Israel’s Privacy Protection Authority Fines Meuhedet HMO in Landmark Enforcement of Amendment 13

Privacy Protection Law Amendment 13
For the first time since Amendment 13 to Israel's Privacy Protection Law took effect, the Privacy Protection Authority fined Meuhedet HMO 256,000 NIS for failing to immediately report a serious data security incident that exposed insured members' medical records to family members.

Israel’s Privacy Protection Authority at the Ministry of Justice has imposed a financial penalty of NIS 256,000 on Meuhedet Health Fund. This is the first fine issued since Amendment 13 to the Privacy Protection Law took effect, in August 2025. The reason for the fine: the HMO failed to immediately report a serious data security incident within its systems.

What happened

A flaw in Meuhedet’s digital systems allowed insured members, under certain conditions, to view sensitive medical records belonging to family members. The exposure first came to light when a member contacted the HMO. He reported that he could view his stepsister’s medical file. Following that report, Meuhedet fixed the issue – at the end of January 2026.

According to the Authority, the database involved is large, containing personal information on a broad population. Among the data is medical information, which the law defines as “especially sensitive.” Meuhedet, for its part, argued otherwise: it says the actual exposure was very limited. According to the HMO, over the past two years only the member who filed the complaint had actually been exposed to another person’s data.

The core dispute: when does the reporting obligation begin

The disagreement between the parties centers mainly on timing. According to the Authority, Meuhedet was aware of the incident as early as November 2025. However, it reported the incident only about two months later – in January, and only after completing its own internal checks. The Authority’s position is clear: the duty to report immediately arises the moment unauthorized access becomes known. Therefore, there is no room to wait for internal investigations to conclude, for the scope of the breach to be mapped, or for the root cause to be identified. In other words, an initial report must be filed right away, with additional details to follow later.

In practice, this marks the Authority actively exercising the enforcement powers granted to it under Amendment 13 – tools designed to protect the public’s personal and sensitive information.

The Authority’s position

Adv. Gilad Samama, head of the Privacy Protection Authority, addressed the case in a press statement. According to him, violations of the Privacy Protection Law following the amendment can carry significant sanctions, as this case demonstrates. Accordingly, he called on companies and organizations to closely examine their information systems, in order to ensure that Israeli citizens’ sensitive data is properly protected.

Background: Amendment 13

Amendment 13 took effect in August 2025, and is considered the most significant reform to Israeli privacy law in decades. The first major change is the expansion of the Authority’s oversight and enforcement powers. Among other things, this includes the ability to impose heavy financial penalties reaching hundreds of thousands of shekels, and even to open criminal investigations. In addition, the amendment requires organizations that process large volumes of sensitive data – such as hospitals, banks, and public bodies – to appoint a Data Protection Officer (DPO). Furthermore, it expands the legal definition of “sensitive information.” At the same time, it also reduces certain technical regulatory burdens on organizations.

According to the Authority, handling this case took roughly six months. The process included gathering evidence, requesting documents, and both written and oral hearings. This, then, is the first case to reach a final decision. The Authority sees it as an opportunity to send a clear message to the market: immediate reporting of data security incidents is critical.

Meuhedet’s response

The HMO stated that it was Meuhedet itself that initiated the report to the Authority, once the exact details of the case became clear. According to the company, the case involved a single patient only. However, in its response, Meuhedet also raised criticism: it said the requirement for immediate reporting is not always realistic, and does not leave time for a full clarification of the facts. The company also expressed surprise that the Authority chose to fine a public organization. In closing, Meuhedet stated that it is considering appealing the decision.

What this means for you

The Meuhedet case is an important reminder: Amendment 13 is not merely a theoretical regulatory change. In fact, it is already being enforced in practice, with real financial consequences – even for established, well-known organizations. Therefore, the question every organization should be asking today isn’t “will this happen,” but “are we ready if it happens to us.” A few key questions worth checking: Is there an immediate reporting process in place for data security incidents? Is your organization’s sensitive data properly protected and monitored? And finally – is there a designated officer (DPO) in place, if the law requires one for you?

With that in mind, anyone who would like a quick initial snapshot of their organization’s readiness for Amendment 13 requirements is welcome to fill out a short questionnaire here.


Based on an article by Nevo Tarablsi, Globes (July 21, 2026) – link

The First Step Starts Here
Professionalism
Our primary asset lies in our human capital, delivering real-time solutions on-site. Therefore, our IT technicians undergo continuous training and certification to ensure top-quality service.
Quality Assurance and Reliability
We implement high-standard quality processes that include clear procedures, documented monitoring, extensive control systems, and thorough inspections.
Availability and Teamwork
We understand the importance of maintaining the continuous operation of our clients' computer systems. Our team ensures full availability to support you whenever needed.
Integrity and Reliability
Integrity and reliability are our guiding principles, serving as a solid foundation for productive and successful collaboration.
Data Protection
T.O.M is committed to maintaining the confidentiality of information and utilizing advanced technological means to safeguard the assets of the organization and, of course, all its clients.

IT solutions designed for your peace of mind

How can we assist you?

This site uses information collection technologies such as Cookies, including by third parties, in order to provide you with a better browsing experience as well as for statistical, profiling and marketing purposes. Continued browsing of this site constitutes your consent to this. For more information and the option to manage the use of these tools, please see our updated Privacy Policy