The Workplace Violence Prevention Plan Mandate: A 2026 Compliance Briefing on California SB 553, Emerging State Laws, and the Federal Standard Taking Shape
Home / Intelligence / The Workplace Violence Prevention Plan Mandate:...
Standards & Compliance

The Workplace Violence Prevention Plan Mandate: A 2026 Compliance Briefing on California SB 553, Emerging State Laws, and the Federal Standard Taking Shape

How California SB 553, 19+ state healthcare mandates, and OSHA active rulemaking are reshaping WVPP compliance obligations for security directors and risk managers in 2026

Published 2026-05-15
Read Time 18 min read
Stream Standards & Compliance
470
Workplace homicides in 2024 (BLS CFOI)
19+
States with active WPV prevention statutes
July 1, 2024
California SB 553 effective date

Workplace Violence Prevention Plans Are Now Law: What Every Employer Needs to Know About California SB 553, State Mandates, and the Coming Federal Standard

470 Workplace homicides recorded in 2024, up from 458 the prior year (BLS Census of Fatal Occupational Injuries, February 2026)
19+ States with enacted healthcare-specific workplace violence prevention statutes as of 2026, with general-industry mandates now spreading beyond healthcare
July 1, 2024 Effective date of California SB 553, the first general-industry WVPP mandate covering nearly all California employers regardless of sector

The compliance posture for workplace violence prevention changed permanently in 2024. California's Senate Bill 553, signed into law on September 30, 2023, and effective July 1, 2024, imposed a written workplace violence prevention plan requirement on virtually every California employer, becoming the first state to extend this mandate beyond healthcare workers to the general workforce. It was not the last. Across the country, state legislatures are advancing similar requirements, and at the federal level the Occupational Safety and Health Administration is completing the rulemaking process on a national standard that would cover healthcare and social assistance workers in every state.

For security directors, risk managers, and operations leaders, the practical implication is straightforward: a written workplace violence prevention program is no longer a best practice. It is increasingly a legal obligation. And the question that follows, what technology supports a defensible WVPP, is one that AI-powered computer vision is increasingly positioned to answer. This briefing covers the regulatory landscape, what the mandates actually require, where they converge, and how detection technology fits into the compliance architecture.

Real IntelliSee gun detection screenshot from a hospital nurse station security camera showing weapon identification with bounding box and confidence score overlay
LIVE CAM-07 · NURSE STATION
Actual IntelliSee detection output from a hospital nurse station camera. A drawn firearm identified in a healthcare security feed with visible bounding box and confidence score. Under California SB 553 and its emerging counterparts, employers must document the technology and procedures used to identify and respond to workplace violence hazards. Real-time detection with an auditable alert log is precisely the kind of documented preventive control regulators are looking for.

California SB 553: What the general-industry WVPP mandate actually requires

California Labor Code section 6401.9, enacted by SB 553, became effective July 1, 2024 for most employers and November 1, 2024 for employers in industries already covered by Cal/OSHA's existing healthcare-specific workplace violence prevention standard. It applies to virtually all employers in California with at least one employee, a scope far broader than previous state mandates, which had been limited to hospitals, skilled nursing facilities, or healthcare settings.

The law requires every covered employer to establish, implement, and maintain a written Workplace Violence Prevention Plan. That plan must contain, at minimum:

Identification of the person or persons responsible for the WVPP. The employer must designate someone accountable for the plan's implementation and operation. This cannot be an informal designation. It must be documented in the written plan.

Procedures for involving employees in developing, implementing, and reviewing the WVPP. The law specifically requires a mechanism for employee participation, not just employer promulgation. For multi-shift operations or facilities with unionized staff, this means a structured process that can be audited.

Methods to coordinate implementation of the WVPP with other employers when employees of different employers share a workplace. Multi-tenant office buildings, shared industrial facilities, and contractor-heavy environments must address coordination explicitly. This is a provision most general-industry employers had not previously encountered in occupational safety compliance.

Procedures for the employer to accept and respond to reports of workplace violence. Employees must have a way to report incidents and near-misses. The employer must have a documented response procedure. Retaliation against employees who report is explicitly prohibited and carries enforcement teeth.

Procedures to ensure that supervisors and employees comply with the WVPP. Compliance accountability must be internal. The plan cannot simply exist on paper; it must include how the employer will enforce adherence.

Procedures to communicate with employees regarding workplace violence matters. This encompasses how the employer notifies employees of incidents, near-misses, and changes to the WVPP. Communication records become part of the compliance documentation trail.

Procedures for conducting workplace violence hazard assessments. The employer must document how it identifies and evaluates workplace violence risks. This is the provision that most directly creates a role for detection technology: a system that logs threat detections and alerts creates an auditable record of the hazard identification process.

Procedures for investigating workplace violence incidents. Every incident must be investigated, not just reported. The investigation must identify root causes and corrective actions. An employer whose camera network detected a prior threat event but failed to respond to it is in a materially worse legal position than one whose detection system triggered a documented response.

Procedures for correcting workplace violence hazards in a timely manner. Identified hazards, whether from a formal assessment or a reported near-miss, must be corrected with documented timelines and responsible parties.

Procedures for post-incident response and investigation. Following a violent event, the employer must have a defined process for immediate response, preservation of evidence, and employee support.

Procedures for emergency response to workplace violence incidents. The plan must address what happens during an active incident, not just before and after. This is the element most directly addressed by real-time AI detection systems that trigger emergency alerts within seconds of a threat being identified.

An employee training program on WVPP procedures. Training must be provided to all employees and supervisors before they start work and annually thereafter. Training records must be maintained for one year.

A violent incident log. Every workplace violence incident must be recorded, including the date, time, location, type of violence, description of the incident, circumstances, and any corrective actions taken. Records must be maintained for five years. Cal/OSHA can request these logs at any time.

Enforcement Reality

Cal/OSHA began WVPP enforcement on July 1, 2024, and the citation risk is not theoretical

Cal/OSHA's enforcement posture on SB 553 is active, not advisory. The Division of Occupational Safety and Health began accepting complaints and conducting inspections related to WVPP compliance as of the statute's effective date. Penalties for a general violation under California Labor Code run to $15,625 per violation; repeat or willful violations carry penalties up to $156,259 per violation. For a multi-location employer with no written WVPP, a single inspection covering five facilities could generate citations well into the seven-figure range. The absence of a violent incident log, even with zero incidents to report, is itself a citable violation.

The state mandate landscape beyond California: where WVPP laws exist and where they are advancing

California's general-industry mandate is the broadest in scope, but it did not emerge from a vacuum. Healthcare-specific workplace violence prevention laws have been accumulating in state codes for more than a decade, and the passage of SB 553 has accelerated legislative interest in extending those frameworks to the general workforce. Understanding where mandates exist and where they are advancing is essential for multi-state employers building a WVPP program architecture.

Regulatory Landscape

WVPP Mandate Status Across Three Tiers: Enacted, Advancing, and Federal

As of May 2026. Healthcare-specific laws precede general-industry mandates in most states. California stands alone with a true general-industry WVPP law.

Enacted & Active

States with Active WVPP Mandates

  • California (SB 553) General industry, all employers, effective July 1, 2024. Most expansive in scope.
  • California (SB 1299) Healthcare-specific standard (hospitals, SNFs, home health) predating SB 553 and still active.
  • New York NY Labor Law §27-b requires WPV prevention programs for all public employers and most private employers with 10+ employees.
  • Illinois Healthcare WPV prevention requirements under 820 ILCS 275 covering hospitals, long-term care, and emergency medical services.
  • Oregon ORS 654.412 healthcare workplace violence prevention law with written plan and reporting requirements.
  • Washington WAC 296-817 WPV rule covering healthcare and social service sectors.
  • Virginia HB 2269/SB 1260 hospital security plan requirements, effective 2025.
Advancing in 2025–2026

Active Legislation in the Pipeline

  • Missouri HB 3401 Passed House Rules-Legislative Committee, April 2026. Requires WPV prevention committees, written plans, and incident investigation at all Missouri hospitals.
  • Massachusetts H.4767 Healthcare WPV prevention legislation requiring written plans, annual risk assessments, and incident reporting across hospital systems.
  • Vermont H.259 / Act 9 Enacted provisions requiring hospital WPV prevention plans with specific technology and training components.
  • Pennsylvania HB 1087 Active healthcare WPV prevention bill extending requirements to behavioral health settings.
  • Texas SB 240 Hospital-sector WPV prevention plan requirement advancing in the 89th Legislature.
  • Florida HB 1455 Hospital and emergency services WPV prevention requirements under active consideration.
Federal

The Federal Standard Taking Shape

  • H.R. 2531 (119th Congress) Workplace Violence Prevention for Health Care and Social Service Workers Act. Directs OSHA to issue a final WPV prevention standard within 42 months of enactment.
  • OSHA RIN 1218-AD08 OSHA's active rulemaking docket for the healthcare/social assistance WPV standard. SBREFA panel completed. Proposed rule expected in late 2025 or 2026.
  • OSHA General Duty Clause 29 U.S.C. §654(a)(1). OSHA continues to cite healthcare employers for WPV hazards under the GDC even before the sector-specific standard is finalized.

The pattern across these mandates is not accidental. State legislatures are responding to the same pressure: workplace violence rates that have not improved despite decades of policy attention, a healthcare workforce under severe retention pressure, and unions representing nurses, social workers, and emergency responders that have made WVPP legislation a priority bargaining and legislative objective.

What the mandates require technically: the hazard identification and detection gap

Across every enacted and advancing WVPP mandate, a common technical requirement emerges: the employer must conduct and document a hazard assessment, implement preventive controls, and maintain a record of incidents and near-misses that allows iterative improvement.

This is where the gap between traditional physical security and AI-augmented detection becomes a compliance question, not just an operational one.

Traditional surveillance infrastructure — cameras, access control, manned guard stations — provides coverage and reactive documentation. What it does not provide is a systematic, auditable record of detected threat precursors: a person loitering at an entrance for 12 minutes before an incident, a weapon brought onto premises 4 minutes before an assault, an unauthorized access breach that preceded a patient elopement. Traditional systems record these events only if someone happens to be watching at the precise moment. The vast majority of surveillance footage captures threat precursors that are not acted on in real time and are reviewed only forensically, after harm has occurred.

The WVPP mandates ask employers to demonstrate that they have a systematic approach to identifying hazards, not a reactive hope that someone was watching. AI detection technology directly addresses this gap: it creates a structured, timestamped, auditable log of every threat event it detects, including drawn firearms, loitering beyond threshold, unauthorized zone access, and crowd formation, regardless of whether any human was watching the camera feed at that moment.

The Audit Trail Requirement

Why a violent incident log is not enough, and what regulators are actually looking for

California's SB 553 and OSHA's draft healthcare standard both require a violent incident log. But the hazard assessment requirement goes further: it requires documented evidence that the employer actively looked for hazards, not just that it recorded the ones that resulted in incidents. An employer that can show a 90-day alert log from an AI detection system, including threat detections that triggered responses, near-miss events that led to corrective action, and trend data by location and time of day, is demonstrating an active hazard identification program. An employer that only has incident reports is demonstrating that it waited for incidents to happen. That distinction is material in both OSHA enforcement and civil litigation.

The federal standard taking shape: OSHA RIN 1218-AD08 and H.R. 2531

At the federal level, two parallel processes are converging on what will eventually become a national WVPP requirement for healthcare and social service workers.

H.R. 2531: The Workplace Violence Prevention for Health Care and Social Service Workers Act has been introduced in multiple Congresses and has re-entered the legislative calendar in the 119th Congress. The bill directs OSHA to issue a final workplace violence prevention standard for healthcare and social service workers within 42 months of enactment. It also establishes interim protections during the rulemaking period, requires covered employers to develop and implement a workplace violence prevention plan, and creates anti-retaliation protections for workers who report incidents or participate in WVPP implementation.

The bill defines "workplace violence" broadly: physical assault, threat of physical assault, verbal abuse, harassment, intimidation, and other disruptive behavior that occurs at the workplace and poses a risk to employees. This definition is wider than what many employers' current security policies contemplate. It explicitly includes non-patient sources of violence, visitors, contractors, domestic partners who appear at a worksite, not only the patient-on-staff incidents that dominate healthcare WPV research.

