If you have received a SHIN-NY compliance notification from your Regional Health Information Organization and seen the term "CSPP," you may be wondering exactly what this document is, who writes it, what it needs to contain, and whether your agency already has something that satisfies the requirement.
This guide answers all of those questions. The CSPP — Cybersecurity Policies and Procedures Program — is the cornerstone of SHIN-NY compliance. Understanding what it is, and what it is not, is the starting point for every New York home health agency participating in the statewide health information exchange.
What the CSPP Is
The Cybersecurity Policies and Procedures Program is a written document — or organized set of documents — that describes your agency's security governance structure, policies, and operational procedures for protecting electronic protected health information, with specific attention to data accessed through or transmitted via SHIN-NY.
It is not a checklist, although it may include checklists. It is not a technical configuration guide, although it references technical controls. It is a governance document: it establishes who is responsible for security at your agency, what policies are in place, and how those policies are implemented and enforced.
Think of it as the organizational equivalent of a HIPAA Security Rule compliance program — because that is exactly what it is, with specific framing for SHIN-NY participation.
What a Compliant CSPP Must Contain
Section 1: Scope and Applicability
Defines what the CSPP covers — which systems, data types, and personnel. For a home health agency, this typically covers: EHR systems connected to SHIN-NY, email systems containing ePHI, devices used to access SHIN-NY data (including field devices), and all workforce members with access to SHIN-NY-connected systems.
Section 2: Security Governance
Designated Security Officer. The CSPP must identify a named individual responsible for cybersecurity at your agency. For most home health agencies, this is the compliance officer, executive director, or a senior administrator. The role does not require technical expertise — it requires organizational authority to enforce security policies.
Roles and Responsibilities. Documents who is responsible for specific security functions: who approves access requests, who reviews audit logs, who handles incident response, who conducts staff training.
Section 3: Risk Assessment
A documented risk assessment covering the systems and data flows relevant to SHIN-NY participation. Must include: identified threats and vulnerabilities, likelihood and impact ratings, and the controls implemented to address each risk. Must be updated when significant changes occur.
Section 4: Access Control Policies
Documents how access to SHIN-NY data is granted, managed, and revoked. Covers: user provisioning procedures, role-based access definitions, MFA requirements, session management, and off-boarding procedures for departing staff.
Section 5: Encryption and Data Protection
Documents encryption controls: what is encrypted, how, and what the verification process is. Confirms that field devices are encrypted and that data in transit uses TLS 1.2 or higher.
