Why Hospital Radioactive Material Is a Documented Dirty Bomb Concern

Hospital radioactive sources are a documented dirty-bomb concern because the cesium-137, cobalt-60, and iridium-192 used in routine cancer treatment and nuclear medicine are the same isotopes and activity levels capable of powering a radiological dispersal device. A dirty bomb does not require a nuclear weapon, weapons-grade fissile material, or state-level sponsorship — only conventional explosives or another dispersal mechanism paired with a sealed radioactive source large enough to contaminate an area and create lasting public fear, economic disruption, and cleanup costs that can run into the billions. The sources capable of that kind of event are not exotic. They are sitting, right now, in the nuclear medicine departments, radiation oncology suites, and blood irradiators of hospitals across the country.

Cesium-137 teletherapy and blood irradiator sources, cobalt-60 units used in gamma knife and external beam radiation therapy, and iridium-192 sources used in high-dose-rate brachytherapy are the exact isotypes and quantities that the International Atomic Energy Agency’s source security categorization system and the U.S. Nuclear Regulatory Commission both treat as high-consequence material. The IAEA’s categorization framework for radioactive sources ranks sealed sources by the potential for the material, if lost or malicious acted upon, to cause severe deterministic health effects — and the isotopes and activity levels found in hospital radiation-therapy and nuclear medicine equipment routinely fall into the highest-risk categories on that scale.

The U.S. Department of Homeland Security and the NRC have both identified hospital-held radioactive sources as a component of the domestic radiological terrorism threat picture precisely because hospitals are, structurally, softer targets than military or Department of Energy facilities. A hospital campus is designed for open access. Patients, families, vendors, contractors, and staff move through it around the clock. That openness is a clinical and operational necessity — and it is also the exact vulnerability profile that makes a hospital’s Category 1 or Category 2 radioactive material a more attainable target than a heavily guarded federal nuclear site.

The Uncomfortable Reality

A radiological dispersal device does not need to kill people to succeed as an act of terrorism. Contamination of a hospital campus, a downtown core, or a transit hub — even at survivable exposure levels — can trigger evacuation, indefinite closure, and economic damage far exceeding any device’s actual lethality. That is precisely why the sources capable of enabling it are federally regulated at the physical-protection level, not just the radiation-safety level.

What NRC 10 CFR Part 37 Actually Requires

NRC 10 CFR Part 37, “Physical Protection of Category 1 and Category 2 Quantities of Radioactive Material,” requires licensees to implement access controls, trustworthiness and reliability determinations, continuous monitoring, law-enforcement coordination, and defense-in-depth around high-activity radioactive sources. It applies to any licensee — hospital, cancer center, blood bank, or research institution — that possesses radioactive material at or above defined Category 1 or Category 2 quantities of concern. Category 1 quantities are those the NRC has determined could, if not properly controlled, cause permanent injury or death to individuals in close proximity within a short time; Category 2 quantities carry a somewhat lower but still serious consequence profile. Cesium-137 blood irradiators and teletherapy units, cobalt-60 therapy sources, and high-activity iridium-192 brachytherapy sources are the isotopes most likely to place a hospital squarely inside Part 37’s scope.

Part 37 grew out of an earlier NRC framework known as “Increased Controls” — interim security orders issued in the years following the September 11 attacks that required licensees possessing radioactive sources above defined quantities of concern to implement access controls, monitoring, and coordination with local law enforcement ahead of a formal rulemaking. Part 37 codified and expanded those Increased Controls requirements into a permanent regulation, and its core physical protection obligations include:

  • Access controls — licensees must limit unescorted access to Category 1 and 2 material and devices to individuals specifically approved by the licensee, with all others escorted by an approved individual at all times.
  • Trustworthiness and reliability determinations — before granting unescorted access, the licensee must complete a background investigation covering identity verification, employment history, and a fingerprint-based FBI criminal history records check, consistent with NRC’s trustworthiness and reliability requirements.
  • Monitoring and detection — continuous monitoring of the source location, whether through direct observation, electronic surveillance, or intrusion detection, sufficient to detect and respond to unauthorized access or attempted removal.
  • Coordination with local law enforcement (LLEA) — a documented pre-arranged coordination plan with the local law enforcement agency of jurisdiction, covering response times and communication protocols in the event of an actual or attempted theft or diversion.
  • Defense-in-depth — layered controls so that no single point of failure — a propped door, a bypassed badge reader, an unescorted vendor — results in unmonitored access to the material.

These are not radiation-safety obligations. They are physical-security obligations, imposed by a nuclear regulator, on a facility type — the general acute-care hospital — that historically has not thought of itself as operating under nuclear-security law.

