Board Member & Advisor

Physician | Cybersecurity Founder | Digital Identity Innovator | Standards Contributor

Expertise

Identity Risk Exposure Assessment

Identifying where authentication weakness, credential sprawl, and unverified access create material enterprise risk before a breach forces the conversation.

Regulated Industry Fluency

Translating between clinical, financial, and technical stakeholders in environments where compliance, privacy, and patient or customer trust carry legal weight.

AI Threat Realism

Separating genuine exposure from vendor narrative as synthetic media, voice cloning, and automated social engineering reshape what identity verification must withstand.

Standards & Interoperability Judgment

Assessing whether security architecture aligns with emerging standards and can integrate across enterprise, payment, and healthcare systems rather than operating in isolation.

Deep Technology Commercialization

Evaluating the path from patent to product to procurement, including channel strategy, government contracting realities, and enterprise deployment friction.

Founder Accountability Discipline

Applying clinical rigor to performance claims, holding leadership to evidence rather than optimism, and protecting institutional credibility.

Areas of Advisory

Cybersecurity & Identity Governance

Advising boards on authentication strategy, access control posture, and the governance questions that surface after an identity-based incident.

Healthcare Technology Oversight

Providing clinical and operational perspective on health system digitization, patient data protection, and technology adoption inside care delivery.

Product & Commercialization Strategy

Offering founder-level perspective on taking protected technology from patent through pilot to enterprise and public sector deployment.

Regulatory & Compliance Alignment

Advising on privacy obligations, standards conformance, and the distinction between documented compliance and demonstrated security.

“A board does not need to understand the cryptography. It needs to know who has access, how that access was verified, and what happens the day that verification fails.”

Jose Bolaños, MDBoard Member & Advisor