How to Complete the Rochester RHIO CSPP for Western New York Home Health Agencies
Compliance Guide

How to Complete the Rochester RHIO CSPP for Western New York Home Health Agencies

The Rochester RHIO serves Western New York including Monroe, Livingston, Ontario, Seneca, Wayne, and Yates counties — one of the most medically integrated regional health markets in New York State,…

The Rochester RHIO serves Western New York including Monroe, Livingston, Ontario, Seneca, Wayne, and Yates counties — one of the most medically integrated regional health markets in New York State, anchored by the University of Rochester Medical Center and a network of community health organisations with strong health information exchange participation. The Rochester RHIO's CSPP review process reflects this integration culture: reviewers expect to see security programmes that are genuinely integrated into organisational operations, not compliance documents that exist separately from how the organisation actually manages data.

Of the four New York RHIOs, Rochester RHIO has the most detailed CSPP review process for the technical controls section and the only mandatory self-assessment component embedded in the SCPA. This combination means that submissions which succeed at Healthix or HealtheConnections without revision may require significant additional specificity to clear Rochester RHIO review. Agencies that have participated in other RHIOs and are adding Rochester RHIO participation, or agencies submitting their first CSPP to Rochester RHIO, should approach the submission with the specificity standards described in this guide rather than adapting a prior RHIO submission.

Obtaining the Current Rochester RHIO Template and Requirements

Contact your Rochester RHIO participant services representative to request the current CSPP template and any updated requirements before beginning your submission. Rochester RHIO updates its CSPP guidance periodically, and the current version may include requirements that were added after your last review of the template. Request the template directly rather than using a copy from a prior submission — the version date on the template confirms you are working with current requirements.

Rochester RHIO participant services representatives are genuinely helpful in the CSPP development process and are more accessible than administrators typically expect. A 30-minute call with your participant services contact to review the current template requirements and confirm any areas of ambiguity before you begin writing is a more efficient use of time than submitting a draft that comes back with multiple clarification requests. Rochester RHIO does not offer a formal pre-submission review service like HealtheConnections, but participant services contacts will answer specific questions about template requirements.

Rochester RHIO CSPP Content Requirements

Section 1: Governance and Programme Overview

Rochester RHIO requires identification of the HIPAA Security Officer by name and title, with confirmation that the Security Officer role is actively performed — not just designated. This is a nuance that distinguishes Rochester RHIO's review from other RHIOs: they ask what the Security Officer does, not just who they are. For a small home health agency where the Security Officer is also the executive director or a clinical director with multiple responsibilities, be specific about the security programme management activities the Security Officer performs: conducting the annual risk analysis, reviewing the quarterly access audit, managing the HIPAA compliance calendar, and serving as the primary contact for RHIO compliance matters.

Describe the leadership oversight of the security programme explicitly — how the executive director or board receives information about the security programme's status and exercises oversight. Rochester RHIO reviewers look for evidence that security programme governance is embedded in the organisation's normal management processes rather than operating as a standalone compliance function that leadership is not engaged with.

Section 2: Risk Assessment and Management

Rochester RHIO requires that the CSPP reference a current risk analysis completed within the past 12 months at the time of submission. Rochester RHIO is one of the RHIOs most likely to request the full risk analysis as a supporting document rather than accepting a description of the risk analysis process. Be prepared to produce the complete risk analysis — not a summary — if requested. The risk analysis must cover systems that access SHIN-NY data specifically; a general organisational risk analysis that does not address RHIO-connected systems may not satisfy the Rochester RHIO requirement.

Section 3: Technical Controls

The technical controls section is where Rochester RHIO's review is most rigorous. The CSPP must address each of the following with specificity rather than generality:

       MFA enforcement: name the identity platform, describe the enforcement mechanism, confirm the scope covers all accounts accessing SHIN-NY data, and note the date MFA enforcement was implemented or most recently verified. "We use Microsoft Authenticator" is insufficient. "MFA is enforced through Microsoft Entra ID Conditional Access Policy requiring MFA for all accounts in the [name] security group that includes all staff with SHIN-NY data access, verified in [month/year]" satisfies the requirement.

       Encryption: confirm full disk encryption on all devices accessing SHIN-NY data with the verification mechanism (MDM compliance report, specific platform) and the most recent verification date. Confirm TLS version for the RHIO connection specifically.

       Access controls: describe the role-based access framework for SHIN-NY data access — how roles are defined, how access is provisioned, how access reviews occur, and how access is terminated. Include the frequency of access reviews and the most recent review date.

       Vulnerability scanning: describe the biannual scanning programme with the scanning tool or service, scope, frequency, and most recent scan date with remediation status summary.

       Penetration testing: describe the annual testing programme with the conducting firm's qualifications, scope, most recent test date, and remediation status summary.

Section 4: Incident Response and RHIO Notification

Rochester RHIO requires that the incident response section name Rochester RHIO explicitly, state the 72-hour notification timeline, and identify the current Rochester RHIO security incident contact by name and contact information (obtained from your participant services representative). The section must also describe the content of the initial notification: the nature of the incident, the systems affected, the initial assessment of SHIN-NY data involvement, and the immediate containment actions taken.

Additionally, Rochester RHIO requires a description of the post-incident report process: the timeline (30 days from incident resolution), the content (confirmed scope, remediation steps, programme changes), and the submission process (through the Rochester RHIO participant services channel). This post-incident reporting requirement is more detailed than what most other RHIOs specify and is a common omission in first-time Rochester RHIO submissions.

The Rochester RHIO Self-Assessment: The Component That Determines Submission Success

The Rochester RHIO SCPA includes a self-assessment component that is unique among the four New York RHIOs. Where other RHIOs incorporate security requirements into the SCPA as attestations or general compliance confirmations, Rochester RHIO includes a structured self-assessment that evaluates the organisation's compliance against specific security control requirements across multiple domains. The Security Officer must complete this self-assessment accurately and the executive director must attest to its accuracy before the SCPA can be executed.

Understanding what the self-assessment covers — and what level of evidence each question requires for an accurate "yes" answer — is the foundation of completing it correctly. A self-assessment that overstates the organisation's security posture creates two problems: it produces an inaccurate SCPA attestation that Rochester RHIO may discover during a subsequent compliance review, and it creates a misrepresentation that could affect the organisation's standing with the RHIO and potentially with OCR.

Self-Assessment Domain 1: Identity and Access Management

The identity and access management domain covers MFA enforcement, unique user identification, access review frequency, and account deactivation procedures. For each question in this domain, the evidence that supports an accurate "yes" answer:

       MFA enforced on all accounts with SHIN-NY access: the conditional access policy configuration screenshot or identity platform setting that shows enforcement (not availability) for the relevant accounts

       Unique user identification with no shared accounts: a statement from the EHR or system administrator confirming that all accounts are individually assigned, with the access review log confirming no shared accounts were identified in the most recent review

       Access reviewed at least annually: the most recent access review log with the review date, the systems covered, and the findings — including both accounts confirmed appropriate and any accounts that were modified or deactivated as a result of the review

       Accounts deactivated within [timeframe] of separation: the offboarding procedure documentation and a sample record (sanitised) showing the most recent deactivation with the separation date and deactivation date

Self-Assessment Domain 2: Technical Safeguards

The technical safeguards domain covers encryption, vulnerability scanning, penetration testing, and audit logging. For each question:

       Encryption on all devices with SHIN-NY data access: the MDM compliance report or equivalent showing encryption status across the enrolled device fleet, with the report date

       Biannual vulnerability scanning conducted: the most recent scan report executive summary with the scan date and scope, plus the remediation tracking document showing finding status

       Annual penetration testing by qualified party: the penetration test report cover page showing the conducting firm, the tester credentials, the test scope and dates, and the remediation tracking document

       Audit logging enabled for SHIN-NY system access: the EHR or system configuration documentation confirming audit logging is active, with the log retention period specified

Self-Assessment Domain 3: Workforce and Training

The workforce and training domain covers security awareness training completion, incident reporting procedures, and sanctions policy. For each question:

       Annual security training completed by all staff with SHIN-NY access: the training completion report or individual completion records for the current compliance year, with the training content description and completion dates

       Staff aware of incident reporting procedures: the incident response procedure documentation that has been distributed to staff, with the distribution date — this can be the relevant section of the CSPP if it is distributed as a staff reference document

       Sanctions policy in place for security violations: the sanctions policy document with the effective date — Rochester RHIO reviewers confirm the sanctions policy is a written document, not just a general statement that violations are addressed

Completing the Self-Assessment Accurately

The most common self-assessment failure at Rochester RHIO is answering "yes" to questions where the honest answer is "partially" or "not yet" — particularly for MFA enforcement (where availability is confused with enforcement), access review frequency (where an informal annual review without documentation is treated as equivalent to a documented review), and penetration testing (where a vulnerability scan is treated as equivalent to a penetration test).

If an honest assessment of your current programme produces "no" answers in any domain, the correct approach is not to delay submission until every gap is remediated. It is to complete the self-assessment accurately, identify the gaps in the CSPP as risk management items with remediation timelines, and submit with an honest assessment and a documented remediation plan. Rochester RHIO reviewers who receive accurate self-assessments with gap acknowledgement and remediation plans respond more constructively than reviewers who discover that an "all yes" self-assessment does not match the security programme evidence.

Technical Integration Documentation: Rochester RHIO's Distinctive Requirement

Rochester RHIO's technical integration documentation requirement is more specific than what other RHIOs ask for. The CSPP must describe how the agency's systems connect to the RHIO network with enough technical specificity to confirm the security of that connection. The required content:

       Connection mechanism: whether the agency uses EHR-mediated integration (through the EHR platform's connection to the RHIO) or direct portal access, and which specific integration model is in use

       Encryption standard: the TLS version used for the RHIO connection — confirm with your EHR vendor or the Rochester RHIO technical team if you are not certain of the current TLS version in use

       Authentication mechanism: how users authenticate to the RHIO-connected system, with MFA enforcement confirmed

       Monitoring of the connection: whether and how the agency monitors the RHIO-connected systems for security events — audit log review, SOC monitoring, or equivalent

If your agency uses EHR-mediated integration, obtain written confirmation from your EHR vendor of the TLS version used for the Rochester RHIO connection and retain it as supporting documentation. Rochester RHIO may request this confirmation during review.

The Rochester RHIO Annual Renewal Process

Rochester RHIO conducts annual SCPA renewals that include a CSPP review component and a self-assessment update. The renewal notice is sent to the organisation's primary compliance contact approximately 90 days before the renewal date. The self-assessment must be completed fresh each year — not carried forward from the prior year — reflecting the current state of the organisation's security programme at the time of renewal.

The renewal process is relatively streamlined for organisations with current, well-maintained CSPPs and self-assessments. Rochester RHIO's review of renewal submissions focuses on changes since the prior submission: new technology, staff changes, programme updates, and incident history. A brief cover letter with the renewal submission describing what has changed since the prior CSPP submission — and confirming what has remained the same — signals to the reviewer that the organisation is actively managing its programme rather than submitting static documentation year over year.

 

ShieldForce manages the Rochester RHIO CSPP, self-assessment, and annual renewal process for Western New York home health clients — including the technical integration documentation, self-assessment evidence assembly, and renewal submission coordination that make Rochester RHIO participation straightforward rather than onerous. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#Compliance Guide#Compliance
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.