference between a minor inconvenience and a financial crisis. This guide covers PBM audits from end to end - from prevention through appeal. Whether you are currently facing an audit or want to build audit-proof documentation systems, this is the playbook you need. #### Signature Log Management Maintaining complete, dated signature logs for every dispensed prescription, including delivery prescriptions, with electronic or legible paper capture systems verified daily for completeness. **Pros:** - Eliminates the most common single audit finding across all PBM audits - Electronic capture systems create tamper-evident records with timestamps - Daily verification catches gaps before they become systemic problems **Cons:** - Missing signatures result in automatic recoupment of the entire claim amount - Paper signature logs with gaps or illegible entries are treated the same as missing signatures - Delivery prescriptions without chain-of-custody documentation are especially vulnerable #### DAW Code Documentation Verifying that every DAW-1 claim has corresponding prescriber-directed documentation on the physical prescription or electronic record, with weekly reconciliation checks. **Pros:** - Prevents recoupment of brand-priced claims that should have been dispensed as generic - Weekly reconciliation catches coding errors before they accumulate across hundreds of claims - Proper documentation supports the pharmacy in price differential disputes **Cons:** - Unsupported DAW-1 codes can trigger fraud referrals, not just recoupment - High DAW-1 utilization without documentation is a primary trigger for focused audits - Recoupment on DAW code findings often covers the full brand-to-generic price difference per claim #### Compound Claims Documentation Maintaining complete compound formulation records including master formulas, individual compounding logs with ingredient NDCs and lot numbers, beyond-use dating, and compounding pharmacist identification. **Pros:** - Protects against the largest recoupment category in PBM audits - Complete formulation records also satisfy state board compounding inspection requirements - Detailed ingredient documentation supports pricing accuracy and MAC compliance **Cons:** - Incomplete compound records almost always result in 100% claim recoupment - Missing ingredient lot numbers or NDCs are treated as documentation failures, not minor oversights - Compound claims without supporting prescriptions face automatic recoupment plus potential fraud scrutiny #### Usual and Customary Pricing Compliance Documenting and maintaining a consistent U&C pricing policy, understanding how discount programs interact with U&C obligations, and verifying pricing submissions against actual cash prices. **Pros:** - Prevents retroactive recoupment across all claims where U&C was lower than billed - A documented pricing policy provides defensible evidence during price audits - Understanding discount program implications avoids unintentional U&C violations **Cons:** - U&C discrepancies can result in recoupment across thousands of claims, not just audited ones - Inconsistent pricing creates the appearance of intentional billing manipulation - Discount card and loyalty program pricing may inadvertently establish a lower U&C baseline #### Appeals Process Execution Systematically reviewing preliminary audit findings, compiling additional documentation for each contested claim, writing fact-based appeals, and leveraging state audit protection laws. **Pros:** - Appeals frequently reverse a significant portion of preliminary recoupment amounts - State audit protection laws may prohibit PBM practices like extrapolation - Documented appeals create a record that supports escalation to regulators if needed **Cons:** - Failing to appeal within the required timeline forfeits all appeal rights - Uncontested preliminary findings become final recoupments automatically - Pharmacies that do not cite state audit protection laws waive those protections in practice **Conclusion:** PBM audits are a permanent feature of pharmacy operations, and the pharmacies that treat them as manageable business events rather than catastrophes are the ones that come through with minimal financial impact. The key is building audit-proof documentation systems before the audit letter arrives - daily signature verification, complete compound records, consistent DAW documentation, and defensible pricing policies. When audits do come, respond systematically, appeal every questionable finding, and know your state's pharmacy audit protections. Rxperts offers audit preparation tools designed specifically for pharmacy operations, including documentation checklists and mock audit workflows that help you identify and fix gaps before a PBM auditor finds them. ### HIPAA Compliance for Pharmacies: Beyond the Basics *Published: 2025-06-10* *URL: https://www.rx-perts.com/blog/hipaa-compliance-pharmacies-beyond-basics* Advanced HIPAA compliance for pharmacies covering BAAs, minimum necessary standard, breach notification, PHI disposal, and social engineering defense. Every pharmacy knows the HIPAA basics: train your staff, do not discuss patient information in public, use privacy screens. But HIPAA compliance in a pharmacy setting goes far deeper than these surface-level practices, and the areas where pharmacies actually get into trouble with the Office for Civil Rights (OCR) are almost never the obvious ones. The real HIPAA risks for pharmacies live in the gaps - the Business Associate Agreement that was never signed with your new software vendor, the breach notification that was sent on day 62 instead of day 60, the minimum necessary standard that nobody applied to the daily prescription report your staff prints for the entire pharmacy. These are the issues that generate enforcement actions, and they require a more sophisticated understanding of the Privacy Rule, the Security Rule, and the Breach Notification Rule than most pharmacy HIPAA training provides. This guide covers the HIPAA compliance areas that most pharmacy training programs skip entirely or address only superficially. If you have already completed your annual HIPAA training and think you are covered, this article will show you the gaps that still need your attention. #### Business Associate Agreement Management Conducting a complete vendor inventory, executing BAAs with all entities that access PHI per 45 CFR 164.502(e), and implementing annual BAA audits with current and terminated vendors. **Pros:** - Eliminates one of the most common HIPAA compliance gaps in pharmacies - Creates contractual protections when vendor breaches occur - Demonstrates organizational maturity during OCR investigations **Cons:** - Missing BAAs create direct HIPAA violations that can be discovered in any investigation - Terminated vendors without proper BAA wind-down may retain PHI indefinitely - Every un-covered vendor relationship is a potential breach exposure #### Minimum Necessary Standard Implementation Configuring role-based access controls, limiting PHI in reports and communications, and training staff to apply the minimum necessary principle under 45 CFR 164.502(b) to all non-treatment disclosures. **Pros:** - Reduces the scope and impact of potential breaches by limiting exposed data - Role-based access controls also improve operational efficiency - Demonstrates a mature privacy program to regulators and patients **Cons:** - Over-broad access means every unauthorized access incident involves more PHI - Full-access reports printed for limited purposes create unnecessary paper PHI - Failure to limit disclosures to law enforcement or insurers exposes the pharmacy to OCR scrutiny #### Breach Notification and Response Program Establishing a breach risk assessment process under 45 CFR 164.402, maintaining a small breach log, meeting the 60-day notification timeline, and conducting annual incident response drills. **Pros:** - Documented risk assessments protect against after-the-fact OCR second-guessing - Prepared breach response reduces notification timeline stress - Annual drills ensure the response team can execute under pressure **Cons:** - Missing the 60-day notification window is itself a separate HIPAA violation - Failure to log small breaches results in inaccurate annual reporting to HHS - Ad-hoc breach response without a plan leads to inconsistent and legally risky decisions #### PHI Disposal and Media Sanitization Implementing secure disposal procedures for paper PHI (cross-cut shredding with certificates of destruction) and electronic media sanitization per NIST SP 800-88, including often-overlooked PHI sources. **Pros:** - Eliminates the risk of PHI recovery from discarded materials - Destruction certificates provide auditable compliance evidence - Addressing overlooked sources (bag labels, fax sheets, scratch pads) closes common gaps **Cons:** - Improper disposal is a straightforward HIPAA violation that is easy for OCR to prove - Unsanitized electronic media sold or recycled can expose thousands of patient records - Shredding vendor without a BAA creates a compounding compliance failure #### Social Engineering Defense Training staff to recognize and resist social engineering attacks targeting pharmacy PHI, implementing callback verification protocols, and establishing reporting procedures for suspicious contacts. **Pros:** - Addresses the fastest-growing threat vector for pharmacy data breaches - Callback verification protocols prevent the majority of phone-based attacks - Trained staff become a security asset rather than a vulnerability **Cons:** - Pharmacies without social engineering training are highly susceptible to impersonation attacks - A single successful social engineering attack can expose hundreds of patient records - Staff who click phishing links can compromise the entire pharmacy management system **Conclusion:** HIPAA compliance in a pharmacy cannot stop at annual training and privacy notices. The areas covered in this guide - BAA management, minimum necessary enforcement, breach response, PHI disposal, and social engineering defense - are where real compliance failures happen and where OCR enforcement actions originate. Building a mature HIPAA program requires treating these advanced requirements with the same attention you give to your basic privacy practices. Rxperts provides pharmacy-specific compliance tools, including HIPAA checklists and audit preparation workflows, that can help you move beyond surface-level compliance and build the kind of documented, systematic privacy program that withstands regulatory scrutiny. ### How to Prepare for a DEA Pharmacy Inspection *Published: 2025-05-20* *URL: https://www.rx-perts.com/blog/how-to-prepare-dea-pharmacy-inspection* Step-by-step guide to preparing for a DEA pharmacy inspection covering biennial inventory, Schedule II-V recordkeeping, ARCOS reporting, and red flags. A DEA inspection at your pharmacy is not a question of if - it is a question of when. The Drug Enforcement Administration conducts both scheduled and unannounced inspections of registered pharmacies, and the stakes are as high as they get in pharmacy compliance. A DEA registration revocation effectively ends your ability to dispense controlled substances, which for most pharmacies means closing the doors. The good news is that DEA inspections follow a predictable pattern. Investigators look at specific records, ask specific questions, and focus on specific risk areas. If you understand what they are looking for and prepare accordingly, an inspection becomes a manageable operational event rather than a crisis. This guide walks through every major area a DEA investigator will examine, with specific references to the Code of Federal Regulations so you can verify requirements against the primary source. Whether you are facing an upcoming inspection or simply want to maintain ongoing readiness, these steps will help you build a defensible controlled substance program. #### Biennial Inventory Compliance Conducting accurate biennial inventories per 21 CFR 1304.11, including exact counts for Schedule II, proper timestamps, and coverage of all storage locations in the pharmacy. **Pros:** - Demonstrates organizational discipline to investigators - Creates the baseline for accountability reconciliations - Identifies discrepancies before they become enforcement issues **Cons:** - Incorrect inventory dates or missing timestamps signal systemic disorganization - Estimated Schedule II counts violate the regulation and trigger citations - Missing inventory locations (ADCs, will-call bins) create unexplained variances #### Schedule II Recordkeeping and Reconciliation Maintaining separate or readily retrievable Schedule II records per 21 CFR 1304.04(h), including prescription documentation, order records, and quarterly accountability reconciliations. **Pros:** - Closed-loop accountability demonstrates diversion prevention - Quarterly reconciliation catches discrepancies before they compound - Organized records allow rapid response to investigator document requests **Cons:** - Unexplained discrepancies between received, dispensed, and on-hand quantities are the top red flag - Failure to maintain separate Schedule II records is a common citation - Missing order records (Form 222 or CSOS) break the chain of custody #### Corresponding Responsibility Documentation Establishing and documenting a red flag identification and resolution process under 21 CFR 1306.04(a), including standardized forms, PDMP checks, and prescriber verification. **Pros:** - Demonstrates active professional judgment to investigators - Protects individual pharmacist licenses during enforcement actions - Creates a documented pattern of diligence over time **Cons:** - Absence of a documented process implies prescriptions are filled without professional scrutiny - Investigators view inconsistent application as worse than no process at all - Individual pharmacists face personal DEA registration consequences for failures #### Physical Security and Theft Reporting Meeting DEA physical security standards under 21 CFR 1301.75, maintaining surveillance systems, and promptly reporting theft or significant loss on DEA Form 106. **Pros:** - Robust security reduces actual theft and diversion risk - Prompt loss reporting demonstrates transparency and good faith - Camera footage can exonerate staff during investigations **Cons:** - Inadequate storage security is a citable deficiency that can trigger enforcement - Delayed theft reporting raises suspicion of concealment - Lack of surveillance makes internal diversion nearly impossible to investigate #### Inspection Conduct and Follow-Up Having a designated point person, maintaining organized records for rapid retrieval, cooperating professionally during the inspection, and implementing corrective actions promptly after findings. **Pros:** - A calm, organized response builds investigator confidence in your compliance culture - Documented corrective actions can mitigate enforcement outcomes - Post-inspection improvements demonstrate willingness to maintain compliance **Cons:** - Disorganized record retrieval during inspection creates negative impressions that color the entire review - Failing to implement corrective actions after cited deficiencies escalates enforcement - Handling an Order to Show Cause without legal counsel risks registration revocation **Conclusion:** DEA inspection preparation is fundamentally about building daily habits, not last-minute scrambles. The pharmacies that perform best during inspections are the ones where controlled substance compliance is woven into everyday operations - where perpetual inventories are reconciled regularly, red flags are documented consistently, and every staff member understands their role in the compliance chain. If you are looking for a structured approach to maintaining inspection readiness year-round, Rxperts offers mock inspection tools and compliance checklists specifically designed for pharmacy operations, giving you a systematic way to verify DEA readiness before an investigator ever walks through the door. ### The Complete Pharmacy Compliance Checklist for 2025 *Published: 2025-04-15* *URL: https://www.rx-perts.com/blog/complete-pharmacy-compliance-checklist-2025* Pharmacy compliance checklist for 2025 covering HIPAA, DEA, state board, FWA, OIG screening, and PBM contracts with actionable steps. Pharmacy compliance in 2025 is not a single task you check off annually - it is an ongoing operational discipline that touches every department, every workflow, and every staff member in your pharmacy. Between federal regulators tightening enforcement, PBM audit activity increasing year over year, and state boards adopting more prescriptive inspection criteria, the pharmacies that thrive are the ones treating compliance as a daily practice rather than a periodic scramble. This checklist is designed to be a working document. Print it, pin it to your office wall, and revisit it monthly. It consolidates the major compliance domains that independent and chain pharmacies must address in 2025: HIPAA privacy and security, DEA controlled substance requirements, state Board of Pharmacy regulations, fraud-waste-abuse (FWA) prevention, OIG exclusion screening, and PBM contract obligations. Each section includes specific action items you can delegate, schedule, and verify. If you have been relying on a patchwork of spreadsheets and memory to manage compliance, this is your signal to systematize. The cost of a single DEA citation, HIPAA breach, or PBM recoupment can dwarf the investment in building a proper compliance infrastructure. #### HIPAA Privacy and Security Comprehensive HIPAA compliance covering risk analysis, BAAs, technical safeguards, breach notification procedures, and PHI disposal documentation per 45 CFR 164. **Pros:** - Avoids OCR enforcement actions and fines ranging from $25,000 to $1.5 million - Protects patient trust and pharmacy reputation - Creates defensible documentation if a breach occurs - Streamlines breach response with pre-built notification procedures **Cons:** - Non-compliance risks significant financial penalties from OCR - Breaches without a response plan can escalate into class-action litigation - Failure to maintain BAAs exposes the pharmacy to liability for vendor actions #### DEA Controlled Substance Compliance Covers DEA registration, biennial inventory, Schedule II-V recordkeeping, ARCOS reporting, and corresponding responsibility documentation under 21 CFR 1301-1311. **Pros:** - Prevents DEA registration revocation that would shut down controlled substance dispensing - Demonstrates corresponding responsibility diligence to investigators - Organized recordkeeping reduces stress during unannounced inspections **Cons:** - Non-compliance can result in immediate registration suspension - Recordkeeping gaps create presumption of diversion - Failure to document red flag resolution exposes individual pharmacists to personal liability #### State Board of Pharmacy Requirements State-specific licensing, staffing ratios, counseling documentation, temperature monitoring, prescription filing, and expired medication management. **Pros:** - Maintains active pharmacy license and avoids operational shutdowns - Proper staffing ratios protect patient safety and reduce dispensing errors - Documented counseling demonstrates standard of care in malpractice situations **Cons:** - License violations can result in probation, fines, or revocation - Staffing ratio violations may void professional liability insurance coverage - Temperature log gaps can trigger full inventory quarantine during inspections #### Fraud, Waste, and Abuse Prevention Medicare Part D FWA training, compliance program requirements, dispensing data monitoring, and billing anomaly detection per 42 CFR 423.504. **Pros:** - Fulfills CMS compliance program requirements for Medicare Part D participation - Early detection of billing anomalies prevents large-scale recoupments - Documented FWA training protects against allegations of knowingly fraudulent billing **Cons:** - Failure to train