Board Member & Advisor
Physician | Cybersecurity Founder | Digital Identity Innovator | Standards Contributor
Expertise
Identity Risk Exposure Assessment
Identifying where authentication weakness, credential sprawl, and unverified access create material enterprise risk before a breach forces the conversation.
Regulated Industry Fluency
Translating between clinical, financial, and technical stakeholders in environments where compliance, privacy, and patient or customer trust carry legal weight.
AI Threat Realism
Separating genuine exposure from vendor narrative as synthetic media, voice cloning, and automated social engineering reshape what identity verification must withstand.
Standards & Interoperability Judgment
Assessing whether security architecture aligns with emerging standards and can integrate across enterprise, payment, and healthcare systems rather than operating in isolation.
Deep Technology Commercialization
Evaluating the path from patent to product to procurement, including channel strategy, government contracting realities, and enterprise deployment friction.
Founder Accountability Discipline
Applying clinical rigor to performance claims, holding leadership to evidence rather than optimism, and protecting institutional credibility.
Areas of Advisory
Cybersecurity & Identity Governance
Advising boards on authentication strategy, access control posture, and the governance questions that surface after an identity-based incident.
Healthcare Technology Oversight
Providing clinical and operational perspective on health system digitization, patient data protection, and technology adoption inside care delivery.
Product & Commercialization Strategy
Offering founder-level perspective on taking protected technology from patent through pilot to enterprise and public sector deployment.
Regulatory & Compliance Alignment
Advising on privacy obligations, standards conformance, and the distinction between documented compliance and demonstrated security.
“A board does not need to understand the cryptography. It needs to know who has access, how that access was verified, and what happens the day that verification fails.”
Jose Bolaños, MDBoard Member & Advisor