Workforce training is required by both HIPAA and SHIN-NY — but the training most home health agencies provide falls short of what either framework demands. A 15-minute annual video about password hygiene, completed on a shared office computer, does not meet the standard. Neither does a HIPAA privacy training module that was designed for hospital staff working at fixed desks.
The workforce training requirement for SHIN-NY compliance is specific: it must be documented, it must cover SHIN-NY-relevant security topics, and it must be tailored to the actual work environment of the people being trained. For home health agencies, that means field nurses, home health aides, care coordinators, and billing staff who work in patient homes, on personal devices, and in distributed environments that bear no resemblance to a hospital or clinic setting.
What SHIN-NY Requires for Workforce Training
Your CSPP must document a workforce security awareness training program that includes:
Coverage: All workforce members with access to SHIN-NY data or SHIN-NY-connected systems. This includes clinical staff (nurses, aides, therapists), administrative staff (scheduling, coordination), billing staff, and any contractors with system access.
Content: Training covering the policies and procedures relevant to your CSPP — which means the specific security obligations that SHIN-NY participation creates, not just general HIPAA awareness.
Documentation: Completion records for every trained staff member. Name, date of training, training content covered, and assessment results if applicable. These records must be retained and available for RHIO review.
Frequency: At minimum annually. The CSPP should specify the training schedule, and the documentation should confirm that every staff member has completed training within the required period.
Relevance: Training that addresses the actual risks staff face in their specific role. Field staff need training relevant to field scenarios. Billing staff need training relevant to billing-specific threats (BEC, Medicare portal phishing).
What the Training Must Actually Cover
Module 1: SHIN-NY and Why It Matters
Staff who understand what SHIN-NY is — that it connects your agency to a statewide network of patient health records — understand why their individual security behavior matters to the entire network. Training should explain:
- What SHIN-NY is and what data flows through it
- Why SHIN-NY data is sensitive and what happens if it is breached
- What your agency's obligations are as a SHIN-NY participant
- The individual staff member's role in protecting SHIN-NY data
Module 2: Phishing Recognition — Mobile-First
Most HIPAA and security awareness training presents phishing examples on desktop email clients. Your field staff primarily access email on smartphones. Mobile phishing looks different — sender addresses are often hidden, links are harder to inspect, and the urgency of mobile communication works in the attacker's favor.
Training must include:

