CHSP Security Management — Questions and Answers
Question 1: According to The Joint Commission Environment of Care standards, which of the following is a required component of a healthcare organization's security management plan?
- A security risk assessment that identifies security vulnerabilities specific to the organization (Correct answer)
- Installation of metal detectors at all facility entrances
- Mandatory background checks for all patients admitted to the facility
- A minimum of two armed security officers on duty at all times
Correct answer: A security risk assessment that identifies security vulnerabilities specific to the organization
TJC EC.02.01.01 requires healthcare organizations to conduct a security risk assessment to identify their unique security vulnerabilities. The other options may be appropriate responses to identified risks but are not universally required components of every security management plan.
Question 2: A healthcare safety professional is developing a workplace violence prevention program. Which of the following is the MOST effective primary prevention strategy?
- Installing panic buttons at every nursing station
- Conducting environmental design assessments to reduce violence risk factors (Correct answer)
- Training staff to physically restrain aggressive patients
- Posting warning signs about zero-tolerance violence policies
Correct answer: Conducting environmental design assessments to reduce violence risk factors
Environmental design (CPTED — Crime Prevention Through Environmental Design) is a primary prevention approach that modifies the physical environment to reduce the opportunity for violence before it occurs. Panic buttons and physical restraint training are reactive measures, and signage alone is rarely effective as a primary prevention strategy.
Question 3: Under OSHA's General Duty Clause, healthcare employers are required to protect workers from workplace violence when:
- An employee has personally filed a complaint with OSHA about a threat
- The hazard is recognized and a feasible means of abatement exists (Correct answer)
- A violent incident has already occurred in the facility within the past year
- More than 10% of employees report feeling unsafe at work
Correct answer: The hazard is recognized and a feasible means of abatement exists
The General Duty Clause (Section 5(a)(1) of the OSH Act) requires employers to address recognized hazards for which feasible abatement methods exist. OSHA does not require a prior incident or a formal complaint — if the hazard is recognized (known or should be known) and can be reasonably abated, the employer has a duty to act.
Question 4: Which access control strategy is most appropriate for a hospital's high-security area such as a pharmacy or behavioral health unit?
- Key-based locks with master keys held by department managers
- Visitor sign-in logs at the main entrance
- Proximity card readers with role-based access permissions and audit logging (Correct answer)
- Security cameras monitored during business hours only
Correct answer: Proximity card readers with role-based access permissions and audit logging
Proximity card readers with role-based permissions and audit logging provide layered security: they limit access to authorized personnel by role, create a time-stamped record of entries and exits, and allow rapid deactivation of credentials when needed. Key-based systems lack audit trails and cannot be quickly deactivated; sign-in logs and cameras alone do not restrict unauthorized access.
Question 5: A patient with dementia is found missing from a locked unit. This type of event is classified as:
- A workplace violence incident
- A patient elopement requiring a facility-wide security response (Correct answer)
- A medication error because sedatives were not administered
- A near-miss with no reportable consequences
Correct answer: A patient elopement requiring a facility-wide security response
Patient elopement — the unauthorized departure of a patient from a healthcare facility — is a distinct security event category requiring an immediate, coordinated response (search protocol, notification of family, incident report, and often regulatory notification). It is not classified as workplace violence or a medication error, and because a vulnerable patient is at risk, it is never a 'near-miss' even if the patient is found unharmed.
Question 6: When performing a security vulnerability assessment, the healthcare safety professional should use which framework as a primary reference?
- NFPA 101 Life Safety Code
- The International Association for Healthcare Security and Safety (IAHSS) Healthcare Security Guidelines (Correct answer)
- OSHA 29 CFR 1910.1200 (Hazard Communication Standard)
- CMS Conditions of Participation for Critical Access Hospitals
Correct answer: The International Association for Healthcare Security and Safety (IAHSS) Healthcare Security Guidelines
The IAHSS Healthcare Security Guidelines are the industry-standard reference specifically designed for assessing and improving security in healthcare settings. NFPA 101 addresses life safety/fire, OSHA 1910.1200 covers chemical hazard communication, and CMS CoPs address broad operational compliance — none are security assessment frameworks.
According to The Joint Commission Environment of Care standards, which of the following is a required component of a healthcare organization's security management plan?