staff can result in exclusion from Medicare Part D networks - Undetected billing patterns may trigger fraud investigations - Lack of a compliance program is itself a violation under CMS requirements #### OIG Exclusion Screening Monthly screening of all employees, contractors, and vendors against the OIG List of Excluded Individuals/Entities (LEIE) per 42 USC 1320a-7. **Pros:** - Prevents civil monetary penalties of up to $100,000 per item or service - Monthly screening catches status changes between annual checks - Creates an auditable compliance trail for CMS and state Medicaid auditors **Cons:** - Employing an excluded individual triggers treble damages plus per-item penalties - Annual-only screening may miss mid-year exclusions - Failure to screen vendors extends liability beyond direct employees #### PBM Contract Compliance and Audit Readiness Documentation standards for signature logs, DAW codes, compound claims, usual and customary pricing, and audit response timelines. **Pros:** - Audit-ready records reduce response time from weeks to days - Proper DAW documentation prevents automatic recoupments on branded dispensing - Defensible U&C pricing withstands MAC appeals and audit challenges **Cons:** - Missing signature logs result in automatic recoupment of the entire claim - Improper DAW-1 documentation can trigger fraud referrals from PBMs - Unorganized records within the 10-14 day response window leads to default findings **Conclusion:** Building a comprehensive compliance program is not a one-time project - it is an ongoing commitment to operational excellence. The checklist above covers the major regulatory domains, but your pharmacy may have additional requirements based on your state, your payer mix, and your service offerings (compounding, long-term care, specialty). Start with what is here, customize it for your operation, and commit to the calendar. Platforms like Rxperts can help you systematize this work with mock inspections, compliance checklists, and audit preparation tools that turn this checklist into a living, trackable workflow rather than a static document gathering dust in a binder. --- ## Newsletter Archive ### March 2026: Spring Inspection Surge + PBM Audit Season *Published: 2026-03-01* *URL: https://www.rx-perts.com/newsletter/compliance-digest-2026-03* State boards ramp up inspections, PBM audit letters arrive, and OSHA updates March through June is historically the busiest period for pharmacy inspections. State boards staff up after the new fiscal year, PBM audit cycles kick into gear, and CMS Plan Sponsors issue their first wave of Part D audit notifications. If your compliance program has been coasting since January, this is the wake-up call. Here is what to expect and what to do about it. #### Spring Inspection Season: What to Expect State board inspection activity typically peaks between March and June. Budget cycles, new inspector hires, and fiscal year targets all converge during this window. Based on historical data, pharmacies are roughly 40% more likely to receive an unannounced inspection in Q2 than in Q4. This year, several states have also expanded their inspection authority. At least six states now allow boards to request electronic records remotely before scheduling an on-site visit - meaning the inspection process may start before an inspector ever walks through your door. The best preparation is not a last-minute scramble. It is having your compliance program running consistently so that any day could be inspection day. If you do want to do a self-assessment before spring, walk your pharmacy as if you were the inspector: check every posting, verify every license, count your controlled substance inventory, and pull your training records. #### PBM Audit Season Is Here The major PBMs typically issue their largest wave of audit notifications in Q1, with document submission deadlines falling in March through May. If you receive an audit letter this month, here is what matters most: Timeline is everything. Note every deadline in the notification letter and calendar them immediately. Missing a response deadline can result in automatic recoupment of the full audited amount, regardless of whether you have supporting documentation. Organize before you respond. Pull every document they request - prescriptions, signature logs, dispensing records - and organize them by claim before submitting anything. Incomplete or disorganized submissions lead to adverse findings that are difficult to reverse on appeal. Keep copies of everything you submit. This seems obvious, but many pharmacies send original documents or fail to document what they submitted and when. Your appeal rights depend on being able to prove what you provided during the initial audit. #### OSHA Update: Pharmacy Workplace Safety Requirements OSHA has updated several workplace safety requirements that affect pharmacy operations. The changes are not dramatic, but they expand documentation requirements in areas that pharmacies sometimes overlook: Hazardous drug handling. The updated USP 800 enforcement landscape means pharmacies handling hazardous drugs need current Standard Operating Procedures, documented training for all staff who handle these medications, and evidence of proper PPE availability and use. If your pharmacy compounds or repackages hazardous drugs, verify your USP 800 compliance documentation is current. Bloodborne pathogen exposure plans. Pharmacies offering immunizations and point-of-care testing need documented exposure control plans, staff training records, and sharps disposal compliance. With more states expanding pharmacy immunization authority, this area is getting more attention from both OSHA and state board inspectors. Emergency action plans. OSHA requires written emergency action plans for workplaces above a certain size threshold. Many pharmacies fall into this requirement but have not formalized their plans. At minimum, you need documented evacuation procedures, emergency contact information, and evidence that staff have been trained on the plan. #### Did You Know: The Most Common "Easy Fix" Deficiencies Across the inspection data we track, roughly 35% of all deficiencies found during pharmacy inspections could have been fixed in under 15 minutes. These are not complex operational failures - they are simple oversights that create unnecessary deficiency findings: - Expired regulatory postings (pharmacist license, DEA registration, state license) - Missing or outdated Notice of Privacy Practices - Temperature monitoring logs with weekend gaps - Fire extinguisher inspection tags that have not been signed - Emergency exit signs with burned-out bulbs - Missing "Pharmacist Not on Duty" signage (required in many states) None of these reflect a deep compliance failure. But every one of them appears on the inspection report and signals to the inspector that attention to detail may be lacking. A 15-minute walk-through once a month catches all of them. #### The Shortlist - Conduct a self-assessment walkthrough of your pharmacy this week - Calendar all PBM audit response deadlines if you received audit notifications - Verify USP 800 compliance documentation for hazardous drug handling - Update OSHA exposure control plan if your pharmacy offers immunizations - Check all regulatory postings for currency (licenses, DEA, privacy notice) - Review temperature monitoring logs for any gaps - Ensure emergency action plan is documented and staff are trained # March 2026: Spring Inspection Surge + PBM Audit Season March through June is historically the busiest period for pharmacy inspections. State boards staff up after the new fiscal year, PBM audit cycles kick into gear, and CMS Plan Sponsors issue their first wave of Part D audit notifications. If your compliance program has been coasting since January, this is the wake-up call. Here is what to expect and what to do about it. --- ## Spring Inspection Season: What to Expect State board inspection activity typically peaks between March and June. Budget cycles, new inspector hires, and fiscal year targets all converge during this window. Based on historical data, pharmacies are roughly 40% more likely to receive an unannounced inspection in Q2 than in Q4. This year, several states have also expanded their inspection authority. At least six states now allow boards to request electronic records remotely before scheduling an on-site visit - meaning the inspection process may start before an inspector ever walks through your door. The best preparation is not a last-minute scramble. It is having your compliance program running consistently so that any day could be inspection day. If you do want to do a self-assessment before spring, walk your pharmacy as if you were the inspector: check every posting, verify every license, count your controlled substance inventory, and pull your training records. --- ## PBM Audit Season Is Here The major PBMs typically issue their largest wave of audit notifications in Q1, with document submission deadlines falling in March through May. If you receive an audit letter this month, here is what matters most: **Timeline is everything.** Note every deadline in the notification letter and calendar them immediately. Missing a response deadline can result in automatic recoupment of the full audited amount, regardless of whether you have supporting documentation. **Organize before you respond.** Pull every document they request - prescriptions, signature logs, dispensing records - and organize them by claim before submitting anything. Incomplete or disorganized submissions lead to adverse findings that are difficult to reverse on appeal. **Keep copies of everything you submit.** This seems obvious, but many pharmacies send original documents or fail to document what they submitted and when. Your appeal rights depend on being able to prove what you provided during the initial audit. --- ## OSHA Update: Pharmacy Workplace Safety Requirements OSHA has updated several workplace safety requirements that affect pharmacy operations. The changes are not dramatic, but they expand documentation requirements in areas that pharmacies sometimes overlook: **Hazardous drug handling.** The updated USP 800 enforcement landscape means pharmacies handling hazardous drugs need current Standard Operating Procedures, documented training for all staff who handle these medications, and evidence of proper PPE availability and use. If your pharmacy compounds or repackages hazardous drugs, verify your USP 800 compliance documentation is current. **Bloodborne pathogen exposure plans.** Pharmacies offering immunizations and point-of-care testing need documented exposure control plans, staff training records, and sharps disposal compliance. With more states expanding pharmacy immunization authority, this area is getting more attention from both OSHA and state board inspectors. **Emergency action plans.** OSHA requires written emergency action plans for workplaces above a certain size threshold. Many pharmacies fall into this requirement but have not formalized their plans. At minimum, you need documented evacuation procedures, emergency contact information, and evidence that staff have been trained on the plan. --- ## Did You Know: The Most Common "Easy Fix" Deficiencies Across the inspection data we track, roughly 35% of all deficiencies found during pharmacy inspections could have been fixed in under 15 minutes. These are not complex operational failures - they are simple oversights that create unnecessary deficiency findings: - Expired regulatory postings (pharmacist license, DEA registration, state license) - Missing or outdated Notice of Privacy Practices - Temperature monitoring logs with weekend gaps - Fire extinguisher inspection tags that have not been signed - Emergency exit signs with burned-out bulbs - Missing "Pharmacist Not on Duty" signage (required in many states) None of these reflect a deep compliance failure. But every one of them appears on the inspection report and signals to the inspector that attention to detail may be lacking. A 15-minute walk-through once a month catches all of them. --- ## This Month's Checklist - Conduct a self-assessment walkthrough of your pharmacy this week - Calendar all PBM audit response deadlines if you received audit notifications - Verify USP 800 compliance documentation for hazardous drug handling - Update OSHA exposure control plan if your pharmacy offers immunizations - Check all regulatory postings for currency (licenses, DEA, privacy notice) - Review temperature monitoring logs for any gaps - Ensure emergency action plan is documented and staff are trained --- Stay compliant. Stay ahead. - The Rxperts Team ### February 2026: DEA Enforcement Hits Record Highs *Published: 2026-02-15* *URL: https://www.rx-perts.com/newsletter/compliance-digest-2026-02* DEA suspensions up 34%, HIPAA settlements climbing, and 3 things to check this month # February 2026: DEA Enforcement Hits Record Highs The enforcement numbers for 2025 are in, and they are not subtle. DEA pharmacy suspensions hit an all-time high. HIPAA settlement amounts climbed for the fifth consecutive year. PBM audit recoupments crossed the $38,000 average mark. This issue breaks down the numbers, highlights what changed, and gives you three things to verify in your pharmacy this month. --- ## By the Numbers: 2025 Pharmacy Enforcement in Review We compiled data from federal enforcement databases and state board records to build a picture of pharmacy enforcement in 2025. The headline numbers: The DEA issued **1,247 administrative actions** against pharmacies, including **189 immediate suspension orders** - up 34% from 2023. The median fine rose to **$67,500**. Most actions targeted controlled substance documentation failures, not dramatic diversion cases. The pharmacies that got hit were not running pill mills; they were independent pharmacies with inventory discrepancies and incomplete records. OCR settled pharmacy HIPAA cases for an average of **$142,000**. Every single pharmacy settlement involved one common finding: failure to conduct a security risk analysis. It does not matter how good your training program is if you cannot produce evidence that you assessed your security risks. PBM audit recoupments averaged **$38,400** for standard retail claims and **$127,000** for compound claims. The three largest PBMs audited over **22,000 pharmacy locations**. The theme across all of these: documentation. Not intent, not negligence, not bad actors. Documentation gaps in otherwise well-run pharmacies. --- ## Regulatory Watch: Telehealth Prescribing Rules Finalized The DEA finalized its framework for controlled substance prescribing via telehealth. The new rules impose additional documentation requirements on pharmacies dispensing CS prescriptions originating from telehealth encounters. The key change: pharmacies must verify that the prescriber has met the required standard for patient evaluation under the applicable telemedicine exception. For Schedule II prescriptions via telehealth, this means confirming the prescriber has documented compliance with 21 U.S.C. 802(54). If your pharmacy fills a significant volume of telehealth CS prescriptions, review your verification procedures now. The DEA has signaled that pharmacy-level enforcement for telehealth violations will increase through 2026, particularly targeting pharmacies serving as preferred dispensing locations for high-volume telehealth prescribers. --- ## Three Things to Check in Your Pharmacy This Month February is a natural checkpoint for compliance programs. Here are three items to verify before the end of the month: 1. **DEA Biennial Inventory.** If your pharmacy is due for its biennial controlled substance inventory, check the exact due date. The biennial inventory runs from the date of your initial inventory, not the calendar year. Missing the date is a common finding in DEA inspections. 2. **Employee License Expirations.** Pull a list of every pharmacist and technician license, certification, and registration in your pharmacy. Check for any expiring in Q1 2026. An expired license for even one staff member is a deficiency that inspectors catch instantly. 3. **OIG Screening Records.** If you have not run your February OIG/SAM exclusion screening yet, do it this week. The LEIE database updates monthly (typically mid-month). Document the date, databases checked, and results for every individual screened. --- ## Trend Alert: States Expanding Mandatory Compliance Programs Four additional states are considering legislation in 2026 that would require retail pharmacies to maintain formal compliance programs. Currently about 12 states have some form of compliance program requirement. The proposed requirements vary by state but generally include: a designated compliance officer, written compliance policies, employee training programs, internal monitoring and auditing procedures, and a process for responding to detected violations. Even if your state does not currently mandate a compliance program, having one in place demonstrates due diligence if you ever face an enforcement action. Regulators and courts consistently look more favorably on organizations that can show a good-faith compliance effort. --- ## This Month's Checklist - Check your DEA biennial inventory due date and ensure it is scheduled - Review all staff license and certification expiration dates for Q1 2026 - Run February OIG/SAM exclusion screening and document results - Review telehealth prescribing verification procedures for controlled substances - Verify HIPAA security risk analysis is current and documented - Check that all regulatory postings are current and properly displayed --- Stay compliant. Stay ahead. - The Rxperts Team ### Year-End Compliance Wrap-Up and 2026 Preview *Published: 2026-01-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2026-01-01* Your 2025 compliance scorecard and what is coming in 2026 Happy New Year from the Rxperts team. Before we dive into 2026, let us take a moment to look back at the compliance landscape of 2025 - what changed, what caught pharmacies off guard, and what lessons we should carry forward. Then we will look ahead at the regulatory changes and trends that will define pharmacy compliance in the year ahead. #### 2025 in Review: The Compliance Stories That Mattered Most Looking back at 2025, several compliance themes dominated the pharmacy landscape. PBM reform gained real momentum. The FTC continued its investigation into PBM practices, several states passed meaningful transparency and reform legislation, and CMS implemented new oversight requirements for Part D plan sponsors. While pharmacies are still fighting uphill, the regulatory environment is shifting in a direction that favors greater transparency and accountability from PBMs. DEA enforcement remained aggressive. The agency continued to prioritize corresponding responsibility enforcement, and we saw several pharmacies face significant penalties for failing to identify and act on red flags in controlled substance prescriptions. The lesson from 2025 is clear: documentation of your clinical decision-making process is not optional. HIPAA enforcement set new records. OCR resolved more Right of Access cases in 2025 than in any previous year, and the penalties continued to climb. The pattern is unmistakable: when patients ask for their records, you must deliver them promptly and in the requested format. OIG exclusion screening became a compliance flashpoint. Several high-profile enforcement actions involving excluded individuals highlighted the financial risk of missed screenings, and CMS guidance made it clear that monthly screening of all workforce members is the expected standard. #### Regulatory Preview: What Is Coming in 2026 Here is what we are watching for the year ahead. Medicare Part D continues to evolve under the Inflation Reduction Act. The next round of drug price negotiations will affect a broader set of medications, and pharmacies should expect continued adjustments to plan formularies and reimbursement structures. Stay engaged with your PSAO and state pharmacy association to track these changes. DEA electronic prescribing for controlled substances may see updated regulations. The Modernizing Opioid Treatment Access Act and related legislative efforts could expand access to electronic prescribing while also increasing the technology requirements for pharmacies. If you have not migrated to a fully electronic controlled substance prescribing workflow, 2026 is the year to complete that transition. State-level pharmacy regulation continues to diversify. We are seeing states take increasingly different approaches to pharmacy practice, from expanding technician scope of practice to implementing new compounding regulations. If you operate in multiple states, keeping track of these differences is a full-time job - and getting it wrong can cost you your license. USP General Chapter revisions continue to affect compounding pharmacies. USP 795, 797, and 800 updates will bring new requirements for facilities, training, and documentation. If you compound, stay connected with the USP revision process and start planning for any facility or equipment changes you may need. Cybersecurity in healthcare is getting regulatory attention. Following several high-profile data breaches in 2024 and 2025, HHS has signaled plans for updated HIPAA Security Rule requirements. Pharmacies should begin assessing their cybersecurity posture now, including network security, access controls, encryption, and incident response plans. #### HIPAA Focus for 2026: Security Rule Modernization HHS has proposed updates to the HIPAA Security Rule that would, among other things, require covered entities to conduct a written risk analysis, implement multi-factor authentication for access to systems containing ePHI, encrypt all ePHI at rest and in transit, and maintain detailed technology asset inventories. While the final rule may differ from the proposal, the direction is clear: the government expects healthcare entities, including pharmacies, to take information security more seriously than ever. If your pharmacy still relies on shared passwords, unencrypted email for PHI, or has not conducted a formal security risk assessment, these changes will require significant investment. Start with a risk assessment. You cannot protect what you do not understand, and a formal risk assessment is already required under the current Security Rule - most pharmacies just have not done one. Identify your systems that contain ePHI, the threats and vulnerabilities affecting each one, and the safeguards you have in place. This assessment becomes your roadmap for the security improvements you need to make in 2026. #### Your 2026 Compliance Action Plan Here is a month-by-month framework to keep your compliance program on track for the new year. January: Conduct your annual compliance program review. Update your P&P manual, refresh your compliance plan, and schedule all required training for the year. February: Complete your annual HIPAA security risk assessment. Identify gaps and create a remediation timeline. March: File your annual HHS breach report for any small breaches discovered in 2025. Verify Medicare enrollment revalidation status. April through June: Conduct your first-half internal audits - PBM documentation, controlled substance accountability, and OIG screening compliance. July: Mid-year training check. Ensure all staff are current on HIPAA, FWA, and controlled substance training. Catch up on any new hire training that slipped. August through September: Begin preparation for Q4 PBM audits. Review documentation practices and run a mock audit on a sample of claims. October: Conduct a self-inspection using your state board checklist. Review all required postings, licenses, and registrations for expiration dates. November through December: Year-end compliance wrap-up. Review contracts, update vendor lists and BAAs, and document your annual compliance program activities. Tape this to your wall, put it in your calendar, or track it in [Rxperts](/portal/compliance-tracker). However you manage it, having a plan beats reacting to problems after they happen. Here is to a compliant and successful 2026. #### The Shortlist - Complete your annual compliance program review and update your P&P manual - Schedule all required training sessions for 2026 now - Conduct a HIPAA security risk assessment in Q1 - Review and update all vendor BAAs for the new year - Set up monthly OIG screening reminders if you have not already - Bookmark the 2026 compliance calendar and assign responsibility for each milestone # Year-End Compliance Wrap-Up and 2026 Preview Happy New Year from the Rxperts team. Before we dive into 2026, let us take a moment to look back at the compliance landscape of 2025 - what changed, what caught pharmacies off guard, and what lessons we should carry forward. Then we will look ahead at the regulatory changes and trends that will define pharmacy compliance in the year ahead. --- ## 2025 in Review: The Compliance Stories That Mattered Most Looking back at 2025, several compliance themes dominated the pharmacy landscape. **PBM reform gained real momentum.** The FTC continued its investigation into PBM practices, several states passed meaningful transparency and reform legislation, and CMS implemented new oversight requirements for Part D plan sponsors. While pharmacies are still fighting uphill, the regulatory environment is shifting in a direction that favors greater transparency and accountability from PBMs. **DEA enforcement remained aggressive.** The agency continued to prioritize corresponding responsibility enforcement, and we saw several pharmacies face significant penalties for failing to identify and act on red flags in controlled substance prescriptions. The lesson from 2025 is clear: documentation of your clinical decision-making process is not optional. **HIPAA enforcement set new records.** OCR resolved more Right of Access cases in 2025 than in any previous year, and the penalties continued to climb. The pattern is unmistakable: when patients ask for their records, you must deliver them promptly and in the requested format. **OIG exclusion screening became a compliance flashpoint.** Several high-profile enforcement actions involving excluded individuals highlighted the financial risk of missed screenings, and CMS guidance made it clear that monthly screening of all workforce members is the expected standard. --- ## Regulatory Preview: What Is Coming in 2026 Here is what we are watching for the year ahead. **Medicare Part D continues to evolve** under the Inflation Reduction Act. The next round of drug price negotiations will affect a broader set of medications, and pharmacies should expect continued adjustments to plan formularies and reimbursement structures. Stay engaged with your PSAO and state pharmacy association to track these changes. **DEA electronic prescribing for controlled substances** may see updated regulations. The Modernizing Opioid Treatment Access Act and related legislative efforts could expand access to electronic prescribing while also increasing the technology requirements for pharmacies. If you have not migrated to a fully electronic controlled substance prescribing workflow, 2026 is the year to complete that transition. **State-level pharmacy regulation continues to diversify.** We are seeing states take increasingly different approaches to pharmacy practice, from expanding technician scope of practice to implementing new compounding regulations. If you operate in multiple states, keeping track of these differences is a full-time job - and getting it wrong can cost you your license. **USP General Chapter revisions** continue to affect compounding pharmacies. USP 795, 797, and 800 updates will bring new requirements for facilities, training, and documentation. If you compound, stay connected with the USP revision process and start planning for any facility or equipment changes you may need. **Cybersecurity in healthcare** is getting regulatory attention. Following several high-profile data breaches in 2024 and 2025, HHS has signaled plans for updated HIPAA Security Rule requirements. Pharmacies should begin assessing their cybersecurity posture now, including network security, access controls, encryption, and incident response plans. --- ## HIPAA Focus for 2026: Security Rule Modernization HHS has proposed updates to the HIPAA Security Rule that would, among other things, require covered entities to conduct a written risk analysis, implement multi-factor authentication for access to systems containing ePHI, encrypt all ePHI at rest and in transit, and maintain detailed technology asset inventories. While the final rule may differ from the proposal, the direction is clear: the government expects healthcare entities, including pharmacies, to take information security more seriously than ever. If your pharmacy still relies on shared passwords, unencrypted email for PHI, or has not conducted a formal security risk assessment, these changes will require significant investment. Start with a risk assessment. You cannot protect what you do not understand, and a formal risk assessment is already required under the current Security Rule - most pharmacies just have not done one. Identify your systems that contain ePHI, the threats and vulnerabilities affecting each one, and the safeguards you have in place. This assessment becomes your roadmap for the security improvements you need to make in 2026. --- ## Your 2026 Compliance Action Plan Here is a month-by-month framework to keep your compliance program on track for the new year. **January:** Conduct your annual compliance program review. Update your P&P manual, refresh your compliance plan, and schedule all required training for the year. **February:** Complete your annual HIPAA security risk assessment. Identify gaps and create a remediation timeline. **March:** File your annual HHS breach report for any small breaches discovered in 2025. Verify Medicare enrollment revalidation status. **April through June:** Conduct your first-half internal audits - PBM documentation, controlled substance accountability, and OIG screening compliance. **July:** Mid-year training check. Ensure all staff are current on HIPAA, FWA, and controlled substance training. Catch up on any new hire training that slipped. **August through September:** Begin preparation for Q4 PBM audits. Review documentation practices and run a mock audit on a sample of claims. **October:** Conduct a self-inspection using your state board checklist. Review all required postings, licenses, and registrations for expiration dates. **November through December:** Year-end compliance wrap-up. Review contracts, update vendor lists and BAAs, and document your annual compliance program activities. Tape this to your wall, put it in your calendar, or track it in [Rxperts](/portal/compliance-tracker). However you manage it, having a plan beats reacting to problems after they happen. Here is to a compliant and successful 2026. --- ## Quick Hits - Complete your annual compliance program review and update your P&P manual - Schedule all required training sessions for 2026 now - Conduct a HIPAA security risk assessment in Q1 - Review and update all vendor BAAs for the new year - Set up monthly OIG screening reminders if you have not already - Bookmark the 2026 compliance calendar and assign responsibility for each milestone --- Stay compliant. Stay ahead. - The Rxperts Team ### Medicare and Medicaid Updates for Pharmacy Owners *Published: 2025-12-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-12-01* Part D changes, Medicaid reimbursement shifts, and what they mean for you # Medicare and Medicaid Updates for Pharmacy Owners December means two things for pharmacy owners: year-end close-out tasks and preparing for the regulatory changes taking effect in January. This month we are focused on Medicare and Medicaid - the programs that keep many pharmacies running but also create some of the most complex compliance obligations in healthcare. Here is what is changing and what you need to do about it. --- ## Regulatory Update: Medicare Part D Changes Taking Effect in 2026 The Inflation Reduction Act continues to reshape Medicare Part D, and pharmacies need to prepare for the next wave of changes. The $2,000 annual out-of-pocket cap for Part D beneficiaries, which took effect in 2025, has altered patient utilization patterns in ways that affect pharmacy workflow and cash flow. Plan sponsors are adjusting their formularies and network contracts in response to these changes, and some pharmacies are seeing shifts in their payer mix as a result. If you have not reviewed your Part D contract terms recently, do it before the new plan year starts. Pay particular attention to DIR fee structures, preferred pharmacy status, and any changes to dispensing fee schedules. Additionally, CMS is expanding the Medicare Drug Price Negotiation Program, with a new set of drugs subject to negotiated maximum fair prices taking effect in 2026. While the direct impact on pharmacy-level reimbursement will vary by drug and plan, these negotiated prices will filter through the supply chain and may affect your acquisition costs and margins on affected products. Stay informed about which drugs are included and how your wholesaler is pricing them. --- ## Medicaid Reimbursement: What Pharmacy Owners Need to Watch Medicaid reimbursement continues to be a moving target, and 2025 has brought significant changes at the state level. Several states have transitioned to or modified their Actual Acquisition Cost (AAC) based reimbursement models, moving away from Average Wholesale Price (AWP) benchmarks. If your state made this transition and you have not adjusted your pricing expectations, you may be leaving money on the table - or accepting reimbursement below cost without realizing it. The professional dispensing fee is where many pharmacies recover the margin lost in the ingredient cost reimbursement change. Know your state's current dispensing fee and compare it to your actual cost of dispensing. If there is a gap, engage with your state pharmacy association on advocacy for fair dispensing fees. Also watch for changes in Medicaid managed care contracts. As states shift more of their Medicaid population into managed care organizations (MCOs), your reimbursement terms may be set by the MCO rather than the state fee schedule. Review your MCO contracts carefully and compare their rates to the state Medicaid fee schedule. In some cases, MCO rates are lower, and you may need to negotiate or consider whether participation makes financial sense. Keep documentation of your cost of dispensing analysis. If you ever need to appeal a reimbursement decision or participate in a state rate-setting process, having current data on your actual costs is essential. --- ## HIPAA and Government Program Compliance: Where They Intersect Participating in Medicare and Medicaid creates compliance obligations beyond standard HIPAA requirements. The False Claims Act, Anti-Kickback Statute, and Stark Law all come into play when you bill federal healthcare programs, and violations of these laws can have consequences that dwarf a typical HIPAA penalty. One area where we see pharmacies stumble is patient inducements. Routinely waiving copayments for Medicare or Medicaid patients can constitute a violation of the Anti-Kickback Statute and may also implicate the False Claims Act. There are limited exceptions - financial hardship waivers for patients who genuinely cannot afford their copayment - but these must be documented on a case-by-case basis. A blanket policy of waiving copays is not permitted. Another common issue is improper billing practices. Billing for a quantity not dispensed, billing for a brand when a generic was dispensed, or billing for a higher-cost product than what was actually provided can all constitute false claims. These often result from data entry errors rather than intentional fraud, but the government does not always make that distinction. Regular self-audits of your billing data are your best defense. --- ## Year-End Checklist for Government Program Compliance Before you close the books on 2025, run through this checklist to ensure your Medicare and Medicaid compliance is solid heading into the new year. **Revalidation status:** Confirm your Medicare enrollment is active and your next revalidation date is on your calendar. Check PECOS for any pending actions or requests. **NPI accuracy:** Verify that your NPI information is current in NPPES. This includes your business address, authorized officials, and taxonomy codes. Incorrect NPI data can cause claim denials and compliance issues. **Medicaid enrollment:** Confirm your enrollment is active in every state where you dispense to Medicaid patients. If you added a new pharmacy location this year, make sure it is properly enrolled. **Contract review:** Pull your Part D and Medicaid MCO contracts. Note any rate changes, DIR fee modifications, or new requirements taking effect January 1. **Compliance program review:** CMS requires pharmacies participating in Part D to have a compliance program. Review your program against the seven elements of an effective compliance program: written standards, compliance officer, training, communication lines, internal monitoring, enforcement, and corrective action. Document your year-end review. A written summary showing that you reviewed each of these areas demonstrates the kind of proactive compliance that CMS looks for during audits. --- ## Quick Hits - Check your Medicare enrollment status and revalidation date in PECOS - Verify NPI information is current and accurate in NPPES - Review Part D and Medicaid MCO contracts for January 1 changes - Audit copayment waiver practices for Anti-Kickback Statute compliance - Run a self-audit on billing accuracy for the past quarter - Document your year-end compliance program review --- Stay compliant. Stay ahead. - The Rxperts Team ### Controlled Substances: New Reporting Requirements *Published: 2025-11-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-11-01* Updated ARCOS rules and theft reporting - what changed and action steps Controlled substance management is getting more scrutiny, and the reporting requirements keep expanding. Whether it is ARCOS reporting, theft and loss procedures, or inventory reconciliation, DEA expects pharmacies to have their controlled substance house in order at all times. This month, we are covering the latest changes and giving you a practical guide to staying ahead of them. #### Regulatory Update: ARCOS Reporting and Electronic Recordkeeping Changes The Automation of Reports and Consolidated Orders System (ARCOS) is DEA's tracking system for Schedule I and II controlled substances and select Schedule III substances (like buprenorphine products). Manufacturers and distributors report transactions into ARCOS, and DEA uses this data to monitor the distribution chain and identify potential diversion. For pharmacies, the key development is DEA's increasing use of ARCOS data to flag pharmacies whose ordering patterns deviate significantly from their peers. If your pharmacy is ordering quantities of a controlled substance that are statistically unusual for your pharmacy type, size, and geography, expect a letter - or a visit. The practical takeaway: review your controlled substance ordering patterns quarterly. Compare your current ordering volumes to the previous quarter and the same quarter last year. If you see significant increases, be prepared to explain them with clinical documentation - new prescribers in your area, a patient population shift, or a legitimate change in your dispensing patterns. Having the explanation ready before DEA asks for it is always better than scrambling after the fact. #### Theft and Loss Reporting: The Complete Guide When controlled substances go missing from your pharmacy, DEA requires notification - and the timeline and method depend on the circumstances. For a significant theft or loss - defined as any theft, or a loss that is significant in quantity or that