Hospital security is the only branch of the discipline where the regulator has written the programme for you. That is unusual, and it changes the conversation. In most sectors a security manager has to argue for budget on risk grounds. In healthcare the argument is largely settled: an accreditation body requires a defined programme, and the survey looks for it.
The consequence is that hospitals which under-invest are not merely accepting risk. They are carrying a findable deficiency.
The scale of the problem
The Joint Commission, citing OSHA, states that healthcare workers are four to five times more likely to suffer workplace violence injuries than workers in private industry overall.
The trend behind that is measurable. Incidence rates of nonfatal occupational injuries involving days away from work due to intentional injury by another person, in the private healthcare and social assistance industry, rose from 10.4 per 10,000 full-time workers in 2018 to 15.2 per 10,000 in 2020 — a 46% increase in two years.
OSHA’s own healthcare workplace violence resources reinforce the point and set out the control categories: a written and implemented prevention programme combined with engineering controls, administrative controls and training.
The regulatory frame, stated plainly
In 2022 the Joint Commission issued new and revised standards establishing a framework for hospital workplace violence prevention, and extended those requirements across all of its accreditation programmes. The framework has seven components: leadership oversight, policies and procedures, reporting systems, data collection and analysis, post-incident strategies, training, and education.
Specifically, hospitals are required to:
- Run a workplace violence prevention programme led by a designated individual and developed by a multidisciplinary team.
- Provide training, education and resources to staff and leadership at hire and regularly thereafter.
- Maintain policies and processes to prevent and respond to violence, to report incidents so that incidents and trends can be analysed, and to follow up with and support victims and witnesses.
- Report workplace violence to the governing body.
- Complete a worksite analysis and act on what it finds to mitigate or resolve safety and security risks.
Since January 2022 the Joint Commission has cited hospitals on more than one hundred requirements for improvement relating to these standards during survey activity, with correction required within sixty days.
The definition is broader than most hospitals implement
This is the part that trips organisations up. The Joint Commission defines workplace violence as an act or threat occurring at the workplace that can include verbal, nonverbal, written or physical aggression; threatening, intimidating, harassing or humiliating words or actions; bullying; sabotage; sexual harassment; physical assaults; or other behaviours of concern involving staff, licensed practitioners, patients or visitors.
Note what that captures. Bullying. Sabotage. Intimidation. Behaviour between colleagues, not only from patients and visitors. A hospital whose incident reporting only records physical assaults by patients is measuring a fraction of what the standard covers, and its data will not support the analysis the standard requires.
Where the physical risk actually concentrates
The regulatory frame does not tell you where to put people. The site does.
The emergency department is the consistent hotspot: unscreened entry, pain, intoxication, waiting, and bad news. It is also where a security presence is most visible to the public, which cuts both ways.
Behavioural health units carry elevated risk by the nature of the population, and are the area where physical design — ligature resistance, sightlines, furniture — does the most work.
Car parks and shift-change routes. Staff leaving at 11 p.m. cross a large dark space. This is a predictable exposure and one of the cheapest to address, through lighting, escort at shift change, and a patrol pass timed to the change rather than to the hour.
Maternity and paediatrics carry infant abduction protocols and custody-dispute risk, both of which need controlled egress rather than controlled entry.
Pharmacy and controlled substance storage is an internal diversion problem more often than an external theft problem, and the controls that catch it are audit-based.
Loading docks and after-hours entrances are how people get in when the main doors are staffed.
Where hospital programmes commonly fall short
Under-reporting. Clinical staff frequently regard verbal abuse and minor physical aggression as part of the job and do not report it. That is a data problem before it is a culture problem: a worksite analysis built on under-reported data understates the risk and misdirects the response. Getting reporting up will make the numbers look worse, and leadership has to be told that in advance.
Security treated as separate from clinical operations. The standard requires a multidisciplinary team. A programme owned solely by a security manager, without nursing, behavioural health, HR and facilities in the room, will not satisfy it and will not work.
Training that is generic. De-escalation training aimed at an emergency department nurse and at a car park attendant should not be the same training.
No post-incident support. Follow-up with victims and witnesses is an explicit requirement, and it is the element most often absent. It is also the one that most affects whether people report the next incident.
The practical takeaway
A hospital that treats security as guards at a door is exposed twice over — to the incident, and to the finding. The programme the standards describe is largely administrative: someone accountable, a team, a reporting route, analysis of what comes in, a worksite analysis acted upon, training, and support afterwards. Officers matter, but they are one control inside that structure rather than a substitute for it.
Honeybadger Solutions works with facilities on both halves — the physical posture at the points where risk concentrates, and the programme structure that has to sit around it. How to choose the posture itself is covered in standing post, patrol or armed; the staff-facing element is delivered through security awareness training; and where an incident involves a specific individual who needs identifying or tracing, that becomes private investigations.
Workplace violence: the standard the regulator now enforces
Healthcare is the sector where the workplace-violence problem is worst and the rules are most explicit. Since January 2022 the Joint Commission’s workplace-violence-prevention standards have required accredited hospitals to run a worksite analysis, maintain a written prevention policy, collect and follow up on incident reporting, and train staff — not as good practice but as a condition of accreditation. OSHA reaches the same behaviour through the General Duty Clause, citing healthcare employers who fail to protect staff from a hazard they knew about, and publishes healthcare-specific violence-prevention guidelines that inspectors use as the yardstick. CMS’s Conditions of Participation sit underneath both, obliging a hospital to provide a safe environment as a condition of Medicare funding. The practical effect is that a hospital security programme is now audited from three directions at once, and the design details — sightlines, controlled access to the emergency department and behavioural-health units, panic infrastructure, and the IAHSS design guidelines — are the evidence that the programme is real rather than paper.
Frequently asked questions
Is hospital security legally required?
Yes, in effect. No single statute says “hire guards,” but the Joint Commission’s workplace-violence standards, OSHA’s General Duty Clause, and CMS Conditions of Participation together require a hospital to identify security risks and control them — and to show its work. A hospital without a documented, active security programme is exposed on all three fronts.
What does the Joint Commission require for security?
Since 2022 its workplace-violence-prevention standards require a worksite analysis, a written prevention plan, incident reporting and follow-up, and staff training. It does not prescribe guard counts; it requires evidence that risks were assessed and addressed.
Does OSHA regulate violence against healthcare workers?
Yes, through the General Duty Clause. OSHA has cited hospitals for failing to protect staff from foreseeable violence and publishes healthcare-specific guidelines its inspectors apply as the standard of care.
Should hospital security officers be armed?
It depends on the threat assessment, the state, and the facility’s policy — there is no single right answer. What matters more is training, de-escalation capability, behavioural-health protocols, and a clear use-of-force policy. Many hospitals run a tiered model rather than a blanket armed-or-unarmed rule.
What is IAHSS?
The International Association for Healthcare Security and Safety, which publishes the design and industry guidelines most hospitals and accreditation surveyors treat as the standard of care for healthcare security.
Where do hospital security programmes most often fall short?
The recurring gaps are uncontrolled access to the emergency department and behavioural-health units, weak incident reporting that hides the true frequency of assaults, and training that stops at policy rather than de-escalation. Programmes also drift out of date between accreditation cycles, so what passed a survey two years ago no longer matches the building or the threat.
How often should a hospital security assessment be updated?
At least annually, and after any incident, renovation, or change in patient population. Behavioural-health volume, emergency-department throughput, and local crime all shift the risk picture faster than most programmes are reviewed.
Benchmark your hospital security programme
A credible programme starts with an honest assessment against these standards — where access control, the emergency department, and behavioural health actually stand against what the Joint Commission, OSHA, and CMS expect. See our security assessments and security services. Honeybadger Solutions is a veteran-owned, Arizona-licensed firm — request a consultation to benchmark yours.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles