top of page

Beyond Officers and Equipment: What Makes a Hospital Security Program Comprehensive?

Writer: Mike Dunning
Mike Dunning
Aug 12
11 min read

If you like this article, please scroll to the bottom and hit "Like" and leave a comment or two. Thank you for reading!


Ask someone what makes up a hospital security program, and the answer will often include security officers, cameras, access-control systems, metal detectors, panic alarms, and perhaps weapons.


Those may all be parts of the program, but having them does not automatically create a comprehensive security program.


A comprehensive program must protect patients, visitors, employees, information, critical spaces, and the hospital’s ability to continue providing care when something goes wrong.


Non-escalation matters. De-escalation matters. But they are individual tools within one layer of a much larger system.


People cannot communicate their way out of every dangerous situation. Cameras cannot compensate for poor staffing. Metal detectors cannot identify intent. Badge readers cannot protect doors that are routinely propped open. Security officers cannot succeed without clear direction, appropriate training, effective equipment, clinical partnership, and organizational support.


The question is not how many layers the hospital owns. The question is whether it has the right layers, whether they address the organization’s actual risks, and whether they work together.


Start With Risk and Leadership


There is no universal security program that can simply be copied from one hospital and installed in another.


A rural critical access hospital does not have the same risks or resources as an urban Level I trauma center. A children’s hospital does not have the same patient population as a behavioral health facility. Even two similar hospitals in the same community may differ in design, staffing, history, culture, surrounding crime, and law-enforcement response.


The program must be based on the risks of the individual organization.

Security risks should be incorporated into the hospital’s Hazard Vulnerability Analysis, or


HVA, because the process is essentially the same:

  • What could happen?

  • How likely is it?

  • Who or what could be affected?

  • How severe could the consequences be?

  • What safeguards are already in place?

  • How prepared is the hospital to prevent, respond to, and recover from it?

  • Where do significant gaps remain?


Hospitals routinely use the HVA to evaluate natural hazards, technological failures, hazardous-material incidents, emerging infectious diseases, and human-caused events.


Workplace violence, active threats, infant or child abduction, unauthorized access, civil unrest, bomb threats, cyberattacks, and other security events belong in that analysis.


The HVA and a detailed security assessment should inform one another, but they are not necessarily the same document. The HVA identifies and compares the hospital’s hazards. The security assessment takes the priority security concerns apart and examines whether the safeguards can actually manage them.


For example, the HVA may identify workplace violence as a high-priority hazard. The security assessment should then determine where incidents occur, who is most exposed, what contributes to the risk, whether employees know how to get help, how quickly assistance arrives, and whether responders are prepared for what the hospital expects them to do.


This cannot be completed by security alone. Nursing, behavioral health, facilities, emergency management, risk management, human resources, information technology, pharmacy, clinical leadership, communications, legal counsel, and executive leadership all hold pieces of the risk picture.


Someone must be accountable for leading the program. Priorities must be established, responsibilities assigned, funding decisions made, and unresolved risks brought to leaders with the authority to address or formally accept them.


Executives also need more than counts of calls, reports, or arrests. They need to know where the greatest risks are, what gaps remain, whether corrective actions are being completed, and whether employees trust the response system.


Security is not simply a departmental expense. It is part of the hospital’s responsibility for patient safety, workforce safety, enterprise risk, emergency preparedness, and operational continuity.


The Leader Must Learn the Mission


Hospitals frequently look to former law-enforcement officers, military leaders, and federal agents to lead their security programs.


That makes sense. These professionals may bring valuable experience in investigations, emergency response, criminal behavior, threat assessment, evidence, and working under pressure.


But experience in one environment does not automatically prepare us to lead in another.


I say that from experience.


I came into healthcare after a 20-year military career. I had worked in security, executive protection, and demanding environments where preparation, discipline, and response mattered. I then took responsibility for security at a Level I trauma center in a major metropolitan area.


I brought useful experience with me. I also had a great deal to learn.


A hospital is not a military installation, police department, or federal agency. Its primary mission is to provide care. The person causing concern may also be a patient experiencing pain, illness, medication effects, cognitive impairment, substance use, trauma, or a behavioral health crisis.


That does not make dangerous behavior acceptable. It does change how the situation must be understood and managed.


I had to learn the clinical environment, patient rights, healthcare regulations, hospital culture, and the responsibilities of departments whose work was very different from mine. I had to understand when security should lead, when it should support, and when clinical expertise should guide the response.


I also had to learn the financial realities of healthcare.


Most hospitals face limited resources and many competing priorities. Security generally does not generate revenue, even though a security failure can create enormous human, operational, legal, and financial consequences.


The ideal program may not be financially possible today. That does not mean ignoring risk or lowering standards. It means separating immediate needs from long-term improvements, developing phased options, documenting what remains unresolved, and giving leaders a realistic path forward.


