Hospital security: managing access, aggression and incident response
Hospital security works best when patient flow, staff safety, access control, behavioural risk and escalation routes are managed as one joined-up operation with clear ownership at every stage.

Hospital security works best when patient flow, staff safety, access control, behavioural risk and escalation routes are managed as one joined-up operation with clear ownership at every stage.
Hospitals operate as open, high-pressure sites where patients, relatives, visitors, clinical teams, contractors, ambulance crews and the wider public often move through the same areas. At the same time, wards, treatment rooms, staff-only spaces, medicines, records, plant and service areas require different levels of access control. The security operating model therefore needs to be built around how the site actually runs: where demand peaks, where behaviour or access risk increases, who owns each decision and how incidents are escalated without disrupting care.
Seven areas to keep under active review
Start with how the hospital actually operates
Before deciding officer numbers or fixed posts, map how patients, visitors, staff, ambulances, contractors, deliveries and security incidents move across the site during the full operating cycle. Include A&E arrivals, outpatient clinics, visiting periods, shift changes, ambulance handovers, discharge activity, contractor access, service deliveries, staff entrances, car parks and night access.
Then identify where control is most likely to weaken: queues at reception, open routes into restricted areas, periods when staffing reduces, competing incidents, delayed clinical handovers or points where staff routinely call for security support. Coverage should follow those operating pressures rather than remain fixed simply because a post has historically existed.
Questions to ask
- Where do patient, visitor, staff or vehicle movements create the greatest pressure on access control or security response?
- Which areas, times and incident types require a named owner and a defined escalation route?
- When responsibility moves between clinical teams, security, management or police, how is that handover made clear?
Control access at each stage of the patient journey
Hospitals must remain accessible, but access should tighten as people move away from public routes and towards clinical, staff-only or sensitive areas.
Main entrances, A&E reception and outpatient areas may be relatively open; wards, treatment rooms, maternity and paediatric areas, pharmacies, medicine stores, records, plant rooms and service areas require clearer authority over who can enter, when and for what purpose. Visitor, contractor and out-of-hours arrangements should define the normal route, the approval needed for exceptions and who makes the decision when somebody cannot be verified.
Separate behavioural risk from criminality
Not every difficult interaction is the same security problem. Pain, fear, distress, confusion, mental ill-health, medication, alcohol or drugs, and changes in a person’s physical or emotional condition can all affect behaviour. Security teams therefore need to understand the operating context before responding. The practical question is what risk is present now, what the clinical team needs, what authority security has and what action will reduce harm without escalating the situation unnecessarily.
Translate risk information into clear officer instructions
Where a patient or visitor presents a known risk of violence or aggression, relevant information should be converted into practical instructions for the people expected to manage it. Officers may need to know recognised triggers, agreed precautions, restricted routes, who the clinical lead is, when additional support must be called and any limits on intervention. They do not need unnecessary clinical detail. The purpose is to make the response safer and more consistent before pressure builds.
Give staff a clear route to security support
Reception teams, nurses, porters, healthcare assistants, clinicians and other staff often see a situation changing before security does. They should not have to improvise how to get help. Call points, radios, alarms, escalation numbers and priority levels should be understood, tested and linked to a response that staff can rely on.
Security coverage should also reflect where support is repeatedly needed. Where behaviour escalates, the first task is to protect people, create space, maintain access to care and prevent the incident spreading. Security should support de-escalation, safe separation, controlled access and escalation under the organisation’s approved procedures. Physical intervention is a last resort and should only be carried out by appropriately trained people acting within their authority and local healthcare policy. Clinical decisions remain with the clinical team.
Keep visitor, contractor and restricted-area controls workable
Visitors may be distressed, unfamiliar with the site or focused on reaching a patient quickly. Contractors may need temporary access through routes they do not normally use. Security controls therefore need to be simple enough to apply consistently: who may enter, what evidence or approval is required, which areas they may access, how temporary permissions end and who can authorise an exception.
The same rules must hold when somebody refuses a restriction, attempts to enter a controlled area or remains after being asked to leave. Staff should know when the issue remains with reception or the ward, when security takes control of the access problem and what threshold requires management, safeguarding, police or another external response.
Treat A&E and out-of-hours as a different operating condition
A&E, urgent care, waiting areas, discharge points and other 24-hour services should not be treated as daytime operations with fewer staff. Demand, delay, distress, intoxication, safeguarding concerns and multiple simultaneous incidents can change the security requirement quickly. The operating model should define where officers are positioned, how incidents are prioritised, who can redeploy resources and what happens when more than one area requires support at the same time.
The same review should cover car parks, ambulance routes, staff entrances, smoking areas and isolated external routes, particularly around night shifts and shift changes. Security must protect movement through these areas without obstructing ambulance access, emergency routes or normal clinical operations.
Define incident ownership before the handover is needed
Hospital incidents regularly cross operational boundaries. A distressed patient may become aggressive, a visitor dispute may become a safeguarding issue, suspected theft may require evidence preservation and a serious assault may require police involvement. The response should already define what the clinical team owns, what security controls, when the duty manager becomes involved and what trigger transfers part or all of the incident to an external agency.
Officers need the information and authority to act without guessing: exact locations, access routes, alarm or CCTV coverage, who the clinical or duty lead is, how additional support is requested and what must be recorded. Incident reports should capture the sequence of events, decisions, actions, handovers and notifications clearly enough for the organisation to review what happened without security drifting into clinical judgement.
Use incidents and near misses to change the operating model
Security requirements should move with the hospital. Review recurring incidents, near misses, staff concerns, response times, access exceptions and repeat locations alongside changes to services, patient pathways, opening hours, building layouts and staffing. Where the same weakness appears more than once, change the operating model – posts, patrols, access permissions, escalation thresholds, communication routes or assignment instructions – rather than allowing an informal workaround to become the real procedure.
Related operational evidence.
Security support within a busy Birmingham A&E environment
A Birmingham hospital required dedicated security support within its A&E department, where anti-social behaviour, aggression and conflict were creating additional pressure for clinical and reception teams. Innovative Security Solutions worked with hospital management to understand the environment before deploying SIA-licensed security officers into the department.
Read more →The UK national terrorism threat level is set by MI5 and reflects the likelihood of an attack in the UK.
We monitor relevant official updates and factor the risk context into site risk assessments and deployment planning.
View the current official threat level →Discuss your security requirements
Talk to Innovative Security Solutions about the operating environment, current risks and the service model you need.
Discuss Your Security Requirements →