NAPLEX Quiz: Regulations And Regulatory Bodies
20 questions · exam conditions
0:00
Regulations And Regulatory BodiesQuestion 1 of 20

A pharmacist receives an electronic prescription for hydrocodone/acetaminophen (a Schedule II controlled substance) with a note from the prescriber: "Please dispense early; patient traveling." The pharmacist also notices the patient has filled similar prescriptions at multiple pharmacies in the last month based on the state prescription drug monitoring program (PDMP). Under the pharmacist's corresponding responsibility and DEA expectations for preventing diversion, how should the pharmacist handle this regulatory compliance concern?

Dispense as written because a Schedule II electronic prescription is legally valid and the prescriber requested an early fill
Refuse to dispense and report the prescriber to the FDA because early fills are prohibited by FDA labeling
Assess for red flags (including PDMP findings), contact the prescriber to resolve concerns, document the due diligence performed, and only dispense if the prescription is issued for a legitimate medical purpose
Dispense a partial fill without contacting the prescriber because partial fills eliminate diversion risk and require no additional documentation
← Back to quizzes

NAPLEX Quiz

NAPLEX Quiz: Regulations And Regulatory Bodies

Practice Regulations And Regulatory Bodies in NAPLEX with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Regulations And Regulatory Bodies, giving you a quick way to practice the rules, question types, and explanations that matter most for NAPLEX.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

A pharmacist receives an electronic prescription for hydrocodone/acetaminophen (a Schedule II controlled substance) with a note from the prescriber: "Please dispense early; patient traveling." The pharmacist also notices the patient has filled similar prescriptions at multiple pharmacies in the last month based on the state prescription drug monitoring program (PDMP). Under the pharmacist's corresponding responsibility and DEA expectations for preventing diversion, how should the pharmacist handle this regulatory compliance concern?

  1. Dispense as written because a Schedule II electronic prescription is legally valid and the prescriber requested an early fill
  2. Refuse to dispense and report the prescriber to the FDA because early fills are prohibited by FDA labeling
  3. Assess for red flags (including PDMP findings), contact the prescriber to resolve concerns, document the due diligence performed, and only dispense if the prescription is issued for a legitimate medical purpose (correct answer)
  4. Dispense a partial fill without contacting the prescriber because partial fills eliminate diversion risk and require no additional documentation

Explanation: This question tests understanding of the pharmacist's corresponding responsibility under DEA regulations. Pharmacists share responsibility with prescribers for ensuring controlled substances are dispensed only for legitimate medical purposes, requiring due diligence when red flags are present. Assessing red flags, contacting the prescriber, and documenting due diligence (Answer C) is correct because it fulfills the pharmacist's corresponding responsibility by investigating concerning patterns and ensuring legitimate use before dispensing. Answer A is incorrect because electronic validity alone doesn't override the duty to investigate red flags. Answer B is incorrect because this is a DEA compliance issue, not FDA, and refusal without investigation doesn't meet corresponding responsibility requirements. Answer D is incorrect because partial fills don't eliminate the need to verify legitimate medical purpose and require specific documentation. The compliance framework includes: review PDMP data, identify red flags, contact prescriber to resolve concerns, document all due diligence efforts, and make informed dispensing decisions based on professional judgment.

Question 2

In a high-volume community pharmacy, the pharmacist is counseling a patient on a new antidepressant at the pick-up counter while other patients are within earshot. A technician suggests speaking louder to move the line faster. Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, which action best ensures compliance while still providing appropriate counseling?

  1. Provide counseling at the counter but avoid using the patient's name; this is sufficient to prevent disclosure of protected health information.
  2. Move the consultation to a semi-private counseling area or lower voice and offer written information, using reasonable safeguards to limit incidental disclosures. (correct answer)
  3. Refuse to counsel unless the patient signs a HIPAA authorization permitting discussion in public.
  4. Ask the patient to discuss medication details only after leaving the pharmacy to avoid any possible disclosure.

Explanation: This question tests compliance with the HIPAA Privacy Rule regarding incidental disclosures during patient counseling in a pharmacy setting. The key regulatory requirement is that pharmacies must implement reasonable safeguards to protect protected health information (PHI) from unauthorized disclosure, while still permitting necessary communications for treatment and operations. Choice B is the best action because it employs practical measures like moving to a semi-private area, lowering voice volume, and providing written materials to minimize incidental disclosures without refusing counseling. Choice A is incorrect as avoiding the patient's name alone does not sufficiently safeguard PHI, and choice C is wrong because HIPAA does not require authorization for routine counseling, potentially denying patient care. Choice D is misguided as it shifts responsibility to the patient and avoids providing immediate counseling, contrary to pharmacy practice standards. A transferable strategy for HIPAA compliance involves assessing the environment for privacy risks and using layered safeguards such as physical barriers, quiet speech, and alternative communication methods. For complex scenarios, key steps include identifying potential disclosures, evaluating minimum necessary information, implementing safeguards, and documenting any incidents.

Question 3

A pharmacist at a retail pharmacy receives a voicemail from a prescriber's office after hours authorizing a refill for alprazolam (a Schedule IV controlled substance) with 5 additional refills. The original prescription is 4 months old, and the patient is requesting an early refill due to "lost medication." Under DEA rules for Schedule III–V controlled substances, what is the most appropriate way to document and process this refill authorization?

  1. Process the refill and document "OK to refill" in the patient profile without recording the caller's name because it came from the prescriber's office
  2. Treat the voicemail as a new prescription and dispense immediately, since Schedule IV prescriptions can be phoned in and refilled up to 12 times
  3. Document the date/time, prescriber, medication details, number of refills authorized, and the identity of the caller (if known), and ensure the total refills do not exceed 5 within 6 months from the issue date before dispensing (correct answer)
  4. Deny all refills because controlled substances cannot be refilled once the prescription is older than 90 days

Explanation: This question tests knowledge of DEA requirements for documenting and processing controlled substance refill authorizations. DEA regulations permit Schedule III-V prescriptions to be refilled up to 5 times within 6 months of the issue date, with specific documentation requirements for each refill. Documenting all required information and verifying refill limits (Answer C) is correct because it ensures compliance with DEA recordkeeping requirements and refill limitations. Answer A is incorrect because all refill authorizations require complete documentation including the caller's identity. Answer B is incorrect because this is a refill authorization, not a new prescription, and Schedule IV prescriptions are limited to 5 refills, not 12. Answer D is incorrect because Schedule IV prescriptions remain valid for refills up to 6 months from the issue date, not 90 days. The compliance strategy requires: verify prescription validity period, confirm refill limits not exceeded, document all required information, address any red flags like early refills, and maintain complete records.

Question 4

At an independent community pharmacy, a patient calls and reports severe hives and shortness of breath shortly after taking the first dose of a newly dispensed antibiotic. The pharmacist advises the patient to seek emergency care and wants to report the event. Which action best follows the appropriate process for reporting this adverse event to the Food and Drug Administration (FDA) through MedWatch?

  1. Report the event to the DEA because it involves a medication-related harm and the DEA tracks patient safety events
  2. Submit a MedWatch report (FDA Form 3500/3500B) with relevant clinical details and product information, even if all information is not yet available (correct answer)
  3. Wait to report until the prescriber confirms causality and provides a written statement linking the antibiotic to the reaction
  4. Document the event only in the pharmacy's internal log because MedWatch is limited to manufacturers and prescribers

Explanation: This question tests understanding of FDA MedWatch adverse event reporting requirements and procedures. The FDA encourages healthcare professionals to report serious adverse events through the MedWatch program to support post-market surveillance and patient safety. Submitting a MedWatch report with available information (Answer B) is correct because FDA accepts and encourages voluntary reports from healthcare professionals even when complete information is not yet available. Answer A is incorrect because DEA handles controlled substance issues, not general adverse event reporting. Answer C is incorrect because MedWatch reports do not require confirmed causality - suspected associations are reportable. Answer D is incorrect because healthcare professionals, including pharmacists, can and should submit MedWatch reports directly. The compliance framework includes: recognize reportable events, gather available information, submit reports promptly even with incomplete data, follow up with additional information as available, and maintain documentation of reports submitted.

