RxFinder.ai
340b-program

340B patient definition: how HRSA defines covered outpatient drugs, dispensing eligibility, and the records that establish patient status

How patient status is established in 340B turns on documented care, outpatient drug use, and records that can survive audit review.

Image: Drug Channels (Adam J. Fein / Drug Channels Institute)
Image: Drug Channels (Adam J. Fein / Drug Channels Institute)

The problem usually shows up at dispense, not at registration

A 340B program can look clean until a refill lands in the work queue at a contract pharmacy or an in-house outpatient pharmacy and no one can show why that prescription was tagged eligible. That is when patient definition stops being an abstract policy issue and becomes repayment risk.

The compliance question isn't whether the person is generally known to the hospital or clinic. It is whether the covered entity can support that the drug was ordered and dispensed in a way that fits HRSA's patient framework for 340B use, and whether the drug itself is a covered outpatient drug. Those are separate questions, and programs run into trouble when they blur them into one loose idea of "our patient."

That matters even more in a program this large. Drug Channels reported that discounted purchases under the 340B program reached $100 billion in 2025, with hospitals accounting for 87% of 340B purchases. Bigger program dollars don't change the rule. They do raise the stakes when internal records are weak.

For HRSA, the patient definition comes down to documentation

When administrators talk about the 340B patient definition, they usually mean HRSA's long-used framework for deciding whether a prescription can be replenished as 340B. In practice, the point is straightforward: the covered entity has to tie the prescription back to care for which it maintains responsibility, through records it controls or can produce. If the chart, encounter record, order trail, and dispensing record do not line up, the patient definition usually fails in practice, even when staff believe the prescription came from legitimate care.

That is why a pharmacy claim alone cannot establish patient status. A claim can show that a drug was dispensed. It does not, by itself, show that the individual was a patient of the covered entity for 340B purposes at the relevant time, or that the prescribing relationship fits the program's requirements. Same problem with a registration record, an insurance card, or a problem list sitting in the electronic record without a documented encounter that supports the order.

The records have to tell one coherent story. The covered entity's records should show that the individual received care from the entity, that the prescribing professional's order is tied to that care, and that the drug was dispensed as an outpatient drug. If the only tidy record sits at the contract pharmacy while the covered entity's chart is thin or delayed, that is not a technology problem. It is a patient definition problem.

Patient status is one gate; covered outpatient drug status is another

Programs get sloppy when they assume every outpatient prescription written after an encounter automatically qualifies as a 340B drug. It doesn't. Before anyone even reaches patient definition, the product has to qualify as a covered outpatient drug. After that, the covered entity still has to determine that the dispense was outpatient and that the individual met the patient standard tied to the entity's care.

Operationally, that distinction matters because mixed settings invite bad assumptions. A discharge prescription, a clinic-administered product, a referral-driven order, and a specialty fill routed through an outside dispensing location do not share the same documentation profile. Treating them as interchangeable is how split-billing logic gets ahead of the medical record.

The same pressure shows up in contract pharmacy models. Drug Channels said its 2026 analysis found a more mature contract pharmacy market with consolidation, slower growth, and increasing dominance by the largest participants. It also reported that five large pharmacy chains and PBMs now account for 77% of all relationships. That does not answer any patient definition question by itself. It does mean more dispenses can move through complex external arrangements where pharmacy data is abundant and covered-entity clinical documentation is the weak link.

If a prescription comes from a location the entity does not own, through a prescriber who rotates across settings, the compliance answer cannot be "the software qualified it." Software can apply rules. It cannot create patient status the record does not support.

What actually proves patient status in the record

The safest approach is to treat patient status as something proven by a record set, not a single field.

At a minimum, the covered entity should be able to produce documentation connecting the patient, the provider, the encounter, the order, and the dispense. Usually that means the chart reflects care delivered by the covered entity, the prescriber is tied to that care in a documented way, the order appears in the entity's clinical record or an integrated workflow the entity can substantiate, and the dispense record can be matched back to that order.

If one of those links is missing, administrators should stop calling the claim clean.

A common real-world scenario involves a specialist seeing a patient under an arrangement that feels operationally integrated, while the prescription is filled later at a contract pharmacy using an eligibility file. Everyone assumes the entity relationship is obvious. Then an audit request asks for the underlying encounter, the treatment record, the prescribing documentation, and proof that the entity retained responsibility for the care reflected in the order. That is where weak files fall apart. A scheduling note, a scanned fax, or a pharmacy refill history will not repair a missing clinical connection.

Refills deserve special attention. The original qualifying encounter and order trail have to support the refill logic used by the program. If a refill continues long after the documented care relationship becomes stale or unclear, the burden remains on the covered entity to show why the later dispense stayed eligible.

Internal policy should say what records are reviewed, how long an encounter can support later fills under the entity's rules, and when a prescription has to be excluded because the clinical tie is no longer supportable. If the policy is vague, the audit defense will be vague too.

Before HRSA asks, tighten the weak spots

Start where the team is leaning on assumptions. Cross-coverage providers, referrals, hospital discharge workflows, mixed-use clinics, and specialty pharmacy channels are usually the trouble spots because they create distance between the care event and the dispense record. Those are the files worth testing first.

Then look at who owns the record. If the entity cannot readily retrieve the encounter documentation supporting the prescription, the transaction is already on shaky ground. A contract pharmacy can store dispensing data, but it cannot replace covered-entity clinical documentation. The entity needs a defensible audit trail inside its own compliance process, not just confidence that an outside partner has data.

Scale is another reason to stop tolerating weak standards. Drug Channels described 2025 340B purchases as $100 billion and said the program's current operations and economic incentives have diverged dramatically from the original intent. Whether a covered entity agrees with that critique or not, the operational message is clear enough: in a larger, more visible program, a loose patient definition policy is not just sloppy. It invites scrutiny.

The cleanest programs do not try to stretch the definition. They build eligibility around records they can defend. No apology, no improvisation. If the chart does not clearly establish the care relationship, the order path, and the outpatient dispense, the right answer is usually exclusion, not debate.

Sources

This article is for informational and educational purposes only and is not a substitute for professional medical, legal, or compliance advice. Always consult qualified professionals for decisions affecting patient care or regulatory compliance.

Related on RxFinder.ai