1–2NRC Source Categories Triggering Part 37
Cs-137Blood Irradiators & Teletherapy
Co-60External Beam & Gamma Knife
Ir-192High-Dose-Rate Brachytherapy

The Security Gap: Radiation Safety Compliance Is Not a Physical Security Assessment

Every hospital that holds Category 1 or 2 material has a Radiation Safety Officer (RSO) and an NRC- or Agreement State–approved radiation safety program. Radiation safety programs are rigorous on the dosimetry, shielding, contamination control, and regulatory-reporting side of the equation. That is their job, and hospitals generally do it well — radiation safety compliance is heavily audited and has a mature professional infrastructure behind it.

What radiation safety programs are not built to do is independently evaluate the physical security architecture surrounding the source — the access-control hardware, the sightlines into the hot lab, the badge-reader logic, the loading-dock and service-corridor pathways that lead to the linear accelerator vault, the insider-threat exposure created by contractor and vendor access, or how those elements interact with each other under defense-in-depth principles. A radiation safety audit asks: is the source shielded, labeled, and inventoried correctly? A physical security assessment asks a fundamentally different question: could someone who is not supposed to be here get to it, and how would we know?

The Joint Commission’s Environment of Care standards touch on security planning at a general facility level, and Part 37 itself requires the security elements described above — but neither framework, nor the typical radiation safety program, produces a scored, documented, defensible physical vulnerability assessment specific to the RAM storage areas, hot labs, and access pathways that Part 37 is actually designed to protect. That is the gap. Most hospitals can produce a radiation safety license file. Very few can produce a structured vulnerability assessment of the physical protection measures surrounding that license’s material.

Key Distinction

Radiation safety compliance documents that the material is accounted for. Physical vulnerability intelligence documents whether the physical protection surrounding that material would actually stop, delay, or detect an adversary. NRC Part 37 requires both — most hospital compliance files only demonstrate the first.

How VYKEN Property Vulnerability Intelligence™ Assesses Radiological Source Protection

VYKEN Property Vulnerability Intelligence™ applies the same structured Detect → Analyze → Assess → Report methodology used across every VYKEN™ engagement to the specific physical protection obligations created by NRC 10 CFR Part 37 — mapping each phase directly onto the RAM storage areas, hot labs, treatment vaults, and access pathways that fall inside Part 37’s scope. At the center of the assessment is the VYKEN Asset Protection Matrix™ (VAPM™) — Vyken’s proprietary framework integrating recognized methodologies including CPTED and CARVER alongside proprietary AI-native analytics — applied here to the highest-consequence asset class a hospital can hold.

1

Detect — Environmental Intelligence Around RAM Storage and Hot Labs

The assessment documents every physical pathway to Category 1 and 2 material: hot lab and nuclear medicine suite entry points, linear accelerator and gamma knife vault access corridors, loading docks used for source delivery and exchange, service and maintenance access routes, and adjacency to lower-security public areas. VAPM™’s environmental-design layer — drawing on CPTED principles — evaluates lighting, sightlines, badge-reader placement, door hardware, and natural surveillance around each of these pathways, producing the environmental picture Part 37’s access-control and monitoring requirements assume exists but rarely verify independently.

2

Analyze — VAPM™ Scoring of RAM-Related Assets

Each radiological source location, storage vault, and transport pathway is identified and scored through VAPM™’s six dimensions of vulnerability and criticality — the same rigor applied to any high-value asset, calibrated here to reflect the consequence profile the NRC assigns to Category 1 and 2 material. This phase also evaluates insider-threat exposure: which roles have unescorted access, how consistently escort protocols are enforced for vendors and contractors, and whether the access list in practice matches the access list on paper.

3

Assess — Synthesis Into a Scored VPVI™

Environmental findings and VAPM™ asset scores are synthesized into the VYKEN Property Vulnerability Index™ (VPVI™) — a 0–100 composite score for the assessed campus or department, supported by a VYKEN Business Impact Score™ (VBIS™) that translates vulnerability findings into operational and reputational exposure, and a VYKEN Threat Exposure Analysis™ (VTEA™) that maps identified gaps to realistic scenarios — including unauthorized access, insider diversion, and forced entry to source storage.

4

Report — A VPVIA™ Built for Inspection and Board-Level Review

Findings are compiled into a VYKEN Property Vulnerability Intelligence Assessment™ (VPVIA™) report, with a Corrective Action Plan that prioritizes remediation by risk reduction per dollar invested and includes planning-level cost guidance. For hospitals subject to Part 37, this becomes the physical-security counterpart to the RSO’s radiation safety documentation — a defensible, dated record that the facility independently evaluated the physical protection surrounding its Category 1 and 2 material.