Question 5

A compounding pharmacy is preparing a nonsterile omeprazole oral suspension from bulk ingredients for a pediatric patient because a commercially available product is not suitable. The pharmacist is training a new technician who plans to compound it on the same counter used for counting tablets, without documenting the formulation or beyond-use date. Under United States Pharmacopeia (USP) standards for nonsterile compounding (USP <795>), how should the pharmacist respond to ensure compliance?

  1. Allow compounding on the counting counter if it is wiped with alcohol afterward; documentation is optional for nonsterile preparations
  2. Require a designated compounding area with appropriate cleaning procedures and complete a compounding record that includes ingredients, calculations, and an assigned beyond-use date consistent with USP <795> (correct answer)
  3. Use USP <797> as the primary standard and assign a beyond-use date based only on sterile compounding risk level
  4. Proceed without a compounding record as long as the prescriber provides written confirmation that the preparation is medically necessary

Explanation: This question tests knowledge of USP <795> standards for nonsterile pharmaceutical compounding. USP <795> requires designated compounding areas with appropriate environmental controls and comprehensive documentation for all compounded preparations. Requiring a designated area with proper documentation including beyond-use dating (Answer B) is correct because USP <795> mandates specific facility requirements and complete compounding records for quality assurance. Answer A is incorrect because USP <795> requires designated compounding areas separate from dispensing activities and mandatory documentation. Answer C is incorrect because USP <797> applies to sterile compounding, not nonsterile preparations. Answer D is incorrect because compounding records are required regardless of medical necessity. The compliance framework includes: designate appropriate compounding areas, follow cleaning and environmental procedures, create comprehensive compounding records, assign appropriate beyond-use dates based on USP guidelines, and maintain quality assurance documentation.

Question 6

A specialty pharmacy receives a new prescription for isotretinoin for a 17-year-old patient, and the prescriber notes that therapy must start today. The pharmacist sees the patient has not completed the required iPLEDGE steps and there is no documentation of current program authorization in the pharmacy system. Under the Food and Drug Administration (FDA)-mandated Risk Evaluation and Mitigation Strategy (REMS) for isotretinoin, how should the pharmacist handle this situation to remain compliant?

  1. Dispense a 3-day emergency supply and complete REMS documentation after the patient starts therapy
  2. Dispense the prescription if the prescriber's note indicates REMS requirements were met, even without pharmacy verification
  3. Verify the patient and prescriber are authorized and all REMS requirements are met in iPLEDGE before dispensing; if not met, do not dispense and coordinate completion of required steps (correct answer)
  4. Dispense only if the patient signs a HIPAA authorization allowing the pharmacy to share information with the REMS program

Explanation: This question tests understanding of FDA-mandated REMS requirements for isotretinoin under the iPLEDGE program. The iPLEDGE REMS requires verification that both prescriber and patient are authorized in the system and all program requirements are met before dispensing can occur. Verifying authorization and ensuring all REMS requirements are met before dispensing (Answer C) is the only compliant approach because iPLEDGE has strict verification requirements that cannot be bypassed. Answer A is incorrect because emergency supplies are not permitted under iPLEDGE - the system requires real-time verification. Answer B is incorrect because the pharmacy must independently verify REMS compliance, not rely solely on prescriber notes. Answer D is incorrect because HIPAA authorization is separate from REMS requirements and does not address the compliance issue. The compliance framework for REMS medications requires: verify program enrollment, confirm all requirements are met, document verification, and only dispense when fully compliant.

Question 7

In a long-term care pharmacy, a nurse requests a resident's full medication list be faxed to a non-affiliated physical therapy clinic to "help with treatment planning." The patient has not provided authorization. Under HIPAA, how should the pharmacist handle this request?

