Hospital security inspection isn't a walk with a clipboard anymore — as of January 2026, The Joint Commission has folded Environment of Care and Life Safety into a single new Physical Environment (PE) chapter, elevated Workplace Violence Prevention to a National Performance Goal, and made annual worksite analysis a specific expectation. Surveyors are no longer asking "does a binder exist" — they're asking what the data shows about the program's effectiveness. This checklist walks through the per-shift inspection points a hospital security team should touch, mapped to TJC 2026 PE, OSHA 3148, CMS 42 CFR 482, and IAHSS Healthcare Security Industry Guidelines — plus how to run it as a defensible digital program. Start free on OxMaint to load this as a shift template today, or book a demo to see the TJC survey-ready record pack generate on demand.
Survey-Ready Security · Every Shift, Every Zone
TJC 2026 PE + Workplace Violence NPG · OSHA 3148 · CMS 42 CFR 482 · IAHSS.
Jan 2026
EC + LS chapters merged into unified Physical Environment (PE) chapter
~35%
Of TJC surveys cite EC.02.01.01 — outdated security risk assessments
36 mo
Unannounced TJC survey window — record pack must be ready any day
Annual
Worksite analysis required under the new Workplace Violence Prevention NPG
Risk-Zone Heatmap · Not Every Area Gets the Same Inspection
Hospital security inspection isn't uniform. A behavioral health unit, an infant nursery, and a loading dock at 2 a.m. carry different threat profiles, and a defensible program rounds them at different frequencies with different checklists. The four-tier heatmap below is the field-standard scaffold — sort your building against it before you build your shift template, so patrol coverage matches actual risk instead of square footage.
TIER 1
CRITICAL
Per-shift + hourly patrol
Emergency Department
Behavioral Health Unit
Labor & Delivery / Nursery
Pediatric Wards
TIER 2
HIGH
Per-shift walk-through
Pharmacy / Controlled Substances
ICU / CCU
Radiology (portable isotopes)
Surgical Suites
TIER 3
MODERATE
Twice-daily walk
General Medical / Surgical Units
Imaging Suites (non-isotope)
Cafeteria / Public Corridors
Admin & Records Offices
TIER 4
PERIMETER
Shift-start + random rounds
Parking Structures / Lots
Main Entries & Vestibules
Loading Dock / Service Entry
Morgue & Utility Yards
The Six Inspection Domains · What Every Shift Actually Checks
These are the six checklist domains a hospital security shift covers on every round. Each item captures a mandatory pass/fail outcome in the mobile app, with photo evidence attached where it materially proves the check happened — badge readers, controlled-substance seals, panic-button test results, and any deficiency noted.
Badge-reader function at every restricted-area door
Doors closing and latching — no propping, no tailgating
Visitor management system logging every guest with photo ID
After-hours entrance lockdown per policy time
Elevator access restrictions to sensitive floors
02
Workplace Violence Watch
ED and behavioral-health panic buttons tested by call
Behavioral flag review with charge nurse per unit
De-escalation and duress signage current at nurse stations
Weapons-detection screening operational at ED entry
Incident-report queue reviewed for open items requiring follow-up
03
Controlled Substances & High-Value Assets
Pharmacy perimeter and after-hours access log reviewed
Automated dispensing cabinets — no unresolved discrepancies
Isotope storage seals intact per radiology check
Medical equipment tag audits in high-loss areas
Waste-disposal witness signatures current
04
Infant & Vulnerable Patient Protection
Infant-security tag system function test — active alarm check
Nursery/OB door alarm and delayed-egress function
Wander-management system for cognitively impaired patients
Elopement-risk patient list reviewed with charge nurse
Code Pink drill logs reviewed and posted
Lighting operational — no dark corners in parking structures
Camera coverage confirmed on live monitor for each zone
Loading dock access controlled, no unaccompanied vehicles
Emergency phones and blue-light stations tested
Morgue and utility yard secured, no unauthorized entry
06
Incident Documentation & Handoff
All shift incidents logged in security incident system
Law enforcement coordination documented where applicable
Behavioral escalation events reported per WVP program
Shift handoff briefing captured with sign-off
Any open corrective action escalated with a deadline
Run the Six Domains as a Per-Shift Mobile Round — Free Forever
Sign up on OxMaint's free forever plan and load the six-domain checklist as a per-shift template mapped to each risk tier — mandatory outcomes, photo capture on panic-button tests and access-control fails, e-signature on shift handoff. No card, no time limit.
The TJC 2026 Standards Map · What Each Check Actually Cites
The 2026 Joint Commission restructure consolidated Environment of Care and Life Safety into a single Physical Environment (PE) chapter, and the National Patient Safety Goals became National Performance Goals — with Workplace Violence Prevention elevated as its own NPG. These are the standards a defensible security inspection log needs to trace back to. Sign up free to attach the citation to every checklist item.
TJC PE (2026)
Physical Environment Chapter
The new consolidated chapter — merges former EC (Environment of Care) and LS (Life Safety) requirements. Written security management plan, worksite analysis, and demonstrable data on program effectiveness are the survey focus.
TJC NPG · WVP
Workplace Violence Prevention — National Performance Goal
Elevated to a National Performance Goal for 2026. Requires a designated leader, multidisciplinary team, incident reporting and follow-up, annual training, and an annual worksite analysis with documented findings.
OSHA 3148
Guidelines for Preventing Workplace Violence — Healthcare
OSHA's healthcare-specific workplace-violence prevention guidance. Used by inspectors under the General Duty Clause; forms the underlying framework the TJC WVP standard operationalizes.
CMS · 42 CFR 482
Conditions of Participation for Hospitals
Loss of TJC deemed status means direct CMS survey — 42 CFR 482 is what a hospital gets measured against. Environmental safety and security are CoP-eligible findings.
IAHSS
Healthcare Security Industry Guidelines
The International Association for Healthcare Security & Safety guidelines — the reference document surveyors expect security leadership to cite when explaining program design decisions.
HIPAA
Physical Safeguards (§164.310)
Physical safeguards under the HIPAA Security Rule cover facility access controls, workstation security, and device/media controls — overlapping with the access-control domain of every shift round.
Annual Worksite Analysis · The New TJC 2026 Cornerstone
The single biggest change under the 2026 Workplace Violence Prevention NPG is the annual worksite analysis. It isn't a policy review — it's a proactive, data-driven vulnerability assessment. This is the four-step flow that satisfies the standard and, more importantly, produces the evidence a surveyor asks for when they ask "what does your data show?"
01
Incident-Data Review
Pull 12 months of incident reports — by unit, by shift, by category. Identify the units and time windows with the highest event density; these are your vulnerability hotspots.
→
02
Physical Walk-Through
Multidisciplinary walk of every high-risk area with security, nursing, facilities, and EHS. Photograph blind spots, isolated corridors, blocked sight lines, and single-egress zones.
→
03
Staff-Feedback Survey
Anonymous staff survey — where do they feel unsafe, which shifts, which patient interactions. Underreporting is expected; the survey captures what incident logs don't.
→
04
Findings → Action Plan
Every vulnerability gets a documented action with owner and deadline. The signed report and closed corrective-action list are the primary evidence for the annual TJC WVP review.
Incident Escalation Ladder · Every Event Has a Recorded Path
Workplace-violence events don't fit a single response — a verbal threat, a physical assault, and an active-assailant event trigger different protocols, different staff, and different documentation. The three-level ladder below is the field-standard escalation model; every shift's incident log needs each event mapped to a level so trending and follow-up work.
LEVEL 1
Verbal / Non-Physical
Threats, intimidation, harassment, agitation without contact
Officer response, de-escalation, incident report with charge-nurse witness signature
LEVEL 2
Physical / Contact
Assault, physical restraint required, injury to staff or patient
Code call, medical eval, law-enforcement notification per policy, post-incident debrief documented within 24 hours
LEVEL 3
Weapon / Active Threat
Weapon involvement, hostage, active-assailant event
Facility-wide alert, law enforcement lead, executive notification, incident review at leadership level, root-cause and action report to governing body
How OxMaint Runs the Full Hospital Security Program
The six-domain per-shift round, the annual worksite analysis, the incident escalation ladder, and the TJC 2026 documentation package all live in the same platform — mandatory fields on shift rounds, tracked corrective actions on every finding, and a survey-ready export that pulls every record for any period a Joint Commission surveyor asks about.
Schedule
Per-Shift Rounds By Risk Tier
Tier 1 hourly, Tier 2 per shift, Tier 3 twice daily, Tier 4 shift-start and random — templates auto-generate the right domains on each round.
Execute
Six-Domain Mobile Checklist
Access control, WVP watch, controlled substances, infant/vulnerable, perimeter, incident docs — mandatory outcomes and photo capture on panic-button tests and any fail.
Escalate
Fails Become Tracked Corrective Actions
Any fail — broken lock, propped door, failed panic button, expired seal — auto-generates a tracked corrective action with owner and deadline.
Report
Incident Log With Escalation Level
Every event tagged Level 1/2/3, with charge-nurse witness, law-enforcement notification, and post-incident debrief documented and searchable by unit and shift.
Analyze
Worksite-Analysis Data Roll-Up
12-month incident trending by unit, shift, and category — the data set the annual WVP worksite analysis expects, ready to export.
Prove
TJC PE Survey-Ready Record Pack
Rounds, corrective actions, incident logs, worksite analysis, and training records — one export mapped to the PE chapter and the WVP NPG for any survey window.
Build a Security Program That Survives the Next Unannounced Survey
Free forever plan — no card, no time limit. Load the risk tiers, assign per-shift rounds, and start capturing the mobile evidence your TJC surveyor is going to ask for. Or book 30 minutes and we'll get you live on your highest-risk units in one working session.
Frequently Asked Questions
What changed in TJC 2026 for hospital security inspections?
The 2026 Joint Commission restructure consolidated the Environment of Care (EC) and Life Safety (LS) chapters into a unified Physical Environment (PE) chapter, and the National Patient Safety Goals chapter became the National Performance Goals chapter — with Workplace Violence Prevention elevated to its own NPG. The written security plan requirement carries forward, but surveyors now focus on how the plan changes daily practice and what the incident data shows about its effectiveness.
Book a demo to see the 2026 record pack.
What is the annual worksite analysis, and who has to do it?
Under the 2026 Workplace Violence Prevention NPG, every accredited hospital must conduct an annual worksite analysis to identify vulnerabilities related to workplace violence. It's a four-part process — incident-data review over the past 12 months, a multidisciplinary physical walk-through of high-risk areas, an anonymous staff feedback survey, and a documented action plan with owners and deadlines. The signed report and closed corrective actions become primary survey evidence.
How often should hospital security rounds actually run?
Frequency should match risk tier, not square footage. Tier 1 critical areas (ED, behavioral health, L&D/nursery, pediatrics) warrant hourly patrol plus per-shift checklists; Tier 2 high-risk (pharmacy, ICU, radiology with isotopes) get per-shift walk-throughs; Tier 3 moderate (general units, imaging, admin) run twice daily; Tier 4 perimeter (parking, loading dock, morgue) at shift-start with random rounds. All of it captured in the mobile app with mandatory outcomes.
Which standards should our security inspection log actually cite?
The core reference stack for a US accredited hospital is: TJC 2026 Physical Environment (PE) chapter and the Workplace Violence Prevention National Performance Goal; OSHA 3148 healthcare workplace violence guidance; CMS Conditions of Participation at 42 CFR 482; the IAHSS Healthcare Security Industry Guidelines; and HIPAA §164.310 physical safeguards where access control overlaps with PHI protection. Each checklist item should trace to one of these anchors.
Sign up free to tag each item with its citation.
Can OxMaint produce a TJC-survey-ready security record pack?
Yes. OxMaint stores every per-shift round with mandatory outcomes and photo evidence, every corrective action with owner and closure, every incident tagged by escalation level (Level 1 verbal / Level 2 physical / Level 3 weapon) with witnesses and follow-up, the 12-month trending data feeding the annual worksite analysis, and staff-training records. All of it exports as a single Physical Environment survey pack mapped to the current TJC 2026 standards — pulled in seconds for any survey window inside the 36-month unannounced cycle.