My previous experience gave me a strong foundation, but it did not give me everything I needed to understand healthcare. That came from listening, learning, and recognizing that success in a previous profession did not eliminate the need to become a student again.


The issue is not where we came from. That experience has value.


The question is whether we are willing to learn the mission of the organization we now serve.


Prepare People Before the Incident


Every hospital employee contributes to security.


That does not mean turning nurses, registration staff, environmental services employees, or volunteers into security officers. It means giving them practical skills to recognize when something does not look or feel right and a clear process for getting help.


Employees should know what behaviors or circumstances should raise concern, how to respectfully approach someone who appears lost or out of place, when to disengage, and how to report a concern.


This is where customer service also becomes a security tool.


A simple greeting can help a visitor find the correct department. It also communicates that employees are present and paying attention. It creates an opportunity to observe the person’s behavior, emotional state, response, and reason for being there.


The purpose is to engage, assist, and assess—not to confront.


This is also where the distinction between non-escalation and de-escalation matters.


Non-escalation is what we do from the beginning to avoid unnecessarily making an interaction worse. It includes our tone, body language, positioning, facial expression, word choice, and willingness to listen.


De-escalation is the effort to reduce agitation after escalation has already begun.

They are related, but they are not the same.


Hospitals frequently provide de-escalation training while spending less time teaching employees how their initial approach may lower anxiety or add to it. Preventing unnecessary escalation is better than trying to recover after it occurs.


But non-escalation is not the answer to every threat, and it is not an explanation for violence.


Some people intend to cause harm. Others may be too impaired by illness, substances, cognitive limitations, psychological distress, or emotional crisis to respond rationally. Sometimes, you cannot reason with someone who is not capable of reasoning at that moment.


Communication training must never become a way to blame an employee after an assault. It is one preventive layer—not a substitute for adequate staffing, physical safeguards, trained responders, protective equipment, accountability, or immediate intervention when someone becomes dangerous.


Trauma-informed care has a place in hospital security. Understanding how pain, fear, illness, or trauma may influence behavior can help employees avoid unnecessary conflict. But trauma-informed does not mean passive, defenseless, or consequence-free.

Compassion and protection are not opposing responsibilities.


Employees can only be expected to report early when reporting is simple, assistance is reliable, and previous concerns have been taken seriously. Teaching employees what to recognize must be matched by building a response system they trust.


Design and Control the Environment


Hospitals should identify areas of concern throughout the campus. These may include entrances, emergency departments, behavioral health spaces, labor and delivery, pediatric areas, parking facilities, isolated offices, loading docks, utility areas, and locations where employees work alone.


Within those areas may be locations of increased concern because of what occurs or what is stored there. Pharmacies, medication storage rooms, cash-handling locations, areas containing radioactive materials, information-technology rooms, infant units, and critical utility spaces may require additional protection.


The goal is not to secure every area in the same way. It is to understand the risk and apply the appropriate level of protection.


This includes using Crime Prevention Through Environmental Design, commonly called CPTED. The name may sound technical, but the idea is simple: arrange and maintain the environment so people can see what is happening, visitors are naturally guided toward the right places, unauthorized access is discouraged, and opportunities for harmful behavior are reduced.


Can employees see who is approaching? Are entrances easy to identify? Do signs guide visitors to the correct locations? Are there blind corners or dark areas? Can someone enter without being noticed? Do employees have a safe exit if an interaction becomes dangerous? Does furniture trap them or allow someone to block the way out?

Good environmental design does not require making a hospital look like a prison. The most effective measures often improve safety without being obvious to patients and visitors.


Hospitals must also study how people move.


Patients, visitors, employees, vendors, contractors, delivery personnel, law enforcement, prisoners, and members of the public may all use the same facility. They should not necessarily use the same entrances or routes.


Sometimes the concern is a door. Sometimes it is the path leading to the door. Frequently, it is the workflow surrounding it.


Access control is only partly about locks, badges, and readers. A sophisticated system cannot protect a door that is routinely propped open. But when employees repeatedly bypass a safeguard, leaders should not immediately assume carelessness. The behavior may reveal a design, workflow, staffing, or equipment problem that the organization has failed to resolve.


The answer may require education, accountability, better equipment, or a change in process. Often, it requires a combination of all four.


Use Technology Without Creating New Risk


Cameras, access-control systems, duress alarms, visitor-management systems, weapons-screening technology, communications equipment, and AI-assisted analytics can all strengthen a security program.


But technology should be selected to address an identified risk.


Before installing a camera, the hospital should know what it is intended to observe, whether it will provide a useful image, who will receive alerts, how recordings will be protected, and whether the footage can be reliably retrieved when needed.

The same applies to AI. It may help identify unusual movement, entry into restricted spaces, crowd formation, or other defined activities. But an alert that no one receives, understands, or acts upon provides little protection.


