
A healthcare security policy must be risk-based, meet Work Health and Safety duties, and align with AS 4485. It has to specify access control, CCTV and guarding arrangements, incident reporting, staff training, and procurement and licensing requirements for anyone providing security services on site.
That’s the whole verdict in one sentence. Everything else is detail. If you’re briefing a security provider or auditing what you already have, check the policy covers:
- A documented, multidisciplinary risk assessment with staff and health and safety representative (HSR) consultation
- Zoned access control, from public areas through to restricted pharmacy and records zones
- CCTV and alarm operation, privacy safeguards, retention rules and maintenance schedules
- Defined duties for guards versus clinical staff, and licensing checks for contracted security providers
- Incident reporting and investigation procedures, including Code Black and duress response
- Mandatory training and drill schedules
- A fixed review cycle tied to incidents and site changes
Get these seven elements right and you’ve met the practical core of what regulators and standards bodies expect. Providers like ABCO Security build policy frameworks around exactly this structure.
Key Takeaways
A defensible healthcare security policy is risk-based, aligned with AS 4485, and built on documented consultation, zoned access control and tested incident response procedures.
| Point | Details |
|---|---|
| Governance comes first | Appoint a policy owner and multidisciplinary risk team before writing any operational clauses. |
| Zone every area | Match access controls to risk, from open public zones to dual-authorisation pharmacy and records areas. |
| CCTV needs rules, not just cameras | Document placement, retention, live monitoring responsibility and quarterly testing schedules. |
| Licensing is a contract clause | Require proof of individual guard licences and contractor insurance before the first shift. |
| Review on triggers, not just the calendar | Bring reviews forward after major incidents, site changes or accreditation findings. |
| Engage a specialist provider | ABCO Security combines ISO 9001/ISO 30000 certified processes with healthcare-specific risk assessments, guarding and monitoring. |
Table of Contents
- What are the WHS and governance requirements for a healthcare security policy?
- How should access control and visitor zoning work in a hospital?
- What must a CCTV and alarm policy include?
- What should a policy require from security guards and contractors?
- How should incidents be reported and investigated?
- What training and drills does the policy need to mandate?
- How often should the security policy be reviewed?
- What should go into a practical implementation checklist?
- How should pharmaceuticals and sensitive equipment be secured?
- How should patient data privacy fit into a physical security policy?
- How does the policy align with broader healthcare regulatory obligations?
- Where does IT security intersect with physical security policy?
- How ABCO Security helps you build and run this policy
- A practitioner’s note on where policies actually fail
- Sources
- FAQ
What are the WHS and governance requirements for a healthcare security policy?
Under Australian WHS law, healthcare employers must identify and manage reasonably foreseeable security risks, and must consult workers and HSRs when planning security arrangements, not just inform them after the fact. This isn’t optional paperwork. It’s a legal duty that shapes how the whole policy gets built.
Start with governance. Someone senior, typically a facility manager or director of operations, needs to own the policy. Below that sits a multidisciplinary risk team: clinical leads, security, WHS representatives, and often a patient safety officer.
- Appoint a named policy owner with sign-off authority.
- Convene a risk assessment team covering clinical, security and WHS perspectives.
- Document every hazard identified, the control chosen, and who was consulted.
- Maintain a live risk register, not a static annual report.
- Record consultation minutes as formal evidence for audits.
State health guidance treats occupational violence and aggression as the dominant operational risk in healthcare settings, which is why consultation and design work needs to happen before an incident, not after one.
Pro Tip: Keep risk register entries dated and version numbered. When an inspector or accreditation auditor asks “when was this last reviewed,” a paper trail beats a verbal explanation every time.
How should access control and visitor zoning work in a hospital?
Not every corridor needs the same level of security, and treating them as equal wastes budget while leaving the areas that matter under protected. A workable policy defines zones and matches controls to risk, something AS 4485.1:2021 sets out as the benchmark for Australian healthcare facilities.
- Public zones (foyers, waiting rooms): open access, staffed reception, CCTV coverage, no card restriction.
- Semi-restricted zones (wards, outpatient clinics): visitor sign-in, staff escort for after-hours entry, swipe access for staff.
- Restricted zones (pharmacy, medical records, mental health units): card or biometric access, logged entry, limited authorised personnel list.
- High-security zones (drug safes, server rooms): dual authorisation, audit trail on every entry.
Lockdown procedures need a clear escalation path, who can call it, who authorises re-opening zones, and how staff are notified. Sample clauses for this sit in access control policies for facility managers, which cover visitor sign-in and escort protocols in more depth.
What must a CCTV and alarm policy include?
CCTV footage is worthless if it’s badly aimed, retained for the wrong period, or handled sloppily after an incident. Camera placement has to avoid clinical privacy breaches, meaning no coverage inside consult rooms or bathrooms, while still capturing corridors, entry points and high-risk zones like emergency department waiting areas.
- State monitoring hours and who’s watching live feeds (on-site guard, control room, or remote monitoring provider).
- Set a documented retention period and a clear evidence handover process for police or investigators.
- Require chain-of-custody logging for any footage pulled for an incident review.
- Schedule quarterly testing of cameras, alarms and duress buttons, with results logged.
CCTV and monitoring decisions should follow the risk assessment, not precede it. Health facility design guidance recommends a formal security services brief covering access control, duress systems, lighting and CCTV together, rather than bolting cameras on as an afterthought. Facilities running older analogue systems often find retrofit costs outweigh planning properly from the start, a pattern common enough that most current hospital fit-outs specify IP camera networks with centralised recording from day one.
What should a policy require from security guards and contractors?
Your policy is only as good as the people enforcing it, and that means the procurement clauses matter as much as the operational ones. Every contracted guard needs to hold the correct state security licence, and your contract should require proof before the first shift, not after a complaint.
- Confirm licensing for every individual guard, not just the contracting company.
- Define the boundary between security duties and clinical roles, particularly around physical restraint, which should sit with trained clinical staff, not guards, except in genuine duress situations.
- Specify duress and escort response times in the contract, with measurable KPIs.
- Require proof of public liability insurance and WHS compliance from the contractor.
- Build in audit rights, so you can review incident logs, training records and licence renewals on request.
Queensland Health guidance recommends benchmarking local security procedures against AS 4485 when writing these clauses, which gives you a defensible standard to point to if a contractor pushes back on scope.
How should incidents be reported and investigated?
Every security incident needs a defined first response: who triggers the duress alarm, who responds, and the threshold for calling police rather than managing it internally. Ambiguity here costs seconds that matter during an actual event.
- Log every incident, including near misses, in a standard reporting template.
- Trigger a multidisciplinary review for anything involving injury, restraint, or repeated aggression from the same source.
- Focus investigations on root cause, not blame, so staff report honestly instead of covering up minor incidents.
- Notify affected staff and offer support pathways after any physical or high-stress event.
- Feed findings back into the risk register within a set timeframe, not at the next annual review.
NSW Health’s manual on protecting people and property requires documented incident investigation and multidisciplinary review as standard practice, and it explicitly frames near misses as data, not noise.
Pro Tip: Track near misses separately from confirmed incidents. A spike in near misses in one ward is often the earliest warning sign you’ll get before something more serious happens there.
What training and drills does the policy need to mandate?
Training is where most policies quietly fail. A document that specifies excellent controls but never tests whether staff know how to use them is a policy in name only.
- Core modules: de-escalation, Code Black response, CCTV and privacy obligations, incident reporting procedure.
- Induction: temporary staff and contractors complete a shortened security briefing before their first shift, not their first week.
- Drills: run Code Black and lockdown drills at a set frequency, documented with attendance and outcomes.
- Refresh cycles: annual refresher training as a minimum, more often for high-risk units like emergency departments.
Include HSRs in evaluating whether training actually changes behaviour on the floor, not just whether attendance boxes got ticked.
How often should the security policy be reviewed?
Treat the policy as a living document tied to real triggers, not a fixed annual box-tick exercise. Set a routine review cycle, typically every 12 months, but bring the review forward immediately after any of these:
- A major incident or near miss involving injury or property damage.
- Significant site changes, a new ward, a redesigned entry point, or added restricted zone.
- Adverse accreditation or audit findings.
- New WHS guidance or a revised AS 4485 edition.
Feed incident data, audit results and staff feedback directly into the update. Every revision needs version control: date, approver, and a distribution record confirming staff actually received the update.
What should go into a practical implementation checklist?
Before handing a policy to a security provider or auditing your own, confirm the front matter covers scope, responsibilities, legal references and key definitions. Everything after that should map cleanly to the areas already covered.
| Policy area | Documentation to collect |
|---|---|
| Risk assessment | Risk register, consultation records, HSR sign-off |
| Access control | Zone map, card access logs, visitor procedures |
| CCTV and alarms | Camera placement plan, retention policy, maintenance log |
| Guards and contractors | Licence copies, insurance certificates, contract KPIs |
| Incident management | Reporting templates, investigation records, review minutes |
| Training | Attendance records, drill logs, competency assessments |
| Procurement | Supplier licensing proof, service agreements, audit rights clause |
| Review | Version history, approval record, distribution log |
A security risk assessment checklist built for Australian facilities gives you a working starting template if you’re drafting this from scratch.
How should pharmaceuticals and sensitive equipment be secured?
Drug safes, pharmacy dispensaries, and high-value diagnostic equipment need controls well above what the rest of the building runs. A hospital pharmacy holding Schedule 8 medications is a realistic theft target, and the policy has to treat it that way rather than folding it into general ward security.
Specify dual-authorisation access to pharmacy stock areas, meaning no single staff member can enter alone outside standard dispensing procedures. Drug safes should sit on a separate access log from general ward doors, with entries time-stamped and reviewed weekly, not just when a discrepancy shows up during stocktake. CCTV coverage of dispensary entry points, without breaching patient privacy in adjacent clinical areas, is worth building into the camera plan from the design stage rather than retrofitting later.
Portable medical equipment, imaging machines, monitors, infusion pumps carry a different risk: not theft for resale so much as loss through misplacement or unauthorised removal between wards. Asset tagging with RFID or barcode tracking, tied to a central register, closes most of that gap. Pair it with a sign-out procedure for equipment moved between departments, and audit the register quarterly against physical stock.
Power continuity matters here too; facilities dependent on life support and monitoring systems should confirm backup power arrangements for critical medical equipment cover security infrastructure as well as clinical devices. A CCTV blackout or access control failure during a mains outage leaves both pharmacy stock and monitoring equipment exposed at exactly the moment risk is highest. Facilities dependent on life support and monitoring systems should confirm backup power arrangements for critical medical equipment cover security infrastructure as well as clinical devices, since a generator that keeps ventilators running but drops the access control system solves only half the problem.
How should patient data privacy fit into a physical security policy?
Physical security and information privacy overlap more than most policies acknowledge, particularly around records storage, visual privacy, and who can physically access areas where patient information is visible or stored.
Records rooms and administrative areas holding physical patient files need the same restricted-zone treatment as pharmacy stock: logged access, limited authorised personnel, and CCTV at entry points rather than inside the room itself. Screens at reception and nursing stations should be positioned so casual visitors can’t read patient details over a shoulder, a simple layout fix that costs nothing and closes a surprisingly common gap.
Visitor management ties in directly. A sign-in process that also restricts wandering into semi-restricted zones protects both physical safety and the privacy of other patients on a ward. Staff moving between departments should carry credentials that log where they’ve been, useful both for security incident review and for demonstrating who had physical access to a records area if a privacy complaint arises.
None of this replaces a dedicated information governance framework, but the physical security policy is the first line of defence for paper records, visible screens, and controlled areas where patient information exists in physical form. Get the zoning and access logging right, and a large share of physical privacy risk disappears before it ever becomes an incident.
How does the policy align with broader healthcare regulatory obligations?
A physical security policy doesn’t operate in isolation. It needs to sit consistently alongside the facility’s other compliance obligations, accreditation standards, WHS law, and any sector-specific regulatory requirements the facility already reports against.
The clearest overlap is with accreditation frameworks. Auditors reviewing a facility’s broader compliance posture will often ask for the same evidence a security policy should already hold: documented risk assessments, incident logs, training records, and a defined review cycle. Building the security policy to those same evidentiary standards from the outset means one audit trail serves both purposes, rather than duplicating records to satisfy different reviewers.
Cross-reference the security policy explicitly with the facility’s WHS management system, incident reporting framework, and any state health department guidance the facility already follows. Queensland Health’s security guidelines recommend exactly this kind of alignment, treating security procedures as one component of a broader compliance and safety framework rather than a standalone document.
Where the policy touches on data or records handling in a physical sense, storage room access, visitor restrictions near administrative areas, the front matter should note which broader regulatory framework governs that data, even if the detailed compliance rules sit in a separate document. That cross-reference alone saves confusion when a new manager inherits the policy and needs to understand how it fits the bigger compliance picture.
Where does IT security intersect with physical security policy?
Physical security policy and IT security policy are separate documents with separate owners, but they meet at a few concrete points worth naming explicitly rather than leaving assumed.
Server rooms and network equipment cabinets are physical spaces, and they belong in the same restricted-zone category as pharmacy stock: card access, logged entry, no unescorted contractor access without IT sign-off. If your facility’s IT team hasn’t specified physical access requirements for network infrastructure, that’s a gap the security policy should flag and close, not quietly ignore because it sits outside traditional security scope.
CCTV systems themselves increasingly run on the same network as clinical IT systems, particularly with IP camera installations replacing older analogue setups. That means camera feeds, access control logs and alarm systems can be a route into the broader network if they’re poorly secured, a fact worth raising with whoever manages network security rather than assuming it’s covered elsewhere. Access control systems tied to a central card database carry the same consideration.
Practically, this means the physical security policy should name a liaison point with IT for any system that touches the network, camera servers, access control panels, alarm monitoring platforms, and specify who’s responsible for firmware updates and password management on that equipment. It’s a short clause, but leaving it out is how physical security hardware becomes an unmonitored gap in an otherwise well-managed network.
How ABCO Security helps you build and run this policy
Writing the policy is one job. Running it day to day, guards on shift, cameras maintained, incidents actually investigated, is another, and it’s the part that trips up most facilities within twelve months of a policy going live.
ABCO Security has longstanding experience working across healthcare, construction and corporate security, holding ISO 9001 and ISO 30000 certification, which matters when your board or accreditation body asks how a contracted provider’s quality systems get verified. For hospitals and clinics specifically, that means multidisciplinary risk assessments that feed straight into policy drafting, not a generic template dropped into your document folder.
On the operational side, ABCO Security provides licensed guards briefed on the boundary between security duties and clinical roles, CCTV and alarm installation matched to zoning requirements rather than a one-size camera package, and 24/7 monitoring that keeps duress response times measurable and auditable. If you’re starting from a blank page or auditing what you’ve already got, the healthcare security services page outlines how a risk assessment and policy draft come together, or you can go straight to the integrated security solutions guide to see how guarding, CCTV and access control get specified as one coordinated system rather than three separate contracts. Book a site risk assessment as the first concrete step.
A practitioner’s note on where policies actually fail
Most healthcare security policies I’ve seen fail quietly, not through bad writing but through neglect after sign off. The document gets approved, filed, and revisited only when an auditor asks for it. That’s backwards. A policy is only as good as the incident data feeding back into it, and facilities that treat the risk register as a live working document catch problems, a poorly lit loading dock, a ward with recurring aggression incidents, months before they escalate into something that makes the news.
The conventional advice to “review annually” misses the point entirely. Review on triggers: after incidents, after site changes, after every accreditation finding. If you’re starting this process now, commission a proper multidisciplinary risk assessment first, open staff consultation early, and schedule your first audit within six months, not twelve.
— Abco
Sources
These references carry the most weight when you’re citing standards in board reports or defending policy clauses during an audit:
- AS 4485.1:2021 Security for healthcare facilities — Standards Australia
- NSW Health — Protecting people and property
- Queensland Health — Security guidelines
- Victorian Department of Health — Occupational violence and aggression: security
FAQ
What standard should a healthcare security policy align with?
Australian healthcare facilities should align their policy with AS 4485.1:2021, which sets out security requirements and procedures specific to healthcare settings.
Who needs to be consulted when writing the policy?
WHS law requires consultation with staff and health and safety representatives during the planning and design of security arrangements, not simply notification after the policy is finalised.
How often should a hospital security policy be reviewed?
Review on a routine cycle of roughly 12 months, but bring the review forward immediately after a major incident, a significant site change, or an adverse accreditation finding.
Do security guards need to be licensed?
Yes. Every guard working in a healthcare facility needs to hold the correct state security licence, and contracts should require proof of that licence before the first rostered shift.
Can a provider like ABCO Security help write the policy itself?
Yes. ABCO Security conducts multidisciplinary risk assessments and drafts policy content alongside its guarding, CCTV and monitoring services, so the operational and documentation sides develop together rather than separately.







