TL;DR
  • Workplace violence in healthcare is heavily underreported, and the underreporting is structural, not accidental.
  • Reported numbers can represent as little as 20 to 40 percent of actual physical assault events.
  • A program calibrated to reported incidents is calibrated to a fraction of the real exposure.

Healthcare workers experience workplace violence at rates significantly higher than almost any other industry. The data on this is not in dispute. What is less well understood is that the data vastly underrepresents what is actually happening in clinical environments — and that the gap between reported incidents and actual incidents shapes how healthcare organizations make security investment decisions.

If your security program is calibrated to your reported incident rate, it is calibrated to a fraction of your actual exposure.

Why underreporting is structural, not accidental

Healthcare workers don't fail to report workplace violence because they're not paying attention or because they don't understand reporting requirements. They underreport because the culture of many clinical environments treats certain categories of violent behavior as an inherent part of the job.

Verbal aggression from patients in acute distress. Physical contact during restraint procedures. Threatening behavior from family members under stress. These incidents often don't get reported not because staff don't recognize them as incidents, but because they've been socialized to absorb them as the cost of working in healthcare.

This isn't a failure of individual staff members. It's a systemic normalization that produces a reporting environment where the most common forms of workplace violence are the least likely to generate a formal record.

What the unreported data looks like

Studies examining healthcare workplace violence through anonymous surveys and direct observation consistently find reporting rates between 20% and 40% for physical assault events, and significantly lower for verbal and psychological incidents. That means for every reported physical assault in a clinical setting, there are likely two to four that were not reported.

The implications for security program design are significant. An organization that believes it has 12 workplace violence incidents per year may be operating in an environment with 30 to 50. The risk model built on the reported number is built on incomplete data.

Where the physical security gaps tend to be

When we assess healthcare facilities, the security gaps we find most consistently are not in the areas that generate the most reported incidents. They're in the areas that generate the most unreported ones:

The Joint Commission and the compliance gap

Joint Commission standards address workplace violence prevention in healthcare settings. Most healthcare organizations have documented compliance with these standards. What Joint Commission compliance does not guarantee is that the documented program reflects the actual threat environment — because the compliance framework is built around reported data, not actual incident rates.

An organization can be fully compliant with Joint Commission workplace violence standards and simultaneously be operating a security program that significantly underestimates its exposure. Compliance is a floor, not a ceiling.

Calibrating your security program to your reported incident rate is like calibrating your smoke detectors to the fires your neighbors have reported.

What a useful assessment looks like in this context

A meaningful security assessment in a healthcare setting has to go beyond the incident log. It has to include structured observation during actual operating conditions — including high-stress periods — anonymous staff surveys that surface unreported experiences, and a systematic review of the physical environment against the actual patterns of patient and visitor behavior.

The goal isn't to produce a higher incident count. It's to understand the actual risk environment so that security investments can be directed at the right problems.

The organizations that get this right aren't the ones with the lowest reported incident rates. They're the ones that stopped using reported incident rates as their primary measure of security effectiveness.

Sources and further reading

Healthcare security built for the actual threat environment.

WorldSafe assessments go beyond the incident log — including direct observation, staff interviews, and a systematic physical review calibrated to clinical operating conditions.

Book a consultation