OSHA's regulatory docket (RIN 1218-AD08) is running parallel to the legislative process. OSHA completed its Small Business Regulatory Enforcement Fairness Act (SBREFA) panel process in 2023, gathering input from small healthcare and social assistance employers on the anticipated costs and requirements of a proposed standard. The SBREFA panel report confirmed that OSHA intends to require covered employers to:

  • Develop and implement a written workplace violence prevention plan tailored to the specific hazards at their facility
  • Conduct regular worksite analyses to identify potential workplace violence hazards
  • Implement engineering controls, administrative controls, and work practice controls to prevent or mitigate identified hazards
  • Provide training to all workers and supervisors on WPV prevention
  • Maintain a violent incident log and incident reporting system
  • Conduct annual reviews of the WVPP and update it as needed
  • Involve workers in the development, implementation, and review of the WVPP

The proposed rule is expected to apply to hospitals, residential treatment facilities, non-residential treatment facilities, home health care, social assistance services, and outpatient mental health facilities. Employers already subject to state WVPP laws would remain subject to those laws. OSHA's standard establishes a federal floor, not a ceiling.

The practical implication for employers preparing now: the architecture of a WVPP built to satisfy California SB 553, documented hazard assessment, engineering controls, incident log, annual review, is substantially the same architecture that will be required under the federal standard when it is finalized. Getting into compliance with California's law is not California-specific compliance work; it is essentially pre-positioning for the federal standard.

What a defensible WVPP looks like: the five components that hold up under inspection

Across the enacted and advancing mandates, enforcement agencies and plaintiff's attorneys have developed a consistent picture of what a WVPP that holds up under scrutiny looks like. It is not simply a document on a shared drive. The following components distinguish a defensible program from a paper compliance exercise.

A Written Plan With Named Accountability

The WVPP must be a live document with designated owners, not a PDF that last changed in 2021. California SB 553 specifically requires the plan to identify who is responsible for its implementation. OSHA's draft standard makes the same requirement. In enforcement actions, the first question is who owns this program. If the answer is unclear, the citation follows automatically.

A Documented Hazard Assessment Process

The assessment cannot be a one-time site walkthrough. It must be a repeatable process, conducted on a defined schedule, documented, and linked to the controls implemented in response. AI threat detection systems that generate timestamped alert logs contribute directly to this evidence base: they demonstrate that the employer is actively and continuously assessing the threat landscape, not relying on annual walkthrough reports alone.

Engineering and Administrative Controls, Documented

Controls are the core of the regulatory requirement. Engineering controls, physical barriers, access control, detection systems, must be documented alongside the hazards they address. Administrative controls, staffing policies, visitor protocols, de-escalation training, must be recorded and auditable. The controls must be proportionate to the assessed hazards. An employer that assessed a high loitering risk at a parking structure but installed no detection capability in response will have a difficult time explaining that gap in enforcement or litigation.

A Maintained Violent Incident Log

Both California's mandate and OSHA's draft standard require a violent incident log maintained for a minimum of five years and accessible to inspectors on request. The log must capture the date, time, location, type of violence, description of circumstances, and corrective actions taken. AI detection systems that generate structured alert records can feed this log automatically, eliminating the under-reporting problem that plagues manually maintained incident logs.

Documented Employee Training and Annual Review

Training records, who was trained, when, on what content, must be maintained for one year under California's SB 553. The WVPP itself must be reviewed annually and following any serious workplace violence incident. An employer that cannot demonstrate completed training for all employees in the current calendar year has a citable deficiency regardless of the quality of its written plan.

Zero Tolerance for Under-Reporting

Every enacted and proposed standard explicitly prohibits discouraging employee reporting of incidents or near-misses. An employer culture that pressures staff not to report minor incidents creates a compounding violation risk: the under-reported incidents are themselves a deficiency, and the suppression of reporting is an independent violation. Building reporting channels that are low-friction and anonymous where permitted is a prerequisite for a defensible program.