is unusual - you must file a DEA 106 form. There is no specific timeline mandated by federal regulation for submitting the DEA 106, but best practice (and many state requirements) is to file within one business day of discovery. Some states require notification to the state board of pharmacy within 24 hours as well, so check your state rules. For breakage and spillage that can be accounted for (you dropped a bottle and it spilled), you do not need to file a DEA 106, but you do need to document the loss internally. Record what was lost, the quantity, the circumstances, the date, and the witnesses present. Have the pharmacist-in-charge and one witness sign the record. Do not wait to investigate before reporting. DEA expects you to report the discovery promptly and then conduct your investigation. Filing the DEA 106 is not an admission of fault - it is a legal obligation. Pharmacies get into far more trouble for delayed reporting than for the loss itself. After filing the DEA 106, conduct a thorough investigation. Review security camera footage, audit dispensing records, check your perpetual inventory against physical counts, and interview staff if appropriate. Document your investigation and its findings, and implement corrective actions to prevent recurrence. Keep all of this documentation for at least five years. #### HIPAA Considerations in Controlled Substance Investigations When investigating a potential controlled substance theft or diversion, you may need to review dispensing records that contain patient information. This is permissible under HIPAA when the review is conducted for healthcare operations purposes, which includes compliance activities and internal investigations. However, limit the scope of your review to what is necessary for the investigation. If you suspect a specific drug was diverted, review records for that drug - not every controlled substance in your inventory. If you bring in outside investigators or law enforcement, HIPAA permits disclosure for law enforcement purposes, but document the disclosure and limit the information shared to what is relevant to the investigation. If your investigation reveals that patient records were accessed inappropriately as part of a diversion scheme, that may also constitute a HIPAA breach. Evaluate the situation under your breach assessment procedures and report as required. #### Building a Controlled Substance Accountability System The pharmacies that avoid controlled substance compliance problems share a common trait: they treat accountability as a daily practice, not an annual event. Here is how to build that system. Implement a perpetual inventory for at least your top 20 controlled substances by volume. A perpetual inventory means recording every receipt and every dispensing event, so you have a running count that can be compared to a physical count at any time. Many pharmacy management systems support this feature - if yours does, turn it on. If it does not, a simple spreadsheet works. Conduct random physical counts weekly. Pick two to three controlled substances at random each week, count the physical stock, and compare it to your perpetual inventory or your last physical count adjusted for receipts and dispensings. Document the count, the expected quantity, the actual quantity, and any discrepancy. Investigate discrepancies immediately. Secure your controlled substance storage and limit access. Only pharmacists and specifically authorized staff should have access to Schedule II storage. Log who opens the safe or cabinet and when. Some pharmacies use time-delay safes, which both deter robbery and create access logs. Review your security camera coverage. Cameras should cover controlled substance storage areas, dispensing counters, and delivery receiving areas. Retention should be at least 90 days. If DEA or law enforcement needs footage from six months ago and you only keep 30 days, you have a problem. Use our [Controlled Substance Compliance Checklist](/blog/controlled-substance-management) as a starting point for building your system. #### The Shortlist - Review your controlled substance ordering patterns for unusual changes - Verify your DEA 106 reporting procedure is documented and all pharmacists know it - Implement or audit your perpetual inventory for high-volume controlled substances - Conduct a random physical count of 3 controlled substances this week - Check security camera coverage and retention for all controlled substance storage areas - Confirm breakage and spillage documentation procedures are being followed # Controlled Substances: New Reporting Requirements Controlled substance management is getting more scrutiny, and the reporting requirements keep expanding. Whether it is ARCOS reporting, theft and loss procedures, or inventory reconciliation, DEA expects pharmacies to have their controlled substance house in order at all times. This month, we are covering the latest changes and giving you a practical guide to staying ahead of them. --- ## Regulatory Update: ARCOS Reporting and Electronic Recordkeeping Changes The Automation of Reports and Consolidated Orders System (ARCOS) is DEA's tracking system for Schedule I and II controlled substances and select Schedule III substances (like buprenorphine products). Manufacturers and distributors report transactions into ARCOS, and DEA uses this data to monitor the distribution chain and identify potential diversion. For pharmacies, the key development is DEA's increasing use of ARCOS data to flag pharmacies whose ordering patterns deviate significantly from their peers. If your pharmacy is ordering quantities of a controlled substance that are statistically unusual for your pharmacy type, size, and geography, expect a letter - or a visit. The practical takeaway: review your controlled substance ordering patterns quarterly. Compare your current ordering volumes to the previous quarter and the same quarter last year. If you see significant increases, be prepared to explain them with clinical documentation - new prescribers in your area, a patient population shift, or a legitimate change in your dispensing patterns. Having the explanation ready before DEA asks for it is always better than scrambling after the fact. --- ## Theft and Loss Reporting: The Complete Guide When controlled substances go missing from your pharmacy, DEA requires notification - and the timeline and method depend on the circumstances. **For a significant theft or loss** - defined as any theft, or a loss that is significant in quantity or that is unusual - you must file a DEA 106 form. There is no specific timeline mandated by federal regulation for submitting the DEA 106, but best practice (and many state requirements) is to file within one business day of discovery. Some states require notification to the state board of pharmacy within 24 hours as well, so check your state rules. **For breakage and spillage** that can be accounted for (you dropped a bottle and it spilled), you do not need to file a DEA 106, but you do need to document the loss internally. Record what was lost, the quantity, the circumstances, the date, and the witnesses present. Have the pharmacist-in-charge and one witness sign the record. Do not wait to investigate before reporting. DEA expects you to report the discovery promptly and then conduct your investigation. Filing the DEA 106 is not an admission of fault - it is a legal obligation. Pharmacies get into far more trouble for delayed reporting than for the loss itself. After filing the DEA 106, conduct a thorough investigation. Review security camera footage, audit dispensing records, check your perpetual inventory against physical counts, and interview staff if appropriate. Document your investigation and its findings, and implement corrective actions to prevent recurrence. Keep all of this documentation for at least five years. --- ## HIPAA Considerations in Controlled Substance Investigations When investigating a potential controlled substance theft or diversion, you may need to review dispensing records that contain patient information. This is permissible under HIPAA when the review is conducted for healthcare operations purposes, which includes compliance activities and internal investigations. However, limit the scope of your review to what is necessary for the investigation. If you suspect a specific drug was diverted, review records for that drug - not every controlled substance in your inventory. If you bring in outside investigators or law enforcement, HIPAA permits disclosure for law enforcement purposes, but document the disclosure and limit the information shared to what is relevant to the investigation. If your investigation reveals that patient records were accessed inappropriately as part of a diversion scheme, that may also constitute a HIPAA breach. Evaluate the situation under your breach assessment procedures and report as required. --- ## Building a Controlled Substance Accountability System The pharmacies that avoid controlled substance compliance problems share a common trait: they treat accountability as a daily practice, not an annual event. Here is how to build that system. **Implement a perpetual inventory** for at least your top 20 controlled substances by volume. A perpetual inventory means recording every receipt and every dispensing event, so you have a running count that can be compared to a physical count at any time. Many pharmacy management systems support this feature - if yours does, turn it on. If it does not, a simple spreadsheet works. **Conduct random physical counts weekly.** Pick two to three controlled substances at random each week, count the physical stock, and compare it to your perpetual inventory or your last physical count adjusted for receipts and dispensings. Document the count, the expected quantity, the actual quantity, and any discrepancy. Investigate discrepancies immediately. **Secure your controlled substance storage and limit access.** Only pharmacists and specifically authorized staff should have access to Schedule II storage. Log who opens the safe or cabinet and when. Some pharmacies use time-delay safes, which both deter robbery and create access logs. **Review your security camera coverage.** Cameras should cover controlled substance storage areas, dispensing counters, and delivery receiving areas. Retention should be at least 90 days. If DEA or law enforcement needs footage from six months ago and you only keep 30 days, you have a problem. Use our [Controlled Substance Compliance Checklist](/blog/controlled-substance-management) as a starting point for building your system. --- ## Quick Hits - Review your controlled substance ordering patterns for unusual changes - Verify your DEA 106 reporting procedure is documented and all pharmacists know it - Implement or audit your perpetual inventory for high-volume controlled substances - Conduct a random physical count of 3 controlled substances this week - Check security camera coverage and retention for all controlled substance storage areas - Confirm breakage and spillage documentation procedures are being followed --- Stay compliant. Stay ahead. - The Rxperts Team ### State Board Inspections: Lessons from the Field *Published: 2025-10-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-10-01* What inspectors actually look for - insider tips from 200+ inspections State board of pharmacy inspections can be stressful, but they do not have to be surprises. After working with pharmacies across dozens of states and reviewing hundreds of inspection reports, patterns emerge. Inspectors look at the same things in roughly the same order, and the pharmacies that pass with flying colors are the ones that prepared. Here are the lessons from the field. #### Regulatory Update: State Boards Increase Inspection Frequency Several state boards of pharmacy have increased their inspection cadence over the past year, driven partly by post-pandemic catch-up and partly by a broader push toward proactive oversight. States including Texas, Florida, California, and Ohio have all expanded their inspection staff or announced plans to increase routine inspection frequency. For pharmacy owners, this means the days of going three to five years between inspections may be ending. If your approach to inspection readiness has been "we will clean up when we hear they are coming," that strategy no longer works. Inspections are increasingly unannounced, and inspectors are arriving with more detailed checklists than they carried five years ago. The silver lining: if your pharmacy is truly compliant every day, an inspection is just a confirmation. The work you do to stay ready is the same work that prevents errors, protects patients, and keeps your license secure. #### The Top 10 Inspection Findings We See Repeatedly These are the findings that show up in inspection reports again and again, across multiple states. Fix these and you eliminate the vast majority of deficiency citations. 1. Outdated or missing policies and procedures manual. Inspectors will ask to see it, and they will check revision dates. 2. Expired medications on shelves - including OTC products, sample medications, and items in the refrigerator. 3. Improper controlled substance storage. Schedule II drugs must be stored in a securely locked, substantially constructed cabinet or dispersed throughout non-controlled stock. 4. Missing or incomplete controlled substance inventories. Your biennial inventory should be readily accessible. 5. Temperature logs not maintained for refrigerator and room temperature storage areas. 6. Missing pharmacist-in-charge postings or outdated information on required postings (DEA registration, state license, PIC notification). 7. Prescription files not maintained in required order or not accessible for the required retention period. 8. Lack of documented counseling offers for new prescriptions in states that require it. 9. Physical plant deficiencies - inadequate lighting, broken equipment, unsanitary conditions in compounding areas. 10. Unlicensed or unregistered staff members working in the pharmacy. Check that every technician and intern has a current registration with your state board. #### HIPAA and Inspections: What You Must and Must Not Share Board of pharmacy inspectors have broad authority to inspect your pharmacy, but that authority has limits when it comes to patient information. Inspectors can review prescription records, dispensing logs, and controlled substance documentation as part of their regulatory oversight function. This is permitted under HIPAA as a "health oversight activity." However, inspectors should not be browsing patient profiles unrelated to their inspection scope, and they should not be taking photographs of screens displaying patient information unless it is directly relevant to a specific finding. If an inspector asks for something that feels outside the scope of a routine inspection, it is reasonable to ask for clarification on the legal basis for the request. Document what the inspector reviewed during their visit. This protects both the pharmacy and the patients whose records were accessed. #### Your Monthly Self-Inspection Checklist The easiest way to pass a state board inspection is to conduct your own every month. Here is a streamlined checklist you can complete in under an hour. Start at the front door and work your way through the pharmacy as an inspector would. Check that all required postings are current and visible: state pharmacy license, DEA registration, pharmacist licenses, technician registrations, PIC notification, and your Notice of Privacy Practices. Move to the dispensing area. Verify that prescription files are organized and accessible. Check for expired medications on every shelf, in the refrigerator, and in the compounding area. Verify that controlled substances are properly secured and that your most recent inventory is on file. Check your equipment: refrigerator and freezer temperatures logged, prescription balances calibrated (if applicable), automated dispensing equipment maintained per manufacturer specifications. Review your records: training documentation current, P&P manual reviewed within the last 12 months, OIG screenings up to date, BAAs on file for all applicable vendors. Finally, do a physical plant walk-through: adequate lighting, clean and organized work surfaces, no obstructed exits, proper signage, and security systems functional. Document each self-inspection with the date, findings, and any corrective actions taken. This creates a record of proactive compliance that inspectors appreciate and that protects you if a finding arises. Download our [Inspection Readiness Checklist](/blog/state-board-inspection-prep) for a printable version. #### The Shortlist - Walk your pharmacy today and check all required postings for accuracy and currency - Pull every expired product from shelves, refrigerators, and compounding areas - Verify controlled substance storage meets your state requirements - Confirm every technician and intern has a current state registration on file - Check that temperature logs are complete for at least the last 30 days - Schedule a monthly self-inspection and document the results # State Board Inspections: Lessons from the Field State board of pharmacy inspections can be stressful, but they do not have to be surprises. After working with pharmacies across dozens of states and reviewing hundreds of inspection reports, patterns emerge. Inspectors look at the same things in roughly the same order, and the pharmacies that pass with flying colors are the ones that prepared. Here are the lessons from the field. --- ## Regulatory Update: State Boards Increase Inspection Frequency Several state boards of pharmacy have increased their inspection cadence over the past year, driven partly by post-pandemic catch-up and partly by a broader push toward proactive oversight. States including Texas, Florida, California, and Ohio have all expanded their inspection staff or announced plans to increase routine inspection frequency. For pharmacy owners, this means the days of going three to five years between inspections may be ending. If your approach to inspection readiness has been "we will clean up when we hear they are coming," that strategy no longer works. Inspections are increasingly unannounced, and inspectors are arriving with more detailed checklists than they carried five years ago. The silver lining: if your pharmacy is truly compliant every day, an inspection is just a confirmation. The work you do to stay ready is the same work that prevents errors, protects patients, and keeps your license secure. --- ## The Top 10 Inspection Findings We See Repeatedly These are the findings that show up in inspection reports again and again, across multiple states. Fix these and you eliminate the vast majority of deficiency citations. 1. **Outdated or missing policies and procedures manual.** Inspectors will ask to see it, and they will check revision dates. 2. **Expired medications on shelves** - including OTC products, sample medications, and items in the refrigerator. 3. **Improper controlled substance storage.** Schedule II drugs must be stored in a securely locked, substantially constructed cabinet or dispersed throughout non-controlled stock. 4. **Missing or incomplete controlled substance inventories.** Your biennial inventory should be readily accessible. 5. **Temperature logs not maintained** for refrigerator and room temperature storage areas. 6. **Missing pharmacist-in-charge postings** or outdated information on required postings (DEA registration, state license, PIC notification). 7. **Prescription files not maintained** in required order or not accessible for the required retention period. 8. **Lack of documented counseling offers** for new prescriptions in states that require it. 9. **Physical plant deficiencies** - inadequate lighting, broken equipment, unsanitary conditions in compounding areas. 10. **Unlicensed or unregistered staff members** working in the pharmacy. Check that every technician and intern has a current registration with your state board. --- ## HIPAA and Inspections: What You Must and Must Not Share Board of pharmacy inspectors have broad authority to inspect your pharmacy, but that authority has limits when it comes to patient information. Inspectors can review prescription records, dispensing logs, and controlled substance documentation as part of their regulatory oversight function. This is permitted under HIPAA as a "health oversight activity." However, inspectors should not be browsing patient profiles unrelated to their inspection scope, and they should not be taking photographs of screens displaying patient information unless it is directly relevant to a specific finding. If an inspector asks for something that feels outside the scope of a routine inspection, it is reasonable to ask for clarification on the legal basis for the request. Document what the inspector reviewed during their visit. This protects both the pharmacy and the patients whose records were accessed. --- ## Your Monthly Self-Inspection Checklist The easiest way to pass a state board inspection is to conduct your own every month. Here is a streamlined checklist you can complete in under an hour. **Start at the front door** and work your way through the pharmacy as an inspector would. Check that all required postings are current and visible: state pharmacy license, DEA registration, pharmacist licenses, technician registrations, PIC notification, and your Notice of Privacy Practices. **Move to the dispensing area.** Verify that prescription files are organized and accessible. Check for expired medications on every shelf, in the refrigerator, and in the compounding area. Verify that controlled substances are properly secured and that your most recent inventory is on file. **Check your equipment:** refrigerator and freezer temperatures logged, prescription balances calibrated (if applicable), automated dispensing equipment maintained per manufacturer specifications. **Review your records:** training documentation current, P&P manual reviewed within the last 12 months, OIG screenings up to date, BAAs on file for all applicable vendors. **Finally, do a physical plant walk-through:** adequate lighting, clean and organized work surfaces, no obstructed exits, proper signage, and security systems functional. Document each self-inspection with the date, findings, and any corrective actions taken. This creates a record of proactive compliance that inspectors appreciate and that protects you if a finding arises. Download our [Inspection Readiness Checklist](/blog/state-board-inspection-prep) for a printable version. --- ## Quick Hits - Walk your pharmacy today and check all required postings for accuracy and currency - Pull every expired product from shelves, refrigerators, and compounding areas - Verify controlled substance storage meets your state requirements - Confirm every technician and intern has a current state registration on file - Check that temperature logs are complete for at least the last 30 days - Schedule a monthly self-inspection and document the results --- Stay compliant. Stay ahead. - The Rxperts Team ### Mid-Year Training Check: Is Your Staff Up to Date? *Published: 2025-09-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-09-01* Training gaps are the #1 audit finding - close yours this month September is the perfect time for a mid-year training check. We are past the summer slump, new hires from the busy season are settling in, and there is still enough runway to close any gaps before year-end audits. If training documentation is the weakest part of your compliance program - and for most pharmacies, it is - this newsletter is your action plan. #### Regulatory Update: CMS Strengthens FWA Training Requirements for Part D CMS has continued to tighten compliance program requirements for Medicare Part D plan sponsors, and those requirements flow down to network pharmacies. Under current guidance, pharmacies participating in Medicare Part D must ensure that their workforce receives training on Fraud, Waste, and Abuse within 90 days of hire and annually thereafter. This is not optional, and it is not satisfied by a generic orientation session. FWA training must cover the definition of fraud, waste, and abuse in the context of federal healthcare programs, the laws and regulations that address FWA (including the False Claims Act, the Anti-Kickback Statute, and the Stark Law as applicable), how to report suspected FWA through your internal compliance program and to external entities like the OIG and CMS, and the protections available for whistleblowers. If you are a PSAO member, your PSAO may offer FWA training resources. But using a PSAO resource does not relieve you of the responsibility to ensure every workforce member completes the training and that completion is documented. #### The Complete Pharmacy Training Requirement Checklist Here is every training topic your pharmacy staff should be current on, broken down by requirement source. From HIPAA: Privacy and security awareness training for all workforce members, within a reasonable time after hire and when material changes occur. Best practice is annual refresher training, documented with dates and signatures. From DEA and state boards: Controlled substance handling, corresponding responsibility, and PDMP use. Most state boards require continuing education on controlled substance topics as part of license renewal, but your internal training should go beyond CE requirements to cover your specific pharmacy policies. From CMS (Medicare Part D): Fraud, Waste, and Abuse training within 90 days of hire and annually. General compliance training covering your compliance program structure, code of conduct, and reporting mechanisms. From OSHA: Bloodborne pathogen training if staff may be exposed (pharmacy-based immunization programs), hazard communication training if you handle hazardous drugs, and workplace safety orientation. From USP (if applicable): USP 795, 797, and 800 training for pharmacies that compound. This includes initial competency assessments and ongoing training specific to the types of compounding performed. For each topic, you need three things in your training file: the training content or materials used, the date the training was completed, and a signature or electronic acknowledgment from each employee who completed it. Missing any one of these three elements and the training is as good as undocumented. #### HIPAA Training: What Actually Counts HIPAA training requirements are more flexible than most people think, but that flexibility is not a license to cut corners. The HIPAA Privacy Rule requires training on your policies and procedures for all workforce members. The Security Rule requires security awareness training. There is no prescribed curriculum, duration, or format. That said, effective HIPAA training for pharmacy staff should cover patient rights (access, amendment, accounting of disclosures), minimum necessary standard, proper PHI disposal, workstation security, breach identification and reporting, and your specific pharmacy policies. Online courses work fine, but make sure the content is specific to pharmacy settings - not generic healthcare training. A 20-minute module that covers how to handle a patient who wants to pick up a prescription for their spouse is more valuable than a two-hour lecture on the history of HIPAA legislation. Pro tip: keep a training binder at each pharmacy location with printed completion certificates, sign-in sheets, and training materials. When an auditor asks to see your training records, handing them a complete, organized binder makes a strong first impression. #### Building a Training Calendar That Sticks The biggest training problem we see is not that pharmacies refuse to train - it is that training happens sporadically, is poorly documented, and new hires fall through the cracks. Here is a simple system that works. Create a training matrix spreadsheet with every employee name in rows and every required training topic in columns. In each cell, enter the date of the most recent completion. Color-code the cells: green for current (within 12 months), yellow for expiring within 60 days, and red for expired. Review this matrix on the first of every month. Schedule annual training in two blocks - one in January and one in July. By splitting it into two sessions six months apart, you avoid the year-end scramble and you catch mid-year hires before they drift past their deadlines. For new hires, build a training checklist into your onboarding process. Every new employee should complete HIPAA privacy and security training, FWA training, controlled substance policies review, and pharmacy-specific P&P orientation within their first 90 days - ideally within their first two weeks. Track everything in one place, whether that is a shared spreadsheet, your HR system, or a compliance platform like [Rxperts](/portal/training). The format matters less than the consistency. #### The Shortlist - Audit every employee training file for current HIPAA and FWA completion - Verify new hires from the past 6 months completed all required training within 90 days - Update your training matrix and identify anyone with expired or expiring certifications - Schedule a mid-year training session for topics due for annual renewal - Confirm USP training is current for all compounding staff - Organize training documentation into a presentable format for auditors # Mid-Year Training Check: Is Your Staff Up to Date? September is the perfect time for a mid-year training check. We are past the summer slump, new hires from the busy season are settling in, and there is still enough runway to close any gaps before year-end audits. If training documentation is the weakest part of your compliance program - and for most pharmacies, it is - this newsletter is your action plan. --- ## Regulatory Update: CMS Strengthens FWA Training Requirements for Part D CMS has continued to tighten compliance program requirements for Medicare Part D plan sponsors, and those requirements flow down to network pharmacies. Under current guidance, pharmacies participating in Medicare Part D must ensure that their workforce receives training on Fraud, Waste, and Abuse within 90 days of hire and annually thereafter. This is not optional, and it is not satisfied by a generic orientation session. FWA training must cover the definition of fraud, waste, and abuse in the context of federal healthcare programs, the laws and regulations that address FWA (including the False Claims Act, the Anti-Kickback Statute, and the Stark Law as applicable), how to report suspected FWA through your internal compliance program and to external entities like the OIG and CMS, and the protections available for whistleblowers. If you are a PSAO member, your PSAO may offer FWA training resources. But using a PSAO resource does not relieve you of the responsibility to ensure every workforce member completes the training and that completion is documented. --- ## The Complete Pharmacy Training Requirement Checklist Here is every training topic your pharmacy staff should be current on, broken down by requirement source. **From HIPAA:** Privacy and security awareness training for all workforce members, within a reasonable time after hire and when material changes occur. Best practice is annual refresher training, documented with dates and signatures. **From DEA and state boards:** Controlled substance handling, corresponding responsibility, and PDMP use. Most state boards require continuing education on controlled substance topics as part of license renewal, but your internal training should go beyond CE requirements to cover your specific pharmacy policies. **From CMS (Medicare Part D):** Fraud, Waste, and Abuse training within 90 days of hire and annually. General compliance training covering your compliance program structure, code of conduct, and reporting mechanisms. **From OSHA:** Bloodborne pathogen training if staff may be exposed (pharmacy-based immunization programs), hazard communication training if you handle hazardous drugs, and workplace safety orientation. **From USP (if applicable):** USP 795, 797, and 800 training for pharmacies that compound. This includes initial competency assessments and ongoing training specific to the types of compounding performed. For each topic, you need three things in your training file: the training content or materials used, the date the training was completed, and a signature or electronic acknowledgment from each employee who completed it. Missing any one of these three elements and the training is as good as undocumented. --- ## HIPAA Training: What Actually Counts HIPAA training requirements are more flexible than most people think, but that flexibility is not a license to cut corners. The HIPAA Privacy Rule requires training on your policies and procedures for all workforce members. The Security Rule requires security awareness training. There is no prescribed curriculum, duration, or format. That said, effective HIPAA training for pharmacy staff should cover patient rights (access, amendment, accounting of disclosures), minimum necessary standard, proper PHI disposal, workstation security, breach identification and reporting, and your specific pharmacy policies. Online courses work fine, but make sure the content is specific to pharmacy settings - not generic healthcare training. A 20-minute module that covers how to handle a patient who wants to pick up a prescription for their spouse is more valuable than a two-hour lecture on the history of HIPAA legislation. Pro tip: keep a training binder at each pharmacy location with printed completion certificates, sign-in sheets, and training materials. When an auditor asks to see your training records, handing them a complete, organized binder makes a strong first impression. --- ## Building a Training Calendar That Sticks The biggest training problem we see is not that pharmacies refuse to train - it is that training happens sporadically, is poorly documented, and new hires fall through the cracks. Here is a simple system that works. Create a training matrix spreadsheet with every employee name in rows and every required training topic in columns. In each cell, enter the date of the most recent completion. Color-code the cells: green for current (within 12 months), yellow for expiring within 60 days, and red for expired. Review this matrix on the first of every month. Schedule annual training in two blocks - one in January and one in July. By splitting it into two sessions six months apart, you avoid the year-end scramble and you catch mid-year hires before they drift past their deadlines. For new hires, build a training checklist into your onboarding process. Every new employee should complete HIPAA privacy and security training, FWA training, controlled substance policies review, and pharmacy-specific P&P orientation within their first 90 days - ideally within their first two weeks. Track everything in one place, whether that is a shared spreadsheet, your HR system, or a compliance platform like [Rxperts](/portal/training). The format matters less than the consistency. --- ## Quick Hits - Audit every employee training file for current HIPAA and FWA completion - Verify new hires from the past 6 months completed all required training within 90 days - Update your training matrix and identify anyone with expired or expiring certifications - Schedule a mid-year training session for topics due for annual renewal - Confirm USP training is current for all compounding staff - Organize training documentation into a presentable format for auditors --- Stay compliant. Stay ahead. - The Rxperts Team ### OIG Screening: What Happens When You Skip a Month *Published: 2025-08-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-08-01* Missed OIG screenings can cost you your Medicare contract - real cases inside We get it - OIG exclusion screening feels like one more checkbox in an endless compliance to-do list. But skipping it, even for a month, can have consequences that make every other compliance issue look minor. This month, we are talking about what actually happens when pharmacies fail to screen, with real enforcement examples and a workflow that takes the pain out of the process. #### Regulatory Update: OIG Updates LEIE Database and Screening Guidance The Office of Inspector General updates the List of Excluded Individuals and Entities (LEIE) monthly, and recent additions have included pharmacy technicians, pharmacists, and pharmacy owners. The OIG has also published updated guidance emphasizing that healthcare entities participating in federal healthcare programs must screen all employees and contractors - not just clinical staff - against the LEIE and the GSA System for Award Management (SAM) exclusion database. This means your delivery drivers, your billing staff, your IT contractors, and anyone else who has a role in providing or supporting items or services billed to federal healthcare programs must be screened. If you have been limiting your screening to pharmacists and technicians, expand your scope now. #### What Actually Happens When You Employ an Excluded Individual Here is the part that should get your attention. Under the Civil Monetary Penalties Law, if your pharmacy employs or contracts with an individual or entity excluded from federal healthcare programs, you can face penalties of up to $100,000 for each item or service furnished by the excluded individual and billed to a federal healthcare program. On top of that, you face treble damages (three times the amount claimed) and potential exclusion from federal healthcare programs yourself. That is not a theoretical risk. In one enforcement action, a healthcare provider was required to pay over $150,000 in penalties and damages after employing an excluded individual for just eight months. The provider claimed they did not know the employee was excluded. The OIG response was clear: it is your responsibility to check. The math is straightforward. A pharmacy technician processes dozens of prescriptions per shift. If even a fraction of those are billed to Medicare or Medicaid, and the technician is on the exclusion list, every single one of those claims becomes a potential penalty. A few months of missed screening can turn into millions of dollars in liability. This is not about catching bad actors in your pharmacy. It is about protecting yourself from a liability you did not know existed. People end up on the exclusion list for reasons that may not be obvious - a previous employer's fraud, personal legal issues, licensing problems. Monthly screening catches these situations before they become your problem. #### HIPAA Connection: OIG Screening and Workforce Records When you screen employees against the LEIE and SAM databases, you are handling personal information - names, dates of birth, Social Security Numbers in some cases. This data needs to be protected. Store screening results in secure, access-controlled files. Limit access to your compliance officer or the person responsible for screening. When documenting results, you do not need to retain the full search output for individuals who are not found on the exclusion list - a log entry showing the person screened, the date of screening, the databases checked, and the result (no match found) is sufficient. For any potential matches, retain the full search results and your resolution documentation. If you use a third-party screening service, confirm you have a BAA in place if the service will be accessing or storing any protected health information as part of the screening process. #### Building an OIG Screening Workflow That Actually Works The reason pharmacies skip OIG screening is not that they do not care - it is that the process is manual, time-consuming, and easy to forget. Here is how to fix that. First, designate one person as responsible for monthly screening. This should not be a shared responsibility, because shared responsibility is no responsibility. Assign it, put it in their job description, and hold them accountable. Second, set a recurring calendar event for the first business day of every month. When the reminder fires, the designated person screens every individual on your workforce list against both the LEIE (at oig.hhs.gov) and SAM (at sam.gov). This includes employees, contractors, relief pharmacists, cleaning services - anyone connected to your pharmacy operations. Third, document everything in a screening log. The log should include the date of screening, the name of every individual screened, the databases queried, the result, and the name of the person who performed the screening. Keep this log for at least seven years. Fourth, screen new hires before their start date, not on their first day, not during orientation - before they walk in the door. Or, use a tool that automates all of this. Rxperts includes built-in [OIG screening tools](/portal/oig-screening) that check both LEIE and SAM, flag potential matches, and maintain a complete audit trail. If you are still doing this manually, consider whether the time savings alone justify the switch. #### The Shortlist - Verify your screening scope includes ALL workforce members, not just clinical staff - Check that screenings have been completed every month for the past 12 months - Confirm new hires are screened before their start date - Review your screening log for completeness - dates, names, databases, results - If using a third-party screening service, ensure a BAA is in place - Consider automating your screening process to eliminate missed months # OIG Screening: What Happens When You Skip a Month We get it - OIG exclusion screening feels like one more checkbox in an endless compliance to-do list. But skipping it, even for a month, can have consequences that make every other compliance issue look minor. This month, we are talking about what actually happens when pharmacies fail to screen, with real enforcement examples and a workflow that takes the pain out of the process. --- ## Regulatory Update: OIG Updates LEIE Database and Screening Guidance The Office of Inspector General updates the List of Excluded Individuals and Entities (LEIE) monthly, and recent additions have included pharmacy technicians, pharmacists, and pharmacy owners. The OIG has also published updated guidance emphasizing that healthcare entities participating in federal healthcare programs must screen all employees and contractors - not just clinical staff - against the LEIE and the GSA System for Award Management (SAM) exclusion database. This means your delivery drivers, your billing staff, your IT contractors, and anyone else who has a role in providing or supporting items or services billed to federal healthcare programs must be screened. If you have been limiting your screening to pharmacists and technicians, expand your scope now. --- ## What Actually Happens When You Employ an Excluded Individual Here is the part that should get your attention. Under the Civil Monetary Penalties Law, if your pharmacy employs or contracts with an individual or entity excluded from federal healthcare programs, you can face penalties of up to $100,000 for each item or service furnished by the excluded individual and billed to a federal healthcare program. On top of that, you face treble damages (three times the amount claimed) and potential exclusion from federal healthcare programs yourself. That is not a theoretical risk. In one enforcement action, a healthcare provider was required to pay over $150,000 in penalties and damages after employing an excluded individual for just eight months. The provider claimed they did not know the employee was excluded. The OIG response was clear: it is your responsibility to check. The math is straightforward. A pharmacy technician processes dozens of prescriptions per shift. If even a fraction of those are billed to Medicare or Medicaid, and the technician is on the exclusion list, every single one of those claims becomes a potential penalty. A few months of missed screening can turn into millions of dollars in liability. This is not about catching bad actors in your pharmacy. It is about protecting yourself from a liability you did not know existed. People end up on the exclusion list for reasons that may not be obvious - a previous employer's fraud, personal legal issues, licensing problems. Monthly screening catches these situations before they become your problem. --- ## HIPAA Connection: OIG Screening and Workforce Records When you screen employees against the LEIE and SAM databases, you are handling personal information - names, dates of birth, Social Security Numbers in some cases. This data needs to be protected. Store screening results in secure, access-controlled files. Limit access to your compliance officer or the person responsible for screening. When documenting results, you do not need to retain the full search output for individuals who are not found on the exclusion list - a log entry showing the person screened, the date of screening, the databases checked, and the result (no match found) is sufficient. For any potential matches, retain the full search results and your resolution documentation. If you use a third-party screening service, confirm you have a BAA in place if the service will be accessing or storing any protected health information as part of the screening process. --- ## Building an OIG Screening Workflow That Actually Works The reason pharmacies skip OIG screening is not that they do not care - it is that the process is manual, time-consuming, and easy to forget. Here is how to fix that. **First,** designate one person as responsible for monthly screening. This should not be a shared responsibility, because shared responsibility is no responsibility. Assign it, put it in their job description, and hold them accountable. **Second,** set a recurring calendar event for the first business day of every month. When the reminder fires, the designated person screens every individual on your workforce list against both the LEIE (at oig.hhs.gov) and SAM (at sam.gov). This includes employees, contractors, relief pharmacists, cleaning services - anyone connected to your pharmacy operations. **Third,** document everything in a screening log. The log should include the date of screening, the name of every individual screened, the databases queried, the result, and the name of the person who performed the screening. Keep this log for at least seven years. **Fourth,** screen new hires before their start date, not on their first day, not during orientation - before they walk in the door. Or, use a tool that automates all of this. Rxperts includes built-in [OIG screening tools](/portal/oig-screening) that check both LEIE and SAM, flag potential matches, and maintain a complete audit trail. If you are still doing this manually, consider whether the time savings alone justify the switch. --- ## Quick Hits - Verify your screening scope includes ALL workforce members, not just clinical staff - Check that screenings have been completed every month for the past 12 months - Confirm new hires are screened before their start date - Review your screening log for completeness - dates, names, databases, results - If using a third-party screening service, ensure a BAA is in place - Consider automating your screening process to eliminate missed months --- Stay compliant. Stay ahead. - The Rxperts Team ### DEA Compliance Changes Every Pharmacy Should Know *Published: 2025-07-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-07-01* New DEA rules are live - here is what changed and what to do now DEA compliance is one of those areas where "we have always done it this way" can get you into serious trouble. The regulatory landscape around controlled substances continues to evolve, and the stakes - criminal liability, loss of your DEA registration, pharmacy closure - are as high as they get. This month we are breaking down what has changed, what is coming, and what you should be doing right now. #### Regulatory Update: DEA Tightens PDMP Integration Requirements Prescription Drug Monitoring Programs have been mandatory in every state for years, but DEA is now looking more closely at whether pharmacies are actually using them as intended - not just checking the box. Recent enforcement actions have cited pharmacies for filling controlled substance prescriptions without querying the PDMP when required, or for failing to act on red flags revealed by PDMP data. Most states require a PDMP check before dispensing Schedule II through IV controlled substances, though the specific triggers vary. Some states require a check on every fill, while others only require checks for new patients or new prescriptions. Know your state requirements, and if you are operating in multiple states, know the requirements for each one. Document your PDMP queries. Your pharmacy management system may log these automatically, but verify that the logs are complete and retrievable. If DEA or your state board asks to see proof that you checked the PDMP before filling a specific prescription, you need to be able to produce it. #### Compliance Deep Dive: Corresponding Responsibility in Practice The concept of corresponding responsibility is at the heart of DEA compliance for pharmacists, and it is the area where we see the most confusion. Under 21 CFR 1306.04, a pharmacist has a corresponding responsibility (along with the prescriber) to ensure that a controlled substance prescription is issued for a legitimate medical purpose by a practitioner acting in the usual course of professional practice. What does this look like in practice? It means you cannot simply fill every controlled substance prescription that comes across your counter without exercising professional judgment. Red flags that require further investigation include - but are not limited to - prescriptions from geographically distant prescribers, multiple controlled substance prescriptions from the same prescriber for the same patient, early refill requests, cash payment when the patient has insurance, and combinations of drugs commonly associated with diversion (the "holy trinity" of an opioid, a benzodiazepine, and a muscle relaxant). When you identify a red flag, you must investigate before dispensing. Call the prescriber, check the PDMP, review the patient profile, and document your findings. If you are satisfied that the prescription is legitimate, document why and fill it. If you are not satisfied, you have the right - and the obligation - to refuse to fill it. Document that decision too. The key is documentation. Every red flag identified, every investigation conducted, and every clinical decision made should be recorded in the patient profile. "I felt uncomfortable but filled it anyway" is not a defensible position. Neither is "I did not notice anything unusual" when PDMP data shows the patient is filling controlled substances at five other pharmacies. #### HIPAA Intersection: PDMP Data and Patient Privacy PDMP data creates an interesting intersection between DEA compliance and HIPAA. While PDMP queries are permitted under HIPAA for treatment and healthcare operations purposes, the data you receive from a PDMP check is sensitive and should be treated accordingly. Do not discuss a patient's PDMP results in an area where other patients or staff without a need to know can overhear. Store PDMP printouts (if you print them) in a secure location and shred them when no longer needed. If you share PDMP information with a prescriber as part of a corresponding responsibility investigation, document the disclosure and limit the information to what is necessary for the clinical decision. #### Practical Guide: Controlled Substance Inventory Requirements Your DEA biennial inventory is not just a box-checking exercise - it is a legal document. Here is what DEA requires and what we recommend. The biennial inventory must be conducted every two years from the date of your initial inventory. You choose the date, but once established, the two-year cycle runs from that date. The inventory must include the name, dosage form, and strength of every controlled substance on hand, along with the quantity. For Schedule II substances, you must perform an exact count. For Schedule III through V, an estimated count is permitted unless the container holds more than 1,000 dosage units, in which case an exact count is required. Beyond the biennial, you also need a new inventory whenever there is a change in pharmacist-in-charge, when your pharmacy first opens, and when it permanently closes. If you experience a theft or significant loss, conduct an additional inventory immediately and file a DEA 106 form. We recommend going beyond the minimum. Conduct a full controlled substance inventory quarterly, not just biennially. This makes it much easier to identify discrepancies early and demonstrates a culture of compliance if you are ever investigated. Keep all inventory records for at least two years - though we recommend five years, since that aligns with most state record retention requirements. #### The Shortlist - Verify your PDMP query process is documented and logs are retrievable - Review your corresponding responsibility policy with all pharmacists on staff - Confirm your biennial inventory date and schedule the next one if it is overdue - Audit your red flag documentation process for controlled substance prescriptions - Check that PDMP printouts and data are stored and disposed of securely - Ensure all pharmacists understand their state-specific PDMP query requirements # DEA Compliance Changes Every Pharmacy Should Know DEA compliance is one of those areas where "we have always done it this way" can get you into serious trouble. The regulatory landscape around controlled substances continues to evolve, and the stakes - criminal liability, loss of your DEA registration, pharmacy closure - are as high as they get. This month we are breaking down what has changed, what is coming, and what you should be doing right now. --- ## Regulatory Update: DEA Tightens PDMP Integration Requirements Prescription Drug Monitoring Programs have been mandatory in every state for years, but DEA is now looking more closely at whether pharmacies are actually using them as intended - not just checking the box. Recent enforcement actions have cited pharmacies for filling controlled substance prescriptions without querying the PDMP when required, or for failing to act on red flags revealed by PDMP data. Most states require a PDMP check before dispensing Schedule II through IV controlled substances, though the specific triggers vary. Some states require a check on every fill, while others only require checks for new patients or new prescriptions. Know your state requirements, and if you are operating in multiple states, know the requirements for each one. Document your PDMP queries. Your pharmacy management system may log these automatically, but verify that the logs are complete and retrievable. If DEA or your state board asks to see proof that you checked the PDMP before filling a specific prescription, you need to be able to produce it. --- ## Compliance Deep Dive: Corresponding Responsibility in Practice The concept of corresponding responsibility is at the heart of DEA compliance for pharmacists, and it is the area where we see the most confusion. Under 21 CFR 1306.04, a pharmacist has a corresponding responsibility (along with the prescriber) to ensure that a controlled substance prescription is issued for a legitimate medical purpose by a practitioner acting in the usual course of professional practice. What does this look like in practice? It means you cannot simply fill every controlled substance prescription that comes across your counter without exercising professional judgment. Red flags that require further investigation include - but are not limited to - prescriptions from geographically distant prescribers, multiple controlled substance prescriptions from the same prescriber for the same patient, early refill requests, cash payment when the patient has insurance, and combinations of drugs commonly associated with diversion (the "holy trinity" of an opioid, a benzodiazepine, and a muscle relaxant). When you identify a red flag, you must investigate before dispensing. Call the prescriber, check the PDMP, review the patient profile, and document your findings. If you are satisfied that the prescription is legitimate, document why and fill it. If you are not satisfied, you have the right - and the obligation - to refuse to fill it. Document that decision too. The key is documentation. Every red flag identified, every investigation conducted, and every clinical decision made should be recorded in the patient profile. "I felt uncomfortable but filled it anyway" is not a defensible position. Neither is "I did not notice anything unusual" when PDMP data shows the patient is filling controlled substances at five other pharmacies. --- ## HIPAA Intersection: PDMP Data and Patient Privacy PDMP data creates an interesting intersection between DEA compliance and HIPAA. While PDMP queries are permitted under HIPAA for treatment and healthcare operations purposes, the data you receive from a PDMP check is sensitive and should be treated accordingly. Do not discuss a patient's PDMP results in an area where other patients or staff without a need to know can overhear. Store PDMP printouts (if you print them) in a secure location and shred them when no longer needed. If you share PDMP information with a prescriber as part of a corresponding responsibility investigation, document the disclosure and limit the information to what is necessary for the clinical decision. --- ## Practical Guide: Controlled Substance Inventory Requirements Your DEA biennial inventory is not just a box-checking exercise - it is a legal document. Here is what DEA requires and what we recommend. The biennial inventory must be conducted every two years from the date of your initial inventory. You choose the date, but once established, the two-year cycle runs from that date. The inventory must include the name, dosage form, and strength of every controlled substance on hand, along with the quantity. For Schedule II substances, you must perform an exact count. For Schedule III through V, an estimated count is permitted unless the container holds more than 1,000 dosage units, in which case an exact count is required. Beyond the biennial, you also need a new inventory whenever there is a change in pharmacist-in-charge, when your pharmacy first opens, and when it permanently closes. If you experience a theft or significant loss, conduct an additional inventory immediately and file a DEA 106 form. We recommend going beyond the minimum. Conduct a full controlled substance inventory quarterly, not just biennially. This makes it much easier to identify discrepancies early and demonstrates a culture of compliance if you are ever investigated. Keep all inventory records for at least two years - though we recommend five years, since that aligns with most state record retention requirements. --- ## Quick Hits - Verify your PDMP query process is documented and logs are retrievable - Review your corresponding responsibility policy with all pharmacists on staff - Confirm your biennial inventory date and schedule the next one if it is overdue - Audit your red flag documentation process for controlled substance prescriptions - Check that PDMP printouts and data are stored and disposed of securely - Ensure all pharmacists understand their state-specific PDMP query requirements --- Stay compliant. Stay ahead. - The Rxperts Team ### PBM Audit Season is Here - Are You Ready? *Published: 2025-06-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-06-01* Survive PBM audits with zero recoupments - prep checklist inside PBM audit letters are hitting mailboxes across the country, and if you have not started preparing, today is the day. We have helped pharmacies navigate hundreds of PBM audits, and the pharmacies that come out clean share one thing in common - they prepared before the letter arrived. Here is everything you need to know to get through audit season without writing a check back to a PBM. #### Regulatory Update: FTC Continues PBM Transparency Push The FTC has been turning up the heat on PBM practices, and the latest developments are worth watching. Following the 2024 interim report that highlighted concerns about PBM consolidation, pricing practices, and impacts on independent pharmacies, several states have introduced or passed legislation requiring greater PBM transparency and limiting spread pricing in Medicaid contracts. While these changes will not help you during this audit cycle, they represent a shift in the regulatory landscape that could benefit pharmacies long-term. In the meantime, the best defense remains airtight documentation. If you can prove that every claim you submitted was dispensed as written, with valid prescriptions and proper documentation, recoupment demands become much harder for PBMs to sustain on appeal. #### PBM Audit Prep: Your Complete Documentation Checklist When a PBM audit letter arrives, you typically have 10 to 14 business days to gather and submit documentation. That is not much time if your records are scattered across multiple systems, filing cabinets, and shoebox archives. Here is what you need to have ready for every claim they review. For each prescription: the original hardcopy or electronic prescription, the dispensing record from your pharmacy management system, the signature log showing pickup, any prior authorization documentation, and proof of delivery for mailed prescriptions. For compound prescriptions, you also need the compounding log, ingredient invoices with lot numbers and NDCs, and your master formula record. Compound claims are audited at a much higher rate than finished dosage forms, and the documentation requirements are unforgiving. For prescriptions where you performed a drug utilization review intervention - therapeutic substitution, generic substitution with prescriber approval, quantity adjustments - document the clinical rationale and the prescriber communication. "I called the doctor" is not documentation. A note in the patient profile with the date, time, person spoken to, and outcome is documentation. Start pulling together a sample audit file this week, even if you have not received a letter yet. Pick 20 random claims from the last 90 days and see if you can produce complete documentation for each one. If you find gaps, fix the process now. #### HIPAA Note: Sharing Records with PBM Auditors A question that comes up during every PBM audit: can I share patient records with the PBM auditor without patient consent? The short answer is yes, but with limits. HIPAA permits disclosure of PHI for payment-related activities, which includes responding to a legitimate audit by a PBM with whom you have a contractual relationship. However, you should only share the minimum necessary information to respond to the audit. If the auditor asks for 50 claims, do not send your entire patient file for those 50 patients. Send the prescription records, dispensing logs, and signature logs for the specific claims under review. Keep a log of exactly what you sent, when, and to whom. This protects you if there is ever a question about the scope of the disclosure. #### Common Recoupment Triggers and How to Avoid Them Based on the audits we have seen, here are the top reasons PBMs claw back money from pharmacies. Missing or illegible prescriptions. If you cannot produce the original prescription (hardcopy or electronic), the PBM will recoup the claim. Period. Make sure your prescription image scanning is working and that images are legible. Check your scanner quality monthly. Signature log gaps. If a patient or their representative did not sign for the prescription, many PBMs will treat it as undispensed and demand the money back. Train your staff to get a signature on every pickup, every time. For delivery prescriptions, use a delivery confirmation service that captures a signature or photo proof. Dispensing quantity mismatches. If the claim says 90 tablets but your dispensing record shows 30, that is a recoupment. These usually result from data entry errors or refill-too-soon adjustments that were not properly documented. DAW code errors. Dispensing a brand-name product with a DAW-0 code (no product selection indicated) when the prescriber did not specify brand is a common finding. Make sure your DAW codes accurately reflect what the prescriber ordered and what you dispensed. Get ahead of these issues by running your own internal audit. Our [PBM Audit Prep Guide](/blog/pbm-audit-preparation) walks you through the process step by step. #### The Shortlist - Pull 20 random claims and verify you can produce complete documentation for each - Test your prescription scanner to ensure images are legible and properly archived - Audit your signature logs for gaps - especially delivery and mail-order prescriptions - Review compound prescription records for complete ingredient documentation - Verify DAW codes match prescriber intent across recent dispensing records - Create a PBM audit response folder template so you are ready when the letter arrives # PBM Audit Season is Here - Are You Ready? PBM audit letters are hitting mailboxes across the country, and if you have not started preparing, today is the day. We have helped pharmacies navigate hundreds of PBM audits, and the pharmacies that come out clean share one thing in common - they prepared before the letter arrived. Here is everything you need to know to get through audit season without writing a check back to a PBM. --- ## Regulatory Update: FTC Continues PBM Transparency Push The FTC has been turning up the heat on PBM practices, and the latest developments are worth watching. Following the 2024 interim report that highlighted concerns about PBM consolidation, pricing practices, and impacts on independent pharmacies, several states have introduced or passed legislation requiring greater PBM transparency and limiting spread pricing in Medicaid contracts. While these changes will not help you during this audit cycle, they represent a shift in the regulatory landscape that could benefit pharmacies long-term. In the meantime, the best defense remains airtight documentation. If you can prove that every claim you submitted was dispensed as written, with valid prescriptions and proper documentation, recoupment demands become much harder for PBMs to sustain on appeal. --- ## PBM Audit Prep: Your Complete Documentation Checklist When a PBM audit letter arrives, you typically have 10 to 14 business days to gather and submit documentation. That is not much time if your records are scattered across multiple systems, filing cabinets, and shoebox archives. Here is what you need to have ready for every claim they review. **For each prescription:** the original hardcopy or electronic prescription, the dispensing record from your pharmacy management system, the signature log showing pickup, any prior authorization documentation, and proof of delivery for mailed prescriptions. **For compound prescriptions,** you also need the compounding log, ingredient invoices with lot numbers and NDCs, and your master formula record. Compound claims are audited at a much higher rate than finished dosage forms, and the documentation requirements are unforgiving. **For prescriptions where you performed a drug utilization review intervention** - therapeutic substitution, generic substitution with prescriber approval, quantity adjustments - document the clinical rationale and the prescriber communication. "I called the doctor" is not documentation. A note in the patient profile with the date, time, person spoken to, and outcome is documentation. Start pulling together a sample audit file this week, even if you have not received a letter yet. Pick 20 random claims from the last 90 days and see if you can produce complete documentation for each one. If you find gaps, fix the process now. --- ## HIPAA Note: Sharing Records with PBM Auditors A question that comes up during every PBM audit: can I share patient records with the PBM auditor without patient consent? The short answer is yes, but with limits. HIPAA permits disclosure of PHI for payment-related activities, which includes responding to a legitimate audit by a PBM with whom you have a contractual relationship. However, you should only share the minimum necessary information to respond to the audit. If the auditor asks for 50 claims, do not send your entire patient file for those 50 patients. Send the prescription records, dispensing logs, and signature logs for the specific claims under review. Keep a log of exactly what you sent, when, and to whom. This protects you if there is ever a question about the scope of the disclosure. --- ## Common Recoupment Triggers and How to Avoid Them Based on the audits we have seen, here are the top reasons PBMs claw back money from pharmacies. **Missing or illegible prescriptions.** If you cannot produce the original prescription (hardcopy or electronic), the PBM will recoup the claim. Period. Make sure your prescription image scanning is working and that images are legible. Check your scanner quality monthly. **Signature log gaps.** If a patient or their representative did not sign for the prescription, many PBMs will treat it as undispensed and demand the money back. Train your staff to get a signature on every pickup, every time. For delivery prescriptions, use a delivery confirmation service that captures a signature or photo proof. **Dispensing quantity mismatches.** If the claim says 90 tablets but your dispensing record shows 30, that is a recoupment. These usually result from data entry errors or refill-too-soon adjustments that were not properly documented. **DAW code errors.** Dispensing a brand-name product with a DAW-0 code (no product selection indicated) when the prescriber did not specify brand is a common finding. Make sure your DAW codes accurately reflect what the prescriber ordered and what you dispensed. Get ahead of these issues by running your own internal audit. Our [PBM Audit Prep Guide](/blog/pbm-audit-preparation) walks you through the process step by step. --- ## Quick Hits - Pull 20 random claims and verify you can produce complete documentation for each - Test your prescription scanner to ensure images are legible and properly archived - Audit your signature logs for gaps - especially delivery and mail-order prescriptions - Review compound prescription records for complete ingredient documentation - Verify DAW codes match prescriber intent across recent dispensing records - Create a PBM audit response folder template so you are ready when the letter arrives --- Stay compliant. Stay ahead. - The Rxperts Team ### HIPAA Refresher: Common Pharmacy Privacy Mistakes *Published: 2025-05-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-05-01* These HIPAA slip-ups cost pharmacies thousands - avoid them today Let us talk about HIPAA - specifically, the mistakes we keep seeing pharmacies make over and over. Most of these are not the result of bad intent. They come from outdated training, informal workarounds that became habit, and the daily pressure of running a busy pharmacy. The good news is every one of them is fixable. Here is what to watch for. #### Regulatory Update: OCR Ramps Up Right of Access Enforcement The Office for Civil Rights has been aggressively enforcing the HIPAA Right of Access since 2019, and the pace has not slowed. In the latest round of settlements, OCR fined providers between $15,000 and $240,000 for failing to provide patients with timely access to their records. Pharmacies are not exempt from this. Under HIPAA, when a patient requests their records, you have 30 calendar days to provide them - and that includes prescription records, pharmacy notes, and any other designated record set. Charging unreasonable fees or requiring patients to submit requests in a specific format (like requiring it in writing when they ask verbally) can also trigger a violation. Review your patient access request process this month and make sure every staff member knows the timeline and the rules. #### HIPAA Deep Dive: The 7 Most Common Pharmacy Privacy Mistakes After years of working with pharmacies on HIPAA compliance, these are the violations we see most often. First, discussing patient information in areas where other customers can overhear. Consultation windows, drive-throughs, and open counter areas are the worst offenders. You cannot eliminate all incidental disclosures, but you are required to implement reasonable safeguards - things like lowering your voice, stepping to a private area, or using a consultation room. Second, leaving computer screens visible to patients. If a customer standing at the counter can read another patient's prescription information on your monitor, that is a violation. Screen privacy filters cost less than $30 and take two minutes to install. Third, disposing of PHI in regular trash. Prescription labels, patient profiles, voided scripts, and even the labels from returned-to-stock medications must go in a HIPAA-compliant shredding bin - not the wastebasket under the counter. Fourth, texting patient information on personal phones. This is rampant in pharmacy, and it is a clear violation unless you are using an encrypted, HIPAA-compliant messaging platform. "But it is faster" does not count as a security exception. Fifth, failing to log off workstations. Automatic screen locks should be set to activate after no more than two minutes of inactivity. If your pharmacy software does not support this, your operating system does. Sixth, sharing login credentials. Every user needs their own unique login for your pharmacy management system, your dispensing software, and any system that contains PHI. Shared logins make audit trails meaningless. Seventh, not training temporary or relief staff. If a relief pharmacist or a temp tech works even one shift at your pharmacy, they need to be briefed on your privacy practices and sign an acknowledgment. No exceptions. #### Compliance Tip: Breach Notification Timelines You Need to Know When a breach of unsecured PHI occurs, HIPAA requires notification - but the timelines trip people up. Here is the breakdown. For breaches affecting fewer than 500 individuals, you must notify each affected person without unreasonable delay and no later than 60 calendar days from discovery. You must also log the breach and report it to HHS annually by March 1 of the following year. For breaches affecting 500 or more individuals, the same 60-day individual notification applies, but you must also notify HHS and prominent media outlets serving your state or jurisdiction within that same 60-day window. Discovery does not mean the day you found out about it informally. Under HIPAA, a breach is considered "discovered" on the first day it is known - or should have been known - by any person in your workforce. That means if a pharmacy tech notices something suspicious on a Tuesday and does not report it until the following Monday, your clock started on Tuesday. Document everything. When you discover a potential breach, start a written record immediately: what happened, when you found out, what data was involved, and what steps you took. This documentation is your defense if OCR comes knocking. #### Patient Access Requests: Getting It Right Patients have the right to access their pharmacy records, and most pharmacies handle routine requests without issue. The problems start when the request is unusual - a patient asks for records in electronic format, requests that records be sent to a third party, or asks for records going back several years. You are required to provide records in the format the patient requests if it is readily producible. If a patient asks for their records as a PDF emailed to their personal email, and your system can export a PDF, you need to accommodate that. You can charge a reasonable cost-based fee for labor and supplies, but you cannot charge for search and retrieval time, and you cannot refuse the request because it is inconvenient. Create a simple, written procedure for handling patient access requests and post it where your staff can reference it. Include the 30-day timeline, acceptable formats, fee limits, and who is responsible for fulfilling the request. A clear process prevents most of the errors that lead to OCR complaints. #### The Shortlist - Install privacy screen filters on all patient-facing monitors - Audit your PHI disposal process - no patient information in regular trash - Verify automatic screen locks are set to 2 minutes or less on all workstations - Review your breach notification procedure and ensure all staff know the reporting chain - Confirm every workforce member (including temps) has signed a HIPAA acknowledgment - Check that your patient access request process meets the 30-day deadline # HIPAA Refresher: Common Pharmacy Privacy Mistakes Let us talk about HIPAA - specifically, the mistakes we keep seeing pharmacies make over and over. Most of these are not the result of bad intent. They come from outdated training, informal workarounds that became habit, and the daily pressure of running a busy pharmacy. The good news is every one of them is fixable. Here is what to watch for. --- ## Regulatory Update: OCR Ramps Up Right of Access Enforcement The Office for Civil Rights has been aggressively enforcing the HIPAA Right of Access since 2019, and the pace has not slowed. In the latest round of settlements, OCR fined providers between $15,000 and $240,000 for failing to provide patients with timely access to their records. Pharmacies are not exempt from this. Under HIPAA, when a patient requests their records, you have 30 calendar days to provide them - and that includes prescription records, pharmacy notes, and any other designated record set. Charging unreasonable fees or requiring patients to submit requests in a specific format (like requiring it in writing when they ask verbally) can also trigger a violation. Review your patient access request process this month and make sure every staff member knows the timeline and the rules. --- ## HIPAA Deep Dive: The 7 Most Common Pharmacy Privacy Mistakes After years of working with pharmacies on HIPAA compliance, these are the violations we see most often. **1. Discussing patient information in areas where other customers can overhear.** Consultation windows, drive-throughs, and open counter areas are the worst offenders. You cannot eliminate all incidental disclosures, but you are required to implement reasonable safeguards - things like lowering your voice, stepping to a private area, or using a consultation room. **2. Leaving computer screens visible to patients.** If a customer standing at the counter can read another patient's prescription information on your monitor, that is a violation. Screen privacy filters cost less than $30 and take two minutes to install. **3. Disposing of PHI in regular trash.** Prescription labels, patient profiles, voided scripts, and even the labels from returned-to-stock medications must go in a HIPAA-compliant shredding bin - not the wastebasket under the counter. **4. Texting patient information on personal phones.** This is rampant in pharmacy, and it is a clear violation unless you are using an encrypted, HIPAA-compliant messaging platform. "But it is faster" does not count as a security exception. **5. Failing to log off workstations.** Automatic screen locks should be set to activate after no more than two minutes of inactivity. If your pharmacy software does not support this, your operating system does. **6. Sharing login credentials.** Every user needs their own unique login for your pharmacy management system, your dispensing software, and any system that contains PHI. Shared logins make audit trails meaningless. **7. Not training temporary or relief staff.** If a relief pharmacist or a temp tech works even one shift at your pharmacy, they need to be briefed on your privacy practices and sign an acknowledgment. No exceptions. --- ## Compliance Tip: Breach Notification Timelines You Need to Know When a breach of unsecured PHI occurs, HIPAA requires notification - but the timelines trip people up. Here is the breakdown. For breaches affecting **fewer than 500 individuals**, you must notify each affected person without unreasonable delay and no later than 60 calendar days from discovery. You must also log the breach and report it to HHS annually by March 1 of the following year. For breaches affecting **500 or more individuals**, the same 60-day individual notification applies, but you must also notify HHS and prominent media outlets serving your state or jurisdiction within that same 60-day window. Discovery does not mean the day you found out about it informally. Under HIPAA, a breach is considered "discovered" on the first day it is known - or should have been known - by any person in your workforce. That means if a pharmacy tech notices something suspicious on a Tuesday and does not report it until the following Monday, your clock started on Tuesday. Document everything. When you discover a potential breach, start a written record immediately: what happened, when you found out, what data was involved, and what steps you took. This documentation is your defense if OCR comes knocking. --- ## Patient Access Requests: Getting It Right Patients have the right to access their pharmacy records, and most pharmacies handle routine requests without issue. The problems start when the request is unusual - a patient asks for records in electronic format, requests that records be sent to a third party, or asks for records going back several years. You are required to provide records in the format the patient requests if it is readily producible. If a patient asks for their records as a PDF emailed to their personal email, and your system can export a PDF, you need to accommodate that. You can charge a reasonable cost-based fee for labor and supplies, but you cannot charge for search and retrieval time, and you cannot refuse the request because it is inconvenient. Create a simple, written procedure for handling patient access requests and post it where your staff can reference it. Include the 30-day timeline, acceptable formats, fee limits, and who is responsible for fulfilling the request. A clear process prevents most of the errors that lead to OCR complaints. --- ## Quick Hits - Install privacy screen filters on all patient-facing monitors - Audit your PHI disposal process - no patient information in regular trash - Verify automatic screen locks are set to 2 minutes or less on all workstations - Review your breach notification procedure and ensure all staff know the reporting chain - Confirm every workforce member (including temps) has signed a HIPAA acknowledgment - Check that your patient access request process meets the 30-day deadline --- Stay compliant. Stay ahead. - The Rxperts Team ### New Year Compliance Reset: 5 Things to Fix This Week *Published: 2025-04-01* *URL: https://www.rx-perts.com/newsletter/weekly-compliance-roundup-2025-04-01* Start Q2 right - your compliance quick-win checklist inside Happy Q2, pharmacy friends. If your compliance program has been running on autopilot since January, you are not alone - but this is the perfect week to hit the reset button. We put together five things you can fix right now, no budget approvals needed, that will save you real headaches later this year. #### Regulatory Update: CMS Updates Provider Enrollment Revalidation Timelines CMS recently adjusted revalidation timelines for Medicare-enrolled pharmacies, and the new schedule is catching some operators off guard. If your pharmacy received a revalidation notice in the last 60 days, do not let it sit in your inbox. Missing the deadline can result in deactivation of your Medicare billing privileges - and reactivation is not instant. Check your CMS enrollment record at PECOS to confirm your next revalidation date. If it is coming up, start gathering your updated ownership disclosures, NPI documentation, and state license copies now. The process takes longer than most people expect, especially if there have been any changes to your ownership structure or authorized officials since the last cycle. #### Compliance Tip: 5 Things to Fix This Week Here is your quick-win checklist for Q2. None of these require a consultant or a committee meeting - just someone with 30 minutes and access to your policy binder. 1. Pull your P&P manual and check the "last reviewed" date on every policy. If anything is older than 12 months, update the review date and make any necessary edits. Boards of pharmacy and PBM auditors look at this. 2. Run an OIG and SAM exclusion check on every employee, contractor, and vendor with access to your pharmacy. If you have not done one since January, you are behind. Document the results with dates and screenshots. 3. Verify that your Notice of Privacy Practices is current, posted visibly, and available in the languages your patient population needs. This is a common HIPAA gap that gets flagged during complaint investigations. 4. Review your Business Associate Agreements. If you switched pharmacy software, delivery services, or shredding vendors in the last year, confirm you have a signed BAA on file for each one. No BAA means no compliance - period. 5. Check your training log. Every staff member should have documented HIPAA and Fraud, Waste, and Abuse training within the last 12 months. If anyone is missing, schedule it this week. #### HIPAA Corner: Business Associate Agreements Are Not Optional We still see pharmacies treating BAAs as a nice-to-have. They are not. Under HIPAA, any entity that creates, receives, maintains, or transmits protected health information on your behalf must have a signed BAA in place before they touch a single record. This includes your pharmacy management system vendor, your cloud backup provider, your delivery service (if they access patient names and addresses), your shredding company, your IT support, and yes, even your answering service. If a breach occurs through one of these vendors and you cannot produce a signed BAA, you are on the hook - not just them. Audit your vendor list this week. Make a spreadsheet with three columns: vendor name, does the vendor access PHI, and BAA on file (yes or no). For any vendor where the answer is yes and no, get that agreement signed immediately. Templates are available in your Rxperts document vault under [HIPAA Templates](/portal/documents). #### From the Field: What We Saw in Q1 Audits Across the pharmacies we worked with in Q1, three issues came up more than anything else. First, expired or missing DEA 222 forms for Schedule II orders. If you are still using paper 222s, make sure your supply is current and your voided forms are filed properly. Second, pharmacies could not produce a current inventory of controlled substances when asked. You need a full biennial inventory, plus any additional inventories triggered by theft, loss, or a change in pharmacist-in-charge. Third, we saw multiple pharmacies with outdated emergency contact information posted for the pharmacist-in-charge and the DEA. If your PIC changed and you did not update the posting, fix it today. These are not obscure gotchas - they are bread-and-butter compliance items that regulators check every time. A 15-minute walk-through of your pharmacy with fresh eyes will catch most of them. If you want a structured way to do this, our [Mock Inspection Checklist](/portal/mock-inspection) walks you through every area an inspector would review, so nothing falls through the cracks. #### The Shortlist - Update your P&P manual review dates before the end of the week - Run OIG/SAM exclusion screenings on all staff and document results - Verify BAAs are in place for every vendor with PHI access - Check that your Notice of Privacy Practices is current and posted - Confirm all staff have completed annual HIPAA and FWA training - Review your DEA registrations and ensure posted information is accurate # New Year Compliance Reset: 5 Things to Fix This Week Happy Q2, pharmacy friends. If your compliance program has been running on autopilot since January, you are not alone - but this is the perfect week to hit the reset button. We put together five things you can fix right now, no budget approvals needed, that will save you real headaches later this year. --- ## Regulatory Update: CMS Updates Provider Enrollment Revalidation Timelines CMS recently adjusted revalidation timelines for Medicare-enrolled pharmacies, and the new schedule is catching some operators off guard. If your pharmacy received a revalidation notice in the last 60 days, do not let it sit in your inbox. Missing the deadline can result in deactivation of your Medicare billing privileges - and reactivation is not instant. Check your CMS enrollment record at PECOS to confirm your next revalidation date. If it is coming up, start gathering your updated ownership disclosures, NPI documentation, and state license copies now. The process takes longer than most people expect, especially if there have been any changes to your ownership structure or authorized officials since the last cycle. --- ## Compliance Tip: 5 Things to Fix This Week Here is your quick-win checklist for Q2. None of these require a consultant or a committee meeting - just someone with 30 minutes and access to your policy binder. 1. **Pull your P&P manual** and check the "last reviewed" date on every policy. If anything is older than 12 months, update the review date and make any necessary edits. Boards of pharmacy and PBM auditors look at this. 2. **Run an OIG and SAM exclusion check** on every employee, contractor, and vendor with access to your pharmacy. If you have not done one since January, you are behind. Document the results with dates and screenshots. 3. **Verify your Notice of Privacy Practices** is current, posted visibly, and available in the languages your patient population needs. This is a common HIPAA gap that gets flagged during complaint investigations. 4. **Review your Business Associate Agreements.** If you switched pharmacy software, delivery services, or shredding vendors in the last year, confirm you have a signed BAA on file for each one. No BAA means no compliance - period. 5. **Check your training log.** Every staff member should have documented HIPAA and Fraud, Waste, and Abuse training within the last 12 months. If anyone is missing, schedule it this week. --- ## HIPAA Corner: Business Associate Agreements Are Not Optional We still see pharmacies treating BAAs as a nice-to-have. They are not. Under HIPAA, any entity that creates, receives, maintains, or transmits protected health information on your behalf must have a signed BAA in place before they touch a single record. This includes your pharmacy management system vendor, your cloud backup provider, your delivery service (if they access patient names and addresses), your shredding company, your IT support, and yes, even your answering service. If a breach occurs through one of these vendors and you cannot produce a signed BAA, you are on the hook - not just them. Audit your vendor list this week. Make a spreadsheet with three columns: vendor name, does the vendor access PHI, and BAA on file (yes or no). For any vendor where the answer is yes and no, get that agreement signed immediately. Templates are available in your Rxperts document vault under [HIPAA Templates](/portal/documents). --- ## From the Field: What We Saw in Q1 Audits Across the pharmacies we worked with in Q1, three issues came up more than anything else. First, expired or missing DEA 222 forms for Schedule II orders. If you are still using paper 222s, make sure your supply is current and your voided forms are filed properly. Second, pharmacies could not produce a current inventory of controlled substances when asked. You need a full biennial inventory, plus any additional inventories triggered by theft, loss, or a change in pharmacist-in-charge. Third, we saw multiple pharmacies with outdated emergency contact information posted for the pharmacist-in-charge and the DEA. If your PIC changed and you did not update the posting, fix it today. These are not obscure gotchas - they are bread-and-butter compliance items that regulators check every time. A 15-minute walk-through of your pharmacy with fresh eyes will catch most of them. If you want a structured way to do this, our [Mock Inspection Checklist](/portal/mock-inspection) walks you through every area an inspector would review, so nothing falls through the cracks. --- ## Quick Hits - Update your P&P manual review dates before the end of the week - Run OIG/SAM exclusion screenings on all staff and document results - Verify BAAs are in place for every vendor with PHI access - Check that your Notice of Privacy Practices is current and posted - Confirm all staff have completed annual HIPAA and FWA training - Review your DEA registrations and ensure posted information is accurate --- Stay compliant. Stay ahead. - The Rxperts Team --- ## Pharmacy Compliance Glossary **HIPAA (Health Insurance Portability and Accountability Act)**: A 1996 federal law that, among other things, sets national standards for protecting individuals’ health information. For pharmacies it drives privacy, security, and breach-notification obligations around protected health information (PHI). [https://www.rx-perts.com/glossary/hipaa] **HIPAA Privacy Rule**: The HIPAA regulation that governs how protected health information (PHI) may be used and disclosed, and gives patients rights over their records. Codified at 45 CFR Part 160 and Part 164 (Subparts A and E). [https://www.rx-perts.com/glossary/hipaa-privacy-rule] **HIPAA Security Rule**: The HIPAA regulation that requires administrative, physical, and technical safeguards for electronic protected health information (ePHI). Codified at 45 CFR Part 164 Subpart C. [https://www.rx-perts.com/glossary/hipaa-security-rule] **Breach Notification Rule**: The HIPAA rule requiring covered entities to notify affected individuals, HHS, and sometimes the media after a breach of unsecured protected health information. Codified at 45 CFR §§164.400-414. [https://www.rx-perts.com/glossary/breach-notification-rule] **Fraud, Waste, and Abuse (FWA)**: A category of compliance training and controls required of pharmacies that participate in Medicare Part D, aimed at preventing improper billing, kickbacks, and misuse of program funds. [https://www.rx-perts.com/glossary/fraud-waste-and-abuse] **Office of Inspector General (OIG)**: The HHS Office of Inspector General - the federal office that investigates fraud in HHS programs and maintains the list of individuals and entities excluded from federal health-care programs. [https://www.rx-perts.com/glossary/oig] **List of Excluded Individuals/Entities (LEIE)**: The OIG’s public database of individuals and entities barred from participating in federal health-care programs. Pharmacies screen staff and vendors against it. [https://www.rx-perts.com/glossary/leie] **OIG Exclusion Screening**: The process of checking employees, contractors, and vendors against the OIG LEIE (and often SAM.gov) to confirm none are excluded from federal health-care programs. [https://www.rx-perts.com/glossary/oig-exclusion-screening] **SAM.gov Exclusions (SAM)**: The exclusion records in the federal System for Award Management (SAM.gov), covering parties debarred or excluded from federal contracts and programs - a complement to the OIG LEIE. [https://www.rx-perts.com/glossary/sam-exclusions] **USP Chapter 795 (USP <795>)**: The United States Pharmacopeia general chapter that sets standards for compounding nonsterile preparations (creams, capsules, oral liquids, and similar). [https://www.rx-perts.com/glossary/usp-795] **USP Chapter 797 (USP <797>)**: The USP general chapter governing sterile compounding, including environmental controls, beyond-use dating, and personnel training to prevent contamination. [https://www.rx-perts.com/glossary/usp-797] **USP Chapter 800 (USP <800>)**: The USP general chapter on safe handling of hazardous drugs in health-care settings, protecting workers, patients, and the environment across receipt, storage, compounding, and disposal. [https://www.rx-perts.com/glossary/usp-800] **DEA Form 224**: The DEA application a retail pharmacy uses to register to dispense controlled substances. The resulting registration must be renewed every three years. [https://www.rx-perts.com/glossary/dea-form-224] **Board of Pharmacy (BOP)**: The state agency that licenses pharmacies and pharmacists and inspects them for compliance with state pharmacy law. Requirements vary by state. [https://www.rx-perts.com/glossary/board-of-pharmacy] **Prescription Drug Monitoring Program (PDMP)**: A state-run electronic database that tracks dispensing of controlled substances. Most states require pharmacies to report dispensing data and many require prescribers or pharmacists to check it. [https://www.rx-perts.com/glossary/pdmp] **Pharmacy Benefit Manager (PBM)**: A third-party company that administers prescription drug benefits for health plans - processing claims, setting reimbursement, and contracting with pharmacies through their networks. [https://www.rx-perts.com/glossary/pbm] **PBM Credentialing**: The process of completing and maintaining the applications, documents, and verifications a Pharmacy Benefit Manager requires for a pharmacy to join and stay in its network. [https://www.rx-perts.com/glossary/pbm-credentialing] **Drug Supply Chain Security Act (DSCSA)**: A 2013 federal law (Title II of the Drug Quality and Security Act) that builds an electronic, interoperable system to trace prescription drugs through the U.S. supply chain. [https://www.rx-perts.com/glossary/dscsa] **DIR Fees (Direct and Indirect Remuneration)**: Price concessions and incentive payments in Medicare Part D that adjust a pharmacy’s final reimbursement after the point of sale. Reforms moved these concessions to the point of sale beginning January 1, 2024. [https://www.rx-perts.com/glossary/dir-fees] **Medicare Part D**: The Medicare prescription drug benefit, delivered through private plans. Pharmacies that serve Part D patients must meet the compliance-program expectations CMS places on plan networks. [https://www.rx-perts.com/glossary/medicare-part-d] **Mock Inspection**: A practice run of a regulatory inspection in which a consultant evaluates a pharmacy the way a board or PBM auditor would, then delivers findings and a remediation plan before the real inspection. [https://www.rx-perts.com/glossary/mock-inspection] **Policy and Procedure Manual (P&P Manual)**: The pharmacy’s written set of policies and standard operating procedures covering how it meets federal and state requirements. Inspectors routinely ask to see it. [https://www.rx-perts.com/glossary/policy-and-procedure-manual] **Security Risk Assessment (SRA)**: The documented analysis of risks to electronic protected health information required by the HIPAA Security Rule, together with the measures taken to reduce them. [https://www.rx-perts.com/glossary/security-risk-assessment] **Controlled Substance Schedules**: The five federal schedules (I-V) that classify controlled substances by abuse potential and accepted medical use under the Controlled Substances Act (21 USC 812). [https://www.rx-perts.com/glossary/controlled-substance-schedules] **Compliance Score**: A single, continuously updated measure of how inspection-ready a pharmacy is across its compliance areas - tasks complete, training current, screenings logged, and documents on file. [https://www.rx-perts.com/glossary/compliance-score] *Full glossary: https://www.rx-perts.com/glossary* --- ## Links - Homepage: https://www.rx-perts.com - Pricing: https://www.rx-perts.com/pricing - Mock Inspections: https://www.rx-perts.com/mock-inspection - Book a Demo: https://www.rx-perts.com/book-a-demo - Get a Quote: https://www.rx-perts.com/get-a-quote - Compliance Facts: https://www.rx-perts.com/facts - Glossary: https://www.rx-perts.com/glossary - Blog: https://www.rx-perts.com/blog - Newsletter: https://www.rx-perts.com/newsletter - Privacy: https://www.rx-perts.com/privacy - Terms: https://www.rx-perts.com/terms