  1. Fax the full list because treatment-related requests never require any limitations or verification.
  2. Decline unless a permitted disclosure applies and verify the requestor and minimum necessary information; otherwise obtain appropriate patient authorization before sending. (correct answer)
  3. Send the list after removing the patient's name; this fully de-identifies the information.
  4. Send the list only if the nurse signs a statement accepting responsibility for HIPAA compliance.

Explanation: This question examines HIPAA Privacy Rule for disclosing protected health information (PHI) to external providers without authorization. The key requirement allows disclosures for treatment if the recipient is a covered entity, but pharmacies must verify the requestor, ensure minimum necessary information, and confirm it's permitted; otherwise, authorization is needed. Choice B is appropriate as it emphasizes verification and permitted purposes, protecting PHI while facilitating care. Choice A is incorrect because even treatment requests require minimum necessary limits and verification, and choice C is wrong as removing the name does not fully de-identify PHI. Choice D is misguided since responsibility lies with the disclosing pharmacy, not the recipient. A transferable HIPAA strategy involves a verification checklist for all disclosure requests. For complex requests, steps include confirming the purpose, verifying identity, redacting unnecessary data, and documenting the disclosure.

Question 8

A pharmacist is preparing to transfer Schedule III–V prescription information to another pharmacy at a patient's request. The receiving pharmacy asks for a verbal transfer. Under typical controlled substance transfer rules, what is the most appropriate way to document this activity?

  1. Document the transfer with required details (date, receiving pharmacy information, pharmacist names/initials, and prescription information) and note it on both pharmacies' records as required. (correct answer)
  2. Transfer verbally without documentation because documentation is only required for Schedule II prescriptions.
  3. Send the original hard copy to the other pharmacy and delete the electronic record to prevent duplication.
  4. Transfer only if the patient signs a HIPAA authorization; transfers are not permitted under routine pharmacy operations.

Explanation: This question tests controlled substance transfer rules under the DEA for Schedules III-V. The key requirement is documenting transfers with details like date, pharmacies involved, pharmacist identifiers, and prescription data on both ends to maintain accountability. Choice A is best as it ensures complete records, preventing duplication and aiding audits. Choice B is incorrect because documentation is required for all controlled transfers, not just Schedule II, and choice C is wrong as sending originals risks loss and violates electronic rules. Choice D is misguided since transfers are operational and do not need HIPAA authorization. A transferable strategy is to use transfer logs integrated into pharmacy software. For transfers, steps include verifying patient request, exchanging details verbally or electronically, documenting fully, and marking the original as transferred.

Question 9

A prescriber calls in a prescription for hydrocodone/acetaminophen to a community pharmacy. The intern takes the call but forgets to record the prescriber's DEA number on the hard copy. Under federal controlled substance rules, what is the most appropriate way to document this prescription before dispensing?

  1. Dispense as written because the prescriber called it in; DEA numbers are only required for Schedule II prescriptions.
  2. Contact the prescriber (or authorized agent) to obtain the missing required information and document the clarification per pharmacy policy before dispensing. (correct answer)
  3. Add the prescriber's DEA number from a previous prescription on file without contacting the prescriber to save time.
  4. Ask the patient to provide the prescriber's DEA number and document it as patient-supplied information.

Explanation: This question assesses federal controlled substance rules for documenting phoned-in prescriptions, particularly for Schedule II drugs like hydrocodone/acetaminophen. The key requirement under the Controlled Substances Act is that prescriptions must include the prescriber's DEA number, and missing elements must be obtained from the prescriber or agent before dispensing. Choice B is best as it involves contacting the prescriber to verify and document the DEA number, ensuring prescription validity and preventing errors. Choice A is incorrect because DEA numbers are required for all controlled substance prescriptions, not just Schedule II, and choice C is wrong as pharmacists cannot add information without verification, risking forgery claims. Choice D is inappropriate since patients cannot supply prescriber details, violating documentation rules. A transferable strategy is to verify all required elements on controlled substance prescriptions through direct prescriber contact. For complex cases, steps include identifying missing data, contacting the prescriber, documenting clarifications, and retaining records for audits.

