New York home healthcare agencies operate in the most complex cybersecurity compliance environment of any state in the country. Three distinct legal frameworks create overlapping — and sometimes diverging — obligations for the same underlying security activities. Navigating all three without a clear map leads to either compliance gaps or redundant effort.
This guide maps each framework's requirements, identifies where they overlap, where they diverge, and how to build a single compliance program that satisfies all three efficiently.
The Three Frameworks
Framework 1: HIPAA Security Rule (Federal)
The Health Insurance Portability and Accountability Act applies to all covered entities — which includes home health agencies transmitting ePHI in standard electronic transactions — and their business associates.
The HIPAA Security Rule requires a comprehensive set of administrative, physical, and technical safeguards for all electronic protected health information. The 2026 update made several previously "addressable" safeguards mandatory, including encryption and MFA.
OCR enforces HIPAA. Penalties range from $100 to $50,000 per violation, with annual caps up to $1.9 million for willful neglect.
Jurisdiction: All ePHI in your organization — every system, device, and process.
Framework 2: NY SHIELD Act (State)
The New York Stop Hacks and Improve Electronic Data Security Act, effective March 2020, requires any person or entity that owns or licenses "private information" of New York residents to implement a reasonable data security program.
The SHIELD Act defines "private information" broadly — it includes not just Social Security numbers and financial account data but also usernames and passwords for online accounts, and biometric data. For a home health agency, virtually all patient data qualifies.
The NY AG enforces the SHIELD Act. The enforcement standard is "reasonable security" which is calibrated to the size and nature of the organization and the sensitivity of the data.
Jurisdiction: Private information of New York residents — which for a home health agency means essentially all patient data.
Framework 3: SHIN-NY Participation Requirements (State Program)
SHIN-NY participation requirements are not a statute — they are contractual obligations in the RHIO participation agreement. But because SHIN-NY participation is effectively a condition of Medicaid reimbursement and referral relationships for most NY home health agencies, the participation requirements have practical mandatory force.
The SHIN-NY technical requirements — CSPP, MFA, encryption, audit logging, vulnerability management, incident reporting — are enforced by the RHIOs, which can suspend or terminate access for non-compliant participants.
Jurisdiction: Systems and data flows connected to SHIN-NY participation.
Where the Three Frameworks Overlap
The good news is that the three frameworks have extensive overlap. A requirement that satisfies HIPAA typically satisfies both SHIN-NY and SHIELD Act for the same activity.
| Requirement | HIPAA | SHIN-NY | SHIELD Act |
|---|---|---|---|
| Risk analysis | Required | Required (SHIN-NY scoped) | Implied by "reasonable security" |
| Written security program | Required | Required (CSPP) | Required |
| MFA | Required (2026) | Required | Implied for sensitive systems |
| Encryption at rest and in transit | Required (2026) | Required | Required for "private information" |
| Incident response plan | Required | Required | Required |
| Breach notification to regulators | Required (OCR, 60 days) | Required (RHIO, 24–72 hours) | Required (NY AG, "expedient") |
| Breach notification to individuals | Required (60 days) | N/A | Required ("expedient") |
| Workforce training | Required | Required | Implied |
| Vendor management (BAAs) | Required (BAAs) | Required for licenses | — |
Where the Three Frameworks Diverge
Breach Notification Timelines
This is the most practically significant divergence across the three frameworks:

