Physical security requires board-level attention, governance structures designed for strategic impact, and leadership with executive competencies. Each of those principles raises a question that most healthcare organizations have not clearly answered: when a security incident occurs, who is accountable?
The instinctive answer — the security department — is the wrong one. And the consequences of that misunderstanding extend well beyond incident response. When accountability for security risk is unclear, organizations create the conditions for exactly the failures they are trying to prevent.
The misconception
Bob Pocica, CSA Practice Area Lead, Corporate Security and former Senior Vice President and Chief Security Officer at McKesson Corporation, identifies the foundational error: “Management owns the risk. The CSO provides insight, guidance, and mitigation.” That distinction is not semantic. It defines whether security operates as a strategic advisory function or as a department that absorbs blame when things go wrong.
In Pocica’s framework, the security leader’s role is to identify risk, assess it, recommend mitigation, and communicate clearly to the leaders who own the assets and operations at stake. The decision to accept, mitigate, or transfer that risk belongs to the operational leaders and, ultimately, to the board. Pocica is explicit about how he ensured that distinction held: “I confirm this in an email, not just a conversation.” The paper trail is not bureaucracy — it is the mechanism that ensures risk decisions are visible, documented, and owned by the people with the authority to make them.
“Management owns the risk. The CSO provides insight, guidance, and mitigation.”
Bob Pocica, CSA Practice Area Lead, Corporate Security • Former SVP & CSO, McKesson Corporation
Healthcare already applies this principle to other forms of risk. Clinical liability is not owned by the quality department — it is owned by the clinicians, departments, and executives who deliver care, with quality providing oversight, measurement, and guidance. Financial compliance is not owned by the audit function — it is owned by the leaders who authorize transactions and manage budgets. Security risk should follow the same model: distributed ownership with centralized advisory capability.
What governance already requires
The regulatory framework for healthcare accountability has been strengthened significantly. The HHS Office of Inspector General’s General Compliance Program Guidance, updated in November 2023, outlines seven elements of an effective compliance program and is explicit about board responsibility. The guidance states that governing boards should be knowledgeable about the content and operation of the compliance program, should meet with the compliance officer at least quarterly, and should receive annual reports on the program’s effectiveness in addressing identified risks. The board has a fiduciary duty to ensure that information and reporting systems exist to allow informed judgments about compliance and risk.
The accountability gap becomes especially visible when compared to cybersecurity. In July 2023, the SEC adopted rules requiring public companies to disclose material cybersecurity incidents within four business days of determining materiality and to describe the board’s oversight of cyber risk in annual filings. That framework establishes mandatory, board-level accountability for one form of security risk — with defined timelines, disclosure requirements, and governance expectations. No comparable framework exists for physical security. A healthcare organization that experiences a workplace violence incident resulting in serious injury or death faces no equivalent obligation to disclose the event, describe its governance of the risk, or demonstrate that the board was informed and exercising oversight.
That compliance framework applies broadly, but the accountability architecture it describes — board oversight, quarterly engagement, documented risk assessment, clear reporting relationships — is precisely what physical security governance lacks in most healthcare organizations. Compliance officers report to the board. Chief Medical Officers report to the board. Chief Information Security Officers increasingly report to the board on cyber risk. Physical security leaders, in most systems, do not.
Brad Brekke, CSA’s Chief Business Officer and former Vice President of Assets Protection and Corporate Security at Target Corporation, frames the exposure in terms any board member understands: “Are you running the organization like a car without seatbelts?” The analogy is apt. An organization that has not defined who owns security risk, how that risk is escalated, and what decisions require board-level visibility is operating without the mechanisms that would protect it when — not if — an incident occurs.
When accountability fails
The consequences of unclear accountability are visible in patterns that recur across healthcare systems. Jeremy Baumann, CSA’s Chief Executive Officer, describes the structural version of the problem at a major health system where security reported too far down the organizational hierarchy. Information was filtered before it reached leadership — shaped not by what the organization needed to know but by the priorities and agenda of the intermediary. Critical risk information that should have reached the executive committee was softened, delayed, or reframed. The result was not a failure of the security function but a failure of the accountability structure: the information existed, but the reporting pathway prevented it from reaching the people who needed to act on it.
