Enrolling in EPCS with DrFirst: Step-by-Step Guide for Providers

Last updated: September 28, 2026

This guide walks you through enrolling in Electronic Prescribing of Controlled Substances (EPCS) with DrFirst as a provider on Canvas. When you finish, your practice's EPCS administrator will activate your access with you using your passphrase and token.

Before you start

  • Put aside a half hour to complete the session: The ID photo step has to be done within an hour, and your token has to be added within 24 hours of starting.

  • Find your invite email from epcs-do-not-reply@drfirst.com .

  • Gather the following items: your phone, your driver's license, state ID, or passport, NPI and your Social Security number, and a credit card (it won't be charged).

  • Install the VIP Access app (by Symantec/Broadcom) from the App Store or Google Play. It generates the 6-digit codes you'll use to sign controlled-substance prescriptions.

    iPhone: VIP Access for iPhone

    VIP Access for iPhone listing in the Apple App Store, developer Broadcom Inc

    Android: VIP Access

    VIP Access listing in Google Play, by Symantec VIP

Step 1: Open your email invite

Open the DrFirst invite email from epcs-do-not-reply@drfirst.com and click Enroll now.

DrFirst invite email with the Enroll now link highlighted

Step 2: Enter your invite details

  1. On the DrFirst page, locate the "I have an Invite" section on the right.

  2. Check that your NPI and Invite ID are already filled in. Clicking Enroll now in the email fills them in for you.

  3. Click Proceed.

DrFirst EPCS Gold page with the I have an Invite section highlighted

Step 3: Review the reminder of what you need and click "Continue"

IMPORTANT This screen suggests OneSpan or iPrescribe - you don't need either one. Canvas uses the VIP Access app instead which is available for free.

DrFirst reminder screen with the Continue button highlighted

Step 4: Complete identity proofing

If you've done DrFirst identity proofing before, at any practice, DrFirst will ask how you if you want to use your existing credentials or complete the identity proofing process again.

Click Complete the identity proofing process again, even if you've used DrFirst or iPrescribe somewhere else.

DrFirst screen offering Use my existing authentication credentials or Complete the identity proofing process again, with the second option highlighted

If you click Use my existing authentication credentials by mistake, you'll land on the screen below asking for your passphrase and a token. Click Cancel or your browser's back button, and choose Complete the identity proofing process again instead.

The existing credentials sign-in screen, which you should back out of

Step 5: Identity Proofing Process: Evidence Collection

DrFirst uses Experian to confirm who you are. Your details need to match your credit report exactly.

  1. Fill in your home address, date of birth, mobile phone number, and Social Security number. Use your personal mobile number, not your office line.

  2. Leave periods and special characters out of your address (for example, "1 E Main St Apt 204" instead of "1 E. Main St. Apt. #204").

  3. Enter a Visa or Mastercard credit card number, it will not be charged.

  4. Click Continue. If Experian can't match you right away, it asks 3 to 5 questions based on your credit history.

Identity proofing evidence collection form

Step 6: Verify your ID on your phone

DrFirst shows a QR code and a session code.

  1. Save the session code. If your session times out, it lets you pick up where you left off.

  2. Open your phone's camera and scan the QR code.

  3. On your phone, follow the prompts to photograph your ID and take a selfie. The QR code works only once, and this part must be finished within an hour.

  4. When your phone says you're done, go back to your computer and click Check Status. If it says it's still waiting for your identity, wait a minute and click it again.

Identity documents screen with the resume code and Check Status button highlighted

Step 7: Register your token

When identity proofing succeeds, you'll see Progress saved! with your session code. You have 24 hours from when you started to add a token.

  1. Click Add New Token. If you've used DrFirst before, you may see old tokens in the list. You can leave them there.

Token Management screen with the Add New Token button highlighted
  1. Under Code Generator, click Add.

    • Don't choose Push Notification (iPrescribe Authenticator).

Select Your 2FA Method with the Code Generator Add button highlighted
  1. Fill in the form:

    • Token Manufacturer: SYMANTEC

    • Token Issuer: DRFIRST

    • Token Type: OTP SOFT TOKEN

    • Token Nickname: anything that helps you recognize it, like "Canvas"

    • Serial Number or Credential ID: the Credential ID shown in your VIP Access app, starting with SYMC. Type it with no spaces.

    • One Time Pin (OTP): the current 6-digit code in VIP Access that changes every 30 seconds.

  2. Click Save.

Add Two-Factor Authentication Token form filled in with Symantec, DrFirst, OTP Soft Token, and a nickname
  1. Your new token shows ACTIVATED, and the Continue button becomes clickable. Click Continue.

Token successfully added and marked ACTIVATED, with the Continue button highlighted

Your Canvas token starts with SYMC. If DrFirst ever shows you more than one token (for example, one starting with TID), always pick the SYMC one for Canvas.

Step 8: Create your passphrase and security question

You'll enter this passphrase every time you sign a controlled-substance prescription. Fill in all four fields: Passphrase, Confirm Passphrase, Security Question, and Security Answer. DrFirst uses the security question if you ever need to recover your passphrase.

Your passphrase must have:

  • 8 to 20 characters

  • At least 1 uppercase letter, 1 lowercase letter, and 1 number

  • No special characters (no *, !, #, and so on)

  • No more than 2 of the same character in a row

This screen may accept a passphrase with special characters, but it will fail later with "Authentication failed. Access is denied." Stick to letters and numbers, and store your passphrase in a password manager.

Passphrase Creation screen with the passphrase and security question fields highlighted

Step 9: Enter your verification code

DrFirst texts a code to the mobile number you entered. It can take up to 5 minutes to arrive. Type it into Verification Code and click Continue. If it doesn't come, click Didn't receive your code?

Verification Code screen with the code field highlighted

Step 10: You're done enrolling with DrFirst

You'll see Congratulations! You have completed the Identity Proofing and EPCS Enrollment Process! Your part on DrFirst is finished. Before you can prescribe controlled substances, your practice's EPCS administrator has to grant you access.

Congratulations screen telling you to contact your organization's administrator

Step 11: Activate your access with your EPCS administrator

Tell your practice's EPCS administrator you've finished enrollment. You'll need to be available at the same time, because you'll give them your passphrase and a fresh VIP Access code while they enter them. Your administrator's steps are in Activating EPCS Grants with DrFirst.

  1. Your administrator searches for you by name or NPI in DrFirst.

  2. They select your SYMC token.

  3. You give them your passphrase and the current code from VIP Access.

  4. The admin clicks Authorize before the code changes.

DrFirst grant activation signature screen with the device, signing passphrase, and one-time pin fields highlighted

If your administrator can't find you right after you finish, have them refresh the page and try again in a few minutes.

Step 12: Wait for Canvas Support to finalize setup

After activation, tell Canvas Support to finalize your enrollment. This can take up to 24 hours. Your EPCS administrator will let you know when you're ready.

Related articles