A hospital is one of the few buildings that people can walk into without being formally stopped. Patients arrive with families in tow and often in emergency situations. Deliveries, agency staff and service workers move through the corridors all day, making it a very open environment. It's this openness that makes contractor and visitor identification such a difficult problem for the healthcare sector to get right.

Why hospitals are a different kind of security problem

Most organisations can control their perimeter more strictly than a hospital. Buildings typically have multiple public entrances, 24-hour emergency access, a constant rotation of agency and staff and a huge volume of third-party contractors including estates, maintenance, decontamination and sterile services, catering, IT, pharmacy, delivery, equipment engineers and more. Many of whom need access to areas that hold vulnerable patients, controlled drugs or lots of expensive equipment.

The scale involved is easy to underestimate. NHS Digital's most recent workforce statistics put the Hospital and Community Health Services workforce in England at 1,537,301 people as of May 2026, with professionally qualified clinical staff, doctors, nurses, midwives, and allied health professionals making up over half of that total and still growing year on year. Every one of those people needs a valid badge, and that's before adding the agency staff, volunteers, and contractors who sit outside the headcount entirely. An identification system that relies on individual vigilance rather than a consistent, enforced standard was never going to hold up at this scale.

That workforce is also constantly changing. NHS England's turnover data for the year to May 2026 records 156,676 leavers and 153,244 joiners across the HCHS workforce, a headcount leaver rate of just over 10%. That's roughly 310,000 individual badge issuances or deactivations in a single year, before a single contractor, agency worker, or volunteer is added to the count. Even the Hotel, Property & Estates group, the team most directly responsible for managing site access, saw over 8,100 leavers and 8,700 joiners of its own over the same period, a reminder that the team holding the access system together is itself turning over at nearly one in ten roles a year.

Violence and abuse against healthcare staff is rising

The most recent NHS Staff Survey found that 14.47% of respondents had experienced at least one incident of physical violence from a patient, relative, or member of the public in the previous 12 months, the highest reading in three years. A further quarter of staff reported harassment, bullying or abuse from the same group.

This is the environment that any identification system has to function within; a setting where staff are already dealing with heightened risk daily.

Impersonation is a real threat

In May this year, the news reported that a man had allegedly posed as a medical student for several months and accessed Aberdeen hospital's wards and files. This isn't an isolated case; a man was also accused in 2023 of dressing up as a nurse at Glasgow's Queen Elizabeth University Hospital whilst carrying a fake ID. With people also selling NHS-branded uniforms on TikTok, the threat of impersonation is real across the UK healthcare system.

The cost of poor access control is millions

The NHS Counter Fraud Authority estimates that the NHS is vulnerable to £1.346 billion worth of fraud every year, money that comes straight out of funding meant for patient care. Identification and access sit at the centre of a meaningful share of that figure. The NHSCFA's own fraud awareness material names "using fake identification to gain employment in the NHS" as a recognised fraud type in its own right, alongside ghost patients, payroll fraud, and procurement fraud, precisely because a convincing badge or a falsified reference can be enough to get someone through the door and onto the payroll.

Who needs identifying in a hospital?

A trust's identification system must cover several specific populations, each with different requirements:

  • Employed staff: those employed directly by the trust, typically issued a photo ID badge that doubles as their access control credential.
  • Agency/bank staff: typically, the highest turnover group, and one of the most exposed to the kind of impersonation seen previously, as they're less likely to be recognised by permanent colleagues.
  • Contractors: estates, decontamination, IT, pharmacy, equipment engineers, all of whom may need access to restricted, clinical areas but sit outside the trust's normal HR processes.
  • Volunteers: a growing number across most trusts and currently at 72,000, often working directly with patients.
  • Visitors: the largest and least predictable population, present for a single visit with no ongoing relationship with the organisation.

The badge itself sits on top of a formal national standard. NHS Employers' Identity Checks Standard sets out identity verification as the most fundamental of all NHS pre-employment checks, on the basis that every other check- DBS, right-to-work, professional registration- is meaningless if the organisation can't first prove the individual is who they claim to be.

Crucially, the standard applies to everyone before they set foot on site, not just directly employed staff: it explicitly covers volunteers, students, temporary workers, and contractors, all of whom must have their identity verified before commencing any type of work or volunteering. For contractors and agency staff supplied through a third party, the standard puts the burden on the trust to gain assurance from the staffing provider that identity checks have been completed to the same standard as its own, and to make clear that anyone supplied will still need to present photographic ID on their first day so it can be cross-matched against what was submitted earlier in the process.

On top of that, DBS checks sit behind the badge for anyone in a role involving contact with patients. In other words, the badge is meant to be the visible endpoint of a verification chain, not a substitute for one, and that chain is only as strong as the weakest link a trust allows a third-party supplier to skip.

What a well-run identification system looks like in a hospital

Photo as a baseline

A laminated ID card is the minimum level of security a hospital needs, as it's too easy to get past a busy reception where staff are used to seeing dozens of unfamiliar faces every week. The badge needs unique features that can't be replicated by a printer at home, such as a UV-visible layer, a holographic overlay, or an encoded chip that a fake couldn't.

Colour-coded lanyards

Lanyards aren't just another form of marketing or branding; it can also be a big first step of identification in big organisations like hospitals. A member of staff, a patient or a visitor should be able to tell staff, contractor and visitors apart from across a corridor, without stopping to read a name badge. Many trusts already do this informally, but formalising trust-wide colour-coded lanyards will close an easy ID gap.

Self-expiring visitor badges

A day-dated or self-voiding visitor badge can help ensure visitor passes that aren't returned can't be misused to access important or confidential parts of the hospital.

Using a digital visitor management system

Hospitals should by now have removed all paper sign-in books to comply with GDPR and stop visitor names, companies and departments from being compromised. A digital visitor management system like EntrySign, replaces the analogue approach with pre-registration, printed badges and a real time record of exactly who is on site, which matters considerably more in a hospital in case of evacuation or emergency.

Encoded access control

The most effective layer of security sits behind the badge. Encoded access control, whether MIFARE, HID, or a comparable credential, means a badge that looks perfect on first glance still fails the moment it's presented at a door it isn't authorised to open.

In nearly thirty years of doing this, hospitals are consistently the hardest sites to get right, not because trusts don't take it seriously, but because the building has to stay open to the public by design. The trusts who manage it well aren't the ones with the most expensive kit. They're the ones who've made identification boringly consistent: the same badge standard for every contractor, the same lanyard colours on every ward, the same sign-in process at every entrance. Consistency is what actually gets noticed when something's wrong.

The good news, none of this requires ripping out an existing system and starting again. Most trusts and private hospitals already have the right foundations for effective visitor management such as the badges, lanyards, some access control and a reception process. The gap is usually consistency.

If you're reviewing how your hospital or healthcare site identifies contractors and visitors, get in touch with the team. We work with NHS trusts and private healthcare providers across the UK on badge design, colour-coded lanyard schemes and management software and can help you build a bespoke system that fits your site's size and budget.