LEGISLATION

CMS Workplace Violence Prevention Requirements for Hospitals (QSO-23-04-Hospitals / Conditions of Participation)

Updated May 12, 2026

Status: In Effect — The CMS memorandum has been operative since November 28, 2022 (QSO-23-04-Hospitals) and has not been rescinded. It remains the federal enforcement mechanism for workplace violence prevention in hospitals participating in Medicare and Medicaid as of 2026.

Memorandum Number: QSO-23-04-Hospitals (CMS Quality, Safety & Oversight Group)

Jurisdiction: Federal (Centers for Medicare & Medicaid Services, U.S. Department of Health and Human Services)

Category: Healthcare Workplace Violence, Federal Conditions of Participation Enforcement

Industries: Healthcare (Acute Care Hospitals, Critical Access Hospitals, Psychiatric Hospitals, Long-Term Care Hospitals)

Effective Date: November 28, 2022 (in force; no expiration)

Summary: On November 28, 2022, the Centers for Medicare & Medicaid Services issued QSO-23-04-Hospitals, a memorandum to State Survey Agency Directors clarifying that hospitals risk Hospital Conditions of Participation (CoP) violations when they fail to adequately respond to and prevent workplace violence. The memo is a regulatory enforcement clarification, not a new rule — it makes explicit that existing CoP language already requires hospitals to protect both patients and staff from violence. CMS identified three CoP regulatory tags that surveyors should cite during complaint investigations and recertification surveys when hospitals fail to address workplace violence hazards. As of May 2026, multiple healthcare industry coalitions have asked CMS for additional guidance on permissible anti-violence signage in emergency departments under the Emergency Medical Treatment and Labor Act (EMTALA), but the underlying memorandum and the Conditions of Participation enforcement framework remain in effect.

Cited CoP Regulatory Tags:

  • 42 C.F.R. § 482.13(c)(2) — Patient Rights / Care in a Safe Setting: Hospitals must protect each patient’s right to receive care in a safe setting, including protection from intentional harm by others.
  • 42 C.F.R. § 482.41 — Physical Environment: Hospitals must maintain a physical environment that protects the health and safety of patients, staff, and visitors, including security risk assessment and mitigation.
  • 42 C.F.R. § 482.15 — Emergency Preparedness: Hospitals must develop, train, and exercise an all-hazards emergency preparedness plan informed by an annual risk assessment that accounts for workplace violence as a foreseeable hazard.

Affected Entities: All hospitals participating in Medicare or Medicaid, including acute care hospitals, critical access hospitals, psychiatric hospitals, and long-term care hospitals. Survey agencies cite under the CoPs during complaint surveys, validation surveys, and recertification surveys.

Penalties and Enforcement: Citation under the Hospital Conditions of Participation can trigger Plans of Correction, condition-level deficiencies, and in severe or repeat cases, termination from Medicare and Medicaid participation — an existential financial consequence for any U.S. hospital. Joint Commission and other deemed accrediting organizations are required to enforce equivalent standards (including NPG 2a) so that accreditation status protects CMS participation. CMS is the federal floor; The Joint Commission is the operational mechanism most hospitals encounter first.

IntelliSee Relevance: High. The CMS memorandum makes workplace violence prevention an enforceable federal requirement for every U.S. hospital participating in Medicare. IntelliSee’s AI-powered visual intelligence platform supports compliance under all three cited CoPs:

  • Patient Rights / Safe Setting (§ 482.13): AI weapon detection identifies visible firearms in emergency departments, behavioral health units, and waiting rooms before violent incidents escalate, supporting the hospital’s affirmative obligation to provide care in a safe setting.
  • Physical Environment (§ 482.41): Continuous AI monitoring functions as an engineering control documented in the hospital’s security risk assessment, with timestamped detection records that demonstrate active hazard mitigation.
  • Emergency Preparedness (§ 482.15): IntelliSee’s 24/7 autonomous monitoring extends the reach of the all-hazards emergency preparedness plan, with detection records that support post-incident review and annual risk assessment refinement.

IntelliSee operates without facial recognition, which keeps deployments compatible with HIPAA, patient confidentiality, and the patient-rights framework that the CoPs themselves protect.

Related Legislation & Resources

Stay Ahead of Compliance

Turn Legislative Mandates Into a Working Safety Program

IntelliSee tracks the safety legislation that affects your facilities and maps each mandate to practical AI threat detection on the cameras you already own.

See All Tracked Legislation Talk to IntelliSee About Compliance