Healthix is the largest New York RHIO by patient population, serving New York City's five boroughs, Long Island, and portions of the Hudson Valley. The breadth and complexity of the markets it serves are reflected in its CSPP review process — which is the most comprehensive and detailed of the four New York RHIOs. Home health agencies that submit CSPPs to Healthix expecting the same review experience as smaller RHIOs typically encounter clarification requests, resubmission requirements, and extended timelines that they were not prepared for. The agencies that complete the Healthix CSPP process smoothly are the ones that understand what Healthix specifically requires — not just what a generic SHIN-NY CSPP should contain.
The Healthix CSPP Structure: What Makes It Different
The Healthix CSPP template is more prescriptive than the templates used by other New York RHIOs. Where some RHIOs accept a narrative security programme document that addresses the required content areas in the organisation's own format, Healthix expects submissions that follow its template structure closely, with each section addressing specific questions in a specific sequence. Deviating significantly from the template structure — even with a substantively complete and accurate programme description — results in clarification requests that delay approval.
Obtain the current Healthix CSPP template directly from your Healthix participant services contact before beginning your CSPP development or update. The template is updated periodically, and using an older version of the template creates avoidable revision requirements. Confirm the current version date when you receive the template.
Required Content Areas: Section by Section
Section 1: Organisational Information and Security Programme Overview
This section requires the organisation's legal name (as registered with Healthix), the primary contact for CSPP-related correspondence (with direct phone and email), the HIPAA Security Officer name and title, and a brief description of the organisation's security programme framework — referencing the NIST CSF, the HIPAA Security Rule, or another recognised framework as the foundation. The Security Officer information must match the designation documentation in the HIPAA compliance programme.
Section 2: Risk Assessment and Management
Describe the organisation's risk assessment process: the frequency of risk assessments (annually plus when significant operational changes occur), the methodology used (referencing the HIPAA Security Rule risk analysis requirements), and the process for implementing risk management measures based on assessment findings. Include the date of the most recent risk assessment. Healthix reviewers check that the risk assessment date falls within the past 12 months — a risk assessment dated more than 12 months ago at the time of submission will generate a clarification request.
Section 3: Access Controls and Authentication
This is the section most commonly requiring revision at Healthix. The required content: description of how user access to SHIN-NY data is provisioned (role-based, documented by named roles); confirmation that MFA is enforced (describing the enforcement mechanism — conditional access policy, application-level enforcement, or equivalent); description of the access review process (frequency, documentation format, responsible party); and the process for terminating access when staff leave or change roles. "MFA is available to staff" does not satisfy this section. "MFA is enforced through Microsoft Conditional Access Policy for all accounts accessing SHIN-NY data, with no exceptions permitted" does.
Section 4: Incident Response and RHIO Notification
Healthix requires that the CSPP specifically describe the RHIO notification process — the timeframe within which Healthix will be notified of a security incident involving SHIN-NY data (72 hours is the current standard), the Healthix contact information used for notification, and the content of the initial notification. This section must reference Healthix by name, not just describe a generic incident notification process. Generic incident response plans that were not written for SHIN-NY do not satisfy this requirement.
The Most Common Reasons Healthix Returns CSPPs for Revision
• MFA documentation that describes availability rather than enforcement
• Risk assessment date that exceeds 12 months at time of submission
• Incident response section that does not specifically name Healthix or describe the RHIO notification process
• Technology asset inventory referenced in the CSPP but not attached as a supporting document when requested
• CSPP submitted without the executed SCPA — Healthix requires both documents to be submitted together for initial review
Protecting your New York home health agency does not have to be complicated. It has to be done — completely, correctly, and documented in a way that holds up when it matters. ShieldForce makes that possible for organisations without IT departments, without compliance staff, and without the budget of a hospital system. Start with a free assessment.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

