Pharmacy Security Audit Checklist 2026: Audit-Ready Guide
Share
Check three things before an inspector or a self-audit deadline arrives: your administrative, physical, and technical safeguards are documented under the HIPAA Security Rule, your controlled-substance records (DEA Form 222/CSOS and Form 106) are pulled and retrievable, and your retention files match the longest applicable rule.
- HIPAA-related documentation must be retained for a minimum of a minimum of several years; DEA records need a minimum of a couple of years.
- Store both under the longer required window if you don’t want to sort files by regulation later.
- Every vendor touching electronic protected health information needs a signed Business Associate Agreement on file, not a verbal understanding.
Inspectors don’t grade intentions. They grade paper trails. A safe that works but has no access log is functionally the same, to an auditor, as no safe at all. If you’re stocking or upgrading secure storage for controlled substances, Safes and Security Solutions carries the burglary and fire-rated units pharmacies use to close that gap.
Key Takeaways
A pharmacy security audit checklist works only when administrative, physical, and technical safeguards are documented with retrievable evidence, not assumed from memory.
| Point | Details |
|---|---|
| Retention alignment | Keep DEA records a minimum of a couple of years and HIPAA documentation a minimum of several years, filing under the longer window when unsure. |
| Controlled-substance paper trail | Have Form 222/CSOS, biennial inventories, and Form 106 filings retrievable before an inspector asks. |
| Sample before you’re sampled | Pull at least 10% of logs and records at random during self-audits to catch gaps early. |
| Vendor oversight | Maintain a signed BAA for every vendor touching ePHI, reassessed annually. |
| Physical controls that hold up | Rated safes with logged access, like those from Safes and Security Solutions, plus tamper-resistant surveillance close the most common inspection gaps. |
Table of Contents
- Pharmacy Security Audit Checklist 2026: One-Page Version
- What Controlled-Substance Records Do Inspectors Check First?
- How Should Pharmacies Secure Safes and Access Points?
- Which Technical Controls Protect ePHI and Dispensing Data?
- What Administrative Documentation Do Auditors Expect?
- How Do You Actually Run a Pharmacy Security Audit?
- What Happens After an Audit Finds Gaps?
- A Supplier’s View on What Actually Fails Inspections
- Where Safes and Security Solutions Fits Into Your Checklist
- Where to Find the Official Rules
- Sources
Pharmacy Security Audit Checklist 2026: One-Page Version
Print this, tape it inside the compliance binder, and update it after every incident or major system change. Group findings into three buckets so a reviewer, whether internal or from the board of pharmacy, can move through the same categories NABP inspectors use.
Administrative
- Documented Security Risk Analysis, dated within the last 12 months, with a named Security Officer.
- Written policy register covering access control, incident response, and sanctions for violations.
- Signed workforce training attestations tied to each safeguard category.
Physical
- Safe access logs showing who opened controlled-substance storage and when.
- Surveillance footage retention schedule with tamper-resistant timestamps.
- Key control ledger noting spare-key custody and re-key events after any breach.
Technical
- Unique user IDs and automatic logoff enabled on every dispensing workstation.
- Encryption at AES-128 or stronger for ePHI at rest and in transit.
- Audit logs centralized and protected from unauthorized edits.
Retention rules differ by document type, and that trips up more pharmacies than any missing lock. DEA-related paperwork, Form 222/CSOS submissions and inventory counts, needs a minimum of a couple of years. HIPAA documentation, including risk analyses and training logs, needs six. Where state pharmacy board rules or DSCSA transaction requirements extend further, follow the longest applicable window and file everything in a single restricted repository rather than splitting it across systems.
CMS’s Pharmacy Self-Audit Checklist runs many detailed steps across prescribing, controlled-substance management, invoicing, and billing, and it’s a useful model for how granular your own evidence list should get: not “we have a safe” but “safe model, location, last service date, and access log attached.”
Pro Tip: Time-stamp and sign every piece of evidence the day you collect it, then lock the file against edits. Auditors trust a version-controlled PDF far more than a spreadsheet someone could have touched last night.
