Skip to content
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA

DoseSpot Integration for Telehealth Platforms: What It Covers and What It Requires

DoseSpot integration connects telehealth platforms with e-prescribing workflows, EPCS, Surescripts, pharmacy benefit checks, and HIPAA requirements. Understand the BAA chain, integration options, controlled substance safeguards, and technical decisions before development begins.

DoseSpot Integration for Telehealth Platforms: What It Covers and What It Requires
Qrolic Health Technical Team.
5 min read
DoseSpot
Telehealth Platform
E-Prescribing
EPCS
Surescripts
HIPAA
BAA
Healthcare Architecture
Table of Content

Healthcare Compliance Guide

Reviewed and updated for the latest developments in healthcare compliance guide and related healthcare compliance standards.

Adding e-prescribing to a telehealth platform is more than connecting a prescription form to an external service. Your architecture must account for controlled substance prescribing, prescriber authentication, pharmacy transmission, HIPAA obligations, and the contractual relationships between vendors.

DoseSpot integration for telehealth platforms can provide these capabilities through embedded or API-based approaches. The right implementation depends on how much prescribing functionality you want to control inside your own application.

The DEA's Electronic Prescriptions for Controlled Substances requirements also introduce specific safeguards when controlled substances are prescribed electronically. Identity proofing, two-factor authentication, access controls, and electronic signing must fit the clinical workflow rather than sit outside it.

This distinction matters when you are building a telehealth product for the US market and deciding how deeply e-prescribing should be integrated.

What DoseSpot actually provides for a telehealth platform

DoseSpot can provide the e-prescribing layer within a broader telehealth application, allowing your platform to connect prescribing workflows with patient and provider experiences.

The integration decision should start with the clinical workflow you want to support. A simple embedded prescribing experience has different architectural requirements from a fully customised prescribing interface.

For organisations planning broader telehealth platform development, e-prescribing should be treated as part of the clinical workflow architecture rather than an isolated feature.

During healthcare implementations, the practical question is usually how much prescribing should feel native to the platform and how much functionality can remain within the e-prescribing provider's interface.

Prescription creation and clinical workflow

Prescription creation is the core workflow connecting the prescriber to the medication and pharmacy process.

A telehealth platform may need to provide patient selection, medication selection, dosage information, directions, pharmacy selection, prescription review, and final signing.

The application should also make the prescribing state clear. Drafting, reviewing, signing, and transmitting a prescription are distinct actions and should not appear as one undifferentiated button.

For controlled substances, the prescriber must affirmatively review the prescription before signing. The DEA Diversion Control Division states that the prescribing practitioner remains responsible for ensuring the prescription conforms to applicable requirements.

That means your interface should make the final review step clear rather than hiding it behind an automated workflow.

Prescription history and medication reconciliation

Medication history can support clinical decision-making by giving authorised users access to relevant medication information.

For a telehealth platform, that data may need to appear alongside consultation notes, allergies, diagnoses, and other clinical information.

The architecture should define which system remains authoritative for each data element. Otherwise, your application can create conflicting medication information between the telehealth platform and e-prescribing system.

Medication reconciliation also needs appropriate access controls. Not every application user should automatically receive access to every medication record available through an integration.

Pharmacy benefit management checks at the point of prescribing

Pharmacy benefit information can help providers understand coverage and cost information before transmitting a prescription.

DoseSpot describes pharmacy benefit checks as part of its prescribing workflow, allowing relevant information to be surfaced during the prescribing process.

The practical value comes from placing that information at the right point in the workflow. If the provider has already completed the prescription and selected a pharmacy, late-stage benefit information can create unnecessary rework.

Design the workflow so coverage information supports the prescribing decision without making the clinical interface unnecessarily complex.

Prescribing controlled substances without EPCS in place?

Controlled substance prescribing introduces requirements that ordinary e-prescribing workflows do not cover. Confirm the EPCS capability, identity proofing process, access controls, and applicable state requirements before committing the workflow to production.

Talk to our telehealth integration team →

EPCS and controlled substance prescribing through DoseSpot

Electronic Prescribing of Controlled Substances, or EPCS, introduces additional requirements beyond ordinary electronic prescribing.

The DEA's 2010 Interim Final Rule established the federal framework permitting electronic prescribing of controlled substances through applications that satisfy the applicable requirements.

DEA guidance also makes clear that EPCS remains subject to state, local, and other applicable requirements. State rules can therefore affect how your telehealth platform operates across different jurisdictions.

The key implementation question is whether your e-prescribing architecture supports the required controls at the moment a controlled substance is signed.

What DEA EPCS certification actually requires

A controlled substance prescription cannot simply follow the same technical path as an ordinary electronic prescription.

The DEA requires the electronic prescribing application to satisfy applicable requirements under 21 CFR Part 1311. Application compliance must be established through an approved audit or certification process.

DoseSpot states that its platform supports EPCS and uses multi-factor authentication for electronic prescribing of controlled substances.

Your responsibility does not end with selecting an EPCS-capable vendor. Your telehealth application still needs to implement the integration correctly and ensure authorised prescribers use the required workflow.

Identity proofing and two factor authentication for prescribers

DEA requirements include identity proofing for practitioners who receive authentication credentials used for EPCS.

The authentication credential must use two factors from distinct categories, such as something the practitioner knows, possesses, or is.

The important implementation detail is that two-factor authentication applies specifically to the controlled substance signing process. It is not simply another login screen.

DEA guidance also requires logical access controls that restrict the ability to sign controlled substance prescriptions to authorised individuals.

Based on our healthcare IT experience, EPCS workflows work best when identity proofing and signing requirements are designed around the provider's existing clinical workflow rather than added after the portal is complete.

Why most states now require EPCS for controlled substances

Federal DEA rules permit electronic prescribing when the applicable requirements are met, but state requirements can impose additional obligations.

Exostar's overview of EPCS reports that most US states now mandate electronic prescribing for controlled substances.

For a telehealth platform operating across multiple states, this makes jurisdictional review an important part of the product scope. A platform cannot assume that one prescribing workflow automatically satisfies every state requirement.

Your implementation team should therefore establish the states where prescribing will occur before finalising the EPCS workflow.

For broader context, see our guide to HIPAA compliance for telehealth platforms.

Did You Know ?

DoseSpot integration for telehealth platforms provides prescription creation, EPCS controlled substance prescribing, Surescripts network transmission, and pharmacy benefit checks through API or embedded workflows. It requires appropriate contractual and HIPAA arrangements, while connecting your platform to prescribing, pharmacy, and clinical data workflows.

How prescriptions actually reach the pharmacy: the Surescripts network

DoseSpot and Surescripts have different roles in the prescribing chain.

DoseSpot provides the e-prescribing technology and workflow. Surescripts operates the network through which eligible prescription transactions can be routed to participating pharmacies.

Understanding that distinction helps when troubleshooting failed transmissions. A prescription can be correctly created within your platform while still encountering an issue later in the network or pharmacy workflow.

RxHere provides relevant context for prescription workflow architecture, where pharmacy operations and electronic prescription handling must connect reliably with the broader healthcare platform.

DoseSpot's role versus Surescripts' role in transmission

DoseSpot's documentation states that its prescribing platform can send electronic prescriptions to pharmacies on the Surescripts network.

Surescripts provides the network infrastructure that connects participating healthcare organisations and pharmacies.

For an API-based implementation, certification requirements can also apply to the client workflow. DoseSpot states that API-only users may need separate Surescripts routing certification when handling prescription workflows within their own interface.

That distinction matters when comparing an embedded implementation with a fully customised API experience.

What happens between your platform and the dispensing pharmacy

A simplified prescription flow looks like this:

  1. 1.The provider selects or creates the prescription within the telehealth platform.
  2. 2.The prescription passes through the DoseSpot integration.
  3. 3.Applicable EPCS controls are completed when a controlled substance is prescribed.
  4. 4.The prescription is routed through the appropriate Surescripts workflow.
  5. 5.The receiving pharmacy processes the prescription through its own systems.
  6. 6.The dispensing process continues according to the pharmacy's requirements.

Your platform should provide appropriate status handling around these steps. A user should be able to distinguish between a prescription being prepared, signed, transmitted, rejected, or otherwise requiring attention.

That status model becomes especially important when providers prescribe during time-sensitive telehealth encounters.

The BAA chain your platform is responsible for

Prescription data can contain protected health information, so the contractual structure around your vendors matters.

DoseSpot publishes a Business Associate Agreement for covered entities and a Sub-Business Associate Agreement for business associates using DoseSpot as a vendor.

Across recent compliance projects, confirming the BAA relationship before e-prescribing went live helped ensure that the technical integration and contractual arrangement were considered together.

A BAA does not make an application automatically HIPAA compliant. Your platform remains responsible for its own safeguards, configuration, access controls, and operational processes.

For a deeper explanation, see what a Business Associate Agreement actually covers.