Question 10

A pharmacist discovers that a patient received double the intended dose of metoprolol due to a dispensing error. The patient experienced dizziness and sought urgent care. The pharmacy wants to report this adverse event to the FDA MedWatch program. How should the pharmacist handle medication error reporting to MedWatch?

  1. Report the event to MedWatch using the appropriate voluntary reporting form, including relevant details while protecting patient identifiers as required. (correct answer)
  2. Report only to the DEA because MedWatch is limited to controlled substance adverse events.
  3. Do not report because medication errors are handled only by the state board of pharmacy and never by the FDA.
  4. Report to MedWatch only if the prescriber requests it; pharmacists are not permitted to submit MedWatch reports.

Explanation: This question addresses FDA MedWatch reporting for medication errors causing adverse events. The key guideline is that healthcare professionals should voluntarily report serious errors via MedWatch Form 3500, including details while de-identifying patient information to improve safety. Choice A is correct as it follows the process for reporting errors that led to patient harm, contributing to FDA surveillance. Choice B is wrong because MedWatch covers all drugs, not just controlled substances, and DEA handles diversion, not errors. Choice C is incorrect as the FDA encourages MedWatch reporting alongside state requirements, and choice D is misguided since pharmacists can submit reports independently. A transferable strategy is to integrate error reporting into quality assurance programs. For complex events, steps include gathering facts, assessing severity, submitting the report, and implementing preventive measures.

Question 11

A pharmacist is asked to dispense a medication that has a boxed warning and is also under an FDA REMS program requiring dispensing only in certain healthcare settings. The prescriber sends the prescription to a retail pharmacy that is not an approved site. What is the potential consequence of dispensing without meeting REMS distribution requirements?

  1. No consequence, because REMS programs are recommendations and not enforceable requirements.
  2. Potential patient harm and regulatory action, including noncompliance findings and possible restrictions on dispensing REMS medications or other enforcement actions. (correct answer)
  3. Only a HIPAA violation because REMS is part of patient privacy law.
  4. Only a USP <795> violation because REMS is a compounding standard.

Explanation: This question tests the understanding of FDA Risk Evaluation and Mitigation Strategies (REMS) programs, which are designed to manage known or potential serious risks associated with certain medications. The key regulatory requirement is that REMS programs are enforceable by the FDA and may restrict medication distribution to specific healthcare settings, certified prescribers, or pharmacies to ensure safe use. The correct answer, B, is the best choice because dispensing without meeting REMS requirements can lead to patient harm due to unmitigated risks and trigger FDA enforcement actions, such as noncompliance citations, restrictions on handling REMS drugs, or other penalties. Choice A is incorrect because REMS elements are mandatory and enforceable, not mere recommendations, which is a common misconception among those unfamiliar with FDA oversight. Choices C and D are wrong as REMS is unrelated to HIPAA privacy rules or USP <795> compounding standards, respectively, highlighting the importance of distinguishing between different regulatory frameworks. To ensure compliance with REMS, pharmacists should verify the program's specific requirements, such as enrollment or certification, before dispensing. A transferable strategy is to always consult the FDA REMS database and product labeling to confirm restrictions and maintain documentation of compliance efforts.

Question 12

A hospital outpatient pharmacy dispenses clozapine and the pharmacist is aware it has an FDA REMS program requiring specific monitoring and documentation. The prescriber's office requests that the pharmacy bypass REMS checks because the patient is stable. What is the pharmacist's primary responsibility under the clozapine REMS requirements?

  1. Dispense if the prescriber attests verbally that monitoring is current; the pharmacy is not responsible for REMS compliance.
  2. Ensure REMS requirements are met (including required patient monitoring status and documentation in the REMS system) prior to dispensing. (correct answer)
  3. Dispense a partial fill without REMS verification because partial fills are exempt from REMS rules.
  4. Require the patient to sign a waiver releasing the pharmacy from liability and then dispense.

Explanation: This question tests pharmacist responsibilities under FDA REMS programs for medications like clozapine, which require monitoring for agranulocytosis. The key requirement is that pharmacies must verify patient monitoring status and document in the REMS system before each dispense, regardless of prescriber requests to bypass. Choice B ensures compliance by confirming all REMS elements are met, protecting patient safety and avoiding regulatory violations. Choice A is incorrect as pharmacies share REMS responsibility and cannot rely solely on prescriber attestation, while choice C is wrong because partial fills are not exempt from REMS. Choice D is inappropriate as patient waivers do not override REMS mandates. A transferable framework for REMS involves integrating verification into dispensing workflows. For complex REMS, outline steps: check prescriber/patient enrollment, verify lab results or monitoring, document in the system, and dispense only if compliant.

Question 13

A pharmacy experiences a break-in overnight and multiple bottles of Schedule II opioids are missing. The pharmacist-in-charge is determining next steps. Under DEA requirements, how should the pharmacist respond to this controlled substance loss?

  1. Wait until the next DEA inspection to report the loss so the pharmacy can complete an internal investigation first.
  2. Notify local law enforcement as appropriate and report the theft or significant loss to the DEA promptly using the required reporting process (e.g., DEA Form 106). (correct answer)
  3. Report the loss only to the FDA MedWatch program because missing opioids are a medication safety risk.
  4. Replace the missing stock and adjust inventory records without reporting to avoid negative consequences.

Explanation: This question tests DEA requirements for reporting theft or significant loss of controlled substances. The key guideline mandates prompt notification to local law enforcement and the DEA via Form 106, detailing the incident to combat diversion. Choice B is correct by following reporting protocols, ensuring regulatory compliance and investigation. Choice A is incorrect as delays violate timely reporting rules, and choice C is wrong because DEA handles losses, not MedWatch. Choice D is misguided since unreported adjustments are illegal. For loss prevention, maintain security and inventory controls. In theft cases, steps include securing the site, inventorying losses, notifying authorities, submitting Form 106, and updating records.

Question 14

In a busy chain pharmacy, a technician prints a patient's medication profile and leaves it on the counter where other customers can see it. Under HIPAA, how should the pharmacist respond to this regulatory violation?

  1. Ignore it because the profile is part of routine operations and incidental disclosures are always permitted without safeguards.
  2. Immediately remove the document from public view, remind staff of minimum necessary and safeguarding practices, and follow the pharmacy's HIPAA incident procedures as applicable. (correct answer)
  3. Shred all patient profiles daily to prevent future issues; retaining profiles is prohibited by HIPAA.
  4. Report the technician to the DEA because leaving profiles out is a controlled substance diversion risk.

Explanation: This question examines HIPAA Privacy Rule responses to incidental disclosures of protected health information (PHI) in a pharmacy. The key guideline requires covered entities to mitigate unauthorized disclosures, train staff on safeguards, and follow incident response procedures without overreacting to minor issues. Choice B is appropriate as it addresses the violation by removing the document, reinforcing training, and applying HIPAA incident protocols to prevent recurrence. Choice A is incorrect because incidental disclosures require safeguards, not blanket permission, and choice C is wrong as shredding profiles daily violates record retention rules and is unnecessary. Choice D is misguided since this is a HIPAA privacy issue, not a DEA diversion matter. For ongoing HIPAA compliance, implement staff training on minimum necessary use and physical safeguards for PHI. In complex incidents, steps include assessing breach risk, notifying affected parties if required, documenting the event, and updating policies.

Question 15

A pharmacist receives a prescription for a Schedule II opioid with directions that appear clinically inappropriate and a quantity that seems excessive for an opioid-naïve patient. The prescriber is difficult to reach, and the patient is demanding the medication. Under controlled substance dispensing responsibilities, how should the pharmacist handle this situation?

  1. Dispense as written because verifying medical necessity is outside the pharmacist's legal responsibilities for controlled substances.
  2. Exercise corresponding responsibility by assessing legitimacy, attempting to contact the prescriber to resolve concerns, and declining to dispense if the prescription is not for a legitimate medical purpose. (correct answer)
  3. Dispense a reduced quantity without prescriber authorization to improve safety and document the change.
  4. Report the prescriber to the FDA MedWatch program because excessive opioid quantities are adverse events.

Explanation: This question assesses pharmacists' corresponding responsibility under the Controlled Substances Act for dispensing controlled substances. The key requirement is verifying that prescriptions are issued for legitimate medical purposes, including assessing appropriateness and contacting prescribers if concerns arise. Choice B is best by exercising judgment, attempting verification, and declining if invalid, preventing misuse. Choice A is incorrect as pharmacists must evaluate legitimacy, and choice C is wrong because altering quantities without authorization is illegal. Choice D is misguided since MedWatch is for adverse events, not prescribing issues. For opioid dispensing, use tools like PDMPs and guidelines for assessment. In questionable cases, steps include reviewing history, contacting prescriber, documenting rationale, and refusing if unresolved.

Question 16

During a state board of pharmacy inspection at an outpatient pharmacy, the inspector asks to see how Schedule II controlled substances are stored. The pharmacist currently keeps Schedule II medications in an unlocked drawer behind the counter for faster access. Under Drug Enforcement Administration (DEA) requirements, how should the pharmacist respond to ensure proper controlled substance security?

  1. Continue current practice because Schedule II medications may be stored in any area behind the counter if staff are present.
  2. Move Schedule II medications into a securely locked cabinet or disperse them throughout non-controlled stock in a manner that deters theft, consistent with DEA security requirements. (correct answer)
  3. Store Schedule II medications in the patient will-call bins to separate them from inventory and reduce diversion risk.
  4. Store Schedule II medications in the refrigerator regardless of labeling to increase security and reduce access.

Explanation: This question evaluates compliance with DEA security requirements for storing Schedule II controlled substances in pharmacies. The key regulation mandates that Schedule II drugs must be stored in a securely locked cabinet or dispersed throughout non-controlled stock to deter theft, unless in a safe or vault. Choice B is correct as it aligns with DEA guidelines by recommending locked storage or dispersion, ensuring security while allowing operational efficiency. Choice A is wrong because unlocked storage behind the counter does not meet security standards even with staff presence, and choice C is incorrect as will-call bins are not secure and increase diversion risk. Choice D is misguided since refrigeration is for stability, not security, and may not apply to all Schedule II drugs. To ensure controlled substance security, pharmacies should conduct regular risk assessments and implement physical controls like locks and surveillance. For comprehensive compliance, key steps include designating secure areas, limiting access, maintaining inventories, and training staff on protocols.

Question 17

A community pharmacy receives a request from a local law enforcement officer asking for a patient's controlled substance fill history without a warrant. The officer states it is part of an investigation. Under HIPAA, what is the pharmacist's most appropriate response?

  1. Provide the information immediately because law enforcement requests are always exempt from HIPAA.
  2. Decline to disclose unless HIPAA law enforcement disclosure conditions are met (e.g., valid legal process) and follow the pharmacy's procedures for such requests. (correct answer)
  3. Provide only the medication names but not dates or quantities; HIPAA permits partial disclosure without verification.
  4. Provide the information if the patient's insurer is notified within 24 hours.

Explanation: This question examines HIPAA rules for disclosing protected health information (PHI) to law enforcement. The key requirement permits disclosures only under specific conditions like a warrant, court order, or administrative subpoena, with verification of the request's legitimacy. Choice B is appropriate by declining without valid process and following procedures, protecting patient privacy. Choice A is incorrect as law enforcement requests are not automatically exempt, and choice C is wrong because partial disclosures still require legal basis. Choice D is misguided since insurer notification is irrelevant. For HIPAA compliance with authorities, use a standardized verification process. In complex requests, steps include reviewing legal authority, limiting to minimum necessary, documenting, and consulting legal if needed.

