SHIN-NY Audit Preparation: How to Get Ready for a RHIO Compliance Review
How-To Guide

SHIN-NY Audit Preparation: How to Get Ready for a RHIO Compliance Review

RHIO compliance reviews are no longer a rare occurrence at SHIN-NY participating home health agencies. All four New York RHIOs have expanded their compliance review programmes in response to increasing…

RHIO compliance reviews are no longer a rare occurrence at SHIN-NY participating home health agencies. All four New York RHIOs have expanded their compliance review programmes in response to increasing cybersecurity expectations from the New York State Department of Health and the influence of the 2026 HIPAA mandatory requirements on SHIN-NY compliance expectations. Agencies that approach compliance reviews as a periodic, somewhat unpredictable event rather than as a continuous compliance posture are the ones that struggle when the review arrives.

The preparation framework I recommend to every SHIN-NY participating home health agency is simple: maintain your compliance documentation as if a review could arrive tomorrow, because — with increasing RHIO compliance review frequency — it might.

What RHIO Reviewers Examine

RHIO compliance reviews for SHIN-NY participants focus on four primary areas, regardless of which RHIO is conducting the review:

       CSPP currency and accuracy: is the current CSPP on file with the RHIO the same as the CSPP the organisation is actually operating under? Has the CSPP been updated to reflect any material changes in the organisation's security programme, technology, or operations since the last submission? Does the CSPP reflect the 2026 HIPAA mandatory requirements?

       Implementation evidence: reviewers are increasingly asking for evidence that the controls described in the CSPP are actually implemented — not just described. MFA enforcement evidence (configuration screenshot or MDM compliance report), device encryption verification (MDM compliance report), and security training completion records (individual completion documentation) are the most commonly requested evidence items.

       Incident history: reviewers ask whether the organisation has experienced any security incidents since the last compliance submission and, if so, whether those incidents were reported to the RHIO per the notification requirements in the CSPP.

       Operational changes: reviewers ask whether there have been material changes in the organisation's operations, technology, or security programme since the last CSPP submission that are not reflected in the current CSPP on file. EHR platform changes, operational expansions, staff changes affecting Security Officer designation, and technology additions are the most commonly identified changes that were not reflected in submitted CSPPs.

The SHIN-NY Compliance Documentation File

Maintain a SHIN-NY compliance documentation file — separate from but consistent with the HIPAA compliance documentation file — that contains:

       The current CSPP, with version date and the last update date noted

       The executed SCPA, with execution date and renewal date noted

       The most recent RHIO approval or compliance review outcome letter

       MFA enforcement evidence, dated within the past 12 months

       Device encryption verification report, dated within the past 12 months

       Security training completion records for the current compliance year

       Biannual vulnerability scan results, with remediation status noted

       Annual penetration test documentation, with remediation status noted

       Incident log for the current compliance period — including "no incidents to report" notation if no incidents occurred

Staff Preparation for Compliance Review Conversations

RHIO compliance reviewers may request a conversation with the HIPAA Security Officer or another designated compliance contact. The person who takes this call should be genuinely familiar with the security programme — not reading from the CSPP for the first time during the call. Conduct an internal review session before the call: walk through the CSPP section by section, confirm that the current operations match what the document describes, and prepare concise answers to likely questions about MFA enforcement, incident history, and recent programme changes.

 

Protecting your New York home health agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

 

Share this post

Topics

#How-To Guide#How-To-Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.