The electronic physical-security backbone of a hospital — the access-control system (ACS) that governs who passes through which door, the video surveillance (CCTV/IP video) system that records and monitors the campus, and the security management platform that fuses doors, cameras, alarms, intercoms, and duress into a single operational picture. Done well, these systems protect patients, staff, infants, behavioral-health populations, controlled substances, and infrastructure while staying invisible to ordinary clinical traffic and never impeding egress or emergency response.
Hospitals are simultaneously the most open and most regulated of building types. They run 24/7, admit the public through multiple uncontrolled entrances, and must remain welcoming — yet they also house high-risk populations (infants, emergency-department patients, behavioral-health and forensic patients), high-value targets (pharmacy, controlled substances, biologics, infusion drugs, radioactive materials), and sensitive data and equipment. The security system must reconcile open access with selective control, layering protection so that the public corridor and the neonatal unit can coexist in the same building.
The discipline is driven less by a single prescriptive code than by a risk-based security management program that the hospital is expected to maintain. The Joint Commission's Environment of Care standards (the EC chapter, notably EC.02.01.01) require a written security management plan based on proactive risk assessment, with identification of security-sensitive areas, controls appropriate to risk, and a response process for security incidents (including infant/pediatric abduction and workplace violence). DNV's NIAHO standards impose parallel physical-environment and security expectations. CMS Conditions of Participation reach security indirectly through the physical environment and patient-rights requirements. The IAHSS (International Association for Healthcare Security & Safety) publishes the Healthcare Security Industry Guidelines and Security Design Guidelines for Healthcare Facilities, which function as the de-facto design reference for security-sensitive areas, electronic protection layers, and CPTED (Crime Prevention Through Environmental Design) in healthcare. The 2026 cycle of the Facility Guidelines Institute (FGI) Guidelines carries a dedicated security risk assessment (SRA) requirement that ties physical and electronic security measures to a documented, multidisciplinary assessment performed during planning.
The result: there is rarely a code line that says "put a card reader here." Instead, the Security Risk Assessment drives device placement, and the design must then satisfy the hard constraints that do come from code — egress, fire/life-safety, and accessibility.
This is the single most important rule in the entire discipline and the one most frequently violated by integrators unfamiliar with healthcare. Access control restricts entry; it must almost never restrict exit. Every electronically locked door in a means-of-egress path is governed by NFPA 101 (Life Safety Code) and IBC egress provisions, which CMS adopts by reference (CMS requires the 2012 edition of NFPA 101/99 for certified facilities, subject to AHJ updates).
Two NFPA 101 lock types dominate healthcare:
Critically, clinical override of egress is itself a regulated exception. The 2012 NFPA 101 introduced provisions (the "clinical needs" / specialized locking arrangements, §18/19.2.2.2.x and §7.2.1.6.3) allowing certain doors in healthcare occupancies to be locked against egress where patients require containment for their own safety (behavioral health, memory care, pediatrics, ED psych holds, forensic) — but only under strict conditions: staff carry keys/credentials at all times, the locks release on fire alarm and power loss unless the AHJ has approved a remote-release/clinical-needs arrangement, and the unit operates under approved staff-response procedures. Behavioral-health and secure-unit door locking is a design decision that must be coordinated with the AHJ and documented in the SRA and the life-safety drawings — it is never an integrator field decision.
Every magnetic lock, electric strike, and electrified latch in the building must be cross-checked against the life-safety plan for:
Healthcare access control is organized as concentric and segmented zones, escalating control as one moves from public to clinical to high-security space. A typical layering:
| Zone | Examples | Typical control |
|---|---|---|
| Public / unrestricted | Main lobby, ED waiting, retail, chapel, public cafeteria | Open during hours; perimeter doors on schedule + lockdown capability |
| Semi-restricted / transitional | Elevator lobbies, corridor cross-connects, public-to-staff thresholds | Card reader; time-of-day schedules; visitor management |
| Restricted clinical | Inpatient units, OR suite entries, imaging, labs | Credentialed staff only; door alarms; anti-passback at sensitive thresholds |
| High-security / security-sensitive | Pharmacy (incl. controlled-substance vault), NICU/maternity perimeter, behavioral health, IT/data center, infant security, central sterile, cash handling, loading dock, mechanical/electrical/utility, blood bank, lab specimen, radiology hot lab/nuclear medicine, MRI zones | Multi-factor (card + PIN, sometimes + biometric); positive entry control; audited; often integrated duress and video verification |
Security-sensitive areas are defined by the SRA and are the locations The Joint Commission expects to be specifically identified and controlled. Common designations and their drivers: