Inside ABA C.A.R.E.S. | Culture - Advocacy- Retention- Employee Relations- Systems
Step behind the scenes of the ABA C.A.R.E.S. Summit — exclusive conversations with the people and partners shaping the future of Applied Behavior Analysis, recorded before we gather in Boston this August.
Meet the sponsors and organizations behind the Summit, understand the work they do, and walk into the room already knowing who's there and why it matters. Industry leaders, researchers, advocates, supervisors, and autistic professionals — all united by one mission: to support and strengthen the people behind the practice.
Whether you're already joining us in Boston or still deciding, Inside ABA C.A.R.E.S. is your way in.
Listen to:
- Get to know the partners and organizations behind the Summit, and the problems they're built to solve.
- Explore the core themes of C.A.R.E.S. — Culture, Advocacy, Retention, Employee Relations, and Systems.
- Reflect on your own role in building a sustainable, human-centered ABA workforce.
Press play before August, bring your questions to the sessions, and find out what the room is going to be like. We'll see you in Boston or on the other side of the livestream.
Inside ABA C.A.R.E.S. | Culture - Advocacy- Retention- Employee Relations- Systems
The Security Problem Hiding Inside ABA Turnover, with Tom McCadden Episode
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In ABA, we count what turnover costs us in hiring, in training, in continuity of care. Almost nobody counts what it leaves open.
Tom McCadden is the EVP and Chief Technology Officer of Alliance InfoSystems, a Baltimore-based managed IT and security firm that has spent over two decades protecting businesses across the country and has built a specialty serving ABA practices, from single clinics to multi-state organizations. Tom has spent twenty years inside the company building the unglamorous, mission-critical layer: the systems that decide whether a departure is a non-event or a breach. He has watched ABA companies grow every way a company can grow, de novo and by acquisition, and he has seen what happens to client data when nobody owns the offboarding. A-Train's Matt Harrington, BCBA, sits in the guest host chair for this one.
This is the conversation about the risk your practice is already carrying.
Here is what we get into:
- Offboarding as two problems, identity and equipment, and why high RBT churn means you cannot solve either one manually
- The "too small to be a target" mindset, and why behavioral health keeps ending up on attackers' lists anyway
- Growth by acquisition: when you buy a practice, you buy its risks too
- BYOD done right: protecting client data on personal phones without surveilling your staff's personal lives
- Wiring your HR system to your access controls, so a departure closes every door automatically, with a human still watching
- Phishing tests, MFA, and the HIPAA security rule changes turning yesterday's optional into tomorrow's required
- The one thing Tom would have every owner do by Friday
Resources:
- Alliance InfoSystems: ainfosys.com
- Tom McCadden on LinkedIn: linkedin.com/in/tom-mccadden-76453116
Find Tom and the Alliance InfoSystems team at their booth at the ABA C.A.R.E.S. Summit, August 4 through 7 at the Boston Marriott Long Wharf. Before you stop by, answer one question: the last time someone left your practice, how long did their access stay open? If you do not know, that is your conversation starter.
Register: https://behaviorlive.com/conferences/abacares2026/registration
We'll see you in Boston, or on the other side of the livestream.
Hello everyone, my name is Matt Harrington, and you are listening to Inside ABA Cares. Your behind-the-scenes space where we lay the foundation and set expectations for who you'll meet in August, both attendees, speakers, and of course our sponsors. We spend a lot of time at this conference talking about turnover, recruiting, retention, culture, and the cost of losing people. But there's one cost of turnover that we don't talk about too much, which has been getting more and more dangerous as time goes on. Consider this scenario. One of your best RVTs ends up leaving to go to grad school for a BCBA job. That's great, and you celebrate them. But when they leave, what happens to their access? What happens to their email, their tablet, their login, all of that protected tech that holds protected health information oftentimes stays open for days, for weeks, in the car, at the bottom of a drawer. The reality is, is those are all open doors into some of the most sensitive data that you hold, health information about the kids you serve. So turnover, as ugly as it is as a hiring problem, also has another side to the coin, which is the access and security. So my guest Tom handles exactly this. Tom McCadden is the CTO, the chief technical officer at Alliance Info Systems, a managed IT and security form firm that has built a specialty serving ABA practices across the country. Tom has spent two decades building the unglamorous mission critical stuff, the defenses that decide whether a breach becomes a disaster or a non-event. They're a preferred partner of many major ABA practice management organizations, and they support practices from 10 people to multiple thousand. Tom, thank you so much for being here. For those who don't know your story already, I'd love to have you tell it yourself.
SPEAKER_00Thank you for having me. Um, so Alliance as an organization we've been around for uh 24 years. I've been with the organization for 20 years, started entry level and grew with the company. When we started, we were uh only three people. I was the fourth person hired. We're now a firm of uh 55 employees, 38 on the service side, and all HIPAA trained and certified on the support staff. Over the years, Alliance as a company has mainly grown by referrals and kind of word of mouth with the work that we do for our clients, uh, which is how we ended up in the ABA space. We started over 10 years ago with an ABA company, and they were two computer users at the time. Um, they've grown to over 600 and over 2,000 employees in total in multiple states. I do want to take a step back and highlight what I mentioned there just because kind of making the two worlds match in the sense of IT and ABA is when I defined as computer users. So from an IT support standpoint and security, the way that we work with ABA firms, there are employees who use laptops and there are mobile users and you know, the clinicians uh that are out in the field. That's the way that we uh we split those up. And as we get into talking more about security and access to platforms, uh, you'll hear me refer back to those.
SPEAKER_01What are some of the risks just as you scale? And maybe take into account a company that started uh a couple years ago, they're at 30 employees and they're exploding, and we'll be at 75 by the end of the year.
SPEAKER_00Yeah, absolutely. We've grown with ABA companies that have grown in both uh methods, whether that's de novo's or via acquisition, and both have challenges. Scaling and from the de novo standpoint, for example, you have to make sure that you have a proven process to open new centers to or remote employees uh that do maybe do in-home work or on location work. It's being able to, you know, kind of scale that up and have a proven process to get the user accounts created, get uh the devices in their hands that they need to do their job. And then acquisition is a whole nother challenge because then you are acquiring an entire maybe new center, new company that you need to transform that into your uh business practices. And when you do an acquisition, one thing to keep in mind is you're not just acquiring the company, you're also acquiring any risks associated with it. So a very strong due diligence process is certainly uh needed when you know you have that growth model.
SPEAKER_01As your firm grew and you started looking at the different places where you could help and serve, what grew you to ABA specifically?
SPEAKER_00We found they were fast-growing organizations, but they were also accepting of technology. And with it being still a fairly new industry, we found that a lot of them were coming in more cloud-first mindset already. So they didn't have a lot of this uh what we call technical debt that needed to be cleaned up in order to help move them forward.
SPEAKER_01When someone leaves an ABA practice, especially in this field, typically we're talking about RBTs who who churn out pretty fast. What's supposed to happen? What's the ideal, most protected way to go about it?
SPEAKER_00We work in a lot of different uh industries as well. And when we first started with ABA, I think most people getting into it was uh very surprised with that rate. Uh so we had to very quickly determine what's the best way to allow that to happen at scale, not just when someone leaves, but also when someone comes on board, and being able to automate a lot of those processes to be able to do that at scale. So there's kind of two factors when you talk about when someone leaves an organization or comes on for that matter. There's identity and then there's equipment. So there's access to the systems and then there's how they gain access on, you know, whether it be a tablet, a laptop. So we like to work with them to build that foundation first. So make sure that all of your applications are single sign-on. So you maintain that one source of truth. For example, if you disable a user in your HR system, because that's usually the first to start, and then you want that to flow through to all of your other systems seamlessly. So there's not a lot of you know opportunity for things to be missed. Having a streamlined way to lock down that user's access to any you know HIPAA protected data, uh, but then also making it uh you know easy to also lock down the device and recover that device if needed as well.
SPEAKER_01With a lot of startups or even fast-growing companies, uh, this type of thing is oftentimes the last thing on their mind, right? There have a million other clinical things, they have a million other hiring cultural things to worry about. Where do you find this type of maybe not negligence, but just not paying attention to the right thing, that ignorance? Where does that come to bite them in the butt?
SPEAKER_00It's always around the uh we'll get to that kind of mindset. And you know, we'll talk a little bit more about like the cybersecurity possible uh implications of that. But there's also things to think about from just like a reputational standpoint. You know, you don't want an employee that is no longer an employee to, let's say, have access to email, whether it be internally, externally, uh, to be able to send emails, receive emails. Uh so it's kind of those nuances that aren't thought about the what could happen, and we'll get to that until unfortunately sometimes that it does happen.
SPEAKER_01Can you think of a story where all of a sudden these types of concerns that weren't even on an owner's mind suddenly become crucial, maybe in an audit or something similar?
SPEAKER_00Yes, audit yeah, audits are definitely a big part of that. Um another part that we see a lot of times is unfortunately, if a user is uh or an owner is uh finding out about any of an issue, it's usually too late. Um, you know, so someone sends out a maybe a disgruntled email or they have access to um, you know, the practice management system after they are no longer or worse, if it's some type of financial transaction uh that may happen, like transfer or you know, payroll being deposited to the incorrect account, things like that. It's almost unfortunately too late by the time they find that out.
SPEAKER_01What is typically the thing that triggers them finding all of this stuff out? Is it typically an audit or are there other leaks or security notifications that typically come up?
SPEAKER_00It's the process and like what is the end-to-end process of you know a employee leaving, employee coming on board, and then making the technology fit into that. Unfortunately, like I said, it's a lot of times it they almost find out a little bit later. We don't see as much from audits unless we're coming in to do an assessment. Like we don't see third-party auditors uh coming in as much to uh the ABA space just yet. Uh, I think that is something that will come and continue to grow again as the space and the practice uh grows as a whole.
SPEAKER_01Do you see behavioral health as in particular vulnerable to cyber attacks or cybersecurity breaches?
SPEAKER_00I do. Yeah. A lot of the reason I say that it's protected information. It is especially uh children information as well. So and a lot of times, unfortunately, owners, especially of smaller firms, uh, well, they grow rapidly, as you mentioned, uh, so these things aren't always on their mind. But there's also sometimes the mindset of we're too small, no one's gonna target us. And what we see on the majority of incidents, uh, whether it's uh clients coming in or if it's attempted attacks against our existing clients, uh, they're more crimes of opportunity than actually being targeted. Um so thinking that your organization is too small or you don't have the financial data that maybe attackers are going for, things like that, is a very common misconception that we hear a lot as well.
SPEAKER_01To go from uh, we'll say for a 25 company employee, right, fairly you know, small, maybe mid-size, depending on your definition. What does it cost in general to get up to snuff with security on some of these things?
SPEAKER_00One of the biggest things that we see, and it all depends on where they are currently in their you know maturity level. Like for example, if you grew quickly from you know a five-person, 25, now 50, a lot of times they're using personal devices. Maybe the company didn't supply them. So there's no inventory management, there's no lockdown and control of those. So, really where I see, especially if firms try to visit that kind of after they've grown, now you're at, let's say, 500 employees, that's a much bigger lift and ends up being, you know, much more costly project to level set and get back to the basics. Now, when we provide one of the services that we provide is our managed security service. And we have built that over the years and scaled that with our partners to be able to provide really that enterprise grade security at like that small to medium business level as well. So uh it doesn't have to be a concern or a misconception that we're only 20 people, we can't afford to have like 24 by seven security operations center monitoring. That's within reach of all firms of all sizes today. And we're starting to see it, you mentioned audits on the um cyber liability insurance side. Uh things like 24 by 7 monitoring is starting to become not a nice to have, but a must-have.
