Swatting Calls at Hospitals: The Threat May Be Fake, But the Impact Is Real.
- Mike Dunning
- Jul 7
- 13 min read

How hospitals can manage unverified threats, protect people, and prevent false reports from driving the response.
A recent article in Becker’s Hospital Review highlighted a troubling issue for healthcare leaders: hospitals are facing an increase in swatting calls. The article pointed to recent incidents in Wisconsin, including threats involving Marshfield Medical Center and Emplify Health by Gundersen, and outlined why swatting creates risk for hospitals, staff, patients, law enforcement, and the community.
That article does an important job of raising awareness. But awareness is only the first step. Hospitals also need a practical plan for what to do before, during, and after a reported threat.
That distinction matters.
At the beginning of the call, the hospital does not know whether it is dealing with a real threat, a mistaken report, a confused caller, a mental health crisis, or a deliberate swatting attempt. The first response should not be, “Is this fake?” The first response should be, “What do we need to know right now to protect people?”
Swatting is the act of making a false emergency report in order to trigger a law enforcement, SWAT, fire, EMS, or hospital emergency response. In healthcare, it can involve false reports of active shooters, bombs, armed individuals, suspicious persons, medical emergencies, or other dangerous conditions.
The problem is not only that the report may be false. The problem is that the response is real.
Police respond. Hospitals lock down. Staff are frightened. Patients and families see armed officers moving through a care environment. Operations are disrupted. Entrances may close. Ambulance flow may be affected. Leaders are pulled into crisis response. Social media may light up before accurate information is available. A false call can create a very real emergency.
The goal for hospitals should not be to dismiss suspicious calls. That would be dangerous. The goal should be to manage the call as an unverified threat, protect people, verify quickly, communicate clearly, and avoid letting the caller become the incident commander.
Start With the Right Mindset
Every threat must be taken seriously until it is resolved. A call that sounds suspicious may still be real. A caller who sounds calm may still be reporting a true emergency. A caller who lacks details may be scared, injured, hiding, or confused.
At the same time, hospitals need to recognize that some false calls are designed to exploit urgency. The caller wants speed, fear, confusion, and overreaction. They want the hospital and police to move fast before the facts can catch up.
That creates a difficult balance.
Hospitals need procedures that allow them to do two things at the same time:
Protect people as though the threat may be real.
Verify information quickly so the response remains proportionate.
That balance should be built before the call comes in.
Do Not Label It Too Early
One of the biggest mistakes a hospital can make is labeling the call too soon.
If staff assume the call is real without verification, the hospital may overreact and create unnecessary fear, disruption, and operational harm.
If staff assume the call is fake, the hospital may delay action and place people at risk.
Neither assumption is safe.
The better approach is to treat the call as an unverified threat. That means the hospital begins protective actions while also working rapidly to confirm, refine, or rule out the reported information.
The question is not:
“Is this a swatting call?”
The better questions are:
“What is being reported?”
“Where is the caller?”
“Is the caller safe?”
“Where is the threat?”
“What immediate protective actions are needed?”
“What information can we verify right now?”
“What response is appropriate based on what we know?”
This approach keeps the hospital from being passive, but it also keeps the hospital from being pulled into chaos by an unverified report.
Prioritize the Questions
During a threatening call, staff should not work through a long checklist in random order. The first questions should anchor the caller, protect the caller, preserve the connection, and then define the threat.
At the beginning of the call, the hospital does not know whether the report is real, mistaken, secondhand, exaggerated, or intentionally false. The call-taker’s role is not to decide whether the call is swatting. The call-taker’s role is to gather the most useful information as quickly and safely as possible.
The sequence should be simple:
Locate the caller.
Protect the caller.
Preserve the connection.
Define the threat.
Verify the source.

Question Priority 1: Are you in the hospital now?
Start by determining whether the caller is physically at the facility.
“Are you in the hospital right now?”
“Are you inside, outside, or calling from somewhere else?”
This helps the hospital understand whether the caller may be a direct witness, whether the caller may be in danger, and whether the information may be firsthand or secondhand.
A caller who is inside the hospital may be a witness, victim, employee, patient, visitor, or bystander. A caller outside the hospital may be reporting something near an entrance, parking lot, ambulance bay, or adjacent area. A caller from somewhere else may still have valid information, but responders need to know that immediately.