Platform to DoseSpot, the first link

If your telehealth organisation is a covered entity and DoseSpot handles PHI on your behalf, the relationship needs an appropriate Business Associate Agreement.

DoseSpot's published BAA identifies PRN Software LLC, doing business as DoseSpot, as the business associate and describes obligations concerning PHI.

The practical step is to confirm the agreement before production access to patient or prescribing information begins.

Contract review should also identify what information crosses the integration boundary. That helps your technical team align data flows with the agreed services.

DoseSpot to Surescripts, and why this is not your platform's direct responsibility

The relationship between DoseSpot and Surescripts is distinct from your organisation's direct relationship with DoseSpot.

DoseSpot's published contractual documentation describes Surescripts requirements and a separate relationship governing network access.

That does not mean your organisation can ignore the downstream chain. Your agreement with DoseSpot should make clear how the relevant downstream services are handled and what responsibilities flow back to your organisation.

The technical architecture and vendor contract should tell the same story.

Surescripts to pharmacy, where the chain typically ends

The Surescripts network connects prescription transactions with participating pharmacies.

Once the prescription reaches the pharmacy, additional pharmacy-side processes determine how it is received and dispensed.

Your platform therefore should not represent a successful API response as proof that a medication has been dispensed. Transmission and dispensing are separate operational events.

Clear status handling can prevent providers and patients from treating transmission confirmation as confirmation of pharmacy fulfilment.

What breaks when 1 link in this chain is missing

A missing contractual or operational link can create uncertainty around who is permitted to handle PHI and how the information is protected.

DoseSpot's published documentation includes both a BAA and Sub-Business Associate Agreement, illustrating that downstream relationships can require their own contractual treatment.

The practical safeguard is to map every organisation that receives, maintains, transmits, or otherwise handles PHI through the prescribing workflow.

Your legal, compliance, and engineering teams should review that map together before launch.

HIPAA obligations specific to controlled substance prescribing

Controlled substance prescribing creates a concentrated security and audit requirement because the workflow involves identifiable patients, prescribing practitioners, medication information, and legally significant signing actions.

Your HIPAA architecture must cover the entire prescribing journey, not only the API connection to DoseSpot.

A useful implementation approach is to map each event from provider authentication through prescription transmission and identify what is recorded, who can access it, and where the information is stored.

For a broader reference point, see the HIPAA compliance overview.

Audit trail and record retention requirements

The DEA requires electronic prescribing applications to maintain records associated with controlled substance prescriptions.

DEA guidance states that the application must be capable of generating a prescribing history for practitioners covering at least the preceding 2 years, with the information sortable by patient name, drug name, and date of issuance.

DEA guidance also requires the application to digitally sign and archive required prescription information when the controlled substance prescription is signed.

These requirements make auditability a core architecture concern.

Your implementation should therefore establish clear ownership of prescription records and ensure that required records are available through the appropriate system.

Access control differences for controlled versus non controlled prescriptions

Controlled substance prescribing requires more specific access controls than ordinary prescription workflows.

DEA guidance requires application access controls that restrict controlled substance signing privileges to authorised individuals. The access list must also be maintained when prescribers join, leave, or otherwise lose prescribing authority.

That creates an operational requirement beyond initial configuration.

Provider onboarding and offboarding should therefore include EPCS permissions as a defined step rather than treating prescribing access as a permanent application role.

Integration architecture: iFrame embed vs API integration

DoseSpot offers different integration approaches, including an embedded interface and a more deeply customised API model.

The decision is primarily about control. An embedded workflow can reduce the amount of prescribing UI your team has to build, while a full API approach provides greater control over the experience.

During healthcare implementations, the right choice has depended less on technical preference and more on whether prescribing needs to feel native to the platform's primary clinical workflow.

What an iFrame embed gets you quickly

DoseSpot's JumpStart integration can be embedded through an iFrame, object, or web control.

This approach allows a telehealth platform to incorporate a prescribing interface without rebuilding every prescribing screen internally.

It can make sense when your priority is getting a supported prescribing workflow into the application while keeping the e-prescribing interface primarily within DoseSpot's experience.

The tradeoff is control. Your team has less ownership over the detailed prescribing interface than with a fully native implementation.

What a full API integration requires and enables

A full API integration gives your team much greater control over the prescribing experience.

DoseSpot states that its Full Integration offering provides more than 250 API calls and supports custom e-prescribing screens and workflows.

That flexibility also increases your implementation responsibility. Your team must design the prescribing interface, manage the relevant application states, handle integration errors, support certification requirements, and ensure the workflow remains aligned with applicable prescribing rules.

A custom UI should therefore be selected because the product requires it, not simply because the APIs are available.

How Herexa Health approached this tradeoff

Herexa Health is a useful example of how healthcare platforms can require a deeper integration strategy than a basic patient-facing website.

The platform brought together patient onboarding, medical intake, clinical review, treatment management, provider operations, consultation management, and e-prescribing workflows.

For that type of product, integration architecture needs to account for how prescribing fits into the complete clinical journey.

You can review our Herexa Health case study for additional context on the platform architecture and healthcare workflow requirements.

Qrolic Health perspective

Qrolic Health works on healthcare platforms where e-prescribing is part of a wider patient and provider workflow.

Our approach is to establish the prescribing requirements first, then map the required DoseSpot capabilities, EPCS controls, data flows, contractual relationships, and user experience.

That helps prevent a common implementation problem, where the e-prescribing vendor is selected first and the platform architecture is forced around the vendor's workflow later.

Conclusion

DoseSpot integration for telehealth platforms should be evaluated as part of the complete prescribing architecture, not as a simple API connection.

The right implementation must account for prescription creation, medication data, pharmacy benefit checks, EPCS requirements, prescriber identity proofing, access controls, Surescripts transmission, and the contractual chain around PHI.

Your choice between an embedded interface and full API integration also affects development responsibility. An embedded approach can reduce custom UI work, while a full API implementation gives your team greater control over the prescribing experience.

For organisations entering the US telehealth market, state prescribing requirements add another layer that should be addressed during product planning.

The strongest implementation starts with the clinical workflow, then works backwards into vendor capability, security, compliance, and integration architecture.

Build the e-prescribing layer around your actual telehealth workflow

A missing BAA relationship, incomplete EPCS workflow, or poorly scoped API integration can create problems after development has already started. Define the prescribing architecture before those decisions become expensive to change.

Talk to our telehealth integration team →

Frequently Asked Questions

Does DoseSpot require a separate BAA from Surescripts?

Your direct BAA relationship will depend on how your organisation and vendors handle PHI. DoseSpot publishes its own BAA and downstream contractual documentation covering its relationship with Surescripts and other parties.

Can DoseSpot be used to prescribe controlled substances?

Yes. DoseSpot states that its platform supports EPCS. Prescribers still need the applicable identity proofing, two-factor authentication, access controls, and other requirements before controlled substance prescriptions can be electronically signed.

What is the difference between DoseSpot's iFrame and API integration?

An iFrame or embedded approach lets your platform incorporate DoseSpot's prescribing interface with less custom UI development. A full API integration gives your team greater control over screens, workflows, and the prescribing experience.

Is DoseSpot HIPAA compliant?

DoseSpot publishes a Business Associate Agreement and describes safeguards for handling PHI. However, using a vendor with HIPAA-related safeguards does not make your complete telehealth platform compliant automatically. Your implementation and operational controls remain important.

Does every telehealth platform need EPCS capability?

Only platforms that prescribe controlled substances need EPCS capability for that workflow. However, state requirements can mandate electronic prescribing for controlled substances, so the applicable jurisdictions should be established before product requirements are finalised.

What happens if a link in the BAA chain is missing?

An incomplete contractual chain can create uncertainty about authorised PHI handling and vendor responsibilities. Map each party that handles prescription information and confirm the appropriate agreement before production data moves through the workflow.

Does DoseSpot handle pharmacy benefit checks automatically?

DoseSpot describes pharmacy benefit checks as part of its prescribing workflow. The practical implementation depends on the selected integration and available functionality, so your team should confirm the required benefit workflow during technical scoping.

How long does DoseSpot integration typically take?

The timeline depends on integration depth, certification requirements, and project scope. An embedded approach generally involves less custom prescribing UI work, while a full API implementation requires considerably more application development and integration planning.

Qrolic Health Technical Team.

Qrolic Health Technical Team.

Updated for 2026 Compliance Guidance.
Qrolic Health - Healthcare Website Design Specialists

Qrolic Health works on telehealth platforms where e-prescribing, patient workflows, clinical integrations, and healthcare security requirements must operate together.

Qrolic Health - Healthcare Website Design Specialists

Ready to Build Your Healthcare Platform?

Work with a team that understands HIPAA, accessibility, and healthcare digital experiences from day one.

Service we offer:
HIPAA-Compliant Websites
Healthcare Website Design
Telehealth Platforms
Website Redesign & Migration
Healthcare SEO