Free for ABA agency leaders

Your agency runs on systems you were never trained to secure.

Scheduling lives in one platform. Session data lives in another. Parents text your clinicians. Recordings sit on somebody's phone. Every one of those is a place protected health information lives, and most agencies have never mapped a single one of them.

We turned the federal cybersecurity guidance for small healthcare organizations into a 49-item self-evaluation written for how ABA agencies actually operate. It is free.

Send me the checklist

This is for you if…


  • You know a risk analysis is required, and yours is old or missing.
  • Your clinicians work in homes, schools, and clinics on devices you do not fully control.
  • Parents text your team, and no written rule governs what gets sent.
  • You have signed BAAs, and nobody has looked at a vendor since.
  • You want to know where you actually stand before a payer, an accreditor, or an incident tells you.
The pattern we see

ABA agencies do not fail at security because they are careless.

They fail because they grew into healthcare obligations nobody taught them. Three gaps show up in nearly every agency we assess.

The risk analysis that never happened


The HIPAA Security Rule requires one, and it is the most common finding in federal enforcement. Many agencies have never completed one, or completed one before they changed practice management systems, added telehealth, and doubled their staff.

The platforms nobody inventoried


Scheduling, data collection, telehealth, billing, transcription, parent surveys. Each one holds client information. Each one needs an agreement. Most agencies can name two and have signed for one.

The communication nobody governed


Parents text. Clinicians text back from personal phones. Supervisors record sessions to review later. None of it reaches the record, and no written rule says what is allowed.

Three files, no cost

Everything you need to score your agency this week.

The checklist (Word)


49 items across 10 practice areas. Every item gives you the practice, a plain-language explanation, what full implementation actually looks like, and the close-but-incomplete version that fools most self-assessments. Checkboxes and an evidence line on every item.

The scoring workbook (Excel)


The same 49 items with a rating dropdown, owner, target date, and evidence column. A summary tab calculates readiness by practice area and overall, so you can see which domain is dragging you down.

The source document (HICP)


Technical Volume 1 of the federal Health Industry Cybersecurity Practices publication, the guidance the checklist is built from. Useful when a payer, accreditor, or board member asks where your standard came from.

See how it works

One real item, exactly as it appears.

The near-miss example is the part that does the work. Most agencies fail these items by doing ninety percent of the job.

1.2 Multi-factor authentication is turned on and required for every email account, including owners and contractors.


What this means: A password alone can be stolen through a fake login page. Multi-factor authentication adds a second step, usually a code or a prompt on a phone, so a stolen password by itself does not open the mailbox.

Fully implemented looks like: Multi-factor authentication is enforced by policy at the account level for all users, and the admin console shows zero enrolled users without it.

Close, but not there yet: Multi-factor authentication is available and most clinicians turned it on, but the owner and two part-time BCBAs skipped enrollment. Attackers target leadership mailboxes first, so the exception undoes much of the protection.

Free download

Tell us where to send it.

Enter your name and email and all three files land in your inbox within a minute. No sales call, no trial, no credit card.

We will occasionally send you other compliance resources for ABA agencies. Unsubscribe whenever you like.

Cybersecurity Self-Evaluation Checklist for ABA agencies, checklist and scoring workbook

Get the checklist

Checklist, scoring workbook, and the HICP source document.

We will never sell or share your information.

Who made this

Two BCBAs who went and learned the compliance side.

Michael Fabrizio, Co-Founder of ABA Compliance Solutions

Michael Fabrizio

Co-Founder, ABA Compliance Solutions


Michael works on the healthcare-system side of compliance: what a rule requires, why it exists, and what a defensible position actually looks like. He previously served as Privacy and Security Officer for a research and learning organization, which is where most of this checklist comes from.

Rose Feddock, Co-Founder of ABA Compliance Solutions

Rose Feddock

Co-Founder, ABA Compliance Solutions


Rose works on the implementation side: what a requirement means for your team on Monday morning. She is the reason this checklist is written in plain language instead of regulatory shorthand, and the reason every item includes an example of doing it almost right.

Questions people ask first

You will find something.

Every agency that runs this honestly finds at least a few items sitting at "close, but not there yet." That is the point. Finding them yourself, on your own timeline, costs a great deal less than finding them during an incident or an audit.

Send me the checklist