When new legislation appears, it is easy to assume it belongs with senior managers, compliance teams, or legal departments.

Martyn’s Law can look like one of those subjects at first glance. Much of the public discussion has focused on football stadiums, concert venues, shopping centres, and other large public spaces.

But for healthcare security, the implications are much closer to home.

Hospitals are among the busiest publicly accessible places in the country. Patients, visitors, contractors, volunteers, ambulance crews, and staff move through them around the clock. People arrive without appointments, emotions can run high, and the operational picture can change within minutes.

That makes practical preparedness particularly important.

First, what does “Martyn’s Law is here” actually mean?

Martyn’s Law is the name commonly used for the Terrorism (Protection of Premises) Act 2025. It received Royal Assent on 3 April 2025 and establishes the Security Industry Authority (SIA) as the regulator.

However, the Act is not yet in force.

The SIA’s latest guidance says commencement is expected in spring 2027, with the exact date to be confirmed. Organisations do not yet need to notify the SIA, and its notification portal is not yet live.

That distinction matters. The law is on the statute book, but the present period is about understanding scope, ownership, procedures, and practical readiness before duties commence.

The official starting points are the SIA’s guidance on understanding Martyn’s Law and its regulatory role and the Home Office statutory guidance on the Terrorism (Protection of Premises) Act 2025.

What are the two tiers?

The Act takes a proportionate, tiered approach based largely on how many people it is reasonable to expect may be present at the same time.

  • Standard tier: qualifying premises where 200 to 799 people may be present.
  • Enhanced tier: qualifying premises where 800 or more people may be present, as well as qualifying events.

Standard-tier premises will need to notify the SIA and have appropriate public protection procedures in place, so far as is reasonably practicable, to reduce the risk of physical harm if an attack occurs at or near the premises.

The four procedure areas identified by the Act are:

  • Evacuation.
  • Invacuation, meaning moving people to a safer place within the premises.
  • Lockdown.
  • Communication.

Enhanced-tier premises and qualifying events have additional requirements. These include appropriate public protection measures, documentation explaining the procedures and measures in place, and further organisational responsibilities.

The responsible person for each healthcare site will need to determine whether the premises is in scope and which tier applies. Security teams can provide vital operational knowledge, but they should not be expected to make that legal determination alone.

Why hospitals are different

Hospitals rarely have the luxury of controlling exactly who enters or when they arrive.

Emergency departments do not close. Relatives arrive unexpectedly. Patients may walk in without warning. Contractors, delivery drivers, agency staff, volunteers, and emergency services move around the site throughout the day.

At the same time, some patients cannot simply evacuate. Others may depend on clinical equipment, need staff assistance, or become more vulnerable if routine care is interrupted.

A hospital therefore has to remain accessible and welcoming while protecting vulnerable people and critical services.

That is why Martyn’s Law cannot be approached by copying a procedure from a stadium or entertainment venue. Healthcare organisations need arrangements that work alongside clinical priorities, complex estates, emergency access, and patient movement.

Good healthcare security is already prevention-led

Experienced healthcare security officers spend much of their day doing work that rarely attracts attention.

They notice unusual behaviour. They identify doors left unsecured. They challenge someone professionally because their presence does not fit the location. They report damaged access-control equipment. They pass information to colleagues. They build relationships with ward, reception, estates, and facilities teams.

None of those actions looks dramatic.

Together, they create a stronger security environment.

The free Recognising Violence & Aggression Early guide focuses on a different risk area, but the professional habits transfer: notice meaningful change, assess context, communicate early, and avoid treating one sign as proof of intent.

Preparedness should encourage alertness and sensible reporting, not suspicion of everyone who behaves differently.

Preparedness is more than an emergency plan

Policies and plans matter, but they are only useful when people understand what they mean in practice.

If a serious incident occurred tomorrow, would staff know:

  • Who to contact and how to raise the alarm?
  • How reliable information should be communicated?
  • Whether to evacuate, invacuate, or lock down?
  • Which entrances or routes must remain available for emergency services?
  • How clinical teams will support patients who cannot move independently?
  • Who coordinates the response until police or other emergency services take control?

Those questions are difficult to answer for the first time during an incident.

