A home health administrator in Syracuse told me recently that her agency had passed its SHIN-NY renewal without any findings and was therefore confident in its HIPAA compliance. I did not want to discourage her — the SHIN-NY renewal was a real achievement — but I had to explain the distinction that the compliance industry has not always made clearly: SHIN-NY compliance and HIPAA compliance are related but separate frameworks. Passing one does not mean passing the other. And treating them as equivalent creates gaps in both directions.
The relationship between SHIN-NY and HIPAA is best understood through three categories: requirements that overlap (where satisfying one generally satisfies the other); requirements that HIPAA imposes beyond what SHIN-NY requires; and requirements that SHIN-NY imposes beyond what HIPAA requires. Understanding all three is the foundation of a compliance programme that genuinely satisfies both frameworks simultaneously.
Category 1: Where SHIN-NY and HIPAA Requirements Overlap
The substantial majority of SHIN-NY cybersecurity requirements reflect the HIPAA Security Rule standards — which makes sense, because SHIN-NY was designed to ensure that participating organisations protect health information at a level consistent with federal law. The overlapping requirements include:
• Risk analysis: both HIPAA and SHIN-NY require a documented risk assessment covering the threats and vulnerabilities to the protected health information in the organisation's control. A HIPAA-compliant risk analysis that includes SHIN-NY data flows within its scope satisfies both requirements.
• Access controls: both frameworks require documented, role-based access controls limiting access to health information to those with a legitimate need. Access control documentation that satisfies HIPAA's minimum necessary standard also satisfies SHIN-NY's access control requirements.
• Workforce training: both HIPAA and SHIN-NY require annual security awareness training for all workforce members with access to protected health information. One training programme, documented to HIPAA standards, satisfies both.
• Encryption: both frameworks require encryption of health information in transit and at rest. HIPAA's 2026 mandatory encryption requirements satisfy SHIN-NY's encryption expectations.
• Incident response: both require a documented incident response plan. SHIN-NY adds specific RHIO notification requirements that must be incorporated into the HIPAA incident response plan — but one document, updated to include the SHIN-NY-specific elements, satisfies both.
Category 2: What HIPAA Requires Beyond SHIN-NY
HIPAA's Security Rule imposes requirements that the SHIN-NY CSPP framework does not explicitly address — meaning a home health agency that focused exclusively on SHIN-NY compliance and ignored these HIPAA-specific requirements would be SHIN-NY compliant but HIPAA non-compliant:
• Technology asset inventory and network map: the 2026 HIPAA mandatory requirements include a documented inventory of all hardware and software touching ePHI and a current data flow diagram. SHIN-NY does not currently mandate these documents explicitly, though RHIO reviewers expect to see evidence that the organisation understands its ePHI environment.
• Specific documentation retention requirements: HIPAA requires six-year retention of all Security Rule documentation. SHIN-NY does not specify documentation retention periods.
• Business Associate Agreements for all ePHI vendors: HIPAA requires a BAA with every vendor that accesses ePHI. SHIN-NY focuses on the security programme of the participating organisation — it does not independently manage the BAA relationship with the organisation's vendors.
• Physical safeguards documentation: HIPAA's physical safeguard requirements (server room access controls, workstation use policies, device disposal) are more prescriptively documented than what SHIN-NY CSPP templates typically require.
Category 3: What SHIN-NY Requires Beyond HIPAA
SHIN-NY imposes obligations that have no direct HIPAA equivalent — requirements specific to participation in the health information exchange network:
• CSPP documentation: the Cybersecurity Policies and Procedures Programme is a SHIN-NY-specific document format. There is no equivalent HIPAA submission requirement.
• SCPA execution: the Security Compliance Plan and Agreement is executed between the participating organisation and the RHIO — a relationship with a governance structure that does not exist under HIPAA.
• Annual RHIO renewal: SHIN-NY participation requires annual reaffirmation through the SCPA renewal process. HIPAA does not have an annual renewal submission requirement — it requires continuous compliance, not annual certification.
• RHIO-specific incident notification: SHIN-NY requires notification to the RHIO within 72 hours of a security incident involving SHIN-NY data. HIPAA's incident notification requirements are directed at affected individuals and HHS OCR — not at health information exchange networks.
Protecting your New York home health agency is not optional — and it does not have to be overwhelming. ShieldForce delivers everything described in this article as a fully managed service, starting at $35/user/month. No IT department needed. BAA signed on day one. Core controls live within 72 hours. Start with a free assessment and see exactly where you stand.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

