Skip to content
mobile-alt icon

877-690-8230

 Workplace Violence Compliance in Healthcare:
Joint Commission, CMS, OSHA, & State Requirements

Four regulators, one requirement each, and a state layer most compliance officers are missing. Here is what each actually requires, cited by number, and what happens to the documentation afterward.

 By Casey Goldschmidt, CEM | Chief Operating Officer, Vistelar 

A health system can pass its accreditation survey with excellent marks in the same year its reported workplace violence incidents rise forty percent.

That is not a scandal. It is the system working as designed. A survey asks whether the program exists. It does not ask whether it worked.

Most compliance writing on this subject stops there, treats the gap as an indictment, and moves on. The gap is real, but it is not the interesting part. The interesting part is what happens to everything you produce in order to close it.

Because every regulator in this article requires you to write down what you know about violence risk in your building. The Joint Commission requires an annual worksite analysis. OSHA requires the injury log. CMS requires a documented risk assessment. Twenty-one states require an assessment, a plan, an incident log, or some combination, and nineteen of them require the written plan.

That file is the compliance requirement. It is also the exhibit. And the organizations that get hurt are not the ones that failed to build it. They are the ones that built it, filed it, and did nothing about what was in it.

I have sat through these surveys on both sides of the table. This article covers all four regulators and what each requires, cited by number so you can look it up, which states impose a real prevention-plan obligation and which only criminalize assault, and what the record you are compelled to create does for you and to you when something goes wrong.

Key Takeaways

  • There are four regulators, not two. Joint Commission, CMS, OSHA, and your state. Most compliance pages cover the first and third and miss the two that carry the sharpest consequences.
  • Federal OSHA has no healthcare workplace violence standard, and the proposed rule has been parked in Long-Term Actions since September 2025. Enforcement runs entirely through the General Duty Clause, and in February 2026 a federal appeals court confirmed that accreditation and CMS compliance do not preempt it.
  • Nineteen states require a written prevention plan. Two more require incident reporting without a plan. That is a different and much shorter list than the states that criminalize assault on a healthcare worker, and conflating the two is the most common error in this category.
  • Workers' compensation is the exclusive remedy in most states, so an assaulted employee generally cannot sue the hospital in tort. The hospital's real tort exposure runs to patients, visitors, contractors, and agency staff.
  • Foreseeability is not presumed in healthcare. That claim circulates widely and no jurisdiction applies it. What is true is that hospitals generate the documentary proof of notice themselves.
  • HIPAA is not the obstacle it is claimed to be. Telling the incoming nurse that a patient has assaulted staff is a treatment disclosure. It needs no authorization and the minimum necessary standard does not apply to it.

The four regulators, and what each one requires

Four Layers, One Program

Four regulators. Four separate citations. No single agency will tell you the other three exist.

Four players-One Program-PP3

 Four regulators. Four separate citations. One program has to satisfy all of them, and no single agency will tell you that. 

Joint Commission: NPG.02.04.01

Effective January 2026, the Joint Commission replaced its National Patient Safety Goals chapter with National Performance Goals. The workplace violence requirement is now cited as NPG.02.04.01, "The hospital has a workplace violence prevention program." It sits under Goal 2, "The governing body and leadership team foster a culture of safety," alongside three unrelated standards.

Two notes before the substance. Goal 2 is not a workplace violence goal, so do not describe it as one. And the Joint Commission's own website labels this "National Performance Goal #2a," but that label does not appear in the standards manual. Cite NPG.02.04.01. A compliance page that cannot be cited by requirement number loses to one that can, and a surveyor will use the number.

There are three Elements of Performance.

EP 1

EP 1 requires a program "led by a designated individual and developed by a multidisciplinary team," including policies and procedures to prevent and respond to workplace violence, a process to report incidents in order to analyze incidents and trends, a process for follow-up and support to victims and witnesses including trauma and psychological counseling if necessary, and reporting of incidents to the governing body.

EP 2

EP 2 requires training, education, and resources delivered at time of hire, annually, and whenever changes occur to the program, provided to leaders, staff, and licensed practitioners, with content determined by role. It specifies four content areas: what constitutes workplace violence; the roles and responsibilities of leaders, clinical staff, security personnel, and external law enforcement; training in de-escalation, nonphysical intervention skills, physical intervention techniques, and response to emergency incidents; and the reporting process.

EP 3

EP 3 requires an annual worksite analysis, and requires the hospital to act on what it finds. The accompanying note defines a worksite analysis as a proactive analysis of the worksite, an investigation of the hospital's own incidents, and an analysis of how policies, procedures, training, education, and environmental design reflect best practices and conform to applicable laws and regulations.  

That clause pulls your state's requirements inside the accreditation requirement.

If your state mandates a prevention plan and you do not have one, that is not only a state problem.

 Read EP 2's third bullet again. The Joint Commission names de-escalation, nonphysical intervention, and physical intervention as separate required content areas. A single annual module does not cover them, and role-appropriate content means an environmental services worker and an emergency department nurse do not get the same class.

What the Joint Commission counts as workplace violence

The definition is broader than most programs are scoped for, and it is worth quoting in full because the last clause is the one that matters:

An act or threat occurring at the workplace that can include any of the following: verbal, nonverbal, written, or physical aggression; threatening, intimidating, harassing, or humiliating words or actions; bullying; sabotage; sexual harassment; physical assaults; or other behaviors of concern involving staff, licensed practitioners, patients, or visitors.

"Other behaviors of concern" is a catch-all, and "staff, licensed practitioners, patients, or visitors" means it runs in every direction. A physician humiliating a nurse is in scope. So is a nurse bullying a technician. Programs built solely around patient-on-staff assault are scoped to a fraction of the definition they are being surveyed against.

One frequently repeated version of this definition begins "verbal, written, or physical aggression." That is the Department of Labor's definition, quoted inside the Joint Commission's 2018 Sentinel Event Alert. It is not the standard, and it drops "nonverbal."

What changed in January 2026, and what did not

Very little changed substantively, and the framing that circulates about it is wrong in a specific way.

Sentinel Event Alert 59 (April 2018, revised June 2021) was never an enforceable standard. Its own language asks that organizations "consider" its suggestions "or reasonable alternatives." It has not been formally retired.

The enforceable obligations began on January 1, 2022, as five Elements of Performance across four standards: LD.03.01.01 EP 9 (the program), HR.01.05.03 EP 29 (training), EC.02.01.01 EP 17 (worksite analysis), and EC.04.01.01 EPs 1 and 6, both revised to add workplace violence to the incidents a hospital must continually monitor, internally report, and investigate.