Sample your own records before someone else does. Pull at least a reasonable sample of dispensing logs, access records, and inventory entries at random, and treat any gap the same way an inspector would: as a finding that needs a corrective-action entry, not a shrug.
What Controlled-Substance Records Do Inspectors Check First?
Diversion cases are what make pharmacy security audits so record-heavy, and inspectors know exactly which documents expose a weak inventory system fast. Have these physically or digitally ready before anyone asks:
- Executed DEA Form 222 or CSOS records for every Schedule II order.
- Biennial inventory counts plus perpetual records for Schedule II stock.
- Vendor invoices matched to received quantities.
- Reverse distributor and destruction records for expired or returned controlled substances.
- DEA Form 106 filings for any theft or significant loss, submitted and retained.
| Record Type | Minimum Retention | Where to Store |
|---|---|---|
| DEA Form 222 / CSOS | 2 years | Restricted compliance repository |
| Biennial inventory | 2 years | Same repository, cross-referenced to dispensing logs |
| HIPAA-related documentation | several years | Access-controlled digital archive |
| DSCSA transaction records | Per state/federal requirement, align to longest rule | Integrated with controlled-substance files |
Diversion red flags worth building into a standing checklist:
- Repeated inventory variances on the same drug or same shift.
- Early refill requests clustering around one prescriber or patient.
- Missing or altered Form 222 line items.
- Unexplained gaps between invoice quantities and shelf counts.
Every flagged variance needs a written investigation note and a corrective-action record, even when the explanation turns out to be clerical. An undocumented explanation is, to an auditor, the same as no explanation.
How Should Pharmacies Secure Safes and Access Points?
Physical security is where checklists get vague and inspections get specific. A pharmacy manager can say “we have a safe” and mean almost anything from a filing cabinet with a padlock to a UL-rated burglary and fire unit bolted to the floor. Auditors want the specifics: safe rating, location, tamper-evident seal status, and who holds the spare key.
Build your evidence around these points:
- Safe model, UL burglary/fire rating, and bolt-down or in-floor installation confirmed.
- Spare key custody log with named holders and last-checked date.
- Safe access log recording every open event, not just deposits.
- Unique alarm codes per employee, deactivated immediately on termination.
- Visitor sign-in with escort requirements in controlled areas.
- Re-keying completed and logged within days of any break-in or suspected compromise.
Surveillance coverage needs a map, not just a promise. Every dispensing counter, safe, and entry point should sit inside camera range, with footage retained long enough to support an investigation and stored where the timestamp can’t be edited after the fact. Practical compliance guides recommend keeping a maintenance log for cameras and alarms alongside access logs, since a camera that’s been offline for three weeks is worse than no camera on paper.
Pro Tip: Test your safe’s lock and your camera feed manually once a quarter, and log the test. “It’s probably fine” is not evidence. A dated function check is.

If you’re evaluating what safe works best for controlled substances or want a refresher on when pharmacies legally need a rated safe, those specifics matter more at inspection time than most managers expect.
Which Technical Controls Protect ePHI and Dispensing Data?
Technical safeguards are the part of a pharmacy compliance audit checklist that ages fastest, because encryption standards and access requirements keep tightening. The current HIPAA Security Rule baseline calls for unique user IDs per employee, automatic logoff on idle workstations, and encryption at AES-128 or stronger for ePHI both at rest and in transit. Proposed updates point toward mandatory multi-factor authentication becoming standard, so adopting it now rather than waiting for the mandate saves a scramble later.
Document these controls the same way you’d document a safe: with logs, not assertions.
- Access logs showing who touched dispensing or patient records, retained and protected from tampering.
- Network segmentation separating dispensing systems from general office traffic.
- Role-based access limiting each user to the minimum data needed for their job.
- Backup and recovery procedures tested, not just written.
Vendor oversight belongs here too. Any system touching ePHI, whether it’s your pharmacy management software or a cloud backup provider, needs a signed BAA and a documented annual reassessment. Mapping ePHI data flows and vendor exposure before an audit, rather than during one, is what separates a clean review from a scramble through old contracts.
What Administrative Documentation Do Auditors Expect?