Jen Moberg, CSA Senior Advisor and Vice President of Emergency Services, identifies a subtler but equally damaging pattern. In her experience, security is rarely invited to participate in root cause analysis after safety events — treated as a separate venue rather than an integrated part of the investigation. When security is excluded from the processes that examine what went wrong, the organization loses the ability to identify whether structural failures, rather than individual failures, contributed to the event. Accountability without investigation is blame assignment. Investigation without security participation is incomplete.
“Are you running the organization like a car without seatbelts?”
Brad Brekke, CSA Chief Business Officer • Former VP of Assets Protection & Corporate Security, Target
Building accountability structures
Effective accountability requires architecture, not aspiration. At McKesson, Pocica established a Senior Risk Advisory Board with clear escalation paths, documented risk acceptance protocols, and defined decision rights at each organizational level. When a risk was identified and a recommendation made, the response was tracked: accepted, modified, or declined — with the declination documented and owned by the leader who made the decision. That structure ensured that accountability was distributed to the people with the authority to act, not concentrated on the person who identified the problem.
Pocica adds a dimension that distinguishes genuine advisory accountability from passive documentation. When he believed a risk decision was wrong, he went back — a second, third, fourth time. The obligation of the security leader does not end with a single recommendation and a documented refusal. A risk that is real on Monday is still real on Friday. The professional responsibility is to persist until the risk is genuinely addressed or the organization has made an informed, eyes-open decision to accept it. Documentation without advocacy is compliance theater. The accountability model works only when the security leader treats the advisory role as a genuine obligation, not a procedural box to check.
For healthcare organizations, building that architecture means defining accountability at three levels: the board, which oversees security governance and receives regular risk reporting; the executive committee, which makes risk decisions and allocates resources; and operational leadership, which owns the implementation of security measures within their areas of responsibility. The security function advises all three levels, provides the risk assessment that informs decisions, and maintains the documentation that ensures accountability is traceable.
The question for your board
When the next security incident occurs — and in healthcare, it is a matter of when, not if — will your organization be able to demonstrate that risk was identified, communicated to the appropriate decisionmakers, and either mitigated or consciously accepted? Can you show who was informed, what they decided, and why? If the answer to those questions depends entirely on the security department’s records, then the organization has not distributed accountability — it has delegated it downward to a function without the authority to act on it.
The HHS-OIG guidance is clear: governing boards have a fiduciary duty to ensure that reporting systems exist for informed risk judgments. The SEC has established that principle for cybersecurity. The question is whether physical security is part of that system — or whether it remains the one enterprise risk that the board has never formally agreed to own.
--
Accountability is one question. What else should healthcare leaders be asking?
Explore the full picture in CSA’s Healthcare Security Governance Imperative: Twelve Questions for Boards and Executive Leaders to Build Safer, More Accountable Health Systems. Drawing on firsthand experience across major health systems, the report examines how governance, leadership, investment, and measurement shape security performance. Use it to guide conversations with your leadership team, identify gaps in your current approach, and set priorities for protecting patients, staff, and the communities you serve.

--
ARTICLE REFERENCES
- U.S. Department of Health and Human Services, Office of Inspector General. (2023). General Compliance Program Guidance (GCPG). Seven elements of an effective compliance program, board oversight requirements, quarterly engagement with compliance officer, annual risk assessment.
- U.S. Securities and Exchange Commission. (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release Nos. 33-11216; 34-97989). Adopted July 26, 2023. Requires material incident disclosure within four business days and annual board oversight reporting.
- U.S. Sentencing Commission. Organizational Sentencing Guidelines, §8B2.1. Governing authority requirement to be knowledgeable about compliance program content and operation.
- ASIS International. (2019). Enterprise Security Risk Management (ESRM) Guideline. Four roles of responsibility: asset owners, security professionals, stakeholders, and top management.
- The Joint Commission. Environment of Care Standards (EC.01.01.01): Leadership reporting requirements for security management activities.
Speak to a Security Expert
Enter your information below to speak to a security expert on our team.


