SHIN-NY Annual Renewal: The Complete Step-by-Step Guide for New York Home Health Agencies
How-To Guide

SHIN-NY Annual Renewal: The Complete Step-by-Step Guide for New York Home Health Agencies

SHIN-NY annual renewal is the compliance event that most New York home health agencies handle reactively — receiving the renewal notice from their RHIO and scrambling to update documentation that…

SHIN-NY annual renewal is the compliance event that most New York home health agencies handle reactively — receiving the renewal notice from their RHIO and scrambling to update documentation that should have been maintained continuously throughout the year. The agencies that handle renewal smoothly are the ones that treat it as a 12-month process with a structured annual submission event, not a one-time annual exercise. The agencies that struggle are the ones whose CSPP reflects the security programme they had two years ago rather than the programme they have today.

I have reviewed hundreds of SHIN-NY renewal submissions across all four New York RHIOs. The most common reasons submissions are returned for revision: the CSPP has not been updated to reflect the 2026 HIPAA mandatory requirements (MFA enforcement, biannual vulnerability scanning, annual penetration testing); the training records referenced in the CSPP are from the prior compliance year; the technical contact information listed in the SCPA is out of date; and the incident response section does not include RHIO-specific notification procedures. Every one of these is preventable with year-round maintenance.

This guide covers the complete annual renewal process — from the 12-month preparation calendar through the four-step submission sequence — and adds what most renewal guides omit: the specific rejection reasons that each RHIO issues most frequently, and the exact steps for responding when your submission is returned for clarification.

The Renewal Timeline: When to Start

SHIN-NY annual renewal notices are typically issued 60–90 days before the agency's renewal date. The renewal date varies by RHIO and by when the agency originally enrolled. Do not wait for the renewal notice to begin preparation. The documentation you submit for renewal should reflect your current, active compliance programme — which means it needs to be maintained throughout the year, not assembled in response to a deadline.

Recommended annual renewal calendar: Month 1 after prior renewal — confirm CSPP reflects all current security controls and regulatory requirements. Month 6 — conduct mid-year CSPP review; update any sections reflecting operational changes (new technology, staff changes, telehealth additions). Month 10 — complete the annual update cycle; ensure penetration test and biannual vulnerability scan results are documented; confirm training completion records are current. Month 11 — submit renewal documentation to your RHIO. Month 12 — complete SCPA re-execution.

Step 1: CSPP Review and Update

The Cybersecurity Policies and Procedures Programme is the foundation of your SHIN-NY compliance submission. For annual renewal, the CSPP must reflect:

       All current security controls — if you have deployed new technology, changed vendors, or modified processes since the last renewal, the CSPP must reflect the current state

       The 2026 HIPAA mandatory requirements — if your CSPP was written before the 2026 update, it must be updated to document MFA enforcement mechanism (not just availability), biannual vulnerability scanning with documented results, and annual penetration testing by a qualified third party

       Current staff and contact information — the HIPAA Security Officer named in the CSPP, the technical contact, and the executive sponsor must be current; a CSPP that names a staff member who left six months ago is a guaranteed clarification request

       Current incident response procedures including RHIO notification — if your incident response plan has been updated since the last renewal, the CSPP must reflect the current version, and the RHIO-specific notification contact and timeline must be explicitly stated

       Current technology asset inventory — the 2026 HIPAA mandatory update requires a documented inventory of all hardware and software touching ePHI; RHIO reviewers increasingly expect this to be referenced or attached

Step 2: Compliance Evidence Assembly

Your CSPP describes your security programme. Renewal reviewers at most RHIOs also require evidence that the programme described is actually implemented. Assemble the following before submitting your renewal:

       Vulnerability scan report — most recent scan results, dated within the past six months, with a summary of findings and remediation status. The scan must cover systems that access SHIN-NY data.

       Penetration test documentation — scope, date, conducting firm credentials, findings summary, and remediation status for the most recent annual test. The 2026 HIPAA mandatory requirement specifies the test must be conducted by a qualified party — ensure the conducting firm's credentials are documented.

       Security awareness training completion records — evidence that all workforce members with SHIN-NY data access completed training in the current compliance year, with individual completion records or aggregate summary with completion dates.

       MFA enforcement evidence — a configuration screenshot or vendor attestation confirming MFA is enforced on all accounts accessing SHIN-NY data. "MFA is available" is not sufficient; enforcement through conditional access policy or equivalent mechanism must be documented.

       Technology asset inventory — a current list of all hardware and software that accesses SHIN-NY data, with the date of last update.

Step 3: SCPA Re-Execution

The Security Compliance Plan and Agreement is the executed agreement between your agency and your RHIO confirming your compliance with SHIN-NY security requirements. The SCPA must be re-executed annually — typically by the agency's executive director or a designee with signing authority, and countersigned by the RHIO. The SCPA renewal process varies by RHIO: some use an electronic signing process; others require wet signature on a physical document. Confirm the current process with your RHIO participant services contact before the renewal deadline.

Before signing the SCPA, review it carefully for any sections that reference specific security controls the agency must maintain. Signing the SCPA is an attestation that these controls are in place. If any control listed in the SCPA is not currently implemented, address the gap before signing rather than signing an inaccurate attestation. RHIO compliance reviewers who discover during a subsequent audit that an SCPA attestation was inaccurate treat this as a more serious compliance finding than a gap that was disclosed proactively.

Step 4: Submission and Follow-Up

Submit your renewal documentation — updated CSPP, compliance evidence, and re-executed SCPA — through your RHIO's designated submission channel before the renewal deadline. Confirm receipt with your RHIO participant services contact within 48 hours of submission. If you do not receive a confirmation within five business days, follow up proactively — submissions that were not received are as consequential as submissions that were not made.

After submission, maintain active communication with your RHIO participant services contact throughout the review period. Most RHIOs will reach out with clarification requests rather than returning a submission without notice. Responding to clarification requests within the RHIO's specified response window — typically five business days — is essential for keeping the review timeline on track for renewal before the deadline.

The Most Common RHIO Rejection Reasons — By RHIO

Understanding why submissions are returned for revision before you submit is the most efficient way to avoid revision cycles. Based on ShieldForce's experience supporting SHIN-NY renewal submissions across all four New York RHIOs, the following rejection reasons are most consistently cited.

Healthix (New York City, Long Island, Hudson Valley)

Healthix has the most detailed CSPP review process of the four RHIOs and generates the highest rate of clarification requests among first-time and lapsed submitters. The four most common Healthix rejection reasons:

       MFA documentation describes availability rather than enforcement: Healthix reviewers specifically ask for the enforcement mechanism — a conditional access policy configuration, an identity platform setting, or an equivalent technical control that makes MFA mandatory. "Staff are encouraged to use MFA" and "MFA is available through Microsoft Authenticator" are both insufficient. "MFA is enforced through Microsoft Conditional Access Policy applied to all accounts with access to SHIN-NY data, with no exceptions" satisfies the requirement.

       Risk assessment date exceeds 12 months at time of submission: Healthix confirms that the risk analysis referenced in the CSPP was completed within the past 12 months. A risk analysis dated 14 months before the submission date generates an automatic clarification request regardless of the quality of the document itself.

       Incident response section does not name Healthix or describe the RHIO notification process: Generic incident response language that describes notification to "relevant authorities" or "as required by applicable regulations" does not satisfy Healthix's requirement for RHIO-specific notification procedures. The CSPP must name Healthix, state the 72-hour notification timeline, and identify the current Healthix security incident contact.

       Technology asset inventory referenced but not attached when requested: Healthix increasingly requests the technology asset inventory as supporting documentation. If the CSPP references an inventory, be prepared to attach it or provide it within the five-business-day response window.

HealtheConnections (Central New York)

HealtheConnections has a more flexible CSPP template than Healthix but applies similarly rigorous standards in review. The two most common HealtheConnections rejection reasons:

       Training records that describe a training session without individual completion documentation: HealtheConnections accepts aggregate training completion summaries but expects them to include total enrolled users, completion count, and completion date — not just a description of the training content. A statement that "annual training was completed in October 2025" without numbers does not satisfy the documentation standard.

       Penetration test documentation that does not identify the conducting firm or the firm's qualifications: HealtheConnections is attentive to the 2026 HIPAA mandatory requirement that penetration testing be conducted by a "qualified party." A penetration test report that does not identify the testing firm and their relevant credentials generates a clarification request.

Hixny (Capital Region, Hudson Valley, Southern Tier)

Hixny reviewers are particularly attentive to whether the CSPP accurately reflects current operations rather than aspirational future programme state. The most common Hixny rejection reason:

       CSPP describes controls the agency plans to implement rather than controls currently in place: Hixny's review approach looks for language that signals future intent ("we will implement MFA" rather than "MFA is enforced") and requests clarification on whether the control is implemented or planned. The CSPP should only describe controls that are currently operational. Planned controls should be addressed separately as part of the risk management plan, not presented in the CSPP as if they are in place.

Rochester RHIO (Western New York)

The Rochester RHIO has the most detailed SCPA self-assessment component and the most specific technical integration documentation requirement. The most common Rochester RHIO rejection reason:

       Technical integration documentation does not describe the security of the connection between the agency's systems and the RHIO network: Rochester RHIO specifically asks how the SHIN-NY data connection is secured — the TLS version, the authentication mechanism, and any monitoring of the connection for security events. This requirement is more specific than what other RHIOs ask and is frequently missing from submissions by agencies accustomed to other RHIOs' requirements.

What to Do When Your Renewal Is Returned for Clarification

A clarification request from a RHIO is not a rejection — it is an invitation to provide additional information or to correct a specific gap before the review is completed. Handling clarification requests effectively requires speed, specificity, and a collaborative approach with the RHIO reviewer.

Step 1: Acknowledge Immediately

Contact your RHIO participant services contact within 24 hours of receiving a clarification request — even if your substantive response will take longer to prepare. Acknowledging receipt and confirming your intent to respond within the specified window demonstrates the responsiveness that RHIO reviewers look for. An unacknowledged clarification request that sits for three days before response signals disorganisation that reflects on the CSPP's credibility.

Step 2: Address Each Point Specifically

Clarification responses should address each requested item specifically and completely. Do not respond to a request for MFA enforcement evidence with a general description of your security programme — provide the specific configuration screenshot or vendor attestation that the reviewer asked for. RHIO reviewers who receive general responses to specific questions issue follow-up requests that further delay the review timeline.

Step 3: Update the CSPP Simultaneously

When a clarification request reveals a genuine gap in the CSPP — a section that was inaccurate, incomplete, or insufficiently specific — update the CSPP alongside the clarification response. Submit the updated CSPP with the clarification response, not as a separate future submission. Demonstrating that the agency updated its programme documentation in response to the reviewer's feedback is the most favourable signal a clarification response can send.

Step 4: If Renewal Is Suspended or Access Is Threatened

In the rare case where a RHIO indicates that continued access may be suspended due to renewal deadline failure or significant compliance gaps identified during review, engage your RHIO participant services contact immediately for a direct conversation — not just email correspondence. Most RHIOs have accommodation processes for agencies that are actively engaged in remediation and are making good-faith efforts to complete renewal. An agency that has communicated proactively throughout the process, acknowledged gaps honestly, and demonstrated active remediation is in a significantly better position than one that missed deadlines without communication.

 

ShieldForce manages the complete SHIN-NY annual renewal process for New York home health clients — CSPP updates that reflect the 2026 HIPAA mandatory requirements, evidence assembly, SCPA coordination, and clarification response management — ensuring renewal completion well before RHIO deadlines and handling every outcome including clarification requests and revision cycles. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#How-To Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.