top of page

What Is Inadequate Hospital Security Already Costing You?

Writer: Mike Dunning
Mike Dunning
Aug 31
7 min read

Updated: Sep 7

Why security risk appears in more places than the security budget

Every security request competes with another legitimate healthcare need. An additional officer competes with clinical staffing. A new access-control system competes with medical equipment and facility improvements. Training requires time that departments already struggle to provide. Cameras, alarms, screening systems, and protective modifications all carry implementation and continuing costs.


Healthcare executives are right to scrutinize those requests.


They also need to ask a second question:


What is inadequate or poorly coordinated security already costing the organization?


Those costs may not appear in the security budget. They may be recorded as employee injuries, workers’ compensation, overtime, turnover, legal expenses, claims, property loss, operational disruption, emergency purchases, regulatory remediation, or lost leadership time. Because the costs are distributed across multiple departments, their common source can remain hidden.


The organization may already be paying for an inadequate security program. It may simply be paying in ways that are difficult to see.


More spending does not automatically mean more/better security


The answer is not to approve every security request or continually add personnel and technology. More spending does not automatically produce a safer hospital.


A camera may record an event without deterring it, alerting anyone, or improving the response. A panic alarm may be installed without reliable testing or clear expectations for who receives the signal. An access-control system may be bypassed because workflow was never considered. Additional officers may be deployed without defined priorities, suitable training, effective supervision, or integration with clinical operations.


Competitive wages are important to recruiting and retaining capable security officers. However, increasing wages without evaluating officer deployment, workload, performance, productivity, supervision, and operational effectiveness may simply increase the cost of an ineffective program. Leaders should understand what officers are expected to accomplish, whether staffing aligns with actual risk and demand, and whether officers have the preparation, tools, and accountability necessary to perform effectively. Compensation should support the ability to attract and retain the right people, but higher wages alone will not correct unclear expectations, poor deployment, inadequate training, weak supervision, or ineffective performance management. The goal is not simply to pay more for the same activity; it is to ensure that compensation and program performance improve together.


An organization can spend a significant amount on security and still remain exposed.


That is why leaders must ask more than, “How much are we spending?” They should also ask:

  • Which risks are these expenditures intended to reduce?

  • Are those risks among the organization’s highest priorities?

  • Do personnel, technology, policies, training, and the physical environment support one another?

  • What continuing staffing, maintenance, testing, and replacement costs accompany the investment?

  • What evidence will show whether the investment worked?


The objective is not simply a larger security budget. It is more deliberate use of limited resources.


Deferring a security cost does not make it disappear


When a known security need is deferred, the organization may avoid an immediate expense. It does not necessarily avoid the cost. It may transfer that cost to another department, another budget, another person, or another year.


A broken door that remains unsecured may later become an access incident. A communication gap may become a delayed response. Chronic understaffing in a high-demand area may produce overtime, fatigue, injuries, and turnover. Repeated aggression that is treated as a series of unrelated events may eventually result in serious harm.


Consider cameras as one example. An organization may spend thousands—or hundreds of thousands—of dollars purchasing and installing a camera system, yet fail to budget for routine maintenance, software updates, repairs, licensing, storage, or the replacement of individual components. Cameras are operational equipment, and they require periodic inspection and maintenance to remain reliable. Without a lifecycle plan, image quality deteriorates, cameras fail, recording gaps develop, and outdated components become difficult or impossible to support. Eventually, the organization may face the premature replacement of an entire system because smaller problems were allowed to accumulate. A basic maintenance schedule, assigned accountability, and a modest annual budget can extend the useful life of the system, preserve its operational value, and prevent significantly larger expenses later.


Not every deferred request creates a serious event, and not every requested solution is justified. Leaders must make choices. The important distinction is whether the choice is informed.


An organization should be able to explain:

  • What risk has been identified

  • What options were considered

  • What action is being taken or deferred

  • Why that decision is reasonable

  • What exposure remains

  • What conditions would cause the decision to be reconsidered


That is risk management. Allowing a request to disappear within the budget process without resolving the underlying concern is not.


The cost of an injury extends beyond medical treatment


When a patient, visitor, or employee is injured, the immediate expense may be only a small part of the total organizational cost.


An employee injury can involve medical care, workers’ compensation, lost workdays, overtime, replacement labor, schedule disruption, and the possible departure of an experienced employee. Coworkers who witnessed the event may question whether they are adequately protected. Managers may spend weeks addressing staffing, documentation, follow-up, and employee concerns.