Radiation Safety Compliance vs. VYKEN Vulnerability Intelligence™

Hospitals do not need to choose between their radiation safety program and a vulnerability assessment — the two are complementary and address different halves of the same regulation. Understanding where each one stops is what allows a hospital to close the gap Part 37 was written to prevent.

Dimension Traditional Radiation Safety Compliance VYKEN Property Vulnerability Intelligence™
Primary question answered Is the material accounted for, shielded, and used safely? Could an adversary physically reach the material, and how would the facility know?
Owner Radiation Safety Officer / medical physics Hospital security director, risk management, RSO (jointly)
Methodology basis NRC/Agreement State radiation safety license conditions VYKEN Asset Protection Matrix™ (VAPM™) — integrating CPTED and CARVER with proprietary analytics
Output format License file, dosimetry records, inventory logs Scored VPVIA™ report with a prioritized Corrective Action Plan
Insider-threat coverage Limited — generally assumes authorized users are trusted Explicitly scored — access-list accuracy, escort compliance, credential exposure
Trackability over time Point-in-time license renewal cycle Trackable VPVI™ score, with ongoing monitoring available via VYKEN Intelligence Monitoring™ (VIM™)
Inspection posture Demonstrates regulatory recordkeeping Demonstrates independent, documented physical-security due diligence

The last row is the one that matters most to a hospital compliance officer or general counsel. Recordkeeping demonstrates that a program exists. It does not, by itself, demonstrate that the program was independently tested against a structured vulnerability standard. That distinction becomes very important the first time an NRC inspector, a Joint Commission surveyor, or opposing counsel in a post-incident deposition asks a more specific question than “do you have a radiation safety program.”

Documentation and Inspection Defensibility

NRC inspections of Part 37 licensees examine whether the required physical protection program elements — access controls, trustworthiness and reliability determinations, monitoring, and LLEA coordination — are not just written into a plan but actually implemented and functioning. A written access-control policy that does not match what happens at the hot lab door on a Tuesday afternoon is exactly the kind of gap an inspection, or a real incident, will expose.

A VYKEN Property Vulnerability Intelligence Assessment™ produces the kind of documentation that holds up under that scrutiny: a scored, dated, methodology-driven record showing exactly what was observed, how it was weighted, and what corrective actions were prioritized as a result. For a hospital risk management office, that record does three things a license file alone cannot:

  • It demonstrates proactive due diligence — the facility did not wait for an inspection finding or an incident to evaluate its physical protection posture.
  • It creates a defensible paper trail for boards, insurers, and legal counsel in the event of a security incident, an NRC finding, or a Joint Commission survey question touching on environment-of-care security planning.
  • It gives the RSO and the security director a shared, scored reference point — rather than two departments each holding a partial picture of the same regulatory obligation.

Ongoing exposure changes as staff turn over, construction alters access corridors, and vendor relationships shift. VYKEN Intelligence Monitoring™ (VIM™) extends the initial VPVIA™ into a tracked VPVI™ score over time, so the documentation reflects the facility’s current physical protection posture — not a snapshot from the last license renewal cycle.

Bottom Line

NRC 10 CFR Part 37 legally mandates physical protection of Category 1 and 2 radioactive material. Most hospitals can prove they comply with the radiation safety half of that mandate. Very few can prove — with a scored, structured, third-party record — that the physical protection half was independently assessed. That is the exact document a VYKEN Property Vulnerability Intelligence Assessment™ produces.

Who Needs This Assessment

Part 37’s physical protection obligations touch more roles inside a hospital than the license itself suggests. In practice, four groups have the most direct need for a VYKEN Property Vulnerability Intelligence™ assessment focused on radiological source protection.

Radiation Safety Officers

The RSO is accountable for the radiation safety program and, in most facilities, is pulled into physical security questions they were never trained to independently evaluate. A VPVIA™ gives the RSO a scored, professional physical-security record to pair with the radiation safety file — closing the exact gap between “the source is accounted for” and “the source is physically protected the way Part 37 requires.”

Hospital Security Directors

Hospital security leadership typically owns badge access, camera coverage, and guard staffing across the entire campus — but rarely has a source-specific, scored assessment of the hot lab, treatment vault, and RAM storage pathways that carry the highest regulatory consequence of any asset on the property. VYKEN Property Vulnerability Intelligence™ gives security directors a defensible, prioritized basis for capital requests specific to these areas, rather than competing for budget on general intuition.

Health-System Risk Management and Compliance

System-level risk officers need a consistent way to compare physical protection posture across multiple hospital campuses that each hold Category 1 or 2 material — something a facility-by-facility patchwork of radiation safety files cannot provide. A scored VPVI™ across a portfolio of facilities gives risk management a comparable, trackable metric for board reporting and insurance renewal conversations.

