Free for ABA agency leaders

Your agency runs on systems you were never trained to secure.

  • Scheduling lives in one platform.
  • Session data lives in another.
  • Parents text your clinicians.
  • Recordings sit on somebody's phone.

Every one of those is a place protected health information lives, and most agencies have never mapped a single one of them.

We turned the federal cybersecurity guidance for small healthcare organizations into a 49-item self-evaluation written for how ABA agencies actually operate.
It is free.

Cybersecurity Self-Evaluation Checklist for ABA agencies

Get the checklist

Enter your name and email once.
All three files open on the next page.

We will never sell or share your information. Unsubscribe any time.

Four things you will know by the end

Score your agency before a payer, an accreditor, or an incident does it for you.

  • Where PHI actually lives across scheduling, data collection, telehealth, billing, and the phones your clinicians carry.
  • Whether your risk analysis holds up, or was completed before you changed systems, added telehealth, and doubled your staff.
  • Which vendors hold client data without a signed agreement, and which agreements nobody has looked at since signing.
  • Where you sit at "close, but not there yet" on the safeguards federal enforcement checks first.
Three files, no cost

Everything you need to score your agency this week.

The checklist (PDF)

49 items across 10 practice areas. Every item gives you the practice, a plain-language explanation, what full implementation actually looks like, and the close-but-incomplete version that fools most self-assessments. Checkboxes and an evidence line on every item, ready to print.

The scoring workbook (Excel)

The same 49 items with a rating dropdown, owner, target date, and evidence column. A summary tab calculates readiness by practice area and overall, so you can see which domain is dragging you down.

The source document (HICP)

Technical Volume 1 of the federal Health Industry Cybersecurity Practices publication, the guidance the checklist is built from. Useful when a payer, accreditor, or board member asks where your standard came from.

Who built this

Written by the people who ran the security program, not just the audit.

Michael Fabrizio, Co-Founder of ABA Compliance Solutions

Michael A. Fabrizio

M.A., BCBA, LBA-WA, CCEP®, CHC®, CHA℠, CHPC®, CHPSE® · Co-Founder


Thirty years a behavior analyst, and a certified healthcare compliance, privacy, and security professional. Michael built one of the earliest compliance programs inside his own ABA organization and served as its Privacy and Security Officer through licensing reviews and payer audits. This checklist is the standard he held that program to, translated into plain language.

Rose Feddock, Co-Founder of ABA Compliance Solutions

Rose Feddock

M.A., BCBA, LBS-PA, CHC® · Co-Founder


Twenty-five years a behavior analyst, more than a decade in healthcare compliance, and a leader in industry-wide standards development for ABA. Rose builds the systems that let clinical teams do their work without tripping over the safeguards: policies, documentation, monitoring. She made sure every item on this checklist tells you what "done" looks like on Monday morning.

Free download

Get all three files now.

Enter your name and email once. The next page opens our full resource library, where the checklist, the scoring workbook, and the HICP source document are ready to download. No sales call, no trial, no credit card.

  • 49-item checklist (PDF)
  • Scoring workbook (Excel)
  • HICP Technical Volume 1 (PDF)
Cybersecurity Self-Evaluation Checklist for ABA agencies

Get the checklist

Checklist, scoring workbook, and the HICP source document.

We will never sell or share your information. Unsubscribe any time.