Where AI detection technology fits into the WVPP compliance architecture

Computer vision-based threat detection is not a WVPP in itself. It is an engineering control — one of the three control categories (engineering, administrative, work practice) that every enacted and proposed WVPP standard requires employers to implement in response to documented hazards. Understanding this framing matters: it means that deploying AI detection without the written plan, the hazard assessment, the incident log, and the training is still a compliance gap. And it means that a WVPP without engineering controls proportionate to the assessed hazards is also a gap. Both must exist.

Within the engineering control layer, AI-powered weapon detection, loitering detection, unauthorized access detection, and crowd formation detection address four of the most commonly cited precursor-event categories in workplace violence research:

How AI Detection Modalities Map to WVPP Engineering Control Requirements

Detection TypeHazard AddressedWVPP Evidence GeneratedRelevant Mandate Language
Drawn Weapon DetectionType I violence (criminal intent), Type II (patient/visitor), Type III (co-worker)Timestamped alert log; detection confidence; camera location; response triggeredCal. SB 553 §6401.9(c)(5); OSHA draft standard hazard assessment requirement
Loitering DetectionPre-incident dwelling near entrances, parking structures, isolated corridorsDuration log; location-specific pattern record; repeat-event trend dataNY Labor Law §27-b worksite analysis; OSHA GDC enforcement criteria
Unauthorized AccessRestricted zone breach; patient elopement; contractor/visitor intrusionZone violation log; time-of-day pattern; access control integration recordOR ORS 654.412 engineering control requirement; WA WAC 296-817
Crowd FormationWaiting room escalation; group confrontation in public areasAlert log; threshold configuration record; response escalation documentationCal. SB 553 §6401.9(c)(5)(A); OSHA draft §1910.35(c) hazard control

Beyond the detection function, there is a documentation function that is equally important in the compliance context. Every AI detection alert generates a structured, timestamped record that can be exported and maintained as part of the employer's incident and near-miss log. This creates evidence of a continuous, active hazard identification program — not a periodic exercise. In Cal/OSHA inspections, OSHA General Duty Clause investigations, and civil litigation following a violent incident, the difference between an employer with an active detection log and one without is the difference between documented diligence and documented inaction.

IntelliSee's platform architecture is also specifically suited to WVPP compliance needs because of what it does not do. It does not perform facial recognition. It does not store video off-premises. It does not collect protected health information. For employers in healthcare settings where HIPAA, state behavioral health privacy statutes, and institutional privacy policies overlap, these architectural constraints are prerequisites for deployment approval, not optional features. See the Healthcare Workplace Violence Playbook for a detailed treatment of privacy architecture in clinical environments.

Multi-state employers: building a WVPP that satisfies multiple mandates simultaneously

For employers operating across multiple states, the compliance landscape in 2026 is genuinely complex. California's SB 553 applies to California employees regardless of where the employer is headquartered. New York's mandate applies to New York worksites. Oregon's applies to Oregon operations. The federal standard, when finalized, will apply to covered healthcare and social service employers in all fifty states. An employer with operations in California, New York, Oregon, and Texas faces four overlapping regulatory regimes simultaneously and must satisfy the most stringent applicable requirement in each jurisdiction.

The architecture that handles this most cleanly is a tiered WVPP:

A master written plan that satisfies the universal requirements shared across all mandates, written program, named accountability, hazard assessment process, incident log, training, annual review. This document is the foundation that satisfies the federal baseline and all state requirements simultaneously.

Facility-specific annexes that address the location-specific hazards identified in the hazard assessment and any jurisdiction-specific requirements not captured in the master plan. A California facility annex would include the violent incident log format required by SB 553 and the employee participation mechanism. A New York facility annex would address the NY-specific reporting obligations.

A shared technology and documentation infrastructure, a detection system, incident log, and training record management system, that generates the evidence base applicable across all jurisdictions. This is where the investment in AI detection pays its multi-jurisdictional dividend: a single platform that generates compliant detection logs, alert records, and response documentation that can be cited in response to any state or federal inspection.