General Counsel and Environment-of-Care Committees

The Joint Commission’s environment-of-care framework and a hospital’s own enterprise risk program both benefit from a documented, third-party vulnerability record specific to the facility’s highest-consequence regulated material. In the event of an incident, an NRC finding, or litigation, that record is the difference between “we had a policy” and “we had a policy, and we independently verified it was working.”

Get a VYKEN Property Vulnerability Intelligence™ Assessment for Your Radiation Oncology or Nuclear Medicine Department

Every VYKEN Property Vulnerability Intelligence™ engagement is powered by the same proprietary engine — the VYKEN Asset Protection Matrix™ (VAPM™), integrating recognized methodologies including CPTED and CARVER alongside proprietary AI-native analytics — producing a scored VYKEN Property Vulnerability Index™ (VPVI™) and a documented VYKEN Property Vulnerability Intelligence Assessment™ (VPVIA™) report with a Corrective Action Plan. For hospitals holding Category 1 or 2 quantities of radioactive material under NRC 10 CFR Part 37, that report is the missing physical-security counterpart to an already mature radiation safety program.

The dirty bomb threat tied to hospital radioactive sources is not hypothetical — it is the exact scenario 10 CFR Part 37 was written to prevent. The question is whether your facility can currently prove, with a scored and dated record, that the physical protection surrounding those sources is actually working.

Frequently Asked Questions

What does NRC 10 CFR Part 37 require?

NRC 10 CFR Part 37 requires hospitals and other licensees holding Category 1 or Category 2 quantities of radioactive material to implement physical protection measures: access controls, trustworthiness and reliability determinations (including FBI fingerprint-based background checks), continuous monitoring and detection, coordination with local law enforcement, and defense-in-depth so no single failure point exposes the material. It codified and expanded the post-9/11 Increased Controls security orders into a permanent regulation. These are physical-security obligations layered on top of, and separate from, standard radiation-safety compliance.

Why are hospital radioactive sources considered a dirty-bomb concern?

Hospital radioactive sources are a dirty-bomb concern because cesium-137, cobalt-60, and iridium-192 sources used in nuclear medicine and radiation oncology are the exact isotopes and activity levels that federal agencies classify as capable of enabling a radiological dispersal device. A dirty bomb does not require a nuclear weapon or state sponsorship — only conventional explosives paired with a source large enough to contaminate an area and trigger evacuation, closure, and economic damage. Hospitals are structurally softer targets than guarded federal nuclear sites because they are designed for continuous, open access.

What are Category 1 and Category 2 radioactive sources?

Category 1 and Category 2 are NRC-defined quantity thresholds for radioactive material that trigger Part 37’s physical protection requirements. Category 1 quantities could cause permanent injury or death to someone in close proximity within a short time if not properly controlled; Category 2 quantities carry a somewhat lower but still serious consequence profile. Cesium-137 blood irradiators and teletherapy units, cobalt-60 therapy sources, and high-activity iridium-192 brachytherapy sources are the isotopes most likely to place a hospital inside this scope.

How does VYKEN assess radioactive material (RAM) security?

VYKEN Property Vulnerability Intelligence™ assesses RAM security using its Detect → Analyze → Assess → Report methodology, applying the VYKEN Asset Protection Matrix™ (VAPM™) to the hot labs, treatment vaults, and access pathways covered by Part 37. The process documents environmental and access-control conditions, scores each asset and pathway across VAPM™’s six dimensions of vulnerability and criticality, and synthesizes findings into a VYKEN Property Vulnerability Index™ (VPVI™) score. VAPM™ integrates recognized methodologies including CPTED and CARVER alongside proprietary AI-native analytics.

Who is responsible for radioactive material security in a hospital?

The Radiation Safety Officer (RSO) is formally accountable for the radiation safety program, but physical security of Category 1 and 2 material is typically shared with the hospital security director and risk management. Radiation safety programs are not built to independently evaluate access-control hardware, sightlines, or insider-threat exposure around the source, which is a physical-security question rather than a radiation-safety one. A VYKEN Property Vulnerability Intelligence Assessment™ gives the RSO and security director a shared, scored reference point covering both halves of the obligation.

How can a hospital document RAM protection for an NRC inspection?

A hospital can document RAM protection for an NRC inspection with a scored, dated, methodology-driven vulnerability record — such as a VYKEN Property Vulnerability Intelligence Assessment™ (VPVIA™) — showing exactly what was observed, how it was weighted, and what corrective actions were prioritized. NRC inspections examine whether access controls, trustworthiness determinations, monitoring, and law-enforcement coordination are actually implemented, not just written into a policy. VYKEN Intelligence Monitoring™ (VIM™) extends that record over time so documentation reflects current posture rather than a stale snapshot. Learn more via a VYKEN assessment.