For the first time: A financial sanction of a quarter of a million NIS on the Meuhedet Health Fund - and here's the reason

Shtetl
July 21, 2026   
Photo: 
Kobi Gideon / FLASH90

The Privacy Protection Authority at the Ministry of Justice has initiated an administrative investigation against the Meuhedet Health Fund, following a report of a serious security incident that the fund forwarded to the authority.

In January of this year, the fund reported to the Privacy Protection Authority that a technological glitch had been discovered in the fund's digital system, which in certain cases allowed unauthorized access to insured people's medical information.

Due to reasonable grounds to assume that the report was not immediate, as required by the Privacy Protection Regulations, the Authority initiated an administrative investigation into the matter.

The proceedings revealed that the fund learned of the incident as early as November 2025, but did not report it immediately as required by law.

The incident began following a request from one of the health insurance fund's insured members to the fund's legal office, in which he stated that he could view his stepsister's medical file.

The database in which the incident occurred includes personal information on a very large number of data subjects, including particularly sensitive information relating to a person's health status, including medical information as defined in the Patient's Rights Law.

After about a month and a half, following tests conducted by the fund, it became clear that the malfunction in the database was widespread, and that if a combination of certain conditions were met, insured persons could view the medical information of their relatives.

At the end of January 2026, the fund carried out development to fix the problem, and it was fixed. According to the fund, viewing without permission was only possible for a limited number of people, and in the past two years, only the applicant was actually exposed to the information.

After examining the findings of the administrative investigation, and after considering the fund's claims in the matter, the Authority determined that the fund violated its obligation to immediately report the incident to the Authority. For this violation, the fund was imposed a financial sanction in the amount of NIS 256,000, after reductions in accordance with the provisions of the law.

The Authority emphasizes that the obligation to report immediately arises upon becoming aware of the occurrence of a serious security incident, and must be fulfilled close to the date of discovery and without delay. Another position, according to which the report must be waited until all tests are completed, the fault identified, its scope and consequences identified, empties the "immediacy" requirement stipulated in the regulations of its content. There may be situations in which, at the time of reporting, the reporting entity will not have the full factual picture of the incident. For this reason, the required report is an initial report, based on the information known at the time of reporting, and as additional details become clear during the examination of the incident, they can be supplemented later in a supplementary report.

The Authority clarifies that the regulations do not impose an obligation to immediately report the source of the incident or the identity of the party handling it. The relevant question is whether the company became aware that unauthorized access to information, unauthorized use of it, or damage to the integrity of the information had occurred, and not what the failure was that led to it, whether it was widespread, and how many policyholders were affected by it. There may be situations in which a specific fault, error, or misunderstanding will in itself constitute a serious security incident that requires immediate reporting, where they enable unauthorized access to information or damage its integrity.

In the circumstances of this case, at the latest at the time the applicant's permissions were blocked, the fund already had sufficient information indicating the existence of a serious security incident. The incident was actually reported only about two months later.

Head of the Privacy Protection Authority, Attorney Gilad Samma: "Violations of the Privacy Protection Law after Amendment 13 comes into effect are subject to significant financial sanctions and sanctions, as can also be seen in this case. Companies and organizations must carefully examine their information systems in order to ensure that the sensitive information of Israeli citizens is optimally protected.".

Director of the Enforcement Division at the Privacy Protection Authority, Attorney Adi Menachem Beer: "The obligation to immediately report serious information security incidents arises upon learning of the incident, and one should not wait for the completion of all inspections by the body in which the incident occurred. The Authority will not accept interpretations that empty the requirement of immediacy. It is the responsibility of those who control and hold databases, and in particular when it comes to organizations that control databases with particularly sensitive information in large volumes, to create the appropriate mechanisms in order to fulfill the obligation of immediate reporting according to the law. The Authority's enforcement division will act decisively, while activating the enforcement tools given to the Authority in Amendment 13, in order to raise the level of compliance with the law.""