Priority 2: Where are you?
Next, determine the caller’s exact location.
“Where are you right now?”
“What department, entrance, floor, room number, hallway, parking area, or nearby sign are you closest to?”
The caller’s location may not be the same as the threat location, but it gives responders an anchor point. If the caller disconnects, this may be the only location information available.
Hospitals are complex environments. “I’m at the hospital” is not enough. The response will be very different if the caller is in the emergency department waiting room, a patient room, a clinic across campus, the parking deck, or calling from home.
Priority 3: Are you safe to talk?
The call-taker should quickly determine whether the caller can continue speaking safely.
“Are you safe to talk right now?”
“If not, can you move to a safer place?”
“Can you stay quiet and answer yes or no?”
This protects the caller and helps the call-taker adjust the conversation. A real caller may be hiding, injured, frightened, or unable to speak freely. They may not be able to give a full narrative. They may only be able to whisper, answer yes or no, or stay silent for periods of time.
The call-taker should not pressure the caller to speak if speaking could place them in greater danger.
Priority 4: What number can we call back if disconnected?
Before moving too far into the details, preserve the connection.
“What number can I call you back on if we get disconnected?”
Calls drop. People panic. A caller may need to hide, leave, or stop talking. Getting a callback number early gives security, law enforcement, or dispatch a way to reconnect if the call is lost.
This question also provides useful verification information. A legitimate caller will usually want responders to be able to reach them. A suspicious caller may refuse, avoid the question, or disconnect. That does not prove the call is false, but it becomes one factor in the overall assessment.
Priority 5: What is happening right now?
Once the caller is anchored and the connection is protected, focus on the current situation.
“Tell me exactly what is happening right now.”
“What do you see?”
“What do you hear?”
“Is the person there now?”
“Is anyone injured?”
“Is there a weapon?”
“Are shots being fired?”
This helps determine whether there is an immediate threat or whether the report is based on something heard, seen earlier, or passed along by someone else.
A real-time observation is different from a rumor. “I see a man with a gun at the ED entrance right now” is different from “Someone told me there might be a gun somewhere.” Both may require action, but they should not be treated as the same level of information.
Priority 6: Where is the threat?
Now identify the threat location as precisely as possible.
“Where is the threat right now?”
“What department, entrance, floor, room, parking area, or clinic?”
“Is the person inside or outside?”
“Which direction are they moving?”
“What is the closest landmark, desk, room number, elevator, or sign?”
The caller’s location and the threat location may be different. The caller may be hiding in one area while the threat is somewhere else. The caller may also be reporting something they saw earlier and is no longer near them.
This distinction is critical. Security and law enforcement need to know where to go, where not to go, what areas may need protection, and what areas may simply need to remain alert.
Priority 7: Who or what is involved?
After location and current activity are addressed, gather description.
“How many people are involved?”
“What do they look like?”
“What are they wearing?”
“What kind of weapon or threat did you see?”
“Are they saying anything?”
“Are they alone?”
“Are there injured people nearby?”
Even partial information can help security and law enforcement respond more safely. A description can also help avoid confusion when staff, visitors, patients, officers, or security personnel are moving through the same area.
Priority 8: How do you know?
Finally, clarify the source of the information.
“Did you see this yourself?”
“Did someone tell you?”
“When did this happen?”
“Are you seeing or hearing it now?”
“Who told you?”
“Did they say how they know?”
This helps determine whether the report is firsthand, secondhand, delayed, mistaken, exaggerated, or potentially fabricated.
This question should not come first. In the first few seconds, life safety matters more than credibility testing. But once the caller, safety, connection, and threat details are addressed, understanding how the caller knows becomes important.
The purpose of these questions is not to prove the call is false. The purpose is to gather enough information to protect people, direct responders, and verify the report quickly.
Clues That May Later Suggest a Swatting Call
No single clue proves a call is false. The concern comes from the pattern.
A call may later appear suspicious when there are dramatic claims but thin details. The caller may report an active shooter, armed person, hostage situation, or bomb, but cannot provide a specific department, entrance, floor, room number, suspect description, direction of travel, or what they personally observed.
The caller may use broad statements such as:
“There is a shooter in the hospital.”
“There is a bomb somewhere.”
“People are being killed.”
“They are coming to shoot up the hospital.”
Those statements must be taken seriously. But they should also trigger immediate verification.
Other clues may include a caller who demands a specific response, such as “send SWAT,” “lock down the hospital,” or “evacuate everyone.” The caller may hang up quickly, refuse a callback, or use public information from the hospital website while failing to answer questions about current conditions.
These are not reasons to ignore the call. They are reasons to verify quickly and manage the response carefully.
A real witness may still be confused or emotional. That is expected. But real witnesses often provide sensory, location-based, immediate information. They know what they saw, heard, or experienced. False callers often provide dramatic claims without usable ground truth.
The safest rule is this:
Do not decide it is swatting at the beginning. Build a process that can manage both possibilities.
Verification Should Be Built Into the Response
Hospitals should not wait until a crisis to decide how they will verify a threat.
Verification should include multiple information channels.
Security officers should check cameras, entrances, parking areas, and the reported location if it can be done safely.
The switchboard, operator, call center, or security dispatch should preserve the caller’s exact words, phone number if available, time of call, background noise, and whether the caller stayed on the line.
Unit leaders should be contacted quietly when appropriate to determine whether anything unusual is occurring in the reported area.
Access control, panic alarms, duress buttons, weapon detection systems, emergency phones, and radio traffic should be checked for supporting information.
Local law enforcement should be notified immediately and given both the reported threat and the level of internal corroboration.
The hospital should also determine whether nearby facilities, schools, government buildings, or sister hospitals are receiving similar threats. Multiple similar calls across a region may suggest a coordinated hoax campaign.
The key is speed with discipline. Verification should not delay protective action, but it should shape the scale and type of response.
Avoid the All-or-Nothing Trap
Hospitals sometimes think in extremes: either the threat is real and everything locks down, or the threat is fake and nothing happens.
That is the wrong frame.
A more mature response uses graduated actions based on what is known.
If the threat is specific to an area, the hospital may begin with a targeted protective response while law enforcement and security verify the report.
If the threat is vague and unconfirmed, leadership may increase security posture, restrict certain entrances, notify key departments, review cameras, and prepare for escalation without immediately creating hospital-wide panic.
If there is corroboration, such as gunfire, staff reports, camera confirmation, injuries, panic alarms, or multiple internal calls, the response must escalate quickly.
The goal is not to under-respond. The goal is to avoid turning an unverified hoax into a hospital-wide operational collapse.
Communication Matters
Swatting, or any unverified threat, creates an information vacuum. Information vacuums fill quickly with fear.
Hospitals should prepare internal messages in advance for different scenarios. Staff need clear, plain-language direction. Leaders need to avoid vague alerts that increase fear without providing action steps.
A poor message sounds like this:
“Security incident. Stay alert.”
A better message sounds like this:
“We received an unconfirmed threat involving the Emergency Department entrance. Security and law enforcement are responding. Staff in the ED should move away from public-facing areas if safe to do so and follow department procedures. Other areas should continue operations while remaining alert. More information will follow.”
Communication should answer four questions:
What do we know?
What do we not know yet?
What should staff do right now?
When will the next update come?
Hospitals should also have a plan for external messaging. Patients, families, media, and the community may hear about a police response before the hospital has confirmed the facts. A short, accurate holding statement can help prevent rumor from becoming the loudest voice in the room.
Train the People Most Likely to Receive the First Call
Swatting response does not begin with the incident commander. It often begins with the person who answers the phone.
That may be the switchboard, emergency department registration, a clinic front desk, security dispatch, a nurse’s station, a patient access representative, or a call center employee.
This is where the human factor matters.
A person receiving a threatening call may panic if they have not been trained. That is not a character flaw. It is a normal human response to a frightening message. If someone hears, “There is a shooter coming to the hospital,” their instinct may be to pass that information along as quickly as possible.
But speed without structure can create a dangerous problem.
If the call-taker accepts the report as verified fact without asking basic questions, they may unintentionally relay it as verified fact to security, leadership, law enforcement, or clinical areas. That creates false validation. The next person in the chain may believe the information has already been confirmed, when in reality it has only been reported.
That subtle shift matters.
“There is an active shooter in the Emergency Department” is very different from, “A caller reported an active shooter in the Emergency Department. We have not yet verified the report.”
The first statement sounds confirmed. The second statement is accurate, actionable, and leaves room for verification.
Hospitals should train call-takers to use careful language under stress. They should be taught to separate what is reported from what is confirmed.
For example:
“A caller reported…”
“The caller stated…”
“This has not yet been verified.”
“Security is checking the area now.”
“Law enforcement has been notified.”
“We are working to confirm the location and details.”
That language does not minimize the threat. It protects the decision-making process.
Those staff members need simple training:
Keep the caller on the line if possible.
Ask prioritized, location-based questions.
Capture exact words.
Determine whether the caller is at the hospital.
Determine whether the caller is safe to talk.
Get a callback number early.
Separate reported information from verified information.
Use clear language when escalating the call.
Do not argue with the caller.
Do not tell the caller the hospital thinks the call is fake.
Notify the correct internal and external contacts immediately.
Preserve notes and recordings.
Training should not be limited to security. The first person to receive the call may be the lowest-paid person in the room and the most important person in the first 60 seconds.
The goal is not to turn every call-taker into an investigator. The goal is to give them enough structure so fear does not become the transmission system for unverified information.
Build Law Enforcement Relationships Before the Incident
Hospitals should not be exchanging business cards with law enforcement during a swatting call.
Before an incident happens, hospitals should meet with local law enforcement, 911 leadership, emergency management, fire, EMS, and public information partners. The conversation should include:
How threat calls are received and shared.
Who law enforcement should contact inside the hospital.
How the hospital will provide floor plans, access points, camera support, keys, badges, and staging areas.
How unified command will be established.
How hospital operations will be protected during the response.
How cleared areas will be communicated.
How false reports will be investigated afterward.
Hospitals should also discuss how to avoid unnecessary disruption to patient care areas when a threat is unconfirmed. That does not mean softening the response. It means making the response smarter.
Recovery Is Part of the Response
Once law enforcement determines a call was false, the incident is not over.
Staff may still be shaken. Patients and families may have seen police activity. Departments may have delayed care, held patients, rerouted visitors, or paused normal operations. Rumors may still be spreading online.
Hospitals should complete a structured recovery process:
Send an all-clear message.
Explain what happened in plain language.
Thank staff for following procedures.
Document the operational impact.
Debrief security, emergency management, nursing, operations, communications, and law enforcement.
Identify what worked and what needs improvement.
Provide support to staff directly affected.
Preserve evidence for investigation.
Hospitals should also consider reputational recovery. A swatting call can create the perception that the hospital was unsafe, even when the hospital responded appropriately. Silence after the fact may allow the false narrative to linger.
A simple public statement may be appropriate:
“Earlier today, the hospital received a threat that prompted a law enforcement response. After investigation, the threat was determined to be false. Patient care continued, and we are grateful to our staff and law enforcement partners for their prompt response.”
Practical Steps Hospitals Can Take Now
Hospitals do not need to wait for a swatting call to prepare. They can begin with practical steps:
Add swatting and hoax threats to emergency management planning.
Create a call-taker checklist for threat calls.
Train switchboard, registration, security dispatch, ED front desk, clinic, and unit staff.
Develop verification procedures using cameras, unit contact, access control, alarms, and security response.
Create graduated response levels for unconfirmed, partially confirmed, and confirmed threats.
Build pre-scripted internal and external messages.
Review lockdown procedures to ensure they can be targeted when appropriate.
Coordinate with law enforcement and 911 leadership.
Exercise a swatting scenario during tabletop training.
Debrief every incident or suspicious call.
Swatting is not just a law enforcement issue. In hospitals, it is a public safety issue, an emergency management issue, a communications issue, a patient care issue, and a leadership issue.
The Bottom Line
A swatting call may be false, but the fear, disruption, cost, and risk are real.
Hospitals should never dismiss a threat because it sounds suspicious. But they also should not allow a caller with a phone and bad intent to dictate the entire hospital response.
At the beginning, the hospital does not know whether the threat is real or false. That is why the process matters.
The best approach is simple:
Take it seriously.
Locate the caller.
Protect the caller.
Preserve the connection.
Verify quickly.
Respond proportionately.
Communicate clearly.
Recover deliberately.
Do not let the caller become the incident commander.


Comments