FDA Extends Certain DSCSA Exemptions for Small Pharmacies: What the Additional Year Means
FDA has extended certain DSCSA exemptions for qualifying small pharmacies through November 27, 2027. The additional year provides more time to implement electronic package level tracing, but pharmacies must continue meeting other DSCSA requirements and documenting their progress toward full compliance.
The Food and Drug Administration has given qualifying small pharmacies another year to implement certain enhanced drug distribution security requirements under the Drug Supply Chain Security Act.
On August 6, 2026, FDA announced that small dispensers, along with their trading partners where applicable, will receive exemptions from certain requirements through November 27, 2027. The prior exemption period was scheduled to end on November 27, 2026.
For independent and community pharmacies still working through technology, data exchange, staffing, and trading partner challenges, the additional year is meaningful. It is not, however, a suspension of DSCSA compliance.
The exemption applies only to specific enhanced drug distribution security requirements. Other DSCSA responsibilities remain in effect, and FDA is continuing to urge small dispensers to make progress toward full implementation.
Which Pharmacies Qualify?
For purposes of the new exemptions, FDA considers a dispenser to be a small dispenser if the company that owns the dispenser has 25 or fewer full time employees who are licensed pharmacists or qualified pharmacy technicians as of November 27, 2026.
This means the analysis is based on the company that owns the pharmacy, not necessarily the employee count at one individual pharmacy location. Organizations operating multiple locations should therefore examine their ownership structure and total number of qualifying employees before concluding that the exemption applies.
Qualifying small dispensers do not need to submit an application or notify FDA to use the exemption. A pharmacy should still document its eligibility internally and be prepared to explain the basis for relying on it.
What Has Been Extended?
The exemptions apply to certain enhanced security requirements involving interoperable, electronic, package level product tracing.
During the exemption period, qualifying small dispensers and, where applicable, their trading partners may continue using existing methods for certain activities that would otherwise require fully interoperable electronic systems. These include aspects of:
Exchanging transaction information and transaction statements electronically
Including package level product identifiers in transaction information
Conducting product verification at the package level
Responding to government requests for transaction information during recalls or investigations
Gathering transaction information back through the supply chain
Processing certain saleable returns
The exemption also covers specific product identifier verification requirements when a qualifying pharmacy investigates suspect or illegitimate products. It does not eliminate the pharmacy’s other investigation and verification responsibilities.
What the Exemption Does Not Cover
The extension should not be treated as a general waiver from DSCSA.
Pharmacies must still purchase prescription drugs from authorized trading partners. They must maintain applicable transaction records, identify and investigate suspect products, quarantine products when appropriate, and notify FDA and relevant trading partners when illegitimate products are discovered.
Pharmacies must also maintain policies and procedures that allow employees to recognize and respond to products that may be counterfeit, diverted, stolen, adulterated, or otherwise unfit for distribution.
The additional year changes the timeline for certain enhanced electronic requirements. It does not erase the underlying obligation to protect the integrity of the drug supply chain.
Why FDA Granted More Time
FDA granted the additional exemption while an independent assessment examines whether small dispensers can feasibly implement interoperable, electronic tracing at the package level.
That assessment will evaluate the technology and software available to small pharmacies, including whether existing systems are accessible, functional, and economically feasible. FDA is encouraging small dispensers to complete its assessment survey by September 22, 2026. A small dispenser may designate another organization, such as a consultant, to complete the survey on its behalf.
The survey gives independent pharmacies an opportunity to document the practical difficulties they encounter, including system costs, integration problems, staffing limitations, data quality issues, and dependencies on wholesalers or technology vendors.
How Pharmacies Should Use the Additional Year
The safest approach is to treat the extension as an implementation period, not a waiting period.
A pharmacy relying on the exemption should first document why it qualifies. That documentation should identify the ownership entity, the relevant employee count, and the methodology used to determine which employees are included.
The pharmacy should then evaluate its current DSCSA capabilities. This includes confirming whether it can receive and retrieve transaction information, identify its authorized trading partners, investigate suspect products, quarantine inventory, respond to information requests, and preserve the required records.
Pharmacies should also speak with their wholesalers, buying groups, and technology providers. A pharmacy may qualify for an exemption while one or more of its trading partners operate under different requirements. Understanding how each party will transmit, receive, store, and retrieve information can help prevent purchasing disruptions and inventory delays.
Written policies should reflect what the pharmacy is actually doing today. Employees responsible for purchasing, receiving, returns, inventory management, and product investigations should understand those procedures and know when a problem must be escalated.
Finally, pharmacies should keep records of their implementation efforts. Contracts, vendor communications, training records, system testing, written procedures, corrective actions, and internal assessments can help demonstrate that the pharmacy used the exemption period responsibly.
The Legal and Operational Risk Has Not Disappeared
DSCSA compliance is not solely a technology project. It involves vendor contracts, licensing, purchasing controls, record retention, employee training, product investigations, and relationships with trading partners.
