Meuhedet Health Fund Fined NIS 256,000 for Delayed Reporting of Data Breach
The Israeli Privacy Protection Authority fined Meuhedet Health Fund NIS 256,000 for failing to promptly report a serious security breach that allowed unauthorized access to patients' medical information. The breach was discovered after a patient informed the fund's legal department that he could view his stepsister's medical records. Investigations revealed that Meuhedet was aware of the issue as early as November 2025 but only reported it in January 2026.
The breach involved a systemic glitch that, under certain conditions, enabled insured individuals to access medical data of their relatives. Meuhedet conducted tests and fixed the problem by the end of January 2026. The fund stated that only a limited number of people had access to unauthorized information and that only the reporting individual actually viewed the data in the past two years.
The Privacy Authority emphasized that the obligation to report such incidents immediately arises once the breach is known, even if investigations are incomplete. Initial reports can be supplemented later. The authority also clarified that the reporting duty applies regardless of the breach's cause, the responsible party, or the number of affected individuals. Even minor errors or misunderstandings that allow unauthorized access qualify as serious security events.
Gilead Samama, head of the Privacy Protection Authority, highlighted the significant sanctions under the Privacy Protection Law amendments and urged organizations to rigorously safeguard sensitive Israeli citizens' data.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.