SPEAKER_01I'm curious. If I were an agency owner and I'm listening to this, going through my head right now, I'm probably thinking, oh my gosh, I'm gonna have to change this system, I'm gonna have to change that system. Everything I mean, I won't be able to use this. I'll have to switch over to this new thing and it's not gonna work. And my parents are gonna be mad and upset. Can you talk about what that transition process looks like, especially if they came to you, started your service? How would you help them through that process?
SPEAKER_00Sure. Both from an IT standpoint and from a cybersecurity standpoint, we want to be as least impactful for you providing the service uh to the children as possible. So we want to protect you, but we want to be on the back end. Uh, we don't have any kind of barrier to entry, any impact to providing uh that service. So one example I can uh give you of that is we work with and help, you know, RVTs usually in this case, like if they are maybe providing services and they need to log into their practice management system, but we want to lock it down with multi-factor authentication, you know, to keep the system safe. But maybe they can't have their phone and treatment. It's unique challenges that the ABA industry has to need to solve for those problems and not get in the way of the mission or or the goal. We're familiar with those and we're able to come up with those creative solutions to not be a barrier.
SPEAKER_01Yeah. That makes sense. It kind of points to why you need somebody who specializes because even like I'm obviously deep in ABA myself, I didn't even think of the fact that, you know, I have my phone on me all the time for multi-factor authentication, which isn't allowed on some units uh just for safety reasons. Well, when a practice calls you and you start having conversations with them, is there a moment where you think that if only you had talked to me a month ago, if only we could have fixed this sooner? When's that like a crap, if only moment? And how can owners be prepared for it?
SPEAKER_00Yeah, it's definitely around a lot of it is around asset management and asset inventory, knowing what all is out there and having the ability to manage and control that. So part of our security solution includes a asset management, it's uh remote monitoring and management. So we're able to monitor the devices, secure the devices. And if you have um employees either that provide, let's say, in-home or on-site care, and or that they have uh, you know, multiple centers uh spread out, you know, kind of across the US, wrangling that in and actually getting that time to install that software so we can help secure them, we can manage them. That's usually the biggest time constraint uh and costly of a you know project to build that foundation. So one of the things, just starting out, if you're a smaller firm, try to again get I know I keep saying this, but back to the basics and build that foundation early on, and then it'll save you such an amount of time and headache down the road.
SPEAKER_01Asset management. Uh can you talk a little bit more about that? Maybe explain it for those who their biggest understanding of asset management is if they should buy an iPad or an Android tech device.
SPEAKER_00I mentioned the computer users versus mobile users. So um, you're talking about a laptop versus uh tablets, usually, the ability to monitor them, to control them, to keep them secure, even to help troubleshoot them. Uh let's say your practice management provider rolls out a new app that you want to push out to all of your tablets. Do you have the ability to do that? Or is it going to take each one of them 15, 20 minutes each to install the new app so they can start providing those services? And 10, 15, 20 minutes doesn't sound like a lot, but if you're talking about doing that across 1500 tablets, that adds up pretty quickly. So knowing not just where the tablets are from an asset standpoint, but also the ability to help support and control them is a key part of that as well.
SPEAKER_01The first ABA company I ever worked for, the iPads were all connected to the owner's son's Apple IV. And that son switched off of Apple years ago for Android. And so whenever I would try and install an app as a clinic director, I couldn't because I needed a password that was no longer accessible. And it was all it was a whole mess. One of the hot debates in ABA is which laptop should I buy my BCBAs and which tablet should I buy my technicians? Is there a strong opinion you have over that in terms of security?
SPEAKER_00Uh we don't. Uh so we support on the laptop side both Windows and Mac OS from asset management inventory, cybersecurity protection standpoint. And also with the tablets to manage those, you use something called mobile device management or MDM. And they work on both Android and Mac OS or iOS on the tablets. And a lot of times it comes down to availability and cost, and then also like just knowing what they're going to use it for in their day-to-day and try to find the best, most affordable device uh for them to uh to get their job done.
