SHIN-NY 2026: What New York Home Health Agencies Must Know About Recent Requirement Updates
Regulatory

SHIN-NY 2026: What New York Home Health Agencies Must Know About Recent Requirement Updates

SHIN-NY's cybersecurity requirements for participating home health agencies have continued to evolve through 2025 and into 2026, driven by two parallel forces: the 2026 HIPAA Security Rule mandatory updates, which raised the baseline security standard that SHIN-NY compliance reviewers expect to see documented;

SHIN-NY's cybersecurity requirements for participating home health agencies have continued to evolve through 2025 and into 2026, driven by two parallel forces: the 2026 HIPAA Security Rule mandatory updates, which raised the baseline security standard that SHIN-NY compliance reviewers expect to see documented; and the RHIOs' own increasing sophistication in conducting compliance reviews, as their compliance teams have developed more specific expectations for CSPP content, evidence of implementation, and the technical integration standards that support participation.

New York home health agencies with CSPPs that were last updated in 2023 or early 2024 are operating with documentation that does not reflect the current compliance environment. The practical consequence is RHIO compliance review findings at annual renewal — a finding that delays renewal, creates conditional compliance status, and in some cases temporarily suspends RHIO access while remediation is completed. Updating before renewal is always preferable to remediating after a finding.

This article covers what changed, what each RHIO now expects, a structured 15-minute CSPP gap assessment you can conduct today, and the realistic transition timeline for bringing a pre-2026 CSPP current.

The 2026 HIPAA Mandatory Requirements and Their SHIN-NY CSPP Implications

The six new mandatory requirements that the 2026 HIPAA Security Rule introduced must now be reflected in every SHIN-NY participant's CSPP. RHIOs conducting compliance reviews in 2026 expect to see these requirements either documented as implemented or, if not yet implemented, identified with a specific remediation timeline. Here is what each requirement means for your CSPP specifically.

1. Multi-Factor Authentication

The CSPP must describe how MFA is enforced — not just available — for all accounts with access to SHIN-NY data. The critical distinction: "MFA is available through Microsoft Authenticator" describes availability. "MFA is enforced through Microsoft Conditional Access Policy requiring MFA for all accounts accessing SHIN-NY data, with no exceptions" describes enforcement. RHIO reviewers — particularly Healthix — will specifically flag the first formulation and request clarification. Update the CSPP to describe the enforcement mechanism, the identity platform used, and the coverage scope.

2. Encryption at Rest and in Transit

The CSPP must confirm that all devices storing SHIN-NY data have verified encryption at rest (full disk encryption confirmed through MDM compliance report) and that all data transmitted to and from RHIO systems uses TLS 1.2 or higher. If your CSPP currently describes encryption in general terms without specifying the mechanism and the verification process, update it to include both.

3. Biannual Vulnerability Scanning

The CSPP must describe the vulnerability scanning programme: the frequency (biannual minimum), the scanning tool or service used, the scope (which systems are covered), and the process for reviewing findings and tracking remediation. Reference the date of the most recent scan and confirm findings have been addressed. If your CSPP does not currently include a vulnerability scanning section, add one — and have the first scan completed before your next renewal submission.

4. Annual Penetration Testing

This is the requirement most commonly missing from CSPPs submitted in 2026. The CSPP must describe the penetration testing programme: the annual frequency, the qualification requirement for the testing firm (OSCP-certified tester or equivalent), the scope of the test (external and internal), and the process for acting on findings. If your agency has not yet conducted its first annual penetration test under the 2026 mandatory standard, this should be your immediate priority — both for HIPAA compliance and for SHIN-NY CSPP currency.

5. Technology Asset Inventory

The CSPP must reference a current technology asset inventory that documents all hardware and software with access to SHIN-NY data. This inventory is increasingly requested as supporting evidence during RHIO compliance reviews. The inventory should include: device name or type, the SHIN-NY data it accesses, the access mechanism, and the date last verified. Update the CSPP to reference the inventory and be prepared to attach it or provide it within the RHIO's response window if requested.

6. Documented Incident Response Plan With RHIO Notification

The CSPP must document an incident response plan that specifically includes RHIO notification procedures: the 72-hour notification timeline, the current RHIO security incident contact for your specific RHIO, and the content of the initial notification. Generic incident response language that references "appropriate authorities" does not satisfy this requirement. The CSPP must name the RHIO, state the timeline, and provide the contact — confirm the current contact with your RHIO participant services representative before finalising the CSPP update.

RHIO-Specific Changes in 2026

Healthix

Healthix has updated its CSPP template to explicitly require documentation of MFA enforcement mechanism (not just implementation), biannual vulnerability scanning evidence, and confirmation that the technology asset inventory is current. Submissions that do not address these items receive clarification requests that extend the review timeline by 30–45 days. Healthix is also increasingly requesting the technology asset inventory as an attachment to the CSPP submission rather than accepting a reference to an internal document.

HealtheConnections

HealtheConnections has not updated its formal CSPP template as of June 2026, but its compliance review team is applying standards consistent with the 2026 HIPAA update. Agencies submitting 2026 renewals to HealtheConnections should include the 2026 mandatory control documentation even if the template does not explicitly request it — proactive inclusion prevents post-submission clarification requests. HealtheConnections also offers a pre-submission CSPP review service through its participant services team — worth using for agencies updating their CSPP for the first time under the 2026 standards.

Hixny

Hixny reviewers are specifically attentive to whether the CSPP reflects currently implemented controls rather than planned or aspirational ones. The 2026 update has sharpened this focus: a CSPP that describes MFA enforcement as something the agency "plans to implement" will be returned with a clarification request asking for the implementation date and evidence. Update your CSPP only to reflect controls that are currently operational, and address planned controls through the risk management plan rather than the CSPP body.

Rochester RHIO

Rochester RHIO maintains the most detailed technical integration documentation requirement. The 2026 update has added an expectation that the technical integration section of the CSPP specifically addresses the security of the connection between the agency's systems and the RHIO network in the context of the 2026 mandatory controls — confirming that TLS 1.2 or higher is in use for the RHIO connection, that MFA is enforced for accounts that access SHIN-NY data through the integrated connection, and that the connected systems are included in the biannual vulnerability scanning scope.

The 15-Minute CSPP Gap Assessment

Pull up your current CSPP and answer these six questions. Each "no" or "I'm not sure" is a section that requires updating before your next renewal submission.

       MFA section: Does the CSPP describe MFA enforcement through a named mechanism (conditional access policy, identity platform setting) rather than just MFA availability? Does it confirm that all accounts with SHIN-NY data access are covered with no exceptions?

       Encryption section: Does the CSPP confirm full disk encryption on all devices that access SHIN-NY data, with verification through MDM compliance reports? Does it confirm TLS 1.2 or higher for the RHIO connection?

       Vulnerability scanning section: Does the CSPP describe biannual scanning, name the scanning tool or service, specify the systems covered, and reference the date of the most recent scan with remediation status?

       Penetration testing section: Does the CSPP describe annual penetration testing by a qualified party (with credentials specified), covering both external and internal scope, with a process for acting on findings? If not, does this section exist at all?

       Technology asset inventory: Does the CSPP reference a current technology asset inventory? If Healthix is your RHIO, is the inventory ready to be attached to your next submission?

       Incident response — RHIO notification: Does the CSPP name your specific RHIO, state the 72-hour notification timeline, and provide the current RHIO security incident contact? If any of these three elements are missing, the incident response section is insufficient regardless of how complete the rest of it is.

If you answered "no" or "I'm not sure" to any of the six questions, note the section number, the specific gap, and the evidence you need to gather before revising that section. Do not revise the CSPP based on what you plan to do — revise it to reflect what is currently in place, and implement anything that is not yet in place before the revision.

The Transition Timeline for Pre-2026 CSPPs

For agencies whose CSPPs were last updated before the 2026 HIPAA mandatory requirements took effect, the update process should follow a specific sequence that avoids the most common mistake: revising the CSPP before the underlying controls are implemented, producing documentation that does not reflect reality.

Phase 1: Implement Before Documenting (Weeks 1–4)

Before opening the CSPP to revise it, implement the controls that are currently missing. MFA enforcement is the highest priority — it is the most commonly cited RHIO clarification request and the most foundational control. If MFA is available but not enforced through a conditional access policy, configure the enforcement now. Biannual vulnerability scanning is the second priority — schedule and complete the first scan under the new frequency standard so you have current scan results to reference in the updated CSPP. Annual penetration testing, if not yet completed under the 2026 standard, should be scheduled during this phase and completed before the CSPP update is submitted.

Phase 2: Assemble Evidence (Week 3–4)

While the controls are being implemented, assemble the evidence that the updated CSPP will reference: the MFA enforcement configuration screenshot or vendor attestation; the vulnerability scan report with findings and remediation status; the penetration test report and remediation tracking document; the technology asset inventory with last-verified date; and the training completion records for the current compliance year. Having this evidence in hand before writing the CSPP update ensures that every claim in the document is documentable.

Phase 3: Revise the CSPP (Week 5–6)

With controls implemented and evidence assembled, revise the CSPP to reflect the current, verified state of the security programme. Address each of the six gap assessment questions. Confirm the incident response section names your specific RHIO and includes the current security incident contact. Update all staff contact information, technology references, and vendor relationships to reflect current state. Date the revision clearly and retain the prior version — HIPAA requires six-year retention of all security programme documentation, including superseded versions.

Phase 4: Submit and Monitor (Week 7–8)

Submit the updated CSPP to your RHIO at least 30 days before your renewal deadline — not because the RHIO requires 30 days of review time, but because this buffer accommodates any clarification requests without timeline pressure. Monitor for acknowledgement within 5 business days and respond to any clarification requests within the RHIO's specified window.

ShieldForce manages the complete SHIN-NY CSPP update process for New York home health clients — implementing the 2026 mandatory controls, assembling the evidence portfolio, revising the CSPP to reflect current implemented controls, and coordinating submission with the relevant RHIO. Agencies that engage ShieldForce before their next renewal deadline complete the update process with confidence and without the clarification request cycles that delay renewal for agencies managing the process independently. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

  

Share this post

Topics

#Regulatory#How-To Guide#How-To-Guide#Compliance
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.