SHIN-NY Onboarding for New York Home Health Agencies: What to Expect in the First 90 Days
How-To Guide

SHIN-NY Onboarding for New York Home Health Agencies: What to Expect in the First 90 Days

New SHIN-NY participants consistently underestimate the documentation intensity of the onboarding process. The agencies I have seen complete onboarding smoothly — in 60 days or less — are the ones…

New SHIN-NY participants consistently underestimate the documentation intensity of the onboarding process. The agencies I have seen complete onboarding smoothly — in 60 days or less — are the ones that had a complete HIPAA compliance programme in place before applying for SHIN-NY participation and who approached the CSPP development process with an understanding of what the RHIO reviewers are looking for. The agencies that take 90–150 days are typically those approaching SHIN-NY as the first formal security compliance project their organisation has undertaken, or those who submitted a CSPP that did not reflect current implemented controls and needed multiple revision cycles.

This guide maps the realistic SHIN-NY onboarding timeline for a New York home health agency starting from a position of reasonable HIPAA compliance maturity — an existing security programme that may not be documented to CSPP standards but that reflects genuine implementation of core security controls.

Pre-Onboarding Preparation: The Foundation That Determines Onboarding Speed

The most important determinant of SHIN-NY onboarding speed is the state of the organisation's underlying security programme before the CSPP development process begins. A CSPP is a documentation of a security programme — it cannot create a compliant security programme where one does not exist. An agency that attempts to write a CSPP without first implementing the controls the CSPP will describe creates a document that RHIO reviewers will question during compliance review.

Pre-onboarding preparation should confirm that the following are in place before CSPP development begins: a current HIPAA risk analysis (within the past 12 months); MFA enforced on all accounts with access to clinical systems; device encryption verified on all devices accessing patient data; a designated HIPAA Security Officer with an active compliance programme role; and a documented incident response plan. These are the controls that CSPP reviewers will ask about most specifically. Having them in place before the CSPP is written means the CSPP accurately describes the current state of the programme.

Days 1–30: CSPP Development and Internal Review

CSPP development begins with understanding the template requirements of your specific RHIO. Request the current CSPP template from your RHIO participant services contact and review it thoroughly before writing a single line of the CSPP. Map each required content area to the corresponding element of your current security programme. Identify any gaps — sections the template requires that your current programme does not address — and address those gaps before the CSPP is finalised. A CSPP submitted with acknowledged gaps generates clarification requests that are more damaging to the review timeline than taking the time to close the gaps before submission.

Internal review of the draft CSPP by the HIPAA Security Officer and the executive director (or an equivalent leadership sponsor) should confirm that the document accurately describes current practice, not aspirational future practice. The Security Officer should be prepared to speak knowledgeably about every section of the CSPP in a follow-up conversation with RHIO compliance staff.

Days 30–60: CSPP Submission and RHIO Review

Submit the CSPP and SCPA together to your RHIO through the designated submission channel. Confirm receipt with your participant services contact within 48 hours of submission. The RHIO review period for initial CSPP submissions varies: Healthix typically takes 3–6 weeks; HealtheConnections, Hixny, and Rochester RHIO typically take 2–4 weeks. During the review period, be prepared to respond quickly to clarification requests — a 5-business-day response window is standard, and delays in responding to clarifications extend the overall review timeline correspondingly.

Days 60–90: SCPA Execution and Technical Integration

Following CSPP approval, the SCPA is executed — typically requiring signature by an executive with authority to bind the organisation (executive director, CEO, or equivalent). Some RHIOs require countersignature within a defined period; confirm the countersignature timeline with your participant services contact to avoid inadvertent expiration of the approval. Technical integration — connecting your EHR or configuring portal access — is coordinated with the RHIO's technical team following SCPA execution.

 

Protecting your New York home health agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

View SHIN-NY Readiness Checklist — shieldforce.io/shin-ny/readiness-checklist

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

 

Share this post

Topics

#How-To Guide#How-To-Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.