Multi-Jurisdiction Strategy

The DHS SAFETY Act designation as a multi-state compliance asset

IntelliSee holds DHS SAFETY Act Full Designation as a Qualified Anti-Terrorism Technology, the same certification tier as the other major firearm detection platforms in the market. For multi-state employers evaluating WVPP technology vendors, SAFETY Act designation is not merely a procurement checkbox. It provides liability protection under federal law if a terrorism event occurs while the designated technology is deployed and operating as designed. For a risk manager building the legal architecture around a multi-state WVPP, the SAFETY Act designation is a documented element of the employer's reasonable precaution defense.

What the BLS data says about the scale of the problem these mandates are designed to address

The regulatory response makes more sense in context of what the underlying data shows. The Bureau of Labor Statistics Census of Fatal Occupational Injuries, released in February 2026, documented 470 workplace homicides in 2024, up from 458 in 2023. Firearms accounted for 379 of those fatalities, or approximately 81 percent. These are not clustering in a single sector: they span retail, healthcare, transportation, hospitality, and service industries. The geography is national. The time-of-day distribution shows elevated risk during shift changes, early morning hours, and late evening, which aligns with the access-control and loitering-detection use cases that AI systems address most directly.

The nonfatal data from BLS's Injuries, Illnesses, and Fatalities program is arguably more alarming. For 2021-2022, the BLS documented 57,610 cases of workplace violence resulting in days away from work, restricted work, or job transfer (DART cases) in the private sector alone. Healthcare and social assistance accounted for 72.8 percent of all private industry workplace violence DART cases, a disproportionation that explains why healthcare has been the first sector targeted by every state legislature and by OSHA's proposed federal standard.

The violence-to-near-miss ratio is estimated at roughly 1:600 in occupational safety research generally. Applied to the 57,610 DART cases, that ratio implies more than 34 million workplace violence near-miss events per year in the private sector that are neither recorded nor reported. The WVPP mandates' incident log and near-miss reporting requirements are specifically designed to surface this dark figure — and AI detection systems that capture threat precursors automatically provide the only scalable mechanism for doing so.

Getting into compliance with SB 553 and preparing for what follows

For employers who have not yet built a WVPP, the compliance path is sequential. The steps are not optional, and skipping to the technology layer without completing the foundational documentation steps produces a program that will not hold up under inspection.

Step 1: Conduct a written hazard assessment. Walk every facility with the goal of identifying workplace violence risk factors: isolated work areas, cash-handling points, public-facing service environments, high-patient-acuity zones, parking structures, entrances with limited sight-lines. Document the assessment in writing, with the date, the facility address, the names of the persons who conducted it, and the hazards identified. This document is the legal foundation of the WVPP.

Step 2: Write the WVPP. Using the hazard assessment as the basis, write a plan that addresses every element required by California SB 553 if the employer has California locations, and the applicable state mandates for other locations. Name the person responsible. Document the employee participation mechanism. Define the incident reporting procedure. Establish the investigation procedure. Set the corrective action timeline standard.

Step 3: Implement and document engineering controls. Based on the hazard assessment, identify what detection technology is proportionate to the identified risks. For facilities with public access, parking structures, or high patient-acuity environments, this means AI detection for weapon presence, loitering, unauthorized access, and crowd formation. Document the controls in the WVPP with the date of implementation and the hazards they address.

Step 4: Establish the violent incident log. Create the log format required by SB 553 or the applicable state mandate and begin populating it. Every incident and near-miss, including those captured by AI detection, should generate a log entry. Configure the detection system to generate exportable alert logs that can be appended to the incident record.

Step 5: Train employees and document it. All employees must be trained before starting work and annually thereafter. Training records must be maintained for one year. The training must cover what workplace violence is, how to report it, what the WVPP requires, and what the emergency response procedure is. Training records are one of the first items Cal/OSHA requests in an inspection.

Step 6: Schedule and conduct the annual review. The WVPP must be reviewed and updated annually, and following any serious incident. Build the annual review into the compliance calendar as a documented meeting with named attendees and a written outcome.

For a structured assessment of where an organization stands on this path and what the implementation timeline and budget look like, IntelliSee's team conducts no-obligation risk assessments that produce a gap analysis against applicable mandates and a recommended controls architecture. See also the ROI calculator for a financial model of the cost-avoidance case.

Frequently asked questions about WVPP mandates and compliance technology

Does California SB 553 apply to employers outside California?