Technology can support people. It does not eliminate the need for trained personnel, sound judgment, clear procedures, maintenance, testing, and accountability.

Physical security and cybersecurity must also work together.


Nearly every modern camera, badge reader, alarm, visitor-management system, and AI platform connects to a network, stores information, or communicates with an outside provider. That means every connected security device may also create a new vulnerability.


Departments should not independently purchase and install consumer-grade cameras or other connected devices because they are inexpensive and easy to obtain. The technology must be evaluated for cybersecurity, privacy, network management, data storage, access, evidence retention, vendor support, and system integration.

Security, information technology, cybersecurity, privacy, and other appropriate stakeholders should be involved before—not after—the device is connected.


The hospital must also plan for what happens when technology becomes unavailable. A ransomware attack or network failure may affect cameras, badge access, duress alarms, communications, registration, medication systems, and other critical functions.


That is not merely an IT problem. It can quickly become a physical security, operational, and patient-safety problem.


Build a Response Capability That Matches the Risk


Metal detectors and other weapons-screening systems may be appropriate in some hospital environments. Their presence, however, does not automatically mean effective screening is taking place.


The program must define who will be screened, what is prohibited, how alarms and exceptions will be handled, what happens when a weapon is found, and how staff will respond if someone refuses to cooperate.


The people conducting the screening must understand the equipment, but technical training is not enough.


A metal detector may identify metal. It cannot identify intent, increasing anxiety, attempts to distract the screener, or signs that someone may be preparing to resist or cause harm.


The person operating the equipment is often more important than the equipment itself.

The same principle applies to security officers.


Hospitals must examine more than how many officers are scheduled. They must determine what officers are expected to do and then hire, train, equip, supervise, and evaluate them for that mission.


Hospital officers may respond to workplace violence, behavioral health emergencies, missing patients, domestic violence, weapons, suspicious packages, fires, disasters, criminal activity, and many other events. They may assist clinical teams, manage visitors, preserve evidence, document incidents, and testify in court.


Those responsibilities require more than a uniform and previous security experience.

Hospitals cannot assume officers were properly prepared by a former employer. Even experienced officers must be trained for this hospital, its risks, policies, patients, physical environment, equipment, and expectations.


Equipment decisions—including whether officers should be armed—must also be based on the hospital’s risk, environment, law-enforcement response, and expectations of its officers.


Batons, OC spray, firearms, and conducted-energy weapons cannot be evaluated as though a hospital were a street, correctional facility, or military installation. Each introduces different risks and responsibilities. Selection, policy, training, clinical response, reporting, and oversight are as important as the equipment itself.


Employees want confidence that the person responding is capable, trained, equipped, decisive, and supported by the organization. This is one reason employees sometimes say they want police officers rather than security officers.


They may not literally be asking for arrest authority or a different badge. They may be expressing a lack of confidence in the security team they have.


Leaders should not dismiss that concern. They should determine what is behind it.


Learn, Measure, and Improve


Response is not the end of the security program.


After an incident, the hospital must look beyond whether someone followed a policy. What contributed to the event? Were warning signs present? Did employees call early? Did the environment create additional risk? Did technology work? Were responders properly staffed, trained, and equipped? Did clinical and security personnel work together?


A corrective action written in meeting minutes is not an improvement.

Someone must be responsible for completing it. A deadline must be established. Leadership must verify that the change occurred and is working.


Activity is not the same as effectiveness. Counts of reports, patrols, door checks, or calls may describe workload. They do not necessarily tell leaders whether risk is being reduced.


Measures should connect back to the HVA and security assessment. If workplace violence is a high-priority hazard, what actions were taken, and did they reduce injuries or improve response? If a technology outage is a significant vulnerability, have downtime procedures been tested?


The assessment identifies the priorities. Measurement helps determine whether the hospital is becoming more prepared.


A System, Not a Collection of Parts


A comprehensive hospital security program is not defined by whether the organization has armed officers, metal detectors, cameras, controlled entrances, or the newest technology.


It is defined by how well leadership, people, the physical environment, technology, clinical operations, policies, training, equipment, and response capabilities work together.


Workplace violence prevention is one responsibility of that program. Non-escalation is one tool within that responsibility.


It matters, but it cannot carry the entire burden.


Safer hospitals require aware employees, thoughtful environments, controlled access, properly evaluated technology, capable responders, appropriate equipment, clinical partnership, executive ownership, and an organization willing to learn.


Executive leaders should begin by asking who is accountable for the program, whether security risks are meaningfully represented in the HVA, what the highest-priority gaps are, and whether realistic improvement plans exist.


If those questions cannot be answered, the hospital may have security risks and vulnerabilities, and it does not yet have a comprehensive security program.

1 Comment

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Roy Williams III, MBA, CHPA
Aug 13
Rated 5 out of 5 stars.

Mike, as always, GREAT information you presented here. 100% correct in your assessments.

Like
bottom of page