RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Hospital physical security assessment software with pre-built Joint Commission, NIAHO, OSHA, ASIS, and HIPAA Security Rule libraries.
Summary
RiskWatch ships a physical security assessment platform built around pre-mapped libraries for the hospital security buyer: Joint Commission Environment of Care security management standards (EC.01.01.01 EP5 + EC.02.01.01) folded into the new Physical Environment chapter under Accreditation 360, NIAHO + DNV hospital security plan requirements, ASIS Facility Physical Security Control Standards, NIST 800-53 PE physical and environmental, HIPAA Security Rule physical safeguards at 45 CFR 164.310, OSHA workplace violence prevention guidance for healthcare, and the IAHSS healthcare protection standards. The Site Risk Cycle runs hospital-by-hospital with year-over-year trend reporting, and the browser-based mobile app works offline for clinic networks where cellular is unreliable. Customers include health systems running annual reaccreditation cycles plus utility, pharma, and industrial security programs.
Strengths
- Pre-built libraries for Joint Commission EC + NIAHO + DNV + IAHSS + NIST 800-53 PE + OSHA + HIPAA Security Rule physical safeguards plus 28 other standards day one
- Site Risk Cycle scoped to hospital-by-hospital cadence with year-over-year trend reporting for board, regulator, and insurer reviews
- Browser-based mobile site walks that work offline for ambulatory clinic networks where cellular reception is unreliable
- Single-tenant deployment with customer-owned data residency option for health systems treating physical security findings as ePHI-adjacent
- Crime-data overlay from four feeds (Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware) defensible to insurers and Joint Commission surveyors
- 30-day no-card free trial with full platform access, the only TVRA-first vendor on this list offering it
- Findings convert to tracked tasks with owners, due dates, and proof-of-close for OCR audit and Joint Commission tracer evidence
Weaknesses
- Not a VMS, access control system, or RTLS; integrates with Genetec, Lenel, Avigilon, Verkada, Brivo, and Securitas Healthcare via APIs and bulk imports rather than replacing them
- No native infant security or mother-baby matching module; that workflow belongs to Securitas Healthcare Hugs, HID TotGuard, or Accutech Cuddles
- No native panic-button or wearable duress hardware; dispersed-clinical-staff duress requires a paired vendor (Strongline, Centegix, or similar)
- Public pricing is partial; typical contract bands are published in the pricing calculator on this page but enterprise topology is quote-only
- Brand awareness on G2 and Capterra in healthcare physical security specifically is lower than Verkada or Genetec; total review volume sits below 100
- UI shows operational heritage in some assessment-builder screens; competing newer entrants like Verkada have a more polished first-run experience for non-specialist users
Multi-hospital systems (5-50 facilities), academic medical centers, and integrated health networks running annual Joint Commission, NIAHO, or DNV reaccreditation cycles plus the post-2024 OSHA WVP rule.
Single-clinic buyers who only need cameras and badge readers; Verkada, Brivo, or Avigilon Alta is the better fit there.
Key features
- Pre-built libraries for Joint Commission EC + Accreditation 360 PE chapter, NIAHO + DNV, IAHSS, ASIS Facility Physical Security Control Standards, NIST 800-53 PE, OSHA WVP guidance, HIPAA Security Rule physical safeguards 45 CFR 164.310, NFPA 1600
- Site Risk Cycle with hospital-by-hospital cadence, recommendation register, and proof-of-close
- Browser-based mobile site walks that work offline at remote clinics and sync on reconnect
- Crime-data overlay from Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware
- Multi-facility rollup dashboards at site, region, and system level with year-over-year trends
- Board-ready report templates that survive an insurer or Joint Commission surveyor review
- Single-tenant deployment with customer-owned data residency for health-system buyers
- 30-day free trial, no credit card, full platform access
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Cap Index CRIMECAST, Genetec, Lenel, Avigilon, Verkada (API + bulk import), Securitas Healthcare MobileView (bulk import), Jira / ServiceNow (task sync), Custom REST API.
Target size
250 to 50,000 employees · US · Canada · UK · EU · AU