Role in the sys­tem

All phar­maci­es in Euro­pe (public phar­maci­es, hos­pi­tal phar­maci­es and phar­maci­es that sup­p­ly cli­nics and care homes) are obli­ged to check the safe­ty fea­tures of medi­ci­ne packs and then deac­ti­va­te the uni­que iden­ti­fier. The secu­ri­ty fea­tures con­sist of first-ope­ning pro­tec­tion and the uni­que iden­ti­fier. This affects all pre­scrip­ti­on-only medi­cinal pro­ducts for human use. Excep­ti­ons are lis­ted in a very short list from the EU Com­mis­si­on.

Sin­ce Febru­ary 9, 2019, medi­cinal pro­ducts sub­ject to man­da­to­ry veri­fi­ca­ti­on may no lon­ger be dis­pen­sed to pati­ents if the two safe­ty fea­tures have not been che­cked and the uni­que iden­ti­fier has not been suc­cessful­ly deac­ti­va­ted. Any resul­ting alarms must be inves­ti­ga­ted. In a let­ter dated Octo­ber 18, 2018, the EU Com­mis­si­on lists the obli­ga­ti­ons of the indi­vi­du­al par­ties invol­ved in the imple­men­ta­ti­on of the Fal­si­fied Medi­ci­nes Direc­ti­ve.

Authen­ti­ca­ti­on is car­ri­ed out using the secur­Ph­arm sys­tem. In order to car­ry out the legal­ly requi­red authen­ti­ca­ti­on, phar­maci­es must con­nect to the secur­Ph­arm sys­tem via the phar­ma­cy sys­tem. The phar­ma­cy ser­ver is ope­ra­ted by NGDA - Netz­werk­ge­sell­schaft Deut­scher Apo­the­ker mbH.

The ABDA offers exten­si­ve infor­ma­ti­on for phar­maci­es on secur­Ph­arm on its web­site, inclu­ding a qua­li­ty assu­rance work aid from the Ger­man Fede­ral Cham­ber of Phar­macists (Stan­dard Ope­ra­ting Pro­ce­du­re: secur­Ph­arm - Pro­ce­du­re in the phar­ma­cy).

Sys­tem access

NGDA- Netz­ge­sell­schaft Deut­scher Apo­the­ker mbH (NGDA) ope­ra­tes the phar­ma­cy sys­tem that allows drug veri­fiers to con­nect to the secur­Ph­arm sys­tem. NGDA is also respon­si­ble for the legi­ti­miza­ti­on of the­se sys­tem users.

Sys­tem access

The check­list pro­vi­des an over­view of the sys­tem con­nec­tion and important topics regar­ding the imple­men­ta­ti­on of the Fal­si­fied Medi­ci­nes Direc­ti­ve.

Mitteilungen

Updated BAK working aid

ABDA offers exten­si­ve infor­ma­ti­on for phar­maci­es on secur­Ph­arm on its web­site, inclu­ding an updated working aid from the Ger­man Fede­ral Cham­ber of Phar­macists on qua­li­ty assu­rance (Stan­dard Ope­ra­ting Pro­ce­du­re: secur­Ph­arm - Pro­ce­du­re in the phar­ma­cy, as of 26.8.2025).

Learn More ...

Alarm pro­ces­sing as an important pie­ce of the puz­zle: sup­port for offi­ci­al recon­nais­sance

From May 19, 2025, all aut­ho­ri­ties that alre­a­dy have access to the secur­Ph­arm sys­tem will have access to an addi­tio­nal modu­le: the Natio­nal Alert Manage­ment Sys­tem (NAMS).

Many sys­tem actions can be tra­cked with the help of so-cal­led aut­ho­ri­ty reports, but this is not pos­si­ble in all cases. Espe­ci­al­ly in …

Learn More ...

Recom­men­da­ti­ons from the Ger­man Fede­ral Cham­ber of Phar­macists on how to prepa­re for a power fail­ure in phar­maci­es (Decem­ber 2022)

The working aid of the Ger­man Fede­ral Cham­ber of Phar­macists can be found on the Web­site of the ABDA. You can access the docu­ment direct­ly at this link.…

Learn More ...

secur­Ph­arm-FAQ der ABDA

Über­ar­bei­te­te Ver­si­on 4 (April 2022)…

Learn More ...

Inspec­tions (July 2020)

On July 16, 2020, the EU Com­mis­si­on issued an Aide Memoi­re for the inspec­tion of phar­maci­es.…

Learn More ...

Prac­ti­cal examp­les and tips ( Febru­ary 2019)

Prac­ti­cal examp­les and illus­tra­ted ins­truc­tions are sum­ma­ri­zed in the docu­ment Ins­truc­tions on first-ope­ning pro­tec­tion and the Data Matrix Code.…

Learn More ...

Find a contact

Do you have any questions or need help? Don't worry, we are here to help you. Simply use our contact form and we will forward your request to the right contact person, who will get back to you as quickly as possible. Your stress is our concern – let us help you.

contact us

Questions and Answers(ABDA)

Why do we need a pro­tec­tion sys­tem for medi­ci­nes?

The­re are hard­ly any coun­ter­feits in
phar­maci­es.
So far, the­re have only rare­ly been coun­ter­feit medi­ci­nes in the legal sup­p­ly chain. The wide avai­la­bi­li­ty
of well-made coun­ter­feits increa­ses the dan­ger. The pro­tec­tion sys­tem has the­r­e­fo­re been
intro­du­ced to main­tain and fur­ther impro­ve the high level of safe­ty in the legal phar­maceu­ti­cal trade.
fur­ther impro­ve it.

Who is secur­Ph­arm e.V.?

secur­Ph­arm e. V. is the Ger­man orga­niza­ti­on for the authen­ti­ca­ti­on of phar­maceu­ti­cals and
respon­si­ble for the ope­ra­ti­on of the sys­tem for the authen­ti­ca­ti­on of medi­cinal pro­ducts. The asso­cia­ti­on
was foun­ded to imple­ment the EU Fal­si­fied Medi­ci­nes Direc­ti­ve 2011/62/EU and Dele­ga­ted Regu­la­ti­on (EU) No. 2016/EU.
(EU) No. 2016/161 was foun­ded. Its mem­bers include the Ver­band For­schen­der
Arz­nei­mit­tel­her­stel­ler e. V. (vfa), the Bun­des­ver­band der phar­ma­zeu­ti­schen Indus­trie e. V. (BPI),
the Fede­ral Asso­cia­ti­on of Phar­maceu­ti­cal Manu­fac­tu­r­ers (BAH), Avo­xa - Medi­en­grup­pe Deut­scher
Apo­the­ker GmbH and IFA - Infor­ma­ti­ons­stel­le für Arz­nei­mit­tel GmbH as well as ABDA - Bun­des­ver­ei­ni­gung deut­scher Apo­the­ker­ver­bän­de
Bun­des­ver­ei­ni­gung deut­scher Apo­the­ker­ver­bän­de e. V. secur­Ph­arm ope­ra­tes as a non-pro­fit orga­niza­ti­on.
orga­niza­ti­on. secur­Ph­arm is the Ger­man com­po­nent of the EU-wide net­work
EMVS against coun­ter­feit medi­ci­nes.

How can phar­maci­es par­ti­ci­pa­te in secur­Ph­arm?

Phar­maci­es con­nect to the secur­Ph­arm sys­tem via the phar­ma­cy ser­ver. The tech­ni­cal
The tech­ni­cal imple­men­ta­ti­on is car­ri­ed out by your phar­ma­cy soft­ware com­pa­ny. The ope­ra­tor of the phar­ma­cy ser­ver is
Netz­ge­sell­schaft deut­scher Apo­the­ker mbH (NGDA), a 100% sub­si­dia­ry of Avo­xa.
NGDA is respon­si­ble for the legi­ti­miza­ti­on and con­nec­tion of the par­ti­ci­pan­ts (phar­macists, who­le­sa­lers,
health care faci­li­ties).

Who can con­nect to the phar­ma­cy sys­tem?

All play­ers affec­ted by the Fal­si­fied Medi­ci­nes Direc­ti­ve and who are not phar­maceu­ti­cal com­pa­nies can join the phar­ma­cy sys­tem.
and are not phar­maceu­ti­cal com­pa­nies, in par­ti­cu­lar public phar­maci­es, hos­pi­tals and phar­maceu­ti­cal who­le­sa­lers,
hos­pi­tals and phar­maceu­ti­cal who­le­sa­lers.

What secu­ri­ty fea­tures does the Fal­si­fied Medi­ci­nes Direc­ti­ve requi­re?

Sin­ce Febru­ary 9, 2019, the Fal­si­fied Medi­ci­nes Direc­ti­ve has sti­pu­la­ted two new secu­ri­ty fea­tures
on the pack­a­ging of pre­scrip­ti­on medi­ci­nes. A first-ope­ning pro­tec­tion (anti
tam­pe­ring device), which indi­ca­tes whe­ther a pack has alre­a­dy been ope­ned, is inten­ded to
gua­ran­tee that the con­tents of the pack are genui­ne. An indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture (Uni­que
iden­ti­fier) is inten­ded to make each pack uni­que­ly iden­ti­fia­ble. Both secu­ri­ty fea­tures must be
che­cked by the phar­ma­cy befo­re dis­pen­sing to the pati­ent and, in the case of the uni­que iden­ti­fier, deac­ti­va­ted.
iden­ti­fi­ca­ti­on fea­ture must be deac­ti­va­ted.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 7

What does the uni­que iden­ti­fier look like?

The uni­que iden­ti­fier is a Data Matrix code in which the indi­vi­du­al seri­al num­ber, the pro­duct code
num­ber, the pro­duct code, the batch desi­gna­ti­on and the expiry date. In addi­ti­on
This infor­ma­ti­on is also prin­ted in plain text on the pack.

When did the con­nec­tion to the secur­Ph­arm sys­tem and the authen­ti­ci­ty check beco­me man­da­to­ry?
man­da­to­ry?

Medi­cinal pro­ducts sub­ject to man­da­to­ry veri­fi­ca­ti­on that have been released for sale by the manu­fac­tu­rer sin­ce Febru­ary 9, 2019
may only be dis­pen­sed after suc­cessful authen­ti­ca­ti­on.
Medi­cinal pro­ducts that were released for mar­ke­ting befo­re the cut-off date may be sup­pli­ed until the end of their
expiry date wit­hout the safe­ty fea­tures and the­r­e­fo­re wit­hout authen­ti­ca­ti­on.
be dis­pen­sed. The phar­ma­cy soft­ware should auto­ma­ti­cal­ly reco­gni­ze whe­ther a medi­ci­ne is sub­ject to veri­fi­ca­ti­on or not.
auto­ma­ti­cal­ly.

To which medi­ci­nes do the new safe­ty mea­su­res app­ly?

In prin­ci­ple, the new requi­re­ments app­ly to all pre­scrip­ti­on-only medi­cinal pro­ducts for human use
with the excep­ti­on of medi­cinal pro­ducts on the white list (Annex I to the Dele­ga­ted Regu­la­ti­on).
lis­ted medi­cinal pro­ducts. The white list is a list of pre­scrip­ti­on-only medi­cinal pro­ducts and medi­cinal pro­duct
cate­go­ries of medi­cinal pro­ducts that may not bear the safe­ty fea­tures. This list con­ta­ins 14
pro­duct cate­go­ries, inclu­ding home­opa­thics, all­er­gen extra­cts, con­trast media and par­en­te­ral nut­ri­ti­on solu­ti­ons.
solu­ti­ons for par­en­te­ral nut­ri­ti­on. Non-pre­scrip­ti­on medi­ci­nes may not bear the
safe­ty fea­tures. Excep­ti­ons are the medi­cinal pro­ducts lis­ted in the Black List (Annex II to the Dele­ga­ted
Regu­la­ti­on). The Black List is a list of non-pre­scrip­ti­on medi­cinal pro­ducts and
The Black List is a list of non-pre­scrip­ti­on medi­ci­nes and cate­go­ries of medi­ci­nes that must bear the safe­ty fea­tures.
So far, only ome­pra­zo­le is included in two dif­fe­rent strengths.

Can OTCs vol­un­t­a­ri­ly car­ry a Data Matrix Code?

Accor­ding to the EU Com­mis­si­on, the appli­ca­ti­on of a Data Matrix Code to OTC packs is per­mit­ted as long as the Data Matrix Code does not con­tain seri­al num­bers.
the Data Matrix Code does not con­tain a seri­al num­ber, the pro­duct code, expiry date and batch
date and batch num­ber can be included in a machi­ne-rea­da­ble form. Vol­un­t­a­ry par­ti­ci­pa­ti­on in the
in the authen­ti­ca­ti­on of medi­cinal pro­ducts is not pos­si­ble.

May OTCs vol­un­t­a­ri­ly car­ry first-ope­ning pro­tec­tion?

In an announce­ment dated April 11, 2017, the PEI and BfArM (BAnz AT 26.04.2017 B3.) cla­ri­fied
that OTC packs may bear a first-ope­ning pro­tec­tion on a vol­un­t­a­ry basis.

How does the secur­Ph­arm sys­tem for the veri­fi­ca­ti­on of medi­cinal pro­ducts work?

During the pro­duc­tion pro­cess, the phar­maceu­ti­cal manu­fac­tu­rer pro­vi­des each pack of a medi­cinal pro­duct sub­ject to veri­fi­ca­ti­on
phar­maceu­ti­cal pro­duct with an indi­vi­du­al seri­al num­ber. This seri­al num­ber is stored tog­e­ther
tog­e­ther with the pro­duct code (as PPN or NTIN encap­su­la­ted PZN), batch desi­gna­ti­on and expiry
date in the Data Matrix Code (and also in plain text) on the pack. At the same time
This infor­ma­ti­on is uploa­ded to the data­ba­se sys­tem of the phar­maceu­ti­cal indus­try.
To check the authen­ti­ci­ty of a pack, the Data Matrix Code of the pack is scan­ned in the phar­ma­cy.
scan­ned. This trig­gers a check of the seri­al num­ber and pro­duct code against the phar­maceu­ti­cal indus­try data­ba­se.
data­ba­se of the phar­maceu­ti­cal indus­try. The veri­fi­ca­ti­on requests from the phar­maci­es are

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 8

for­ward­ed anony­mously via the phar­ma­cy ser­ver. The sta­tus of a pack recor­ded in this data­ba­se
sta­tus of a pack is repor­ted back to the phar­ma­cy. If the pack is dis­pen­sed after posi­ti­ve
posi­ti­ve feed­back, the sta­tus is set to “dis­pen­sed”. If a second
pack with an iden­ti­cal seri­al and pro­duct num­ber is veri­fied, it will be noti­ced that it has alre­a­dy been
has alre­a­dy been dis­pen­sed.

Why are the­re two sub­sys­tems?

The Ger­man stake­hol­ders have opted for a sys­tem that con­sists of dis­tri­bu­ted data­ba­ses for phar­maci­es and phar­maceu­ti­cal com­pa­nies.
data­ba­ses for phar­maci­es and phar­maceu­ti­cal com­pa­nies. The design of a
model ensu­res spe­cial pro­tec­tion of sen­si­ti­ve data, as data for the veri­fi­ca­ti­on pro­ces­ses (veri­fi­ca­ti­on and
for the veri­fi­ca­ti­on pro­ces­ses (veri­fi­ca­ti­on and sta­tus chan­ges) are only exch­an­ged anony­mously. The
The sub­sys­tems are also ope­ra­ted by dif­fe­rent com­pa­nies. The data­ba­se
sys­tem for phar­maceu­ti­cal com­pa­nies is ope­ra­ted by ACS Phar­ma­Pro­tect GmbH, a com­pa­ny of the phar­maceu­ti­cal
of the phar­maceu­ti­cal asso­cia­ti­ons. The data­ba­se sys­tem for the phar­maceu­ti­cal indus­try
all phar­maceu­ti­cal com­pa­nies who­se pro­ducts are sub­ject to the veri­fi­ca­ti­on obli­ga­ti­on.
sub­ject to the veri­fi­ca­ti­on obli­ga­ti­on. The phar­ma­cy ser­ver is ope­ra­ted by Netz­ge­sell­schaft Deut­scher Apo­the­ker
mbH (NGDA).

Why is this sys­tem also cal­led an “end-to-end sys­tem”?

The phar­maceu­ti­cal com­pa­ny crea­tes a safe­ty fea­ture at one end of the sup­p­ly chain - when pack­a­ging the medi­ci­ne.
the drug - while at the other end of the chain - befo­re dis­pen­sing to the pati­ent in the phar­ma­cy - this
to the pati­ent in the phar­ma­cy - this safe­ty fea­ture is veri­fied and the seri­al num­ber is
writ­ten out.

Why is the Data Matrix Code used for this sys­tem?

Two-dimen­sio­nal bar­codes can hold a lot of data (e.g. in addi­ti­on to the pro­duct code inclu­ding the PZN
seri­al num­ber, the batch desi­gna­ti­on and the expiry date) and dis­play them with a very small
space requi­re­ment.

Do par­al­lel imports car­ry Ger­man or for­eign coding?

Par­al­lel imports car­ry Ger­man coding in the Ger­man mar­ket. Par­al­lel importers must
the uni­que iden­ti­fier of the pro­duct they mar­ket under their own name from the sys­tem of the ori­gi­nal mar­ket.
from the sys­tem of the ori­gi­nal mar­ket and book it out. They then
posi­ti­on as a phar­maceu­ti­cal entre­pre­neur and crea­te a new uni­que iden­ti­fier, which they enter in the
which they upload to the secur­Ph­arm sys­tem.

How are for­eign packs hand­led?

For packs that are not labe­led in Ger­man or in both Ger­man and (one) other
lan­guage, a distinc­tion must be made depen­ding on the sup­p­ly chan­nel.
Apart from the spe­cial dis­tri­bu­ti­on chan­nel § 73 AMG, the fol­lo­wing rule of thumb appli­es: For­eign packs
should be trea­ted like Ger­man packs by scan­ning the Data Matrix.
a) Nor­mal pro­cu­re­ment chan­nel

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 9

For packs that are pro­cu­red via the nor­mal deli­very rou­te and that are available in both
labe­led in Ger­man as well as in (ano­ther) language(s), so-cal­led mul­ti-mar­ket packs
packs, can be hand­led in the same way as Ger­man packs. Mul­ti-mar­ket packs can be
the Ger­man labe­l­ing on the Data Matrix Code, the four data ele­ments in
(PC, SN, LOT, EXP), as well as the PZN in plain text or in the form of Code 39 (bar­code)
or “embedded” in the PC data ele­ment.
For cen­tral­ly aut­ho­ri­zed packs that are not dis­tri­bu­ted in Ger­ma­ny and are obtai­ned
are obtai­ned via the nor­mal deli­very rou­te, the same pro­ce­du­re must be fol­lo­wed as for Ger­man packs.
pro­ce­du­re. The­se packs often have packa­ge labe­l­ing in a non-Ger­man lan­guage (excep­ti­on
lan­guage (excep­ti­on: e.g. Aus­tria). The PZN is gene­ral­ly neither writ­ten in plain text
nor can it be recon­s­truc­ted from the Data Matrix Code. You should the­r­e­fo­re
the­r­e­fo­re use the Data Matrix Code and the seri­al num­ber (SN) on the pack to deter­mi­ne the
to deter­mi­ne a veri­fi­ca­ti­on obli­ga­ti­on.
The scan of the Data Matrix Code trig­gers a veri­fi­ca­ti­on request, which is for­ward­ed via the
Euro­pean hub to the respec­ti­ve natio­nal sys­tem in which the pack data is stored.
pack­a­ging data is stored. The pro­cess is also refer­red to as an IMT (Inter­mar­ket
tran­sac­tion). For exam­p­le, if you veri­fy pack­a­ging data uploa­ded to the Spa­nish sys­tem
the veri­fi­ca­ti­on request is for­ward­ed via the Euro­pean hub to the Spa­nish veri­fi­ca­ti­on sys­tem.
veri­fi­ca­ti­on sys­tem via the Euro­pean hub. IMT packs can­not be manu­al­ly veri­fied or boo­ked out with the secur­Ph­arm GUI.
manu­al­ly veri­fied or boo­ked out.
b) Sepa­ra­te dis­tri­bu­ti­on chan­nel
If you do not obtain a pack via the nor­mal dis­tri­bu­ti­on chan­nel, e.g. as a sin­gle or
indi­vi­du­al import accor­ding to § 73 AMG, the veri­fi­ca­ti­on obli­ga­ti­on in the export­ing coun­try is decisi­ve.
is decisi­ve. This appli­es even if a Data Matrix Code and a seri­al num­ber are appli­ed.
are appli­ed.
Plea­se note in gene­ral for dis­tri­bu­ti­on chan­nels that devia­te from the nor­mal dis­tri­bu­ti­on chan­nel,
(e.g. § 79 AMG) and ques­ti­ons regar­ding secur­Ph­arm hand­ling, plea­se refer to the
publi­ca­ti­ons of the fede­ral aut­ho­ri­ties, the AMK (https://www.abda.de/fuer-
apo­the­ker/­arz­nei­mit­tel­kom­mis­si­on/amk-nach­rich­ten/) and the ABDA. In the past
the­re were excep­ti­ons to the basic veri­fi­ca­ti­on obli­ga­ti­on.
For ques­ti­ons about the hub, plea­se refer to ques­ti­ons 1.18 and 1.19.

What data is gene­ra­ted when end users use the secur­Ph­arm sys­tem?

If a phar­ma­cy veri­fies a pack or checks it out, a request is sent to the phar­ma­cy sys­tem (AP sys­tem).
sys­tem (AP sys­tem). The N-ID (i.e. the pseud­ony­mi­zed user ID/APO num­ber)
nung/APO num­ber), the time stamp, the action/process and the pack data con­tai­ned in the Data Matrix Code (PC
(PC, SN, LOT, EXP) are trans­mit­ted. Only NGDA has access to this data.
access. From the APS, the request is for­ward­ed to the data­ba­se of the phar­maceu­ti­cal indus­try (PU-
sys­tem). Howe­ver, the iden­ti­ty of the phar­ma­cy remains hid­den from the PU sys­tem becau­se

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 10

all requests are for­ward­ed anony­mously under a spe­cial NGDA user ID. Your
per­so­nal data is the­r­e­fo­re not trans­mit­ted to the PU sys­tem. The pur­po­se of the query is
The only pur­po­se of the query is to compa­re the infor­ma­ti­on read out (secu­ri­ty fea­tures of the pa
the data stored in the sys­tem for the respec­ti­ve pack. The data exch­an­ge
the authen­ti­ci­ty of the medi­ci­ne can be veri­fied.
Every request to the data­ba­ses is saved. This enables the respon­si­ble super­vi­so­ry
aut­ho­ri­ties to inves­ti­ga­te a suspec­ted case of fal­si­fi­ca­ti­on and com­pli­ance with the Dele­ga­ted Regu­la­ti­on.
inves­ti­ga­ti­on. See also question:4.7 and 4.8

What is the Euro­pean hub?

The Euro­pean hub is nee­ded to enable cross-bor­der flows of goods. It
net­works the veri­fi­ca­ti­on sys­tems of the indi­vi­du­al mem­ber sta­tes with each other so that every medi­ci­ne pack
pack of medi­ci­nes bea­ring the safe­ty fea­tures can be che­cked in every phar­ma­cy in Euro­pe.
phar­ma­cy in Euro­pe. In addi­ti­on, phar­maceu­ti­cal com­pa­nies upload the pack data to the Euro­pean hub (EU hub).
hub) to upload the pack data to the respec­ti­ve natio­nal sys­tem. The ope­ra­tor of the EU Hub is EMVO,
the Euro­pean Medi­ci­nes Veri­fi­ca­ti­on Orga­niza­ti­on. More about EMVO at https://emvo-
medicines.eu/

Which count­ries are con­nec­ted to the Euro­pean hub?

The authen­ti­ca­ti­on sys­tems of the EU mem­ber sta­tes as well as Ice­land, Liech­ten­stein, Nor­way, Nor­t­hern
mem­ber sta­tes as well as Ice­land, Liech­ten­stein, Nor­way, Nor­t­hern Ire­land and Switz­er­land are con­nec­ted to the Euro­pean hub. The sys­tems of
Ita­ly and Greece will not be added until 2025. The­se have been gran­ted a tran­si­ti­on peri­od by the legis­la­tor.
The­se count­ries have been gran­ted a tran­si­tio­nal peri­od by the legis­la­tor becau­se the­se count­ries alre­a­dy had
regu­la­ti­on came into force, the­se count­ries alre­a­dy had sys­tems in place for the veri­fi­ca­ti­on of medi­cinal
requi­re­ments. In Switz­er­land, the appli­ca­ti­on of safe­ty
safe­ty fea­tures and their test­ing is curr­ent­ly still car­ri­ed out on a vol­un­t­a­ry basis in Switz­er­land.

Who is the EMVO?

The Euro­pean Medi­ci­nes Veri­fi­ca­ti­on Orga­niza­ti­on (EMVO) ope­ra­tes the EU hub through which the indi­vi­du­al
the indi­vi­du­al coun­try sys­tems exch­an­ge the pack­a­ging data. A cor­re­spon­ding agree­ment was con­cluded bet­ween EMVO and secur­Ph­arm
agree­ment was con­cluded bet­ween EMVO and secur­Ph­arm to con­nect the secur­Ph­arm sys­tem with the EU Hub
and thus inte­gra­te it into the Euro­pean anti-coun­ter­feit­ing sys­tem.

What is the EMVS?

The Euro­pean Medi­ci­nes Veri­fi­ca­ti­on Sys­tem (EMVS) is the Euro­pe-wide anti-coun­ter­feit­ing sys­tem.
It con­sists of two com­pon­ents. One com­po­nent is for­med by the natio­nal orga­niza­ti­ons for
the Dele­ga­ted Regu­la­ti­on (NMVOs) with the cor­re­spon­ding natio­nal sys­tems (NMVS).
(NMVS).
The second com­po­nent of the EMVS is for­med by the Euro­pean hub. This hub
This hub acts as a rou­ter (con­nec­tion point) to ensu­re the exch­an­ge of data from the natio­nal data
and is also used by phar­maceu­ti­cal com­pa­nies to upload pack­a­ging data.
com­pa­nies.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 11

How are the secu­ri­ty fea­tures inten­ded to increase coun­ter­feit pro­tec­tion?

The new anti-coun­ter­feit­ing pro­tec­tion con­sis­ting of an indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture and first-ope­ning pro­tec­tion
coun­ter­feits are easier to reco­gni­ze. The indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture makes each pack
uni­que, making coun­ter­feit­ing less attrac­ti­ve and the risk of detec­tion high.
is high.

Deal­ing with packs that car­ry a second Data Matrix code, e.g. for medi­ci­nes manu­fac­tu­red and packa­ged in India.
manu­fac­tu­red and packa­ged in India?

Medi­cinal pro­ducts manu­fac­tu­red in India and sub­se­quent­ly expor­ted may bear a Data Matrix Code
which is very simi­lar to the Data Matrix Code pre­scri­bed in the Euro­pean Uni­on.
If the Indi­an Data Matrix Code on the pack­a­ging is scan­ned in the phar­ma­cy,
the pack can­not be iden­ti­fied in the secur­Ph­arm sys­tem. During the authen­ti­ci­ty
the­r­e­fo­re have to ensu­re that the cor­rect Data Matrix Code is scan­ned.
is scan­ned. The “PPN” emblem in clear text next to the code can pro­vi­de an indi­ca­ti­on of the cor­rect Data Matrix Code.
next to the code.
The pro­blem occur­red par­ti­cu­lar­ly short­ly after the intro­duc­tion of the Euro­pean anti-coun­ter­feit­ing sys­tem.
and should now be rare.

Whe­re can I find out which coun­ter­feits have been detec­ted by the secur­Ph­arm sys­tem?

Is the­re
Is the­re a list of detec­ted coun­ter­feits?
secur­Ph­arm sup­ports the respon­si­ble super­vi­so­ry aut­ho­ri­ties in the inves­ti­ga­ti­on of suspec­ted coun­ter­feit
by pro­vi­ding reports from the secur­Ph­arm sys­tem, the so-cal­led audit trails of indi­vi­du­al packs.
of indi­vi­du­al packs. As a rule, secur­Ph­arm does not recei­ve any infor­ma­ti­on about the
gene­ral­ly does not recei­ve any infor­ma­ti­on. Infor­ma­ti­on on coun­ter­feits must the­r­e­fo­re be obtai­ned from the respon­si­ble
super­vi­so­ry aut­ho­ri­ties.
1.25 Deal­ing with reclas­si­fied pre­scrip­ti­on-only medi­cal samples
Pre­scrip­ti­on-only medi­cal samples are medi­cinal pro­duct packs that are dis­tri­bu­ted by the
phar­maceu­ti­cal com­pa­ny direct­ly to doc­tors as (free) samples.
Phar­maci­es are not nor­mal­ly allo­wed to sup­p­ly the­se packs to the public.
If the com­pe­tent aut­ho­ri­ties allow phar­maci­es to sup­p­ly phy­si­ci­an samples in excep­tio­nal
If, in excep­tio­nal cases, the com­pe­tent aut­ho­ri­ties allow phar­maci­es to dis­pen­se medi­cal samples, the­se packs may not be pos­ted. This is becau­se the
reclas­si­fied phy­si­ci­an samples are alre­a­dy boo­ked out as “sample/sample” and a rene­wed
a new check-out via the secur­Ph­arm sys­tem will result in an alarm. Veri­fi­ca­ti­on of the pack is
pos­si­ble.
1.26 What is an IMT?
IMT stands for Inter­mar­ket Tran­sac­tion and descri­bes cross-bor­der data com­mu­ni­ca­ti­on.
data com­mu­ni­ca­ti­on.
Exam­p­le: Veri­fi­ca­ti­on pro­cess of a Spa­nish pack (Spa­nish pre­sen­ta­ti­on, ori­gi­nal­ly f.
pro­du­ced for the Spa­nish mar­ket).