A pharmacy that waits until the exemption is about to expire may discover that its software cannot communicate effectively with a wholesaler, its transaction data cannot be retrieved promptly, or its written policies no longer reflect its operations. Those problems can affect more than regulatory compliance. They can interrupt purchasing, delay returns, create audit exposure, and ultimately affect patient access.
FDA’s extension gives qualifying small pharmacies valuable time to address those risks. The best use of that time is to build a compliance program that is both operationally workable and legally defensible.
Lanton, Lanton & Sosa Law PLLC advises pharmacies, healthcare organizations, and other regulated businesses on compliance, contracting, audits, licensing, reimbursement, and operational risk. Organizations evaluating the DSCSA exemption should assess both their eligibility and the steps necessary to reach full compliance before the exemption ends.
This article is provided for general informational purposes and does not constitute legal advice.
New York State Bar Association (NYSBA) Journal Publishes Ron Lanton III Article on Global Healthcare Reform and Life Sciences Strategy
Ron Lanton III’s article, “The Global Healthcare Divorce: How US and EU Reforms Are Reshaping the Structure of Life Sciences Companies,” was published in the Summer 2026 issue of the New York State Bar Association Journal. The article examines how healthcare reform in the United States and European Union is affecting life sciences strategy, market access, reimbursement planning, and company structure.
Lanton, Lanton & Sosa Law PLLC is pleased to share that Ron Lanton III’s article, “The Global Healthcare Divorce: How US and EU Reforms Are Reshaping the Structure of Life Sciences Companies,” was published in the Summer 2026 issue of the New York State Bar Association Journal.
The article examines how healthcare reform in the United States and European Union is beginning to affect more than compliance. These changes are also shaping life sciences strategy, company structure, market access, exclusivity, reimbursement planning, and capital decisions.
For healthcare and life sciences companies, the larger takeaway is that regulatory change is becoming a business planning issue. Companies operating across markets need to understand how policy developments may affect contracts, commercialization strategy, investor expectations, and long-term growth.
At Lanton, Lanton & Sosa Law PLLC, we work with healthcare organizations, life sciences companies, pharmacies, physician groups, and health-adjacent businesses on the legal, regulatory, and strategic issues that affect growth in highly regulated markets.
The article begins on page 51 of the Summer 2026 NYSBA Journal seen at https://nysba.org/wp-content/uploads/2026/06/jrnl_summer2026-6-23-26-FINAL-WEB.pdf
AI Medical Advice Is Moving Faster Than Healthcare Risk Management
As patients increasingly rely on AI tools for health-related questions, healthcare organizations need to understand how those tools are being used, who is relying on them, and where legal, clinical, and operational risk may begin.
Artificial intelligence is quickly becoming part of the healthcare experience. Patients are using AI tools to ask questions, interpret symptoms, manage medications, and decide whether they need to seek care. Some of these tools are being introduced through formal healthcare partnerships. Others are consumer-facing platforms that were never designed to operate as part of the healthcare system.
The problem is that patients are not always seeing the difference between a tool that gives general information and a tool that sounds like it is giving medical guidance. This is where real risks comes in.
The recent lawsuit in Pennsylvania involving Character.AI is a reminder that healthcare risk is no longer limited to hospitals, physicians, pharmacies, or traditional medical technology companies. When patients rely on AI-generated information to make decisions about their health, the legal and regulatory questions become much more complicated.
Who is responsible if the information is wrong? Was the platform providing general information, or did it cross into something closer to medical advice? Did the user understand the limits of the tool? Was there any process for escalation, disclosure, clinical review, or human oversight?
These questions matter because AI is not entering healthcare through one clean channel. It is coming through consumer applications, state partnerships, provider workflows, payer systems, pharmacy tools, and patient-facing platforms. Some uses may be administrative. Others may influence clinical decision-making in ways that are not obvious at the beginning.
That creates a different kind of risk environment for healthcare organizations.
The issue is not whether AI should be used in healthcare. It will be used and increasingly so. The more important question is whether healthcare organizations have the governance structure to understand how it is being used, who is relying on it, and where the legal risk sits.
For providers, pharmacies, health systems, digital health companies, and other healthcare organizations, AI review cannot sit only with the technology team. It needs to involve legal, compliance, clinical, operational, and risk management leadership before the tool is placed in front of patients or built into a workflow.
That review should start with practical questions. What is the tool actually doing? Is it generating general information, making recommendations, triaging care, renewing medications, or influencing a provider’s decision? Who reviews the output? What disclosures are being made to patients? How are errors identified? What happens when the AI reaches the limit of what it should answer?
The answers to those questions may determine whether an organization is using AI as a helpful support tool or unintentionally creating a new source of professional, regulatory, and operational exposure.
Healthcare has always depended on trust. AI does not remove that obligation. It simply changes where the trust is being placed.
As AI becomes more visible in healthcare, the organizations that move carefully will not be the ones avoiding innovation. They will be the ones that understand that innovation needs structure around it.