Customer Case Studies

Compliance Programs
Built, Not Bolted On.

Iron Fort customers are lean teams carrying real regulatory weight — connected medical devices streaming physiological data, and clinical workforces touching PHI at dozens of client sites. Here is how they got audit-ready and stayed that way.

HIPAASecurity & Privacy Rule
SOC 2Trust Services Criteria
ITSG-33Government of Canada

Two Very Different Compliance Problems

One customer builds a regulated product. The other deploys a regulated workforce. Both needed the same thing: a documented, continuously maintained program they could put in front of a partner, an auditor, or a regulator on demand.

Anjo.ai
anjo.ai
Device Manufacturer HIPAA SOC 2

Building a HIPAA Program Alongside a Connected Medical Device

Anjo.ai's wearable-integrated platform analyses physiological signals to detect severe allergic reactions early. Continuous data from consumer wearables, a mobile app, a cloud backend, and a clinician-facing review portal meant PHI touched every layer of the stack — and academic medical centre and platform partners ran security diligence before a single record could flow.

Read the case study →
SyncNurse
syncnurse.com
HIPAA & Training Business Associate Workforce

Documented HIPAA Training for a Distributed Per Diem Nursing Workforce

SyncNurse places per diem nurses into infusion centres and wellness clinics. Every clinician handles PHI at a client facility, and every client facility asks for proof of HIPAA training and a signed BAA before a shift is covered — a required implementation specification that spreadsheets could not evidence at hiring speed.

Read the case study →

Small Teams. Regulator-Sized Obligations.

Neither customer had a full-time compliance department. Both are accountable under HIPAA the moment PHI moves.

One Documented PHI Inventory

Every system, integration, and subprocessor that touches protected health information — inventoried once, then kept current as the architecture changes.

Evidence That Already Exists

Control tests, policy approvals, training completions, and risk decisions captured with timestamps — so a diligence request is answered from the record, not reconstructed.

A Program That Stays Current

Configuration drift, expiring BAAs, and lapsed workforce training surface as alerts instead of being discovered during an audit.

Join Our Case Study Program

Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.

We Do the Writing

A compliance writer and an Iron Fort engineer handle the interview, the draft, and the design. Your team reviews and approves every word before anything is published.

Co-Marketing Reach

Your story goes in front of Iron Fort's network of health tech decision-makers, government buyers, and SaaS founders — with a link back to you.

Assets You Keep

A publish-ready PDF and web version for your own sales, procurement, and investor conversations — yours to use however you like.