SPEAKER_01Are you able to do a similar asset management job when staff are using personal phones for data collection?
SPEAKER_00So personal phones, yes. Uh specifically, what we typically do, not to go too far down the you know down that rabbit hole, but on like the uh mobile device management solutions, we have the ability to control at an application level without actually controlling the phone. So in practice, what that could look like is you could say, you know, my company has our practice management app, we have our Outlook or Google Mail, we may have OneGive or Google Drive, um, and the ability to, if that person leaves, that information in those company-owned apps are kind of siloed from all of their personal data. So you would have the ability to wipe out just those apps while not even having access or seeing anything into their personal devices. So that allows almost all companies that we work with, ABA or other industries, have personal devices. We see less and less nowadays where the company is providing the uh the phone specifically. So having that still keeping the organization secure, but also respecting the employees' personal privacy is kind of key in those bring your own device or BYOD scenarios like that.
SPEAKER_01In the intro, I mentioned a really common scenario where somebody leaves for whatever reason and devices get thrown in a drawer or just you know scattered and everyone kind of forgets about them. With really strong security protocols and asset management, what does that process look like?
SPEAKER_00Yeah, and that's going to depend on, again, not just unique to the ABA industry, but the you know healthcare industry in general, is whether it's collecting from a center or collecting a clinician that may be out in the field. It all comes down to laying that process. I've said that a couple of times, but like what is the process, not just when someone leaves, but how do you collect the device? Who's responsibility? Who's the owner? Is it the center administrator? Is it someone within HR that handles that? And then we talk through that process with owners. We let them know what we've seen as successful in other ABA firms, and then we help them build that process from a business standpoint, and then we back the technology into it. So we never come into like ABA firms and say, here's your mobile device management, here's your asset management. We can make suggestions, what we've seen work in the past to help your business get to that, but we want to transform the technology to you, not make you transform your business to technology.
SPEAKER_01You've talked a lot about processes. Typically in the age of AI and automation, after processes comes automation, after automations come AI. So I'm curious what is the next step? How do we take some of the human error out of the conversation so we can harden our security protocols even further with automation? And is AI in the question on these types of things?
SPEAKER_00Yeah, absolutely. Uh I have the AI conversation, as you can imagine, quite frequently now with uh not just our ABA clients, but other industries as well. And it provides a unique challenge, especially to a couple things within like the ABA space, is you never want to trust AI for any treatment advice or anything to that matter. You also have to be very careful with the data that's put in to AI platforms, you know, especially uh like the free versions of all of the Chat GPT, Copilot, Claude, what any of those out there, there's a chance that any protected information that may enter them, if they're the free version, that it could be exposed. So having that plan just to introduce AI. So an AI-driven policy that is laid out to your organization. I always tell clients too, when it comes to AI, uh this is a lot around the cybersecurity conversations I used to have years ago as well, is don't just make that a technology of no, you can't do that. You always want to answer no, but here's what the you know organization allows. Here's the guardrails that we put in place. Because if not, they're gonna find a way to do it, right? If if you don't give them a secure means of doing so. And then you start looking at once you have that kind of foundation of you know the guardrails and the policies around AI and training for your staff, it then also comes into now what you We're talking about implementation. So start looking at some of those easy, kind of low-hanging fruit things that you can automate. So maybe it's just something like intake and some of that process, or, you know, maybe like the front of your physical center, like the front desk sign-in process and all of the flows on the back end. So again, very similar to like I mentioned with cybersecurity earlier. We're having those same type of conversations around all right, what's your business processes? And now how can we fit automation and and possibly AI into those processes?
SPEAKER_01Is there a use case for automation, especially that if you could wave a magic wand and give it to the ABA field, everyone would be happy? Like just like a slam dunk that you want to just say, just do this at least.
SPEAKER_00Yeah, I mean, definitely around from the cybersecurity standpoint, around getting ahead of it, uh policies, procedures around what's allowed, what's not, some like practical use case that I mentioned that uh we've seen and we're, you know, consulting with some of our uh clients around in the ABA space is certain things like intake, like I mentioned, signing in process, signing out process, uh checking in, checking out for employees, not just uh, you know, parents uh and children, but then even around getting into more of the weeds and maybe doing like a first pass on treatment plan review, not for any clinical terms or any clinic, but just things that you may submit to insurance for that claim to be processed that it needs to include. So nothing on the medical side, and uh I know I keep highlighting that, but that's very important that you don't use that as something giving you advice, but you can use it to, you know, maybe increase or like the frequency of reviews of those plans, just as another example.
SPEAKER_01What do you find is the most common barrier to people putting in automation?
SPEAKER_00Is it tech debt? It's mostly uh what is possible out there, you know, and that's what we work with firms to okay, let's look at your practice management software, let's look at your HR platform and see do they have the ability to build any type of automations into it and let us contact the vendors for you and let you know if it is possible and to what extent. And then you decide, you know, is that investment on that automation process worth going through or not? Because maybe it automates 10%, maybe it automates 95. But we help work with those third-party vendors to determine that on your behalf.
SPEAKER_01You mentioned uh when we were talking about your staff and managing security, you mentioned something along the lines of when a staff asks for an ability to do something, you have to give them a no, but you can do it this way, a secure way. Are you finding that becoming more and more of a problem as the younger generation of the RBTs become more and more tech native?
SPEAKER_00As you know, the RBTs are usually the largest uh section of your uh employees, right? Uh to license them for anything or uh provide them additional licenses, uh there can be a cost to that. Um we saw that very early on with just email. They weren't provided with maybe firm or company uh practice emails, so they would just use personal email, communicate with uh parents with uh personal emails. And then from there we saw it more on the uh file sharing side. So using personal OneDrive, personal Google, and there's just ways like specifically in like there's a type of Microsoft license, for example, that is very affordable, but provides them with those types of functionality. So again, knowing that and knowing how they work, what they need to do in those roles, and providing them that functionality is really key. And again, that comes back to knowing and working in the industry for so long. And now we're also seeing that uh with AI. And because again, that's just kind of the next evolution. It was email, it was files, and now we're at the you know the age of AI and we're seeing it there as well.
SPEAKER_01As a company, if you looked at three different companies, one small starting out, one mid-size, and a national large provider. Can you walk through some of the different security risks at each size?
SPEAKER_00Small is usually that um mindset that I mentioned. No one's attacking us, no one's targeting us, and also not, especially if it's a startup, not having the funds to put into you know buying company-owned devices for um you know, for people to use. Uh so just kind of getting that foundation, but that is the easiest place to implement that. Mid-size is what you where you run in. So now they have a to get them to that foundation, it may cost more because you have more devices out there, you have more employees. You're also starting to increase your tax surface. Uh, the more employees you have, the more chances for phishing emails and social engineering type attacks. And then that rolls right into the larger nationwide providers. They may be ones that are being targeted. And they do have that much larger footprint uh to where they could possibly be tacked, the more employees, the larger the attack surface, the more data you have, the more capital you may have for those type of financial-based attacks.
SPEAKER_01You mentioned phishing, and that like triggered in me the memories of working at a large hospital organization and your co-worker clicking on the phishing link, and suddenly you all have to go through and do the training again. Yeah. But uh it's it's a real point in terms of social engineering and getting scams. It's more than just somebody emailing you and asking for gift cards. Can you go through some of the scams or risks that behavioral health organizations?
SPEAKER_00Yeah, absolutely. So we do provide as part of our managed security service uh phishing simulations, email, uh email protection, and end user training, because to your point, it that is what we find the largest uh attack kind of surface there. It's still just the easiest barrier entry for these um attackers. Uh and with everything being cloud-based, it's not the scenario of that big hospital that you know has server rooms and uh and data warehouses that they need to protect. You know, everything is more cloud-based. So the attackers are going, they want the user's credentials. They want to be able to log in as that user. Uh and maybe it's just the RBT that clicked on that phishing email and had their account compromised. That may just be a stepping stone for what an attacker is trying to do. They may use that to go further up the chain and send additional social engineering kind of emails with inside of there. We are still seeing by far that's the largest attack surface that's social engineering and phishing.