Administrative safeguards are the paperwork spine holding the rest of the audit together, and they’re the category most often treated as a formality until an inspector asks for a specific document by name.
Maintain, at minimum:
- A documented enterprise Security Risk Analysis, refreshed annually and after any major system change.
- A written risk management plan tied to that analysis, not a separate wish list.
- Named Security and Privacy Officers with defined responsibilities.
- An incident response procedure that staff have actually seen and signed.
Security Risk Analysis is an ongoing roadmap, not a one-time checkbox, and vendor BAA gaps show up as a recurring finding across pharmacy audits. Version-control every policy document, restrict edit access to the repository, and set a formal review schedule: annually at minimum, plus an out-of-cycle review any time you change EHR systems, add a vendor, or open a new location.
How Do You Actually Run a Pharmacy Security Audit?
Run it the same way an inspector would, in five steps:
- Define scope: which locations, systems, and record types are in play.
- Assemble evidence: pull policies, logs, and forms into one folder before you start scoring anything.
- Sample records: pull at least a reasonable sample of dispensing logs, access records, and inventory entries at random.
- Test control operation: manually check that safes lock, cameras record, and logoff timers actually fire.
- Score findings: rate each gap by likelihood and impact, not just presence or absence.
Your audit report needs three parts to hold up under review:
- An executive summary stating overall risk level in plain language.
- A risk heat map ranking findings by severity.
- A corrective-action template listing each gap, the owner, the fix, and a verification date.
What Happens After an Audit Finds Gaps?
Rank fixes by likelihood times impact, not by which one is easiest to close first. A missing BAA on a low-use vendor can wait a week; an unlogged safe with controlled substances inside cannot.
- Log every corrective action with an owner, a deadline, and evidence of completion (a signed log, a screenshot, a dated photo).
- Track fixes against a simple monitoring KPI, like percentage of open findings closed within 30 days.
- Verify each fix closes the loop: re-check the control, don’t just check the box.
Pro Tip: Set a quarterly progress check on open corrective actions and a full annual re-audit, plus an out-of-cycle review any time you change vendors, systems, or locations.
A Supplier’s View on What Actually Fails Inspections
We hear the same complaint every inspection season: the safe was fine, the cameras were fine, but nobody could produce the log fast enough. Auditors reward speed of proof as much as the control itself. A tamper-evident seal that nobody photographed is a weaker answer than a clearly labeled folder someone can hand over in minutes.
Run a mock inspection twice a year, from the inspector’s seat, not the manager’s. Build a binder or shared portal that any on-duty lead could produce cold, with licenses, logs, and BAAs already sorted by category.

Where Safes and Security Solutions Fits Into Your Checklist
Most of the physical-security gaps this checklist surfaces come down to one problem: the storage equipment doesn’t match what an inspector expects to see. A locked drawer isn’t a rated safe. A dead camera isn’t a surveillance log.

Safes and Security Solutions carries the hardware that closes those specific gaps. For controlled-substance storage, the American Security BFS2214 Burglary and Fire Safe gives you a UL-rated, bolt-down option sized for daily dispensing volume, while smaller locations can look at the American Security BFS912 Burglary and Fire Safe for a compact footprint without dropping the burglary rating. Pair either with a tamper-resistant surveillance system covering the safe and dispensing counter, and you’ve addressed two of the physical-security line items an inspector checks first.
Browse specs, weight, and fire ratings on the product pages, then request installation guidance so the unit is bolted and logged correctly from day one.
Where to Find the Official Rules
- HHS: HIPAA Security Rule guidance
- USC EHS: Controlled substances inventory guidance
- CMS: Pharmacy Self-Audit Checklist
- NABP: Multistate Inspection Blueprint
Keep these links in your audit binder and flag which sections informed each remediation decision.
Sources
- USC EHS: Controlled substances inventory guidance
- HHS: HIPAA Security Rule guidance
- CMS: Pharmacy Self-Audit Checklist (PDF)
- NABP: Inspections and Multistate Inspection Blueprint
- AccountableHQ: Pharmacy Compliance Guide 2026