Healthcare organisations already have useful foundations: major-incident plans, emergency command structures, business-continuity arrangements, fire procedures, and multi-department exercises. Martyn’s Law preparation should connect with those systems rather than create an isolated counter-terrorism folder.

Our earlier article, Martyn’s Law in Healthcare: Why Training Matters More Than Paperwork, looks more closely at why exercises and practical learning are essential.

Security cannot do it alone

One of the biggest misconceptions is that Martyn’s Law belongs solely to the security department.

It does not.

Security officers may bring specialist knowledge, site awareness, and incident experience, but they make up only a small part of a healthcare workforce.

A receptionist may notice somebody repeatedly testing access. A domestic assistant may find an unattended item. A porter may identify an unfamiliar vehicle in an unusual location. A nurse may hear information that changes the risk picture.

Security often connects those small pieces of information before they become something larger.

That depends on staff understanding what to report, how to report it, and what they should do after raising a concern. It also depends on leaders making reporting straightforward and responding proportionately when concerns prove innocent.

Technology supports judgement; it does not replace it

Modern hospitals may use CCTV analytics, access control, body-worn video, automatic number-plate recognition, alarm systems, and mass-notification tools.

Those systems can improve awareness and coordination, but they do not remove the need for professional judgement.

A camera may highlight movement without understanding context. An access alert may show that a door opened without explaining why. A system can create information, but people still need to assess its relevance and communicate it clearly.

Our article on AI CCTV in healthcare security explores this balance between technology, context, privacy, and human oversight.

Dynamic risk assessment still matters

Few incidents unfold exactly as a procedure predicts.

An aggressive visitor may suddenly become medically unwell. A suspicious item may turn out to be harmless. A fire alarm may coincide with an unrelated security incident. An exit route may be clinically essential or temporarily unavailable.

Good officers continually reassess what is happening as information changes. They do not abandon local procedures, but they understand that procedures must be applied to a live environment.

The free Dynamic Risk Assessment Guide supports this kind of structured thinking, while the Professional Radio Procedure & Etiquette guide helps teams communicate the changing picture clearly.

Training should build confidence, not fear

Martyn’s Law is concerned with rare but potentially devastating events. That does not mean training should make staff fearful or encourage them to see ordinary behaviour as a threat.

Good training should increase confidence.

People who understand their role are more likely to remain calm, pass useful information, and follow local procedures under pressure. For healthcare security teams, that means connecting protective-security awareness with skills officers already use:

  • Observation and situational awareness.
  • Clear radio and face-to-face communication.
  • Dynamic risk assessment.
  • Professional challenge.
  • Incident reporting.
  • Multi-agency working.
  • Post-incident debrief and learning.

These capabilities support exceptional incidents, but they also improve everyday security work.

What NHS security teams can do now

The exact legal responsibilities sit with the relevant responsible person and organisation, but security teams can make a valuable contribution during the preparation period.

Practical questions include:

  1. Has each site identified who is leading the organisation’s Martyn’s Law work?
  2. Has the responsible person assessed whether the premises is in scope and which tier may apply?
  3. Do evacuation, invacuation, lockdown, and communication procedures reflect the realities of patient care?
  4. Are public entrances, emergency routes, restricted areas, and vulnerable locations understood?
  5. Can control rooms, reception teams, clinical areas, estates, and security share information quickly?
  6. Have procedures been discussed or exercised with the departments expected to use them?
  7. Are lessons from exercises and incidents recorded, assigned, and reviewed?
  8. Are teams following current official guidance rather than relying on product claims or unofficial compliance guarantees?

The SIA explicitly advises organisations to use official guidance and notes that it does not endorse third-party products or providers claiming to guarantee compliance.

Final thoughts

Martyn’s Law should not be viewed as an entirely new way of thinking for NHS security teams.

Many already observe, communicate, assess risk, coordinate with colleagues, and help hospitals respond when normal arrangements break down.

The challenge is to make those capabilities consistent, supported, exercised, and connected across the wider organisation.

Preparedness is not about expecting the worst. It is about giving people the knowledge, procedures, and confidence to respond effectively if the unexpected happens.

This article provides general learning information, not legal or compliance advice. Healthcare organisations should use the latest Home Office and SIA guidance when determining whether premises are in scope and how the Act applies.