Free for ABA agency leaders
Your agency runs on systems you were never trained to secure.
- Scheduling lives in one platform.
- Session data lives in another.
- Parents text your clinicians.
- Recordings sit on somebody's phone.
Every one of those is a place protected health information lives, and most agencies have never mapped a single one of them.
We turned the federal cybersecurity guidance for small healthcare organizations into a 49-item self-evaluation written for how ABA agencies actually operate.
It is free.

Get the checklist
Enter your name and email once.
All three files open on the next page.
We will never sell or share your information. Unsubscribe any time.
Four things you will know by the end
Score your agency before a payer, an accreditor, or an incident does it for you.
- Where PHI actually lives across scheduling, data collection, telehealth, billing, and the phones your clinicians carry.
- Whether your risk analysis holds up, or was completed before you changed systems, added telehealth, and doubled your staff.
- Which vendors hold client data without a signed agreement, and which agreements nobody has looked at since signing.
- Where you sit at "close, but not there yet" on the safeguards federal enforcement checks first.
Three files, no cost
Everything you need to score your agency this week.
The checklist (PDF)
49 items across 10 practice areas. Every item gives you the practice, a plain-language explanation, what full implementation actually looks like, and the close-but-incomplete version that fools most self-assessments. Checkboxes and an evidence line on every item, ready to print.
The scoring workbook (Excel)
The same 49 items with a rating dropdown, owner, target date, and evidence column. A summary tab calculates readiness by practice area and overall, so you can see which domain is dragging you down.
The source document (HICP)
Technical Volume 1 of the federal Health Industry Cybersecurity Practices publication, the guidance the checklist is built from. Useful when a payer, accreditor, or board member asks where your standard came from.
Who built this
Written by the people who ran the security program, not just the audit.
Michael A. Fabrizio
M.A., BCBA, LBA-WA, CCEP®, CHC®, CHA℠, CHPC®, CHPSE® · Co-Founder
Thirty years a behavior analyst, and a certified healthcare compliance, privacy, and security professional. Michael built one of the earliest compliance programs inside his own ABA organization and served as its Privacy and Security Officer through licensing reviews and payer audits. This checklist is the standard he held that program to, translated into plain language.
Rose Feddock
M.A., BCBA, LBS-PA, CHC® · Co-Founder
Twenty-five years a behavior analyst, more than a decade in healthcare compliance, and a leader in industry-wide standards development for ABA. Rose builds the systems that let clinical teams do their work without tripping over the safeguards: policies, documentation, monitoring. She made sure every item on this checklist tells you what "done" looks like on Monday morning.
Free download
Get all three files now.
Enter your name and email once. The next page opens our full resource library, where the checklist, the scoring workbook, and the HICP source document are ready to download. No sales call, no trial, no credit card.
- 49-item checklist (PDF)
- Scoring workbook (Excel)
- HICP Technical Volume 1 (PDF)
Get the checklist
Checklist, scoring workbook, and the HICP source document.
We will never sell or share your information. Unsubscribe any time.