Although they sound similar, these two credentials serve different purposes in DrFirst and Rcopia.
1. Signature Password (Used for Electronic Signatures on Non‑Controlled Scripts)
What it is:
The Signature Password is used when electronically signing non‑controlled medication prescriptions or clinical documents within Rcopia.
Purpose:
- Authorizes signature on standard prescriptions (non‑EPCS).
- Provides a security check but is not tied to DEA regulations.
- Signature password is always the provider's first name +"rx" in lower-case letters, e.g.: "joerx"
- Can be disabled in some states. See instructions below.

2. Signing Passphrase (Used for EPCS – Controlled Substances)
What it is:
The Signing Passphrase is the secret phrase a provider enters every time they sign and transmit an EPCS (controlled substance) prescription.
Purpose:
- It is part of DEA‑required two‑factor authentication (2FA).
- It confirms the provider’s identity at the moment of prescribing a controlled substance.
- It is created once, during the EPCS identity‑proofing/registration process.

Important:
- DrFirst and 4D EMR cannot see or recover the passphrase—it is encrypted.
-
The Signing Passphrase is NOT your login password and NOT your regular electronic signature password.
-
It cannot be recovered, only reset.You must have access to your token device/app to perform the reset.
-
Reset Signing Passphrase Instructions
Disable Signature Password
Some states allow the Signature Password to be disabled. It is your responsibility to confirm this is allowed in your state.
- Open a test patient's chart then go to Clinical > ePrescribe
- Click on the menu button located in the top left corner then click Settings

- Click on Preferences
- In the Location menu click on 'Prescription'
- Uncheck the box labled 'Allow a provider to approve a prescription without entering a signature password..'

Help Center