SPEAKER_01So it's more than just uh my CEO asking me for in the moment gift cards.
SPEAKER_00You know? Yes. Yeah, and a lot of the attacks that uh they're attempting to do with phishing, they're becoming more and more sophisticated. I mean, it's continuously this cat and mouse game, right? If we educate people, hey, don't buy those Apple gift cards. Well, then the attackers need to find a different way in and to where the user may not even know that anything happened that just could be a normal login prompt. And they log in and it takes them to where they want to go. But on the back end, uh, you know, the attacker could have captured. So that monitoring for those type of activities and those type of anomalous activities is where we see it that's really critical nowadays.
SPEAKER_01With some of those additional risks come additional security. The HIPAA security rule is changing pretty soon coming up. Things that used to be optional, like multi-factor authentication, encryption are now becoming required. In your estimation, how many practices in behavioral health, like what percentage would you say are actually prepared for the new ruling?
SPEAKER_00I'd say 50, 60 percent that we come across that we just do um like initial engagements with or just discussions at conferences and and things like that. We find that multi-factor specifically, or or even encryption for that matter, they turn it on or they enable it on certain areas, but then they may not enable it everywhere across the board. So there's some of those gaps in like MFA. We encrypted all of our laptops, but not our tablets. Most firms we don't see that are at that 100% covered because there's little gaps. There's a lot of systems. Do you have MFA on everything? So your Microsoft, your Google, as well as your practice management system, um, your HR system. So it's that full breadth of coverage that we're seeing is not as covered as you know you would hope. But it's definitely a lot better, to be honest, than we would have even seen three, four years ago.
SPEAKER_01Is there a difference in risk of a company who is 50% there versus 90% there or 99% there? Or is it a truly one loose chain knocks everything over?
SPEAKER_00It depends where that uh where kind of that loose or that gap could be. A lot of times what I do see though is if they're only 50 to 60% there, for example, sometimes that can create a uh you know, false sense of uh confidence around security. Um like we may have Microsoft lockdown, for example, but not thinking about like the practice management system, which that's where a lot of your Hipposcoped data lives, uh, you know, and being able to do that. That's why like that foundation of making it easy as well. Like we usually recommend single sign-on wherever you can. So then that's one source of truth, one area that needs to be protected because that's your only identity, rather than everyone having 10 accounts throughout the organization that you need to lock down.
SPEAKER_01When it comes to locking down offboarding, is there a way that you could do that through automations within the overall maybe alliance infosystems ecosystem? Like, is it a conversation that's hey X person off-boarded, can you shut them down? Or is there a way to take the human error out of that?
SPEAKER_00Sure. So uh a lot of times what we would want to do, especially with ABA, because like we started off the conversation of the that high turnover rate, unfortunately, in ABA firms, is we would want to automate that as much as possible with human oversight. So I'll give you an example. We would connect, let's say, your HR system, because that's usually the source of truth, because that's usually tied to payroll and and things like that. That's then connected to your Microsoft or Google account, which then it's also connected to your practice management system. And maybe if you have any marketing platforms or Salesforce type platform out there, and then you would want whoever is responsible for that, whether it's someone in HR or management, to be able to turn that account off in one place and feel comfortable that it was taken care of everywhere else. Uh, that human insight piece that or oversight is where we always trust but verify when it comes to automation. So we would have a ticket created after all the changes to make sure everything was successful. Now that offboarding goes from a you know 15 to 30 minute hands-on the keyboard technician handling it to a three-minute look over the uh results of the output of everything that the automation did, and it can take that time to resolution drastically down.