All five carried forward. The first three became NPG.02.04.01 EPs 1 through 3 with essentially cosmetic wording changes, and the EC.04.01.01 incident reporting and investigation content is now inside EP 1's requirement for "a process to report incidents in order to analyze incidents and trends" and EP 3's requirement for "an investigation of the hospital's workplace violence incidents." Workplace violence moved out of the physical environment chapter entirely. If your program still maps these obligations to an Environment of Care citation, the citation is retired even though the obligation is not.

The escalated finding

The Joint Commission's parallel to a CMS immediate jeopardy is an Immediate Threat to Health or Safety, and it has its own requirement: APR.09.04.01 EP 1, that the hospital "provides care, treatment, services, and an environment that pose no risk of an Immediate Threat to Health or Safety." It is defined as a threat representing immediate risk that has or may have serious adverse effects on patient health or safety.

An ITHS can trigger a Preliminary Denial of Accreditation, an abatement survey, and a period of conditional accreditation. Two features make it different from an ordinary Requirement for Improvement. It cannot be resolved through the post-survey clarification process, which means you cannot argue it away afterward with documents. And the decision is posted publicly.

Separately, the Sentinel Event chapter makes several workplace violence events reviewable sentinel events in their own right, including homicide of a staff member, visitor, or vendor on site, sexual assault of the same, and physical assault leading to death, permanent harm, or severe harm. That is an independent reporting channel from the NPG standard, and programs often miss it.

(A note on sourcing: the ITHS procedural sequence above comes from a compliance publisher rather than from the Joint Commission directly. The requirement and the definition are from the manual.)

CMS: the layer most programs miss entirely

This is the largest gap in most compliance programs, and the one with the sharpest financial consequence.

On November 28, 2022, CMS issued QSO-23-04-Hospitals, "Workplace Violence-Hospitals," effective immediately. It creates no new regulation. It tells state survey agencies that existing Conditions of Participation already reach workplace violence, and it names them:

42 CFR §482.13(c)(2)

42 CFR §482.13(c)(2), patient rights: "The patient has the right to receive care in a safe setting."

 

42 CFR §482.15(a)(1)

42 CFR §482.15(a)(1), emergency preparedness: the plan must "be based on and include a documented, facility-based and community-based risk assessment, utilizing an all-hazards approach."

42 CFR §482.15(d)(1)

 42 CFR §482.15(d)(1), training: initial training for new and existing staff, individuals providing services under arrangement, and volunteers, at least every two years thereafter, with documentation and demonstrated staff knowledge.

The memo advises hospitals to identify patients at risk of harming themselves or others, identify environmental safety risks, and train staff and volunteers at orientation and whenever policies change, and it recommends ongoing training at least every two years. Note the verb. The binding two-year training cycle is in §482.15(d)(1); the memo's own language is a recommendation. It also contains a sentence worth reading twice: "CMS has cited hospitals in the past for failures to meet these obligations."

One thing to understand about the CMS theory, because counsel will raise it. §482.13(c)(2) is a patient right. CMS does not regulate employee safety; that is OSHA's jurisdiction. The CMS route to workplace violence runs through the proposition that a hospital where staff are being assaulted is not a safe setting for patients. That is a real and well-established theory, and it is also why a CMS finding tends to be framed around patient exposure rather than staff injury.

Why this matters more than an accreditation finding. Joint Commission accreditation carries deemed status for Medicare purposes. But a Requirement for Improvement is not a Condition of Participation deficiency, and there is no automatic conversion between them. What actually creates CMS exposure is that a deemed hospital must authorize its accreditor to release its survey and related information to CMS, and CMS may then find noncompliance "on the basis of its own investigation of the accreditation survey or any other information related to the survey." Validation surveys and complaint surveys are the other routes.

One channel is automatic, and it is the one that matters most. Under 42 CFR §488.5(a)(4)(ix), an accrediting organization must notify CMS of an immediate jeopardy identified on an accreditation survey or complaint investigation within two business days. For the escalated finding, the pipe from your accreditor to CMS is mandatory and fast.

Below that threshold the chain is real but discretionary. A workplace violence finding creates a documentary record CMS is entitled to obtain, a factual predicate for a complaint or validation survey, and, if it escalates, a public posting that can itself generate one. The consequence at the end of that chain is termination of the provider agreement, which is why this belongs in a conversation with a CFO and not only with a survey coordinator.

Immediate jeopardy, correctly stated

This gets described wrong constantly, and a risk manager will know it cold.

The governing document is QSO-25-09-ALL (November 21, 2024), which revised the 2019 memo that created the Core Appendix Q used across all provider types. Immediate jeopardy is:

a situation in which a recipient of care has suffered or is likely to suffer serious injury, harm, impairment, or death as a result of a provider's, supplier's, or laboratory's noncompliance with one or more health and safety requirements.

Three components, and only three. Noncompliance; that it caused or created a likelihood of serious injury, harm, impairment, or death; and that immediate action is necessary to prevent occurrence or recurrence.

Two corrections to what circulates. Culpability is not an element. CMS removed it in 2019 because the regulatory definition never required it, so "the organization knew and did not act" is not something a surveyor must establish. And there is no twenty-four-hour corrective action plan requirement. The surveyor notifies the administrator immediately and provides the completed IJ template. A removal plan is required "as soon as the entity has identified the steps it will take." No hour count appears anywhere in the memo. If your policy references a twenty-four-hour deadline, you may have imported the Joint Commission's ITHS timeline into the CMS process.

OSHA: a General Duty Clause, and a February 2026 decision that changes the calculus

There is no federal OSHA standard for workplace violence in healthcare.

The proposed rule, RIN 1218-AD08, was moved to Long-Term Actions in the Unified Agenda published September 22, 2025, with the proposed rule date changed to "To Be Determined," and it remained there in the agenda released July 3, 2026. Long-Term Actions means the agency does not expect to act within twelve months.

There is also no National Emphasis Program and no healthcare workplace violence Regional Emphasis Program. The only regional instrument is a Region II directive governing follow-up on Hazard Alert Letters.

What exists instead is OSH Act §5(a)(1), 29 U.S.C. §654(a)(1):

Each employer shall furnish to each of his employees employment and a place of employment which are free from recognized hazards that are causing or are likely to cause death or serious physical harm to his employees.

Enforcement procedures are in CPL 02-01-058, "Enforcement Procedures and Scheduling for Occupational Exposure to Workplace Violence," dated January 10, 2017 and still current. It expressly identifies healthcare as a high-risk industry and gives setting-specific guidance for hospitals, residential treatment, and field work.

The guidance document everyone cites is OSHA 3148-06R (2016), Guidelines for Preventing Workplace Violence for Healthcare and Social Service Workers, first issued in 1996. It is voluntary guidance, not a standard, and it is enforceable only derivatively, as evidence that a hazard was recognized and that abatement was feasible. Note that OSHA's own healthcare webpage still calls it the 2015 edition, which is a stale page describing the superseded 3148-04R.

Its five components, as the section headings name them:

1

Management Commitment and Worker Participation

2

Worksite Analysis and Hazard Identification

3

Hazard Prevention and Control

4

Safety and Health Training

5

Recordkeeping and Program Evaluation

A written program is not one of the five. It appears earlier, in the introduction, as a recommendation: a written program "offers an effective approach to reduce or eliminate the risk of violence." Substituting it for element 1 drops management commitment, which is the element OSHA weights most heavily in General Duty Clause cases. That substitution is common and it is a meaningful error in a document about defensibility.

(One wrinkle worth knowing so you are not caught out: OSHA's own document lists these twice, and the narrative sentence on page 5 uses slightly different wording, including "employee participation" rather than "worker participation." Both appear in the same publication. The section headings govern.)

What is Enforceable and What is Not

The right column cannot be cited against you directly. It is how the left column gets proven.

Enforceable-Not-Enforceable-PP3

 The documents on the right cannot be cited against you directly. They are how the documents on the left get proven. 

On February 13, 2026, the Tenth Circuit issued a published opinion in Cedar Springs Hospital, Inc. v. OSHRC, No. 24-9519, affirming a General Duty Clause citation against a psychiatric hospital for workplace violence.

One holding and one piece of reasoning matter to anyone building a program.

The holding: compliance with CMS requirements and accreditation standards does not preempt OSHA.

The argument that a hospital is already regulated on patient and staff safety by other bodies, and therefore should not face a §5(a)(1) citation for the same conduct, was rejected. The court noted that an accreditor "is a private entity, not an agency exercising regulatory authority." Passing your survey is not a defense to an OSHA citation.

The reasoning to sit with: the court found abatement feasible partly on the strength of what the hospital did after it was cited. Evidence of effectiveness came, in the court's words, not only from experience at other hospitals but also from Cedar Springs' own actions following the citation. The fixes it made afterward helped show it could have made them before.

That second holding is uncomfortable and it is also correct as a matter of long-standing OSHA law. It does not mean you should hesitate to fix things. It means the window in which a known hazard sits unremediated is the window that creates the exposure, and the length of that window is entirely within your control.

Penalties, and the number that is wrong in most decks

The figure of "$156,000" still circulating in safety presentations is from 2023 and understates current exposure.

 Violation type

 Maximum per violation

Willful or repeated

$165,514

Serious, other-than-serious, posting

$16,550

Failure to abate

$16,550 per day

These took effect for penalties assessed after January 15, 2025, and remain in effect for calendar year 2026 because no inflation adjustment was made.

The reason is worth stating precisely, because the usual version is imprecise. A lapse in appropriations in October and November 2025 meant the Bureau of Labor Statistics could not produce the October 2025 consumer price index, and the governing statute permits no alternative method. OMB Memorandum M-26-11, dated April 17, 2026, then cancelled the 2026 penalty inflation adjustments government-wide and directed agencies to hold at 2025 levels while still publishing a Federal Register notice reflecting the outcome. OSHA's memo followed on May 21, 2026, and the Department of Labor's Federal Register notice on May 27, 2026, at 91 Fed. Reg. 31358. So OSHA published something titled a 2026 annual adjustment whose content is that there is no adjustment.

Some minimum penalty amounts did move, but not because of inflation. They reflect Field Operations Manual revisions effective July 14, 2025 that expanded penalty reductions, which mechanically lowers the floor.

Rather than re-checking a dollar figure every January, describe the exposure as over $150,000 per violation for willful or repeated violations, adjusted for inflation annually. That is accurate today and will not need correcting next year. 

One structural point that matters more than the headline number. Assaults resulting in days away or restricted duty are recordable on the OSHA 300 log, and a log entry raises your DART rate. An elevated DART rate can make an establishment selectable for a programmed inspection that arrives without a complaint or a referral. Once an inspector is on site, the workplace violence program is available for evaluation. Under-recording to suppress the rate is not a way out, because it creates independent recordkeeping exposure and any discrepancy between the 300 log and your internal incident log is immediately visible. 

The federal bills that get confused
(and what they would actually do)

Four bills are pending in the 119th Congress. They come up constantly in internal materials, usually merged into one, and they do entirely different things.

The Save Healthcare Workers Act

H.R.3178 (Rep. Madeleine Dean) and S.1600 (Sen. Cindy Hyde-Smith), both introduced May 5, 2025, would make assaulting a healthcare worker a federal crime. It is a criminal statute. It touches OSHA rulemaking not at all and would impose no compliance obligation on your organization.

Note the name. It is the Save Healthcare Workers Act, not an acronym. The SAVE Act, the Safety from Violence for Healthcare Employees Act, was the predecessor in the 118th Congress. Writing "SAVE" in a board memo is a small thing that tells a legislative affairs colleague you got it from a secondary source.

The Workplace Violence Prevention for Health Care and Social Service Workers Act

H.R.2531 (Rep. Joe Courtney) and S.1232 (Sen. Tammy Baldwin, referred to the Senate HELP committee), is the one that would create an obligation. It would direct the Department of Labor to issue an enforceable OSHA standard, which is the thing the agency has affirmatively shelved.

It also carries a Medicare hook that gets overstated, so state it carefully. The bill would condition Medicare participation on compliance for hospitals and skilled nursing facilities not otherwise subject to the OSH Act or an approved state plan. That is a jurisdictional gap-filler aimed at facilities OSHA cannot reach, such as state and local government employers in states without an approved plan. It is not a blanket Medicare condition, and describing it as one will not survive a conversation with anyone who has read it.

Nothing has moved.

All four bills sit at their 2025 committee referrals. No hearing, no markup, no floor action as of August 2026. Cosponsors continue to accumulate, which is accretion rather than progress and is easy to mistake for momentum in a tracking report.

"The bills would compel a standard the agency has already parked. Building a program around either is building around a schedule nobody controls."

Which is the argument for reading the next section carefully, because the enforceable obligation that is actually growing is not federal at all.

The state layer, and the distinction nobody publishes

Here is where most compliance pages fail their reader.

Two entirely different categories of state law get treated as one. States that criminalize or enhance penalties for assaulting a healthcare worker create no employer obligation whatsoever. States that mandate a written prevention plan create an affirmative, documentable duty. A compliance officer needs the second list. Almost every published resource gives them the first.

regulatory-binder-records-tabs-pillar-page-3

Four regulators, four separate records, one program that has to satisfy all of them.

Two Maps, Not One

These get published as one map. Only one of them is a compliance requirement. 

Two-Maps-Not-One-PP3

 These two maps get published as one map. Only one of them is a compliance requirement.

