Case Studies/Device Manufacturer
Medical Device & Digital Health

Anjo.ai: A HIPAA Program Built
Alongside the Device.

Anjo.ai is building an AI-enabled platform for managing severe and life-threatening allergies — analysing physiological signals from wearables to deliver remote monitoring, early detection, and personalised allergy insights. Protected health information moves through every layer of that stack, so the compliance program had to be engineered in, not retrofitted before a launch date.

Medical DeviceIndustry
HIPAA + SOC 2Frameworks
New York & Tel AvivLocations
Pre-CommercialStage

The Company

Anjo.ai develops an AI-enabled platform for people living with severe and life-threatening allergies. The system continuously monitors physiological data from smartwatches and similar wearables, and applies a patent-pending model to detect the early signs of an allergic reaction before severe symptoms present.

Around that core, the platform surfaces daily risk factors, alerts users when they are separated from their epinephrine auto-injector, and logs allergic events for clinical review. It is designed to be useful across the whole arc of care — diagnosis, therapy, and everyday life — including in clinical settings such as Oral Food Challenge testing. The company is headquartered in New York with an office in Tel Aviv, and works with partners including Mount Sinai, Samsung Health, Intrommune, and the Allergy Fund.

Why this is a hard compliance problem: a connected-device company does not have one system holding PHI. It has a wearable, a mobile application, a cloud backend, an inference pipeline, and a clinician-facing review surface — plus every partner and subprocessor in between. Each is a place where protected health information is created, transmitted, or stored, and each has to be inventoried, risk-assessed, and evidenced.

The Challenge

Anjo.ai came to Iron Fort with the problem every pre-commercial digital health company eventually hits: the compliance obligations arrive before the compliance headcount does.

  • PHI spread across a device-to-cloud pipeline. Physiological signal data flows continuously from consumer wearables into a clinical-grade platform. Establishing where PHI enters, where it rests, who can reach it, and which subprocessors touch it required a real data-flow inventory — not a diagram drawn once for a questionnaire.
  • Partner diligence gates the roadmap. Academic medical centres and platform partners run security reviews and require executed Business Associate Agreements before data-sharing begins. For a company whose clinical validation depends on those relationships, a slow or incomplete security review is a schedule risk, not a paperwork problem.
  • No full-time compliance function. Engineering and clinical validation consume the team. There was no security officer whose day job was to chase evidence, track policy approvals, or maintain a risk register.
  • Retrofitting is more expensive than building in. A platform on a regulated path accumulates design decisions — data retention, access control, audit logging, encryption — that are cheap to make correctly on day one and expensive to reverse after the fact.
  • HIPAA was not going to be the last framework. Commercial customers and enterprise partners were always going to ask for SOC 2. Running that as a second, separate project would have meant collecting much of the same evidence twice.

The Solution

Iron Fort deployed as the system of record for the whole program, rather than as a checklist run at the end of a development cycle.

Map the PHI, continuously

Iron Fort connected to Anjo.ai's cloud infrastructure and inventoried where protected health information is created, transmitted, and stored across the device-to-clinician pipeline. That inventory feeds a continuous risk analysis that updates as infrastructure changes — satisfying the HIPAA Security Rule's risk analysis requirement without an annual scramble to rebuild the picture from scratch.

Stand up the policy set

The platform's HIPAA policy library gave the team an approved administrative, physical, and technical safeguard set to work from instead of a blank page, with the AI policy analyser flagging missing required elements against the Security Rule's implementation specifications.

Manage the partner and subprocessor chain

Every Business Associate Agreement — clinical partners, cloud providers, and downstream subcontractors — is tracked centrally through its lifecycle, with alerts ahead of renewal or expiry, and the subcontractor chain mapped rather than assumed.

Make diligence answerable from the record

Control tests, policy approvals, risk decisions, and workforce training completions land in the evidence vault with tamper-evident timestamps. When a partner sends a security questionnaire or asks for an audit response package, the answer is assembled from evidence that already exists.

Run HIPAA and SOC 2 on one control set

Because the Security Rule safeguards and the SOC 2 Trust Services Criteria share a substantial control base, both frameworks are maintained against a single evidence stream — so commercial diligence does not start a second compliance project from zero.

A note on scope: Iron Fort is a compliance management platform, not an application database. Anjo.ai's patient data stays in Anjo.ai's systems — Iron Fort analyses infrastructure, policies, and controls, and Iron Fort signs a BAA with every customer.

The Outcome

The program Anjo.ai runs today is documented, continuously maintained, and produced from the same platform their engineers already work in.

A Live PHI Inventory

One maintained picture of every system, integration, and subprocessor touching protected health information across the device-to-clinician pipeline.

Diligence Without a Fire Drill

Partner security reviews are answered from a maintained evidence set, so a data-sharing conversation is not gated on weeks of document collection.

BAAs Under Control

Every agreement in the partner and subprocessor chain tracked centrally, with renewal alerts before an expiry becomes an exposure.

Room to Commercialise

HIPAA and SOC 2 maintained on a shared control set, so enterprise diligence does not restart the program at launch.

Next Case Study

SyncNurse: Documented HIPAA Training for a Distributed Nursing Workforce

Read It →

Join Our Case Study Program

Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.