Question 18

A community pharmacy receives a written prescription for oxycodone. The prescription is missing the prescriber's address, but includes patient name, drug, strength, directions, quantity, and prescriber signature. Before dispensing, how should the pharmacist handle this prescription validity issue under typical legal requirements for controlled substance prescriptions?

  1. Dispense because the prescriber signature is present; missing address is not required for controlled substance prescriptions.
  2. Contact the prescriber to obtain and document the missing required prescriber information before dispensing, consistent with federal/state requirements. (correct answer)
  3. Ask the patient to write the prescriber's address on the prescription and then dispense.
  4. Convert the prescription to an over-the-counter recommendation to avoid legal requirements.

Explanation: This question evaluates legal requirements for valid controlled substance prescriptions under the Controlled Substances Act and state laws. The key guideline mandates that written Schedule II prescriptions include the prescriber's address, among other elements, and missing information must be obtained from the prescriber before dispensing. Choice B is best as it requires contacting the prescriber to document the address, ensuring the prescription's completeness and legitimacy. Choice A is incorrect because the prescriber's address is required for controlled substances, and choice C is wrong as patients cannot add prescriber details. Choice D is inappropriate as converting to OTC avoids the issue but may not meet patient needs or legal standards. To maintain prescription validity, always cross-check against required elements and verify ambiguities. For complex prescriptions, steps include reviewing for completeness, contacting the prescriber, documenting changes, and filing appropriately.

Question 19

A pharmacist plans to compound a non-sterile topical cream and wants to assign a beyond-use date (BUD). The pharmacist has no stability data for the formulation and is using USP-grade ingredients. Under USP <795>, what is the most appropriate approach to setting the BUD?

  1. Assign a BUD based on USP <795> default BUD guidance for non-sterile preparations when stability data are not available, and document the rationale. (correct answer)
  2. Assign a 1-year BUD because USP-grade ingredients are assumed stable for at least 12 months.
  3. Assign the manufacturer's expiration date of the active ingredient as the BUD for the compounded preparation.
  4. Do not assign a BUD because BUDs are required only for sterile compounded preparations.

Explanation: This question evaluates USP <795> guidelines for assigning beyond-use dates (BUDs) to non-sterile compounded preparations. The key standard provides default BUDs based on formulation type and storage when stability data are absent, such as 6 months for non-aqueous liquids. Choice A is appropriate by using USP defaults and documenting, ensuring safety without overextending dates. Choice B is incorrect as arbitrary 1-year BUDs ignore USP limits, and choice C is wrong because ingredient expirations do not directly set BUDs. Choice D is misguided since BUDs are required for all compounds. A strategy for BUD assignment involves consulting USP and literature routinely. For non-sterile compounding, steps include evaluating ingredients, applying default BUDs, considering storage, and labeling clearly.

Question 20

A pharmacist is asked by a prescriber to dispense a REMS medication even though the pharmacy is not certified in the REMS program. The prescriber offers to ship the medication to the pharmacy and have it dispensed from there. Which action best ensures compliance with the REMS restricted distribution requirements?

  1. Accept the shipment and dispense because prescriber involvement substitutes for pharmacy certification.
  2. Decline to dispense until the pharmacy completes REMS certification and all REMS dispensing requirements are met and documented. (correct answer)
  3. Dispense only the first dose and require the patient to obtain remaining doses from the prescriber.
  4. Dispense if the patient signs a waiver acknowledging the pharmacy is not REMS-certified.

Explanation: This question addresses compliance with FDA REMS restricted distribution requirements. The key guideline requires pharmacies to be certified in the REMS program before receiving or dispensing the medication, regardless of prescriber actions. Choice B ensures compliance by declining until certification, preventing unauthorized handling. Choice A is incorrect as prescriber involvement does not certify the pharmacy, and choice C is wrong because splitting doses violates restricted distribution. Choice D is misguided since waivers do not override REMS. A framework for REMS involves pharmacy enrollment prior to stocking. For restricted REMS, steps include applying for certification, training staff, verifying shipments, and documenting dispenses.