The 19 states that require a plan 

California

  • Citation:  8 CCR §3342
  • Core Requirement:  Written plan, hazard ID, violent incident log, initial and annual training, incident reporting to Cal/OSHA
  • Covered:  Health facilities, home health and hospice, EMS, drug treatment, outpatient correctional medical
  • Effective:  Log and reporting April 1, 2017; plan and training April 1, 2018

Connecticut

  • Citation:   Conn. Gen. Stat. §19a-490q
  • Core Requirement:  Safety committee at least half non-management, annual risk assessment, written plan
  • Covered:  Health care employers with 50+ employees
  • Effective:  In force since 2011; risk assessment by Oct 1 and plan by Jan 1, annually  

Illinois

  • Citation:  210 ILCS 160
  • Core Requirement:  Plan conforming to OSHA's five components
  • Covered:  Hospitals, retail health facilities, veterans homes
  • Effective:  Jan 1, 2019

Kentucky

  • Citation:  KRS 216.701–216.709
  • Core Requirement:  Safety assessment and plan, training within 90 days of hire and annually with competency testing, incident reporting, post-incident debriefing 
  • Covered:  Licensed health facilities
  • Effective:  Cabinet audits from Jan 1, 2025

Louisiana

  • Citation: La. R.S. 40:2199.15–.16
  • Core Requirement: Written plan, annual risk assessment, annual interactive education, incident response and investigation
  • Covered: Licensed facilities, FQHCs, pharmacies, and provider offices with five or more healthcare professionals
  • Effective: Acts 2022, No. 461

Maine

  • Citation: 22 M.R.S. §1832
  • Core Requirement: Annual adoption of a safety and security plan protecting patients, visitors, and employees from aggressive and violent behavior, including a process to receive and record incidents and threats, and a bar on interfering with anyone making a report
  • Covered: Licensed hospitals
  • Effective: In force since 2011. Amended effective Jan 1, 2027, which keeps this duty and adds a separate cybersecurity plan

Minnesota

  • Citation: Minn. Stat. §144.566
  • Core Requirement: Preparedness and response action plan reviewed annually, committee including non-managerial workers, training at orientation and before first independent shift
  • Covered: Licensed hospitals
  • Effective: Plan Jan 15, 2016; annual submission to the commissioner from Jan 1, 2025

Nevada

  • Citation: NRS 618.7305–618.7318
  • Core Requirement: Safety committee, unit-specific written plan, training on hire and reassignment, hazard assessment, active shooter protocols, annual effectiveness review
  • Covered: Hospitals, psychiatric hospitals, home nursing agencies with 50+ employees, independent emergency care centers, intermediate care and skilled nursing facilities, modified medical detoxification facilities, community triage centers
  • Effective: A.B. 348 (2019)

New Hampshire

  • Citation: RSA ch. 277-C (with RSA 151-J)
  • Core Requirement: Workplace violence prevention program, annual facility-specific risk assessment, training in de-escalation and nonphysical intervention and emergency response, follow-up support for victims and witnesses, anti-retaliation protection, monthly incident reports to the Department of Labor, and annual reports to the state health care workplace safety commission. Joint Commission compliance may be submitted in lieu of the program requirements
  • Covered: Acute care, rehabilitation, psychiatric, and substance abuse treatment hospitals, plus urgent care centers, excluding state-operated facilities and unaffiliated urgent care operators with fewer than three New Hampshire clinics
  • Effective: July 1, 2023; urgent care July 1, 2024; monthly DOL reporting added Aug 9, 2025

New Jersey

  • Citation: N.J.S.A. 26:2H-5.20
  • Core Requirement: Committee at least half direct patient care staff, plan with annual risk assessment, annual training, 5-year record of violent acts, crisis response team
  • Covered: General and special hospitals, nursing homes, state and county psychiatric hospitals, developmental centers
  • Effective: P.L. 2007, c. 236; program within 6 months, written plan within 18 months

New York

  • Citation: Labor Law §27-b; Pub. Health Law §§2832, 2832-a
  • Core Requirement: Public employers: risk evaluation, written program, training. Hospitals and nursing homes: program, annual safety and security assessment, ED security personnel
  • Covered: §27-b: public employers with 20+ employees. §2832: general hospitals and nursing homes
  • Effective: §27-b in force. §2832 act effective Sept 18, 2026; assessments from Jan 1, 2027; programs by Sept 18, 2027

North Carolina

  • Citation: N.C.G.S. §131E-88
  • Core Requirement: Security risk assessment, written security plan, trauma-informed and de-escalation training, law enforcement officer present at all times in or on the same campus as the ED (waivable)
  • Covered: Licensed hospitals with an emergency department
  • Effective: Subsection (b) applies June 1, 2025

Ohio

  • Citation: Ohio Rev. Code §3727.18
  • Core Requirement: Security plan from a risk assessment, team at least half direct-care staff including a current or former patient or family member, de-escalation-trained employee present in ED and psychiatric departments at all times
  • Covered: Each hospital system, and each hospital not part of a system
  • Effective: Apr 9, 2025

Oregon

  • Citation: ORS 654.412–654.416 as amended by SB 537
  • Core Requirement: Plan with investigation procedures and post-incident interviews, annual training, plan and anti-retaliation statement to employees within 30 days, 5-year incident assessment with root-cause analysis
  • Covered: Hospitals (excluding Oregon State Hospital), ambulatory surgical centers, home health, home hospice
  • Effective: Jan 1, 2026

Rhode Island

  • Citation: R.I. Gen. Laws ch. 23-17.28
  • Core Requirement: Safety committee with periodic assessments, assault prevention program, ongoing training across 12 specified topics
  • Covered: Licensed hospitals
  • Effective: P.L. 2021, chs. 330 and 331; training within 90 days of hire; program reviewed at least every 2 years

Texas

  • Citation: Health & Safety Code ch. 331
  • Core Requirement: Prevention committee including a direct-care RN and a physician, written policy with confidential non-retaliatory reporting, written plan with at least annual training, annual committee review reported to the governing body
  • Covered: Hospitals, mental hospitals, ASCs, freestanding EDs, plus nursing facilities and home and community support agencies that employ at least two RNs
  • Effective: Chapter Sept 1, 2023; policy and plan by Sept 1, 2024

Vermont

  • Citation: 18 V.S.A. §1911b
  • Core Requirement: Security plan from a multidisciplinary team including law enforcement, risk assessment covering the ED, de-escalation-trained staff present at all times, anti-retaliation policy, posted notice
  • Covered: Licensed hospitals
  • Effective: July 1, 2025

Virginia

  • Citation: Va. Code §32.1-127(B)(22) and (F)–(I)
  • Core Requirement: Security plan built on a security risk assessment, off-duty law enforcement or trained security present at all times (waivable by the Commissioner), training in de-escalation, restraint, crisis intervention and trauma-informed approaches; plus an incident reporting system with 2-year retention and quarterly internal reporting
  • Covered: Hospitals with an emergency department
  • Effective: July 1, 2025; first annual report to the state health department July 1, 2026

Washington

  • Citation: RCW ch. 49.19 as amended by 2SHB 1162
  • Core Requirement: Security assessment, plan from a committee of employee-elected and employer-selected members, annual plan review, prompt investigation of every incident with systemic-cause and staffing analysis, deidentified summaries to the committee
  • Covered: Hospitals, home health, hospice, home care, evaluation and treatment facilities, behavioral health programs, ASCs
  • Effective: Chapter 2020; amendments Jan 1, 2026
 

Two more states require reporting without a plan. Utah, under Utah Code §26B-2-244, requires hospitals to run an incident reporting system with an anti-retaliation policy, two-year retention, quarterly reports to the chief medical and nursing officers, and an annual report to the state, with compliance due November 1, 2026. Oklahoma, under 63 O.S. §1-114.3, requires hospitals, health clinics, and ambulance services to post a prominent warning sign and report all assaults on medical care providers to the state health department annually, effective November 1, 2020.

