Meuhedet was just the start: dozens of companies face heavy fines
A year after Amendment 13 to the Privacy Protection Law, enforcement is intensifying. The Privacy Protection Authority is investigating about 100 organizations for violations, including failure to report cyber incidents, with the Meuhedet HMO already receiving a significant fine.

The Meuhedet HMO received an unprecedented fine of 256,000 shekels this week from the Privacy Protection Authority, signaling a new era in enforcement in Israel. The penalty was imposed following a two-month delay in reporting a serious security incident—a systemic failure that allowed insured persons to view the sensitive medical information of their relatives. According to the Authority, the HMO was aware of the incident as early as November 2025 but failed to report it immediately.
This fine is the first exercise of powers granted by "Amendment 13 to the Privacy Protection Law." The amendment, which took effect in August 2025, represents the most comprehensive change to Israel's privacy laws in decades. It significantly expands the supervisory and enforcement powers of the Privacy Protection Authority, granting it criminal tools and the ability to impose heavy financial penalties. Furthermore, the amendment mandates the appointment of a Data Protection Officer (DPO) in organizations processing large volumes of sensitive information.
The Authority is now shifting toward aggressive enforcement, with over 100 cases currently being managed against significant entities in the economy.
Fines and the reporting deadline dispute
Each case under review carries the potential for financial sanctions, which estimates suggest could reach millions of shekels. The penalty amount is derived from legal provisions and depends on the violation type, data volume, and sensitivity. While some cases are still under review, the Authority's direction is clear.
Sources indicate that decisions are expected soon in additional cases where hearings have already taken place. Many companies have yet to complete the procedures required for compliance. The process of evidence collection and fine determination can take months, as seen in the Meuhedet case, where the report was submitted in January and the fine imposed in July.
The Authority's position is that the duty to report arises immediately upon knowledge of a violation, without waiting for internal checks to conclude. In response, Meuhedet stated: "The requirement for immediate reporting is often unrealistic and does not allow for a full clarification of details. It is puzzling that the Authority chooses to fine a public organization, and we intend to examine the possibility of an appeal."
Companies under pressure
Attorney Guy Bakshi, head of DPO services at Pearl Cohen, notes: "The first penalty under Amendment 13 is a clear signal that the Authority expects organizations to be prepared in advance, not to explain in retrospect. The amendment has given the Authority teeth, and it is ready to bite."
Dr. Dan Hai, an expert in privacy and cyber protection, adds that the impact is being felt in the field. However, he calls for a more nuanced approach: "Today, there is no distinction between an Iranian cyberattack and an innocent human error, such as an employee sending an email to the wrong address. This creates a massive reporting burden for the Authority, which may lead to missing serious, real incidents."