SB 553 applies to employers with California employees, regardless of where the employer is headquartered. An employer based in Texas with employees working in California facilities or on California worksites is covered by SB 553 for those employees. Multi-state employers with California operations cannot treat this as a California-only concern. The employer's obligation exists wherever the California employee works.

What is the difference between a healthcare-specific WVPP mandate and California SB 553?

Healthcare-specific mandates cover healthcare and social service employers. California SB 553 covers nearly all California employers regardless of industry, including retail, hospitality, manufacturing, professional services, and construction. It is the only enacted general-industry WVPP mandate in the United States as of 2026. Healthcare employers in California must comply with both SB 553 and the healthcare-specific Cal/OSHA standard where both apply.

If we have no workplace violence incidents on record, do we still need a WVPP?

Yes. The absence of reported incidents is not a defense to the requirement to have a written plan. Regulatory agencies and plaintiff's attorneys treat a zero-incident record as potential evidence of under-reporting rather than evidence of a safe workplace. The mandate requires a written plan, a hazard assessment, and an incident log. All three must exist regardless of whether any incidents have occurred. Under California SB 553, the failure to have a written WVPP is itself a citable violation.

How does AI detection technology fit into a WVPP from a legal standpoint?

AI detection is an engineering control, one of three categories of preventive controls (engineering, administrative, work practice) that every enacted and proposed WVPP standard requires employers to implement in proportion to identified hazards. As an engineering control, it must be documented in the written WVPP alongside the hazard it addresses. The alert log it generates becomes part of the employer's hazard identification and incident documentation record. In enforcement actions, an employer that can show an active, timestamped detection log is demonstrating a continuous hazard identification program, not a once-a-year walkthrough.

Will the federal OSHA healthcare standard preempt state WVPP laws?

No. Federal OSHA standards establish a federal floor, not a ceiling. States with OSHA-approved state plans, including California, New York, Oregon, and Washington, retain authority to enforce standards that are at least as stringent as the federal standard. States with stricter laws will keep those laws. Employers in OSHA state-plan states will continue to be subject to the state standard as well as the federal one.

What records does Cal/OSHA typically request during a WVPP inspection?

Cal/OSHA WVPP inspections typically begin with a request for the written WVPP document, the violent incident log for the preceding five years, employee training records for the current and preceding year, records of the most recent hazard assessment, and any corrective action documentation generated in response to reported incidents or near-misses. The inspection may also include employee interviews and a facility walk-through to verify that identified controls are actually in place. Employers who cannot produce the written plan on short notice are already in a difficult position.

Does IntelliSee's platform work with existing security infrastructure, or does it require a full camera replacement?

The platform layers onto existing IP camera networks through the facility's existing video management system. No camera replacement is required. A 1U rack-mounted appliance is installed in the facility's server room; detection runs on-premises with no cloud roundtrip and no video leaving the network. Integration with Milestone XProtect, Genetec Security Center, and most major VMS platforms is supported. A structured assessment will confirm compatibility with specific infrastructure before any procurement decision.

Continue the research

This briefing covers the standards-compliance architecture for workplace violence prevention plans. For related intelligence on specific sectors and technology dimensions:

  • The Cal/OSHA Workplace Violence Prevention Regulation — how the SB 553 statute becomes an enforceable Cal/OSHA Title 8 standard, the April 2026 discussion draft, and the December 31, 2026 adoption deadline.
  • Healthcare Workplace Violence: The AI Detection Playbook — detailed treatment of hospital-specific WVPP implementation, including department-by-department deployment architecture and privacy considerations in behavioral health environments.
  • Security Legislation Tracker — actively maintained database of state and federal workplace violence prevention mandates, including effective dates, compliance scope, and pending legislation status.
  • AI Weapon Detection — technical reference on the firearm detection modality, including DHS SAFETY Act Full Designation and detection architecture.
  • Perimeter and Access Control Detection — how unauthorized zone access detection integrates with existing access control systems to satisfy engineering control documentation requirements.
  • ROI Calculator — financial model for the cost-avoidance case across direct incident costs, staff retention, insurance positioning, and security personnel efficiency.

Get a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment