How to Enroll for ePrescribe Non-Controlled and Controlled Substances

How to Install the Soft Token VIP App

Before selecting “invite” in the email you may want to install the soft token app.  This app can be installed at any time and does not require you to have started the invite process. It is a free app, and it should have a symbol and screenshot like what you see below.  If it asks you to purchase it, you are using the wrong app.

  1. Go to Google Play or Apple App Store and search for: Symantec VIP Access or VIP Access by Symantec. You should see this symbol with VIP Access next to the app to download. 
  1. Select Get or Download to install the app. When you open the app, you will see a screen as pictured below. 
  2. Notice the Credential ID (with SYMC in front) and the Security Code. You will be required to use these values during the invite process.  The credential ID and security code will be different for everyone and every phone.

NOTE: Dr. First sometimes refers to the Credential ID as S/N.  S/N is not your social security number.  The credential ID is the whole value of SYMCxxxxxxxx with the x being numbers.  The Security Code is also called the One Time Pin (OTP).

Enroll in ePCS

This article is for prescribers that will be prescribing non-controlled and controlled substances.  This process requires the addition of an authenticator “token” to your account.  It is recommended that two tokens be added to a prescribers account, one in the form of a soft token and the other in the form of a hard token.  One will act as a backup if the other gets lost or becomes unusable. 

You’ll receive an email (triggered by your administrator) inviting you to register to e-prescribe.

  1. Click on the email link (Enroll now) to auto-populate information on the screen that appears. Next, click Proceed.

You will need to read and accept the terms of use for both EPCS Gold and InfinID by selecting all checkboxes. Otherwise, you will not be allowed to proceed.

Note: For the next steps you will need:

    • Driver’s License, Passport, or State ID
    • Two-Factor authentication token
    • If you don’t have one, follow instructions on the screen or review Requesting a Hard Token.
    • A smartphone
  1. Click Continue.
  1. Home Address: Please enter the address related to your financial records. This is typically a home address. Please do not input any special characters within the address field.

    Recommended field: Credit Card Number. While this is not required, it is highly recommended as this can increase your chances of passing IDP if you fail the first time. Please enter a personal credit card that is either a VISA or Mastercard. You will NOT be charged; Experian requires only the first 8 digits.

  2. Click Continue

Based on the information you provided, Experian will determine whether you have successfully passed IDP.

Note: If you fail three times, this will lock your account. You cannot attempt IDP again for a full 24 hours.

  • If you successfully pass, continue to step 5.

If Experian cannot validate your information, you may be required to answer 3-4 knowledge-based questions pertaining to your financial history. If Experian can validate your information, then your process will continue without the knowledge-based questions.

  1. If your information is verified by Experian, you’ll see a screen prompting you to scan a QR code with a mobile device. If you’re already on a mobile device, you’ll select Tap here instead.

Before you continue, be sure to copy your temporary session password in case your session times out. If it does time out, go back to your email and select invite.  It should ask you to enter your temporary session password.

If your information was not verified by Experian, you may be asked credit-related questions before proceeding.

  1. Click Let’s Get Started. This indicates your consent to move forward with verifying your identity. This includes taking a photograph of an identification card or passport.
  1. Click to select the type of identification (e.g., ID card) you want to submit for identity proofing.
  1. Click Capture ID Photo.
  2. Click Allow to allow access to your phone camera.
  1. Center the front of your identification on screen and photograph it. Repeat this step with the back of your identification. Continue once you’re satisfied with the photos.
  1. Click Take selfie.
Recommended: Take a photo without glasses.
  1. Click Looks good. Finish application.

The application will prompt you to exit from your mobile screen to go back to the identity proofing screen where you scanned the QR code.

ATTENTION: When the InfinID app tells you to return to your identity proofing workflow to view your results make sure you go back to your computer to continue the process as you still have more steps to complete.  You still need to add your soft token and create your passphrase.

IMPORTANT: Once back on the screen shown below, select the Check Status button. 

  1. You’ll receive an email confirmation that you successfully verified your identity. Otherwise, you will be prompted to retry the process.
    • Note: Please keep this email to use later; otherwise, you may need to restart the whole process.
  1. Next, add an authenticator (“token”) to your account. This token generates a one-time-pin (OTP), which acts as a security code in two-factor authentication for e-prescribing controlled substances.
    • There are 2 main types of authenticators that you can add to your account:
      • Symantec VIP Access app (also called a soft token).
      • Physical device (also called a fob or hard token) manufactured by either Onespan or Symantec.

To add a token, fill out the required fields as they appear on screen:

For our scenario:

    1. Token Manufacturer =  SYMANTEC
    2. Token Issuer = DRFIRST
    3. Token Type = OTP SOFT TOKEN (if using a hard token then choose OTP HARD TOKEN)
    4. Token Nickname = Create a nickname that you will remember.  This is what will show in CalMHSA Rx.
    5. Serial Number or Credential ID = Enter ID found on VIP Access app under Credential ID.  If you have a hard token it is found on the back. Enter only the numbers, exclude any dashes.
      1. If it is a soft token, enter SYMC in front of the numbers and exclude any dashes
      2. If it is a hard token, only enter the numbers with no dashes.
    6. One Time Pin (OTP) = This is found on app or hard token and is called Security Code or six-digit pin.

REMEMBER:  Credential ID= SYMCxxxxxxxx (the xxx… being numbers that are in front of the SYMC with no spaces or hyphens).

  1. To add a token, fill out the required fields as they appear on screen:
  1. Next, create your passphrase, which is the password you’ll use to e-prescribe controlled substances as part of two-factor authentication. It is important that you remember this passphrase. Keep it stored in a secure place.  Take time to think about what you want it to be so that you can remember it. It can be changed if forgotten but if you forget it then you must remember your security question and answer to do so.

    Create a security answer and question which you may use in the future to access your account and recover your passphrase. These fields are case sensitive.

  1. Next, you will receive a verification code via text message or mail. Enter the Code..
      • You will get a text message if Experian verified your mobile phone number. Note: If you didn’t get your text message instantly, click Didn’t receive your code? to try again.
      • You will receive a letter in the mail within 5-7 days if Experian only verified your mailing address or if you were unable to receive a text message.
  2. Click Continue.
  •  

Example of letter:

Note: If you received the verification code after you timed out of your session (either via text or email), use the email link you received from InfinIDAdmin@drfirst.com to enter your verification code. 

  •  If you cannot locate this email, you will need to ask your administrator to send you an invitation to begin the identity proofing and registration process again. 
  • In addition to your verification code, enter your passphrase and a one-time-pin from one of the tokens you registered previously.

When you are done, you will see a confirmation message that you’ve completed identity proofing and enrolled to e-prescribe controlled substances (EPCS).

Contact your administrator so they may complete Logical Access Control (LAC), which is the last step to authorize you to e-prescribe controlled substances.

If you will be e-prescribing controlled substances, you’ll need to contact your administrator after you pass identity proofing and register your authenticator (“tokens”) for two-factor authentication.

Before you can begin e-prescribing controlled substances, your administrator will need to complete Logical Access Control (LAC) to authorize (“activate”) you for EPCS.