Audit logging is one of the most frequently cited gaps when New York home health agencies undergo SHIN-NY compliance reviews. Not because agencies don't have logs — most EHR and Microsoft 365 environments generate audit logs automatically. But because having logs and having a compliant audit log program are two different things.
SHIN-NY requires more than passive log generation. It requires documented log retention, active periodic review, and the ability to produce specific access records when requested by the RHIO or in response to a security incident. Here is exactly what that means in practice.
What SHIN-NY Requires You to Log
At minimum, your audit log program must capture the following events for any system connected to SHIN-NY:
User Authentication Events
- Successful logins: who logged in, when, from which device or IP address
- Failed login attempts: who attempted login, when, and how many failed attempts
- MFA events: successful and failed MFA challenges
- Account lockouts
Data Access Events
- Patient record views: which patient record was accessed, by whom, when
- Record searches: queries run against SHIN-NY data
- Document downloads or exports: any ePHI extracted from the system
- Record modifications: additions, edits, or deletions to patient records
Administrative Events
- User account creation, modification, and deletion
- Permission changes: role assignments, access additions or removals
- Configuration changes to SHIN-NY-connected systems
- Privileged account activity
Security Events
- Antivirus or EDR alerts and responses
- Firewall events (at the network level if applicable)
- VPN access events
- Any alerts generated by your security monitoring platform
Retention: How Long You Must Keep Logs
SHIN-NY participation requirements align with HIPAA's documentation retention standard: audit logs must be retained for a minimum of six years from the date of creation or the date they were last in effect, whichever is later.
This is a practical challenge for many home health agencies because:
- Default log retention settings in most systems are far shorter — Microsoft 365 Business Basic retains audit logs for only 90 days; Microsoft 365 Business Premium extends this to 180 days
- EHR audit logs may be retained locally on servers that are not backed up adequately
- No centralized log management system exists, meaning logs are scattered across multiple systems
For SHIN-NY compliance, you need a centralized log management approach with at least six years of retention capacity. This can be achieved through:
