Florida Administrative Code (Last Updated: October 28, 2024) |
61. Department of Business and Professional Regulation |
61N. Drugs, Devices and Cosmetics |
61N-1. Regulations For Drugs, Devices And Cosmetics |
61N-1.025. Certification Authority and Digital Signatures for Self-Authenticating Electronic Pedigree
1(1) As used in this rule chapter the terms “certificate” and “Certification Authority” are as defined by Section 19668.003, F.S. 21(2005). The department will list on its website one or more companies authorized to serve as a Certification Authority to issue digital certificates to persons for purposes of certifying via a digital signature the accuracy and completeness of a pedigree paper for authentication purposes under sub-subparagraph 6761N-1.013(5)(d)1.f., 68F.A.C. The department recognizes that a Certification Authority listed on the department’s website may revoke any digital certificate it has issued. In addition, the department recognizes that the certificate holder and the employer of the certificate holder may also seek revocation of a certificate, for example because of termination of the holder’s employment or change of the holder’s authority to sign a pedigree for the employing establishment.
135(2) The department will list on its website a Certification Authority that requests in writing to the bureau that it be so listed, if the request demonstrates:
162(a) The Certification Authority meets the requirements set forth in the Federal Government Bridge Certification Authority Certificate Policy (FBCA CP), of the federal General Services Administration for “medium assurance” certificates, or comparable requirements.
195(b) The Certification Authority will issue two types of certificates the status of which is ascertainable within the digital signature. One type of certificate will indicate that the person to whom the digital signature is issued signs on behalf of a company that is lawfully permitted in Florida to engage in the unrestricted wholesale distribution of a prescription drug in or into Florida. The other type of certificate will indicate that the person to whom the digital signature is issued signs on behalf of a company that is not lawfully permitted in Florida but is lawfully permitted in its resident state to engage in the wholesale distribution of prescription drugs, or is licensed in Florida under a restricted distributor permit.
315(c) The Certification Authority requires at a minimum the following written documentation prior to granting a digital certificate to the person requesting a digital signature to sign an electronic pedigree:
3451. Authorization from the establishment for whom the person is requesting a digital certificate that that person may sign pedigree papers on the establishment’s behalf,
3702. A valid, unexpired identification document which bears a photograph of the person requesting a digital certificate such as:
389a. A passport issued by the United States, an immigration document issued by the Federal Government, or any document issued by an agency of the Federal Government or the Armed Services of the United States,
424b. A passport issued by a foreign government if the passport includes or is accompanied by a document proving that the alien is lawfully in the United States, or
453c. A document issued by a state or political subdivision if the issuing state or political subdivision prohibits the issuance of the identification document to an alien who is unlawfully in the United States, and the state or political subdivision requires independent verification of the records offered by the person to prove identity when applying for the identification document.
5123.a. A copy of the state issued permit for the company’s name and address for whom the person is requesting a digital certificate demonstrating authorization by the state of Florida to engage in the unrestricted wholesale distribution of prescription drugs in or into Florida, or
557b. A copy of the state issued permit or license for the company’s name and address for whom the person is requesting a digital certificate demonstrating authorization by the state in which the company resides to engage in the wholesale distribution of prescription drugs, or demonstrating authorization by the state of Florida to engage in the wholesale distribution of prescription drugs under a restricted distributor permit.
623(d) The Certification Authority shall submit to the department a statement from an independent auditor confirming that the Certification Authority complies with the requirements of this rule and the applicable provisions of subparagraph 65661N-1.013(5)(d)1., 657F.A.C., so that a recipient of a pedigree signed with a digital signature issued by the Certification Authority can rely on the integrity of the digital signature.
684(3) To remain listed as a Certification Authority on the department’s website, the Certification Authority must submit a signed statement certifying to the department on an annual basis that it operates in accordance with the requirements of this section and has been audited by a qualified independent (from the operator of the Certification Authority) auditor on at least an annual basis. The Certification Authority must also submit a signed statement from an independent auditor that the Certification Authority complies with the requirements of this rule and the applicable provisions of sub-subparagraph 77561N-1.013(5)(d)1.f., 776F.A.C. This documentation must be submitted to the department by June 1 of each year in order to remain listed on the department’s website as a Certification Authority for the next July 1 – June 30 period.
813(4) If a Certification Authority proposes comparable requirements to the FBCA CP “medium assurance” certificates, the Certification Authority must provide a detailed crosswalk between the standards set forth for the FBCA CP “medium assurance” certificates and the proposed comparable requirements with a detailed explanation describing how the comparable requirements provide at least the same level of assurance as the FBCA CP standards.
875(5) If any of the requirements in the FBCA CP differ from those set forth in this rule, the ones set forth in this rule shall prevail.
902(6) If authorized by the affected establishments that lawfully purchase or receive prescription drugs to digitally sign their electronic pedigrees, an employee may be issued digital certificates for each such establishment or for multiple permits of a single establishment.
941(7)(a) The loss, theft, or compromise of a private key or password must be communicated to the Certification Authority within 24 hours of discovery of the key’s loss, theft, or compromise. Notification should promptly result in a request for revocation of the Certificate holder’s digital certificate and must include sufficient information to uniquely identify the certificate holder. Revocation shall be effective upon issuance of the next Certificate Revocation List.
1010(b) During the lifetime of the certificate, the Certificate Authority must for each certificate issued verify the license status has not been suspended, revoked, or otherwise inactivated for the wholesale distribution of prescription drugs. The Certificate Authority must perform this check at least weekly. If it is found the license status has been suspended, revoked, or otherwise inactivated, then the Certificate Authority must issue a certificate revocation for all certificates issued effective the date of the license change.
1088(8) Either the certificate holder or the establishment shall request revocation of a certificate holder’s digital certificate upon termination of the certificate holder’s authorization to make digital signatures on behalf of the establishment. Notification should promptly request revocation of the certificate holder’s digital certificate and must include sufficient information to uniquely identify the certificate holder. Revocation shall be effective upon issuance of the next Certificate Revocation List.
1155(9) The establishment is ultimately responsible for electronic pedigrees that have been digitally signed on its behalf.
1172(10) Until a Certification Authority can submit the audit required in paragraph (2)(d) or June 30, 2007, whichever is earlier, the Department will 1195provisionally list a Certification Authority requesting to be listed on the Department’s website www.myfloridalicense.com as a Certification Authority, provided that the Certification authority submits the audit required by paragraph (2)(d) by June 15, 2007, and otherwise operates in accordance with the requirements of this rule. A digital certification issued by a provisionally listed Certification 1249Authority must expire and be revoked on or before June 30, 2007. Any provisionally listed Certification Authority that has not submitted the audit required in paragraph (2)(d) by June 15, 2007, will be removed from the provisional list and may not operate as a Certification Authority under this section. Upon submission of the audit required by paragraph (2)(d), the Certification Authority will be listed without the provisional designation. Upon removal of the provisional designation, a Certification Authority must reissue all existing digital certificates.
1332Rulemaking Authority 1334499.003, 1335499.0121, 1336499.0122, 499.013, 499.014, 1339499.05 FS. 1341Law Implemented 1343499.003, 1344499.012, 1345499.0121, 1346499.0122, 499.013, 499.014, 1349499.051, 1350499.052 FS. 1352History–New 8-6-06, Amended 9-5-07, Formerly 135764F-12.025.