# Configure MHRA AS2 Connection

Safety supports the United Kingdom Medical and Healthcare products Regulatory Agency (UK MHRA) Gateway through AS2 (system-to-system) communication. The UK MHRA Gateway can be used for ICSR submissions to the MHRA in the EMA E2B(R3) file format. Safety defines the _Case_ criteria for these _Submissions_ using the _MHRA Rule Set_, which is based on the _EMA ICSR Reporting Rule Set_.

Vault's integration with the UK MHRA allows you to set up an <a href="/en/gr/703946/">_AS2 Connection_</a> to submit ICSRs directly from Safety and receive gateway responses.

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: If your organization is a CRO making <em>Submissions</em> on behalf of clients, you must complete each of the steps on this page separately for each sponsor, including setting up a new MHRA Account and obtaining new certificates.</p>
    </div>
  </div>
</div>



<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: If your Vault currently uses the <a href="/en/gr/01208/">MHRA <em>Gateway Profile</em></a> to communicate with the MHRA, we recommend that you <a href="#create-as2-connection">create an <em>AS2 Connection</em> to the MHRA</a> as described in this article and then follow the instructions in <a href="/en/gr/01460/">Replace a Gateway Profile with an AS2 Connection</a>.</p>
    </div>
  </div>
</div>



## Prerequisites

In addition to enabling <a href="/en/gr/01459/">AS2 Connections</a>, you must perform the following one-time configuration changes before you can set up MHRA Gateway submissions:

* [Activate MHRA as a Standard _Organization_][1]
* [Update Country Records][2]

### Prerequisite: Activate MHRA as a Standard Organization {#activate-mhra-org}

MHRA is a standard _Agency_ provided with Safety. However, in certain Vaults, your Admin must activate the _Agency_ record.

Complete the following steps if MHRA is inactive in your Vault:

1. Navigate to **Business Admin > Objects > Organizations**.
2. Open the **MHRA (UK)** _Agency_ record.
3. From the **All Actions** menu, select **Change State to Active**.


<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: 
The <strong>Change State to Active</strong> user action appears only if configured by your Admin. <a href="/en/gr/01433/#add-user-action-to-the-organization-lifecycle-inactive-state">Enable Regulatory Agencies as Standard Organizations</a> provides instructions.</p>
    </div>
  </div>
</div>



### Prerequisite: Update Country Records {#update-uk-northern-ireland}

From January 1, 2021, all products authorized in Great Britain must have their ICSRs submitted to the MHRA. ICSRs for products authorized in Northern Ireland should be submitted to the EMA. For more information, visit the United Kingdom's <a target="_blank" href="https://www.gov.uk/government/publications/guidance-on-pharmacovigilance-procedures-in-the-event-from-1-january-2021/updated-guidance-on-pharmacovigilance-procedures">Guidance on Pharmacovigilance Procedures website</a>.

To ensure all new _Cases_ reference the correct _Country and _Agency_, we recommend updating the existing **United Kingdom of Great Britain and Northern Ireland** record in your Vault to separate **Great Britain** and **Northern Ireland** records.

Complete the following steps to update the **Country** records:

* [Step One: Update Existing Country Record to the United Kingdom (Great Britain) Record][3]
* [Step Two: Create the United Kingdom (Northern Ireland) Record][4]

#### Step One: Update Existing Country Record to the United Kingdom (Great Britain) Record {#update-uk-gb}

1. Navigate to **Business Admin > Objects > Countries**.
2. Select **United Kingdom of Great Britain and Northern Ireland**. The **Country** page appears.
3. Select <strong>Edit</strong>.
4. Under <strong>Details</strong>, update the following fields:
    * **Name:** Enter **United Kingdom (Great Britain)**.
    * **Code (2-letter):** Enter **GB**.
    * **Code (3-letter):** Enter **GBR**.
    * **Agency:** Select **MHRA (UK)** from the picklist.
5. Select **Save**.

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: We recommend updating the existing <strong>Country</strong> record as detailed above instead of changing its state to Inactive and creating a new record for Great Britain. Due to an overlap in Code (3-letter) values, creating a new record with the same code will cause E2B imports to fail.</p>
    </div>
  </div>
</div>



#### Step Two: Create the United Kingdom (Northern Ireland) Record {#create-uk-ni}

1. Navigate to **Business Admin > Objects > Countries**.
2. Select **Create**. The **Create Country** page appears.
3. Under **Details**, complete the following fields:
    * **Name:** Enter **United Kingdom (Northern Ireland)**.
    * **Code (2-letter):** Enter **XI**.
    * **Code (3-letter):** Enter **GBR**.
    * **Agency:** Select **EMA** from the picklist.
4. Select **Save**.

**Result**

Your Vault has two (2) updated **Country** records:

<a href="https://platform.veevavault.help/assets/images/saf-uk-updated-country-records.png" data-lightbox="saf-uk-updated-country-records.png" data-title="" data-alt="Updated UK Country Records">
  <img class="docimage" src="https://platform.veevavault.help/assets/images/saf-uk-updated-country-records.png" alt="Updated UK Country Records" style=""  />
</a>

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: Once the <em>Country</em> records have been updated, we recommend that pre-existing <em>Products</em> and <em>Cases</em> should be reviewed and updated with the correct <em>Country</em> and <em>Agency</em>. For more information, see the EMA’s <a target="_blank" class="uk-link" href="https://www.ema.europa.eu/en/documents/other/questions-answers-stakeholders-implementation-protocol-ireland/northern-ireland_en.pdf">Northern Ireland Submission Guidelines</a>.</p>
    </div>
  </div>
</div>



## Configure a UK MHRA AS2 Account

Before you can configure the Safety _AS2 Connection_, you must have an active UK MHRA AS2 account. The <a target="_blank" href="https://www.gov.uk/guidance/registering-to-make-submissions-to-the-mhra-from-1-january-2021">MHRA website</a> provides instructions for setting up the gateway registration.

### Public and Private Certificates

As part of the MHRA registration process, you must obtain a public and private certificate pair and send the public certificate to the MHRA.
Your Admin can <a href="/en/gr/872385/#create-sponsor-cert">create these certificates within Vault</a>.


## <a id="create-as2-connection"></a> Configure a Safety AS2 Connection

1. Navigate to **Admin > Connections**, then select **Create**.
2. For the **Connection Type**, select **AS2**, then select **Continue**.
3. Complete the applicable <a href="#as2-connection-fields">fields</a>.
4. Select **Save**.

### AS2 Connection Fields {#as2-connection-fields}

With the exception of <a href="#transfer-fields">_Transfer Connection_</a> fields and fields populated by Vault, complete all fields in the following sections:

* <a href="#details-fields">AS2 Details Fields</a>
* <a href="#partner-fields">AS2 Partner Details Fields</a>
* <a href="#sponsor-fields">AS2 Sponsor Details Fields</a>

#### AS2 Details Fields {#details-fields}

<table>
    <thead>
        <tr>
            <th>
                Field
            </th>
            <th>
                Description
            </th>
        </tr>
    </thead>
    <tbody>
        <tr>
            <td>
                <em>Name</em>
            </td>
            <td>
                Enter a name for the <em>AS2 Connection</em>.<br>
                This name must be unique in your Vault.
            </td>
        </tr>
        <tr>
            <td>
                <em>API Name</em>
            </td>
            <td>
                Enter an API Name for the <em>AS2 Connection</em>.<br>
                This name must be unique in your Vault.<br>
            </td>
        </tr>
        <tr>
            <td>
                <em>Description</em>
            </td>
            <td>
                Enter a description for the <em>AS2 Connection</em>.
            </td>
        </tr>
        <tr>
            <td>
                <em>Contact Email</em>
            </td>
            <td>
                Enter the Sender's Email.
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Vault Gateway State</em><a id="as2-vault-gateway-state"></a>
            </td>
            <td>
                Vault populates this field with the current state of the AS2 Vault Gateway, which consists of one (1) of the following options:
                <ul>
                    <li>
                        <strong>Unregistered</strong>: The <strong>Sync to Gateway</strong> action has not yet been run for this <em>AS2 Connection</em>.
                    </li>
                    <li>
                        <strong>Registered</strong>: The <em>AS2 Connection</em> is synchronized with the Gateway.
                    </li>
                    <li>
                        <strong>Out of Sync</strong>: Changes have been made to the <em>AS2 Connection</em> or its Connection Allowed List since the last time the <strong>Sync to Gateway</strong> action was run. From the <strong>All Actions</strong> menu, select <strong>Sync To Gateway</strong> to resync the <em>AS2 Connection</em> with the Gateway.
                    </li>
                </ul>
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Encryption</em>
            </td>
            <td>
                The algorithm Vault uses to encrypt outbound AS2 messages and decrypt inbound messages.<br>Vault supports the following algorithms:
                <ul>
                    <li>Triple DES (3DES)</li>
                    <li>AES-256-GCM</li>
                    <li>AES-256-CBC</li>
                </ul>
                
                        For the MHRA, select <strong>Triple DES (3DES)</strong>.
                    
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 MDN Setting</em>
            </td>
            <td>
                Whether the Message Delivery Notification (MDN) can be exchanged synchronously (<strong>Sync</strong>) or asynchronously (<strong>Async</strong>).<br>
                
                        For the MHRA, select <strong>Async</strong>.
                    
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Signature</em>
            </td>
            <td>
                The method Vault uses to sign outbound AS2 messages. Vault supports the following signing methods:
                <ul>
                    <li>SHA-1</li>
                    <li>SHA-256</li>
                </ul>
                
                        For the MHRA, select <strong>SHA-256</strong>.
                    
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Additional ACK Stages</em>
            </td>
            <td>
                If required, select one (1) or more of the following options:
                <ul>
                    <li>
                        <strong>HTTP Handshake</strong>: Used primarily for asynchronous requests.
                    </li>
                    <li>
                        <strong>PRE-ACK</strong>: Used mainly for FDA VAERS, but can be used with synchronous or asynchronous requests.
                    </li>
                </ul>
                <div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: We do not recommend using any additional ACK stages.</p>
    </div>
  </div>
</div>


            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Partner Sends ACK on MDN URL</em><a id="partner-ack-on-mdn-url"></a>
            </td>
            <td>
                <p>
                    The default setting for this field is <em>No</em>, as Vault expects an AS2 partner to send the ACK using a different URL than that used to send the MDN.
                </p>
                <p>
                
                        Select <strong>No</strong>.
                
                </p>
                <p>
                    For more information about AS2 gateway communications, see <a href="/en/gr/01266/#what-is-as2-gateway-communication">Send a Gateway Transmission</a>.
                </p>
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Compression Settings</em><a id="as2-compression-settings"></a>
            </td>
            <td>
                
                        For the MHRA, select <strong>Compress After Sign (Standard)</strong>.
                    
            </td>
        </tr>
    </tbody>
</table>

#### AS2 Partner Details Fields {#partner-fields}

<table>
    <thead>
        <tr>
            <th>
                Field
            </th>
            <th>
                Description
            </th>
        </tr>
    </thead>
    <tbody>
        <tr>
            <td>
                <em>AS2 Partner ID</em>
            </td>
            <td>
                
                        <p>
                            Enter one of the following MHRA identification codes:
                        </p>
                        <ul>
                            <li>For a production account, enter <code>MHRAUK</code></li>
                            <li>For a test account, enter <code>MHRAUKTEST</code></li>
                        </ul>
                    <p>This value cannot include spaces. Instead, use a hyphen (<code>-</code>) or an underscore (<code>_</code>).</p>
                    
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Partner URL</em>
            </td>
            <td>
                
                        <p>
                            Enter one (1) of the following destination MHRA Gateway URLs:
                        </p>
                        <ul>
                            <li>
                                For a production account, confirm with the MHRA which of the following URLs to enter:
                                <ul>
                                    <li><code>https://mft.mhra.gov.uk/as2receiver.aspx?Tag=PV</code></li>
                                    <li><code>https://mft1.mhra.gov.uk/as2receiver.aspx?Tag=PV</code></li>
                                </ul>
                            </li>
                            <li>
                                For a test account,  confirm with the MHRA which of the following URLs to enter:
                                <ul>
                                    <li><code>https://mft.test.mhra.gov.uk/as2receiver.aspx?Tag=PV</code></li>
                                    <li><code>https://mft1.test.mhra.gov.uk/as2receiver.aspx?Tag=PV</code></li>
                                </ul>
                            </li>
                        </ul>
                    
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Partner Certificate Expiry</em>
            </td>
            <td>
                Vault populates this field when your Admin <a
                href="#upload-certificates">uploads the partner certificate</a>.
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Partner Certificate Serial Number</em>
            </td>
            <td>
                When you upload a new partner certificate for this connection, Vault sets this field to the Serial Number of the certificate in decimal format.
            </td>
        </tr>
    </tbody>
</table>

#### AS2 Sponsor Details Fields {#sponsor-fields}

<table>
    <thead>
        <tr>
            <th>
                Field
            </th>
            <th>
                Description
            </th>
        </tr>
    </thead>
    <tbody>
        <tr>
            <td>
                <em>AS2 Vault ID</em>
            </td>
            <td>
                
                      Enter the sponsor ID registered with the MHRA. This value is the same as the customer's Routing ID you provided when setting up your production or test MHRA account. This value cannot include spaces. Instead, use a hyphen (<code>-</code>) or an underscore (<code>_</code>). 
                    
            </td>
        </tr>
        <tr>
            <td>
                <a id="as2-vault-url"></a>
                <em>AS2 Vault URL</em>
            </td>
            <td>
                
                <p>
                    Enter the AS2 URL of your Vault in the following format, replacing <code>&lt;SponsorName&gt;&lt;Partner&gt;&lt;Environment&gt;</code> with the corresponding values of your Vault:
                </p>
                <p>
                    <code>https://&lt;SponsorName&gt;&lt;Partner&gt;&lt;Environment&gt;.gateway.veevavaultsafety.com:4080</code>
                </p>
                <p>
                    The following example demonstrates how to form the AS2 Vault URL for a Vault with the following values:
                </p>
                <ul>
                    <li><code>&lt;SponsorName&gt;</code> = vern</li>
                    <li><code>&lt;Partner&gt;</code> = mhra</li>
                    <li><code>&lt;Environment&gt;</code> = validation</li>
                    <li>AS2 Vault URL = <code>https://vernmhravalidation.gateway.veevavaultsafety.com:4080</code></li>
                </ul>
                <p>
                    <strong>Informing the Partner of your AS2 Vault URL</strong>
                </p>
                <p>
                    When informing the partner of the URL they need to use for this <em>AS2 Connection</em>, use the value you entered in this field appended with <code>/api/v1/inbound/transmission</code>
                </p>
                <p>
                    In the example shown above, this is <code>https://vernmhravalidation.gateway.veevavaultsafety.com:4080/api/v1/inbound/transmission</code>
                </p>
                
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Vault Certificate Expiry</em>
            </td>
            <td>
                Vault populates this field when your Admin <a
                href="#upload-certificates">uploads the sponsor certificate</a>.
            </td>
        </tr>
        <tr>
            <td>
                <em>AS2 Vault Certificate Serial Number</em>
            </td>
            <td>
                When you upload a new sponsor certificate for this connection, Vault sets this field to the Serial Number of the certificate.
            </td>
        </tr>
        <tr>
            <td>
                <a id="as2-vault-domain-ip-config"></a>
                <em>AS2 Vault Domain / IP Configuration</em>
            </td>
            <td>
                <p>
                    Select the method the partner uses to interface with the <em>AS2 Connection</em>.
                </p>
                <ul>
                    <li><strong>AS2 Vault URL: Domain Name (typical)</strong>: A standard domain name that resolves to dynamic IP addresses.</li>
                    <li><strong>AS2 Vault URL: Domain Name bound to static IP addresses</strong>: A standard domain name that resolves to static IP addresses.</li>
                    <li><strong>AS2 Vault URL: IP URL (uncommon)</strong>: A non-standard IP address domain name that resolves to an IP address.</li>
                </ul>
                
                      For the MHRA, select <strong>AS2 Vault URL: Domain Name bound to static IP addresses</strong>.
                    
            </td>
        </tr>
    </tbody>
</table>

#### Transfer Connection Fields {#transfer-fields}

Leave the fields in this section blank.


### Upload the Partner and Sponsor Certificates {#upload-certificates}

Safety uses
<a href="/en/gr/872385/">partner and sponsor certificates</a>
to communicate securely with the partner. You will have received the partner certificate as part of creating your account with the partner.

Complete the following steps to create and upload these certificates:
* <a href="/en/gr/872385/#upload-partner-cert">Upload the partner certificate for the connection</a>.
* <a href="/en/gr/872385/#create-sponsor-cert">Create a sponsor certificate for the connection</a>.

### Add Connection Allowed IPs

Specify one (1) or more Allowed Connections for the _AS2 Connection_. These are Internet Protocol (IP) addresses that Vault will allow to connect with this _AS2 Connection_.

Perform the following steps for each Allowed Connection you want to add to the _AS2 Connection_:

1. Navigate to **Admin > Connections > [Connection] > Connection Allowed Lists**, then select **Create**.
2. On the **Create Connection Allowed List** window, complete the following information:
  * **Name**: Enter a name for the Allowed Connection.
  * (Optional) **Description**: Enter a description for the Allowed Connection.
  * **IP**: Enter the address of the Allowed Connection. \
  Ensure the format of the **IP** address is `XX.XX.XX.XX` or `XX.XX.XX.XX/{subnet mask}` where the `{subnet mask} `is a number between 24 and 32.
3. Repeat the above steps for each Allowed Connection.
4. When you have added all the Allowed Connections, select **Save**.

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: By default, Vaults are limited to 512 Allowed Connections. If your organization requires more, contact your Veeva Representative.</p>
    </div>
  </div>
</div>



### Synchronize the Connection {#sync-as2-connection}

Once you have entered all the details of the _AS2 Connection_, the Connection must be synchronized with the Gateway.

From the **All Actions** menu, select **Sync Connection to Gateway**.

When Vault successfully completes this action, the Connection's [AS2 Vault Gateway State](#as2-vault-gateway-state) changes to **Registered** and Vault can send and receive messages using this Connection.

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: If the <em>Sync Connection to Gateway</em> action is not successful, ensure each field value on the <em>AS2 Connection</em> is correct before retrying the action again. If the issue persists, <a href="/en/gr/728014/">troubleshoot the connection</a>.</p>
    </div>
  </div>
</div>



If you make any changes to the **Connection** object or its Connection Allowed List, the **AS2 Vault Gateway State** changes to **Registered - Out of Sync**. Vault cannot send or receive any messages using this Connection while it is in the **Registered - Out of Sync** state. You will need to repeat the **All Actions > Sync to Gateway** action to restore the Connection to the **Registered** state.


**Result**

The UK MHRA _AS2 Connection_ is active and available to use to submit case reports to the MHRA.

## <a id="configure-the-MHRA-transmission-profile"></a>Configure the MHRA Transmission Profile

Safety comes with a system-provided **MHRA** _Transmission Profile_ for electronic _Submissions_ to MHRA.  You must configure this _Transmission Profile_ as part of the MHRA Gateway setup.

<a href="/en/gr/01202/">Manage Transmission Profiles</a> provides instructions on setting up _Transmission Profiles_.

Complete the following steps to set up the _Transmission Profile_:

1. **Origin ID:** Enter the ID registered with the MHRA, typically your D-U-N-S number. This value is the same as the customer's Routing ID you provided when setting up your production or test MHRA account.
2. **Destination ID:** Enter one (1) of the following Destination IDs:
    * For a production account, enter `MHRAUK`.
    * For a test account, enter `MHRAUKTEST`.
3. **Routing ID:** Enter one of the following Routing IDs:
    * For a production account, enter `MHRAUK`.
    * For a test account, enter `MHRAUKTEST`.

Once you set up the MHRA _Transmission Profile_, Vault uses the appropriate _Transmission Profile_ to generate _Submissions_ based on your Vault's MHRA <a href="/en/gr/01252/">reporting rules</a>.

[1]: #activate-mhra-org
[2]: #update-uk-northern-ireland
[3]: #update-uk-gb
[4]: #create-uk-ni