Israel’s Privacy Protection Authority at the Ministry of Justice has imposed a financial penalty of NIS 256,000 on Meuhedet Health Fund. This is the first fine issued since Amendment 13 to the Privacy Protection Law took effect, in August 2025. The reason for the fine: the HMO failed to immediately report a serious data security incident within its systems.
What happened
A flaw in Meuhedet’s digital systems allowed insured members, under certain conditions, to view sensitive medical records belonging to family members. The exposure first came to light when a member contacted the HMO. He reported that he could view his stepsister’s medical file. Following that report, Meuhedet fixed the issue – at the end of January 2026.
According to the Authority, the database involved is large, containing personal information on a broad population. Among the data is medical information, which the law defines as “especially sensitive.” Meuhedet, for its part, argued otherwise: it says the actual exposure was very limited. According to the HMO, over the past two years only the member who filed the complaint had actually been exposed to another person’s data.
The core dispute: when does the reporting obligation begin
The disagreement between the parties centers mainly on timing. According to the Authority, Meuhedet was aware of the incident as early as November 2025. However, it reported the incident only about two months later – in January, and only after completing its own internal checks. The Authority’s position is clear: the duty to report immediately arises the moment unauthorized access becomes known. Therefore, there is no room to wait for internal investigations to conclude, for the scope of the breach to be mapped, or for the root cause to be identified. In other words, an initial report must be filed right away, with additional details to follow later.
In practice, this marks the Authority actively exercising the enforcement powers granted to it under Amendment 13 – tools designed to protect the public’s personal and sensitive information.
The Authority’s position
Adv. Gilad Samama, head of the Privacy Protection Authority, addressed the case in a press statement. According to him, violations of the Privacy Protection Law following the amendment can carry significant sanctions, as this case demonstrates. Accordingly, he called on companies and organizations to closely examine their information systems, in order to ensure that Israeli citizens’ sensitive data is properly protected.
Background: Amendment 13
Amendment 13 took effect in August 2025, and is considered the most significant reform to Israeli privacy law in decades. The first major change is the expansion of the Authority’s oversight and enforcement powers. Among other things, this includes the ability to impose heavy financial penalties reaching hundreds of thousands of shekels, and even to open criminal investigations. In addition, the amendment requires organizations that process large volumes of sensitive data – such as hospitals, banks, and public bodies – to appoint a Data Protection Officer (DPO). Furthermore, it expands the legal definition of “sensitive information.” At the same time, it also reduces certain technical regulatory burdens on organizations.
According to the Authority, handling this case took roughly six months. The process included gathering evidence, requesting documents, and both written and oral hearings. This, then, is the first case to reach a final decision. The Authority sees it as an opportunity to send a clear message to the market: immediate reporting of data security incidents is critical.
Meuhedet’s response
The HMO stated that it was Meuhedet itself that initiated the report to the Authority, once the exact details of the case became clear. According to the company, the case involved a single patient only. However, in its response, Meuhedet also raised criticism: it said the requirement for immediate reporting is not always realistic, and does not leave time for a full clarification of the facts. The company also expressed surprise that the Authority chose to fine a public organization. In closing, Meuhedet stated that it is considering appealing the decision.
What this means for you
The Meuhedet case is an important reminder: Amendment 13 is not merely a theoretical regulatory change. In fact, it is already being enforced in practice, with real financial consequences – even for established, well-known organizations. Therefore, the question every organization should be asking today isn’t “will this happen,” but “are we ready if it happens to us.” A few key questions worth checking: Is there an immediate reporting process in place for data security incidents? Is your organization’s sensitive data properly protected and monitored? And finally – is there a designated officer (DPO) in place, if the law requires one for you?
With that in mind, anyone who would like a quick initial snapshot of their organization’s readiness for Amendment 13 requirements is welcome to fill out a short questionnaire here.
Based on an article by Nevo Tarablsi, Globes (July 21, 2026) – link