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 12

For exam­p­le, if you veri­fy a pack uploa­ded in the Spa­nish sys­tem, the
veri­fi­ca­ti­on request is for­ward­ed to the Spa­nish veri­fi­ca­ti­on sys­tem via the Euro­pean hub.
for­ward­ed to the Spa­nish veri­fi­ca­ti­on sys­tem. The phar­ma­cy then recei­ves the usu­al feed­back again via the hub.
feed­back via the hub.
Among other things, the Euro­pean hub requi­res the batch desi­gna­ti­on (LOT) for for­war­ding. The­r­e­fo­re
an IMT pack can­not be pro­ces­sed via the secur­Ph­arm GUI, as only the PC and SN can be ente­red the­re.
and SN can be ente­red the­re.
If your soft­ware pro­vi­der offers a func­tion for manu­al secur­Ph­arm ent­ry with all data ele­ments (PC, SN, LOT, EXP), this can be used to veri­fy and wri­te off IMT packs.

What are the requi­re­ments for using the secur­Ph­arm sys­tem?

In addi­ti­on to the tech­ni­cal requi­re­ments (hard­ware and soft­ware, Inter­net con­nec­tion), the use of the secur­Ph­arm sys­tem requi­res
and soft­ware, Inter­net con­nec­tion), access to the phar­ma­cy ser­ver of the secur­Ph­arm sys­tem in the form of an
sys­tem in the form of an elec­tro­nic cer­ti­fi­ca­te (N-ID). In order to pre­vent unaut­ho­ri­zed use of the sys
sys­tem, a user goes through a legi­ti­miza­ti­on pro­cess befo­re acces­sing the sys­tem. The
legi­ti­ma­ti­on is che­cked at regu­lar inter­vals and the user is re-aut­ho­ri­zed. This
This is done via the NGDA por­tal. For the initi­al access to the secur­Ph­arm sys­tem, secur­Ph­arm
has com­pi­led a check­list at https://www.securpharm.de/apotheken-systemzugang/.

What is the NGDA por­tal?

The NGDA por­tal pro­vi­des access for various tar­get groups. Phar­macists or tho­se respon­si­ble
or tho­se respon­si­ble for a site can use the NGDA por­tal to mana­ge the cer­ti­fi­ca­tes of one or more sites.
mana­ge the cer­ti­fi­ca­tes of one or more sites. In the N-Ident pro­ce­du­re, each ope­ra­ting site recei­ves its own
N-ID (APO num­ber). The cont­act details of the respec­ti­ve busi­ness pre­mi­ses (inclu­ding e-mail address) should
always be kept up to date. When regis­tering in the NGDA por­tal, a user name and pass­word are
pass­word are defi­ned. The por­tal can be acces­sed at www.ngda.de.

What is the N-ID?

The N-ID is the elec­tro­nic iden­ti­ty of an indi­vi­du­al busi­ness estab­lish­ment veri­fied as part of the N-Ident pro­cess.
busi­ness pre­mi­ses. It is used to access digi­tal ser­vices and sys­tems wit­hout addi­tio­nal regis­tra
regis­tra­ti­on and is a man­da­to­ry requi­re­ment for par­ti­ci­pa­ti­on in the secur­Ph­arm sys­tem. Behind the N-ID
is a cer­ti­fi­ca­te that is valid for 24 months.
When regis­tering and legi­ti­mi­zing a busi­ness estab­lish­ment in the NGDA por­tal, an N-ID cer­ti­fi­ca­te can be acqui­red.
cer­ti­fi­ca­te can be acqui­red. With the cer­ti­fi­ca­te, a user recei­ves a com­bi­na­ti­on of user name,
the N-ID (e.g. apo1234567) and pass­word. If the cer­ti­fi­ca­te for the indi­vi­du­al ope­ra­ting site has been
rene­wed, a new pass­word is issued for the cer­ti­fi­ca­te, but the user name (N-ID) for the ope­ra­ting site remains the same.
for the ope­ra­ting site remains the same.

What can be done if dif­fi­cul­ties ari­se when log­ging into the NGDA por­tal?

If you have for­got­ten your pass­word, you can obtain a new pass­word from the NGDA web­site.
pass­word. To do this, you must enter your user name and the e-mail address you have pro­vi­ded.
You can find help with this at www.ngda.de.

What can I do if I have dif­fi­cul­ties log­ging in to the secur­Ph­arm GUI?

To log in to the secur­Ph­arm GUI, you will need the N-ID and pass­word from the first PIN let­ter you recei­ved by post.
let­ter that was sent by post. When rene­wing a cer­ti­fi­ca­te, users recei­ve
recei­ve a new pass­word, but the pass­word from the first PIN let­ter is still used to access the
GUI.
In the event that the pass­word is for­got­ten, a new pass­word can be obtai­ned from the NGDA web­site.
pass­word. The user name and the stored e-mail address must be ente­red for this pur­po­se.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 14

The pass­word is sent to the e-mail address stored in the NGDA por­tal for this ope­ra­ting site.
sent. It is the­r­e­fo­re important to keep the e-mail address stored in the NGDA por­tal up to date.
The secur­Ph­arm GUI can be rea­ched at: https://securpharm-gui.ngda.de/ .

Who is respon­si­ble for con­nec­ting to the sys­tem?

The respon­si­bi­li­ty for imple­men­ting the legal requi­re­ments of the Fal­si­fied Medi­ci­nes Direc­ti­ve
and the Dele­ga­ted Regu­la­ti­on, which also includes the con­nec­tion to secur­Ph­arm via the phar­ma­cy
ser­ver, is the respon­si­bi­li­ty of the phar­ma­cy owner.

What does the con­nec­tion to the secur­Ph­arm sys­tem cost?

The cos­ts for the phar­ma­cy ser­ver amount to € 10 plus VAT per month per busi­ness pre­mi­ses.
VAT. The one-time onboar­ding fee of €125 for public phar­maci­es is cover­ed by ABDA.
for public phar­maci­es. In addi­ti­on, the­re is a fee of €20 plus VAT for each ope­ra­ting site for the neces­sa­ry cer­ti­fi­ca­te.
cer­ti­fi­ca­te with a term of 24 months.

How do I app­ly for an N-ID for the first time?

The N-Ident regis­tra­ti­on pro­ce­du­re is divi­ded into three stages. First, an account must be crea­ted at
https://ngda.de/ must be crea­ted. Then each busi­ness estab­lish­ment for which an N-ID is requi­red must be crea­ted in the account.
is requi­red must be crea­ted in the account. Final­ly, the access aut­ho­riza­ti­on must be che­cked.
To do this, the rele­vant docu­ments must be sub­mit­ted to the NGDA for veri­fi­ca­ti­on by uploa­ding the requi­red docu­ments.
uploa­ding the requi­red docu­ments. Once the docu­ments have been suc­cessful­ly che­cked,
the N-ID can be acqui­red for the busi­ness pre­mi­ses. Once pay­ment has been recei­ved, the cer­ti­fi-
cer­ti­fi­ca­te is issued. The PIN for the down­load is sent to the busi­ness pre­mi­ses by post. Sub­se­quent­ly
the cer­ti­fi­ca­te can be down­loa­ded and inte­gra­ted.
The NGDA recom­mends allo­wing a peri­od of 4 weeks for the legi­ti­miza­ti­on pro­cess descri­bed abo­ve befo­re ope­ning a phar­ma­cy.
weeks befo­re the ope­ning of a phar­ma­cy.

When do I have to re-legi­ti­mi­ze my branch?

Re-legi­ti­miza­ti­on is requi­red every 24 months in con­nec­tion with the cer­ti­fi­ca­te rene­wal in order to
to pro­ve the con­tin­ued aut­ho­riza­ti­on to use the digi­tal ser­vices.

What docu­ments are requi­red for rele­gi­ti­miza­ti­on?

Phar­ma­cy owners requi­re two docu­ments, the basic ope­ra­ting licen­se and a pro­of of ac
pro­of of acti­vi­ty. The aut­ho­riza­ti­on must be uploa­ded to the NGDA por­tal, the pro­of of acti­vi­ty
auto­ma­ti­cal­ly, as the pre­vious use of the secur­Ph­arm sys­tem in the past is reco­gni­zed.
is reco­gni­zed.
With the issue of the health pro­fes­sio­nal cards and the intro­duc­tion of the insti­tu­ti­on card (SMC-B), the (re)legitimization takes place.
(re-)legitimation will be based on the insti­tu­ti­on card ins­tead of the phar­ma­cy ope­ra­ting licen­se.
ope­ra­ting licen­se.
Infor­ma­ti­on on initi­al legi­ti­ma­ti­on can be found in ques­ti­on 2.8.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 15

Are the­re any dis­ad­van­ta­ges if I order a new cer­ti­fi­ca­te befo­re the cer­ti­fi­ca­te expi­res?
befo­re the cer­ti­fi­ca­te expi­res?

The cer­ti­fi­ca­te has a term of 24 months, which beg­ins with the first down­load. As
the pro­cess of re-legi­ti­miza­ti­on and cer­ti­fi­ca­te rene­wal takes some time, the NGDA recom
NGDA recom­mends initia­ting the cer­ti­fi­ca­te rene­wal at an ear­ly stage. The phar­macist has a built-in
phar­macist has no dis­ad­van­ta­ges if he requests a new cer­ti­fi­ca­te up to 3 months befo­re the cer­ti­fi­ca­te expi­res and acti­va­tes it accor­din­gly.
new cer­ti­fi­ca­te and acti­va­tes it accor­din­gly (down­load and inte­gra­te).
The cer­ti­fi­ca­te is only dis­play­ed as acti­ve in the NGDA por­tal after the first down­load.

How do I know when an N-ID cer­ti­fi­ca­te rene­wal is due?

NGDA informs you by e-mail in good time befo­re the cer­ti­fi­ca­te expi­res so that the orde­ring pro­cess can be initia­ted in good time.
order pro­cess can be initia­ted in good time. To recei­ve a remin­der, the
cont­act details in the NGDA por­tal for the respec­ti­ve busi­ness pre­mi­ses must be kept up to date.
It should be noted that the cer­ti­fi­ca­te does not have to be down­loa­ded from the NGDA web­site, but from the phar­ma­cy soft­ware.
soft­ware must be down­loa­ded. This requi­res the pass­word (PIN), which phar­maci­es recei­ve
phar­maci­es recei­ved by let­ter with the purcha­se of the N-ID.

What do I have to con­sider with the N-Ident pro­ce­du­re if I also ope­ra­te branch phar­maci­es?
ope­ra­te branch phar­maci­es?

A sin­gle regis­tra­ti­on in the NGDA por­tal is suf­fi­ci­ent for owners of seve­ral bran­ches.
The­re, in addi­ti­on to the main phar­ma­cy, the branch phar­maci­es can also be crea­ted as busi­ness pre­mi­ses.
pre­mi­ses. Each branch must be legi­ti­mi­zed and requi­res its own elec­tro­nic cer­ti­fi­ca­te.
cer­ti­fi­ca­te. Plea­se ensu­re that the cont­act details asso­cia­ted with the respec­ti­ve busi­ness pre­mi­ses (e.g. e-mail address) are always up to date.
e-mail address) up to date at all times.

What do I need to bear in mind if I also have a who­le­sa­le per­mit?

If you have an addi­tio­nal who­le­sa­le per­mit, you must app­ly for an addi­tio­nal who­le­sa­le N-ID.
must be appli­ed for. The N-Ident regis­tra­ti­on pro­ce­du­re is simi­lar to that for a phar­ma­cy N-ID and can be crea­ted in the same account.
account. The addi­tio­nal N-ID is neces­sa­ry becau­se with a who­le­sa­le aut­ho­riza­ti­on
other acti­vi­ties can be car­ri­ed out in the secur­Ph­arm sys­tem (e.g. set­ting the sta­tus of a pack to “expor­ted”).
“expor­ted”). An over­view of the aut­ho­riza­ti­ons, which actor can set which sta­tus
can set can be found under ques­ti­on: 3.46.

What do I have to bear in mind if I give up or clo­se my phar­ma­cy?

The cur­rent owner of the phar­ma­cy ter­mi­na­tes the cer­ti­fi­ca­te of the ope­ra­ting cen­ter, sta­ting the ter­mi­na­ti­on date.
date of ter­mi­na­ti­on. The noti­ce of ter­mi­na­ti­on is sent by e-mail to kuendigung@ngda.de, sta­ting the
num­ber (APOxxxxxxx), the full address and the date of ter­mi­na­ti­on.
date of ter­mi­na­ti­on. Plea­se note that, if pos­si­ble, the e-mail should be sent from the same address
as the e-mail address of the N-Ident account hol­der. An employee of NGDA will check the ter­mi­na­ti­on
the ter­mi­na­ti­on and then initia­te all the neces­sa­ry steps.
initia­ted.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 16

I have taken over a phar­ma­cy, can I also take over the N-ID?

The exis­ting N-ID cer­ti­fi­ca­te can­not be trans­fer­red. The regis­tra­ti­on for an exis­ting phar­ma­cy
exis­ting phar­ma­cy can take place in two ways:
” The new owner has not yet regis­tered a phar­ma­cy with the NGDA.
In this case, the regis­tra­ti­on of an N-Ident account inclu­ding the crea­ti­on of the busi­ness pre­mi­ses is neces­sa­ry.
neces­sa­ry.
” The new owner alre­a­dy has one or more phar­maci­es.
In this case, a new busi­ness pre­mi­ses must be crea­ted within the NGDA por­tal.

I have taken over/established a phar­ma­cy, but do not yet have a phar­ma­cy ope­ra­ting
licen­se. How can I app­ly for my N-ID?

If you do not yet have a valid phar­ma­cy ope­ra­ting licen­se at the time of the legi­ti­ma­ti­on request
per­mit, you can app­ly for legi­ti­miza­ti­on as a phar­ma­cy with reser­va­tions. The fol­lo­wing docu­ments are requi­red
the fol­lo­wing docu­ments are requi­red:
” the sub­mis­si­on of a copy of the appli­ca­ti­on for a phar­ma­cy ope­ra­ting licen­se and the
Pro­of of per­mis­si­on to ope­ra­te a phar­ma­cy.
This pro­of can be
” by means of a copy of the Ger­man licen­se to prac­ti­ce phar­ma­cy or
” a cer­ti­fi­ca­te of good repu­te from a cham­ber of phar­macists that is not older than 6 months
or
” the invoice of a valid cer­ti­fi­ca­te from ano­ther busi­ness estab­lish­ment.
In this case, the appli­cant and reci­pi­ent must be iden­ti­cal.
The legi­ti­miza­ti­on is then limi­t­ed to 6 weeks. Within this peri­od, a cur­rent
ope­ra­ting licen­se must be sub­mit­ted to can­cel this time limit. This pre­sen­ta­ti­on is made in the
the same way as for regis­tra­ti­on by sen­ding the copy to the NGDA using the cover sheet from the
cover sheet from the N-Ident por­tal.

