continuity of care) are clinical events. Reframing cybersecurity events as clinical events aligns them with existing patient safety frameworks, emphasizing prevention, system design and human factors.
The Human Factor in Cybersecurity Risk
Despite substantial investments in technical safeguards, the majority of healthcare cyberattacks exploit human vulnerabilities rather than system flaws. Phishing attacks, credential theft and insecure user behaviors account for a large proportion of breaches. Clinicians, by virtue of their access to sensitive systems and data, are central to this risk landscape. Routine behaviors, such as clicking on email links, sharing login credentials or accessing patient data from unsecured devices, can bypass even the most sophisticated security infrastructure.
This evidence challenges the prevailing assumption that cybersecurity is primarily an IT responsibility. Instead, it suggests that clinician behavior is a decisive factor in determining system vulnerability. However, framing this solely as an issue of compliance or training is insufficient. Human behavior in clinical environments is shaped by cognitive load, time pressure, emotional stress and competing priorities. A physician managing a full clinic, navigating complex documentation requirements and responding to patient needs operates under conditions that are inherently vulnerable to error: not only clinical error, but digital error. Thus, cybersecurity risk cannot be fully mitigated without addressing the conditions under which clinicians think, decide and act.
The Physician as Practitioner: Cognitive Load, Burnout and Digital Risk
Medicine has long asked its practitioners to carry the weight of others’ suffering without adequate provision for their own cognitive and emotional sustainability. The result, reflected in high rates of burnout, depression and moral injury, represents a parallel crisis within the profession. When viewed through a biopsychosocial lens applied to the clinician, a similar gap emerges as in patient care: the existential dimension remains largely unaddressed. Yet this dimension directly influences attention, judgment and capacities required for both clinical care and secure system use.
Burnout is not merely an issue of well-being; it is a systems risk. Exhausted clinicians are more likely to click without scrutiny, reuse passwords or bypass security protocols in the interest of efficiency. Emotional depletion narrows attention and increases reliance on cognitive shortcuts, amplifying vulnerability to phishing and social engineering attacks. In this context, clinician well-being and cybersecurity are not separate domains. They are functionally interdependent.
Saint Intelligence as Clinical Infrastructure
Addressing this interdependence requires expanding the concept of professional competence. Technical skill and clinical knowledge, while necessary, are insufficient to meet the demands of modern practice. Clinicians must also develop capacities that support sustained attention, ethical clarity and emotional regulation under pressure.“ Saint Intelligence” can be understood as a secular, practical framework describing these capacities. It refers to the ability to remain present with complexity without becoming overwhelmed, to make decisions guided by values rather than fear and to act with consistency across high-pressure environments.
For the clinician, this is not a philosophical luxury. It is professional infrastructure. The ability to pause before clicking a suspicious link, to recognize urgency as a potential manipulation or to adhere to security protocols despite time pressure all depend on the same underlying capacities that support good clinical judgment. Operationally, this framework can be translated into a simple reflective hierarchy applied in real time:
· Head: What do I understand about this situation? Is this request legitimate?
· Heart: What am I feeling( urgency, anxiety, pressure?) and how might that be influencing my response?
· Habits: What practices have I built that guide my behavior under stress?
This“ Head – Heart – Habits” structure mirrors established models in behavioral science while remaining brief enough for use between clinical tasks. It reinforces the principle that secure behavior is not solely a matter of knowledge, but of awareness and practice.
Toward an Integrative Model: Life-GPS and System Design
A modern approach to cybersecurity in healthcare must integrate technological safeguards with human-centered design and clinician development. The Life-GPS framework offers one such organizing model:
· Guidance: Values-based decision-making that prioritizes patient safety and data integrity.
· Protection: Emotional and cognitive regulation that reduces susceptibility to manipulation.
· System: Habitual practices that reinforce secure and consistent behavior.
Importantly, this framework aligns with existing evidence-based interventions, including mindfulness-based stress reduction, acceptance and commitment therapy and self-compassion training. These approaches, already used to address clinician burnout, also enhance attention, impulse control and decision-making – capacities directly relevant to cybersecurity. From a systems perspective, this integration suggests that investments in clinician well-being are also investments in digital safety. Training programs that combine cybersecurity awareness with cognitive and behavioral skill development may be more effective than purely technical education. Similarly, system design should account for human limitations. Reducing alert fatigue, simplifying authentication processes and aligning workflows with clinical realities can decrease the likelihood of unsafe behaviors.
Caution as Protection: A Unifying Principle
Across clinical ethics, patient safety and cybersecurity, a common prin-( continued on page 24)
June 2026 23