SHIN-NY RHIO Comparison: Hixny vs. Rochester RHIO vs. HealtheConnections vs. Healthix
SHIN-NY

SHIN-NY RHIO Comparison: Hixny vs. Rochester RHIO vs. HealtheConnections vs. Healthix

6 min read
SF
Obi Ibeto

New York's four RHIOs — Hixny, Rochester RHIO, HealtheConnections, and Healthix — each have specific SHIN-NY compliance processes. Here's what home health agencies need to know about each one.

Every New York home health agency participating in SHIN-NY does so through one of four Regional Health Information Organizations. Which RHIO your agency works with depends on your geographic location — and that matters for compliance, because each RHIO has its own documentation formats, renewal processes, timeline requirements, and technical assistance offerings.

Understanding the RHIO-specific requirements for your organization — rather than treating SHIN-NY as a uniform statewide standard — is the difference between a smooth compliance process and a frustrating one.

This guide compares the four RHIOs on the dimensions that matter most for home health agency compliance officers: geographic coverage, CSPP documentation format, SCPA renewal timeline, incident notification process, and available support resources.

The Four New York RHIOs: Geographic Coverage

Hixny (Health Information Xchange of New York)

Serves the Capital Region, Hudson Valley, and parts of the Southern Tier. Coverage area includes Albany, Schenectady, Troy, Saratoga Springs, Poughkeepsie, Kingston, and surrounding counties. Home health agencies in these counties participate in SHIN-NY through Hixny.

Rochester RHIO

Serves the Greater Rochester region, including Monroe, Livingston, Ontario, Seneca, Wayne, and Yates counties. One of the oldest and most established RHIOs in the state, with a strong focus on care coordination across the regional health system.

HealtheConnections

Serves Central New York and surrounding areas, including Onondaga, Oswego, Madison, Cayuga, and Cortland counties, as well as portions of the Southern Tier. Syracuse-based agencies participate through HealtheConnections.

Healthix

The largest RHIO by patient population, serving New York City's five boroughs, Long Island, and the Hudson Valley south of the Capital Region. Home health agencies serving patients in the five boroughs, Nassau, Suffolk, Westchester, Rockland, Putnam, and Orange counties participate through Healthix.

CSPP Documentation: What Each RHIO Requires

All four RHIOs require a Cybersecurity Policies and Procedures Program document as a condition of SHIN-NY participation. The substantive requirements are consistent — they align with HIPAA Security Rule standards across all four RHIOs. The differences are in format, submission process, and review intensity.

Hixny: Requires submission of the CSPP document as part of onboarding and annual renewal. Provides a template framework that new participants can use as a starting point. Renewal process involves a self-attestation form confirming the CSPP remains current, supplemented by the updated CSPP document for organizations that have experienced significant changes.

Rochester RHIO: Has one of the most detailed CSPP review processes among the four RHIOs, reflecting its emphasis on clinical data quality and participant accountability. The CSPP must address specific Rochester RHIO technical integration requirements in addition to the standard SHIN-NY content areas. New participants should budget additional time for the initial CSPP review.

HealtheConnections: Provides a structured CSPP template that participants can complete and submit. The template is regularly updated to reflect current HIPAA and SHIN-NY requirements. HealtheConnections offers technical assistance sessions for organizations that need support completing the CSPP — a resource that smaller home health agencies should take advantage of.

Healthix: As the RHIO serving the highest-volume, highest-complexity market (NYC and Long Island), Healthix has developed robust compliance documentation and review processes. The CSPP submission includes specific sections addressing the multi-site and multi-provider complexity typical of the NYC home health market. Healthix has a dedicated compliance team that reviews CSPPs for completeness and technical adequacy.

SCPA Renewal: Timelines and Processes

Annual renewal is required by all four RHIOs. The Security Compliance Plan and Agreement must be renewed with an updated attestation each year. However, the specific timing and process differ:

Hixny: Renewal cycle tied to the anniversary of initial SCPA execution. Organizations receive renewal notices approximately 60 days before expiration. The renewal requires executive signature on an updated attestation form and confirmation that the CSPP remains current.

Rochester RHIO: Renewal process includes a compliance self-assessment questionnaire in addition to the SCPA renewal form. Organizations answer specific questions about their security controls — MFA status, encryption verification, vulnerability scan completion — and these responses are reviewed against prior years for consistency.

HealtheConnections: Provides a streamlined renewal process with clear online submission tools. Renewal can typically be completed in a single session if the CSPP is current and the required attestation information is available.

Healthix: Given the volume of participants it serves, Healthix has developed a systematic renewal management process with staggered renewal dates and proactive outreach to participants approaching expiration. Healthix participants who miss renewal deadlines may experience temporary access restrictions until renewal documentation is submitted.

Incident Notification: RHIO-Specific Requirements

All four RHIOs require notification of security incidents affecting SHIN-NY data. The notification timeframe is typically 24–72 hours for confirmed breaches, but the specific contact process varies:

Hixny: Incident notification via dedicated security incident email address with a required incident report form. Follow-up phone contact with the Hixny security team is expected for significant incidents.

Rochester RHIO: Incident notification to the Rochester RHIO Privacy and Security Officer. The initial notification should include the estimated scope of the incident and the containment status. Rochester RHIO may request a formal post-incident report within 30 days of resolution.

HealtheConnections: Incident notification via a dedicated incident reporting portal in addition to direct contact with the HealtheConnections compliance team. The portal submission creates a formal record and assigns a tracking number.

Healthix: Given the volume and complexity of the Healthix participant network, Healthix has a structured incident response protocol with specific escalation paths depending on the nature and severity of the incident. Participants should confirm the current incident notification contact information directly with Healthix, as the process has been updated as their compliance team has grown.

Technical Assistance: What Each RHIO Offers

One of the most underutilized SHIN-NY compliance resources is the technical assistance available from each RHIO. Smaller home health agencies that are working through CSPP development for the first time should actively engage with their RHIO's support resources:

Hixny: Offers scheduled compliance consultation sessions for participants who need guidance on CSPP content or the renewal process. Contact Hixny's participant services team to schedule.

Rochester RHIO: Provides educational resources and webinars for participants on SHIN-NY compliance requirements, including CSPP development guidance.

HealtheConnections: Offers one-on-one technical assistance sessions for organizations completing their initial CSPP or addressing identified compliance gaps. This is particularly valuable for small home health agencies without dedicated compliance staff.

Healthix: Maintains a compliance resource library for participants and conducts periodic educational programming on SHIN-NY requirements. The Healthix compliance team is available for direct consultation for participants navigating complex compliance questions.

ShieldForce and RHIO-Specific Compliance

ShieldForce has direct experience working with all four New York RHIOs and understands the specific documentation formats, review processes, and expectations of each. For home health agencies in any New York region, ShieldForce provides CSPP development and annual renewal support that is calibrated to your specific RHIO's requirements — not a generic template.


Get SHIN-NY compliant through your specific RHIO — with expert guidance. ShieldForce provides RHIO-specific CSPP development and annual renewal support for home health agencies across all four New York regions.

Explore SHIN-NY Compliance Solutions →

Start with a free SHIN-NY readiness assessment.

Get Your Free Assessment → | View Pricing →

Share this post

Topics

#SHIN-NY#RHIO#Hixny#Healthix#HealtheConnections#Rochester RHIO#home health#New York
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.