00:00:00.160 --> 00:00:05.759
Hello everyone, my name is Matt Harrington, and you are listening to Inside ABA Cares.
00:00:05.919 --> 00:00:15.199
Your behind-the-scenes space where we lay the foundation and set expectations for who you'll meet in August, both attendees, speakers, and of course our sponsors.
00:00:15.359 --> 00:00:22.800
We spend a lot of time at this conference talking about turnover, recruiting, retention, culture, and the cost of losing people.
00:00:22.960 --> 00:00:30.559
But there's one cost of turnover that we don't talk about too much, which has been getting more and more dangerous as time goes on.
00:00:30.719 --> 00:00:31.920
Consider this scenario.
00:00:32.159 --> 00:00:37.439
One of your best RVTs ends up leaving to go to grad school for a BCBA job.
00:00:37.600 --> 00:00:39.520
That's great, and you celebrate them.
00:00:39.840 --> 00:00:42.640
But when they leave, what happens to their access?
00:00:42.799 --> 00:00:56.880
What happens to their email, their tablet, their login, all of that protected tech that holds protected health information oftentimes stays open for days, for weeks, in the car, at the bottom of a drawer.
00:00:57.119 --> 00:01:04.560
The reality is, is those are all open doors into some of the most sensitive data that you hold, health information about the kids you serve.
00:01:04.799 --> 00:01:12.480
So turnover, as ugly as it is as a hiring problem, also has another side to the coin, which is the access and security.
00:01:12.719 --> 00:01:15.920
So my guest Tom handles exactly this.
00:01:16.159 --> 00:01:27.120
Tom McCadden is the CTO, the chief technical officer at Alliance Info Systems, a managed IT and security form firm that has built a specialty serving ABA practices across the country.
00:01:27.359 --> 00:01:37.439
Tom has spent two decades building the unglamorous mission critical stuff, the defenses that decide whether a breach becomes a disaster or a non-event.
00:01:37.599 --> 00:01:46.159
They're a preferred partner of many major ABA practice management organizations, and they support practices from 10 people to multiple thousand.
00:01:46.400 --> 00:01:48.079
Tom, thank you so much for being here.
00:01:48.239 --> 00:01:52.239
For those who don't know your story already, I'd love to have you tell it yourself.
00:01:52.480 --> 00:01:53.359
Thank you for having me.
00:01:53.519 --> 00:01:58.640
Um, so Alliance as an organization we've been around for uh 24 years.
00:01:58.879 --> 00:02:05.840
I've been with the organization for 20 years, started entry level and grew with the company.
00:02:06.079 --> 00:02:08.879
When we started, we were uh only three people.
00:02:09.039 --> 00:02:10.879
I was the fourth person hired.
00:02:10.960 --> 00:02:21.840
We're now a firm of uh 55 employees, 38 on the service side, and all HIPAA trained and certified on the support staff.
00:02:22.080 --> 00:02:34.000
Over the years, Alliance as a company has mainly grown by referrals and kind of word of mouth with the work that we do for our clients, uh, which is how we ended up in the ABA space.
00:02:34.159 --> 00:02:42.159
We started over 10 years ago with an ABA company, and they were two computer users at the time.
00:02:42.319 --> 00:02:49.439
Um, they've grown to over 600 and over 2,000 employees in total in multiple states.
00:02:49.599 --> 00:03:00.719
I do want to take a step back and highlight what I mentioned there just because kind of making the two worlds match in the sense of IT and ABA is when I defined as computer users.
00:03:00.879 --> 00:03:14.319
So from an IT support standpoint and security, the way that we work with ABA firms, there are employees who use laptops and there are mobile users and you know, the clinicians uh that are out in the field.
00:03:14.479 --> 00:03:16.719
That's the way that we uh we split those up.
00:03:16.800 --> 00:03:24.240
And as we get into talking more about security and access to platforms, uh, you'll hear me refer back to those.
00:03:24.560 --> 00:03:27.199
What are some of the risks just as you scale?
00:03:27.360 --> 00:03:36.400
And maybe take into account a company that started uh a couple years ago, they're at 30 employees and they're exploding, and we'll be at 75 by the end of the year.
00:03:36.719 --> 00:03:37.360
Yeah, absolutely.
00:03:37.599 --> 00:03:47.199
We've grown with ABA companies that have grown in both uh methods, whether that's de novo's or via acquisition, and both have challenges.
00:03:47.360 --> 00:04:00.400
Scaling and from the de novo standpoint, for example, you have to make sure that you have a proven process to open new centers to or remote employees uh that do maybe do in-home work or on location work.
00:04:00.560 --> 00:04:10.319
It's being able to, you know, kind of scale that up and have a proven process to get the user accounts created, get uh the devices in their hands that they need to do their job.
00:04:10.400 --> 00:04:24.000
And then acquisition is a whole nother challenge because then you are acquiring an entire maybe new center, new company that you need to transform that into your uh business practices.
00:04:24.240 --> 00:04:33.040
And when you do an acquisition, one thing to keep in mind is you're not just acquiring the company, you're also acquiring any risks associated with it.
00:04:33.279 --> 00:04:41.120
So a very strong due diligence process is certainly uh needed when you know you have that growth model.
00:04:41.519 --> 00:04:49.839
As your firm grew and you started looking at the different places where you could help and serve, what grew you to ABA specifically?
00:04:50.240 --> 00:04:57.360
We found they were fast-growing organizations, but they were also accepting of technology.
00:04:57.439 --> 00:05:06.560
And with it being still a fairly new industry, we found that a lot of them were coming in more cloud-first mindset already.
00:05:06.720 --> 00:05:13.199
So they didn't have a lot of this uh what we call technical debt that needed to be cleaned up in order to help move them forward.
00:05:13.519 --> 00:05:20.879
When someone leaves an ABA practice, especially in this field, typically we're talking about RBTs who who churn out pretty fast.
00:05:21.120 --> 00:05:22.399
What's supposed to happen?
00:05:22.560 --> 00:05:26.000
What's the ideal, most protected way to go about it?
00:05:26.560 --> 00:05:29.279
We work in a lot of different uh industries as well.
00:05:29.360 --> 00:05:36.000
And when we first started with ABA, I think most people getting into it was uh very surprised with that rate.
00:05:36.160 --> 00:05:52.480
Uh so we had to very quickly determine what's the best way to allow that to happen at scale, not just when someone leaves, but also when someone comes on board, and being able to automate a lot of those processes to be able to do that at scale.
00:05:52.720 --> 00:05:59.199
So there's kind of two factors when you talk about when someone leaves an organization or comes on for that matter.
00:05:59.360 --> 00:06:01.920
There's identity and then there's equipment.
00:06:02.079 --> 00:06:08.240
So there's access to the systems and then there's how they gain access on, you know, whether it be a tablet, a laptop.
00:06:08.480 --> 00:06:12.560
So we like to work with them to build that foundation first.
00:06:12.800 --> 00:06:16.959
So make sure that all of your applications are single sign-on.
00:06:17.199 --> 00:06:19.600
So you maintain that one source of truth.
00:06:19.839 --> 00:06:31.279
For example, if you disable a user in your HR system, because that's usually the first to start, and then you want that to flow through to all of your other systems seamlessly.
00:06:31.439 --> 00:06:35.920
So there's not a lot of you know opportunity for things to be missed.
00:06:36.399 --> 00:06:51.759
Having a streamlined way to lock down that user's access to any you know HIPAA protected data, uh, but then also making it uh you know easy to also lock down the device and recover that device if needed as well.
00:06:52.160 --> 00:06:59.839
With a lot of startups or even fast-growing companies, uh, this type of thing is oftentimes the last thing on their mind, right?
00:07:00.000 --> 00:07:05.759
There have a million other clinical things, they have a million other hiring cultural things to worry about.
00:07:06.000 --> 00:07:13.279
Where do you find this type of maybe not negligence, but just not paying attention to the right thing, that ignorance?
00:07:13.439 --> 00:07:15.199
Where does that come to bite them in the butt?
00:07:15.439 --> 00:07:18.560
It's always around the uh we'll get to that kind of mindset.
00:07:18.720 --> 00:07:24.959
And you know, we'll talk a little bit more about like the cybersecurity possible uh implications of that.
00:07:25.120 --> 00:07:28.959
But there's also things to think about from just like a reputational standpoint.
00:07:29.199 --> 00:07:40.720
You know, you don't want an employee that is no longer an employee to, let's say, have access to email, whether it be internally, externally, uh, to be able to send emails, receive emails.
00:07:40.800 --> 00:07:50.399
Uh so it's kind of those nuances that aren't thought about the what could happen, and we'll get to that until unfortunately sometimes that it does happen.
00:07:50.720 --> 00:08:00.480
Can you think of a story where all of a sudden these types of concerns that weren't even on an owner's mind suddenly become crucial, maybe in an audit or something similar?
00:08:00.800 --> 00:08:03.519
Yes, audit yeah, audits are definitely a big part of that.
00:08:03.600 --> 00:08:15.439
Um another part that we see a lot of times is unfortunately, if a user is uh or an owner is uh finding out about any of an issue, it's usually too late.
00:08:15.600 --> 00:08:35.200
Um, you know, so someone sends out a maybe a disgruntled email or they have access to um, you know, the practice management system after they are no longer or worse, if it's some type of financial transaction uh that may happen, like transfer or you know, payroll being deposited to the incorrect account, things like that.
00:08:35.279 --> 00:08:40.000
It's almost unfortunately too late by the time they find that out.
00:08:40.399 --> 00:08:44.799
What is typically the thing that triggers them finding all of this stuff out?
00:08:44.960 --> 00:08:50.480
Is it typically an audit or are there other leaks or security notifications that typically come up?
00:08:50.879 --> 00:09:01.840
It's the process and like what is the end-to-end process of you know a employee leaving, employee coming on board, and then making the technology fit into that.
00:09:02.000 --> 00:09:07.360
Unfortunately, like I said, it's a lot of times it they almost find out a little bit later.
00:09:07.919 --> 00:09:12.799
We don't see as much from audits unless we're coming in to do an assessment.
00:09:12.879 --> 00:09:19.200
Like we don't see third-party auditors uh coming in as much to uh the ABA space just yet.
00:09:19.360 --> 00:09:26.559
Uh, I think that is something that will come and continue to grow again as the space and the practice uh grows as a whole.
00:09:26.960 --> 00:09:35.200
Do you see behavioral health as in particular vulnerable to cyber attacks or cybersecurity breaches?
00:09:35.440 --> 00:09:35.759
I do.
00:09:35.840 --> 00:09:36.080
Yeah.
00:09:36.399 --> 00:09:39.840
A lot of the reason I say that it's protected information.
00:09:40.159 --> 00:09:43.279
It is especially uh children information as well.
00:09:43.360 --> 00:09:53.039
So and a lot of times, unfortunately, owners, especially of smaller firms, uh, well, they grow rapidly, as you mentioned, uh, so these things aren't always on their mind.
00:09:53.120 --> 00:09:57.519
But there's also sometimes the mindset of we're too small, no one's gonna target us.
00:09:57.759 --> 00:10:12.639
And what we see on the majority of incidents, uh, whether it's uh clients coming in or if it's attempted attacks against our existing clients, uh, they're more crimes of opportunity than actually being targeted.
00:10:12.799 --> 00:10:24.799
Um so thinking that your organization is too small or you don't have the financial data that maybe attackers are going for, things like that, is a very common misconception that we hear a lot as well.
00:10:25.120 --> 00:10:33.519
To go from uh, we'll say for a 25 company employee, right, fairly you know, small, maybe mid-size, depending on your definition.
00:10:33.759 --> 00:10:38.720
What does it cost in general to get up to snuff with security on some of these things?
00:10:39.039 --> 00:10:45.519
One of the biggest things that we see, and it all depends on where they are currently in their you know maturity level.
00:10:45.679 --> 00:10:55.360
Like for example, if you grew quickly from you know a five-person, 25, now 50, a lot of times they're using personal devices.
00:10:55.679 --> 00:10:57.519
Maybe the company didn't supply them.
00:10:57.679 --> 00:11:03.440
So there's no inventory management, there's no lockdown and control of those.
00:11:03.679 --> 00:11:19.600
So, really where I see, especially if firms try to visit that kind of after they've grown, now you're at, let's say, 500 employees, that's a much bigger lift and ends up being, you know, much more costly project to level set and get back to the basics.
00:11:19.840 --> 00:11:26.559
Now, when we provide one of the services that we provide is our managed security service.
00:11:26.720 --> 00:11:38.879
And we have built that over the years and scaled that with our partners to be able to provide really that enterprise grade security at like that small to medium business level as well.
00:11:39.039 --> 00:11:50.159
So uh it doesn't have to be a concern or a misconception that we're only 20 people, we can't afford to have like 24 by seven security operations center monitoring.
00:11:50.559 --> 00:11:54.960
That's within reach of all firms of all sizes today.
00:11:55.120 --> 00:12:00.720
And we're starting to see it, you mentioned audits on the um cyber liability insurance side.
00:12:00.799 --> 00:12:06.480
Uh things like 24 by 7 monitoring is starting to become not a nice to have, but a must-have.
00:12:06.799 --> 00:12:07.440
I'm curious.
00:12:07.600 --> 00:12:16.720
If I were an agency owner and I'm listening to this, going through my head right now, I'm probably thinking, oh my gosh, I'm gonna have to change this system, I'm gonna have to change that system.
00:12:16.879 --> 00:12:19.039
Everything I mean, I won't be able to use this.
00:12:19.120 --> 00:12:21.440
I'll have to switch over to this new thing and it's not gonna work.
00:12:21.519 --> 00:12:23.200
And my parents are gonna be mad and upset.
00:12:23.360 --> 00:12:28.639
Can you talk about what that transition process looks like, especially if they came to you, started your service?
00:12:28.720 --> 00:12:31.679
How would you help them through that process?
00:12:32.080 --> 00:12:32.399
Sure.
00:12:32.559 --> 00:12:45.039
Both from an IT standpoint and from a cybersecurity standpoint, we want to be as least impactful for you providing the service uh to the children as possible.
00:12:45.279 --> 00:12:48.480
So we want to protect you, but we want to be on the back end.
00:12:48.559 --> 00:12:54.559
Uh, we don't have any kind of barrier to entry, any impact to providing uh that service.
00:12:54.720 --> 00:13:15.519
So one example I can uh give you of that is we work with and help, you know, RVTs usually in this case, like if they are maybe providing services and they need to log into their practice management system, but we want to lock it down with multi-factor authentication, you know, to keep the system safe.
00:13:15.759 --> 00:13:18.080
But maybe they can't have their phone and treatment.
00:13:18.240 --> 00:13:27.279
It's unique challenges that the ABA industry has to need to solve for those problems and not get in the way of the mission or or the goal.
00:13:27.440 --> 00:13:32.559
We're familiar with those and we're able to come up with those creative solutions to not be a barrier.
00:13:32.799 --> 00:13:33.039
Yeah.
00:13:33.200 --> 00:13:33.759
That makes sense.
00:13:33.840 --> 00:13:51.039
It kind of points to why you need somebody who specializes because even like I'm obviously deep in ABA myself, I didn't even think of the fact that, you know, I have my phone on me all the time for multi-factor authentication, which isn't allowed on some units uh just for safety reasons.
00:13:51.279 --> 00:14:02.240
Well, when a practice calls you and you start having conversations with them, is there a moment where you think that if only you had talked to me a month ago, if only we could have fixed this sooner?
00:14:02.480 --> 00:14:05.440
When's that like a crap, if only moment?
00:14:05.600 --> 00:14:07.840
And how can owners be prepared for it?
00:14:08.080 --> 00:14:18.320
Yeah, it's definitely around a lot of it is around asset management and asset inventory, knowing what all is out there and having the ability to manage and control that.
00:14:18.480 --> 00:14:24.639
So part of our security solution includes a asset management, it's uh remote monitoring and management.
00:14:24.720 --> 00:14:28.480
So we're able to monitor the devices, secure the devices.
00:14:28.720 --> 00:14:48.639
And if you have um employees either that provide, let's say, in-home or on-site care, and or that they have uh, you know, multiple centers uh spread out, you know, kind of across the US, wrangling that in and actually getting that time to install that software so we can help secure them, we can manage them.
00:14:48.879 --> 00:14:56.240
That's usually the biggest time constraint uh and costly of a you know project to build that foundation.
00:14:56.480 --> 00:15:11.600
So one of the things, just starting out, if you're a smaller firm, try to again get I know I keep saying this, but back to the basics and build that foundation early on, and then it'll save you such an amount of time and headache down the road.
00:15:12.000 --> 00:15:13.120
Asset management.
00:15:13.200 --> 00:15:15.279
Uh can you talk a little bit more about that?
00:15:15.360 --> 00:15:22.799
Maybe explain it for those who their biggest understanding of asset management is if they should buy an iPad or an Android tech device.
00:15:23.120 --> 00:15:26.240
I mentioned the computer users versus mobile users.
00:15:26.480 --> 00:15:36.799
So um, you're talking about a laptop versus uh tablets, usually, the ability to monitor them, to control them, to keep them secure, even to help troubleshoot them.
00:15:36.960 --> 00:15:43.840
Uh let's say your practice management provider rolls out a new app that you want to push out to all of your tablets.
00:15:44.080 --> 00:15:45.519
Do you have the ability to do that?
00:15:45.679 --> 00:15:53.600
Or is it going to take each one of them 15, 20 minutes each to install the new app so they can start providing those services?
00:15:53.679 --> 00:16:01.840
And 10, 15, 20 minutes doesn't sound like a lot, but if you're talking about doing that across 1500 tablets, that adds up pretty quickly.
00:16:02.000 --> 00:16:12.159
So knowing not just where the tablets are from an asset standpoint, but also the ability to help support and control them is a key part of that as well.
00:16:12.480 --> 00:16:19.600
The first ABA company I ever worked for, the iPads were all connected to the owner's son's Apple IV.
00:16:19.759 --> 00:16:24.000
And that son switched off of Apple years ago for Android.
00:16:24.080 --> 00:16:30.960
And so whenever I would try and install an app as a clinic director, I couldn't because I needed a password that was no longer accessible.
00:16:31.120 --> 00:16:32.879
And it was all it was a whole mess.
00:16:33.039 --> 00:16:40.879
One of the hot debates in ABA is which laptop should I buy my BCBAs and which tablet should I buy my technicians?
00:16:41.200 --> 00:16:45.600
Is there a strong opinion you have over that in terms of security?
00:16:45.759 --> 00:16:46.639
Uh we don't.
00:16:46.799 --> 00:16:56.320
Uh so we support on the laptop side both Windows and Mac OS from asset management inventory, cybersecurity protection standpoint.
00:16:56.559 --> 00:17:03.600
And also with the tablets to manage those, you use something called mobile device management or MDM.
00:17:03.759 --> 00:17:09.440
And they work on both Android and Mac OS or iOS on the tablets.
00:17:09.599 --> 00:17:25.920
And a lot of times it comes down to availability and cost, and then also like just knowing what they're going to use it for in their day-to-day and try to find the best, most affordable device uh for them to uh to get their job done.
00:17:26.240 --> 00:17:33.920
Are you able to do a similar asset management job when staff are using personal phones for data collection?
00:17:34.160 --> 00:17:36.160
So personal phones, yes.
00:17:36.319 --> 00:17:51.920
Uh specifically, what we typically do, not to go too far down the you know down that rabbit hole, but on like the uh mobile device management solutions, we have the ability to control at an application level without actually controlling the phone.
00:17:52.079 --> 00:18:13.599
So in practice, what that could look like is you could say, you know, my company has our practice management app, we have our Outlook or Google Mail, we may have OneGive or Google Drive, um, and the ability to, if that person leaves, that information in those company-owned apps are kind of siloed from all of their personal data.
00:18:13.759 --> 00:18:21.359
So you would have the ability to wipe out just those apps while not even having access or seeing anything into their personal devices.
00:18:21.599 --> 00:18:27.519
So that allows almost all companies that we work with, ABA or other industries, have personal devices.
00:18:27.680 --> 00:18:33.759
We see less and less nowadays where the company is providing the uh the phone specifically.
00:18:34.000 --> 00:18:46.559
So having that still keeping the organization secure, but also respecting the employees' personal privacy is kind of key in those bring your own device or BYOD scenarios like that.
00:18:46.880 --> 00:18:59.359
In the intro, I mentioned a really common scenario where somebody leaves for whatever reason and devices get thrown in a drawer or just you know scattered and everyone kind of forgets about them.
00:18:59.680 --> 00:19:04.559
With really strong security protocols and asset management, what does that process look like?
00:19:04.799 --> 00:19:16.240
Yeah, and that's going to depend on, again, not just unique to the ABA industry, but the you know healthcare industry in general, is whether it's collecting from a center or collecting a clinician that may be out in the field.
00:19:16.400 --> 00:19:18.240
It all comes down to laying that process.
00:19:18.480 --> 00:19:23.759
I've said that a couple of times, but like what is the process, not just when someone leaves, but how do you collect the device?
00:19:24.000 --> 00:19:25.279
Who's responsibility?
00:19:25.440 --> 00:19:26.799
Who's the owner?
00:19:26.960 --> 00:19:28.559
Is it the center administrator?
00:19:28.720 --> 00:19:31.920
Is it someone within HR that handles that?
00:19:32.160 --> 00:19:35.839
And then we talk through that process with owners.
00:19:36.079 --> 00:19:46.880
We let them know what we've seen as successful in other ABA firms, and then we help them build that process from a business standpoint, and then we back the technology into it.
00:19:47.039 --> 00:19:54.160
So we never come into like ABA firms and say, here's your mobile device management, here's your asset management.
00:19:54.400 --> 00:20:05.519
We can make suggestions, what we've seen work in the past to help your business get to that, but we want to transform the technology to you, not make you transform your business to technology.
00:20:06.000 --> 00:20:07.680
You've talked a lot about processes.
00:20:08.079 --> 00:20:15.039
Typically in the age of AI and automation, after processes comes automation, after automations come AI.
00:20:15.200 --> 00:20:18.319
So I'm curious what is the next step?
00:20:18.480 --> 00:20:26.480
How do we take some of the human error out of the conversation so we can harden our security protocols even further with automation?
00:20:26.640 --> 00:20:29.200
And is AI in the question on these types of things?
00:20:29.440 --> 00:20:30.319
Yeah, absolutely.
00:20:30.400 --> 00:20:38.720
Uh I have the AI conversation, as you can imagine, quite frequently now with uh not just our ABA clients, but other industries as well.
00:20:38.960 --> 00:20:51.759
And it provides a unique challenge, especially to a couple things within like the ABA space, is you never want to trust AI for any treatment advice or anything to that matter.
00:20:51.920 --> 00:21:12.880
You also have to be very careful with the data that's put in to AI platforms, you know, especially uh like the free versions of all of the Chat GPT, Copilot, Claude, what any of those out there, there's a chance that any protected information that may enter them, if they're the free version, that it could be exposed.
00:21:13.039 --> 00:21:17.039
So having that plan just to introduce AI.
00:21:17.200 --> 00:21:21.039
So an AI-driven policy that is laid out to your organization.
00:21:21.200 --> 00:21:32.640
I always tell clients too, when it comes to AI, uh this is a lot around the cybersecurity conversations I used to have years ago as well, is don't just make that a technology of no, you can't do that.
00:21:32.960 --> 00:21:38.799
You always want to answer no, but here's what the you know organization allows.
00:21:38.880 --> 00:21:41.039
Here's the guardrails that we put in place.
00:21:41.200 --> 00:21:43.759
Because if not, they're gonna find a way to do it, right?
00:21:43.920 --> 00:21:47.680
If if you don't give them a secure means of doing so.
00:21:48.079 --> 00:22:01.440
And then you start looking at once you have that kind of foundation of you know the guardrails and the policies around AI and training for your staff, it then also comes into now what you We're talking about implementation.
00:22:01.599 --> 00:22:07.920
So start looking at some of those easy, kind of low-hanging fruit things that you can automate.
00:22:08.079 --> 00:22:19.200
So maybe it's just something like intake and some of that process, or, you know, maybe like the front of your physical center, like the front desk sign-in process and all of the flows on the back end.
00:22:19.359 --> 00:22:23.039
So again, very similar to like I mentioned with cybersecurity earlier.
00:22:23.200 --> 00:22:27.920
We're having those same type of conversations around all right, what's your business processes?
00:22:28.000 --> 00:22:32.799
And now how can we fit automation and and possibly AI into those processes?
00:22:33.119 --> 00:22:41.599
Is there a use case for automation, especially that if you could wave a magic wand and give it to the ABA field, everyone would be happy?
00:22:41.759 --> 00:22:45.839
Like just like a slam dunk that you want to just say, just do this at least.
00:22:46.160 --> 00:23:32.240
Yeah, I mean, definitely around from the cybersecurity standpoint, around getting ahead of it, uh policies, procedures around what's allowed, what's not, some like practical use case that I mentioned that uh we've seen and we're, you know, consulting with some of our uh clients around in the ABA space is certain things like intake, like I mentioned, signing in process, signing out process, uh checking in, checking out for employees, not just uh, you know, parents uh and children, but then even around getting into more of the weeds and maybe doing like a first pass on treatment plan review, not for any clinical terms or any clinic, but just things that you may submit to insurance for that claim to be processed that it needs to include.
00:23:32.400 --> 00:23:49.440
So nothing on the medical side, and uh I know I keep highlighting that, but that's very important that you don't use that as something giving you advice, but you can use it to, you know, maybe increase or like the frequency of reviews of those plans, just as another example.
00:23:49.920 --> 00:23:55.119
What do you find is the most common barrier to people putting in automation?
00:23:55.279 --> 00:23:56.720
Is it tech debt?
00:23:57.039 --> 00:24:19.839
It's mostly uh what is possible out there, you know, and that's what we work with firms to okay, let's look at your practice management software, let's look at your HR platform and see do they have the ability to build any type of automations into it and let us contact the vendors for you and let you know if it is possible and to what extent.
00:24:20.000 --> 00:24:26.319
And then you decide, you know, is that investment on that automation process worth going through or not?
00:24:26.480 --> 00:24:29.920
Because maybe it automates 10%, maybe it automates 95.
00:24:30.160 --> 00:24:34.880
But we help work with those third-party vendors to determine that on your behalf.
00:24:35.279 --> 00:24:50.880
You mentioned uh when we were talking about your staff and managing security, you mentioned something along the lines of when a staff asks for an ability to do something, you have to give them a no, but you can do it this way, a secure way.
00:24:51.200 --> 00:24:58.960
Are you finding that becoming more and more of a problem as the younger generation of the RBTs become more and more tech native?
00:24:59.200 --> 00:25:05.200
As you know, the RBTs are usually the largest uh section of your uh employees, right?
00:25:05.359 --> 00:25:12.640
Uh to license them for anything or uh provide them additional licenses, uh there can be a cost to that.
00:25:12.720 --> 00:25:15.920
Um we saw that very early on with just email.
00:25:16.079 --> 00:25:26.240
They weren't provided with maybe firm or company uh practice emails, so they would just use personal email, communicate with uh parents with uh personal emails.
00:25:26.319 --> 00:25:30.799
And then from there we saw it more on the uh file sharing side.
00:25:30.960 --> 00:25:45.359
So using personal OneDrive, personal Google, and there's just ways like specifically in like there's a type of Microsoft license, for example, that is very affordable, but provides them with those types of functionality.
00:25:45.519 --> 00:25:53.599
So again, knowing that and knowing how they work, what they need to do in those roles, and providing them that functionality is really key.
00:25:53.680 --> 00:25:57.279
And again, that comes back to knowing and working in the industry for so long.
00:25:57.599 --> 00:26:00.559
And now we're also seeing that uh with AI.
00:26:00.720 --> 00:26:03.279
And because again, that's just kind of the next evolution.
00:26:03.359 --> 00:26:08.400
It was email, it was files, and now we're at the you know the age of AI and we're seeing it there as well.
00:26:08.720 --> 00:26:15.920
As a company, if you looked at three different companies, one small starting out, one mid-size, and a national large provider.
00:26:16.160 --> 00:26:20.240
Can you walk through some of the different security risks at each size?
00:26:20.640 --> 00:26:23.359
Small is usually that um mindset that I mentioned.
00:26:23.759 --> 00:26:38.400
No one's attacking us, no one's targeting us, and also not, especially if it's a startup, not having the funds to put into you know buying company-owned devices for um you know, for people to use.
00:26:38.559 --> 00:26:44.240
Uh so just kind of getting that foundation, but that is the easiest place to implement that.
00:26:44.480 --> 00:26:47.119
Mid-size is what you where you run in.
00:26:47.359 --> 00:26:55.200
So now they have a to get them to that foundation, it may cost more because you have more devices out there, you have more employees.
00:26:55.359 --> 00:26:58.559
You're also starting to increase your tax surface.
00:26:58.640 --> 00:27:04.559
Uh, the more employees you have, the more chances for phishing emails and social engineering type attacks.
00:27:04.720 --> 00:27:08.880
And then that rolls right into the larger nationwide providers.
00:27:08.960 --> 00:27:11.039
They may be ones that are being targeted.
00:27:11.200 --> 00:27:26.000
And they do have that much larger footprint uh to where they could possibly be tacked, the more employees, the larger the attack surface, the more data you have, the more capital you may have for those type of financial-based attacks.
00:27:26.240 --> 00:27:39.519
You mentioned phishing, and that like triggered in me the memories of working at a large hospital organization and your co-worker clicking on the phishing link, and suddenly you all have to go through and do the training again.
00:27:39.759 --> 00:27:40.319
Yeah.
00:27:40.640 --> 00:27:45.359
But uh it's it's a real point in terms of social engineering and getting scams.
00:27:45.440 --> 00:27:48.559
It's more than just somebody emailing you and asking for gift cards.
00:27:48.799 --> 00:27:54.400
Can you go through some of the scams or risks that behavioral health organizations?
00:27:55.119 --> 00:27:55.839
Yeah, absolutely.
00:27:56.000 --> 00:28:12.319
So we do provide as part of our managed security service uh phishing simulations, email, uh email protection, and end user training, because to your point, it that is what we find the largest uh attack kind of surface there.
00:28:12.480 --> 00:28:17.119
It's still just the easiest barrier entry for these um attackers.
00:28:17.200 --> 00:28:27.920
Uh and with everything being cloud-based, it's not the scenario of that big hospital that you know has server rooms and uh and data warehouses that they need to protect.
00:28:28.000 --> 00:28:29.839
You know, everything is more cloud-based.
00:28:29.920 --> 00:28:33.839
So the attackers are going, they want the user's credentials.
00:28:33.920 --> 00:28:36.480
They want to be able to log in as that user.
00:28:36.559 --> 00:28:43.359
Uh and maybe it's just the RBT that clicked on that phishing email and had their account compromised.
00:28:43.519 --> 00:28:47.839
That may just be a stepping stone for what an attacker is trying to do.
00:28:48.160 --> 00:28:55.759
They may use that to go further up the chain and send additional social engineering kind of emails with inside of there.
00:28:56.000 --> 00:29:02.000
We are still seeing by far that's the largest attack surface that's social engineering and phishing.
00:29:02.319 --> 00:29:07.039
So it's more than just uh my CEO asking me for in the moment gift cards.
00:29:07.279 --> 00:29:07.759
You know?
00:29:08.079 --> 00:29:08.400
Yes.
00:29:08.880 --> 00:29:15.519
Yeah, and a lot of the attacks that uh they're attempting to do with phishing, they're becoming more and more sophisticated.
00:29:15.599 --> 00:29:18.240
I mean, it's continuously this cat and mouse game, right?
00:29:18.319 --> 00:29:21.839
If we educate people, hey, don't buy those Apple gift cards.
00:29:22.000 --> 00:29:30.640
Well, then the attackers need to find a different way in and to where the user may not even know that anything happened that just could be a normal login prompt.
00:29:30.720 --> 00:29:33.759
And they log in and it takes them to where they want to go.
00:29:33.920 --> 00:29:36.640
But on the back end, uh, you know, the attacker could have captured.
00:29:36.799 --> 00:29:45.759
So that monitoring for those type of activities and those type of anomalous activities is where we see it that's really critical nowadays.
00:29:46.079 --> 00:29:49.680
With some of those additional risks come additional security.
00:29:49.920 --> 00:29:54.240
The HIPAA security rule is changing pretty soon coming up.
00:29:54.480 --> 00:30:00.640
Things that used to be optional, like multi-factor authentication, encryption are now becoming required.
00:30:00.880 --> 00:30:08.160
In your estimation, how many practices in behavioral health, like what percentage would you say are actually prepared for the new ruling?
00:30:08.799 --> 00:30:18.160
I'd say 50, 60 percent that we come across that we just do um like initial engagements with or just discussions at conferences and and things like that.
00:30:18.319 --> 00:30:31.759
We find that multi-factor specifically, or or even encryption for that matter, they turn it on or they enable it on certain areas, but then they may not enable it everywhere across the board.
00:30:31.920 --> 00:30:34.799
So there's some of those gaps in like MFA.
00:30:35.200 --> 00:30:38.079
We encrypted all of our laptops, but not our tablets.
00:30:38.400 --> 00:30:44.480
Most firms we don't see that are at that 100% covered because there's little gaps.
00:30:44.559 --> 00:30:45.680
There's a lot of systems.
00:30:45.839 --> 00:30:47.759
Do you have MFA on everything?
00:30:47.920 --> 00:30:55.119
So your Microsoft, your Google, as well as your practice management system, um, your HR system.
00:30:55.279 --> 00:31:01.440
So it's that full breadth of coverage that we're seeing is not as covered as you know you would hope.
00:31:01.599 --> 00:31:06.640
But it's definitely a lot better, to be honest, than we would have even seen three, four years ago.
00:31:07.039 --> 00:31:16.240
Is there a difference in risk of a company who is 50% there versus 90% there or 99% there?
00:31:16.480 --> 00:31:20.160
Or is it a truly one loose chain knocks everything over?
00:31:20.640 --> 00:31:24.960
It depends where that uh where kind of that loose or that gap could be.
00:31:25.200 --> 00:31:37.039
A lot of times what I do see though is if they're only 50 to 60% there, for example, sometimes that can create a uh you know, false sense of uh confidence around security.
00:31:37.200 --> 00:31:49.200
Um like we may have Microsoft lockdown, for example, but not thinking about like the practice management system, which that's where a lot of your Hipposcoped data lives, uh, you know, and being able to do that.
00:31:49.359 --> 00:31:53.519
That's why like that foundation of making it easy as well.
00:31:53.680 --> 00:31:57.759
Like we usually recommend single sign-on wherever you can.
00:31:57.839 --> 00:32:07.839
So then that's one source of truth, one area that needs to be protected because that's your only identity, rather than everyone having 10 accounts throughout the organization that you need to lock down.
00:32:08.160 --> 00:32:20.640
When it comes to locking down offboarding, is there a way that you could do that through automations within the overall maybe alliance infosystems ecosystem?
00:32:20.799 --> 00:32:25.599
Like, is it a conversation that's hey X person off-boarded, can you shut them down?
00:32:25.680 --> 00:32:28.319
Or is there a way to take the human error out of that?
00:32:28.960 --> 00:32:29.359
Sure.
00:32:29.519 --> 00:32:44.160
So uh a lot of times what we would want to do, especially with ABA, because like we started off the conversation of the that high turnover rate, unfortunately, in ABA firms, is we would want to automate that as much as possible with human oversight.
00:32:44.400 --> 00:32:45.519
So I'll give you an example.
00:32:45.839 --> 00:32:53.680
We would connect, let's say, your HR system, because that's usually the source of truth, because that's usually tied to payroll and and things like that.
00:32:53.920 --> 00:33:02.640
That's then connected to your Microsoft or Google account, which then it's also connected to your practice management system.
00:33:02.720 --> 00:33:20.880
And maybe if you have any marketing platforms or Salesforce type platform out there, and then you would want whoever is responsible for that, whether it's someone in HR or management, to be able to turn that account off in one place and feel comfortable that it was taken care of everywhere else.
00:33:21.039 --> 00:33:29.119
Uh, that human insight piece that or oversight is where we always trust but verify when it comes to automation.
00:33:29.279 --> 00:33:35.200
So we would have a ticket created after all the changes to make sure everything was successful.
00:33:35.440 --> 00:33:54.480
Now that offboarding goes from a you know 15 to 30 minute hands-on the keyboard technician handling it to a three-minute look over the uh results of the output of everything that the automation did, and it can take that time to resolution drastically down.
00:33:54.799 --> 00:34:00.079
One thing that you've shared in the past is that security isn't just protection.
00:34:00.160 --> 00:34:04.319
It's a practice that you can show parents and help build trust with them.
00:34:04.559 --> 00:34:09.039
How should the owner think about their data security as a trust symbol?
00:34:09.360 --> 00:34:15.360
The way that I have that conversation around data security is you're building that foundation of trust.
00:34:15.519 --> 00:34:27.119
The parents are trusting that their children will be safe when they're dropped off at the center or when they're you know in the care of um you know an RBT or an ABA organization.
00:34:27.280 --> 00:34:32.159
And they would want to have that same trust with their child's information and their child's data.
00:34:32.320 --> 00:34:44.719
So that's the kind of talking point there is that you know, you have that end-to-end safety discussion, not just physical safety like everyone thinks right off the bat, but also their digital safety as well.
00:34:45.119 --> 00:34:55.119
Do you think that in general most ABA practices that you meet are overprepared or underprepared for a security breach or cyber attack?
00:34:55.440 --> 00:35:16.000
Especially when you're at the small to medium uh size of that, uh, they're still getting better, but still for an actual breach to do like a tabletop exercise of an incident to see who is responsible uh for what roles, what can happen during a breach, how chaotic, depending upon the uh scope of that breach, can be.
00:35:16.320 --> 00:35:23.199
I think there's still a good amount of work to do there to uh to prepare for something like that to happen.
00:35:23.679 --> 00:35:35.360
Is there is there one thing that comes to mind that if you said, if nothing else, if you can just do this by Friday, I would feel more comfortable with your your practices, security standards.
00:35:35.599 --> 00:35:36.639
What would that thing be?
00:35:37.039 --> 00:35:38.960
I'd say think about the basics.
00:35:39.039 --> 00:35:53.599
And again, I know I've mentioned it over and over, but building that foundation, having your asset management, having everything as single sign-on tied back to kind of one source of truth, so then you know where everything authenticates to and from.
00:35:53.920 --> 00:36:01.599
Because then that can lead you right into the more effective protection, such as multi-factor authentication.
00:36:01.679 --> 00:36:15.920
So really building that foundation early on, that way as you scale, it's just continuing to build on that and you don't have to come back and try to retrofit uh that as you've scaled over uh time.
00:36:16.320 --> 00:36:26.480
For the for those listening and for those who are going to be at the APA CARES conference, um, what's one thing that you hope they get out of chatting with you and your team?
00:36:26.639 --> 00:36:28.559
What's that one nugget that you can give them?
00:36:28.960 --> 00:36:35.039
The ABA field, as we've learned over the years, provides unique challenges like we've talked about today.
00:36:35.199 --> 00:36:44.320
Having someone who understands those challenges, who has been through them, who supports firms everywhere from 10 users all the way up to practices with a few thousand.
00:36:44.480 --> 00:36:49.199
That industry knowledge is very helpful uh in the uh in the ABA space.
00:36:49.599 --> 00:36:52.880
What's your recommendation for folks on getting started with you?
00:36:53.039 --> 00:36:54.719
Does it start with a discovery call?
00:36:54.800 --> 00:36:57.119
Does it start with an informational survey?
00:36:57.280 --> 00:36:59.760
What's the first step for folks when they go into Alliance?
00:37:00.079 --> 00:37:09.679
We do a discovery call introduction of Alliance, who we are, how we can help, uh, just so you understand and feel comfortable kind of with us.
00:37:09.760 --> 00:37:12.719
And then we start talking through what type of care do you provide?
00:37:12.800 --> 00:37:13.599
Is it in-home?
00:37:13.679 --> 00:37:14.639
Is it center-based?
00:37:14.800 --> 00:37:18.960
And we just start pulling back on that thread of uh of what we know about the industry.
00:37:19.119 --> 00:37:23.199
And then we can make some uh recommendations right off the bat.
00:37:23.360 --> 00:37:33.599
We can help build a roadmap, even before we get into the actual technical assessment, which would be the next step after that, just based on a conversation and a discovery call.
00:37:33.840 --> 00:37:38.719
Well, Tom, I appreciate all that you've shared with us as well as all of your expertise.
00:37:38.880 --> 00:37:51.039
What sticks with me the most is that throughout all these conversations that I've been lucky enough to have with exhibitors and sponsors, we've talked about retention and culture, good clinicians, how to keep them.
00:37:51.280 --> 00:37:59.039
This conversation was more focused on the underlying uh facility, the groundwork that all of these other things are built on.
00:37:59.199 --> 00:38:08.000
And I appreciate the fact that honestly, someone is talking about it because it's not something that, frankly, before this podcast, I really thought a lot about.
00:38:08.400 --> 00:38:14.800
That's why Holly and the whole team at ABA CARES was really excited to get Alliance in the room.
00:38:15.039 --> 00:38:17.840
Most of us are not going to become security experts.
00:38:18.000 --> 00:38:20.719
I have no interest in it, and most of us will never get there.
00:38:20.880 --> 00:38:28.559
But being able to walk up to people who do this all day and ask them questions that you've been worried about in the back of your mind is something invaluable.
00:38:28.800 --> 00:38:45.119
So if that describes you, if you have some things that you're concerned about with your security, the Alliance Info System booth at the ABA Care Summit is the best place to go, or connect with them over their website and their LinkedIn profiles, which will all be in the show notes.
00:38:45.360 --> 00:38:49.679
Keep in mind that August 4th through the 7th is ABA CARES.
00:38:49.840 --> 00:38:52.400
That's where you will be able to find us in Boston.
00:38:52.639 --> 00:38:56.639
If you are one of the live attendees, we cannot wait to see you.
00:38:56.880 --> 00:39:02.800
If you're joining us virtual, well, then I hope you can't wait to see us over the live stream.
00:39:02.960 --> 00:39:06.000
Tom, thank you so much for being here and for all those listening.
00:39:06.079 --> 00:39:07.119
I hope you have a wonderful day.
00:39:07.360 --> 00:39:07.840
Thanks, Matt.
00:39:07.920 --> 00:39:08.400
Thanks for having me.