Probably the simplest way to deal with "restricting" access to a known group of people, is by using
JS, of course this is my suggestion in keeping with my Keep-It-Simple filosofy.
All you need to do is name your html file in itself to a very obscure bunch of characters, have the script read the "password" and open up the appropriate window, if the pwd is wrong then an error page is opened. The obvious advantage is that there is NO mention of the target page under any circumstance.
If you find this idea acceptable, post here, and I can help you with the
JS, if u dont already know it.
Cheers