Why do I recei­ve a PIN let­ter?

To purcha­se the N-ID cer­ti­fi­ca­te, the phar­macist recei­ves a let­ter with a pass­word (PIN).
Tog­e­ther with the cor­re­spon­ding N-ID (e.g. APOxxxxxxx), this PIN is requi­red to down­load and unpack the cer­ti­fi­ca­te.
and unpack­ing the cer­ti­fi­ca­te. For this action, most soft­ware ven­dors have deve­lo­ped a
soft­ware pro­vi­ders have crea­ted a func­tion in the mer­chan­di­se manage­ment sys­tem for this action. As soon as the cor­re­spon­ding soft­ware update
is instal­led, the N-ID can be inte­gra­ted into the soft­ware. Only after the first down­load
the cer­ti­fi­ca­te is also dis­play­ed as acti­ve in the NGDA por­tal.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 17

The access data should be stored secu­re­ly, as they are used not only for cer­ti­fi­ca­te rene­wal
also for the web inter­face of the secur­Ph­arm phar­ma­cy ser­ver (www.securpharm-gui.ngda.de/)
are requi­red.

How often can I down­load the cer­ti­fi­ca­te?

The cer­ti­fi­ca­te can be down­loa­ded up to three times with the cur­rent licen­se. For the
For the mer­chan­di­se manage­ment sys­tem in the phar­ma­cy, it is suf­fi­ci­ent to down­load the cer­ti­fi­ca­te once. The
phar­ma­cy soft­ware can then access the secur­Ph­arm sys­tem from all work­sta­tions within a busi­ness pre­mi­ses.
access the secur­Ph­arm sys­tem.

My down­load did not work, what do I have to con­sider?

The NGDA has published the fol­lo­wing ins­truc­tions for down­loa­ding the N-ID cer­ti­fi­ca­te:
” It is pos­si­ble to down­load the cer­ti­fi­ca­te three times, fai­led attempts due to incor­rect ent­ry
of the N-ID (APO num­ber) or incor­rect PIN ent­ry will not be coun­ted. The spel­ling of the
N-ID with upper or lower case let­ters is irrele­vant.
” Cer­ti­fi­ca­te down­loads are not blo­cked if a sub­scri­ber enters the wrong PIN three times.
three times.
” If a P=N is unclear (pos­si­bi­li­ty of con­fu­sing “O” and “0” or “l” and “=”), the cor­rect PIN can be deter­mi­ned by tri­al and error.
cor­rect PIN can be deter­mi­ned by tri­al and error.
” NGDA does not know the respec­ti­ve PINs and is the­r­e­fo­re unfort­u­na­te­ly unable to pro­vi­de any assis­tance.
” Plea­se note that any exis­ting secu­ri­ty infra­struc­tu­re - such as a fire­wall - can also pre­vent the down­load.
a fire­wall - can pre­vent the down­load.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 18

3. ques­ti­ons about secur­Ph­arm in ever­y­day phar­ma­cy life

How can I reco­gni­ze a pre­scrip­ti­on-only medi­ci­ne?

As a rule of thumb, with a few excep­ti­ons, the fol­lo­wing appli­es: Pre­scrip­ti­on-only medi­cinal pro­ducts are
sub­ject to veri­fi­ca­ti­on, i.e. they must be che­cked with the secur­Ph­arm sys­tem.
Medi­cinal pro­ducts requi­ring veri­fi­ca­ti­on can also be reco­gni­zed by the Data Matrix Code
and the data iden­ti­fiers (PC, SN, LOT, EXP).
The IFA data­ba­se or the ABDA artic­le mas­ter pro­vi­des pre­cise infor­ma­ti­on on the veri­fi­ca­ti­on obli­ga­ti­on.
artic­le mas­ter. The pharmacy’s mer­chan­di­se manage­ment sys­tem should, if it uses the ABDA
artic­le mas­ter, the pharmacy’s mer­chan­di­se manage­ment sys­tem should reco­gni­ze whe­ther the pro­duct is sub­ject to veri­fi­ca­ti­on.
Excep­ti­ons to the veri­fi­ca­ti­on and wri­te-off obli­ga­ti­on can be found under ques­ti­on: 1.8

If all the medi­ci­nes I dis­pen­se that are sub­ject to veri­fi­ca­ti­on are scan­ned, does the phar­maceu­ti­cal indus­try
will the phar­maceu­ti­cal indus­try learn about my sales figu­res?

No, not at all. secur­Ph­arm is based on the prin­ci­ple of sepa­ra­te data­ba­ses for phar­maceu­ti­cal com­pa­nies and phar­maci­es.
phar­maceu­ti­cal com­pa­nies and phar­maci­es. The phar­ma­cy ser­ver to which your phar­ma­cy soft­ware is con­nec­ted
phar­ma­cy soft­ware is con­nec­ted to, anony­mi­zes every tran­sac­tion so that no one knows whe­re the medi­ci­ne was dis­pen­sed.
was dis­pen­sed.

I have a pack in front of me wit­hout a Data Matrix code. How do I deal with it?

Scan the bar­code (“Code 39”). The mer­chan­di­se manage­ment sys­tem will, if it can access the
the ABDA artic­le mas­ter, will tell you whe­ther this pack must have a Data Matrix code or whe­ther it is a stock item.
or whe­ther it is a stock item that was pla­ced on the mar­ket befo­re Febru­ary 9, 2019.
was pla­ced on the mar­ket.

Is it suf­fi­ci­ent to scan the PZN bar­code ins­tead of the Data Matrix code?

No, becau­se the pre­vious PZN bar­code only con­ta­ins the PZN in machi­ne-rea­da­ble form.
In addi­ti­on to the PZN, the Data Matrix Code also con­ta­ins the seri­al num­ber of the pack, which is used for verification/authenticity checks.
which is used for verification/authenticity checks against the data­ba­se. In addi­ti­on to the
the pro­duct code, the batch desi­gna­ti­on and the expiry date are also trans­mit­ted in the Data Matrix Code.
so that the­se can be recor­ded elec­tro­ni­cal­ly in the mer­chan­di­se manage­ment sys­tem in future. With
With the intro­duc­tion of the Data Matrix Code, the­re is also no lon­ger an obli­ga­ti­on to app­ly the Code 39
on the pack.

What fea­tures must be prin­ted on the pack (in plain text)?

Packs sub­ject to man­da­to­ry veri­fi­ca­ti­on must bear two secu­ri­ty fea­tures: a first-ope­ning
first-ope­ning pro­tec­tion and a Data Matrix Code. In plain text, the data ele­ments
Pro­duct code (PC), seri­al num­ber (SN), batch desi­gna­ti­on (LOT or CH.-B.) and the
expiry date (EXP, use by, use by) must be appli­ed. Excluded from the regu­la­ti­on
are par­ti­cu­lar­ly small packs. Fur­ther infor­ma­ti­on can be found on the IFA web­site.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 19

A medi­ci­ne has been veri­fied and boo­ked out. What should I do if I want to take this medi­ci­ne
want to take it back?

The Dele­ga­ted Regu­la­ti­on gene­ral­ly sti­pu­la­tes that packs who­se sta­tus has been set to “dis­pen­sed“
may be retur­ned within 10 calen­dar days as long as the pharmacy’s con­trol area has not been
the con­trol­led area of the phar­ma­cy has not been left. For the return of medi­cinal pro­ducts
The pro­vi­si­ons of the Phar­ma­cy Ope­ra­ting Regu­la­ti­ons con­ti­nue to app­ly to the taking back of medi­cinal pro­ducts,
as befo­re, is the respon­si­bi­li­ty of the phar­macist.

Can a medi­ci­ne that has been boo­ked out be boo­ked back in if the pati­ent was not found at a phar­ma­cy ser­vice?
not found during a cou­rier ser­vice?

Yes, the cou­rier ser­vice is in the pharmacy’s con­trol area, so a medi­ci­ne that has alre­a­dy been boo­ked out can be retur­ned to the phar­ma­cy within 10 days.
can be boo­ked back into the sys­tem within 10 days.

Why can’t I check and wri­te off a pack when I recei­ve it?

The Dele­ga­ted Regu­la­ti­on sti­pu­la­tes that the authen­ti­ci­ty check must be car­ri­ed out “at the time of sup­p­ly to the public”.
time of dis­pen­sing to the public”, i.e. to the pati­ent. Only the check
only the check imme­dia­te­ly befo­re dis­pen­sing ensu­res that the latest infor­ma­ti­on can be used for the
infor­ma­ti­on can be used for the authen­ti­ci­ty check, e.g. becau­se a batch may have been recal­led in the mean­ti­me or
the pack has alre­a­dy been dis­pen­sed in ano­ther phar­ma­cy.

Can I also scan the Data Matrix code of each pack when I recei­ve the goods and use it for veri­fi­ca­ti­on?
veri­fy it?

We recom­mend veri­fy­ing the Data Matrix code of each pack when the goods are recei­ved in order to
pos­si­ble pro­blems at an ear­ly stage. It is important that the pack is not remo­ved from the sys­tem
sys­tem so that the sta­tus remains acti­ve. In accordance with
veri­fied (again) imme­dia­te­ly befo­re dis­pen­sing to the pati­ent in accordance with legal requi­re­ments
and the uni­que iden­ti­fier must be deac­ti­va­ted.

What hap­pens when I scan the bar­code?

When you scan the bar­code, your mer­chan­di­se manage­ment sys­tem, pro­vi­ded it uses the ABDA
artic­le mas­ter, checks whe­ther it is a pro­duct sub­ject to veri­fi­ca­ti­on and assigns the bar­code to the pro­duct.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 20

in this case that you must scan the Data Matrix Code.

What data does the Data Matrix Code con­tain?

The Data Matrix Code con­ta­ins the pro­duct code, which in turn con­ta­ins the PZN, as well as a
seri­al num­ber, batch num­ber and expiry date.

Is the­re a pre­scri­bed sequence for the infor­ma­ti­on in plain text?

No. Phar­maceu­ti­cal com­pa­nies are free to choo­se the order of the data ele­ments as long as the requi­red
long as the requi­red data ele­ments pro­duct code, seri­al num­ber, batch num­ber and expiry date are included.
expiry date are included. If the dimen­si­ons of the pack­a­ging allow, the human-rea­da­ble data
human-rea­da­ble data ele­ments are loca­ted next to the Data Matrix Code.

How can I tell which Data Matrix Code I need to scan for the authen­ti­ci­ty check?
if the­re are seve­ral Data Matrix Codes on the pack?

If the­re are seve­ral Data Matrix Codes on a pack, the Data Matrix Code for the authen­ti­ci­ty check is next to the Data
Matrix Code for the authen­ti­ci­ty check is mark­ed PPN.

Can a phar­ma­cy dis­pen­se a medi­ci­ne wit­hout pri­or veri­fi­ca­ti­on if, for exam­p­le, the In-
ter­net, the secur­Ph­arm sys­tem or the power fails?

In the event of tem­po­ra­ry tech­ni­cal faults at the time of dis­pen­sing, Artic­le 29 of the Dele­ga­ted
ordi­nan­ce, it is per­mit­ted to dis­pen­se medi­ci­nes (after a sen­so­ry check and in the absence of a suspec­ted
suspec­ted case of coun­ter­feit­ing) and to car­ry out the veri­fi­ca­ti­on and wri­te-off sub­se­quent­ly,
as soon as the faults have been rec­ti­fied. Most soft­ware pro­ducts can send requests to the
secur­Ph­arm sys­tem. This means that the requests are coll­ec­ted and a return
is given as soon as the sys­tem is available again. In order to pre­vent fre­quent
fal­se alarms due to dou­ble log­out attempts, repea­ted log­out attempts should be avo­ided.
attempts should be avo­ided.
If the buf­fer func­tion is unavailable, the packa­ges issued during this time must be boo­ked out manu­al­ly.
cked out manu­al­ly (sub­se­quent­ly if neces­sa­ry). To do this, the seri­al num­ber and pro­duct
num­ber and the pro­duct code must be noted (or pho­to­gra­phed) befo­re dis­pen­sing and the pack sub­se­quent­ly
be boo­ked out manu­al­ly. You can then per­form the manu­al veri­fi­ca­ti­on and wri­te-off as soon as
the fault has been rec­ti­fied and the secur­Ph­arm sys­tem is available again, via the gra­phi­cal user inter­face of the secur­Ph­arm sys­tem.
user inter­face of the secur­Ph­arm phar­ma­cy ser­ver (GUI) (https://securpharm-gui.ngda.de/).
to take.

May the first-ope­ning pro­tec­tion be ope­ned for a ran­dom test of finis­hed medi­cinal pro­ducts in the phar­ma­cy?
be ope­ned in the phar­ma­cy?

As befo­re, phar­macists may open the pack with the tam­per-evi­dent seal for test­ing pur­po­ses if they
for test­ing pur­po­ses if they mark the pack accor­din­gly after a posi­ti­ve test. This labe­l­ing
This labe­l­ing must be explai­ned to the pati­ent befo­re dis­pen­sing if neces­sa­ry. Befo­re ope­ning the pack
the safe­ty fea­tures must be che­cked. Howe­ver, the uni­que iden­ti­fier may only be deac­ti­va­ted when
be deac­ti­va­ted until it is dis­pen­sed to the pati­ent.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 21

What exact­ly do I have to do as a phar­macist?

Sin­ce Febru­ary 9, 2019, phar­macists have had to deac­ti­va­te the secu­ri­ty fea­tures (first-ope­ning pro­tec­tion and
indi­vi­du­al iden­ti­fier) of medi­cinal pro­ducts sub­ject to man­da­to­ry veri­fi­ca­ti­on befo­re dis­pen­sing them to pati­ents.
to the pati­ent. This means that the uni­que iden­ti­fier must be scan­ned and
scan­ned and boo­ked out (deac­ti­va­ted) befo­re dis­pen­sing to the pati­ent. The first-ope­ning pro­tec­tion must also be
also be che­cked for inte­gri­ty by means of a simp­le visu­al inspec­tion. Medi­ci­nes sub­ject to veri­fi­ca­ti­on
are basi­cal­ly all pre­scrip­ti­on-only medi­cinal pro­ducts that have been available from the manu­fac­tu­rer sin­ce
released for sale by the manu­fac­tu­rer sin­ce Febru­ary 9, 2019.

Why should the first veri­fi­ca­ti­on take place upon receipt of goods?

The first veri­fi­ca­ti­on upon receipt of goods has two main advan­ta­ges. On the one hand, phar­maci­es can
first­ly, phar­maci­es can orga­ni­ze their mer­chan­di­se manage­ment effi­ci­ent­ly, as the batch desi­gna­ti­on and expiry date for the
no lon­ger ente­red by hand, but can be scan­ned tog­e­ther with the PZN.
can be scan­ned tog­e­ther with the PZN. On the other hand, a scan at goods inwards can be used to iden­ti­fy non-dis­pensable
can be reco­gni­zed at an ear­ly stage - and not only in the pre­sence of the pati­ent - and assi­gned to the cor­re­spon­ding sup­pli­er.
assi­gned to the appro­pria­te sup­pli­er. This allows pro­blems to be sol­ved more imme­dia­te­ly and pro­ces­ses can be
pro­ces­ses can run in a more struc­tu­red way, which also redu­ces the likeli­hood of, for exam­p­le, dou­ble check-outs and asso­cia­ted alarms.
and the asso­cia­ted alarms.

In the hust­le and bust­le, it can hap­pen that a pack is scanned/verified twice by mista­ke.
twice. Have I des­troy­ed the dis­pen­sing capa­bi­li­ty?

No. The Data Matrix code of a pack can be veri­fied by scan­ning as often as requi­red.
Howe­ver, it is important that you only veri­fy the pack and do not book it out of the sys­tem.
i.e. deac­ti­va­te the indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture. Howe­ver, if this error
error, you can cor­rect it within 10 days. The Dele­ga­ted Regu­la­ti­on
The Dele­ga­ted Regu­la­ti­on sti­pu­la­tes that packs who­se sta­tus has been set to “dis­pen­sed” and which have not left the
trol­led area of the phar­ma­cy can be retur­ned within 10 days in the same estab­lish­ment.
may be retur­ned to the same site within 10 days.

Does secur­Ph­arm also have advan­ta­ges for my mer­chan­di­se manage­ment?

Yes, the scan of the Data Matrix code enables the regu­lar trans­fer of batch desi­gna­ti­ons and expiry dates to the ERP sys­tem.
and expiry date into the mer­chan­di­se manage­ment sys­tem and the clear assign­ment of a drug detec­ted as not
to the respec­ti­ve sup­pli­er. With secur­Ph­arm, batch and expiry date are available for all
and expiry dates are available in machi­ne-rea­da­ble form for all medi­ci­nes sub­ject to man­da­to­ry veri­fi­ca­ti­on.

What is the pro­ce­du­re for dis­pen­sing par­ti­al quan­ti­ties?

If the dis­pen­sing of par­ti­al quan­ti­ties is pre­scri­bed, the pack must be boo­ked out when it is first ope­ned.
be boo­ked out. As part of its con­tents have been dis­pen­sed, it can­not be boo­ked in again.
boo­ked in again. Howe­ver, the rest of the pack remains gene­ral­ly mar­ke­ta­ble and can, with a cor­re­spon­ding par­ti­al quan­ti­ty pre­scrip­ti­on, be boo­ked in again.
can be dis­pen­sed in this phar­ma­cy with a cor­re­spon­ding par­ti­al quan­ti­ty pre­scrip­ti­on.

May the pack data be prin­ted in white let­ters on a black back­ground (inver­se)?

Yes, the Data Matrix Code and the plain text infor­ma­ti­on may be prin­ted in white on a black back­ground.
on a black back­ground is per­mit­ted. A sui­ta­ble and cor­rect­ly adjus­ted scan­ner is capa­ble of rea­ding all appro­ved
read all appro­ved dis­play for­mats.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 22

A pack has rea­ched its expiry date. Does it have to be writ­ten off when it is des­troy­ed?

No, the pack does not have to be dere­gis­tered as this is done auto­ma­ti­cal­ly by the sys­tem at the time of expiry.
auto­ma­ti­cal­ly at the time of expiry. If a pack that requi­res veri­fi­ca­ti­on is des­troy­ed befo­re the expiry date, it must be
expiry date, it must be dere­co­gni­zed.

How do you deal with coded inven­to­ry goods that were uploa­ded for test pur­po­ses befo­re the man­da­to­ry ope­ra­ti­on?
for test pur­po­ses befo­re man­da­to­ry ope­ra­ti­on?

Inven­to­ry goods are goods that were released for dis­tri­bu­ti­on by the manu­fac­tu­rer befo­re Febru­ary 9, 2019
for cir­cu­la­ti­on by the manu­fac­tu­rer befo­re 9 Febru­ary 2019, but which bear secu­ri­ty fea­tures that have
have been appli­ed for test pur­po­ses. The­se can cau­se fal­se alarms in the sys­tem under cer­tain cir­cum­s­tances. The pro­por­ti­on of
of coded stock has alre­a­dy fal­len signi­fi­cant­ly, so the pro­blem should occur less fre­quent­ly.
should occur less fre­quent­ly. Accor­ding to the dele­ga­ted regu­la­ti­on, the­se goods can gene­ral­ly be dis­po­sed of, pro­vi­ded the­re are no other
reasons to the con­tra­ry.

Does a phar­ma­cy have to wri­te off mar­ke­ta­ble packs that it wants to return to who­le­sa­lers before­hand?
to who­le­sa­lers before­hand?

No. By dere­gis­tering from the secur­Ph­arm sys­tem, the safe­ty fea­ture of a pack is de-
acti­va­ted, which means it loses its mar­ke­ta­bi­li­ty. In the case of a pack that is to be retur­ned to the who­le­sa­ler
who­le­sa­lers, the safe­ty fea­ture must the­r­e­fo­re not be deac­ti­va­ted if the pack is to remain mar­ke­ta­ble.
the pack is to remain mar­ke­ta­ble.

May secur­Ph­arm e. V. pro­vi­de phar­maci­es with logs with pack data from the secur­Ph­arm sys­tem, e.g. if they want to know whe­ther they have alre­a­dy che­cked and boo­ked out a pack or not?
or not?

No. Accor­ding to the requi­re­ments of the Dele­ga­ted Regu­la­ti­on, secur­Ph­arm e. V. is allo­wed to send logs with pack
cked data from the secur­Ph­arm sys­tem only to aut­ho­ri­ties.

What is the dif­fe­rence bet­ween veri­fy­ing and wri­ting off a pack?

Veri­fi­ca­ti­on is used to check the sta­tus of the pack, wher­eby the read-out or manu­al­ly
manu­al­ly ente­red pack data is com­pared with the pack data stored in the sys­tem.
stored in the sys­tem. A dis­play reflects the sta­tus of the pack. A pack can be veri­fied as often as requi­red.
veri­fied as often as requi­red.
The wri­te-off (dis­pen­sing) descri­bes the sta­tus chan­ge of an indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture
from “dis­pensable” or “acti­ve” to “dis­pen­sed” or “inac­ti­ve”. The dere­co­gni­ti­on the­r­e­fo­re deac­ti­va­tes
the indi­vi­du­al iden­ti­fi­ca­ti­on fea­ture. Mul­ti­ple wri­te-offs lead to an alarm.
Veri­fi­ca­ti­on can be used to check the sta­tus of a pack, while dere­co­gni­ti­on chan­ges the sta­tus of a pack.
chan­ges the sta­tus of a pack.

How do I know if my scan­ner is sui­ta­ble and working pro­per­ly?

NGDA has deve­lo­ped a scan­ner test that should be used to check the set­tings of all scan­ners.
should be che­cked. The con­fi­gu­ra­ti­on of the scan­ners is important, as this is the only way to ensu­re that the data is
read out and trans­mit­ted cor­rect­ly during scan­ning.
With incor­rect­ly con­fi­gu­red scan­ners, it is often obser­ved that the lan­guage set­ting trig­gers alarms.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 23

trig­gers. For exam­p­le, an Eng­lish lan­guage set­ting is often pre­set, so that Y and Z are swap­ped when rea­ding out.
Y and Z are swap­ped when rea­ding. In addi­ti­on, incor­rect­ly set scan­ners can cau­se errors when
errors in the trans­mis­si­on of upper and lower case let­ters. Incor­rect­ly read inver­se codes
(white on a dark back­ground) are also a fre­quent source of errors that can be avo­ided by con­fi­gu­ring the scan­ner.
can be avo­ided by con­fi­gu­ring the scan­ner.
To ensu­re that the scan­ners in your faci­li­ty can read the Data Matrix code cor­rect­ly, plea­se test all scan­ners.
cor­rect­ly, plea­se test all scan­ners (e.g. inco­ming goods and HV). If you noti­ce any anoma­lies
or if you have any ques­ti­ons about the con­fi­gu­ra­ti­on of the scan­ner, the scan­ner manu­fac­tu­rer or sup­pli­er can
of the scan­ner can pro­vi­de assis­tance.
The scan­ner test is available in the secur­Ph­arm GUI or at https://www.abda.de/sp .

Can my order picker scan the Data Matrix code?

The sup­pli­er of the order picker is the first point of cont­act. Many pro­vi­ders offer
cor­re­spon­ding updates and con­ver­si­ons.

How long do I have to wait until I recei­ve a respon­se from the sys­tem after a scan?
recei­ve?

The Dele­ga­ted Regu­la­ti­on sti­pu­la­tes that the respon­se time of the sys­tem must be less than 300 mil­li­se­conds for at least 95% of queries.
queries must be less than 300 mil­li­se­conds.
The per­for­mance of the data sto­rage sys­tem must enable phar­maci­es to car­ry out their acti­vi­ties wit­hout signi­fi­cant
car­ry out their acti­vi­ties wit­hout any signi­fi­cant delay. Howe­ver, the respon­se time from the pharmacist’s per­spec­ti­ve is also influen­ced by the
Inter­net con­nec­tion bet­ween a veri­fy­ing body and the phar­ma­cy sys­tem as well as the inter­nal
inter­nal infra­struc­tu­re at the veri­fy­ing site, so that the total dura­ti­on of the request can exceed 300 mil­li­se­conds.
query can exceed 300 mil­li­se­conds
If a respon­se takes a dis­pro­por­tio­na­te­ly long time, you can check the avai­la­bi­li­ty of the
secur­Ph­arm sys­tem at www.securpharm-status.de/.
Main­ten­an­ce work on the sys­tem is announ­ced on the secur­Ph­arm web­site and in the ABDA news­room.
announ­ced.
If you want to book out a phar­maceu­ti­cal and the secur­Ph­arm sys­tem, the Inter­net or the
elec­tri­ci­ty is not available, plea­se refer to ques­ti­on 3.14.

I am not sure whe­ther I have alre­a­dy had the pack in my hand. What opti­ons are the­re for che­cking
are the­re?

Plea­se note that you can check the pack sta­tus again at any time (veri­fi­ca­ti­on) in order to obtain infor­ma­ti­on about the pack.
obtain infor­ma­ti­on about the pack.
Many soft­ware com­pa­nies offer the opti­on of using their soft­ware to check pre­vious actions in con­nec­tion with the dele­ga­ted
in con­nec­tion with the Dele­ga­ted Regu­la­ti­on (sta­tus check and chan­ge).
to under­stand. This check is car­ri­ed out via a pro­to­col or log file. If you have any ques­ti­ons about this
plea­se cont­act your soft­ware manu­fac­tu­rer.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 24

How is the 10-day char­ge­back peri­od cal­cu­la­ted?

The char­ge­back peri­od beg­ins at the time of the wri­te-off and ends exact­ly after 10 calen­dar days at the same time.
days at the same time.

What aspects must be taken into account when making a char­ge­back?

A char­ge­back must be made within the 10-day char­ge­back peri­od and may only be car­ri­ed out if the pack
only be car­ri­ed out if the pack has not left the pharmacy’s con­trol area.
has left the phar­ma­cy. =Once the sta­tus of the pack has been set to “sto­len” or “des­troy­ed”, a char­ge­back is no lon­ger pos­si­ble.
no lon­ger pos­si­ble. NGDA has no influence on the char­ge­back and can­not reac­ti­va­te the pack or chan­ge the sta­tus.
can­not reac­ti­va­te the packa­ge or extend the expiry date.
Plea­se also con­sider ques­ti­on 3.7 on the sub­ject of the con­trol area and cou­rier ser­vice.

When do hos­pi­tal phar­maci­es have to dere­co­gni­ze?

In Artic­le 25 (2) of the Dele­ga­ted Regu­la­ti­on, hos­pi­tal phar­maci­es are given grea­ter free­dom for the
phar­maci­es a grea­ter degree of free­dom for the time of dere­co­gni­ti­on. They are not obli­ged to book out imme­dia­te­ly befo­re
to the pati­ent, but may do so at any time during which the medi­cinal pro­duct is in their phy­si­cal pos­ses­si­on,
time at which the medi­ci­ne is in their phy­si­cal pos­ses­si­on. Howe­ver, the con­di­ti­on is that
the medi­cinal pro­duct is not sold bet­ween deli­very and dis­pen­sing to the pati­ent.
3.35 When do phar­maci­es sup­p­ly­ing hos­pi­tals have to dere­gis­ter?
The Fede­ral Minis­try of Health has sta­ted that the­re is no Euro­pean Com­mis­si­on
Com­mis­si­on on the inter­pre­ta­ti­on of Artic­le 25 (2) of the Dele­ga­ted Regu­la­ti­on imple­men­ting the Fal­si­fied Medi­ci­nes Direc­ti­ve.
the Fal­si­fied Medi­ci­nes Direc­ti­ve. It is under dis­cus­sion whe­ther phar­maci­es sup­p­ly­ing hos­pi­tals - and
phar­maci­es - as well as hos­pi­tal phar­maci­es sup­p­ly­ing other hos­pi­tals - can also sell phy­si­cal­ly pos­s­es­sed
phar­maci­es - as well as hos­pi­tal phar­maci­es sup­p­ly­ing other hos­pi­tals - are allo­wed to wri­te off medi­ci­nes in their phy­si­cal pos­ses­si­on at any time befo­re their first use. This
equa­li­ty with hos­pi­tal phar­maci­es had been sought by the Ger­man side.
Accor­din­gly, the decis­i­on is now to be made by the com­pe­tent super­vi­so­ry aut­ho­ri­ty.
aut­ho­ri­ty. It will have to be deci­ded whe­ther, on the basis of a sup­p­ly con­tract, the inter­pre­ta­ti­on
that no sale takes place and Artic­le 25 (2) of the Dele­ga­ted Regu­la­ti­on is appli­ca­ble.
Regu­la­ti­on is appli­ca­ble.

Can the “des­troy­ed” or “sto­len” sta­tus be rever­sed?

No, the “des­troy­ed” or “sto­len” sta­tus can­not be reset. The packa­ge may
no lon­ger be included in the sales stock.

I have orde­red the wrong medi­ci­ne and would like to return it to the sup­pli­er.
Do I have to veri­fy and wri­te off the medi­ci­ne before­hand?

No, the medi­ci­ne must not be writ­ten off, as the sta­tus of the pack in the sys­tem remains
must remain “dis­pensable” (acti­ve) in the sys­tem. In addi­ti­on, the pack must not have been ope­ned.
The sup­pli­er will check the sta­tus and inte­gri­ty of the first-ope­ning pro­tec­tion when the pack is retur­ned.
of the pack.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 25

How do I deal with recalls?

Do not deac­ti­va­te the pack if you return it to the phar­maceu­ti­cal who­le­sa­ler or com­pa­ny for dis­po­sal.
who­le­sa­ler or com­pa­ny for dis­po­sal, unless you are expli­cit­ly reques­ted to do so.
Only set the sta­tus of a pack to “Des­troy­ed” if you are dis­po­sing of it yours­elf.
Plea­se note that the sta­tus chan­ge to “Des­troy­ed”, just like “Theft”, can­not be rever­sed.
can­not be rever­sed.

What do I do with packs that have pas­sed their expiry date?

If the expiry date has been rea­ched, the sys­tem auto­ma­ti­cal­ly chan­ges the sta­tus from acti­ve to
inac­ti­ve. The­r­e­fo­re, no dere­co­gni­ti­on may take place befo­re dis­po­sal. If the pack is nevert­hel­ess
is nevert­hel­ess boo­ked out befo­re dis­po­sal, an alarm is trig­ge­red. Veri­fi­ca­ti­on to check the sta­tus
of the sta­tus is still pos­si­ble wit­hout risk. The secur­Ph­arm sys­tem then responds with the
that the expiry date has been excee­ded and the pack must not be dis­po­sed of.

What do I have to con­sider when dis­po­sing of a dama­ged pack?

If the pack has been dama­ged in the phar­ma­cy to such an ext­ent that it can no lon­ger be dis­pen­sed, the code
the code must be remo­ved from the sys­tem befo­re dis­po­sal.

The sys­tem does not respond or only responds with an error mes­sa­ge. How do I reco­gni­ze whe­ther
the secur­Ph­arm sys­tem is acces­si­ble?

You can check the ope­ra­ting sta­tus of the secur­Ph­arm sub­sys­tems at www.securpharm-status.de
.

What do I have to bear in mind when medi­ci­nes are dis­pen­sed to other phar­maci­es by way of
phar­maci­es?

§ Sec­tion 17 para. 6c sen­tence 1 no. 5 ApBe­trO per­mits the sup­p­ly of other phar­maci­es in urgent cases.
In this case, the sup­p­ly­ing phar­ma­cy veri­fies the pack befo­re pas­sing it on, but does not book it out.
out. The recei­ving phar­ma­cy also veri­fies the sta­tus and then books the pack during the dis­pen­sing pro­cess.
from the sys­tem during the dis­pen­sing pro­cess. The docu­men­ta­ti­on obli­ga­ti­on from Sec­tion 17 Para. 6c Sen­tence
2 ApBe­trO (batch num­ber) is met by sto­ring the veri­fi­ca­ti­on result in the phar­ma­cy sys­tems.
phar­ma­cy sys­tems.

Do I have to wri­te off packs when I deli­ver them to my branch phar­ma­cy?

No, as with the pre­vious ques­ti­on, the packa­ges are dere­co­gni­zed at the branch phar­ma­cy when they are dis­pen­sed to the pati­ent.
the pati­ent.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 26

Who can help me with ques­ti­ons and pro­blems?

3.45 It is not clear to me whe­ther I am per­forming a veri­fi­ca­ti­on or wri­te-off with the scan. What can
can I do?
Depen­ding on the soft­ware solu­ti­on and scan­ner set­tings, scan­ning the packa­ge can trig­ger a veri­fi­ca­ti­on
or a wri­te-off. The distinc­tion bet­ween veri­fi­ca­ti­on (as often as requi­red) and
wri­te-off (once) is fun­da­men­tal for the use of the secur­Ph­arm sys­tem. In case of doubt
to find out which pro­cess is trig­ge­red, the­re are various pro­ce­du­res:
- Con­sult the manual/instructions of the scan­ner supplier/provider or the soft­ware.
- To test the scan­ner, see ques­ti­ons 3.28 and 4.3.
- https://securpharm-gui.ngda.de/, alarm moni­to­ring sys­tem and look at the key figu­res.
If alarms occur fre­quent­ly due to dou­ble wri­te-offs (PCK_19), this indi­ca­tes hand­ling errors.
hand­ling errors.
- Obser­ve one-time exe­cu­ti­on of the function/scan and feed­back. The packa­ge should be
be dis­play­ed as “active/deliverable” during veri­fi­ca­ti­on. Recei­ve this feed­back,
this function/scan trig­gers a simp­le veri­fi­ca­ti­on. Howe­ver, if you recei­ve the
feed­back: Dere­gis­tra­ti­on suc­cessful / packa­ge set to inac­ti­ve, a
wri­te-off pro­cess has been trig­ge­red. Taking into account the requi­re­ments of the Dele­ga­ted
Regu­la­ti­on, you can post the packa­ge back again in this case. Plea­se also note
that many soft­ware com­pa­nies offer the opti­on of using their soft­ware to
actions in con­nec­tion with the Dele­ga­ted Regu­la­ti­on (sta­tus check and chan­ge).
chan­ge). This check is car­ri­ed out via a pro­to­col or log file.
If you have any ques­ti­ons about the dis­play in the soft­ware, plea­se cont­act your pro­vi­der. If you

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 27

If you have any ques­ti­ons regar­ding the con­ver­si­on of the scan­ner, plea­se cont­act the provider/supplier of the
scan­ner.
3.46 How can I reach the NGDA help­desk?
You can reach the NGDA help­desk at https://ngda.de/kontakt.php.
Alter­na­tively, you can cont­act the help­desk by e-mail, sta­ting a descrip­ti­on of the pro­blem, the N-
ID (e.g. APOxxxxxxx) and the pack data (pro­duct code, seri­al num­ber, batch and expiry date).
expiry date).
Plea­se note that the pro­ces­sing of each request is time-con­sum­ing and the NGDA does not pro­vi­de any
sta­tus chan­ge (alarm sta­tus, pack sta­tus). It is the­r­e­fo­re advi­sa­ble to
making cont­act
- Cont­act the secur­Ph­arm GUI at https://securPharm-gui.ngda.de/
As well as having che­cked the fol­lo­wing docu­ments for a solu­ti­on to the pro­blem:
- ABDA secur­Ph­arm FAQ
- secur­Ph­arm alarm mes­sa­ge: Pro­ce­du­re in the phar­ma­cy (PDF)
- Cont­act points (see below)

3.47 Which actor can set which pack sta­tus?
The manu­al pro­ces­ses that phar­maci­es can per­form in the GUI are mark­ed with an (m)
sym­bol. Under cer­tain cir­cum­s­tances, a set pack sta­tus can be reset by the same actor.
be reset again. Excep­ti­ons to this are the sta­tus Theft and Des­troy. The­se
sta­tus chan­ges are irre­vo­ca­ble.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 28

3.48 Does the secur­Ph­arm sys­tem also show me batch recalls for phar­maceu­ti­cals?
Yes, batch recalls of phar­maceu­ti­cals sub­ject to man­da­to­ry veri­fi­ca­ti­on should be published via
the usu­al com­mu­ni­ca­ti­on chan­nels (AMK, PZ, DAZ) also be dis­play­ed in the secur­Ph­arm sys­tem.
sys­tem. If the­re is a con­tra­dic­tion bet­ween the secur­Ph­arm dis­play and the publi­ca­ti­ons, we recom­mend
bet­ween the secur­Ph­arm adver­ti­se­ment and the publi­ca­ti­ons, we advi­se you to initi­al­ly not
and, if neces­sa­ry, to cont­act the phar­maceu­ti­cal com­pa­ny.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 29

4 Deal­ing with alarms

What is an alarm or alert?

An alarm or alert is a war­ning mes­sa­ge. This mes­sa­ge pro­vi­des infor­ma­ti­on about a pos­si­ble
in the sys­tem. Depen­ding on the type of alert, dif­fe­rent actors within the secur­Ph­arm sys­tem are noti­fied.
secur­Ph­arm sys­tem are noti­fied. Sen­si­ti­ve data is sub­ject to spe­cial pro­tec­tion.
The occur­rence of such a war­ning mes­sa­ge in the phar­ma­cy initi­al­ly says not­hing about the cul­prit.
per­pe­tra­tor. Trou­ble­shoo­ting is neces­sa­ry to rule out a cau­se in the phar­ma­cy. The
sources of error include tech­ni­cal errors, incom­ple­te­ly uploa­ded pack data,
pro­blems with coding, incor­rect­ly set scan­ners or the pharmacy’s own hand­ling errors (e.g. dou­ble boo­king out of a pack).
dou­ble boo­king out of a pack).

How does an alarm occur in the phar­ma­cy?

In the phar­ma­cy, an alarm can be trig­ge­red both when veri­fy­ing and when chan­ging the sta­tus of a
sta­tus of a pack (e.g. wri­te-off).
A data com­pa­ri­son takes place during the veri­fi­ca­ti­on pro­cess. The pack data of the pack you have
pack is che­cked for con­sis­ten­cy with the data stored in the secur­Ph­arm sys­tem.
che­cked for con­sis­ten­cy. Veri­fi­ca­ti­on can be car­ri­ed out by the scan­ner or by manu­al­ly ente­ring the pack data.
pack data manu­al­ly. If the scan­ner does not read the data cor­rect­ly or a typ­ing error
the pack can­not be found in the sys­tem. This trig­gers an alarm,
This trig­gers an alarm becau­se a pack requi­ring veri­fi­ca­ti­on is being pro­ces­sed who­se iden­ti­ty is unknown to the legal sup­p­ly
chain is unknown.
In the event of a sta­tus chan­ge, the exis­ting pack sta­tus is chan­ged, for exam­p­le from “rea­dy for
dis­pensable” (acti­ve) to “dis­pen­sed” (inac­ti­ve). =Howe­ver, if the desi­red pack sta­tus has alre­a­dy been set befo­re the chan­ge
alre­a­dy set befo­re the chan­ge, the attempt to chan­ge it trig­gers an alarm. In prac­ti­ce, this alarm
alarm often appears as a dou­ble check-out attempt. The cau­se may be a hand­ling error,
for exam­p­le, an inad­ver­tent wri­te-off in goods receipt and then a rene­wed wri­te-off when the goods are
when dis­pen­sing to the pati­ent. From a sys­tem point of view, such a pro­cess indi­ca­tes a pos­si­ble for­feit­u­re.
for­gery, as the­re is a risk that it is a copy of an ori­gi­nal pack.
ori­gi­nal pack.

What role does my scan­ner play?

The scan­ner is an important tool for recor­ding pack infor­ma­ti­on. It faci­li­ta­tes
and speeds up pro­ces­sing when dis­pen­sing packs and pre­vents incor­rect ent­ries during manu­al recor­ding.
when ente­ring infor­ma­ti­on manu­al­ly.
Howe­ver, if the scan­ner is not con­fi­gu­red cor­rect­ly, the pack data is read and trans­mit­ted incor­rect­ly.
trans­mit­ted incor­rect­ly. This can lead to an alarm becau­se the data read out does not match the data stored in the sys­tem.
stored in the sys­tem. This error pat­tern is often seen when upper and lower case
case is not read cor­rect­ly or the scan­ner swaps Y and Z (lan­guage set­ting).
lati­on). In prac­ti­ce, errors also fre­quent­ly occur when sepa­ra­tors are read over or
an inver­se Data Matrix code (white on a dark back­ground) is appli­ed to the pack­a­ging.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 30

To check whe­ther the scan­ners in your phar­ma­cy are set up cor­rect­ly, plea­se test each of your
scan­ners, both in the HV and in the back office. The test is pos­si­ble with the NGDA scan­ner test.
pos­si­ble. The cur­rent ver­si­on of the scan­ner test is available here:
https://ngda.de/loesungen/securpharm/securpharm-scanner.php

What must be obser­ved when ente­ring data manu­al­ly?

When ente­ring data manu­al­ly via the secur­Ph­arm GUI, clo­se atten­ti­on must be paid to the exact
the exact ent­ry of the pack data. In par­ti­cu­lar, the­re is a risk of con­fu­si­on
with “O” and “0” or “l” and “=”. An incor­rect ent­ry will ine­vi­ta­b­ly lead to an alarm, as the reques­ted
data is not stored in the sys­tem.
IMT packs can­not be manu­al­ly che­cked and boo­ked out via the secur­Ph­arm GUI.
be boo­ked out.

What is a dou­ble check-out attempt?

If a packa­ge that has alre­a­dy been boo­ked out is boo­ked out again, an alarm is trig­ge­red in the secur­Ph­arm sys­tem.
alarm is trig­ge­red in the secur­Ph­arm sys­tem. Each pack can be iden­ti­fied via the stored data (pro­duct code, seri­al no,
batch, expiry date). If a pack is boo­ked out seve­ral times, this indi­ca­tes that it has expi­red.
becau­se the­re is only one ori­gi­nal pack with this data com­bi­na­ti­on on the legal phar­maceu­ti­cal mar­ket.
phar­maceu­ti­cal mar­ket.
Uncer­tain­ty imme­dia­te­ly befo­re dis­pen­sing as to whe­ther a pack has alre­a­dy been boo­ked out or not can easi­ly ari­se.
has been boo­ked out or not can easi­ly ari­se. In this case, howe­ver, the pack should not be boo­ked out again
should not be boo­ked out again, becau­se if it has alre­a­dy been boo­ked out, an alarm is trig­ge­red. Ins­tead
Ins­tead, the sta­tus of the pack should first be che­cked (veri­fi­ca­ti­on). When veri­fy­ing
of a packa­ge known to the sys­tem, no alarm is trig­ge­red. It is gene­ral­ly
pro­ces­ses should be che­cked and, if neces­sa­ry, adjus­t­ments made to avo­id the occur­rence of
avo­id the occur­rence of dou­ble check-out attempts.
If you have inad­ver­t­ent­ly boo­ked out the packa­ge twice, you can repeat this pro­cess under cer­tain
(e.g. time limit). Plea­se refer to ques­ti­on 3.33.

Who is infor­med about the alarm?

With every veri­fi­ca­ti­on pro­cess and every sta­tus chan­ge of a pack, com­mu­ni­ca­ti­on takes place bet­ween the phar­ma­cy ser­vers.
bet­ween the phar­ma­cy ser­ver and the phar­maceu­ti­cal indus­try data­ba­se. The
Howe­ver, the iden­ti­ty of the phar­ma­cy remains hid­den from the phar­maceu­ti­cal indus­try data­ba­se.
This also appli­es in the event of an alarm. The data­ba­se sys­tem of the phar­maceu­ti­cal
indus­try data­ba­se sys­tem and the phar­maceu­ti­cal com­pa­ny to which the alarm-trig­ge­ring pack belongs,
the­r­e­fo­re recei­ve no infor­ma­ti­on about whe­re the alarm was trig­ge­red.
If an alarm is trig­ge­red, the respon­si­ble phar­maceu­ti­cal com­pa­ny is infor­med. The­re the
alarm can be clas­si­fied. Depen­ding on the assess­ment, the alarm is auto­ma­ti­cal­ly for­ward­ed by the secur­Parm.
alarm is auto­ma­ti­cal­ly for­ward­ed by the secur­Ph­arm sys­tem to the BfArM for fur­ther pro­ces­sing. The
BfArM acts as the cont­act for all super­vi­so­ry aut­ho­ri­ties.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 31

What infor­ma­ti­on is trans­mit­ted in the event of an alert?

The respon­si­ble phar­maceu­ti­cal com­pa­ny recei­ves the packa­ge data (seri­al no,
pro­duct code, batch num­ber, expiry date), the assi­gned alarm desi­gna­ti­on, an indi­vi­du­al iden­ti
indi­vi­du­al iden­ti­fier of the alarm inci­dent (alarm ID), the time at which the alarm occur­red and the dyna
pseud­ony­mi­zed iden­ti­fier of the loca­ti­on that trig­ge­red the alarm.
If the­re is an auto­ma­tic or manu­al escala­ti­on by the phar­macist or the phar­maceu­ti­cal
phar­macist or the phar­maceu­ti­cal com­pa­ny, the data from both data­ba­ses (PU and AP sys­tem) are
are mer­ged into one report. The com­pe­tent super­vi­so­ry aut­ho­ri­ty has access to this report
report, which is also cal­led the audit trail.
The audit trail con­ta­ins all infor­ma­ti­on on a pack. This means, in addi­ti­on to the pack data,
all tran­sac­tions (inclu­ding veri­fi­ca­ti­ons and sta­tus chan­ges) and alarm infor­ma­ti­on, the asso­cia­ted
asso­cia­ted times and the cor­re­spon­ding de-pseud­ony­mi­zed sys­tem users. Only the aut­ho­ri­ties
aut­ho­ri­ties are given the oppor­tu­ni­ty to iden­ti­fy the indi­vi­du­al phar­ma­cy.
Plea­se also refer to ques­ti­on 4.21 on the sub­ject of access to infor­ma­ti­on by aut­ho­ri­ties.

How is the alarm dis­play­ed in the software/merchandise manage­ment sys­tem?

An alarm is always dis­play­ed direct­ly in the soft­ware when it occurs, i.e. in the event of an incor­rect
veri­fi­ca­ti­on pro­cess or an unsuc­cessful sta­tus chan­ge. Depen­ding on the soft­ware house
the dis­play of the “red traf­fic light” dif­fers. A war­ning win­dow is often ope­ned.
The scope of the infor­ma­ti­on dis­play­ed for the alarm also dif­fers depen­ding on the soft­ware house.
house.
His­to­ri­cal alarms can be dis­play­ed by many soft­ware manu­fac­tu­r­ers using an auto­ma­ti­cal­ly mana­ged
log in the software/merchandise manage­ment sys­tem. Plea­se also note the
secur­Ph­arm GUI, ques­ti­on: 4.9.
If you have any ques­ti­ons regar­ding the dis­play and func­tion­al scope of the soft­ware pro­ducts, plea­se
plea­se cont­act your soft­ware manu­fac­tu­rer direct­ly.

Whe­re can I get more infor­ma­ti­on about an alarm?

In addi­ti­on to the feed­back from the secur­Ph­arm sys­tem, you will find fur­ther infor­ma­ti­on below on the
Clas­si­fi­ca­ti­on of an alarm. To find the cau­se of an alarm, the fol­lo­wing can be hel­pful
can be hel­pful:
- secur­Ph­arm GUI: https://securpharm-gui.ngda.de/, espe­ci­al­ly alarm moni­to­ring
sys­tem by pro­vi­ding fur­ther infor­ma­ti­on on each alarm, such as the type of action that trig­ge­red it
(veri­fi­ca­ti­on or wri­te-off) is lis­ted for each alarm.
- secur­Ph­arm alarm mes­sa­ge: Pro­ce­du­re in the phar­ma­cy (PDF)
- Soft­ware func­tion (if available): Tran­sac­tion histo­ry for veri­fi­ca­ti­on and
wri­te-off (pro­to­col or log file).
If the cau­se of the alarm has been found and the­re are no fur­ther indi­ca­ti­ons of a non

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 32

dis­pensa­bi­li­ty (e.g. published recall, first-ope­ning pro­tec­tion, other aspects) and
the pack sta­tus is acti­ve, the pack can be boo­ked out and released to the public.
be released to the public.
The secur­Ph­arm GUI is available at the fol­lo­wing link: https://securpharm-gui.ngda.de/

How do you deal with packs who­se authen­ti­ci­ty could not be suc­cessful­ly veri­fied
or a sta­tus chan­ge is not suc­cessful?

In prin­ci­ple, a pack who­se veri­fi­ca­ti­on is nega­ti­ve may not be dis­pen­sed and must be sepa­ra­ted.
and must be sepa­ra­ted. In order to con­firm or refu­te the sus­pi­ci­on of a coun­ter­feit, an error ana­ly­sis must be car­ri­ed out.
an error ana­ly­sis must be car­ri­ed out. It is the­r­e­fo­re essen­ti­al that phar­macists actively
actively deal with the error mes­sa­ges that occur in their phar­ma­cy and get to the bot­tom of the cau­ses.
the cau­ses. In par­al­lel, the respon­si­ble phar­maceu­ti­cal com­pa­ny can initia­te an inves­ti­ga­ti­on.
inves­ti­ga­ti­on.
The result of the phar­maceu­ti­cal company’s ana­ly­sis (alarm sta­tus and, if appli­ca­ble, com­ma
tary) can be che­cked via the alarm moni­to­ring in the secur­Ph­arm GUI (https://securpharm-gui.ngda.de/) using the alarm sta­tus.
can be che­cked using the alarm sta­tus. If the ana­ly­sis in the phar­ma­cy shows that the­re are no good
reasons for the assump­ti­on that a tech­ni­cal error or own hand­ling errors (e.g. acci­den­tal
the alarm is due to a tech­ni­cal error or the pharmacy’s own hand­ling errors (e.g. acci­den­tal wri­te-off in inco­ming goods), the pack must
must con­ti­nue to be sepa­ra­ted and the offi­ci­al report­ing chan­nels must be fol­lo­wed.
If the sus­pi­ci­on of coun­ter­feit­ing is inva­li­da­ted by the error ana­ly­sis and the­re are no fur­ther
evi­dence of coun­ter­feit­ing, the pack can be released again. Plea­se note that
only “dis­pensable” (acti­ve) packs can be boo­ked out and dis­pen­sed. Make sure
the pack sta­tus by scan­ning (veri­fy­ing) the pack and only then pick up the pack again.
only then add the pack to the sales stock again.
You can recei­ve sup­port in ana­ly­zing an alarm mes­sa­ge with the working aid from the Fede­ral
of the Ger­man Cham­ber of Phar­macists: “secur­Ph­arm alarm mes­sa­ge - pro­ce­du­re in the phar­ma­cy”. This docu
This docu­ment is available at http://www.abda.de/sp (secur­Ph­arm in prac­ti­ce).

How is an alarm che­cked by the respon­si­ble phar­maceu­ti­cal entre­pre­neur?

After the occur­rence of an alarm, the alarm can be review­ed by the respon­si­ble phar­maceu­ti­cal entre­pre­neur within a time win­dow of seven calen­dar days.
days by the respon­si­ble phar­maceu­ti­cal com­pa­ny. If the respon­si­ble
If the respon­si­ble phar­maceu­ti­cal com­pa­ny deter­mi­nes that it is a fal­se alarm within the time win­dow, it is clas­si­fied as such and thus de-escala­ted.
and thus de-escala­ted. If no reason for a fal­se alarm is found, the alarm must be clas­si­fied as a po-
ten­ti­al case of suspec­ted fal­si­fi­ca­ti­on and the­r­e­fo­re escala­ted. If no assess­ment is made within the
If no assess­ment is made within the dead­line, the alarm is also auto­ma­ti­cal­ly escala­ted.
Plea­se note that the phar­maceu­ti­cal com­pa­ny may only esca­la­te the alarm in the event of errors that it has
errors (e.g. miss­ing data upload, incor­rect expiry date uploa­ded, incor­rect­ly prin­ted pack, etc.).
prin­ted pack, etc.) can only be de-escala­ted. It is the­r­e­fo­re all the more important that you
check the scan­ner set­tings and adjust the pro­ces­ses if neces­sa­ry.
adjust the pro­ces­ses.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 33

If an escala­ti­on occurs, the alarm mes­sa­ge is for­ward­ed by the secur­Ph­arm sys­tem to the BfArM.
for­ward­ed. The BfArM acts as the cont­act for all super­vi­so­ry aut­ho­ri­ties.
Plea­se note any report­ing obli­ga­ti­ons that exist inde­pendent­ly of the eva­lua­ti­on by the phar
phar­maceu­ti­cal com­pa­ny.
Plea­se also con­sider the fol­lo­wing ques­ti­on on the sub­ject of report­ing to aut­ho­ri­ties: 4.19.

May a pack that has trig­ge­red an alarm be retur­ned to the sales stock befo­re the com­pe­tent
befo­re the review by the respon­si­ble phar­maceu­ti­cal com­pa­ny has been com­ple­ted?
has been com­ple­ted?

The packa­ge sta­tus, the first-ope­ning pro­tec­tion and the assess­ment of the respon­si­ble
first-ope­ning pro­tec­tion and the pharmacist’s assess­ment.
If, after careful ana­ly­sis in the phar­ma­cy, the­re are good reasons to assu­me that a
tech­ni­cal error or own hand­ling errors (e.g. inad­ver­tent wri­te-off in the inco­ming goods depart­ment) were
the alarm and the­re are no other indi­ca­ti­ons of coun­ter­feit­ing, the sus­pi­ci­on can be ruled out.
coun­ter­feit­ing, the sus­pi­ci­on of coun­ter­feit­ing can also be refu­ted wit­hout the phar­maceu­ti­cal
com­pa­ny can be refu­ted. Manu­al veri­fi­ca­ti­on, the tran­sac­tion over­view in the soft­ware and the
over­view in the soft­ware as well as the alarm moni­to­ring in the secur­Ph­arm GUI can be hel­pful here.
(https://securpharm-gui.ngda.de/).
In addi­ti­on to the error ana­ly­sis and the pharmacist’s assess­ment of the suspec­ted coun­ter­feit case
the pack sta­tus in the secur­Ph­arm sys­tem is rele­vant for the assess­ment of dis­pensa­bi­li­ty. Only
packs that have the sta­tus “dis­pensable” may be included in the sales inven­to­ry.
be included in the sales stock.
In this con­text, plea­se also refer to the secur­Ph­arm alarm mes­sa­ge - pro­ce­du­re in the phar­ma­cy.
in the phar­ma­cy. This docu­ment is available at http://www.abda.de/sp (secur­Ph­arm in
in prac­ti­ce). Plea­se also note the ques­ti­on: 4.11.
In this con­text, also con­sider the topic of char­ge­backs, ques­ti­on: 3.6.

What is the dif­fe­rence bet­ween alarm sta­tus and pack sta­tus?

The sta­tus of the alarm expres­ses whe­ther an alarm could indi­ca­te an actu­al suspec­ted case of coun­ter­feit­ing
or whe­ther a fal­se alarm has been trig­ge­red. The sta­tus of the pack deter­mi­nes whe­ther
the pack is “dis­pensable” (acti­ve) or not, wher­eby other fac­tors can rest­rict the dis­pensa­bi­li­ty despi­te the
acti­ve sta­tus. The pack sta­tus and alarm sta­tus can be moni­to­red via the phar­ma­cy
the phar­ma­cy soft­ware and the secur­Ph­arm GUI.

Is a pack auto­ma­ti­cal­ly unfit for dis­pen­sing due to an escala­ti­on?

In addi­ti­on to the pack sta­tus, the pharmacist’s assess­ment, taking all infor­ma­ti­on into account, is decisi­ve.
infor­ma­ti­on is decisi­ve. Depen­ding on the case, the pack may or may not be dis­pensable.
Plea­se also con­sider ques­ti­on: 4.10.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 34

What is the secur­Ph­arm GUI?

The secur­Ph­arm GUI is the web inter­face of the secur­Ph­arm phar­ma­cy ser­ver of the NGDA. GUI
stands for Gra­phi­cal User Inter­face. The phar­macist can access the fol­lo­wing func­tions via the GUI
the phar­macist can access the fol­lo­wing func­tions:
a) Manu­al veri­fi­ca­ti­on and wri­te-off of medi­ci­nes requi­ring veri­fi­ca­ti­on.
This opti­on allows you to manu­al­ly veri­fy medi­ci­nes sub­ject to man­da­to­ry veri­fi­ca­ti­on
and the opti­on to chan­ge the sta­tus of the pack. This func­tion is par­ti­cu­lar­ly useful in the event of
in the mer­chan­di­se manage­ment sys­tem.
b) Alarm moni­to­ring
The alarm moni­to­ring sys­tem pro­vi­des you with an over­view of alarms that have occur­red in your phar­ma­cy and
phar­ma­cy and infor­ma­ti­on on the eva­lua­ti­on of the alarm. With the help of a search and sort­ing func­tion
indi­vi­du­al alarms can be fil­te­red out. This infor­ma­ti­on can be hel­pful to cla­ri­fy alarms
and to detect and avo­id sources of error.
c) Key figu­res
The key figu­res func­tion makes it pos­si­ble to track the num­ber of
of veri­fi­ca­ti­ons and wri­te-offs car­ri­ed out as well as the type and quan­ti­ty of your own alarms.
alarms.
This pro­vi­des a simp­le and com­pre­hen­si­ble over­view of all tran­sac­tions of a busi­ness pre­mi­ses
The secur­Ph­arm GUI is available at the fol­lo­wing link: https://securpharm-gui.ngda.de/
Plea­se also refer to the GUI alarm moni­to­ring docu­men­ta­ti­on, which you can find in the GUI under the
tab: “:help”.

Whe­re can I view all tran­sac­tions (veri­fi­ca­ti­ons and sta­tus chan­ges) of my busi­ness pre­mi­ses?
retrie­ve?

Many soft­ware hou­ses offer the opti­on of using their soft­ware to view the pre­vious actions in con­nec­tion with the Dele­ga­ted Regu­la­ti­on.
in con­nec­tion with the Dele­ga­ted Regu­la­ti­on (sta­tus veri­fi­ca­ti­on and chan­ge).
to under­stand. This check is car­ri­ed out via a pro­to­col or log file. If you have any ques­ti­ons about this
plea­se cont­act your soft­ware manu­fac­tu­rer.
Exem­pla­ry repre­sen­ta­ti­on:

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 35

When is a suspec­ted coun­ter­feit case repor­ted to the aut­ho­ri­ties by the secur­Ph­arm sys­tem?
aut­ho­ri­ties?

After an alarm has occur­red in the sys­tem, this alarm can be repor­ted to the aut­ho­ri­ties by the respon­si­ble phar­maceu­ti­cal
phar­maceu­ti­cal com­pa­ny within a time win­dow of seven calen­dar days.
days. The result can be view­ed in the secur­Ph­arm GUI in the respec­ti­ve alarm sta­tus. If the phar­maceu­ti­cal
phar­maceu­ti­cal entre­pre­neur deter­mi­nes within this time win­dow that it is a fal­se alarm
is a fal­se alarm, it is clas­si­fied as such and thus de-escala­ted. De-escala­ti­on eli­mi­na­tes the need for au
auto­ma­tic noti­fi­ca­ti­on by the sys­tem. If no reason for a fal­se alarm is found, the alarm must be
the alarm must be clas­si­fied as a poten­ti­al case of suspec­ted fal­si­fi­ca­ti­on and the­r­e­fo­re escala­ted. If
If no assess­ment is made within the dead­line, the alarm is also escala­ted auto­ma­ti­cal­ly.
If an escala­ti­on occurs, the alarm mes­sa­ge is for­ward­ed by the secur­Ph­arm sys­tem to the BfArM.
for­ward­ed. The BfArM acts as the cont­act for all super­vi­so­ry aut­ho­ri­ties.
In this con­text, plea­se note that the respon­si­ble super­vi­so­ry aut­ho­ri­ties have a right to all infor­ma
infor­ma­ti­on neces­sa­ry to check com­pli­ance with the Dele­ga­ted Regu­la­ti­on. Not appli­ca­ble
If a noti­fi­ca­ti­on by the phar­macist or the secur­Ph­arm sys­tem is omit­ted, the super­vi­so­ry aut­ho­ri­ties may nevert­hel­ess
aut­ho­ri­ties can still view all infor­ma­ti­on (inclu­ding tran­sac­tions and alarms) for this pack.
alarms.

When do I have to report an alarm to the aut­ho­ri­ties?

An alarm could always indi­ca­te a coun­ter­feit. You should the­r­e­fo­re act imme­dia­te­ly. Inves­ti­ga­te
Inves­ti­ga­te the packa­ge and the alarm, using all the infor­ma­ti­on available to you.
infor­ma­ti­on available to you (e.g. assess­ment of the alarm sta­tus by the respon­si­ble com­pa­ny, manu­al input and
and scan­ner test or the tran­sac­tion histo­ry in the soft­ware if available).
Pur­su­ant to Sec­tion 21 (6) ApBe­trO, the legis­la­tor per­mits the inter­nal inves­ti­ga­ti­on (7 calen­dar
days) by the respon­si­ble phar­maceu­ti­cal entre­pre­neur befo­re a report must be made to the aut­ho­ri­ties.
the aut­ho­ri­ties.
If, during the par­al­lel inves­ti­ga­ti­on by the phar­macist, the­re are incre­asing indi­ca­ti­ons that the pro­duct
that it real­ly could be a coun­ter­feit, the­re is an imme­dia­te obli­ga­ti­on to report to the aut­ho­ri­ties and the
the aut­ho­ri­ties and the AMK: The 7 days do not have to be wai­ted for.
In the case of unclear error reports, plea­se refer to the working aid of the Fede­ral Cham­ber of Phar­macists
kam­mer: secur­Ph­arm Alarm mes­sa­ge - Pro­ce­du­re in the phar­ma­cy. You can obtain this docu­ment
at http://www.abda.de/sp .

What infor­ma­ti­on does the aut­ho­ri­ty have access to?

Com­pe­tent super­vi­so­ry aut­ho­ri­ties have a right to all infor­ma­ti­on neces­sa­ry to veri­fy com­pli­ance with the Dele­ga­ted Regu­la­ti­on.
com­pli­ance with the Dele­ga­ted Regu­la­ti­on. This includes infor­ma­ti­on on alerts, but
the tran­sac­tion histo­ry of a packa­ge, inclu­ding veri­fi­ca­ti­ons and wri­te-offs. To obtain the
infor­ma­ti­on from the data repo­si­to­ry, secur­Ph­arm per­forms a de-pseud­ony­miza­ti­on of the ori­gi­na­ting
miza­ti­on of the ori­gi­na­ting enti­ty to the aut­ho­ri­ties. The iden­ti­ty of the phar­ma­cy remains
remains hid­den from the data­ba­se of the phar­maceu­ti­cal indus­try.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 36

Up to now, the super­vi­so­ry aut­ho­ri­ties have gai­ned access by indi­vi­du­al­ly query­ing the so-cal­led
audit trails and the alarm ID via the secur­Ph­arm office.
In the future, this pro­cess will be auto­ma­ted and aut­ho­ri­ties will have direct access. Poten­ti­al
poten­ti­al vio­la­ti­ons of the Fal­si­fied Medi­ci­nes Direc­ti­ve can be tra­ced even more easi­ly and com­pre­hen­si­ve­ly.
more easi­ly and com­pre­hen­si­ve­ly. ABDA and its mem­ber orga­niza­ti­ons will inform you in advan­ce of this auto­ma­ti­on step.
about this auto­ma­ti­on step.
Plea­se also note the fol­lo­wing ques­ti­on on the sub­ject of report­ing to aut­ho­ri­ties: 4.7.

Why should you deal with the secur­Ph­arm sys­tem and the alarms in the phar­ma­cy?
the phar­ma­cy?

In addi­ti­on to ful­fil­ling the legal requi­re­ments, each indi­vi­du­al user con­tri­bu­tes to main­tai­ning the high level of safe­ty in the legal phar­maceu­ti­cal trade.
safe­ty level in the legal phar­maceu­ti­cal trade.
For the anti-coun­ter­feit­ing sys­tem to work, any alarms that occur must be regis­tered and cate­go­ri­zed.
clas­si­fied. The key ques­ti­on here is whe­ther the alarm indi­ca­tes a coun­ter­feit or a fal­se alarm.
a fal­se alarm.
So inves­ti­ga­te the cau­se and fami­lia­ri­ze yours­elf even more with the secur­Ph­arm sys­tem.
sys­tem: “What does the error code that appears when scan­ning or chan­ging the sta­tus of the pack mean?
“How do I reco­gni­ze a packa­ge that has been boo­ked out twice?”; “Is the scan­ner set up cor­rect­ly?“
cor­rect­ly set?”; “Which alarms indi­ca­te an incom­ple­te data upload?”; “What is the
secur­Ph­arm-GU=?”, “Who can help me with pro­blems and ques­ti­ons?“
Bear in mind that every alarm cau­ses addi­tio­nal work and can make it dif­fi­cult to pro­vi­de time­ly care to the pati­ent.
can make it more dif­fi­cult to pro­vi­de prompt care. In addi­ti­on, many fal­se alarms are avo­ida­ble. The­r­e­fo­re, try to pre­vent fal­se
alarms from occur­ring in the first place. Take action, check the set­tings of the scan­ner
scan­ner set­tings and adjust the action sequen­ces if neces­sa­ry.
Last but not least, do not for­get to book out the pack imme­dia­te­ly befo­re han­ding it to the pati­ent.
to the pati­ent.

Does the secur­Ph­arm sys­tem report a suspec­ted fal­si­fi­ca­ti­on to the super­vi­so­ry aut­ho­ri­ty?

4.21: Does the secur­Ph­arm sys­tem report a suspec­ted case of coun­ter­feit­ing to the super­vi­so­ry aut­ho­ri­ty?
Alarms are always stored in the secur­Ph­arm sys­tem so that they are available for pro­ces­sing by the aut­ho­ri­ties.
available for pro­ces­sing by the aut­ho­ri­ties. Aut­ho­ri­ties that recei­ve a suspec­ted fal­si­fied
repor­ted by mar­ket par­ti­ci­pan­ts using the data from the secur­Ph­arm sys­tem
from the secur­Ph­arm sys­tem curr­ent­ly still have to inqui­re with secur­Ph­arm to obtain the cor­re­spon­ding audit trails.
recei­ve the cor­re­spon­ding audit trails. After the plan­ned con­nec­tion of the aut­ho­ri­ties to the secur­Ph­arm sys­tem, they will have
will then have direct access to the data from the sys­tem.
It is also plan­ned that the secur­Ph­arm sys­tem will pro­vi­de the Fede­ral Insti­tu­te for Drugs and
Medi­cal Devices (BfArM) auto­ma­ti­cal­ly as soon as an alarm is escala­ted in the sys­tem.
The BfArM then coor­di­na­tes the cases in con­sul­ta­ti­on with the Paul Ehr­lich Insti­tu­te (PEI), enters them
into its own offi­ci­al coun­ter­feit data­ba­se and informs the super­vi­so­ry aut­ho­ri­ty respon­si­ble for the phar­maceu­ti­cal
com­pe­tent super­vi­so­ry aut­ho­ri­ty for the phar­maceu­ti­cal com­pa­ny.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 37

The noti­fi­ca­ti­on by the secur­Ph­arm sys­tem is an addi­tio­nal noti­fi­ca­ti­on that does not replace the pre­vious
replace the pre­vious report­ing obli­ga­ti­ons of the mar­ket play­ers. The pre­vious report­ing obli­ga­ti­ons con­ti­nue to app­ly in the event of
a well-foun­ded sus­pi­ci­on of fal­si­fi­ca­ti­on.
4.22 What war­ning mes­sa­ges are the­re?
The­re are various war­ning noti­fi­ca­ti­ons that dif­fer in terms of their cri­ti­cal­i­ty. The hig­hest
war­ning mes­sa­ge is an alert mes­sa­ge.
Alert mes­sa­ges always indi­ca­te a poten­ti­al sus­pi­ci­on of coun­ter­feit­ing.
The­se war­ning mes­sa­ges are alarm mes­sa­ges

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 38

The­se war­ning mes­sa­ges do not con­sti­tu­te an alarm, but should still be con­side­red by the phar­macist
be con­side­red:

The error codes dis­play­ed in the ERP sys­tem may dif­fer from the error codes in the GUI
may dif­fer. Howe­ver, the core infor­ma­ti­on is the same.
The table is taken from the GUI help docu­men­ta­ti­on. You can find this and fur­ther
infor­ma­ti­on in the secur­Ph­arm GUI at: https://securpharm-gui.ngda.de/

4.23 What alarm sta­tu­s­es are available?
The alarm sta­tus is only dis­play­ed in the GUI.
Plea­se note that the phar­maceu­ti­cal entre­pre­neur only has to report alarms in the event of errors cau­sed by hims­elf or
known errors (e.g. miss­ing data upload, incor­rect expiry date uploa­ded, incor­rect­ly prin­ted pack, etc.).
incor­rect­ly prin­ted pack, etc.) can car­ry out a de-escala­ti­on.
The alarm sta­tus is addi­tio­nal infor­ma­ti­on to eva­lua­te the alarm and thus also the dis­pensa­bi­li­ty of the pack.
of the pack.
Alarm sta­tus “Crea­ted”: The alarm is being pro­ces­sed, the clas­si­fi­ca­ti­on has not yet been
yet. The time limit of 7 days has not yet expi­red.
Alarm sta­tus “De-escala­te­d/­re­sol­ved”: The alarm has been clas­si­fied as unfoun­ded. (rever­si­ble)
Alarm sta­tus “Escala­ted”: The alarm has been for­ward­ed to the Fede­ral Insti­tu­te for Drugs and
Medi­cal Devices (BfArM).
The “De-escala­te­d/­re­sol­ved” sta­tus is not final. This means that the alarm sta­tus of an alre­a­dy
de-escala­ted alarm can be chan­ged again.
Advan­ce noti­ce: In the future, phar­macists will also be enab­led to report hand­ling errors
PCK_19 and PCK_22) to clas­si­fy the alarm sta­tus. Howe­ver, the tech­ni­cal requi­re­ments
for this still need to be imple­men­ted.

26.04.2022 Ver­si­on 5 crea­ted by secur­Ph­arm e. V. 39

4.24 Whe­re should medi­cinal pro­ducts be stored that have trig­ge­red an alarm and for which
no imme­dia­te tech­ni­cal cau­se or hand­ling error could be found?
could be found?
As long as no cau­se for the alarm has been found, the pack must be sepa­ra­ted and must not be
not be retur­ned. It is advi­sa­ble to desi­gna­te an appro­pria­te sto­rage loca­ti­on for
(tem­po­r­a­ri­ly) non-dis­pensable packs. This loca­ti­on should be labe­led accor­din­gly
so that the enti­re team knows that this pack must not be dis­pen­sed until the alarm has been resol­ved.
be dis­pen­sed until the alarm has been resol­ved. Always obser­ve the 10-day char­ge­back peri­od, for exam­p­le in the case of
Alarms cau­sed by dou­ble wri­te-off attempts.
If a com­pre­hen­si­ve exami­na­ti­on of the pack con­firms the sus­pi­ci­on that it could be
coun­ter­feit, the pack must be pla­ced in a secu­re (locked) sto­rage area until a decis­i­on is made on how to pro­ceed.
qua­ran­ti­ne sto­rage faci­li­ty (lockable) and labe­led as such until a decis­i­on has been made on how to pro­ceed.
and labe­led as such.
Plea­se also obser­ve the docu­men­ta­ti­on and report­ing obli­ga­ti­ons.
4.25 How do I store medi­ci­nes that are suspec­ted of being coun­ter­feit?
Medi­cinal pro­ducts which, after an inten­si­ve exami­na­ti­on of the pack­a­ging and taking into account all
infor­ma­ti­on, are suspec­ted of being coun­ter­fei­ted must be sepa­ra­ted and stored in a
sepa­ra­te­ly labe­led and secu­red sto­rage loca­ti­on.
A sui­ta­ble sto­rage loca­ti­on is, for exam­p­le, a lockable (secu­red) cup­board com­part­ment or an appro­pria­te
box that is used exclu­si­ve­ly for medi­ci­nes suspec­ted of being coun­ter­feit (sepa­ra­te­ly) and
(sepa­ra­te­ly) and labe­led with a label such as “Medi­ci­nes under sus­pi­ci­on of coun­ter­feit­ing”.
(labe­led). In order to avo­id con­fu­si­on with dis­pensable medi­cinal pro­ducts,
medi­ci­nes, this “qua­ran­ti­ne sto­rage” should be in a con­stant loca­ti­on and always available, even if
always available, even if no medi­cinal pro­ducts under con­cre­te sus­pi­ci­on of
medi­ci­nes suspec­ted of being fal­si­fied are stored the­re (per­ma­nent­ly).
In the event of imme­dia­te sus­pi­ci­on of coun­ter­feit­ing, also obser­ve the docu­men­ta­ti­on and
report­ing obli­ga­ti­ons

Downloads & Links

Anlaufstellen für Apotheken

In der Verfassung vom 27. Januar 2020pdf, 16,10 KB

FAQs Apotheken

In der Verfassung vom 26. April 2022pdf, 1,11 MB

Checkliste für den Systemzugang

In der Verfassung vom 24. November 2022pdf, 144,91 KB

Aide Memoire der EU-Kommission für Inspektionen

In der Verfassung vom 16. Juli 2020pdf, 152,09 KB

News

Updated BAK working aid

01 September 2025 | reading time: <1 Minute

Alarm pro­ces­sing as an important pie­ce of the puz­zle: sup­port for offi­ci­al recon­nais­sance

16 Mai 2025