Privacy & Security

How the SHIN-NY Protects Health Information

Protecting patient health information is foundational to the SHIN-NY. Every aspect of the network — from policy to technology to governance — is designed to ensure that health data is handled securely, used appropriately, and accessed only by authorized individuals for permitted purposes.

Regulatory Compliance

The SHIN-NY operates in compliance with:

  • The Health Insurance Portability and Accountability Act (HIPAA)
  • New York State Public Health Law and Mental Hygiene Law
  • 10 N.Y.C.R.R. § 300 (SHIN-NY Regulation)
  • 42 CFR Part 2 (Substance Use Disorder confidentiality protections)
  • Other applicable federal and state privacy and security requirements

Patient Consent in New York

New York operates under a consent model that governs when and how patient health information may be accessed through the SHIN-NY. Patients have the right to make informed decisions about whether their health information is shared electronically through the network. The Statewide Consent Registry maintains a centralized record of patient consent decisions, ensuring that access to information through the SHIN-NY always aligns with each patient’s expressed preferences.

Security Safeguards

The SHIN-NY employs comprehensive technical and administrative safeguards, including:

  • End-to-end encryption of data in transit and at rest
  • Role-based access controls ensuring users only access information necessary for their authorized purpose
  • Comprehensive audit logging of all data access and exchange activity
  • Regular security assessments and compliance monitoring
  • Incident response procedures and breach notification processes
  • Required security standards for all participants and QEs