Patient or visitor harm can affect care, create complaints or claims, consume leadership attention, and damage trust. A serious incident may disrupt access to a department, require emergency staffing, affect normal operations, and cause the organization to make expensive corrective purchases under pressure.


Some consequences may continue long after the incident is closed:

  • Increased fear and reduced employee confidence

  • Absenteeism and difficulty filling shifts

  • Recruitment and retention consequences

  • Lost productivity and management time

  • Legal defense, deductibles, settlements, or judgments

  • Regulatory or accreditation scrutiny

  • Public and media attention

  • Capital improvements made on an accelerated timeline


No security program can prevent every assault, theft, behavioral emergency, unauthorized entry, or intentional act. The financial value of security does not depend on making that promise. It comes from reducing foreseeable risks, limiting the severity of events, improving response, and preventing the same organizational weakness from causing harm repeatedly.


After serious harm, the questions change


Before an incident, a security improvement may be discussed as a discretionary expense. After an incident, leaders may be asked why the underlying risk was not addressed sooner.


The focus may extend beyond the person who caused the harm. Attorneys, regulators, insurers, employees, governing bodies, and the public may ask:

  • Were there previous incidents, threats, or warning signs?

  • Did reports reveal a pattern involving a location, time, service, or population?

  • Were leaders aware of unresolved vulnerabilities?

  • Were staffing and response capabilities appropriate?

  • Did doors, alarms, cameras, communications, or access controls work as intended?

  • Were employees prepared for the responsibilities assigned to them?

  • Were corrective actions completed and tested?


These questions often concern what the organization knew, whether the event was reasonably foreseeable, and whether its response to the known risk was reasonable. The answers are harder to provide when incident information, injury data, claims, facility problems, employee concerns, and corrective actions are held in separate systems.


The Occupational Safety and Health Administration identifies workplace violence as a recognized healthcare hazard. Joint Commission workplace-violence requirements connect leadership oversight, reporting, worksite analysis, training, post-incident response, and mitigation of identified risks. Although organizational obligations vary by event and jurisdiction, both frameworks reinforce the importance of a documented, coordinated process rather than disconnected activity.


A policy by itself will not establish that the organization acted reasonably. A policy may create additional difficulty when it promises practices that are not consistently performed. Patrol requirements, visitor controls, alarm testing, incident escalation, screening procedures, and training commitments must reflect what the organization can reliably execute.


Poorly coordinated spending is also a security cost


Some organizations spend too little in areas of significant exposure. Others spend money on solutions that are visible, appealing, or quickly available but poorly matched to the actual risk.


A camera project may be approved without determining who will monitor the system, how long recordings will be retained, or what response the system is expected to support. Weapons-detection technology may be considered without resolving staffing, secondary screening, prohibited-item storage, law-enforcement response, or effects on emergency access. Additional officers may be added without determining whether deployment matches incident demand.


These are not merely implementation details. They determine whether the purchase produces value.


Technology has acquisition, licensing, maintenance, cybersecurity, training, staffing, integration, and replacement costs. Personnel require recruitment, supervision, preparation, equipment, and clear performance expectations. A lower initial price may become an expensive long-term commitment. A higher-priced option may still be poor value if it does not address a priority risk.


One return from a coordinated security program is better purchasing: distinguishing necessary investments from attractive but low-value solutions and understanding the full cost before the decision is made.


The costs may already be visible—but separately


Executives do not need to manage daily security operations. They do need enough visibility to make informed decisions about resources and organizational risk.


Five questions can begin that conversation:

What are our most significant security risks, and what evidence supports that conclusion?


What are those risks currently costing us across all departments—not only within security?


Which investments are reducing risk, and which are simply maintaining activity?


What known exposure are we accepting when an improvement is deferred?


If a serious event occurred tomorrow, could we explain what we knew, what we did, and why our decision was reasonable?


Security will always compete with other organizational priorities. That does not mean every request should be approved. It means both sides of the financial decision should be visible.


Leaders should understand what improved security will cost. They should also understand what injuries, disruption, turnover, litigation, ineffective purchases, and unresolved vulnerabilities may already be costing them.


The most expensive security problem is not always the one with the largest price tag. It may be the problem the organization continues paying for without recognizing it as a security cost.


References


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page