Healthcare Security Starts With the Questions Leaders Ask
A governance framework for safer, more accountable health systems
A healthcare organization can have dedicated security officers, extensive camera coverage, and a detailed emergency plan while still struggling to answer fundamental questions about safety. Who makes decisions about security risk? Are standards applied consistently across facilities? How does leadership know whether the program is improving?
Those questions reach beyond the security department. They connect physical security to workforce stability, patient care, financial stewardship, and the decisions boards and executive teams make every day.
Corporate Security Advisors’ report, Healthcare Security Governance Imperative: Twelve Questions for Boards and Executive Leaders to Build Safer, More Accountable Health Systems, examines these connections through practitioner experience, examples from healthcare security transformations, and published research and professional guidance. It offers a framework for evaluating how security is governed, supported, and measured across an organization.
The central finding is straightforward: lasting improvement depends on the structures that help people identify risk, make informed decisions, and follow through.
Give security a voice in the decisions that shape risk
Where security sits in an organization influences what it can accomplish. A capable leader may recognize a serious vulnerability but lack access to the executives who can authorize a response. A needed policy may move through committees for months without anyone having clear authority to approve it.
The report describes one large health system where only seven of thirty needed security policies were published over eighteen months. The team had the capability to develop them, but fragmented decision-making slowed implementation.
The lesson extends beyond reporting lines. Effective governance gives security leadership access to enterprise decisions, establishes who can allocate resources, and creates a reliable path for escalating concerns. It also requires a security leader who can translate operational risk into business priorities, build relationships with clinical leaders, and present a credible investment plan.
For executive teams, a useful question is: Does our security leader have the access, authority, and business capabilities to help shape decisions before an incident occurs?
Make ownership of security risk explicit
Security professionals identify threats, assess vulnerabilities, and recommend ways to reduce exposure. Management makes decisions about the operations, assets, and resources affected by those risks. Boards oversee how those decisions are governed.
When these responsibilities are unclear, important recommendations can remain unresolved. A concern is raised, a budget request is deferred, and no one records who accepted the remaining risk or when the decision should be revisited.
The report outlines an approach built around defined decision rights, documented risk decisions, and clear escalation paths. These practices give leadership visibility into what has been identified, what action was recommended, and what remains outstanding. They also give security leaders a basis for continued advocacy when a significant concern has not been addressed.
A practical test is: Can we trace a significant security concern from identification through a decision, implementation, and follow-up?
Understand what the enterprise is actually funding
Health systems that grow through acquisitions often inherit different security technologies, staffing models, and procedures. Without an enterprise view, leadership may have an incomplete picture of both spending and capability.
In one example documented in the report, a health system discovered that annual security spending totaled $11.5 million, compared with the $2–3 million leadership had assumed. Consolidating the information made it possible to evaluate the investment as a whole.
That visibility matters when deciding what to fund next. Cameras, access control, and visitor management systems need defined operating procedures, maintenance, training, and accountability. Their value depends on how effectively they support the program’s objectives.
Enterprise consistency also needs room for local judgment. A rural clinic and an urban emergency department have different needs. Shared standards and oversight provide a common foundation while allowing protective measures to reflect each setting’s risks.
Before approving the next investment, leaders should ask: Do we know our total security spend, the risks it addresses, and the outcomes we expect it to produce?
Develop security teams as partners in the clinical mission
Healthcare security officers work with patients in crisis, distressed family members, and clinical teams under pressure. Their effectiveness depends on empathy, communication, de-escalation skills, and sound judgment, supported by appropriate technical training.
The report describes a team whose turnover fell from 25–30 percent to under 10 percent following structured development, clearer accountability, and sustained investment in officer growth. This example illustrates how workforce practices can strengthen a security program.
Structured onboarding, scenario-based training, individual development plans, and meaningful career pathways help build and retain capability. Joint training with clinical staff also creates shared expectations about how to respond when a situation escalates.
That partnership should extend into daily operations. Security participation in safety huddles, root cause reviews, and multidisciplinary threat assessment helps connect information that might otherwise remain within separate departments.
The question for leadership is: Are we developing our security workforce with the same intentionality we bring to other teams that support safe care?
Measure progress and test preparedness
Incident counts alone offer a limited view of performance. Events need context: type, severity, location, contributing factors, and trends over time. Leadership also needs to understand whether staff feel supported and whether preventive work is being completed.
The report recommends combining measures of past events with indicators of program readiness, such as training completion, proactive rounding, and threat assessment activity. Together, these measures support better decisions about where to focus attention and resources.
Preparedness deserves the same scrutiny. A written emergency plan becomes more useful when exercises test decision-making, communications, and coordination under realistic conditions. The follow-through matters equally: identifying gaps, assigning corrective actions, and verifying that changes work.
Two questions bring this into focus: What evidence shows that our security program is improving? What did our last exercise reveal, and what changed as a result?
Use the twelve questions to start a more informed conversation
Healthcare organizations differ in size, structure, and risk. The report is designed to help leaders evaluate their own environment and identify priorities for improvement. Each chapter can be read independently, making it useful for a focused leadership discussion or a broader review of the security program.
The full report explores twelve questions spanning governance, organizational structure, leadership, accountability, enterprise consistency, technology, investment, workforce development, measurement, cross-functional collaboration, crisis preparedness, and security excellence. It also provides recommendations for boards, executive committees, and security leaders.
Download Healthcare Security Governance Imperative for the complete framework, practitioner perspectives, supporting references, and guidance for turning these conversations into action. Use it to examine where your organization stands today and what it needs to build a safer, more accountable health system.
Speak to a Security Expert
Enter your information below to speak to a security expert on our team.

