Israeli City Fined Over Massive Medical Data Breach
The Beit Shemesh municipality in Israel has been fined 64,000 shekels (approximately $17,000 USD) by the Justice Ministry's Privacy Protection Authority following a significant data security incident. The breach exposed sensitive medical and social welfare information of around 4,600 residents due to a malfunction in the city's Geographic Information System (GIS).
The leak occurred because the GIS system, managed by an external contractor, had a flaw that made the data publicly accessible. A journalist discovered the vulnerability and reported it, after which the system was shut down and access blocked.
An investigation by the Privacy Protection Authority found that the municipality violated privacy regulations in several ways. Notably, the relationship with the external contractor was not properly documented, with the contractor having access to the database for nearly two years without being officially designated as a data "holder." Additionally, the municipality lacked adequate security protocols, failing to clearly define the scope of data access, usage purposes, and duration for the contractor.
The Beit Shemesh municipality argued that the contractor did not meet the legal definition of a data holder and described the incident as an "unintentional administrative oversight" related to legislative changes. They also claimed existing agreements were sufficient. However, the Privacy Protection Authority rejected these arguments, emphasizing the municipality's responsibility to anticipate and enforce legal requirements.
The initial fine proposed was 80,000 shekels, but it was reduced because the municipality had no similar violations in the past five years. Adi Menachem-Bar, head of enforcement at the Privacy Protection Authority, stressed the critical importance of protecting sensitive personal data, especially medical information, and the obligation of organizations to meticulously manage third-party access to such databases.