There have been many changes in the healthcare environment over the past decade. The Affordable Care Act has been established, severe weather events are on the rise, violence along with active shootings continue to increase, behavioural health patients present treatment challenges and hospitals continue to consolidate to increase purchasing and service capabilities. Over the next decade, healthcare will continue to transform. Emphasis will be on financial reform, violence response, emergency preparedness, the proper care and handling of behavioural health patients and service efficiencies.

Current issues affecting healthcare security

Violence in healthcare continues to pose the greatest risk to hospital staff. Several key healthcare organisations have published information to assist security directors in the reduction of violent incidents.

The International Association for Healthcare Security and Safety (IAHSS) publishes security and design guidelines specific for healthcare facilities. These resources provide valuable and internationally recognised practices and standards for addressing healthcare violence. The IAHSS Foundation (IAHSSF) publishes an annual crime and incident survey analysing violence in healthcare.

The American Hospital Association (AHA) recently published a webpage specifically to assist in the mitigation of violence. ASIS International has published several whitepapers addressing healthcare security; specifically violence related to behavioural health patients and disruptive and violent behaviors in healthcare. The Occupational Safety and Health Administration (OSHA) website offers numerous tools and resources pertaining to workplace violence and safety with a section devoted specifically to the healthcare industry.

Possibility of healthcare workplace violence prevention

At the time of writing, the Republican Party had not figured out how to change the Affordable Care Act (ACA) while still making healthcare more affordable. Most likely changes in health care will occur within the expanded purchasing options, Health Savings Accounts (HAS’s), Medicare reimbursement and the use of government exchanges. The indoctrination of the ACA included increased investigation to Medicare fraud and audits to hospitals for billing errors. In 2016, the Federal government collected over three billion dollars in fraud and reconciled billings to Medicare.

Violence will continue to challenge the healthcare sector in the future
Domestic violence, child abuse, behavioural health, drug and alcohol abuse will all continue to challenge hospital staff

The Joint Commission issued Sentinel Alert 57. This alert focuses on the role of leadership in developing a safe culture. The Occupational Health and Safety Administration (OHSA) contemplated issuing a healthcare workplace violence prevention standard. This standard required healthcare institutions to have a clearly defined prevention programme in place.

This year, a total of 25 states have legalised marijuana. This legislation will dramatically change how we care for patients and deal with patients, employees and visitors who are using the substance and may be impaired at work and within the hospital, and who may request continued use while being an in-patient within a facility that is smoke free.

The future for healthcare security

In the future, healthcare security professionals will have to deal with a variety of events from severe weather, violent and active shooter incidents, terrorist attacks, and continued changes to healthcare reimbursement. Severe weather has the potential to impact all healthcare systems across the globe. Specific attention must be directed at knowing the weather threats common to specific geographical locations. A Comprehensive Emergency Management Plan (CEMP) must be current and thorough for disaster response. Performing exercises is a valuable tool in staff education and opportunity to reinforced skills for those assigned to incident command positions.

The Hazard Vulnerability Assessments helps in defining risk severity and identifying historical
patterns of violence

Violence will continue to challenge the healthcare sector in the future. Domestic violence, child abuse, behavioural health, drug and alcohol abuse will all continue to challenge hospital staff in the Emergency Department, Women’s Health, and behavioural health areas. The Hazard Vulnerability Assessments (HVA) along with facility wide risk assessments helps in defining risk severity and identifying historical patterns of violence.

Active shooting incidents

According to the FBI, an analysis of 2014 and 2015 active shooter incidents identified 20 incidents in each of these years. This annual tally is an increase from 17 in the year 2013. In a John Hopkins study entitled, “Hospital-based Shootings in the United States: 2000 to 2011,” Hopkins identified 154 hospital related shooting events (26.6 events per 1,000 hospitals) in 148 hospitals, affecting 235 victims (0.79 per 1,000,000 population). The risk of experiencing an active shooter incident is increasing. Hospitals must be prepared to not only deal with their own active shooter incident, but any that could occur in their service community.

Changes in terrorist tactics now present a new challenge for the healthcare security. According to Homeland Security, hospitals play a major role in the response for terrorist-related incidents and terrorist activities within the United States. Today, incidents are comprised of local combatants whose goal is to kill civilians in crowded areas like restaurants, concerts, and other mass gatherings. Attacks in the past have focused on first responders and their ability to treat victims. Healthcare institutions need to be ready to again accept victims of terrorist events and prepare for the potential for becoming victims of an event as well.

Trump Care

At the writing of this article, “Trump Care” is still being debated. However, certain things seem clear. In the future, Medicare reimbursement will probably be reduced leaving hospitals with less money within their payor mix. Trump Care may also see increased State control over the reimbursement process, allowing each State to decide its own fate when it comes to Medicare and Medicaid payment rates. This could provide hospitals with less revenue, leaving hospital security departments with budgets struggles for both staffing and technology.

Severe weather, violent and active shooter incidents and terrorist attacks all affect healthcare security
Today, incidents are comprised of local combatants whose goal is to kill civilians in crowded areas like restaurants, concerts, and other mass gatherings

Staff recruitment will remain amongst the most challenging endeavour. The need for qualified and skilled security staff will challenge the best of talent recruiters. Competitive wages and benefits will require continual focus for attracting skilled labour. Recruiting practices and personal skill screening tools will be of benefit. Some systems find outsourcing their security department the best option. Hybrid models are options as well as contracting with local law enforcement for additional presence.

Training for healthcare security staff

A key factor of success for security in healthcare is training. Providing staff with the necessary tools and skills will afford significant return on investment with quality and satisfaction outcomes. Healthcare security staff should receive training focusing on patient safety, patient experience, customer experience and quality of service. Awareness and understanding of behavioural health, aggression management and de-escalation talents, crime prevention and customer service abilities and aptitudes are a must. The International Association for Healthcare Security and Safety (IAHSS) offers several educational certification levels designed specifically for healthcare security officers.

Importance of robust security department

Utilising concepts and dynamics of lean tools, technology options, clinical throughput, and Standard Work all influence security services. The concept of Standard Work is popular in the business world. Utilising this concept is beneficial to security. Standard Work can identify staffing needs, work flow process, consistency in service levels, and maximum utilisation of technology resources and equipment. Striving for the right person doing the right work with the right skill set is the desired outcome. Often the same concept will hold true for identifying the right department providing the right service for the right reason.

Data will be of extreme importance in the distribution of those resources. Security departments need to collect relevant data on all aspects of security services from reported crime data, security calls for service, annual risk assessments and benchmarking data. Hospital security departments must create a data-driven environment that can help to demonstrate service needs and improve processes over time. The real success of using data is the analysis of data to determine patterns and trends that can demonstrate the need for and successes in security services.

Methods for managing healthcare security are driving factors. A robust security department will implement and utilise security technology to support and influence safety, security and quality outcome measures. Return on investment (ROI) and the ability to show quality metrics and positive influence in life-safety, security and patient satisfaction scores will be core in driving positive capital decisions. Challenges of healthcare security in the future will require continued education and knowledge of current trends, guidelines, and standards within the healthcare security industry.

By Ben Scaglione and David LaRose

Download PDF version

In case you missed it

What characteristics do salespeople require in the physical security industry?
What characteristics do salespeople require in the physical security industry?

A basic tenet of sales is ABC – always be closing. But it's a principle that most professional salespeople would say oversimplifies the process. Especially in a sophisticated, high-tech market such as physical security, the required sales skills are much more involved and nuanced. We asked this week's Expert Panel Roundtable: What unique characteristics are required of salespeople in the arena of physical security systems?

Can microchip implants replace plastic cards in modern access control?
Can microchip implants replace plastic cards in modern access control?

A futuristic alternative to plastic cards for access control and other applications is being considered by some corporate users in Sweden and the United Kingdom. The idea involves using a microchip device implanted into a user’s hand. About the size of a grain of rice and provided by Swedish company Biohax, the tiny device employs passive near field communication (NFC) to interface with a user’s digital environment. Access control is just one application for the device, which can be deployed in lieu of a smart card in numerous uses. Biohax says more than 4,000 individuals have implanted the device. Using the device for corporate employees Every user is given plenty of information to make an informed decision whether they want to use the deviceCurrently Biohax is having dialogue with curious corporate customers about using the device for their employees. “It’s a dialogue, not Big Brother planning to chip every employee they have,” says Jowan Österlund, CEO at Biohax. Every user is given plenty of information to make an informed decision whether they want to use the device. Data capture form to appear here! “Proof of concept” demonstrations have been conducted at several companies, including Tui, a travel company in Sweden that uses the device for access management, ID management, printing, gym access and self-checkout in the cafeteria. Biohax is also having dialogue with some big companies in the United Kingdom, including legal and financial firms. Österlund aims to have a full working system in place in the next year or so. A Swedish rail company accepts the implanted chip in lieu of a paper train ticket. They accept existing implants but are not offering to implant the chips. Österlund says his company currently has no plans to enter the U.S. market. The device is large enough to locate easily and extract if needed, and small enough to be unobtrusive Access control credential The device is inserted/injected below the skin between the index finger and the thumb. The circuitry has a 10-year lifespan. The device is large enough to locate easily and extract if needed, and small enough to be unobtrusive. The only risk is the possibility of infection, which is true anytime the skin is pierced, and the risk is mitigated by employing health professionals to inject the chip. Use of the device as an access control credential or any other function is offered as a voluntary option; any requirement by an employer to inject the device would be illegal, says Österlund. It’s a convenient choice that is made “based on a well-informed decision by the customer.” Aversion to needles, for example, would make some users squeamish to implant the device. More education of users helps to allay any concerns: Some 10% of employees typically would agree quickly to the system, but a larger group of 50% to 60% are likely to agree over time as they get more comfortable with the idea and understand the convenience, says Österlund. Protection of information The passive device does not actively send out any signals as you walk. It is only powered up by a reader if a user has access rightsIn terms of privacy concerns, information contained on the device is in physical form and is protected. The passive device does not actively send out any signals as you walk. There is no battery. It is only powered up by a reader if a user has access rights. With use of the device being discussed in the United Kingdom, there has been some backlash. For example, Frances O’Grady, general secretary of the Trades Union Congress (TUC), has said: “Microchipping would give bosses even more power and control over their workers.” A big misconception is that the chip is a tracking device, says Österlund. It isn’t. “We love people to get informed,” says Österlund. “If they’re scared or apprehensive, they can just read up. It’s not used to control you – it’s used to give you control.”

Ethical consumption: should you buy security products ‘Made in China’?
Ethical consumption: should you buy security products ‘Made in China’?

Should ‘Made in China’ be seen as a negative in security systems and products? It’s an important and complex issue that merits a more detailed response than my recent comment in the Expert Panel Roundtable. For me, there are two sides of the answer to this question: Buying products that have certain negative attributes that are not in alignment with some part of a belief system or company mandate. Buying products that do not perform as advertised or do something that is unacceptable. For integrators and end users making the buying decisions, the drive to purchase products may not be based on either aspect and instead on the product that can do the best job for their business. But for others, a greater emphasis on the ethical implications of purchasing decisions drives decision-making. What is ethical consumption? Ethical consumption is a type of consumer activism that is based on the concept of ‘positive buying’ in that ethical products are favouredEthical consumption — often called ethical consumerism — is a type of consumer activism that is based on the concept of ‘positive buying’ in that ethical products are favoured, and products that are ethically questionable may be met with a ‘moral boycott’. This can be as simple as only buying organic produce or as complex as boycotting products made in a totalitarian regime that doesn't offer its citizens the same freedoms that we enjoy in the United States. Consider the goals of the Boston Tea Party or the National Consumers League (NCL), which was formed to protect and promote social and economic justice for consumers and workers in the United States and abroad. Some examples of considerations behind ethical consumption include fair trade, treatment of workers, genetic modification, locally made and processed goods, union-made products and services, humane animal treatment, and in general, labour issues and manufacturing practices that take these factors into account. Increase in ethical consumption The numbers show that ethical consumption is on the rise. In a 2017 study by Unilever, 33 percent of consumers reported choosing to buy and support brands that they believe are doing social or environmental good. In the same study, 53 percent of shoppers in the United Kingdom and 78 percent in the United States said they feel better when they buy products that are ‘sustainably’ produced. There’s clear evidence that products from some Chinese companies suffer from cybersecurity vulnerabilities Though the aforementioned question that sparked this conversation centres around concerns with products made in China, there are many other countries where, for example, governments/dictators are extremely repressive to all or parts of their populations, whose products, such as oil, diamonds, minerals, etc., we happily consume. There are also a number of countries that are a threat in terms of cybersecurity. It may be naive and simplistic to single out Chinese manufacturers. Impact on physical security products Product buying decisions based on factors other than product functionality, quality and price are also starting to permeate the security marketplace. While this hasn't been a large focus area from the business-to-business consumption side, it's something that should be considered for commercial security products for a variety of reasons. Hardware hacks are more difficult to pull off and potentially more devastating" There’s clear evidence that products from some Chinese companies suffer from cybersecurity vulnerabilities. Last fall, 30 U.S. companies, including Apple and Amazon, were potentially compromised when it was discovered that a tiny microchip in the motherboard of servers built in China that weren't a part of the original specification. According to a Bloomberg report, “This attack was something graver than the software-based incidents the world has grown accustomed to seeing. Hardware hacks are more difficult to pull off and potentially more devastating, promising the kind of long-term, stealth access that spy agencies are willing to invest millions of dollars and many years to get.” This, along with many other incidents, are changing the considerations behind purchasing decisions even in the physical security industry. Given that physical security products in general have been lax on cybersecurity, this is a welcome change. Combating tech-specific threats In early January, members of the U.S. Senate introduced bipartisan legislation to help combat tech-specific threats to national security posed by foreign actors and ensure U.S. technological supremacy by improving interagency coordination across the U.S. government. The bill creates the Office of Critical Technologies & Security at the White House, an indication that this issue is of critical importance to a number of players across the tech sector. Members of the U.S. Senate introduced bipartisan legislation to help combat tech-specific threats to national security posed by foreign actors To address a significant number of concerns around ethical production, there are certifications such as ISO 26000 which provides guidance on social responsibility by addressing accountability, transparency, ethical behaviour, respect for stakeholder interests, respect for rule of law, respect for international norms of behaviour and respect for human rights. While still emerging within physical security, companies that adhere to these and other standards do exist in the marketplace. Not buying products vulnerable to cyberattacks It may be counter-productive, even irresponsible, to brand all products from an entire country as unfit for purchasing. Some manufacturers’ products may be ethically questionable, or more vulnerable to cyberattacks than others; so not buying products made by those companies would make sense. The physical security industry might be playing a bit of catch up on this front, but I think we're beginning to see a shift toward this kind of responsible buying behaviour.