What makes a CBPM pharmacy's software needs different?
Everything the pharmacy dispenses is an unlicensed Schedule 2 controlled drug, prescribed privately by specialists to remote patients, and each clause of that sentence puts a demand on the system that ordinary dispensing never generates. The specialist-and-private clause means prescriber verification records and private prescription handling are core workflow, not edge cases. The unlicensed clause means the specials regime's five-year transaction records and batch-to-patient traceability, because in an import-dependent supply chain the recall question is when, not if. The Schedule 2 clause means the CD register discipline and the 28-day prescription clock shaping every job. And the remote clause means the clinical assessment, the monitoring record and the delivery evidence all have to live somewhere structured, because the patient never stands at a counter where gaps get papered over conversationally. The regulatory load itself is set out in the setup guide.
The failure mode this produces is predictable and we see it in every pharmacy we onboard from a generic stack: the PMR holds the dispensing, and everything that actually distinguishes the category, verification records, batch capture, monitoring notes, delivery evidence, lives in spreadsheets, inboxes and heads. The record that an inspector, a clinic partner or a recall demands then gets assembled retrospectively, which is the expensive way to discover your system was the wrong one.
What are the criteria for medicinal cannabis pharmacy software?
Score any vendor, including us, against this table. It is the software translation of the rulebook in the CBPM compliance guide and the pipeline in the workflow guide:
| Criterion | Why it matters for CBPMs | What to ask any vendor |
|---|---|---|
| Structured clinical assessment | The remote patient's clinical picture must arrive structured, not as PDFs to re-key | Can assessments be configured, completed by the patient online and embedded on the clinic's website? |
| Patient record with longitudinal fields | Specialist reviews and monitoring observations accumulate over long-term therapy | Can fields be added, updated at each review and tracked over time? |
| Prescriber and clinic records | Verification against the GMC Specialist Register must be recorded and refreshable | Where do prescriber checks and standing verification live, and are they dated and attributable? |
| Drug data and decision support | CBPMs sit alongside patients' conventional medicines; interactions must flag | Is comprehensive drug data built in, with interaction, contraindication and duplicate flags? |
| Dispensing with compliant labelling | Every supply needs the particulars and cautionary wording at the bench | Is dispensing in-platform with label printing including cautionary labels? |
| Batch-to-patient traceability | The specials regime's recall question: who received batch X, answered in a working day | How is batch captured at dispensing and queried afterwards? |
| Controlled drug support | Schedule 2 register discipline is the category's daily workload | What CD functionality exists today, and what is roadmap, with dates? |
| Reminders and recalls | Review cycles and the 28-day clock both need driving, not remembering | Do reminders attach to patients and jobs? |
| Audit trail and access control | Two regulators and a clinic partner will all read these records | Individual logins, role-based access, full audit log: show me |
| Supplier diligence layer | Special category data, clinical software | DCB0129 documentation, UK/EEA hosting, signed DPA, breach terms |
Two rows carry the most differentiation. Batch traceability is the one generic PMRs fail structurally, because NHS dispensing rarely demands batch-level patient linkage and the systems reflect that. And the CD support row is where vendor honesty gets tested: the correct answer is specific and dated, and any vendor whose answer is a vague yes deserves the follow-up questions from DCB0129 for pharmacy software buyers applied with prejudice.
How does Dataforge PMR answer each criterion?
In workflow order, the way a prescription actually moves. The clinical assessment is completed by the patient online and embeds directly on the clinic's website, landing structured in the patient record rather than arriving as an attachment; for a CBPM service that means the eligibility picture, treatment history and consent trail exist as data from the first contact. The patient record carries custom fields that are added to fit the service's own protocol and then updated and tracked over time, which is where specialist review outcomes and monitoring observations accumulate as a comparable series across the months of a long-term therapy. Prescriber details and the notes around verification live on the record, dated and attributed, so the standing-verification discipline from the workflow guide is a query rather than a filing hunt. Prescribing support runs on comprehensive drug data with clinical decision support flagging interactions, contraindications and duplicates, which matters precisely because CBPM patients arrive carrying conventional medication histories. Dispensing closes the loop in the same platform, with drug label printing including cautionary wording generated at the bench, and the dispensing record sits on the same audit trail as everything upstream. Reminders attach to the cadence the category demands: review recalls, follow-ups and the operational prompts a 28-day prescription life makes valuable.
On controlled drugs, the answer we would demand of any vendor, given about ourselves: a controlled drugs register module is scheduled for release at the end of 2026, and until it ships the CD register runs as a disciplined parallel process alongside Dataforge PMR, with named ownership per session, which is a fully inspectable position and the honest current state. On batch traceability, batch details are recorded against the patient record as part of the dispensing workflow rather than held as a structured recall index, so a pharmacy should run its batch log with the same parallel-process discipline as the register today; we would rather tell you that in an article than have you discover it in a recall.
And on the diligence layer, Dataforge PMR answers the questions this site tells buyers to ask everyone: DCB0129 clinical safety documentation, a signed data processing agreement, UK and EEA hosting, individual role-based logins and full audit trails, the same standard set out in the patient data security briefing.
What should the decision process look like?
Buy against your workflow, not against feature lists, and test the vendor's honesty as hard as the software. The process that works: write your pipeline first, the eight gates from the workflow guide annotated with your volumes; score each candidate against the criteria table with evidence, not assurances, demanding a walkthrough of the actual screens for assessment capture, dispensing and labelling; put the two hard questions, CD functionality and batch traceability, to every vendor in writing and keep the answers, because dated, specific replies predict how the relationship will run; run the diligence layer before commercial negotiation, since a missing DPA or absent DCB0129 documentation is a disqualifier, not a discount conversation; and price the total honestly, licence plus the parallel processes any system leaves you running, because the cheapest PMR that leaves the whole compliance stack in spreadsheets is the most expensive option in the room.
"The system's job is to make the record that proves compliance a by-product of doing the work."
So that when the GPhC inspector, the clinic partner or the recall coordinator asks their question, the answer is a query. That is the standard we built Dataforge PMR toward, and it is the standard you should hold every vendor to, including us.
Key takeaways
- A CBPM pharmacy's software must carry what generic PMRs were never built for: structured remote assessments, prescriber verification records, batch-to-patient traceability and monitoring over long-term therapy.
- Score every vendor against the ten criteria, with batch traceability and dated CD functionality as the questions that separate honest answers from feature-list assurances.
- Dataforge PMR runs the clinical-to-dispensing loop in one audit-trailed platform: embedded assessments, longitudinal custom fields, drug data with decision support, notes and dispensing with cautionary-label printing.
- The Dataforge PMR CD register module ships at the end of 2026; until then the register, and the batch log, run as disciplined parallel processes, stated here because vendor honesty is a selection criterion.
- The diligence layer, DCB0129, DPA, UK/EEA hosting, audit trails, is a disqualifier gate, not a negotiating point.
- Buy against your written workflow and keep every vendor's answers in writing; the record-as-by-product principle is the whole game.
FAQs
See where the platform ends.
The fastest way to test this article is against the live system: a 30-minute Dataforge PMR walkthrough covers the embedded assessment, the longitudinal fields, the dispensing and labelling loop and the audit trail, and we will show you exactly where the platform ends and your parallel processes begin, because that boundary is the honest part of every vendor conversation.
Book a 30-minute demo