DrFirst Rcopia: Signing Passphrase vs. Signature Password

2 min. readlast update: 08.08.2026

Although they sound similar, these two credentials serve different purposes in DrFirst and Rcopia.


1. Signature Password (Used for Electronic Signatures on Non‑Controlled Scripts)

What it is:
The Signature Password is used when electronically signing non‑controlled medication prescriptions or clinical documents within Rcopia.

Purpose:

  • Authorizes signature on standard prescriptions (non‑EPCS).
  • Provides a security check but is not tied to DEA regulations.
  • Signature password is always the provider's first name +"rx" in lower-case letters, e.g.: "joerx"
  • Can be disabled in some states. See instructions below. 

 

2. Signing Passphrase (Used for EPCS – Controlled Substances)

What it is:
The Signing Passphrase is the secret phrase a provider enters every time they sign and transmit an EPCS (controlled substance) prescription.

Purpose:

  • It is part of DEA‑required two‑factor authentication (2FA).
  • It confirms the provider’s identity at the moment of prescribing a controlled substance.
  • It is created once, during the EPCS identity‑proofing/registration process.

Important:

  • DrFirst and 4D EMR cannot see or recover the passphrase—it is encrypted.
  • The Signing Passphrase is NOT your login password and NOT your regular electronic signature password.
  • It cannot be recovered, only reset.You must have access to your token device/app to perform the reset.

Disable Signature Password

Some states allow the Signature Password to be disabled. It is your responsibility to confirm this is allowed in your state.

  1. Open a test patient's chart then go to Clinical > ePrescribe
  2. Click on the menu button located in the top left corner then click Settings
  3. Click on Preferences
  4. In the Location menu click on 'Prescription' 
  5. Uncheck the box labled 'Allow a provider to approve a prescription without entering a signature password..'

 

Was this article helpful?