SafeNet Agent for Epic
Version: 3.0.7
Build: 3.0.7.180
Issue Date: June 2026
Product Description
The SafeNet Agent for Epic is a solution to enable strong Two-Factor Authentication (2FA) for Epic.
EPCS Compliance
Customers seeking to comply with the US Drug Enforcement Agency's (DEA) Electronic Prescriptions for Controlled Substances (EPCS) regulation, can demonstrate compliance using any edition of the SAS together with SafeNet MobilePASS software tokens. When MobilePASS is installed on a separate mobile device (smartphone or tablet), the token becomes an EPCS compliant 'hard token'. Updated to extend the EPCS regulation cover for SafeNet Agent for Epic, wherever appropriate.
Release Description
Release Summary – SafeNet Agent for Epic 3.0.7
The SafeNet Agent for Epic 3.0.7 release introduces the following enhancement and resolves a customer-reported issue.
Extended Operating System Support
The SafeNet Agent for Epic 3.0.7 now supports Windows Server 2025 (64-bit).
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-21814 | The end user authentication was failing intermittently after the OTP submission. This issue has now been fixed and the authentication works properly. |
Release Summary – SafeNet Agent for Epic 3.0.6
The SafeNet Agent for Epic 3.0.6 release resolves the following customer-reported issue.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-18589 | The agent was not compatible with the CNG-based certificates for SAML token signing. Now, the agent supports the certificates that are stored using Microsoft Software Key Storage Provider for CNG-based cryptography in addition to the previously supported certificate type, that is, Microsoft RSA SChannel Cryptographic Provider for CryptoAPI (CAPI)-based cryptography. |
Release Summary – SafeNet Agent for Epic 3.0.5
The SafeNet Agent for Epic 3.0.5 release introduces some improvements and resolves a customer-reported issue.
Improvement
- Epic Hyperdrive is now given priority over Epic Hyperspace during agent installation, uninstallation, and upgrade.
- Details of the registry settings are now included in the Configuring Settings via Group Policy Object Editor section in the Installation and Configuration Guide.
Limitation
For this release, the agent does not support Repair and Change functionality.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-18014 | The users were not able to repair the agent from the Control Panel > Programs and Features. Since the repair functionality is not supported via the control panel, the Repair button is now removed. |
Release Summary – SafeNet Agent for Epic 3.0.4
The SafeNet Agent for Epic 3.0.4 release resolves the following customer-reported issue.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-18749 | While signing EPCS, users had to click on the MFA prompt to enter the OTP. This issue is now fixed, and the users can directly enter OTP on the MFA prompt. |
Release Summary – SafeNet Agent for Epic 3.0.3
The SafeNet Agent for Epic 3.0.3 release resolves the following customer-reported issue.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-18645 | When the user attempts for EPCS signing, the SafeNet MFA prompt was hidden behind the EPIC Hyperdrive software, which caused user inconvenience. This issue is now fixed and the MFA prompt is visible to the users as expected. |
Release Summary – SafeNet Agent for Epic 3.0.2
The SafeNet Agent for Epic 3.0.2 release resolves the following customer-reported issue.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-18045 | Earlier, the agent was not being invoked for non-admin users from Epic Hyperspace/Hyperdrive. This issue is now fixed. |
Release Summary – SafeNet Agent for Epic 3.0.1
The SafeNet Agent for Epic 3.0.1 release resolves the following customer-reported issues.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-17372/SASNOI-16038 | Earlier, the agent could not detect the Epic software's DLL if the agent and Epic software installation path is different. Now, the agent works independent of the Epic software's DLL path. |
| SASNOI-16884 | The Universal Naming Convention (UNC) path was not configurable for logging from the management console. Now, the agent supports the UNC format path for logging. |
| SASNOI-17882 | The users were getting an error while invoking the management console via command prompt from a location other than the agent-installed location. This issue is now fixed. |
Release Summary – SafeNet Agent for Epic 3.0.0
The SafeNet Agent for Epic 3.0.0 release introduces the following new features.
Renamed Agent
From this release onwards, the agent is renamed to SafeNet Agent for Epic.
Hyperdrive Support
The SafeNet Agent for Epic 3.0.0 now supports Epic Hyperdrive in addition with Epic Hyperspace.
Certificate tab
A Certificate tab is added in the Epic Management Console that enables to upload the signing certificate. The certificate is used to sign the SAML token response generated when using with Epic Hyperdrive.
Thales Branding
The SafeNet Agent for Epic is updated with the Thales branding.
Extended Operating System Support
The SafeNet Agent for Epic 3.0.0 now supports Windows 11 and Windows Server 2019 (64-bit).
Release Summary – SafeNet Agent for Epic Hyperspace 2.0.1
The SafeNet Agent for Epic Hyperspace 2.0.1 release introduces the following features and resolves a customer-reported issue.
Upgrade Support
The SafeNet Agent for Epic Hyperspace 2.0.1 release supports the upgrade from 1.1.0 (or later versions).
Extended Operating System Support
The SafeNet Agent for Epic Hyperspace 2.0.1 now supports Windows Server 2016 (64-bit).
Ignore server SSL certificate check
A capability to disable the SSL server certificate error check on the agent is added to the Communication tab of Epic Management Console. It is unchecked by default. If customers are using the on-premise deployment of SAS within a well-controlled network (where self-signed certificates are used and cannot be properly validated by the SafeNet Epic Hyperspace Agent), this checkbox needs to be selected.
Note
We strongly recommend the use of SSL certificates.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-9194 | The error "Failed to initialize SignalR COM Library on Hyperspace 11/2018 edition (HRESULT: 0x80131040)" is now resolved. |
Release Summary – SafeNet Agent for Epic Hyperspace 2.0.0
This general availability release offers a new feature, and resolves important issues since the previous release. Following list important details.
Group Policy Settings
Group Policy settings of the SafeNet Agent for Epic Hyperspace can now be updated using Windows tools. Policy settings are stored in a Windows Administrative Template (ADMX) file, and can be configured using the steps:
- Adding ADMX file to Group Policy Object (GPO) Editor
- Configuring ADMX settings using GPO Editor
For more information, refer Installation and Configuration Guide.
Release Summary – SafeNet Agent for Epic Hyperspace 1.1.0
This release includes an enhancement and resolves an issue since the previous release. Following lists the details:
OTP Text and Message Text Fields
Two new text fields (Enter OTP Text and Enter Message Text) are added in the Configuration tab of the Epic Management Console, to allow customization of messages on the Epic OTP prompt window. Based on their deployed tokens, customers can control the messages, to make it clear and consistent with their enterprise terminologies.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-2739 | The agent installation error (ERROR 1722) is now resolved. |
Release Summary – SafeNet Agent for Epic Hyperspace 1.0
The SafeNet Agent for Epic v1.0 is the first formal release of this product.
Prerequisites
- Ensure that the Epic Hyperspace/Hyperdrive application is already installed on the system, where the agent is proposed for the installation.
- Ensure that the user has administrative rights for installing and configuring the SafeNet Agent for Epic.
- To successfully configure and implement the agent, the administrator must be familiar with SafeNet Authentication Service (SAS) Cloud or SAS Service Provider's Edition (SAS SPE)/SAS Private Cloud Edition (SAS PCE) and the SafeNet Trusted Access (STA). Create an account in SafeNet Authentication Service (SAS) Cloud or SAS PCE 3.9.1 (and above).
Supported Use Case
The SafeNet Agent for Epic enables seamless integration with Hyperspace, Epic's legacy client application and Hyperdrive, a Chromium web-based framework. Deploying the SafeNet agent in Epic's environment provides a capability to verify identities and sign records before accessing health records and performing related actions.
The supported use case is presently limited to the application of 2FA while signing the controlled substances patient records. The agent's functionality, though can be extended, to support Epic's other use cases with future releases.
Compatibility and Component Information
Interoperability
Supported operating systems:
- Windows 11
- Windows Server 2016 (64-bit)
- Windows Server 2019 (64-bit)
- Windows Server 2022 (64-bit)
- Windows Server 2025 (64-bit)
Software Component
- Microsoft .NET Framework 4.6
Configuration Component
- SafeNet Epic Management Console utility
Supported Tokens
- All authentication tokens currently supported by SafeNet Authentication Service except Push OTP.
Product Documentation
The following product documentation is associated with this release: