When a security incident potentially involves SHIN-NY health information exchange data, the notification obligations that arise are parallel to — not instead of — HIPAA notification obligations. This distinction matters because the two sets of obligations have different triggers, different timelines, different recipients, and different content requirements. Managing both simultaneously, in a coordinated way that satisfies each framework without confusion or delay, requires a pre-planned process that is documented in the incident response plan before an incident occurs.
The most common failure mode I see when home health agencies experience security incidents is SHIN-NY notification being treated as an afterthought to HIPAA notification — addressed after the HIPAA four-factor risk assessment is complete and notification decisions are made, rather than as a parallel process that begins at incident discovery. The SHIN-NY 72-hour notification clock runs from discovery, not from the completion of the HIPAA risk assessment. By the time a home health agency has completed the HIPAA four-factor assessment and determined whether a reportable breach exists — which may take several days — the SHIN-NY notification deadline may already have passed.
What Triggers the SHIN-NY Notification Obligation
The SHIN-NY notification requirement is triggered by a security incident — defined more broadly than HIPAA's breach definition — that potentially involves health information that was accessed through or is stored in systems connected to the RHIO network. The key word is "potentially": you do not need to confirm that SHIN-NY data was actually accessed or compromised before notifying the RHIO. You need to identify that the incident involved systems that have SHIN-NY connectivity or that contain data obtained through SHIN-NY queries. If those conditions are met, notify the RHIO within 72 hours of discovery, even if the HIPAA four-factor assessment has not yet been completed.
The Initial RHIO Notification: What to Include
The initial 72-hour RHIO notification should be brief, factual, and timely. Do not wait to have complete information before making the initial notification — the initial notification is intended to alert the RHIO to a potential issue, not to provide a complete incident report. Include:
• The date and approximate time of discovery
• A brief description of what is known about the nature of the incident (ransomware, credential compromise, unauthorised access — describe what is known, acknowledge what is not yet known)
• The systems or data types believed to be involved, with specific reference to whether those systems have SHIN-NY connectivity
• The immediate containment actions taken
• The primary contact for RHIO follow-up communications during the incident response
RHIO Contact Information for Incident Notification
The incident notification contact for each RHIO must be documented in your incident response plan before an incident occurs — not looked up from the RHIO website during an incident. Contacts change; confirm the current contact information with your participant services representative at least annually and update the incident response plan immediately when contact information changes.
• Healthix: Contact your assigned Healthix participant services representative for current security incident notification contact. Healthix routes security notifications through its compliance team.
• HealtheConnections: Contact your HealtheConnections participant services representative for the current security incident notification pathway. HealtheConnections maintains a separate security notification process from routine participant services inquiries.
• Hixny: Document the Hixny compliance contact obtained from your participant services relationship. Hixny routes incident notifications through its operations team with compliance team involvement for significant incidents.
• Rochester RHIO: The Rochester RHIO maintains a security incident notification contact through its compliance team — confirmed through your participant services contact.
The Post-Incident Report: What Each RHIO Expects
Following incident resolution, each RHIO expects a written post-incident report within 30 days. The report should describe: the confirmed scope of the incident; which SHIN-NY data, if any, was accessed or potentially compromised; the containment and remediation steps taken; any changes to the security programme implemented as a result of the incident; and confirmation that the SHIN-NY technical integration is restored to normal operation. This report is the documentation that demonstrates the agency's compliance with its SHIN-NY notification obligations and is reviewed during the next annual compliance cycle.
Protecting your New York home health agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

