Just as other healthcare challenges have evolved in the past two decades, so too have those related to security.
“The big thing when you’re considering how healthcare security has changed is that it’s moved beyond traditional access control and asset protection — just responding to calls for service or an incident,” Christopher Carr, director 1–security services at Texas Children’s Hospital in Houston, said on the Becker’s “Pediatric Leadership Podcast.” “Now, regardless of your organization, you face more complex risks.”
He joined the health system in 2013, adding that he has been impressed with Texas Children’s history of being able to “adapt and pivot — before those were even buzzwords.”
In addition to three building blocks of health system security — investing in people, seeking partnerships, and leveling up technology and data — Mr. Carr outlined three areas that require heightened consideration:
1. Behavioral health. From 2018 to 2020, the average rate of mental health-related emergency department visits among children was 14 per 100,000, according to CDC data.
“It’s basically in crisis at this point because there were no resources for it previously,” Mr. Carr said. “You didn’t even really hear of it much prior to 2010 or 2011, and now it’s kind of its own entity. We’ve seen it grow exponentially over the years — just the number of kids who need our services.
“[The behavioral component] is where we really ramp up the empathy and sympathy. We make sure the kids have everything they need, the families, the caregivers, our own staff. We have a great EAP mental health department here that takes care of our staff and makes sure we have everything we need to do the job.”
2. Cybersecurity. The pace of healthcare data breaches nationwide is increasing. According to the nonprofit Identity Theft Resource Center, the number of attacks on organizations in the industry climbed to 281 in the first half of 2026, up from 270 during the same period last year.
Texas Children’s uses a “proactive, prevention-focused approach” to tackle these challenges, Mr. Carr said.
“The organization we partner with for [Information Security] experiences disruptions from time to time, and that ripples into everything we do,” he said. “And safety expectations overall have increased not only from patients, but from caregivers and their families.”
3. Staff protection. “In the time I’ve been [at Texas Children’s], they already had a robust workplace violence program and were ahead of the regulatory requirements,” Mr. Carr said.
“We recently started a sub-department around employee protection. If we think there are domestic issues or other situations where an employee needs our help, we can do everything from changing a parking assignment to getting someone an escort to the garage. It’s taken on a life of its own, and that has primarily been the shift in our response.”
In terms of how to accomplish security goals, that is simple on a grand level, Mr. Carr said.
“It comes back to this: Our officers have to balance a welcoming environment with a high level of safety and professionalism,” he said. “That transfers to any healthcare setting if you set the right priorities. In today’s environment, you’re looking at workplace violence, emergency preparedness, access control and staff safety. Know what your threat management plan looks like, and partner with the right people for critical infrastructure protection.”