SPEAKER_01One thing that you've shared in the past is that security isn't just protection. It's a practice that you can show parents and help build trust with them. How should the owner think about their data security as a trust symbol?
SPEAKER_00The way that I have that conversation around data security is you're building that foundation of trust. The parents are trusting that their children will be safe when they're dropped off at the center or when they're you know in the care of um you know an RBT or an ABA organization. And they would want to have that same trust with their child's information and their child's data. So that's the kind of talking point there is that you know, you have that end-to-end safety discussion, not just physical safety like everyone thinks right off the bat, but also their digital safety as well.
SPEAKER_01Do you think that in general most ABA practices that you meet are overprepared or underprepared for a security breach or cyber attack?
SPEAKER_00Especially when you're at the small to medium uh size of that, uh, they're still getting better, but still for an actual breach to do like a tabletop exercise of an incident to see who is responsible uh for what roles, what can happen during a breach, how chaotic, depending upon the uh scope of that breach, can be. I think there's still a good amount of work to do there to uh to prepare for something like that to happen.
SPEAKER_01Is there is there one thing that comes to mind that if you said, if nothing else, if you can just do this by Friday, I would feel more comfortable with your your practices, security standards. What would that thing be?
SPEAKER_00I'd say think about the basics. And again, I know I've mentioned it over and over, but building that foundation, having your asset management, having everything as single sign-on tied back to kind of one source of truth, so then you know where everything authenticates to and from. Because then that can lead you right into the more effective protection, such as multi-factor authentication. So really building that foundation early on, that way as you scale, it's just continuing to build on that and you don't have to come back and try to retrofit uh that as you've scaled over uh time.
SPEAKER_01For the for those listening and for those who are going to be at the APA CARES conference, um, what's one thing that you hope they get out of chatting with you and your team? What's that one nugget that you can give them?
SPEAKER_00The ABA field, as we've learned over the years, provides unique challenges like we've talked about today. Having someone who understands those challenges, who has been through them, who supports firms everywhere from 10 users all the way up to practices with a few thousand. That industry knowledge is very helpful uh in the uh in the ABA space.
SPEAKER_01What's your recommendation for folks on getting started with you? Does it start with a discovery call? Does it start with an informational survey? What's the first step for folks when they go into Alliance?
SPEAKER_00We do a discovery call introduction of Alliance, who we are, how we can help, uh, just so you understand and feel comfortable kind of with us. And then we start talking through what type of care do you provide? Is it in-home? Is it center-based? And we just start pulling back on that thread of uh of what we know about the industry. And then we can make some uh recommendations right off the bat. We can help build a roadmap, even before we get into the actual technical assessment, which would be the next step after that, just based on a conversation and a discovery call.
SPEAKER_01Well, Tom, I appreciate all that you've shared with us as well as all of your expertise. What sticks with me the most is that throughout all these conversations that I've been lucky enough to have with exhibitors and sponsors, we've talked about retention and culture, good clinicians, how to keep them. This conversation was more focused on the underlying uh facility, the groundwork that all of these other things are built on. And I appreciate the fact that honestly, someone is talking about it because it's not something that, frankly, before this podcast, I really thought a lot about. That's why Holly and the whole team at ABA CARES was really excited to get Alliance in the room. Most of us are not going to become security experts. I have no interest in it, and most of us will never get there. But being able to walk up to people who do this all day and ask them questions that you've been worried about in the back of your mind is something invaluable. So if that describes you, if you have some things that you're concerned about with your security, the Alliance Info System booth at the ABA Care Summit is the best place to go, or connect with them over their website and their LinkedIn profiles, which will all be in the show notes. Keep in mind that August 4th through the 7th is ABA CARES. That's where you will be able to find us in Boston. If you are one of the live attendees, we cannot wait to see you. If you're joining us virtual, well, then I hope you can't wait to see us over the live stream. Tom, thank you so much for being here and for all those listening. I hope you have a wonderful day.
SPEAKER_00Thanks, Matt. Thanks for having me.