On July 2, the emergency department at Marshfield Medical Center in Wisconsin received a phone call indicating that two males were en route to “shoot up” the hospital and would arrive in 20 minutes. The hospital went on lockdown and called the police, who responded, Becker’s Hospital Review reported. However, law enforcement later determined that similar threats had been called into locations across the state the same day. The threat was a swatting call.
“Swatting” is a form of criminal harassment in which someone reports a false or nonexistent emergency to law enforcement or another institution to elicit a police or SWAT (special weapons and tactics) team response. Incidents increased from about 400 cases in 2011 to over 1,000 cases in 2019, according to a report from the International Association for Healthcare Security and Safety (IAHSS) Foundation.
Swatting diverts public safety resources from real emergencies, putting first responders, hospital staff and the public at risk.
While swatting isn’t new, journalists who cover health care should be aware that incidents targeting hospitals appear to be increasing, according to Becker’s Hospital Review. Hospitals are vulnerable due to their 24-hour operations and high-stakes, high-stress environments, according to an article in Healthcare Facilities.
These incidents can trigger lockdowns, patient diversions (sending patients to other hospitals), evacuations and other major disruptions to hospital operations, according to an article in Health Facilities Management by AHCJ member Larry Beresford. Beyond the immediate disruption, potential patients who hear about a SWAT response at a hospital may be more nervous about their safety at that facility and choose to go elsewhere. Each swatting call costs taxpayers an estimated $10,000, the IAHSS Foundation report estimates.
Here are two other recent examples:
- On July 4, police in La Crosse, Wis., received a report of a suspicious person with a gun outside the emergency room of Emplify Health by Gunderson. Police deployed “all necessary resources” before verifying it was a swatting call, Fox9 News reported.
- In March 2025, police swarmed Loma Linda University Children’s Hospital in California after a caller told law enforcement officials that he was in front of the hospital armed with a bomb and was planning to“shoot up” everyone inside, KTLA5 News reported. Initially unaware the report was false, the San Bernardino County Sheriff’s Department responded, notifying the public via social media to avoid the area while deputies cleared the facility. It took them nearly two hours to determine there was no threat.
Why the rise?
New communication technology and social media platforms have made swatting more prevalent and allowed incidents to spread rapidly online, potentially inspiring copycats, a security expert told Beresford. Swatting calls are often made by phone using caller ID spoofing or other techniques to hide the caller’s identity, or through social media, Becker’s Hospital Review’s story noted. Some calls are so amateurish they may not trigger a hospital response, but that’s the balancing act hospitals must navigate: determining which threats warrant a full-scale response, Beresford wrote.
Swatting happens often enough that hospitals should institute policies, procedures and training drills to prepare staff, a security expert told Beresford. Because most calls come in through a switchboard, operators should receive training on hospital protocols and how to gather information from callers, including their claimed name, location and reason for the threat.
There are also potential solutions for mitigating these events, according to a recent newsletter from the Cybersecurity and Infrastructure Security Agency (CISA), a federal agency that helps protect the country from cyberattacks and other threats:
- Through the Telephone Robocall Abuse Criminal Enforcement and Deterrence (TRACED) Act of 2019, the Federal Communications Commission requires domestic voice service providers with more than 100,000 subscribers to implement a robocall mitigation program or caller ID authentication technology. It also authorizes providers to block calls under certain circumstances.
- Other available and emerging technologies include automatic number identification (ANI) validation, which uses a database lookup to verify callers. If the ANI doesn’t match customer records, it could indicate the call is spoofed or manipulated and should be routed for additional review. Voice biometrics uses voice recognition or other biometric data to identify callers and is challenging to replicate. Knowledge-based authentication (KBA) uses specific relevant questions to verify a caller’s identity based on personal information not easily accessible by bad actors.
Meanwhile, the IAHSS Foundation recommends hospitals train staff on how to handle a swatting incident, recognize characteristics of a false report, report incidents to police and use de-escalation tactics to reduce potential harm to patients and staff.
Story angles
Hospitals and police departments may not wish to discuss their emergency response plans for handling swatting incidents with journalists, but reporters can still pursue these story angles about swatting:
- Talk to security experts about the latest technologies to monitor and prevent swatting, or identify people making the calls.
- Talk to hospitals that have experienced swatting incidents to discuss impacts on daily operations and lessons learned.
- Interview patients affected by a swatting event, such as being unable to access a hospital for care and forced to seek treatment elsewhere.
- Find out whether your state’s hospitals have invested in technologies such as caller authentication or enhanced threat assessment since experiencing swatting incidents.
Resources
- Hospitals face rise in swatting calls: 6 notes – Becker’s Hospital Review
- Swatting calls, hoax threats have real consequences for health care – Healthcare Facilities Today
- What to do when swatting happens – Healthcare Facilities Today
- ‘Swatting’ becomes a growing concern – Health Facilities Management
- An introduction to swatting and fraudulent calls for emergency communications center administrators – CISA
- Resources for swatting and hoax threats – Homeland Security
- Mitigating swatting events in the healthcare sector – International Association for Healthcare Security and Safety (IAHSS) Foundation










