Ohio PDMP (OARRS) Data Retention for EPCS Pharmacies: Caching Controlled Substance Histories
OARRS Data Reporting Requirements
What you must report and when
As an Ohio dispenser, you must report every outpatient dispensing of reportable drugs to OARRS within one day (24 hours) of the date dispensed. If no reportable dispensing occurs on a given day, you must file a zero report for that day. These timelines apply to pharmacies and to prescribers who personally furnish medications for use outside the facility. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/oarrs/faq))
Corrections or reversals to data already uploaded must be submitted through the PMP Clearinghouse Data Upload account, which handles file corrections on behalf of the Board. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/oarrs/faq))
Scope of drugs captured
OARRS tracks controlled substances and certain dangerous drugs designated by rule. For example, specified naltrexone products used to treat alcohol dependence or prevent opioid relapse must be reported when dispensed to an outpatient. ([codes.ohio.gov](https://codes.ohio.gov/ohio-administrative-code/chapter-4729%3A8-2?utm_source=openai))
Integration with Electronic Prescribing Systems
How PDMP data appears in your EHR or pharmacy platform
Ohio offers integrated access to OARRS directly inside many EHRs and pharmacy dispensing systems via PMP Gateway (Bamboo Health). The Board covers ongoing maintenance fees for prescribers and pharmacists, enabling in-workflow retrieval of a patient’s prescription history without leaving your core system. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/Oarrs/SoftwareIntegration?utm_source=openai))
Provider Authorization and identity matching
To use integrated access, each request must map to a valid, active OARRS account. PMP Gateway enforces Provider Authorization by verifying identifiers (e.g., DEA, NPI, and/or state license) against the user’s OARRS profile to ensure only authorized users can access PDMP data. ([pmpgateway.zendesk.com](https://pmpgateway.zendesk.com/hc/en-us/articles/9570473319955-OH-Board-of-Pharmacy-enabling-Provider-Authorization?utm_source=openai))
EPCS and message standards
For Electronic Prescribing of Controlled Substances, your e-prescribing network uses NCPDP SCRIPT standards. CMS has announced a transition to SCRIPT version 2023011 for Medicare Part D beginning January 1, 2028, so EPCS pharmacies should align upgrade roadmaps accordingly. ([cms.gov](https://www.cms.gov/medicare/regulations-guidance/electronic-prescribing/adopted-standard-and-transactions?utm_source=openai))
Data Retention Policies for Controlled Substances
State retention of PDMP data
Under Ohio law, OARRS retains collected drug database information for at least five years and may keep identifiable patient information longer when necessary for investigatory or public health purposes. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/section-4729.82?utm_source=openai))
Local caching in EPCS and pharmacy systems
Ohio does not set a specific retention period for locally cached OARRS reports. The Board permits keeping a copy but advises consulting counsel to ensure your storage approach aligns with other applicable requirements (e.g., HIPAA, payer rules). As a compliance anchor, treat any copy you place in the patient record as a pharmacy record subject to state retention rules. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/oarrs/faq))
How long to keep related records
- Pharmacy records under Ohio Administrative Code: retain for three years in a readily retrievable manner (applies when an OARRS report becomes part of the patient record). ([codes.ohio.gov](https://codes.ohio.gov/ohio-administrative-code/rule-4729%3A5-5-03?utm_source=openai))
- DEA recordkeeping for controlled substances: at least two years (federal minimum). ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2015-title21-vol9/pdf/CFR-2015-title21-vol9-part1304-subjectgroup-id105.pdf?utm_source=openai))
- Ohio Medicaid claims documentation: six years from date of payment (payer rule, not PDMP). ([codes.state.oh.us](https://codes.state.oh.us/ohio-administrative-code/rule-5160-9-06?utm_source=openai))
Best practice for “pharmacy data caching policies” is to minimize local storage and implement automatic purging (for example, short-lived caches of 24–72 hours for operational speed, with any long-term retention occurring only in the designated medical/pharmacy record). This approach supports PDMP data retention compliance while reducing breach exposure.
Access Controls and User Authorization
Account ownership, delegates, and permitted purpose
Your OARRS account is for your use only—never share credentials. When appropriate, set up delegates who access reports on your behalf under your supervision. Access is restricted to treatment or other purposes authorized by Ohio law; running reports outside those purposes is prohibited. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/oarrs/faq))
Integrated access governance
With integration, Provider Authorization verifies each user’s license, NPI, and/or DEA against their OARRS profile, blocking mismatches and reducing risk of unauthorized access. Maintain individual user credentials, role-based permissions, and regular audits to align with “prescription history access protocols.” ([pmpgateway.zendesk.com](https://pmpgateway.zendesk.com/hc/en-us/articles/9570473319955-OH-Board-of-Pharmacy-enabling-Provider-Authorization?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Legal and Compliance Considerations
Who may receive OARRS information and when
Authorized recipients and disclosure conditions are set by Ohio Revised Code 4729.80. Use of OARRS data is limited to defined purposes such as patient care and specified investigations; each request is logged by the Board. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/section-4729.80?utm_source=openai))
Consequences of misuse
Unauthorized access, use, or disclosure can trigger Board action and potential criminal or civil penalties under Ohio’s penalty provisions. Guard your credentials, supervise delegates, and document your purpose for each query. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/section-4729.99?utm_source=openai))
Data Security and Confidentiality Measures
Safeguards to put in place
Ohio rules reinforce confidentiality of patient records. In practice, apply least‑privilege access, encrypt PDMP data in transit and at rest, log every query, and implement rapid revocation for offboarded users. Audit caching locations to ensure protected health information is not duplicated unnecessarily and is disposed of on schedule. ([law.cornell.edu](https://www.law.cornell.edu/regulations/ohio/Ohio-Admin-Code-4729-5-3-05?utm_source=openai))
Role of OARRS in Controlled Substance Monitoring
Supporting clinical decisions and diversion prevention
OARRS is Ohio’s PDMP, created to monitor misuse and diversion and to inform safer prescribing and dispensing—integrating with care workflows to support controlled substance abuse prevention. The Board also tracks certain additional data, including medical marijuana sales, which dispensaries must report rapidly after sale. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/chapter-4729?utm_source=openai))
Interstate data sharing
OARRS participates in multi‑state data exchange via PMPi, allowing authorized Ohio users to see prescription activity from numerous partner states when clinically relevant. This broader view strengthens clinical review and helps detect patterns that cross state borders. ([pdmpassist.org](https://www.pdmpassist.org/pdf/state_summaries/Ohio_Summary_Profile.pdf))
FAQs.
What are Ohio's reporting deadlines for controlled substances?
You must report each outpatient dispensing to OARRS within one day (24 hours) of the dispense; if nothing is dispensed, submit a daily zero report. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/oarrs/faq))
How does OARRS integrate with electronic prescribing systems?
Through PMP Gateway, OARRS embeds directly into many EHR and pharmacy systems. Ohio’s Provider Authorization ensures the user’s identifiers match an active OARRS account. For EPCS workflows, maintain compliance with evolving NCPDP SCRIPT standards on your e‑prescribing network. ([pharmacy.ohio.gov](https://www.pharmacy.ohio.gov/Oarrs/SoftwareIntegration?utm_source=openai))
What legal risks exist for unauthorized OARRS data access?
Using OARRS for non‑authorized purposes, sharing credentials, or disclosing reports outside allowed channels can result in Board discipline and potential criminal or civil penalties under Ohio law. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/section-4729.80?utm_source=openai))
How long must pharmacies retain cached controlled substance histories?
Ohio sets no fixed period for locally cached OARRS reports. OARRS itself retains database information at least five years. If you store an OARRS report in the patient record, follow Ohio pharmacy record retention (generally three years), while DEA requires two years for federal controlled‑substance records; Medicaid claims records carry a six‑year retention from date of payment. Many pharmacies therefore minimize caching and purge quickly, keeping any long‑term copies only within the designated record. ([codes.ohio.gov](https://codes.ohio.gov/ohio-revised-code/section-4729.82?utm_source=openai))
Table of Contents
- OARRS Data Reporting Requirements
- Integration with Electronic Prescribing Systems
- Data Retention Policies for Controlled Substances
- Access Controls and User Authorization
- Legal and Compliance Considerations
- Data Security and Confidentiality Measures
- Role of OARRS in Controlled Substance Monitoring
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.