Notes that will save someone a phone call.

California Note

California's SB 553 does not apply to you if §3342 does. Labor Code §6401.9 expressly excludes health care facilities, service categories, and operations covered by 8 CCR §3342. A hospital already running a §3342 plan does not build a second one. This is the most common California question in the category and the answer is usually no.

Two California deadlines are on the Standards Board, not on hospitals. The Board must adopt a general-industry standard by December 31, 2026, and must amend §3342 to address weapons detection screening by March 1, 2027. Neither is a hospital compliance date. Hospitals get roughly ninety days after the screening standard is adopted, so the earliest realistic compliance date is mid-2027 and it floats with the actual adoption.

New York Note

New York's 2025 law has three dates, which is why sources disagree. The act takes effect September 18, 2026, annual assessments begin January 1, 2027, and programs must be established by September 18, 2027. Any source giving one date for it is wrong.

Colorado Note

Colorado is a different shape and deserves a footnote rather than a row. Its prevention-plan bill died in 2024. What passed instead creates a policy and reporting obligation enforced through a hospital quality incentive payment rather than through licensure: from July 1, 2026 the state assesses whether a hospital has adopted a formal workplace violence policy and confirmed its reporting, as an input to that payment. Hospitals under 100 beds are exempt from the reporting piece. Not a licensure mandate, but not optional either if the payment matters to you.

Massachusetts Note

Massachusetts is close. The hospital mandate passed both chambers, H.4767 in the House and S.3184 in the Senate, and went to a conference committee appointed in July 2026. If you operate there, watch it.

The criminal penalty layer, and why every published count is different

Most states criminalize or enhance penalties for assaulting a healthcare worker. This creates no obligation for your organization, and it belongs in your conversation with prosecutors rather than in your compliance file.

A figure of forty-nine states circulates widely. I could not trace it to any source. The National Conference of State Legislatures publishes no such count. Neither does the American Hospital Association, the American Nurses Association, or the Emergency Nurses Association.

 Source

 Count

 What it Counts

Peer-reviewed legal scan, Health Affairs Scholar, 2026

45 states

Any law penalizing perpetrators of violence against healthcare workers, as of June 2024

American Nurses Association

38 states (a list, not a count)

Penalties for assault of nurses, page last updated March 2021

Emergency Nurses Association

31 states

Felony to assault an emergency nurse, undated

American Medical Association

"almost all"

Laws that "enhance, or extend, criminal penalties"

The spread from 31 to 49 is definitional, not factual. Felony only or any enhancement. Emergency nurses or all healthcare workers. A standalone offense or an aggravating factor inside a general assault statute. Any single number is a scope choice. The only count with a documented method is the peer-reviewed one. Note that it also found eighteen states with prevention-plan laws as of June 2024, which is more than this article's list rather than fewer, and the difference is instructive: several states in the table above passed or amended their laws after that scan closed, and the scan's broader definition captured states this article excludes because their requirement is a workgroup, a payment condition, or a public-employee rule rather than a duty on health care employers. Counts differ because scope differs. That is true here too.  

What the documentation does to you

Now the part that most compliance content leaves out. 

Every requirement above compels you to create a written record of what you know about violence risk. Then, if something happens, that record is what a plaintiff's lawyer, an OSHA inspector, or a surveyor reads first. 

Three things follow, and the third is the one that matters.

First: correct who can actually sue you

In most states, an employee assaulted at work cannot sue their employer in tort. Workers' compensation is the exclusive remedy for injuries arising out of and in the course of employment, and recharacterizing the injury as negligent security does not escape it. It is still an employee suing an employer over a work injury.

This is worth being blunt about, because nearly every article and vendor deck in this category tells risk managers that an assaulted nurse will bring negligent hiring, retention, and supervision claims. In most jurisdictions that is wrong, and it misdirects the program.

The exceptions are narrow and state-specific. The intentional-tort exception generally requires that the employer itself committed, directed, or ratified the assault, and a failure to prevent a foreseeable assault is negligence rather than intent. A handful of states apply a deliberate-intent or substantial-certainty test instead, which is broader but still demanding. Assaults arising from a purely personal quarrel imported into the workplace can fall outside comp entirely, which opens the tort door and closes the benefits door at the same time.

Nonsubscriber states are the clearest exception, and the leading case is a warning rather than an opening. In Texas West Oaks Hospital v. Williams, a psychiatric technician injured by a patient could sue his employer because the hospital did not subscribe to workers' compensation. He lost anyway. The Texas Supreme Court held his claim was a health care liability claim under the state's medical liability act, which reaches employee plaintiffs and not only patients, and dismissed it for failure to serve the required expert report. Losing the comp bar does not mean losing every defense.

So where does the real tort exposure sit? With everyone who is not your employee. Patients. Visitors. Vendors and contractors. Employees' family members. And travel and agency staff, whose compensation runs through the staffing agency, which in many states makes the host facility a third party they can sue. Not all states: where the host directs the temporary worker's work, borrowed-servant or special-employer doctrine can restore the bar to the facility. Given how heavily hospitals now rely on contingent staffing, it is worth knowing which rule your state applies before you need to.

The model case is a hospital sued after an employee's daughter was abducted and murdered in its parking ramp. She was a business visitor, not an employee, so exclusivity was irrelevant and the hospital faced a full negligent security case.

Second: foreseeability is not presumed

The claim that foreseeability is "presumed" in healthcare because industry violence data is extensive appears in a great deal of vendor content. No jurisdiction applies that rule. Foreseeability is an element the plaintiff must prove, and in several major jurisdictions the standard is more demanding than ordinary negligence, not less.

Courts use one of four tests: the specific harm rule, prior similar incidents, the totality of the circumstances, or a balancing test weighing foreseeability and gravity of harm against the burden of prevention.

California is worth following in detail, because its leading case is a hospital parking lot shooting and because the law moved after it. Isaacs v. Huntington Memorial Hospital (1985) held that prior similar incidents were helpful but not necessary. Then it was narrowed. Ann M. (1993) held that a high degree of foreseeability is required before a duty to hire security guards attaches, and that it can rarely be shown without prior similar incidents. Sharon P. (1999) applied that to an underground parking garage and found no duty. The line that emerged is a sliding scale, confirmed in Delgado (2005): the more burdensome the precaution, the more foreseeability is required, and simple, low-burden measures need only ordinary foreseeability.

For a hospital that means the analysis turns on what you were asked to do. A demand that you should have posted armed guards faces a high bar. A demand that you should have fixed a light, locked a door, or changed a visitor policy faces a much lower one, and those are the measures your own worksite analysis is most likely to have named.

Anyone citing Isaacs alone is citing forty-year-old law, and opposing counsel will say so.

Third: the record you are required to keep is the proof of notice

Here is where the first two points converge, and it is the reason this article exists.

Foreseeability is not presumed. But in emergency departments, behavioral health units, and parking structures it is often easy to establish on the facts, for a reason hospitals create themselves. Incident reporting systems, security logs, the annual worksite analysis the Joint Commission requires, the OSHA 300 log, the risk assessment CMS requires, and the incident records twenty-one states require all generate a documentary record of actual notice.

In the parking ramp case, the evidence that sank the hospital included its own rape-awareness seminars, which had warned employees that thirty percent of rapes begin or occur in parking lots. The hospital's own safety education proved it knew.

And in the Tenth Circuit case decided this February, the hospital's own post-citation fixes proved abatement had been feasible before the citation.

 "Every regulator requires you to write down what you know. Both of the leading cases turned on a hospital's own documents."  

The conclusion is not to document less. That is unlawful, it fails every requirement in this article, and it is worse on the facts, because a thin file in a setting with obvious risk reads as indifference rather than as innocence.

The conclusion is that an unremediated known risk is the worst available posture, and it is the one a compliant-but-inert program produces by default. A program that generates a worksite analysis every year and acts on none of it has manufactured, at annual intervals, a dated record of everything it knew and did not fix.

That is not a documentation problem. It is the difference between a compliance program and a safety program, and it is visible in the file either way.

What a surveyor will actually ask for 

 The gap between "we have a program" and "we can show you the program" is where findings come from. Here is the mapping, requirement to evidence.

Requirement to Evidence Crosswalk

What is required and what a surveyor actually asks to see on the day

Requirement-to-Evidence-Crosswalk-PP3

 The left column is what is required. The right column is what gets asked for. Most programs have the left and cannot produce the right on the day.

Requirement

 What you will be asked to produce

NPG.02.04.01 EP 1, program and leadership

The named individual's designation. Multidisciplinary team roster and meeting minutes. Written policies and procedures. The incident reporting pathway and evidence that trend analysis occurs. Victim and witness follow-up protocol including counseling access. Governing body minutes showing WPV data was reported.

EP 2, training

Individual completion records tied to specific content and dates, not aggregate percentages. Evidence of training at hire, annually, and after program changes. Role-differentiated curricula. Content covering all four named areas, including de-escalation, nonphysical intervention, and physical intervention as distinct items.

EP 3, worksite analysis

The completed analysis, dated within twelve months. Evidence it was proactive rather than only retrospective. Incident investigation records. Documented actions taken in response, with owners and dates.

42 CFR §482.13(c)(2)

Patient risk assessment strategy. Environmental hazard identification and remediation records.

42 CFR §482.15(a), (d)(1)

Facility-based and community-based risk assessment addressing violence. Training records covering staff, contractors, and volunteers, at least every two years, with evidence of demonstrated knowledge.

OSH Act §5(a)(1)

OSHA 300 logs. Hazard assessment. Controls implemented and dated. Training records. Evidence that identified hazards were abated, and how quickly.

State plan mandate

Whatever your state names. Commonly: the written plan, committee composition and minutes, annual review, incident log, retention schedule, anti-retaliation policy.

 The row that fails most often is the last cell of EP 3. Organizations produce the worksite analysis. Far fewer can produce the record of what changed because of it. 

 

HIPAA is not the obstacle 

Two things get confused here, and the confusion has operational consequences: staff withhold safety-relevant information because someone told them HIPAA forbids sharing it.

Telling the clinical team that a patient has assaulted staff is treatment. It is permitted under 45 CFR §164.502(a)(1)(ii) and §164.506(c), and no authorization is required. Handoff, the responding physician, the sitter: all treatment.

On minimum necessary, be precise, because a privacy officer will be. §164.502(b)(2)(i) exempts disclosures to a health care provider for treatment from the minimum necessary standard. Sharing inside your own organization is technically a use rather than a disclosure, and uses are governed by role-based access under §164.514(d). The result is the same either way, but the reasoning differs, and policies that cite the wrong one invite an argument you do not need.

45 CFR §164.512(j) is a different pathway for a different purpose. It permits disclosure to avert a serious and imminent threat, to someone reasonably able to prevent or lessen it, including the target. That is the authority for telling security or law enforcement, not for routine care team communication. It carries three limits: the threat must be serious and imminent, so a history of violence alone does not qualify; the recipient must be able to act on it; and the disclosure must be consistent with applicable law, which pulls in state duty-to-warn rules.

It also carries a protection almost nobody mentions. A covered entity acting under §164.512(j) is presumed to have acted in good faith if the belief rests on actual knowledge or on a credible representation by someone with apparent knowledge or authority. That presumption is what a charge nurse making a fast decision at two in the morning is entitled to rely on.

Two limits to carry into policy. §164.512(j)(2) restricts using information learned during treatment intended to affect criminal propensity, though only for the law enforcement identification pathway rather than generally. And stricter regimes override: 42 CFR Part 2 for substance use disorder records, plus state mental health confidentiality law.

Flagging patients: no law exists, and that is the finding

Many organizations flag patients with a history of violence in the record. Someone always asks whether that is lawful.

There is no federal statute or regulation squarely on point, and I could locate no CMS, OCR, or Joint Commission guidance either. The absence is itself worth knowing, because it means the constraints are indirect and easy to miss:

  • EMTALA. A flag may never gate medical screening or stabilization. If a flag changes whether or how fast someone is seen, that is a problem independent of the flag.

  • Disability and civil rights law. The published work on behavioral flags points toward disproportionate application to patients with psychiatric and substance use diagnoses, and reports differences by race and payer, with downstream effects on care. If that pattern holds in your own data, that is where discrimination exposure lives, under the ADA, Section 504, and Section 1557. The practical implication is to audit your own flags for disparity rather than to assume the published pattern does or does not describe you.

  • In the absence of regulation, the published literature is the nearest thing to a standard. Work on flag criteria, review cycles, removal processes, and disparity auditing is what an expert witness would likely reach for.

So the practical answer is that flagging is not prohibited, and an unstructured flagging practice with no defined criteria, no expiration, no removal pathway, and no equity audit is a real exposure sitting inside a compliance vacuum.

Building the relationship before you need it 

The most effective single thing an organization can do to see violence against its staff actually prosecuted is to build the relationship with local law enforcement and the district attorney before an incident, not after.

Two counties in the same state can produce completely different outcomes on identical facts, because the local relationship between law enforcement, the prosecutor's office, and the healthcare community differs entirely from one jurisdiction to the next. That gap closes through relationships, not through better policy language.

An introduction meeting, held separately with law enforcement and with the prosecutor's office, should cover three things. What documentation standard the office actually needs to bring a charge that holds. Most organizations have never asked this directly. Whether a memorandum of understanding or an informal operational protocol makes sense locally. And named escalation contacts on both sides.

professional-meeting-room-conversation-pillar-page-3

The introduction is worth more than the policy language, and it has to happen first. 

None of this requires an incident to justify. It requires deciding in advance that the relationship is part of the program, because a compliance program with no path to prosecution is a program that only ever defends itself.

Before or After

The same conversation with law enforcement, held at two different moments

Before-or-after-PP3

 The questions are identical. Only one version of this conversation can still change the outcome.  

Where compliance stops 

Regulators can require that training happened. They cannot require that it worked.

That is not a criticism of the regulators. It is a description of what a rule can do. A surveyor can verify a curriculum, a completion record, and a date. Nobody has designed a survey that can verify whether a nurse in her eleventh hour actually does something different when a family member starts shouting.

But there is a third thing between those two, and it is the one worth measuring. Not whether the training happened, which a surveyor already checks. Not whether it worked, which nobody can check. Whether the organization created the conditions for it to be used.

That one is answerable, and answerable from documents you already hold. Did the worksite analysis produce actions with owners and dates. Did anything change because an incident was reported. Did anyone practice, or only attend. Those are audit questions, not culture questions, and an organization that cannot answer them has found the real gap in its program without needing a surveyor to point at it.

Which means every requirement in this article is a floor, and the floor is real and worth meeting. What sits on top of it is a separate decision that no regulator will make for you, and the two get confused constantly because they use the same documents.

If you want the operational half, it is the skills your staff need. If you want the financial half, it is what the problem is actually costing you. This article is only the part that says you have to.

The part compliance cannot do for you

An article can tell you which four regulators reach you, what each one requires, which citation to look it up under, and what the file does when someone reads it later. Most compliance officers do not have all of it in one place.

What an article cannot do is close the gap between the analysis and the meeting. It cannot get four departments to agree on who owns the worksite analysis. It cannot sit across from a prosecutor who has never met anyone from your organization. And it cannot make anyone act on the finding in a document that has already been written, filed, and forgotten, which is the failure mode every case in this article turns on.

Those are not research problems. They are the same organizational problem underneath all of it: the requirement produces a document, and a document is not an action.

The bottom line

Compliance is not the enemy of a real workplace violence program. It is the floor one gets built on, and the floor is now specific enough to be worth meeting precisely: three Elements of Performance, two Conditions of Participation, one General Duty Clause, and whatever your state requires.

But notice what all four regulators have in common. Every one of them makes you write down what you know. The worksite analysis, the risk assessment, the injury log, the incident record. That file is how you demonstrate compliance, and it is the first thing anyone reads afterward.

Which means the question that decides your exposure is not whether the documents exist. It is whether anything happened because of them.

If your last worksite analysis identified a risk that is still there, you do not have a documentation problem. You have a dated record of a hazard you knew about, which is the precise thing the two leading cases in this area turned on.

The fix is not a bigger binder. It is a short, honest look at your last analysis and an answer to one question: what changed because of it?

 

Frequently Asked Questions

What does the Joint Commission require for workplace violence prevention?

 NPG.02.04.01, effective January 2026, has three Elements of Performance. EP 1 requires a prevention program led by a designated individual and developed by a multidisciplinary team, with policies and procedures, an incident reporting and trend analysis process, follow-up and support for victims and witnesses, and reporting to the governing body. EP 2 requires role-appropriate training at hire, annually, and whenever the program changes, covering what constitutes workplace violence, the roles of leaders, clinical staff, security, and law enforcement, de-escalation and nonphysical and physical intervention, and the reporting process. EP 3 requires an annual worksite analysis and action on its findings. The requirement applies to accredited hospitals and critical access hospitals. 

Is it called National Performance Goal 2a?

 That is the label on the Joint Commission's website, but it does not appear in the standards manual and it is not citable. The standard is NPG.02.04.01, under Goal 2, which is the culture-of-safety goal generally rather than a workplace violence goal. 

Does OSHA have a workplace violence standard for healthcare?

No. The proposed rule, RIN 1218-AD08, was moved to Long-Term Actions in September 2025 and remains there. Enforcement runs through the General Duty Clause, OSH Act §5(a)(1). OSHA's guidance document, publication 3148-06R (2016), is voluntary and enforceable only as evidence that a hazard was recognized and that abatement was feasible. There is no National Emphasis Program for healthcare workplace violence. 

Does passing a Joint Commission survey protect us from an OSHA citation?

 In February 2026 the Tenth Circuit affirmed a General Duty Clause citation against a psychiatric hospital and rejected the argument that CMS and accreditation compliance preempt OSHA. The same decision treated the hospital's own post-citation fixes as evidence that abatement had been feasible beforehand. 

What is the 2026 OSHA penalty for a workplace violence citation?

  $165,514 per violation for willful or repeated, and $16,550 for serious, other-than-serious, and posting. These are the 2025 amounts carried forward, because OMB cancelled the 2026 inflation adjustments government-wide after a shutdown prevented the Bureau of Labor Statistics from producing the required index. Describe the exposure as over $150,000 per violation, adjusted annually, and you will not have to correct it next year. 

How many states require a workplace violence prevention plan in healthcare?

Nineteen require a written plan: California, Connecticut, Illinois, Kentucky, Louisiana, Maine, Minnesota, Nevada, New Hampshire, New Jersey, New York, North Carolina, Ohio, Oregon, Rhode Island, Texas, Vermont, Virginia, and Washington. Utah and Oklahoma require incident reporting without a plan. That is a much shorter list than the states that criminalize assault on a healthcare worker, which create no employer obligation at all. Massachusetts has a mandate in conference committee, and Colorado ties a hospital quality incentive payment to having a policy. 

How many states criminalize assault on a healthcare worker?

 Every published count differs, and the reason is definitional rather than factual. A peer-reviewed legal scan found 45 states with laws penalizing perpetrators of violence against healthcare workers as of June 2024. The American Nurses Association lists 38, last updated in 2021. The Emergency Nurses Association says 31 for felony-level assault on emergency nurses. A figure of 49 circulates widely and traces to no source. None of these creates an obligation for your organization. 

Can an assaulted employee sue our hospital?

In most states, generally not. Workers' compensation is the exclusive remedy for injuries arising out of and in the course of employment, and recasting the claim as negligent security or negligent supervision does not avoid the bar. The narrow exceptions involve an employer that itself committed or ratified the assault, employers that do not subscribe to workers' compensation in states where that is permitted, and assaults arising from purely personal disputes. The hospital's real tort exposure runs to patients, visitors, contractors, agency and travel staff, and employees' family members, none of whom are covered by the bar. 

Is foreseeability presumed in healthcare workplace violence cases?

 No. That claim circulates widely and no jurisdiction applies it. Foreseeability is an element the plaintiff must prove, and courts apply one of four tests. California, whose leading case involved a hospital parking lot shooting, has narrowed the standard against plaintiffs twice since 1985 and now requires a high degree of foreseeability, ordinarily prior similar incidents, before a duty to provide security guards attaches. What is true is that hospitals generate the evidence of notice themselves, through the risk assessments and incident logs that four different regulators require. 

Does HIPAA prevent us from telling staff that a patient has a history of violence?

 No. Sharing that with the clinical team treating the patient is a treatment disclosure under 45 CFR §164.502(a)(1)(ii) and §164.506(c). No authorization is required, and the minimum necessary standard does not apply because §164.502(b)(2)(i) exempts disclosures to a provider for treatment. A different provision, §164.512(j), governs disclosure outside treatment to avert a serious and imminent threat, which is the authority for telling security or law enforcement. Substance use disorder records under 42 CFR Part 2 and state mental health confidentiality laws are stricter and control where they apply. 

What is immediate jeopardy, and does it require a corrective action plan within 24 hours?

  Immediate jeopardy is a CMS determination that a recipient of care has suffered or is likely to suffer serious injury, harm, impairment, or death because of noncompliance. It has three components: noncompliance, the likelihood of serious harm, and the need for immediate action. Culpability is not one of them; CMS removed it in 2019. There is no 24-hour corrective action deadline. The surveyor notifies the administrator immediately and the entity submits a removal plan as soon as it has identified its steps. The Joint Commission's parallel finding is an Immediate Threat to Health or Safety under APR.09.04.01, which is a different system with a different process. 

Will the federal workplace violence bills pass?

Nothing has moved. Four bills are pending in the 119th Congress and all four remain at their 2025 committee referrals with no hearing, markup, or floor action as of August 2026. Cosponsors continue to accumulate, which is accretion rather than progress. Meanwhile OSHA has parked the rulemaking those bills would compel. Build toward the requirements that are already binding. 

Sources

Joint Commission

  • The Joint Commission, National Performance Goals Effective January 2026 for the Hospital Program, NPG.02.04.01, EPs 1–3. Companion document for the Critical Access Hospital program.
  • R3 Report Issue 30, "Workplace Violence Prevention Standards," June 18, 2021, effective January 1, 2022.
  • R3 Report Issue 42 (behavioral health care, effective July 1, 2024) and Issue 45 (home care, effective January 1, 2025).
  • Sentinel Event Alert Issue 59, April 17, 2018, revised June 18, 2021.
  • Accreditation Participation Requirement APR.09.04.01; Comprehensive Accreditation Manual for Hospitals, Sentinel Event chapter, July 2026.

CMS

  • QSO-23-04-Hospitals, "Workplace Violence-Hospitals," November 28, 2022.
  • QSO-25-09-ALL, "REVISED: Revisions to Appendix Q, Guidance on Immediate Jeopardy," November 21, 2024, revising QSO-19-09-ALL (March 5, 2019).
  • 42 CFR §482.13(c)(2); 42 CFR §482.15(a)(1), (d)(1); 42 CFR Part 488, Subpart A, especially §§488.5(a)(4)(ix), 488.7, 488.8, 488.9.

OSHA

  • OSH Act §5(a)(1), 29 U.S.C. §654(a)(1).
  • CPL 02-01-058, "Enforcement Procedures and Scheduling for Occupational Exposure to Workplace Violence," January 10, 2017.
  • OSHA 3148-06R (2016), Guidelines for Preventing Workplace Violence for Healthcare and Social Service Workers.
  • RIN 1218-AD08, Long-Term Actions, 90 Fed. Reg. 45536 (September 22, 2025); Unified Agenda released July 3, 2026.
  • OSHA memorandum, "2026 Annual Adjustments to OSHA Civil Penalties," May 21, 2026; Department of Labor, 91 Fed. Reg. 31358 (May 27, 2026); OMB Memorandum M-26-11, April 17, 2026.

Federal legislation, 119th Congress

  • Save Healthcare Workers Act, H.R.3178 (Rep. Madeleine Dean) and S.1600 (Sen. Cindy Hyde-Smith), both introduced May 5, 2025.
  • Workplace Violence Prevention for Health Care and Social Service Workers Act, H.R.2531 (Rep. Joe Courtney) and S.1232 (Sen. Tammy Baldwin, April 1, 2025, referred to HELP).

Case law

  • Cedar Springs Hospital, Inc. v. OSHRC, No. 24-9519 (10th Cir. Feb. 13, 2026).
  • Small v. McKennan Hospital, 437 N.W.2d 194 (S.D. 1989).
  • Texas West Oaks Hospital, LP v. Williams, 371 S.W.3d 171 (Tex. 2012).
  • Meerbrey v. Marshall Field & Co., 139 Ill. 2d 455 (1990).
  • Posecai v. Wal-Mart Stores, Inc., 752 So. 2d 762 (La. 1999); Isaacs v. Huntington Memorial Hospital, 38 Cal. 3d 112 (1985); Ann M. v. Pacific Plaza Shopping Center, 6 Cal. 4th 666 (1993); Sharon P. v. Arman, Ltd., 21 Cal. 4th 1181 (1999); Delgado v. Trax Bar & Grill, 36 Cal. 4th 224 (2005).

HIPAA

  • 45 CFR §164.502(a)(1)(ii), §164.502(b)(2)(i), §164.506(c), §164.512(j) including (j)(2) and (j)(4), §164.514(d); 42 CFR Part 2.

State law

  • Statutes as cited in the state table. Comparative count from Lombardi, Tapen and Fraher, "State laws that address workplace violence in health care settings," Health Affairs Scholar, February 2026, scan current to June 2024.

 

Related Content from Vistelar

Legal Disclaimer

 This article is general information about regulatory requirements, current as of publication, and is not legal advice. Requirements change, several items discussed here (including proposed rules and pending legislation) are not yet final, and application varies by state and organization. Confirm anything you plan to rely on with your own legal counsel before acting on it. 

Ready for a Better Approach? 

Healthcare systems across the country are rethinking how they approach workplace violence prevention training.

If you're exploring options for improving safety and training consistency across your organization, Vistelar can help.